AWS Certified SysOps Administrator – AssociateMonitoring, Logging, and RemediationEasy

A SysOps administrator needs to proactively identify and respond to security threats within their AWS environment, such as unauthorized access, unusual API calls, or compromised instances. Which AWS service is specifically designed for continuous security monitoring and threat detection?

  1. AAWS CloudTrail
  2. BAWS Config
  3. CAmazon CloudWatch
  4. DAWS GuardDuty
Show answer & explanation

Correct answer: D. AWS GuardDuty

AWS GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect AWS accounts and workloads. It analyzes various data sources like VPC Flow Logs, DNS logs, and CloudTrail management events.

Why the other options are wrong

  • A. AWS CloudTrail records API calls and related events, providing an audit trail, but does not proactively detect threats on its own.
  • B. AWS Config assesses, audits, and evaluates the configurations of your AWS resources, focusing on compliance, not active threat detection.
  • C. Amazon CloudWatch is a monitoring and observability service but does not specialize in threat detection.

AWS GuardDuty

A threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect AWS accounts and workloads.

  • Uses machine learning, anomaly detection, and threat intelligence.
  • Analyzes VPC Flow Logs, DNS logs, and CloudTrail events.
  • Generates security findings for identified threats.

Memory trick: GuardDuty stands guard, detecting threats like a vigilant sentinel.

More Monitoring, Logging, and Remediation questions