A security engineer is configuring a mechanism to send an alert when three or more failed sign-in attempts to the AWS Management Console occur during a 5-minute period. The security engineer creates a trail in AWS CloudTrail to assist in this work.
Which solution will meet these requirements?
The correct answer is B. Configure CloudTrail to send events to Amazon CloudWatch Logs. Create a metric filter for the relevant log group. Create a filter pattern with eventName matching ConsoleLogin and errorMessage matching ''Failed authentication''. Create a CloudWatch alarm with a threshold of 3 and a period of 5 minutes.
The other options are incorrect because:
Justa
11 months agoAleta
11 months agoMable
11 months agoGeorgene
10 months agoViva
10 months agoElfrieda
10 months agoHeike
10 months agoOcie
10 months agoFabiola
10 months agoLon
11 months ago