Which set of additional steps should the DevOps engineer take to meet these requirements MOST cost-effectively?

1 Comment

  1. Brandon
    Author

    From my perspective, the answer is:
    Create a log group in Amazon CloudWatch Logs. Configure the VPC flow log to capture accepted traffic and to send the data to the log group. Create an Amazon CloudWatch metric filter for IP addresses on the deny list. Create a CloudWatch alarm with the metric filter as input. Set the period to 5 minutes and the datapoints to alarm to 1. Use an Amazon Simple Notification Service (Amazon SNS) topic to send alarm notices to the security team.

Leave a Reply

Your email address will not be published. Required fields are marked *

two × five =