Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 312-39 Exam - Topic 8 Question 121 Discussion

SecureTech Inc. operates critical infrastructure and applications in AWS. The SOC detects suspicious activities such as unexpected API calls, unusual outbound traffic from instances, and DNS requests to potentially malicious domains. They need a fully managed AWS security service that continuously monitors for malicious activity, analyzes CloudTrail logs, VPC Flow Logs, and DNS query logs, leverages machine learning and threat intelligence, and provides actionable findings. Which AWS service best fits?
D) Amazon GuardDuty
A) Amazon Macie
B) AWS Config
C) AWS Security Hub

Eccouncil 312-39 Exam - Topic 8 Question 121 Discussion

Actual exam question for Eccouncil's 312-39 exam
Question #: 121
Topic #: 8
[All 312-39 Questions]

SecureTech Inc. operates critical infrastructure and applications in AWS. The SOC detects suspicious activities such as unexpected API calls, unusual outbound traffic from instances, and DNS requests to potentially malicious domains. They need a fully managed AWS security service that continuously monitors for malicious activity, analyzes CloudTrail logs, VPC Flow Logs, and DNS query logs, leverages machine learning and threat intelligence, and provides actionable findings. Which AWS service best fits?

Show Suggested Answer Hide Answer
Suggested Answer: D

Amazon GuardDuty is the fully managed AWS threat detection service designed to analyze CloudTrail events, VPC Flow Logs, and DNS logs to identify suspicious and malicious activity. It uses threat intelligence and behavioral models to detect patterns such as unusual API calls, anomalous network connections (including known malicious destinations), and suspicious DNS activity---directly matching the scenario requirements. Macie is focused on discovering and protecting sensitive data (especially in S3) through classification and data exposure detection, not broad threat detection across API/network/DNS. AWS Config is a configuration compliance and drift monitoring service; it tracks resource configurations and policy compliance but does not provide threat detection based on network and activity logs. Security Hub aggregates and normalizes findings from multiple AWS security services and partners; it is a central view and compliance/finding management layer, but it relies on services like GuardDuty to generate threat findings. From a SOC perspective, GuardDuty provides the near-real-time detection signals the team needs, and those findings can be forwarded to SIEM/SOAR workflows for triage and response.


Contribute your Thoughts:

0/2000 characters
Silva
5 hours ago
I’m a bit confused; I thought AWS Security Hub was the right choice, but it seems more like an aggregation tool rather than a direct monitoring service.
upvoted 0 times
...
Barrie
5 days ago
I feel like I've seen a similar question before, and GuardDuty was definitely the service that stood out for continuous monitoring.
upvoted 0 times
...
Kris
11 days ago
I'm not entirely sure, but I remember something about AWS Config being more about compliance rather than active monitoring.
upvoted 0 times
...
Audra
16 days ago
I think the answer might be D) Amazon GuardDuty since it focuses on threat detection and uses machine learning.
upvoted 0 times
...

Save Cancel