AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringMedium

A security operations center (SOC) team needs to monitor an AWS environment for potential indicators of compromise (IOCs) such as unusual API call patterns, unauthorized access attempts, and known malicious IP addresses. They require a service that can automatically analyze various AWS data sources, generate findings with severity levels, and integrate with existing incident response workflows. Which AWS service is best suited for this requirement?

  1. AAWS Config
  2. BAWS CloudWatch Logs
  3. CAmazon GuardDuty
  4. DAWS Security Hub
Show answer & explanation

Correct answer: C. Amazon GuardDuty

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect AWS accounts and workloads. It analyzes various data sources like VPC Flow Logs, CloudTrail event logs, and DNS logs, providing findings for potential IOCs.

Why the other options are wrong

  • A. AWS Config assesses, audits, and evaluates the configurations of AWS resources, focusing on compliance, not real-time threat detection.
  • B. AWS CloudWatch Logs is a monitoring and logging service, but it doesn't automatically analyze logs for threat detection or generate security findings like GuardDuty.
  • D. AWS Security Hub aggregates security findings from various AWS services and partner products, but GuardDuty is the service that *generates* the specific threat detection findings described.

Amazon GuardDuty

A threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect AWS accounts and workloads.

  • Monitors CloudTrail, VPC Flow Logs, DNS logs
  • Identifies unusual API calls, unauthorized access, known malicious IPs
  • Generates prioritized security findings

Memory trick: GuardDuty stands guard, spotting threats before they start.

More Domain 2: Logging and Monitoring questions