Soru

Zorluk: OrtaSecurity Monitoring and Threat Detection

A retail corporation manages multiple AWS accounts using AWS Organizations. The security team wants to establish a centralized security monitoring solution to detect threats, such as anomalous behavior or unauthorized API calls, and aggregate security compliance findings across all member accounts. The solution must align with the AWS Well-Architected Framework.

Which combination of actions should a solutions architect recommend to meet these requirements? (Select TWO.)

  1. Enable Amazon GuardDuty in all accounts, and designate a security account as the delegated administrator to centrally manage threat detection findings.Cevap
  2. Enable AWS Security Hub in all accounts, and designate the security account as the delegated administrator to aggregate security and compliance alerts.Cevap
  3. C
    Configure stateless Network ACLs on all subnets to inspect and block unauthorized AWS API calls at the network boundary.
  4. D
    Deploy AWS Shield Standard on the Application Load Balancers to inspect incoming HTTP/HTTPS requests for application-layer SQL injection exploits.
  5. E
    Store sensitive API credentials as plaintext parameters in the Systems Manager Parameter Store to facilitate quick environment configuration audits.

Cevap

Enable Amazon GuardDuty in all accounts with a delegated administrator, and enable AWS Security Hub in all accounts with a delegated administrator.
The correct options are enabling Amazon GuardDuty and AWS Security Hub with delegated administrator accounts. GuardDuty leverages machine learning, anomaly detection, and threat intelligence to identify suspicious activities like unauthorized API calls. Security Hub acts as the single pane of glass to aggregate and prioritize compliance assessments and alerts across the AWS Organizations hierarchy.

Adım Adım Çözüm

1
Analyze the requirement for centralized threat detection.
Amazon GuardDuty monitors threat patterns and anomalies across all accounts using a delegated administrator architecture.
This provides the required near-real-time threat detection for anomalous behavior and unauthorized API calls.
2
Analyze the requirement for aggregating compliance findings.
AWS Security Hub centrally aggregates compliance and security posture findings from GuardDuty, Config, and other security services.
This meets the requirement to centrally aggregate and prioritize security alerts and compliance checks.

Anahtar Kavram

Centralized threat detection and security aggregation in multi-account organizations.
Tahmini Süre:2m 0s
Bu soruyu puanla