passdrill
AWS SAA-C03 · IAM & Security · Card 013/014 medium

A security team wants continuous, automated detection of suspicious activity, such as unusual API calls or communication with known-malicious IP addresses, using existing VPC Flow Logs, DNS query logs, and CloudTrail events, without deploying any agent on their instances. Which service fits this need?

  1. AWS Config, configured with custom rules that scan flow logs hourly
  2. Amazon GuardDuty, which continuously analyzes VPC Flow Logs, DNS query logs, and CloudTrail events using threat intelligence to generate findings without requiring any agent installation
  3. AWS Systems Manager Inventory, which lists installed software on managed instances
  4. Amazon Inspector, whose vulnerability scans are focused on detecting network intrusions rather than software vulnerabilities
Next card → Shuffle