A company is migrating containerized workloads to Amazon Elastic Container Service (Amazon ECS) clusters. The company needs to detect potential threats in the workloads and enhance the security posture of the clusters. Which solution meets these needs?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Amazon GuardDuty Runtime Monitoring for the ECS clusters..
Why this is the answer
Enabling Amazon GuardDuty Runtime Monitoring for ECS clusters is the most effective solution because it provides real-time threat detection for containerized workloads. GuardDuty's Runtime Monitoring specifically analyzes runtime activity within ECS tasks, identifying malicious or unauthorized behavior like cryptocurrency mining, unauthorized access, or unusual process execution. This directly addresses the need to detect potential threats and enhance the security posture of the clusters. Other options are less comprehensive: Enabling Amazon Inspector on the VPC is insufficient as Inspector primarily focuses on vulnerability management for EC2 instances and container images, not runtime threat detection within ECS tasks. Auditing ECS API calls with CloudWatch Logs helps detect unauthorized API access but doesn't monitor the runtime behavior of the containers themselves for in-process threats. Placing clusters in the same VPC and using VPC flow logs provides network visibility but does not offer deep insight into the internal activities or potential threats within the running containers.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed