AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceMedium

A global software-as-a-service (SaaS) provider uses AWS for its multi-tenant application. The security team needs to monitor for unusual and potentially unauthorized behavior, such as compromised EC2 instances, unusual API calls, or port scans, across all AWS accounts in their organization. They require a managed threat detection service that continuously monitors their AWS environment for these threats. Which AWS service is best suited for this requirement?

  1. AAmazon CloudWatch
  2. BAmazon GuardDuty
  3. CAWS Trusted Advisor
  4. DAWS Config
Show answer & explanation

Correct answer: B. Amazon GuardDuty

Amazon GuardDuty is a managed threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect AWS accounts and workloads. It analyzes VPC Flow Logs, DNS logs, and CloudTrail management event logs to identify threats like compromised instances, unusual API calls, and port scans.

Why the other options are wrong

  • A. Amazon CloudWatch collects monitoring and operational data (logs, metrics, events) but does not inherently perform threat detection analysis on this data.
  • C. AWS Trusted Advisor provides recommendations to follow AWS best practices in areas like cost optimization, performance, security, etc., but it's not a real-time threat detection service.
  • D. AWS Config monitors and records AWS resource configurations and changes for compliance, but it's not a threat detection service.

Amazon GuardDuty

A managed threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads.

  • Analyzes VPC Flow Logs, DNS logs, CloudTrail logs.
  • Identifies compromised instances, unusual API calls, port scans.
  • Managed, no software to deploy.
  • Can be enabled across multiple accounts via AWS Organizations.

Memory trick: GuardDuty is the vigilant 'security guard' always watching your AWS accounts for danger.

More Network Security, Compliance, and Governance questions