SCS-C03 · Question #104
A company is migrating container workloads from a data center to Amazon Elastic Container Service (Amazon ECS) clusters. The company must implement a solution to detect potential threats in the worklo
The correct answer is B. Enable Amazon GuardDuty Runtime Monitoring on the ECS clusters.. Amazon GuardDuty Runtime Monitoring is specifically designed to detect potential threats and improve the security posture of Amazon ECS clusters. GuardDuty Runtime Monitoring provides detailed analysis of container activity to identify potential security issues, such as unusual b
Question
A company is migrating container workloads from a data center to Amazon Elastic Container Service (Amazon ECS) clusters. The company must implement a solution to detect potential threats in the workloads and to improve the security posture of the container clusters. Which solution will meet these requirements?
Options
- AConfigure Amazon Inspector on the VPC that is running the ECS clusters.
- BEnable Amazon GuardDuty Runtime Monitoring on the ECS clusters.
- CAudit Amazon ECS API access by using Amazon CloudWatch logs to identify unauthorized
- DCreate container clusters in the same VPC. Use VPC flow logs to centrally monitor network traffic.
How the community answered
(49 responses)- A12% (6)
- B78% (38)
- C6% (3)
- D4% (2)
Explanation
Amazon GuardDuty Runtime Monitoring is specifically designed to detect potential threats and improve the security posture of Amazon ECS clusters. GuardDuty Runtime Monitoring provides detailed analysis of container activity to identify potential security issues, such as unusual behavior within the ECS environment. This approach is effective for monitoring both network and application-level threats in containerized workloads.
Topics
Community Discussion
No community discussion yet for this question.