A company wants to continuously monitor its AWS resource configurations to ensure they comply with security standards. The company also needs a centralized dashboard to aggregate security alerts and evaluate compliance against the CIS AWS Foundations Benchmark. Which TWO services should the solutions architect recommend to meet these requirements?
- AWS Config to track resource configuration changes and evaluate compliance against desired configurationsCevap
- AWS Security Hub to aggregate security alerts from multiple AWS services and run automated compliance checks against industry standardsCevap
- CAWS Shield Advanced to automatically monitor and detect application-layer exploits such as SQL injection
- DAWS WAF to monitor API configuration logs and track resource compliance changes across regions
- EVPC Network Access Control Lists (NACLs) to statefully inspect resource modifications and block non-compliant configuration changes
Cevap
AWS Config and AWS Security Hub
AWS Config is the correct service for tracking, auditing, and evaluating configurations of AWS resources. AWS Security Hub is the correct service for aggregating security findings from multiple AWS services and evaluating compliance against security standards (such as the CIS AWS Foundations Benchmark). Together, they satisfy the requirement of continuous configuration compliance monitoring and centralized alert aggregation.
Adım Adım Çözüm
Anahtar Kavram
Continuous security monitoring, compliance checks, and centralized security posture management using AWS Config and AWS Security Hub.