A company runs Kubernetes applications on Amazon Elastic Kubernetes Service (Amazon EKS) and uses Amazon GuardDuty with EKS Protection enabled. However, GuardDuty is not monitoring the Kubernetes-based applications. What action will enable GuardDuty to monitor these applications?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Amazon EKS control plane logging and ensure the logs are delivered to Amazon CloudWatch..
Why this is the answer
Enabling Amazon EKS control plane logging and ensuring logs are delivered to Amazon CloudWatch is crucial because GuardDuty EKS Protection analyzes these logs for potential threats. GuardDuty specifically monitors EKS audit logs, API server logs, and authenticator logs to detect suspicious activities within your Kubernetes environment. Without these logs being collected and accessible, GuardDuty cannot perform its EKS-specific threat detection. VPC flow logs (incorrect option) provide network traffic information but are not the primary data source GuardDuty uses for EKS threat detection. Attaching CloudWatchEventsFullAccess (incorrect option) is unrelated to GuardDuty's ability to ingest EKS logs. The AmazonGuardDutyFullAccess policy (incorrect option) is for GuardDuty's permissions to operate, not for enabling the EKS logging required for its analysis.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed