A security team needs to monitor an AWS environment for active threats and unauthorized behavior. They require a solution that automatically analyzes AWS CloudTrail events, VPC Flow Logs, and DNS logs to identify activities like an Amazon EC2 instance communicating with a known malicious command-and-control server. The solution must be agentless and operate at the account level. Which AWS service should the security team use to meet these requirements?
- AAmazon Inspector
- BAmazon CloudWatch
- Amazon GuardDutyCevap
- DAWS Systems Manager
Cevap
Amazon GuardDuty
Amazon GuardDuty is the correct service because it provides intelligent threat detection. It analyzes data from AWS CloudTrail, VPC Flow Logs, and DNS logs without requiring agents, allowing it to identify suspicious activities like communication with known malicious command-and-control servers.
Adım Adım Çözüm
Anahtar Kavram
AWS Threat Detection and Logging