After an attacker exploited an application vulnerability on an internet-facing EC2 instance and spread malware over the internet, the company fixed the app and replaced the instance. The company needs a low-operational-effort solution that detects when an application deployed on an EC2 instance is propagating malware. Which approach meets this requirement with the least operational overhead?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Amazon GuardDuty to analyze traffic patterns by inspecting DNS requests and VPC flow logs..
Why this is the answer
Amazon GuardDuty is the most suitable option because it is a fully managed threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect AWS accounts and workloads. It analyzes various data sources, including VPC Flow Logs and DNS logs, to identify patterns indicative of malware propagation, such as unusual DNS queries or outbound connections to known malicious IP addresses. This approach requires minimal operational overhead as GuardDuty is enabled with a few clicks and automatically updates its threat intelligence. The other options are less ideal: Deploying AWS managed decoy systems with GuardDuty is not a standard GuardDuty feature for malware detection and would introduce significant operational complexity. Setting up a Gateway Load Balancer with an IDS appliance involves deploying and managing EC2 instances, the Gateway Load Balancer, and the IDS software, leading to higher operational overhead. Amazon Inspector focuses on vulnerability management and security best practices for EC2 instances and container images, not real-time deep packet inspection of outgoing traffic for malware detection.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed