Soru

Zorluk: KolayThreat Detection and Vulnerability Management

A logistics company wants to secure its cloud infrastructure. The development team needs a service to automatically scan their container images in Amazon Elastic Container Registry (ECR) for known software vulnerabilities. At the same time, the security team needs a service to continuously monitor their AWS accounts for malicious activity and unauthorized behavior. Which two AWS services should the company use to meet these requirements? (Select two.)

  1. Amazon InspectorCevap
  2. Amazon GuardDutyCevap
  3. C
    AWS CloudTrail
  4. D
    AWS Artifact
  5. E
    AWS Shield

Cevap

Amazon Inspector and Amazon GuardDuty are the correct services for vulnerability scanning of container images and intelligent threat detection, respectively.
Amazon Inspector is correct because it is the AWS service that automatically discovers and scans workloads, including Amazon ECR container images, for software vulnerabilities. Amazon GuardDuty is correct because it continuously monitors AWS accounts, workloads, and data for malicious activity and anomalies, such as credential compromise or data exfiltration.

Adım Adım Çözüm

1
Identify the requirement for software vulnerability scanning in Amazon ECR.
Amazon Inspector is identified as the AWS service designed to automatically scan container images in Amazon ECR for known vulnerabilities.
This matches the development team's need to check their software packages and dependencies.
2
Identify the requirement for continuous threat detection and monitoring for malicious activity.
Amazon GuardDuty is identified as the intelligent threat detection service that monitors AWS accounts and workloads for anomalous behavior.
This matches the security team's need to identify potential threats and unauthorized actions.

Anahtar Kavram

AWS threat detection and vulnerability management services
Bu soruyu puanla