Soru

Zorluk: KolaySecurity Monitoring and Threat Detection

A retail company wants to implement a solution to continuously monitor its AWS accounts and workloads for threat patterns, such as Amazon EC2 instances communicating with known malicious IP addresses or unexpected IAM activity. Which AWS service should the company use to meet this requirement?

  1. Amazon GuardDutyCevap
  2. B
    AWS Shield
  3. C
    AWS WAF
  4. D
    Amazon VPC Security Groups

Cevap

Amazon GuardDuty
Amazon GuardDuty is the correct choice because it is a threat detection service that continuously monitors for malicious activity and unauthorized behavior. It uses threat intelligence feeds and machine learning to identify signatures such as cryptocurrency mining, communication with known command-and-control servers, and abnormal API patterns.

Adım Adım Çözüm

1
Analyze the requirements for continuous threat detection across AWS accounts and workloads, specifically for malicious IP communication and unexpected account activity.
Identify that the solution requires a service capable of processing multiple log sources (VPC Flow Logs, DNS logs, and CloudTrail logs) and performing anomaly detection.
Understanding the security monitoring scope helps select the appropriate service.
2
Evaluate the capabilities of the available AWS security services against the requirements.
Determine that Amazon GuardDuty is designed for threat detection by analyzing these logs, while firewalls and DDoS protection services act as enforcement mechanisms rather than logging/detection engines.
This isolates the correct threat detection service from traffic filtering services.

Anahtar Kavram

Continuous threat detection and security monitoring across workloads and account activity using Amazon GuardDuty.
Tahmini Süre:45s
Bu soruyu puanla