A global financial firm is designing a security monitoring architecture for its multi-account AWS environment managed via AWS Organizations. The firm needs to detect network anomalies, malicious activity, and unauthorized API calls across all accounts, and aggregate these findings into a single dashboard in a dedicated security account. Additionally, they must ensure that any unauthorized modifications of network security configurations, such as security groups and network ACLs, are automatically detected and flagged for compliance auditing. Which combination of actions should a solutions architect recommend to meet these requirements? (Select TWO.)
- Enable Amazon GuardDuty across all accounts, designate the dedicated security account as the GuardDuty delegated administrator, and integrate GuardDuty findings with AWS Security Hub in the security account.Cevap
- Create AWS Config organizational rules to continuously monitor configuration changes of security groups and network ACLs, and aggregate compliance results in the dedicated security account.Cevap
- CDeploy AWS WAF at the VPC subnet level in all accounts to inspect and log inbound and outbound traffic, and stream these logs to Amazon CloudWatch for threat detection.
- DConfigure stateful network ACLs to block malicious IPs flagged by Amazon GuardDuty, and use AWS CloudTrail to capture and analyze real-time network traffic flows.
- EEnable AWS Shield Advanced on all subnet boundaries to block Layer 7 application exploits, and configure security groups to log stateless packet inspections.
Cevap
Enable Amazon GuardDuty across all accounts, designating the security account as the delegated administrator and integrating with AWS Security Hub, while using AWS Config organizational rules to monitor security group and network ACL configurations.
Centralizing threat detection and compliance tracking in a multi-account organization involves using Amazon GuardDuty integrated with AWS Security Hub to monitor activities and logs, combined with AWS Config organizational rules to track changes to resources like security groups and network ACLs.
Adım Adım Çözüm
Anahtar Kavram
Centralized threat detection and resource configuration compliance auditing in multi-account environments.
Tahmini Süre:2m 0s