A company's web application is hosted on Amazon EC2 instances running behind an Application Load Balancer (ALB) in an Auto Scaling group. An AWS WAF web ACL is associated with the ALB. AWS CloudTrail is enabled, and stores logs in Amazon S3 and Amazon CloudWatch Logs.
The Operations team has observed some EC2 instances reboot at random. After rebooting, all access logs on the instances have been deleted. During an investigation, the Operations team found that each reboot happened just after a PHP error occurred on the new-user-creation.php file. The Operations team needs to view log information to determine if the company is being attacked.
Which set of actions will identify the suspect attacker's IP address for future occurrences?
[Removed]
Highly Voted 3 years, 9 months agoHungdv
Highly Voted 3 years, 9 months agoRaphaello
Most Recent 1 year, 5 months agoOCHT
2 years, 1 month agoITGURU51
2 years, 3 months agoboooliyooo
2 years, 6 months agosapien45
2 years, 11 months agoMoreOps
3 years, 3 months agoTigerInTheCloud
3 years, 3 months agosapien45
3 years agof4bi4n
3 years, 3 months agoRadhaghosh
3 years, 6 months agosiddhu__33
3 years, 8 months agoskipbaylessfor3
3 years, 8 months agoMarcis
3 years, 9 months agocldy
3 years, 9 months agoeskimolander
3 years, 9 months agoAyusef
3 years, 10 months agoAyusef
3 years, 9 months agoChinkSantana
3 years, 9 months agoDayQuil
3 years, 10 months agoca777
3 years, 9 months agoEdgecrusher77
3 years, 9 months ago