ANS-C01 · Question #62
A company is running multiple workloads on Amazon EC2 instances in public subnets. In a recent incident, an attacker exploited an application vulnerability on one of the EC2 instances to gain access t
Sign in or unlock ANS-C01 to reveal the answer and full explanation for question #62. The question stem and answer options stay visible for context.
Question
A company is running multiple workloads on Amazon EC2 instances in public subnets. In a recent incident, an attacker exploited an application vulnerability on one of the EC2 instances to gain access to the instance. The company fixed the application and launched a replacement EC2 instance that contains the updated application. The attacker used the compromised application to spread malware over the internet. The company became aware of the compromise through a notification from AWS. The company needs the ability to identify when an application that is deployed on an EC2 instance is spreading malware. Which solution will meet this requirement with the LEAST operational effort?
Options
- AUse Amazon GuardDuty to analyze traffic patterns by inspecting DNS requests and VPC flow
- BUse Amazon GuardDuty to deploy AWS managed decoy systems that are equipped with the
- CSet up a Gateway Load Balancer. Run an intrusion detection system (IDS) appliance from AWS
- DConfigure Amazon Inspector to perform deep packet inspection of outgoing traffic.
Unlock ANS-C01 to see the answer
You've previewed enough free ANS-C01 questions. Unlock ANS-C01 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.