ETExamTower
Q8

HOTSPOT - A company is designing its security monitoring strategy for an existing sensitive workload on AWS. The security team has identified several scenarios that require monitoring strategies. Select the correct monitoring strategy from the following list for each monitoring scenario. Select each monitoring strategy one time. Automatically isolate Amazon EC2 distances when malware detection findings are confirmed. Correlate security findings from multiple AWS detection services to identify multi-stage attacks. Detect when privileged users perform an unusually high volume of resource deletion operations. Identify patterns of more than 50 failed authentication attempts from specific IP addresses in 1 hour. Monitor network traffic patterns especially large data transfers to external IP addresses outside normal office hours. Configure VPC Flow Logs with Amazon CloudWatch Logs Insights queries to analyze traffic volume and destination patterns during specific time windows.

Question exhibit
← → navigate · a answer
Discussion · 3
2
VPC Flow Logs + CloudWatch Logs Insights -> Monitor network traffic patterns especially large data transfers to external IP addresses outside normal office hours CloudWatch metric filters on application logs -> Identify patterns of more than 50 failed authentication attempts from specific IP addresses in 1 hour CloudTrail Insights -> Detect when privileged users perform an unusually high volume of resource deletion operations Security Hub + EventBridge + Lambda - > Automatically isolate Amazon EC2 instances when malware detection findings are confirmed ??? (Security Hub) -> Correlate security findings from multiple AWS detection services to identify multi-stage attacks Security Hub aggregates: • GuardDuty • Inspector • Macie Provides correlation across services
1
1 Monitor network traffic 2 Identify patterns of more than 50 failed 3 Detect when privileged users 4 Automatically isolate Amazon EC2 5 Correlate security findings
1
Multiple AWS detection services would have thrown me off. Security Hub plus Eventbridge does make sense though.