ExamQuestions.com

Register
Login
AWS Certified DevOps Engineer Professional Exam Questions

Amazon

AWS Certified DevOps Engineer Professional

490 / 500

Question 490:

Your company needs to place automated security policy enforcement in the AWS environment. One requirement is that a system can detect the undesired activities from VPC Flow Logs, AWS CloudTrail logs, and DNS logs. For example, when a compromised EC2 instance is probing a port on a large number of public IP addresses and trying to find vulnerable hosts to exploit, the system can detect this activity from the VPC Flow logs and generate the security findings. How would you set up this system in an easy way?

Answer options:

A.Enable all features in Amazon Macie to automatically discover security issues and protect the AWS environment using machine learning and pattern matching.
B.Create multiple CloudWatch Event rules and Lambda functions to generate security findings based on the abnormal activities in CloudTrail logs, VPC flow logs and DNS logs.
C.Enable AWS Config through AWS Security Hub to detect security issues and continuously aggregate and prioritize the findings.
D.Enable Amazon GuardDuty to pull and analyze independent streams of data from AWS CloudTrail management and Amazon S3 data events, VPC flow logs, and DNS logs to generate security findings.