Which AWS service supports the analysis, investigation, and identification of the root cause of security events and suspicious activities in an AWS account?
Amazon Inspector
Amazon Macie
Amazon Detective
Amazon CloudWatch
Explanations:
Amazon Inspector is primarily used for automated security assessments of applications deployed on AWS. It helps identify vulnerabilities and provides recommendations for improvement but does not focus on analyzing or investigating security events.
Amazon Macie is a data security and privacy service that uses machine learning to discover, classify, and protect sensitive data stored in AWS. While it helps with data protection, it does not specifically analyze or investigate security events in an AWS account.
Amazon Detective is designed for security investigation and analysis. It helps in visualizing and understanding the behavior of users and resources in an AWS account, enabling the identification of the root causes of security issues and suspicious activities.
Amazon CloudWatch is a monitoring and observability service that provides data and insights about AWS resources and applications. While it can help in monitoring metrics and logs, it does not specialize in analyzing or investigating security events.