Soru

Zorluk: ZorThreat Detection and Vulnerability Management

A fintech startup is deploying a digital wallet application. The environment consists of Amazon EC2 instances running payment processing software and containerized microservices hosted on Amazon Elastic Container Registry (Amazon ECR). The security team requires a solution to automatically scan these instances and container images for software vulnerabilities, and to continuously analyze log sources like VPC Flow Logs and CloudTrail events to detect malicious activity or unauthorized behavior. Which AWS services should the startup use to meet these requirements? (Select two.)

  1. Amazon InspectorCevap
  2. B
    AWS CloudTrail
  3. Amazon GuardDutyCevap
  4. D
    Amazon CloudWatch
  5. E
    Amazon Macie

Cevap

The correct services are Amazon Inspector and Amazon GuardDuty.
Amazon Inspector satisfies the requirement to scan Amazon EC2 instances and Amazon ECR container images for software vulnerabilities. Amazon GuardDuty satisfies the requirement to continuously monitor log sources like VPC Flow Logs and AWS CloudTrail events for active threats and malicious activity.

Adım Adım Çözüm

1
Analyze the requirement for vulnerability scanning of Amazon EC2 instances and Amazon ECR container images.
Amazon Inspector is identified as the AWS service that automates software vulnerability and network exposure scans for these resources.
Inspector has native integration to scan EC2 instances and ECR repositories.
2
Analyze the requirement for continuous monitoring and threat detection of malicious activity using logs (VPC Flow Logs, CloudTrail, DNS).
Amazon GuardDuty is identified as the service that performs intelligent threat detection using these log sources.
GuardDuty uses machine learning and threat intelligence feeds to detect anomalies and unauthorized behavior in AWS accounts.
3
Evaluate and eliminate incorrect services based on their primary functions.
AWS CloudTrail, Amazon CloudWatch, and Amazon Macie are excluded as they do not perform the requested combination of host vulnerability scanning and broad threat detection.
CloudTrail is for API logging, CloudWatch is for performance monitoring and basic log management, and Macie is restricted to finding sensitive data within S3 buckets.

Anahtar Kavram

Identifying the respective purposes of Amazon Inspector for vulnerability scanning and Amazon GuardDuty for threat detection, while distinguishing them from logging, monitoring, and data privacy services.
Bu soruyu puanla