Soru

Zorluk: OrtaSecurity Monitoring and Threat Detection

A logistics company hosts a web application on Amazon EC2 instances within a public subnet of a VPC. The security team needs a solution to detect potential SSH brute-force attempts and malicious port scans from the internet. Additionally, they want to ensure that any unauthorized modifications to the VPC subnets' Network Access Control Lists (NACLs) are automatically detected and flagged as non-compliant. Which combination of actions should a solutions architect recommend to meet these requirements? (Select TWO.)

  1. Enable Amazon GuardDuty to monitor and analyze VPC Flow Logs for anomalous network behaviors, such as SSH brute-force attacks and port scanning.Cevap
  2. Deploy an AWS Config rule to track configuration changes of Network ACLs and evaluate compliance against the company's security baseline.Cevap
  3. C
    Configure stateless security groups to block inbound traffic and automatically log return traffic on ephemeral ports to track malicious sources.
  4. D
    Enable AWS Shield Advanced to analyze Layer 7 application traffic and automatically block SQL injection and SSH brute-force attacks.
  5. E
    Generate access keys for the AWS account root user to run a cron job on an EC2 instance that queries and logs changes to the Network ACLs.

Cevap

Enable Amazon GuardDuty to monitor and analyze VPC Flow Logs, and deploy an AWS Config rule to track configuration changes of Network ACLs.
Enabling Amazon GuardDuty allows the logistics company to leverage intelligent threat detection that automatically monitors VPC Flow Logs to identify malicious activities like SSH brute-force attempts and port scans. Concurrently, deploying an AWS Config rule enables continuous compliance tracking by monitoring configuration changes to resource types like Network ACLs and flagging any unauthorized changes that deviate from the defined baseline, aligning with the AWS Well-Architected Framework's security pillar.

Adım Adım Çözüm

1
Enable Amazon GuardDuty to detect threat patterns in network traffic.
GuardDuty will continuously ingest VPC Flow Logs and use threat intelligence to identify anomalies, such as brute-force attacks and port scans.
This provides real-time detection of network anomalies and threats without requiring manual log analysis.
2
Deploy AWS Config and set up a rule for Network ACLs.
AWS Config will record configuration changes to Network ACLs and automatically evaluate them against compliance baselines.
This implements automated compliance tracking and drift detection for critical network boundary configurations.

Anahtar Kavram

Continuous security monitoring using AWS GuardDuty for network threats and AWS Config for configuration compliance.
Tahmini Süre:1m 30s
Bu soruyu puanla