Topic 1 Question 272
A company uses Amazon Elastic Kubernetes Service (Amazon EKS) clusters to run its Kubernetes-based applications. The company uses Amazon GuardDuty to protect the applications.
EKS Protection is enabled in GuardDuty. However, the corresponding GuardDuty feature is not monitoring the Kubernetes-based applications.
Which solution will cause GuardDuty to monitor the Kubernetes-based applications?
Enable VPC flow logs for the VPC that hosts the EKS clusters.
Assign the CloudWatchEventsFullAccess AWS managed policy to the EKS clusters.
Ensure that the AmazonGuardDutyFullAccess AWS managed policy is attached to the GuardDuty service role.
Enable the control plane logs in Amazon EKS. Ensure that the logs are ingested into Amazon CloudWatch.
ユーザの投票
コメント(3)
- 👍 1DewDrop2024/11/24
- 正解だと思う選択肢: D
When you enable EKS Protection, GuardDuty will be able to access your Amazon EKS audit logs only for continuous threat detection. So you need to ensure the audit logs is enabled first. https://docs.aws.amazon.com/eks/latest/userguide/integration-guardduty.html
👍 1m_ch3332025/01/04 - 正解だと思う選択肢: D
For GuardDuty to monitor Kubernetes-based applications in Amazon EKS, EKS Protection in GuardDuty requires the integration of control plane logs. These logs contain critical information about the health and security of the EKS clusters, which GuardDuty uses to detect potential threats and vulnerabilities.
👍 1Pat95952025/02/02
シャッフルモード