Soru

Zorluk: OrtaThreat Detection and Vulnerability Management

A retail company wants to continuously monitor its AWS accounts, Amazon EC2 instances, and container workloads for potential security threats, such as instances communicating with known malicious IP addresses or performing unauthorized API calls. The solution must use threat intelligence and machine learning to identify these anomalies. Which AWS service should the company use to meet these requirements?

  1. Amazon GuardDutyCevap
  2. B
    Amazon Inspector
  3. C
    AWS CloudTrail
  4. D
    AWS Artifact

Cevap

Amazon GuardDuty
Amazon GuardDuty is the correct choice because it is a dedicated threat detection service that continuously monitors for malicious activity and unauthorized behavior. It uses machine learning, anomaly detection, and integrated threat intelligence to identify threats such as cryptocurrency mining, credential compromise, or communications with known malicious command-and-control servers.

Adım Adım Çözüm

1
Identify the primary security requirement.
The requirement is to continuously monitor AWS workloads and accounts for active threats, such as communication with malicious IPs, using threat intelligence and machine intelligence.
This helps distinguish between active threat detection (analyzing behaviors/logs) and vulnerability scanning (identifying static security flaws).
2
Evaluate the capabilities of the available AWS security services.
Amazon GuardDuty uses machine learning and threat intelligence to analyze data sources like VPC Flow Logs, DNS logs, and CloudTrail logs to detect active threats. Amazon Inspector scans for software vulnerabilities. AWS CloudTrail records API calls. AWS Artifact provides compliance reports.
Matching the requirements to the correct service definition ensures the most appropriate service is chosen.

Anahtar Kavram

Continuous threat detection using machine learning and threat intelligence in AWS.
Bu soruyu puanla