A startup wants to implement a security solution that continuously monitors its AWS accounts for malicious activities, unauthorized access, and anomalous behavior. The solution must analyze AWS CloudTrail management logs, VPC Flow Logs, and DNS query logs with zero impact on resource performance. Which AWS service should a solutions architect recommend to satisfy these requirements?
- Amazon GuardDutyCevap
- BAWS WAF
- CAWS Shield
- DNetwork Access Control Lists (Network ACLs)
Cevap
Amazon GuardDuty
The correct answer is Amazon GuardDuty because it is a managed threat detection service that continuously monitors for malicious activity and unauthorized behavior. It does so by analyzing metadata from foundational sources such as AWS CloudTrail event logs, Amazon VPC Flow Logs, and DNS logs without affecting the performance of active EC2 instances.
Adım Adım Çözüm
Anahtar Kavram
Continuous security monitoring and threat detection using Amazon GuardDuty
Tahmini Süre:50s