AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringEasy

A security engineer needs to establish real-time monitoring for suspicious network activities within a Virtual Private Cloud (VPC) to detect potential Distributed Denial of Service (DDoS) attacks or port scans. The solution must be cost-effective and provide actionable insights without requiring extensive custom development. Which AWS service is best suited for this requirement?

  1. AAmazon GuardDuty
  2. BAWS Config
  3. CAmazon CloudWatch Logs
  4. DAWS WAF
Show answer & explanation

Correct answer: A. Amazon GuardDuty

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect AWS accounts and workloads. It provides intelligent threat detection specifically for network activities like port scans and potential DDoS attacks, making it the most suitable and cost-effective choice for real-time monitoring without extensive custom development.

Why the other options are wrong

  • B. AWS Config is used for configuration management and compliance auditing, not real-time threat detection of network anomalies.
  • C. Amazon CloudWatch Logs is a logging service and would require significant custom development and analysis to detect threat patterns, which is not cost-effective or actionable without further services.
  • D. AWS WAF is a web application firewall that protects web applications from common web exploits, not general VPC network activity monitoring for DDoS or port scans.

Amazon GuardDuty

A threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect AWS accounts and workloads.

  • Monitors AWS CloudTrail, VPC Flow Logs, and DNS logs.
  • Uses machine learning, anomaly detection, and threat intelligence.
  • Provides actionable security findings.

Memory trick: GuardDuty stands guard, detecting threats in the cloud's vast network.

More Domain 2: Logging and Monitoring questions