Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

A company requires you to detect failed login attempts in the operating system of a criti - cal instance and to make that information available

A company requires you to detect failed login attempts in the operating system of a criti-
cal instance and to make that information available to security analysts to investigate and decide whether to ignore or isolate. Which of the following actions can be recommended?
(Choose two.)
A. Sending all the OS logs to a SIEM among the AWS Security Hub's partners and using
a SIEM rule to create a finding in AWS Security Hub, then using AWS Security Hub's custom actions to ease isolation
B. Sending all the OS logs to AWS Security Hub and AWS Security Hub's actions to auto-
mate resolution
C. Sending OS logs to Amazon CloudWatch logs through the agent, creating a metric filter
and an alarm, and triggering an AWS Lambda that creates the finding in AWS Security Hub, then using AWS Security Hub's custom actions to ease isolation
D. Sending all the OS logs to a SIEM among the AWS Security Hub's partners and using
a SIEM rule to create a finding in AWS Security Hub, then using Amazon CloudWatch Events to trigger an AWS Lambda function to isolate
image text in transcribed

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

Master The Art Of Data Storytelling With Visualizations

Authors: Alexander N Donovan

1st Edition

B0CNMD9QRD, 979-8867864248

More Books

Students also viewed these Databases questions

Question

5. If yes, then why?

Answered: 1 week ago

Question

6. How would you design your ideal position?

Answered: 1 week ago