A company wants to use machine learning capabilities to analyze log data from its Amazon EC2 instances and efficiently conduct security investigations.
C: Amazon Detective
A managed security service that helps security analysts investigate security issues. Detective can analyze security findings from multiple sources, including GuardDuty, to help identify the root cause of malicious activity. Detective provides interactive visualizations and insights to help users investigate issues more quickly.
Amazon GuardDuty
A threat detection service that continuously monitors AWS environments for unauthorized access and malicious activity. GuardDuty provides real-time alerts and detailed findings to help security teams respond to security incidents.
Amazon GuardDuty
Amazon GuardDuty is a threat detection service that continuously monitors, analyzes, and processes specific AWS data sources and logs in your AWS environment. GuardDuty uses threat intelligence feeds, such as lists of malicious IP addresses and domains, and machine learning (ML) models to identify unexpected, and potentially unauthorized activity in your AWS environment. This includes the following issues:
Honestly, it could be either Detective or Guard Duty:
https://aws.amazon.com/detective/
If you look at the picture, Detective scans VPC Flow Logs, AWS CloudTrail event logs, and EKS Audit Logs too
C. Amazon Detective
Amazon Detective is a fully managed service that helps you to investigate potential security issues or suspicious activities across your AWS environment, including EC2 instances. It automatically collects log data from multiple AWS sources, such as VPC Flow Logs, CloudTrail, and GuardDuty findings, and uses machine learning, statistical analysis, and graph theory to build interactive visualizations and make it easier to identify security issues and conduct investigations.
C. Amazon Detective
Amazon Detective makes it easy to analyze, investigate, and quickly identify the root cause of security issues or suspicious activities. It automatically collects log data from your AWS resources and uses machine learning, statistical analysis, and graph theory to build a linked set of data that enables you to easily conduct investigations. While Amazon GuardDuty is effective for detecting threats, Amazon Detective specializes in analyzing and investigating the security findings that GuardDuty and other services detect, making it an excellent choice for efficiently conducting security investigations with machine learning capabilities.
upvoted 4 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Nikmah
2 weeks, 6 days agoMark_DeSade
2 months agod00b229
4 months, 3 weeks agonewSJ
6 months, 2 weeks agonewSJ
6 months, 2 weeks agoahadh7621
7 months, 2 weeks agoahadh7621
7 months, 2 weeks agoahadh7621
7 months, 2 weeks agochalaka
9 months, 1 week agoAsylgul
10 months, 1 week ago