Soru

Zorluk: OrtaThreat Detection and Vulnerability Management

A health-tech company hosts its patient management portal on Amazon EC2 instances. The security team needs a service that can continuously monitor the AWS environment for potential security threats, such as command-and-control (C2) activity, unauthorized API calls, and brute-force attacks on the instances. Which AWS service is designed to perform this type of intelligent threat detection?

  1. A
    AWS CloudTrail
  2. B
    Amazon Inspector
  3. Amazon GuardDutyCevap
  4. D
    AWS Managed Infrastructure Security (as AWS is responsible for detecting threats within customer EC2 operating systems)

Cevap

Amazon GuardDuty
Amazon GuardDuty is the correct service because it provides intelligent threat detection by continuously monitoring logs (such as VPC Flow Logs, AWS CloudTrail management events, and DNS logs) using machine learning and threat intelligence to identify suspicious activities like brute-force attacks and command-and-control communication.

Adım Adım Çözüm

1
Analyze the business and security requirements in the scenario.
The company needs continuous, intelligent threat detection to identify malicious activities like command-and-control activity, brute-force attacks, and unauthorized API calls within their AWS environment.
Identifying the target behavior (active threat detection) helps narrow down the appropriate AWS security service category.
2
Evaluate the capabilities of the proposed AWS security services.
Amazon GuardDuty uses threat intelligence feeds and machine learning to detect anomalies and unauthorized activities across AWS accounts and workloads, matching all specified requirements.
This step distinguishes active log-based threat detection (GuardDuty) from package vulnerability scanning (Inspector) or API logging (CloudTrail).

Anahtar Kavram

Active threat detection and monitoring on AWS
Tahmini Süre:1m 0s
Bu soruyu puanla