Soru

Zorluk: KolaySecurity Monitoring and Threat Detection

A startup wants to implement a security solution that continuously monitors its AWS accounts for malicious activities, unauthorized access, and anomalous behavior. The solution must analyze AWS CloudTrail management logs, VPC Flow Logs, and DNS query logs with zero impact on resource performance. Which AWS service should a solutions architect recommend to satisfy these requirements?

  1. Amazon GuardDutyCevap
  2. B
    AWS WAF
  3. C
    AWS Shield
  4. D
    Network Access Control Lists (Network ACLs)

Cevap

Amazon GuardDuty
The correct answer is Amazon GuardDuty because it is a managed threat detection service that continuously monitors for malicious activity and unauthorized behavior. It does so by analyzing metadata from foundational sources such as AWS CloudTrail event logs, Amazon VPC Flow Logs, and DNS logs without affecting the performance of active EC2 instances.

Adım Adım Çözüm

1
Identify the data sources to be analyzed
The requirement specifies AWS CloudTrail management logs, VPC Flow Logs, and DNS query logs.
Selecting a service that natively integrates with and ingests these specific log sources is necessary.
2
Evaluate the detection capability needed
The target service must detect malicious activity and unauthorized behavior.
This matches a threat detection service rather than a simple firewall or access control mechanism.
3
Select the service with minimal operational overhead
Amazon GuardDuty matches all requirements and runs completely independently of workloads.
GuardDuty uses machine learning and threat intelligence to process these data sources without requiring agent deployment.

Anahtar Kavram

Continuous security monitoring and threat detection using Amazon GuardDuty
Tahmini Süre:50s
Bu soruyu puanla