AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringEasy

A security engineer needs to establish real-time threat detection and continuous monitoring for an AWS environment, including identifying unusual API calls, potential unauthorized access, and known malicious IP addresses. The solution must be fully managed and integrate seamlessly with existing security workflows. Which AWS service is best suited for this requirement?

  1. AAWS Config
  2. BAmazon GuardDuty
  3. CAmazon Macie
  4. DAWS CloudTrail
Show answer & explanation

Correct answer: B. Amazon GuardDuty

Amazon GuardDuty is a fully managed threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads. It uses machine learning, anomaly detection, and integrated threat intelligence to identify potential threats.

Why the other options are wrong

  • A. AWS Config assesses, audits, and evaluates the configurations of your AWS resources, focusing on compliance, not real-time threat detection.
  • C. Amazon Macie is a data security and data privacy service that uses machine learning and pattern matching to discover and protect sensitive data in AWS, not general threat detection.
  • D. AWS CloudTrail records API calls and associated events in your AWS account, providing an audit trail, but does not perform real-time threat detection or analysis itself.

Amazon GuardDuty

A fully managed threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect AWS accounts and workloads.

  • Uses machine learning, anomaly detection, and threat intelligence.
  • Identifies unusual API calls, unauthorized access, and known malicious IP addresses.
  • Provides findings that can be integrated with other security services.

Memory trick: GuardDuty is your always-on security guard, watching for threats.

More Domain 2: Logging and Monitoring questions