AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceEasy

A security team wants a service that automatically analyzes findings from GuardDuty and other data sources, visually mapping relationships between resources, IP addresses, and users to help investigate the root cause of a potential security incident. Which AWS service should they use?

  1. AAWS Artifact
  2. BAWS Trusted Advisor
  3. CAWS Config
  4. DAmazon Detective
Show answer & explanation

Correct answer: D. Amazon Detective

Amazon Detective automatically collects log data from sources like GuardDuty, VPC Flow Logs, and CloudTrail, and builds a graph-based model to help security teams visualize relationships and investigate the root cause of findings. AWS Config tracks resource configuration compliance, AWS Artifact provides compliance documentation, and Trusted Advisor gives account optimization recommendations, none of which perform security investigation visualization.

Why the other options are wrong

  • A. AWS Artifact is a repository for compliance reports, unrelated to investigations.
  • B. Trusted Advisor offers general account recommendations, not incident investigation.
  • C. AWS Config tracks configuration changes and compliance, not incident investigation graphs.

Amazon Detective

A service that automatically collects and analyzes log data to build visual graphs helping security teams investigate the root cause of security findings.

  • Ingests data from GuardDuty, VPC Flow Logs, CloudTrail
  • Provides interactive visualizations of resource relationships
  • Used for root-cause investigation, not initial detection

Memory trick: Detective 'connects the dots' visually after GuardDuty flags something

More Security and Compliance questions