exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 272 discussion

A company uses Amazon Elastic Kubernetes Service (Amazon EKS) clusters to run its Kubernetes-based applications. The company uses Amazon GuardDuty to protect the applications.

EKS Protection is enabled in GuardDuty. However, the corresponding GuardDuty feature is not monitoring the Kubernetes-based applications.

Which solution will cause GuardDuty to monitor the Kubernetes-based applications?

  • A. Enable VPC flow logs for the VPC that hosts the EKS clusters.
  • B. Assign the CloudWatchEventsFullAccess AWS managed policy to the EKS clusters.
  • C. Ensure that the AmazonGuardDutyFullAccess AWS managed policy is attached to the GuardDuty service role.
  • D. Enable the control plane logs in Amazon EKS. Ensure that the logs are ingested into Amazon CloudWatch.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Pat9595
4 days, 8 hours ago
Selected Answer: D
For GuardDuty to monitor Kubernetes-based applications in Amazon EKS, EKS Protection in GuardDuty requires the integration of control plane logs. These logs contain critical information about the health and security of the EKS clusters, which GuardDuty uses to detect potential threats and vulnerabilities.
upvoted 1 times
...
m_ch333
1 month ago
Selected Answer: D
When you enable EKS Protection, GuardDuty will be able to access your Amazon EKS audit logs only for continuous threat detection. So you need to ensure the audit logs is enabled first. https://docs.aws.amazon.com/eks/latest/userguide/integration-guardduty.html
upvoted 1 times
...
DewDrop
2 months, 2 weeks ago
https://docs.aws.amazon.com/guardduty/latest/ug/kubernetes-protection.html
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago