AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium
A security team wants a fully managed threat detection service that continuously analyzes VPC Flow Logs, DNS logs, and CloudTrail event logs to identify malicious or unauthorized activity without deploying any agents. Which service should they use?
- AAWS Config
- BAWS WAF
- CAmazon GuardDuty
- DAmazon Inspector
Show answer & explanationAnswer & explanation
Correct answer: C. Amazon GuardDuty
Amazon GuardDuty is a managed threat detection service that continuously monitors VPC Flow Logs, DNS logs, and CloudTrail events using machine learning and threat intelligence to detect malicious activity, with no agents required.
Why the other options are wrong
- A. AWS Config tracks resource configuration changes and compliance, not threat detection.
- B. AWS WAF filters web traffic at the application layer; it does not analyze VPC or DNS logs.
- D. Amazon Inspector performs vulnerability assessments on EC2 and container images, not log-based threat detection.
Amazon GuardDuty
A managed threat detection service that uses machine learning and threat intelligence to analyze logs and identify malicious activity across AWS accounts.
- Analyzes VPC Flow Logs, DNS logs, and CloudTrail events
- No agents or additional infrastructure required
- Generates findings that can integrate with Security Hub
Memory trick: GuardDuty guards by watching the logs, not the servers.