Soru

Zorluk: OrtaSecurity Logging, Monitoring, and Auditing

A media streaming company is preparing for a security compliance review. The audit team needs to verify which IAM identity made the API calls to modify the configuration of an Amazon S3 bucket containing sensitive customer billing data. At the same time, the security team wants to set up automated threat detection to identify potential unauthorized activity or compromised credentials in their AWS environment. Which combination of AWS services should the company use to meet these requirements?

  1. AWS CloudTrail to audit the API calls, and Amazon GuardDuty for threat detectionCevap
  2. B
    Amazon CloudWatch to audit the API calls, and AWS CloudTrail for threat detection
  3. C
    AWS CloudTrail to audit the API calls, and Amazon Inspector for threat detection
  4. D
    AWS Managed Infrastructure logs provided under the Shared Responsibility Model to audit the API calls, and AWS Shield for threat detection

Cevap

AWS CloudTrail to audit the API calls, and Amazon GuardDuty for threat detection
AWS CloudTrail logs, continuously monitors, and retains account activity related to actions taken across your AWS infrastructure, satisfying the requirement to audit IAM identity actions on S3 buckets. Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior, satisfying the requirement to identify potential threat vectors like compromised credentials.

Adım Adım Çözüm

1
Identify the service required to track and audit configuration modifications and API actions.
AWS CloudTrail is chosen because it specifically logs, continuously monitors, and retains account activity related to actions taken across your AWS infrastructure.
Auditing access records and verifying which IAM identity performed an operation requires API auditing capabilities.
2
Identify the service required for active, automated threat detection and identifying compromised credentials.
Amazon GuardDuty is selected as it uses machine learning and threat intelligence to detect malicious behavior and unauthorized activities in AWS accounts.
Vulnerability scanners do not monitor live account activity for anomalies like compromised credentials; dedicated threat detection is required.

Anahtar Kavram

Differentiating security monitoring, API logging, and threat detection services in AWS
Bu soruyu puanla