exam questions

Exam ANS-C00 All Questions

View all questions & answers for the ANS-C00 exam

Exam ANS-C00 topic 1 question 22 discussion

Exam question from Amazon's ANS-C00
Question #: 22
Topic #: 1
[All ANS-C00 Questions]

Under increased cybersecurity concerns, a company is deploying a near real-time intrusion detection system (IDS) solution. A system must be put in place as soon as possible. The architecture consists of many AWS accounts, and all results must be delivered to a central location.
Which solution will meet this requirement, while minimizing downtime and costs?

  • A. Deploy a third-party vendor solution to perform deep packet inspection in a transit VPC.
  • B. Enable VPC Flow Logs on each VPC. Set up a stream of the flow logs to a central Amazon Elasticsearch cluster.
  • C. Enable Amazon Macie on each AWS account and configure central reporting.
  • D. Enable Amazon GuardDuty on each account as members of a central account.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
PANDU
Highly Voted 3 years, 8 months ago
Its D, question says as soon as possible , you can't setup transit vpc soon
upvoted 13 times
...
jyrajan69
Highly Voted 3 years, 4 months ago
There is no requirement to setup an IDS, ''A business is using a near real-time intrusion detection system (IDS) solution in response to growing cybersecurity concerns'- They have it in place. Looking for a solution to gather the logs and move to a location for further analyze. So should be B
upvoted 9 times
CloudSpecialist
3 years, 4 months ago
Exactly, the solution is already in place and they need to feed it data to process. https://aws.amazon.com/blogs/security/how-to-visualize-and-refine-your-networks-security-by-adding-security-group-ids-to-your-vpc-flow-logs/
upvoted 1 times
...
...
PavanKushwah123
Most Recent 2 years, 5 months ago
Correct Answer D
upvoted 1 times
...
madperro
3 years ago
Selected Answer: A
The correct answer is A: Guard Duty is not IDS/IPS. For IPS and IDS you need a third party EC2 based solution.
upvoted 2 times
Netsecissp
2 years, 9 months ago
The discussion is on IDS not IPS. So, answer would be still D.
upvoted 1 times
...
...
jeerysrthsvssd
3 years, 3 months ago
Selected Answer: D
D - an AWS blog post calls it an IDS https://aws.amazon.com/blogs/security/new-third-party-test-compares-amazon-guardduty-to-network-intrusion-detection-systems/
upvoted 3 times
...
Cyril_the_Squirl
3 years, 7 months ago
GuardDuty is Correct
upvoted 1 times
...
ChauPhan
3 years, 7 months ago
D. What is Amazon GuardDuty? PDF Kindle RSS Amazon GuardDuty is a continuous security monitoring service that analyzes and processes the following Data sources: VPC Flow Logs, AWS CloudTrail management event logs, Cloudtrail S3 data event logs, and DNS logs. It uses threat intelligence feeds, such as lists of malicious IP addresses and domains, and machine learning to identify unexpected and potentially unauthorized and malicious activity within your AWS environment. This can include issues like escalations of privileges, uses of exposed credentials, or communication with malicious IP addresses, or domains. For example, GuardDuty can detect compromised EC2 instances serving malware or mining bitcoin. It also monitors AWS account access behavior for signs of compromise, such as unauthorized infrastructure deployments, like instances deployed in a Region that has never been used, or unusual API calls, like a password policy change to reduce password strength.
upvoted 1 times
...
Ishu_awsguy
3 years, 7 months ago
AWS has got an audit done for Guardduty lately which qualifies it to be an effective IDS . https://aws.amazon.com/blogs/security/new-third-party-test-compares-amazon-guardduty-to-network-intrusion-detection-systems/ So i think we should go with D
upvoted 2 times
...
Ishu_awsguy
3 years, 7 months ago
A is the correct answer no doubt . No other AWS service provides deep inspection (IDS)
upvoted 2 times
...
Santya
3 years, 7 months ago
Answer is D - GuardDuty is a cloud-centric IDS service that uses Amazon Web Services (AWS) data sources to detect a broad range of threat behaviors. Refer the link https://aws.amazon.com/blogs/security/new-third-party-test-compares-amazon-guardduty-to-network-intrusion-detection-systems/#:~:text=GuardDuty%20is%20a%20cloud%2Dcentric,solutions%20for%20network%20threat%20detection.
upvoted 1 times
...
CloudArchitect
3 years, 7 months ago
A: is the answer. AWS does not offer service for deep packet inspections. IDS solutions in AWS Marketplace can be combined with various AWS services such as Amazon CloudWatch, a monitoring service for resources and applications you run on AWS. Additional services like Amazon Inspector, an automated security assessment service, can also be complemented by offerings in AWS Marketplace. https://aws.amazon.com/mp/scenarios/security/ids/
upvoted 2 times
...
cardiryh
3 years, 7 months ago
I would go for D "The service uses machine learning, anomaly detection, and integrated threat intelligence to identify and prioritize potential threats. GuardDuty analyzes tens of billions of events across multiple AWS data sources, such as AWS CloudTrail event logs, Amazon VPC Flow Logs, and DNS logs. With a few clicks in the AWS Management Console, GuardDuty can be enabled with no software or hardware to deploy or maintain. By integrating with Amazon CloudWatch Events, GuardDuty alerts are actionable, easy to aggregate across multiple accounts, and straightforward to push into existing event management and workflow systems"
upvoted 1 times
...
liono
3 years, 7 months ago
Guard duty is AWS managed threat detection service so the answer is D
upvoted 1 times
...
Erso
3 years, 7 months ago
I think the correct answer is A: Guard Duty is intelligent detection and threat but not IDS/IPS...for IPS and IDS you need a third party solution https://aws.amazon.com/it/mp/scenarios/security/ids/
upvoted 8 times
...
sensor
3 years, 7 months ago
Couldn't find clear statement(Aws doc, public writings) that GuardDuty replaces an IDS tool, but provides 'some functionality' of an IDS therefore not confident with D. However, would go for D because of all reqs in question: asap delivery, near real time IDS, multiaccount support. Still have not good feeling about it and if it's just a question trap.
upvoted 1 times
...
RahulMishra
3 years, 7 months ago
Guard duty is equivalent of IPS IDS devices.
upvoted 3 times
...
andyo
3 years, 8 months ago
A. Third Party
upvoted 3 times
andyo
3 years, 8 months ago
Correction. It is D. Guard Duty. "Near Real Time Detection" "Must be put in place as soon as possible". These statements points to GUARD DUTY. Answer A talks about Deep Packet Inspection which although helpful and close is NOT requirement of question.
upvoted 2 times
andyo
3 years, 7 months ago
GuardDuty identifies threats by continuously monitoring the network activity and account behavior within the AWS environment. Amazon GuardDuty comes integrated with up-to-date threat intelligence feeds In addition to detecting threats, GuardDuty also makes it easy to automate how you respond to threats, reducing your remediation and recovery time. GuardDuty makes enablement and management across multiple accounts easy. Through the multi-account feature, all member accounts findings can be aggregated with a GuardDuty administrator account.
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...