Soru

Zorluk: Çok zorThreat Detection and Vulnerability Management

A financial technology startup has deployed application microservices across multiple AWS accounts. To protect their workloads, the startup's security team needs to implement a solution that continuously scans their container images and virtual machines for software vulnerabilities, while also analyzing log sources (such as VPC Flow Logs and DNS query logs) to detect active threats and potential data exfiltration. Which of the following AWS services should the startup configure to address both of these requirements? (Select two.)

  1. Amazon GuardDuty to continuously monitor and analyze log sources for active security threats and anomalous behaviors.Cevap
  2. Amazon Inspector to automatically scan container images and virtual machine instances for known software vulnerabilities.Cevap
  3. C
    AWS CloudTrail to perform deep packet inspection on network traffic and block unauthorized vulnerability scanning attempts.
  4. D
    Amazon Macie to scan host operating systems for open ports and apply critical security patches automatically.
  5. E
    AWS Shield to monitor system files for integrity and automatically quarantine compromised virtual machines.

Cevap

Amazon GuardDuty for active threat detection and Amazon Inspector for vulnerability scanning
Amazon GuardDuty and Amazon Inspector are the correct choices. Amazon GuardDuty is the managed intelligent threat detection service that monitors VPC Flow Logs, DNS logs, and CloudTrail event logs to identify threats like command-and-control communication or data exfiltration. Amazon Inspector is the automated vulnerability management service that scans EC2 instances and ECR container images for software vulnerabilities and unintended network exposure.

Adım Adım Çözüm

1
Analyze the requirement for active threat detection based on log monitoring.
Identify that the startup needs to detect anomalies and unauthorized activities by analyzing DNS logs and VPC Flow Logs.
Amazon GuardDuty uses machine learning and threat intelligence to analyze AWS logs (CloudTrail, VPC Flow Logs, DNS query logs) to detect active threats.
2
Analyze the requirement for host and container vulnerability management.
Identify that the startup needs to scan virtual machines and container images for software vulnerabilities.
Amazon Inspector is designed specifically to automate vulnerability assessment for Amazon EC2 workloads and Amazon Elastic Container Registry (ECR) images.
3
Evaluate and eliminate incorrect services based on their functions.
Exclude AWS CloudTrail, Amazon Macie, and AWS Shield as they perform auditing, sensitive data discovery, and DDoS protection respectively, rather than host vulnerability scanning or broad log-based threat detection.
Correctly identifying the primary purpose of each AWS security service ensures compliance with the AWS Shared Responsibility Model and architectural best practices.

Anahtar Kavram

AWS Threat Detection and Vulnerability Management using Amazon GuardDuty and Amazon Inspector
Tahmini Süre:2m 0s
Bu soruyu puanla