Soru

Zorluk: KolaySecurity Monitoring and Threat Detection

A company wants to continuously monitor its AWS environment for unauthorized activity and threat behavior, such as EC2 instances communicating with known malicious IP addresses or performing cryptocurrency mining. Which strategy should a solutions architect recommend to detect these security threats?

  1. A
    Deploy AWS Shield Advanced to analyze and block application-layer exploits and automated web scraping attacks.
  2. B
    Configure stateless Network ACL rules at the subnet level to dynamically detect and inspect packet payloads for malicious command-and-control communications.
  3. Enable Amazon GuardDuty to analyze metadata from sources such as AWS CloudTrail logs, VPC Flow Logs, and DNS query logs.Cevap
  4. D
    Enable VPC Flow Logs and configure Security Groups at the subnet level to dynamically block unauthorized outgoing traffic.

Cevap

Enable Amazon GuardDuty to analyze metadata from sources such as AWS CloudTrail logs, VPC Flow Logs, and DNS query logs.
Amazon GuardDuty is a continuous threat detection service that monitors for malicious activity and unauthorized behavior to protect your AWS accounts, workloads, Kubernetes clusters, and data stored in Amazon S3. It analyzes metadata from sources such as AWS CloudTrail events, Amazon VPC Flow Logs, and DNS query logs to identify threats like communication with command-and-control servers or cryptocurrency mining.

Adım Adım Çözüm

1
Identify the core security requirement, which is to detect unauthorized behavior and malicious activities like cryptocurrency mining and command-and-control communication across the AWS environment.
The requirement is dynamic threat detection and behavior monitoring rather than static packet filtering or DDoS prevention.
This establishes that a continuous threat monitoring service is needed.
2
Evaluate the AWS services capable of analyzing logs and metadata to detect security anomalies.
Amazon GuardDuty is built specifically for this purpose and integrates out-of-the-box with CloudTrail, VPC Flow Logs, and DNS logs.
This identifies the correct service aligned with AWS best practices.

Anahtar Kavram

Continuous Threat Detection and Security Monitoring using Amazon GuardDuty
Bu soruyu puanla