Question 1 · choose 1
A security team wants to be alerted when the rate of write API calls in a production account suddenly departs from its usual pattern, for example a burst of DeleteSnapshot or TerminateInstances calls from a compromised role. Normal call volumes vary a lot by hour and by day, so the team does not want to define or maintain thresholds per API. The account already has a trail that logs management events. What should the DevOps engineer do?
- ACreate CloudWatch Logs metric filters for each destructive API name and static alarms on the resulting metrics
- BCreate an EventBridge rule that sends every DeleteSnapshot and TerminateInstances call to the security team's SNS topic
- CTurn on GuardDuty Malware Protection for EC2 so that it scans instances when unusual API activity happens
- DTurn on CloudTrail Insights for API call rate and route its Insights events through EventBridge
Show the answer and why
ACreate CloudWatch Logs metric filters for each destructive API name and static alarms on the resulting metrics
Incorrect
This needs a filter and a hand-set threshold for every API, which the team wants to avoid, and fixed thresholds ignore the varying volume.
BCreate an EventBridge rule that sends every DeleteSnapshot and TerminateInstances call to the security team's SNS topic
Incorrect
This alerts on every normal call as well, not on unusual rates, so the team would be flooded.
CTurn on GuardDuty Malware Protection for EC2 so that it scans instances when unusual API activity happens
Incorrect
Malware Protection scans EBS volumes for malware. It does not baseline API call rates.
DTurn on CloudTrail Insights for API call rate and route its Insights events through EventBridge
Correct
Insights builds a baseline of write management API call rates and logs an Insights event when the current rate deviates from it, and Insights events reach EventBridge.
CloudTrail Insights learns the normal API call rate and error rate of an account and flags deviations, so no per-API thresholds are needed. The API call rate measure needs the trail to log write management events.
AWS documentation