A logistics company manages its supply chain application on AWS. The security team needs to implement a solution that satisfies two requirements: first, automatically scanning container images stored in Amazon Elastic Container Registry (ECR) for software vulnerabilities; second, continuously monitoring the AWS environment for anomalous API activity and potential unauthorized access. Which of the following AWS services should the company use to meet these requirements? (Select two.)
- Amazon InspectorCevap
- Amazon GuardDutyCevap
- CAWS CloudTrail
- DAmazon CloudWatch
- EAWS WAF
Cevap
The logistics company should use Amazon Inspector and Amazon GuardDuty to meet these requirements.
To satisfy the requirements, the company must use a combination of vulnerability scanning and intelligent threat detection. Amazon Inspector automatically and continuously scans container images in Amazon Elastic Container Registry (ECR) for known software vulnerabilities. Amazon GuardDuty provides continuous monitoring and intelligent threat detection by analyzing API actions and logs to identify anomalous behavior and unauthorized access.
Adım Adım Çözüm
Anahtar Kavram
Vulnerability scanning and threat detection using Amazon Inspector and Amazon GuardDuty.
Tahmini Süre:1m 30s