A company wants to continuously monitor its AWS environment for unauthorized activity and threat behavior, such as EC2 instances communicating with known malicious IP addresses or performing cryptocurrency mining. Which strategy should a solutions architect recommend to detect these security threats?
- ADeploy AWS Shield Advanced to analyze and block application-layer exploits and automated web scraping attacks.
- BConfigure stateless Network ACL rules at the subnet level to dynamically detect and inspect packet payloads for malicious command-and-control communications.
- Enable Amazon GuardDuty to analyze metadata from sources such as AWS CloudTrail logs, VPC Flow Logs, and DNS query logs.Cevap
- DEnable VPC Flow Logs and configure Security Groups at the subnet level to dynamically block unauthorized outgoing traffic.
Cevap
Enable Amazon GuardDuty to analyze metadata from sources such as AWS CloudTrail logs, VPC Flow Logs, and DNS query logs.
Amazon GuardDuty is a continuous threat detection service that monitors for malicious activity and unauthorized behavior to protect your AWS accounts, workloads, Kubernetes clusters, and data stored in Amazon S3. It analyzes metadata from sources such as AWS CloudTrail events, Amazon VPC Flow Logs, and DNS query logs to identify threats like communication with command-and-control servers or cryptocurrency mining.
Adım Adım Çözüm
Anahtar Kavram
Continuous Threat Detection and Security Monitoring using Amazon GuardDuty