AWS Certified SysOps Administrator – AssociateSecurity and ComplianceEasy
A security engineer needs to implement a solution to automatically detect and alert on unusual and potentially unauthorized activities within an AWS account, such as API calls from unusual geographic locations, attempts to disable logging, or port scanning activities. The solution must be fully managed and provide intelligent threat detection. Which AWS service is best suited for this requirement?
- AAWS Security Hub
- BAWS CloudTrail
- CAmazon GuardDuty
- DAmazon Inspector
Show answer & explanationAnswer & explanation
Correct answer: C. Amazon GuardDuty
Amazon GuardDuty is a fully managed threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads. It uses machine learning, anomaly detection, and integrated threat intelligence to identify threats like unusual API calls, attempts to disable logging, and port scanning.
Why the other options are wrong
- A. Security Hub aggregates and prioritizes security findings from various AWS services, but GuardDuty is the underlying detection service for these types of threats.
- B. CloudTrail logs API activity but does not intrinsically provide intelligent threat detection or anomaly analysis.
- D. Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS, primarily focusing on vulnerabilities in EC2 instances and container images, not real-time threat detection of account activity.
Amazon GuardDuty
Amazon GuardDuty is a fully managed threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads.
- Uses machine learning, anomaly detection, and threat intelligence.
- Monitors AWS CloudTrail, VPC Flow Logs, and DNS logs.
- Detects unusual API calls, compromised instances, and crypto mining.
- Provides actionable security findings.
Memory trick: GuardDuty Guards Your AWS Accounts with Smart Threat Detection.