Soru

Zorluk: OrtaSecurity Logging, Monitoring, and Auditing

A media company is looking for a way to continuously monitor its AWS accounts and workloads for malicious activities, such as cryptocurrency mining, unauthorized data access, or compromised credentials. The solution must automatically analyze data from AWS CloudTrail logs, VPC Flow Logs, and DNS query logs to identify threats. Which AWS service should the company use to meet this requirement?

  1. A
    Amazon Inspector
  2. B
    Amazon CloudWatch
  3. Amazon GuardDutyCevap
  4. D
    AWS Artifact

Cevap

Amazon GuardDuty
Amazon GuardDuty is the correct service because it continuously monitors AWS accounts and workloads for malicious activity by analyzing data from sources like AWS CloudTrail, VPC Flow Logs, and DNS logs.

Adım Adım Çözüm

1
Identify the primary goal of the scenario: continuously monitoring AWS workloads for malicious activities, unauthorized access, and compromised credentials.
Threat detection requirement.
Enables selection of security services rather than operational or compliance services.
2
Analyze the data sources specified: AWS CloudTrail logs, VPC Flow Logs, and DNS query logs.
Identify the service that natively ingests and analyzes these three specific log sources.
Differentiates from vulnerability scanners that inspect instances directly.
3
Select the service that performs intelligent threat detection using machine learning and anomaly detection.
Amazon GuardDuty is selected as the correct answer.
It is the only service designed to actively process these logs to find threats.

Anahtar Kavram

Intelligent threat detection and security monitoring using Amazon GuardDuty
Bu soruyu puanla