An audit identified potential threats that could appear as spikes in DNS access, abnormal EC2 instance traffic, abnormal network interface traffic, and unusual Amazon S3 API calls, originating from various sources at any time. The company needs continuous, near-real-time monitoring to detect these threats. Which solution will meet these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Amazon GuardDuty from a centralized account. GuardDuty analyzes AWS CloudTrail logs, VPC Flow Logs, and DNS logs to detect these threats..
Why this is the answer
Amazon GuardDuty is the correct solution because it is a continuous threat detection service that monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads. It automatically analyzes AWS CloudTrail logs, VPC Flow Logs, and DNS logs, which directly address the types of threats described (abnormal EC2/network traffic, DNS spikes, S3 API calls). GuardDuty provides near-real-time detection and can be enabled centrally. Enabling CloudTrail, VPC Flow Logs, and DNS logs and sending them to CloudWatch Logs would collect the data, but it wouldn't automatically perform the continuous threat analysis needed; you'd have to build custom monitoring and alerting. Amazon Macie is a data security and privacy service that focuses on discovering and protecting sensitive data in S3, not general threat detection across various log types. Amazon Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS, primarily focusing on EC2 instances and container images, not continuous threat detection from logs like GuardDuty.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed