Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 312-39 Exam - Topic 8 Question 121 Discussion

SecureTech Inc. operates critical infrastructure and applications in AWS. The SOC detects suspicious activities such as unexpected API calls, unusual outbound traffic from instances, and DNS requests to potentially malicious domains. They need a fully managed AWS security service that continuously monitors for malicious activity, analyzes CloudTrail logs, VPC Flow Logs, and DNS query logs, leverages machine learning and threat intelligence, and provides actionable findings. Which AWS service best fits?
D) Amazon GuardDuty
A) Amazon Macie
B) AWS Config
C) AWS Security Hub

Eccouncil 312-39 Exam - Topic 8 Question 121 Discussion

Actual exam question for Eccouncil's 312-39 exam
Question #: 121
Topic #: 8
[All 312-39 Questions]

SecureTech Inc. operates critical infrastructure and applications in AWS. The SOC detects suspicious activities such as unexpected API calls, unusual outbound traffic from instances, and DNS requests to potentially malicious domains. They need a fully managed AWS security service that continuously monitors for malicious activity, analyzes CloudTrail logs, VPC Flow Logs, and DNS query logs, leverages machine learning and threat intelligence, and provides actionable findings. Which AWS service best fits?

Show Suggested Answer Hide Answer
Suggested Answer: D

Amazon GuardDuty is the fully managed AWS threat detection service designed to analyze CloudTrail events, VPC Flow Logs, and DNS logs to identify suspicious and malicious activity. It uses threat intelligence and behavioral models to detect patterns such as unusual API calls, anomalous network connections (including known malicious destinations), and suspicious DNS activity---directly matching the scenario requirements. Macie is focused on discovering and protecting sensitive data (especially in S3) through classification and data exposure detection, not broad threat detection across API/network/DNS. AWS Config is a configuration compliance and drift monitoring service; it tracks resource configurations and policy compliance but does not provide threat detection based on network and activity logs. Security Hub aggregates and normalizes findings from multiple AWS security services and partners; it is a central view and compliance/finding management layer, but it relies on services like GuardDuty to generate threat findings. From a SOC perspective, GuardDuty provides the near-real-time detection signals the team needs, and those findings can be forwarded to SIEM/SOAR workflows for triage and response.


Contribute your Thoughts:

0/2000 characters
Cecily
2 days ago
But Security Hub relies on other services. GuardDuty is more focused on real-time threats.
upvoted 0 times
...
Burma
7 days ago
I'm leaning towards C) AWS Security Hub. It aggregates findings but may not monitor continuously.
upvoted 0 times
...
Nettie
12 days ago
Agreed! GuardDuty uses machine learning for threat detection.
upvoted 0 times
...
Alonso
18 days ago
I think it's D) Amazon GuardDuty. It fits the need for continuous monitoring.
upvoted 0 times
...
Haley
23 days ago
Isn’t AWS Config more about compliance than security monitoring?
upvoted 0 times
...
Tyisha
28 days ago
I agree with GuardDuty, it uses machine learning for threat detection.
upvoted 0 times
...
Charlene
1 month ago
Wait, can GuardDuty really analyze all those logs? Sounds too good to be true.
upvoted 0 times
...
Jamey
1 month ago
I thought it was C) AWS Security Hub, but I guess GuardDuty is more focused.
upvoted 0 times
...
Alfred
1 month ago
Definitely D) Amazon GuardDuty, it’s designed for that!
upvoted 0 times
...
Silva
2 months ago
I’m a bit confused; I thought AWS Security Hub was the right choice, but it seems more like an aggregation tool rather than a direct monitoring service.
upvoted 0 times
...
Barrie
2 months ago
I feel like I've seen a similar question before, and GuardDuty was definitely the service that stood out for continuous monitoring.
upvoted 0 times
...
Kris
2 months ago
I'm not entirely sure, but I remember something about AWS Config being more about compliance rather than active monitoring.
upvoted 0 times
...
Audra
2 months ago
I think the answer might be D) Amazon GuardDuty since it focuses on threat detection and uses machine learning.
upvoted 0 times
...

Save Cancel