ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 566 - SAA-C03 discussion

Report
Export

A company has deployed its newest product on AWS. The product runs in an Auto Scaling group behind a Network Load Balancer. The company stores the product's objects in an Amazon S3 bucket.

The company recently experienced malicious attacks against its systems. The company needs a solution that continuously monitors for malicious activity in the AWS account, workloads, and access patterns to the S3 bucket. The solution must also report suspicious activity and display the information on a dashboard.

Which solution will meet these requirements?

A.
Configure Amazon Made to monitor and report findings to AWS Config.
Answers
A.
Configure Amazon Made to monitor and report findings to AWS Config.
B.
Configure Amazon Inspector to monitor and report findings to AWS CloudTrail.
Answers
B.
Configure Amazon Inspector to monitor and report findings to AWS CloudTrail.
C.
Configure Amazon GuardDuty to monitor and report findings to AWS Security Hub.
Answers
C.
Configure Amazon GuardDuty to monitor and report findings to AWS Security Hub.
D.
Configure AWS Config to monitor and report findings to Amazon EventBridge.
Answers
D.
Configure AWS Config to monitor and report findings to Amazon EventBridge.
Suggested answer: C

Explanation:

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior across the AWS account and workloads. GuardDuty analyzes data sources such as AWS CloudTrail event logs, Amazon VPC Flow Logs, and DNS logs to identify potential threats such as compromised instances, reconnaissance, port scanning, and data exfiltration. GuardDuty can report its findings to AWS Security Hub, which is a service that provides a comprehensive view of the security posture of the AWS account and workloads. Security Hub aggregates, organizes, and prioritizes security alerts from multiple AWS services and partner solutions, and displays them on a dashboard. This solution will meet the requirements, as it enables continuous monitoring, reporting, and visualization of malicious activity in the AWS account, workloads, and access patterns to the S3 bucket.

1 provides an overview of Amazon GuardDuty and its benefits.

2 explains how GuardDuty generates and reports findings based on threat detection.

3 provides an overview of AWS Security Hub and its benefits.

4 describes how Security Hub collects and displays findings from multiple sources on a dashboard

asked 16/09/2024
Dario Esposito
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first