|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/practice-exams-aws-certified-security-specialty/
课程评论:没有评论
课程名称:AWS认证安全专家 - 专业实践考试 课程概述:准备参加AWS认证安全专家SCS-C02考试?本课程是为您提供竞争优势的实践考试。这些实践考试由Stephane Maarek和Abhishek Singh共同编写,他们共同拥有20项AWS认证的丰富经验。问题的语气和风格模拟真实考试,提供详细描述和“考试提醒”,并广泛引用AWS文档,以帮助您了解SCS-C02考试所涵盖的各个领域。我们希望您将本课程视为最终的冲刺站,以便您能够充满信心地通过考试,获得AWS认证!我们相信我们的过程,您在专业的支持下,定能取得成功。所有问题均为原创,并且我们会不断增加新的问题,质量自会显而易见。 示例问题:一家公司最近部署了Amazon GuardDuty来监视AWS环境中的潜在安全威胁。安全团队发现来自某个Amazon EC2实例的RDP暴力破解攻击频繁,决定采取措施以避免任何问题。安全工程师的任务是实施一个自动化解决方案,以便在调查和补救问题之前阻止该可疑实例。 该课程提供丰富的题库,学生可以多次重做考试,若有疑问可获得导师支持,每道题目都有详细解释,并且兼容手机应用,提供30天退款保证以确保您的满意。 欢迎加入这一最佳实践考试课程,祝您学习愉快,并祝好运通过AWS认证安全专家SCS-C02考试!
Preparing for AWS Certified Security Specialty SCS-C02? This is THE practice exams course to give you the winning edge.These practice exams have been co-authored by Stephane Maarek and Abhishek Singh who bring their collective experience of passing 20 AWS Certifications to the table.The tone and tenor of the questions mimic the real exam. Along with the detailed description and "exam alert" provided within the explanations, we have also extensively referenced AWS documentation to get you up to speed on all domain areas being tested for the SCS-C02 exam.We want you to think of this course as the final pit-stop so that you can cross the winning line with absolute confidence and get AWS Certified! Trust our process, you are in good hands.All questions have been written from scratch! And more questions are being added over time! Quality speaks for itselfSAMPLE QUESTION:A mid-sized company recently deployed Amazon GuardDuty to monitor their AWS environment for potential security threats. The security team noticed a high number of RDP brute force attacks originating from an Amazon EC2 instance and decided to take action to prevent any issues. The company's security engineer was tasked with implementing an automated solution that could block the suspicious instance until the issue could be investigated and remediated.Which of the following solutions should the security engineer implement?Have Security Hub ingest GuardDuty findings and send events to Kinesis Data Streams via EventBridge. Configure Kinesis Data Analytics to process the data stream and block traffic to/from the suspicious instance by updating the security group so that it has no inbound and outbound rulesHave Security Hub ingest GuardDuty findings and send events to EventBridge that triggers a Lambda function to block traffic to/from the suspicious instance by updating the WAF web ACLHave Security Hub ingest GuardDuty findings and send events to EventBridge that triggers a Lambda function to block traffic to/from the suspicious instance by updating the network ACL rulesHave Security Hub ingest GuardDuty findings and send events to Kinesis Data Streams via EventBridge. Configure a Lambda function to process the data stream and block traffic to/from the suspicious instance by updating the security group so that it has no inbound and outbound rulesWhat's your guess? Scroll below for the answer.Correct: 4.Explanation:Have Security Hub ingest GuardDuty findings and send events to Kinesis Data Streams via EventBridge. Configure a Lambda function to process the data stream and block traffic to/from the suspicious instance by updating the security group so that it has no inbound and outbound rules filesAWS Security Hub provides you with a comprehensive view of your security state in AWS and helps you check your environment against security industry standards and best practices.Security Hub collects security data from across AWS accounts, services (such as GuardDuty), and supported third-party partner products and helps you analyze your security trends and identify the highest priority security issues.How Security Hub works:Reference Imagevia - Reference LinkLeveraging Amazon EventBridge's integration with Security Hub, you can automate your AWS services to respond automatically to system events such as application availability issues or resource changes. Events from AWS services are delivered to EventBridge in near-real time and on a guaranteed basis. You can write simple rules to indicate which events you are interested in and what automated actions to take when an event matches a rule. The actions that can be automatically triggered include the following:Invoking an AWS Lambda functionInvoking the Amazon EC2 run commandRelaying the event to Amazon Kinesis Data StreamsActivating an AWS Step Functions state machineNotifying an Amazon SNS topic or an Amazon SQS queueSending a finding to a third-party ticketing, chat, SIEM, or incident response and management toolFor the given use case, you can process the Security Hub events in Kinesis Data Streams by using a Lambda function that monitors any UnauthorizedAccess:EC2/RDPBruteForce finding from GuardDuty that is relayed via Security Hub. This finding informs you that an EC2 instance in your AWS environment was involved in a brute force attack aimed at obtaining passwords to RDP services on Windows-based systems. This can indicate unauthorized access to your AWS resources. When the Lambda function sees a matching finding, it can block traffic to/from the suspicious instance by updating the security group so that it has no inbound and outbound rules.Incorrect options:Have Security Hub ingest GuardDuty findings and send events to EventBridge that triggers a Lambda function to block traffic to/from the suspicious instance by updating the WAF web ACL - WAF web ACL can only be applied to the following resource types: CloudFront distribution, Amazon API Gateway REST API, Application Load Balancer, AWS AppSync GraphQL API and Amazon Cognito user pool. You can use AWS WAF to control how your protected resources respond to HTTP(S) web requests. The given use case is about RDP brute force attacks originating from an EC2 instance, so using WAF web ACL is not relevant, as it cannot monitor traffic originating from an EC2 instance.Have Security Hub ingest GuardDuty findings and send events to EventBridge that triggers a Lambda function to block traffic to/from the suspicious instance by updating the network ACL rules - Using Network ACL rules would impact all instances in a subnet. It will not isolate the traffic only for the suspicious instance. Hence this option is incorrect.Have Security Hub ingest GuardDuty findings and send events to Kinesis Data Streams via EventBridge. Configure Kinesis Data Analytics to process the data stream and block traffic to/from the suspicious instance by updating the security group so that it has no inbound and outbound rules - Amazon Kinesis Data Analytics can be used to transform and analyze streaming data in real-time with Apache Flink. Apache Flink is an open-source framework and engine for processing data streams. Kinesis Data Analytics reduces the complexity of building, managing, and integrating Apache Flink applications with other AWS services. This option has been added as a distractor as Kinesis Data Analytics cannot be used to update the security groups for an instance.with reference linksInstructorMy name is Stéphane Maarek, I am passionate about Cloud Computing, and I will be your instructor in this course. I teach about AWS certifications, focusing on helping my students improve their professional proficiencies in AWS.I have already taught 1,500,000+ students and gotten 500,000+ reviews throughout my career in designing and delivering these certifications and courses!I'm delighted to welcome Abhishek Singh as my co-instructor for these practice exams!Welcome to the best practice exams to help you prepare for your AWS Certified Security Specialty exam.You can retake the exams as many times as you wantThis is a huge original question bankYou get support from instructors if you have questionsEach question has a detailed explanationMobile-compatible with the Udemy app30-days money-back guarantee if you're not satisfiedWe hope that by now you're convinced!. And there are a lot more questions inside the course.Happy learning and best of luck for your AWS Certified Security Specialty SCS-C02 exam!