AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceMedium

A global software-as-a-service (SaaS) provider uses AWS for its multi-tenant application. They are concerned about data exfiltration and unauthorized access attempts to their AWS resources. The security team wants to implement a service that continuously monitors AWS accounts for malicious activity and unauthorized behavior, such as unusual API calls, compromised EC2 instances, or cryptocurrency mining. This service should also integrate with their existing security operations center (SOC) for alerting. Which AWS service is best suited for this task?

  1. AAWS CloudTrail
  2. BAmazon GuardDuty
  3. CAWS Security Hub
  4. DAWS Config
Show answer & explanation

Correct answer: B. Amazon GuardDuty

Amazon GuardDuty is a continuous security monitoring service that uses machine learning, anomaly detection, and threat intelligence to identify and alert on potential threats. It specifically looks for malicious activity and unauthorized behavior across AWS accounts, including compromised instances, unusual API calls, and cryptocurrency mining, and integrates with SOC tools for alerting, directly meeting the requirements.

Why the other options are wrong

  • A. AWS CloudTrail logs API calls and account activity, which GuardDuty uses as a data source, but CloudTrail itself does not perform threat detection or anomaly analysis.
  • C. AWS Security Hub aggregates, organizes, and prioritizes security findings from various AWS services and partner products, but it does not perform the actual threat detection itself.
  • D. AWS Config continuously monitors and records your AWS resource configurations and evaluates them against desired configurations, but it is not a threat detection service.

Amazon GuardDuty

A threat detection service that continuously monitors your AWS accounts and workloads for malicious activity and unauthorized behavior to protect your AWS accounts, data, and workloads.

  • Uses machine learning, anomaly detection, and threat intelligence.
  • Monitors VPC Flow Logs, DNS logs, and CloudTrail management events.
  • Provides actionable findings for security incidents.

Memory trick: GUARDDUTY 'DETECTS' the 'THREATS' on your AWS 'ACCOUNT'.

More Network Security, Compliance, and Governance questions