A security engineer must detect whether any Amazon EC2 instances are being used for cryptocurrency mining and send notifications to an Amazon Simple Notification Service (Amazon SNS) topic when related activity occurs. Which solution satisfies these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Amazon GuardDuty and create an Amazon EventBridge rule to forward cryptocurrency-related GuardDuty findings to the SNS topic..
Why this is the answer
Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads. It has built-in detection for cryptocurrency mining activities (e.g., Impact:CryptoCurrency:EC2/BitcoinTool.B!DNS). When GuardDuty detects such activity, it generates a finding. An Amazon EventBridge rule can then be configured to filter these specific GuardDuty findings and forward them to an Amazon SNS topic for notification. AWS Config custom rules with Guard custom policy could detect specific DNS queries, but GuardDuty offers a more comprehensive and managed threat detection service specifically designed for this type of malicious activity, including behavioral analysis beyond just DNS. Amazon Inspector is a vulnerability management service, not a real-time threat detection service for ongoing malicious activity like cryptocurrency mining. While VPC Flow Logs can be analyzed for DNS lookups, this approach requires significant manual effort for setup, analysis, and alert configuration compared to the automated and integrated solution provided by GuardDuty and EventBridge.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed