Soru

Zorluk: KolaySecurity Monitoring and Threat Detection

A company needs to implement a security monitoring strategy for its AWS environment. The strategy must include auditing all API activities for unauthorized actions and automatically detecting when security groups are modified to allow unrestricted public access (0.0.0.0/0). Which of the following actions should the solutions architect take to meet these requirements? (Select TWO.)

  1. Enable AWS CloudTrail to record and audit all API activity across the AWS account.Cevap
  2. Create an AWS Config rule to automatically monitor and detect when security groups are modified to allow unrestricted public traffic.Cevap
  3. C
    Deploy AWS Shield Standard to inspect application-layer traffic and automatically block SQL injection exploits on the web application.
  4. D
    Configure stateful Network Access Control Lists (NACLs) to log, monitor, and restore the configuration history of individual security groups.
  5. E
    Store administrative credentials as plaintext String parameters in Systems Manager Parameter Store to automate threat remediation scripts.

Cevap

Enable AWS CloudTrail to record all API activity, and create an AWS Config rule to monitor security group modifications.
AWS CloudTrail logs and monitors all API activity across the AWS account, providing auditing capability for unauthorized modifications. AWS Config continuously records configuration changes of AWS resources, such as security groups, and evaluates them against compliance rules (e.g., detecting if a security group allows unrestricted 0.0.0.0/0 ingress traffic). Together, these services fulfill the requirements of monitoring API changes and detecting insecure resource configurations.

Adım Adım Çözüm

1
Identify the requirement for tracking and auditing API actions.
AWS CloudTrail is selected to log all API calls across the AWS account.
CloudTrail provides a complete history of API activity, enabling security auditing and monitoring.
2
Identify the requirement for monitoring and alerting on resource configuration compliance.
AWS Config is chosen to detect security group compliance violations.
AWS Config continuously monitors resource configurations and evaluates them against rules (e.g., checking for unrestricted port access).

Anahtar Kavram

AWS CloudTrail is used for auditing and monitoring API activity, while AWS Config is used to monitor, audit, and evaluate the configurations of AWS resources.
Tahmini Süre:1m 0s
Bu soruyu puanla