Examtopics

AWS Certified Security - Specialty
  • Topic 1 Question 272

    A company uses Amazon Elastic Kubernetes Service (Amazon EKS) clusters to run its Kubernetes-based applications. The company uses Amazon GuardDuty to protect the applications.

    EKS Protection is enabled in GuardDuty. However, the corresponding GuardDuty feature is not monitoring the Kubernetes-based applications.

    Which solution will cause GuardDuty to monitor the Kubernetes-based applications?

    • Enable VPC flow logs for the VPC that hosts the EKS clusters.

    • Assign the CloudWatchEventsFullAccess AWS managed policy to the EKS clusters.

    • Ensure that the AmazonGuardDutyFullAccess AWS managed policy is attached to the GuardDuty service role.

    • Enable the control plane logs in Amazon EKS. Ensure that the logs are ingested into Amazon CloudWatch.


    シャッフルモード