Soru

Zorluk: OrtaThreat Detection and Vulnerability Management

A renewable energy company operates a fleet of Amazon EC2 instances to monitor wind turbine telemetry and stores its deployment packages in Amazon Elastic Container Registry (Amazon ECR). The company needs to implement a solution that continuously scans its container images and virtual machines for software vulnerabilities, while also monitoring its AWS accounts for potential unauthorized behavior and DNS data exfiltration attempts.

Which of the following AWS services should the company use to meet these requirements? (Select two.)

  1. Amazon InspectorCevap
  2. Amazon GuardDutyCevap
  3. C
    Amazon Macie
  4. D
    AWS CloudTrail
  5. E
    Amazon CloudWatch

Cevap

Amazon Inspector and Amazon GuardDuty
The correct services are Amazon Inspector and Amazon GuardDuty. Amazon Inspector is designed for vulnerability management, scanning EC2 instances and container images for software vulnerabilities. Amazon GuardDuty is an intelligent threat detection service that monitors logs to identify malicious activity such as DNS data exfiltration.

Adım Adım Çözüm

1
Analyze the requirement for scanning EC2 virtual machines and ECR container images for software vulnerabilities.
Identify Amazon Inspector as the service that automates software vulnerability management for these resources.
Amazon Inspector specifically performs package and software vulnerability scanning on host instances and registry containers.
2
Analyze the requirement for continuous threat detection and monitoring for unauthorized behavior and DNS exfiltration.
Identify Amazon GuardDuty as the service providing intelligent threat detection.
Amazon GuardDuty analyzes VPC Flow Logs, DNS logs, and other sources to detect malicious operations and exfiltration attempts.
3
Evaluate the remaining options to ensure they do not meet the primary goals.
Eliminate Amazon Macie, AWS CloudTrail, and Amazon CloudWatch as they do not scan hosts for software vulnerabilities or perform active threat detection.
These services focus on sensitive data discovery in S3, API call logging, and performance monitoring respectively.

Anahtar Kavram

Differentiating vulnerability management (Amazon Inspector) from threat detection (Amazon GuardDuty) and other AWS security and logging services.
Bu soruyu puanla