A highly regulated company has a policy that DevOps Engineers must not sign in to their Amazon EC2 instances except during emergencies. If a DevOps Engineer does sign in, the Security team must be notified within 15 minutes of the event.
Which solution satisfies these requirements?
A Install the Amazon Inspector agent on each EC2 instance. Subscribe to Amazon CloudWatch Events notifications. Trigger an AWS Lambda function to check if a message is about user logins. If it is, send a notification to the Security team using Amazon SNS. B Install the Amazon CloudWatch agent on each EC2 instance. Configure the agent to push all logs to Amazon CloudWatch Logs and set up a CloudWatch metric filter that searches for user logins. If a login is found, send a notification to the Security team using Amazon SNS. C Set up AWS CloudTrail with Amazon CloudWatch Logs. Subscribe CloudWatch Logs to Amazon Kinesis. Attach AWS Lambda to Kinesis to parse and determine if a log contains a user login. If it does, send a notification to the Security team using Amazon SNS. D Set up a script on each Amazon EC2 instance to push all logs to Amazon S3. Set up an S3 event to trigger an AWS Lambda function, which triggers an Amazon Athena query to run. The Athena query checks for logins and sends the output to the Security team using Amazon SNS. Show Answer Answer Explanation The CloudWatch agent can send EC2 operating-system authentication logs to CloudWatch Logs. A CloudWatch Logs metric filter detects login entries as they arrive; a CloudWatch alarm on that metric can invoke Amazon SNS to notify the Security team within the required interval. CloudTrail tracks AWS API activity rather than general operating-system logins to an instance.
Learn more
Community Discussion