SCS-C02 · Question #15
A company recently had a security audit in which the auditors identified multiple potential threats. These potential threats can cause usage pattern changes such as DNS access peak, abnormal…
The correct answer is C. Enable Amazon GuardDuty from a centralized account. Use GuardDuty to manage AWS. https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_data-sources.html
Question
A company recently had a security audit in which the auditors identified multiple potential threats. These potential threats can cause usage pattern changes such as DNS access peak, abnormal instance traffic, abnormal network interface traffic, and unusual Amazon S3 API calls. The threats can come from different sources and can occur at any time. The company needs to implement a solution to continuously monitor its system and identify all these incoming threats in near-real time. Which solution will meet these requirements?
Options
- AEnable AWS CloudTrail logs, VPC flow logs, and DNS logs. Use Amazon CloudWatch Logs to
- BEnable AWS CloudTrail logs, VPC flow logs, and DNS logs. Use Amazon Macie to monitor these
- CEnable Amazon GuardDuty from a centralized account. Use GuardDuty to manage AWS
- DEnable Amazon Inspector from a centralized account. Use Amazon Inspector to manage AWS
How the community answered
(29 responses)- A3% (1)
- B10% (3)
- C83% (24)
- D3% (1)
Explanation
https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_data-sources.html
Topics
Community Discussion
No community discussion yet for this question.