Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 616 discussion

A company has deployed its newest product on AWS. The product runs in an Auto Scaling group behind a Network Load Balancer. The company stores the product’s objects in an Amazon S3 bucket.

The company recently experienced malicious attacks against its systems. The company needs a solution that continuously monitors for malicious activity in the AWS account, workloads, and access patterns to the S3 bucket. The solution must also report suspicious activity and display the information on a dashboard.

Which solution will meet these requirements?

  • A. Configure Amazon Macie to monitor and report findings to AWS Config.
  • B. Configure Amazon Inspector to monitor and report findings to AWS CloudTrail.
  • C. Configure Amazon GuardDuty to monitor and report findings to AWS Security Hub.
  • D. Configure AWS Config to monitor and report findings to Amazon EventBridge.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Guru4Cloud
Highly Voted 1 year, 1 month ago
Selected Answer: C
The key reasons are: Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior. It analyzes AWS CloudTrail, VPC Flow Logs, and DNS logs. GuardDuty can detect threats like instance or S3 bucket compromise, malicious IP addresses, or unusual API calls. Findings can be sent to AWS Security Hub which provides a centralized security dashboard and alerts. Amazon Macie and Amazon Inspector do not monitor the breadth of activity that GuardDuty does. They focus more on data security and application vulnerabilities respectively. AWS Config monitors for resource configuration changes, not malicious activity.
upvoted 12 times
...
MatAlves
Most Recent 2 months ago
Selected Answer: C
- Amazon Inspector = automated vulnerability management service - Amazon GuardDuty = threat detection service that monitors for malicious activity and anomalous behavior to protect AWS accounts, workloads, and data.
upvoted 1 times
...
KennethNg923
5 months, 1 week ago
Selected Answer: C
“ continuously monitors for malicious activity in the AWS account, workloads, and access patterns to the S3 bucket” only guard duty for this purpose in the options
upvoted 1 times
...
TariqKipkemei
11 months, 3 weeks ago
Selected Answer: C
Amazon Inspector provides you with security assessments of your applications settings and configurations on your EC2 instances while Amazon GuardDuty helps with analyzing your entire AWS environment for potential threats. AWS Security Hub is a cloud security posture management service that aggregates alerts, and enables automated remediation.
upvoted 3 times
...
dilaaziz
1 year ago
Selected Answer: C
Guardduty
upvoted 2 times
...
taustin2
1 year, 2 months ago
Selected Answer: C
What Guard Duty is for.
upvoted 2 times
Guru4Cloud
1 year, 1 month ago
The key reasons are: Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior. It analyzes AWS CloudTrail, VPC Flow Logs, and DNS logs. GuardDuty can detect threats like instance or S3 bucket compromise, malicious IP addresses, or unusual API calls. Findings can be sent to AWS Security Hub which provides a centralized security dashboard and alerts. Amazon Macie and Amazon Inspector do not monitor the breadth of activity that GuardDuty does. They focus more on data security and application vulnerabilities respectively. AWS Config monitors for resource configuration changes, not malicious activity.
upvoted 2 times
...
...
kambarami
1 year, 2 months ago
Answer is C.
upvoted 1 times
...
aleariva
1 year, 2 months ago
C is the correct. https://aws.amazon.com/guardduty/
upvoted 1 times
...
brownie23
1 year, 2 months ago
Answer is C Since Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts, Amazon Elastic Compute Cloud (EC2) workloads, container applications, Amazon Aurora databases, and data stored in Amazon Simple Storage Service (S3).
upvoted 2 times
...
awslearnerin2022
1 year, 2 months ago
Selected Answer: C
Gaurd duty is a threat detection service for accounts and workloads.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...