A media streaming company is preparing for a security compliance review. The audit team needs to verify which IAM identity made the API calls to modify the configuration of an Amazon S3 bucket containing sensitive customer billing data. At the same time, the security team wants to set up automated threat detection to identify potential unauthorized activity or compromised credentials in their AWS environment. Which combination of AWS services should the company use to meet these requirements?
- AWS CloudTrail to audit the API calls, and Amazon GuardDuty for threat detectionCevap
- BAmazon CloudWatch to audit the API calls, and AWS CloudTrail for threat detection
- CAWS CloudTrail to audit the API calls, and Amazon Inspector for threat detection
- DAWS Managed Infrastructure logs provided under the Shared Responsibility Model to audit the API calls, and AWS Shield for threat detection
Cevap
AWS CloudTrail to audit the API calls, and Amazon GuardDuty for threat detection
AWS CloudTrail logs, continuously monitors, and retains account activity related to actions taken across your AWS infrastructure, satisfying the requirement to audit IAM identity actions on S3 buckets. Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior, satisfying the requirement to identify potential threat vectors like compromised credentials.
Adım Adım Çözüm
Anahtar Kavram
Differentiating security monitoring, API logging, and threat detection services in AWS