Soru

Zorluk: KolayThreat Detection and Vulnerability Management

An automobile manufacturer is migrating its web applications to AWS and wants to establish automated security checks. The manufacturer needs to implement software vulnerability assessments on its application hosts and monitor AWS account activity for potential security threats. Which AWS services should be selected to fulfill these requirements? (Select two.)

  1. Amazon InspectorCevap
  2. Amazon GuardDutyCevap
  3. C
    AWS CloudTrail
  4. D
    Amazon CloudWatch
  5. E
    AWS Artifact

Cevap

Amazon Inspector and Amazon GuardDuty should be selected to meet the requirements.
Amazon Inspector is the correct choice for host and software vulnerability scanning on instances and containers. Amazon GuardDuty is the correct choice for continuous threat detection and monitoring of malicious activity across AWS accounts.

Adım Adım Çözüm

1
Identify the requirement for software vulnerability assessment on application hosts.
Determine that Amazon Inspector is the AWS service designed to automatically scan EC2 instances and containers for known software vulnerabilities.
Host security scanning is a core feature of Amazon Inspector.
2
Identify the requirement to monitor AWS account activity for active security threats.
Determine that Amazon GuardDuty is the AWS service that uses intelligent threat detection to identify unauthorized or malicious activity across AWS accounts.
Threat detection based on account activity and network logs is a core feature of Amazon GuardDuty.

Anahtar Kavram

AWS threat detection and vulnerability management services
Bu soruyu puanla