A ridesharing service processes real-time driver and passenger location data on AWS. The security department wants to establish automated threat detection that monitors their AWS accounts for anomalous behavior, such as API activity from unrecognized IP addresses, compromised credentials, or EC2 instances communicating with malicious IP addresses. The service must analyze AWS CloudTrail event logs, VPC Flow Logs, and DNS logs. Which AWS service meets these needs?
- Amazon GuardDutyCevap
- BAmazon Inspector
- CAWS CloudTrail
- DAWS Shield
Cevap
Amazon GuardDuty
Amazon GuardDuty is a threat detection service that continuously monitors AWS accounts and workloads for malicious activity and unauthorized behavior. It uses machine learning, anomaly detection, and integrated threat intelligence to analyze data sources such as AWS CloudTrail event logs, VPC Flow Logs, and DNS logs to identify issues like compromised credentials or EC2 instances communicating with known malicious hosts.
Adım Adım Çözüm
Anahtar Kavram
Amazon GuardDuty is an intelligent threat detection service that analyzes multiple AWS log sources (CloudTrail, VPC Flow Logs, DNS logs) to identify malicious activity and unauthorized behavior.