Soru

Zorluk: Çok zorSecurity Logging, Monitoring, and Auditing

A digital healthcare company hosts a patient portal on AWS and must meet strict regulatory compliance requirements for security monitoring and auditing. The compliance and operations teams define three specific requirements:
1. Every API call made by IAM users or AWS services must be recorded, stored securely, and cryptographically validated to ensure the integrity of the audit logs.
2. System administrators must receive real-time alerts if application-level logs on Amazon EC2 instances show a sudden spike in specific error codes.
3. The environment must be continuously analyzed for malicious activity, such as instances scanning for open ports or communicating with known malicious IP addresses.

Which of the following configurations should the company implement to meet these requirements? (Select TWO.)

  1. Configure AWS CloudTrail with log file integrity validation enabled to record and verify account-wide API calls, and deploy the Amazon CloudWatch agent on EC2 instances to stream application logs to CloudWatch Logs for metric filtering and alerting.Cevap
  2. Enable Amazon GuardDuty to continuously analyze VPC Flow Logs, CloudTrail management events, and DNS logs in order to detect and alert on threat patterns and unauthorized communications.Cevap
  3. C
    Enable Amazon Inspector to continuously scan CloudTrail logs and Amazon S3 buckets for real-time unauthorized API requests and immediately block them.
  4. D
    Configure Amazon CloudWatch Logs to capture all API actions across the AWS account and use its built-in cryptographic validation to secure the audit trail against unauthorized modifications.
  5. E
    Configure AWS Shield to monitor application logs for error codes and automatically patch operating system vulnerabilities on EC2 instances.

Cevap

The correct configurations are the ones utilizing AWS CloudTrail for API auditing and log validation, CloudWatch Logs for EC2 log streaming and alerting, and Amazon GuardDuty for threat detection.
The correct configuration combines AWS CloudTrail and Amazon CloudWatch Logs to address API auditing and application error alerting respectively, and uses Amazon GuardDuty for active threat monitoring. AWS CloudTrail provides log file integrity validation to ensure compliance logs remain unaltered, and the CloudWatch agent is used to export application logs to CloudWatch Logs for alerting. Amazon GuardDuty consumes sources like VPC Flow Logs, DNS logs, and CloudTrail events to identify threats like malicious IP communication and port scanning.

Adım Adım Çözüm

1
Identify the service responsible for recording and validating account-wide API calls.
AWS CloudTrail is identified as the service that records API activity and offers log file integrity validation.
This satisfies the first requirement of cryptographically validating all AWS API calls for audit trail integrity.
2
Determine the mechanism for collecting application logs from EC2 instances and triggering real-time alerts on error patterns.
Deploying the CloudWatch agent on EC2 instances allows log streaming to CloudWatch Logs, where metric filters and CloudWatch Alarms handle threshold alerts.
This satisfies the second requirement of alerting system administrators on EC2 application log errors.
3
Determine the service designed to continuously detect threats and malicious behaviors like port scanning or communicating with bad IPs.
Amazon GuardDuty is selected as it continuously monitors VPC Flow Logs, DNS logs, and CloudTrail events for threat detection.
This satisfies the third requirement of intelligent threat analysis and anomalous behavior detection.
4
Synthesize the findings to select the two options that correctly configure these services.
One option correctly pairs CloudTrail and CloudWatch Logs, while another correctly selects Amazon GuardDuty.
This matches the target requirements exactly while avoiding the services that are either misconfigured or mapped to wrong responsibilities.

Anahtar Kavram

AWS security logging, monitoring, and auditing services (CloudTrail, CloudWatch, GuardDuty) and their operational differences.
Bu soruyu puanla