The security team wants continuous detection of potentially unauthorized AWS Management Console sign-ins that originate from multiple geographic locations within an AWS account. Which AWS service and finding should be used to automatically detect these suspicious console logins?
Choose an answer
Tap an option to check your answer.
Correct answer: Turn on Amazon GuardDuty and monitor the UnauthorizedAccess:IAMUser/ConsoleLoginSuccess.B finding..
Why this is the answer
Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads. The UnauthorizedAccess:IAMUser/ConsoleLoginSuccess.B finding specifically identifies successful AWS Management Console logins from an unusual geographic location, which is precisely what the security team is looking for. Incorrect options: Amazon Cognito is an identity service primarily used for user authentication and authorization in web and mobile applications, not for detecting unauthorized console logins to AWS itself. Amazon Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS. It focuses on scanning EC2 instances and container images for vulnerabilities, not detecting console login anomalies. AWS Config helps you assess, audit, and evaluate the configurations of your AWS resources. While iam-policy-blacklisted-check can identify non-compliant IAM policies, it doesn't detect unauthorized console logins from multiple geographic locations.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed