A fintech startup is deploying a digital wallet application. The environment consists of Amazon EC2 instances running payment processing software and containerized microservices hosted on Amazon Elastic Container Registry (Amazon ECR). The security team requires a solution to automatically scan these instances and container images for software vulnerabilities, and to continuously analyze log sources like VPC Flow Logs and CloudTrail events to detect malicious activity or unauthorized behavior. Which AWS services should the startup use to meet these requirements? (Select two.)
- Amazon InspectorCevap
- BAWS CloudTrail
- Amazon GuardDutyCevap
- DAmazon CloudWatch
- EAmazon Macie
Cevap
The correct services are Amazon Inspector and Amazon GuardDuty.
Amazon Inspector satisfies the requirement to scan Amazon EC2 instances and Amazon ECR container images for software vulnerabilities. Amazon GuardDuty satisfies the requirement to continuously monitor log sources like VPC Flow Logs and AWS CloudTrail events for active threats and malicious activity.
Adım Adım Çözüm
Anahtar Kavram
Identifying the respective purposes of Amazon Inspector for vulnerability scanning and Amazon GuardDuty for threat detection, while distinguishing them from logging, monitoring, and data privacy services.