ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 102 - 312-40 discussion

Report
Export

Being a cloud security administrator, Jonathan is responsible for securing the large-scale cloud infrastructure of his organization SpectrumIT Solutions. The organization has to implement a threat detection and analysis system so that Jonathan would receive alerts regarding all misconfigurations and network intrusions in the organization's cloud infrastructure. Which AWS service would enable him to use to receive alerts related to risks?

A.
Amazon SQS
Answers
A.
Amazon SQS
B.
Amazon VPC
Answers
B.
Amazon VPC
C.
Amazon SNS
Answers
C.
Amazon SNS
D.
Amazon GuardDuty
Answers
D.
Amazon GuardDuty
Suggested answer: D

Explanation:

1.Amazon GuardDuty: It is a threat detection service that continuously monitors for malicious activity and unauthorized behavior across your AWS accounts and workloads1.

1.Continuous Monitoring: GuardDuty keeps an eye on the cloud environment for potential threats by analyzing various data sources, including VPC flow logs, CloudTrail event logs, and DNS logs1.

1.Alerts for Risks: When GuardDuty detects a potential threat or misconfiguration, it generates detailed security findings, which can be used to notify administrators like Jonathan of the risks1.

1.Machine Learning and Threat Intelligence: The service uses machine learning and integrated threat intelligence to identify and classify threats, providing actionable insights for remediation1.

1.Integration with AWS Services: GuardDuty can integrate with other AWS services such as Amazon SNS for notifications, enabling automated responses to detected threats1.

AWS's official documentation on Amazon GuardDuty1.

asked 18/09/2024
Christopher Adams
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first