exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C02 exam

Exam AWS Certified Solutions Architect - Associate SAA-C02 topic 1 question 367 discussion

An administrator of a large company wants to monitor for and prevent any cryptocurrency-related attacks on the company's AWS accounts.
Which AWS service can the administrator use to protect the company against attacks?

  • A. Amazon Cognito
  • B. Amazon GuardDuty
  • C. Amazon Inspector
  • D. Amazon Macie
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dmscountera
Highly Voted 3 years, 7 months ago
B. Amazon GuardDuty
upvoted 37 times
noahsark
3 years, 7 months ago
i think B too. Document below to save everyone some time: https://aws.amazon.com/premiumsupport/knowledge-center/resolve-guardduty-crypto-alerts/
upvoted 21 times
Harshul
3 years, 6 months ago
Thanks, much appreciate.
upvoted 1 times
...
...
...
Atanu_M
Highly Voted 3 years, 7 months ago
B. What is Amazon GuardDuty? PDF Kindle RSS Amazon GuardDuty is a continuous security monitoring service that analyzes and processes the following Data sources: VPC Flow Logs, AWS CloudTrail management event logs, Cloudtrail S3 data event logs, and DNS logs. It uses threat intelligence feeds, such as lists of malicious IP addresses and domains, and machine learning to identify unexpected and potentially unauthorized and malicious activity within your AWS environment. This can include issues like escalations of privileges, uses of exposed credentials, or communication with malicious IP addresses, or domains. For example, GuardDuty can detect compromised EC2 instances serving malware or mining bitcoin. It also monitors AWS account access behavior for signs of compromise, such as unauthorized infrastructure deployments, like instances deployed in a Region that has never been used, or unusual API calls, like a password policy change to reduce password strength.
upvoted 25 times
...
sofiella
Most Recent 2 years, 3 months ago
A. Amazon Cognito is a user identity and data synchronization service that helps securely manage and synchronize app data for any size user base across multiple devices. It is not specifically designed to protect against cryptocurrency-related attacks. B. Amazon GuardDuty is a threat detection service that uses machine learning and behavioral analysis to identify and prioritize potential security threats to AWS accounts and workloads. It can be used to detect and prevent cryptocurrency-related attacks by identifying suspicious activities and alerting administrators. C. Amazon Inspector is a security assessment service that helps improve the security and compliance of applications deployed on AWS. It assesses applications for vulnerabilities or deviations from best practices, but it is not specifically designed to protect against cryptocurrency-related attacks. Ans-B
upvoted 1 times
...
alex1491
2 years, 10 months ago
Selected Answer: B
C is wrong. AWS inspector Automated security assessments for EC2 instances. Answer is B
upvoted 3 times
...
examJack
3 years, 1 month ago
Selected Answer: B
Amazon GuardDuty generates findings that indicate potential security issues. * Detect GuardDuty can detect compromised EC2 instances serving malware or mining bitcoin. It also monitors AWS account access behavior for signs of compromise, such as unauthorized infrastructure deployments, like instances deployed in a Region that has never been used, or unusual API calls, like a password policy change to reduce password strength. * Remediating security issues discovered by GuardDuty Remediating a compromised EC2 instance Remediating a compromised S3 Bucket Remediating compromised AWS credentials Remediating Kubernetes security issues discovered by GuardDuty https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_remediate.html
upvoted 3 times
...
Sharan_25_v
3 years, 4 months ago
Selected Answer: B
According to Stephen Marek Course it is B
upvoted 2 times
...
nutouch
3 years, 4 months ago
Selected Answer: B
Guard Duty:to analyze logs -analyze Cloudtrail ,VPC flow, DNS logs -No need to install any sw since only analyzing logs -Can protect against CryptoCurrency attacks
upvoted 2 times
...
shamg
3 years, 4 months ago
Proactive v/s Reactive - GuardDuty v/s Inspector
upvoted 1 times
...
Gomer
3 years, 5 months ago
https://docs.aws.amazon.com/guardduty/latest/ug/what-is-guardduty.html "GuardDuty can detect compromised EC2 instances serving malware or mining bitcoin."
upvoted 1 times
...
gargaditya
3 years, 5 months ago
B.Guard Duty NOTES: Shield: 1.Shield Standard enabled by default/no need to enable 2.Shield Standard is L3 L4 only eg.SYN/UDP floods,Reflectionattacks,etc 3.Shield Advanced includes L7 as well 4.Sield Advanced gives DDoS protection NOT shield Shield Standard!!! 5.Shield Advanced includes WAF bundled with it 6.Shield Advanced gives access to dedicated DRT(DDos Response Team) 7.Shield advanced gives protection against high fees during usage spikes due to DDoS Inspector:for ec2 -provides security assessments on EC2(known vulnerabilities) -need to install sw(agent) on EC2 (unless using just the 'network assessment' feature--agentless) Guard Duty:to analyze logs -analyze Cloudtrail ,VPC flow, DNS logs -No need to install any sw since only analysing logs -Can protect against CryptoCurrency attacks <<<<<<<<<< Macie:for S3 discover and protect your sensitive data(eg PII) in AWS
upvoted 9 times
RidzV
3 years, 5 months ago
As always, your notes are extremely useful. Thanks for sharing. :)
upvoted 1 times
...
gargaditya
3 years, 5 months ago
WAF:L7 protection -Deploy only on Cloudfront,ALB, API GW -contains Web ACL/rules -can do rate-based rules(to count no fo events)/this also helps in DDoS protection -It protects against common attacks like SQL injection and XSS(Cross Site scripting)--ie L7 based attacks
upvoted 3 times
...
...
vvsandipvv
3 years, 6 months ago
monitorint - go with Amazon GuardDuty
upvoted 1 times
...
Cotter
3 years, 6 months ago
ฺฺฺฺฺฺฺฺฺฺฺฺฺฺฺฺฺฺฺBBBBBBBBBBBBBBBBB
upvoted 2 times
...
Res2
3 years, 6 months ago
Answer: B Amazon GuardDuty -> protect aws account , workload and s3 Amazon Inspector -> protect EC2
upvoted 3 times
mahdeo01
3 years, 6 months ago
NOTE the difference between Inspector & GuardDuty # Inspector is a Proactive tool and used for Compliance or Threat Detection whereas GuardDuty is a Reactive tool that actively monitors the threats as it happens.
upvoted 1 times
...
...
jkwek
3 years, 6 months ago
Answer is B. https://aws.amazon.com/guardduty/ Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts, workloads, and data stored in Amazon S3.
upvoted 2 times
...
massyg
3 years, 7 months ago
Why not C?
upvoted 1 times
mh97
3 years, 6 months ago
Because inspector only monitors it doesn't monitor and protect against threats.
upvoted 2 times
...
...
Suresh108
3 years, 7 months ago
BBBBB *** Ref: https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#cryptocurrency-ec2-bitcointoolbdns
upvoted 3 times
...
leliodesouza
3 years, 7 months ago
The answer is B.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago