A financial technology company wants to continuously monitor its AWS accounts for malicious activity and unauthorized behavior. The company needs a service that can analyze AWS CloudTrail event logs, VPC Flow Logs, and DNS logs using threat intelligence and machine learning to detect issues like compromised EC2 instances or unauthorized API calls. Which AWS service should the company use to meet this requirement?
- Amazon GuardDutyCevap
- BAmazon Inspector
- CAWS CloudTrail
- DAWS Shield
Cevap
Amazon GuardDuty
The correct service is Amazon GuardDuty because it is a threat detection service that continuously monitors AWS accounts and workloads for malicious activity. It analyzes metadata from AWS CloudTrail event logs, VPC Flow Logs, and DNS logs to identify threats like compromised credentials, communication with known malicious IPs, or anomalous behavior.
Adım Adım Çözüm
Anahtar Kavram
Intelligent threat detection using log analysis