AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium
A security team enables a GuardDuty feature that automatically scans Amazon EBS volumes attached to EC2 instances flagged with suspicious activity, looking for known malware file signatures. Which GuardDuty capability does this describe?
- AGuardDuty EKS Protection
- BGuardDuty S3 Protection
- CGuardDuty Malware Protection
- DGuardDuty Threat Intelligence Feeds
Show answer & explanationAnswer & explanation
Correct answer: C. GuardDuty Malware Protection
GuardDuty Malware Protection scans EBS volumes attached to EC2 instances or container workloads when suspicious behavior is detected, checking for malware signatures. S3 Protection monitors S3 data events, EKS Protection analyzes Kubernetes audit logs, and Threat Intelligence Feeds are data sources GuardDuty uses broadly, not a volume-scanning feature.
Why the other options are wrong
- A. EKS Protection analyzes Kubernetes audit logs, unrelated to EBS scanning.
- B. S3 Protection monitors S3 API activity for threats, not EBS volumes.
- D. Threat intelligence feeds provide known-bad indicators but don't scan volumes directly.
GuardDuty Malware Protection
A GuardDuty feature that automatically scans EBS volumes attached to EC2 instances or containers flagged with suspicious findings, checking for malware.
- Triggered by suspicious GuardDuty findings tied to an EC2 instance
- Performs agentless scanning of EBS snapshots
- Generates malware findings that feed into the GuardDuty console and Security Hub
Memory trick: Malware Protection is GuardDuty's doctor checking the volume for infection.