Amazon GuardDuty
An intelligent threat-detection service that continuously monitors for malicious activity.
Amazon GuardDuty is a managed threat-detection service that continuously analyzes AWS CloudTrail event logs, VPC Flow Logs, and DNS query logs to identify suspicious behavior such as unusual API calls, crypto-mining activity, or communication with known malicious IP addresses. It uses machine learning and threat intelligence feeds to surface findings without requiring the customer to deploy or manage any additional software. The key exam distinction is scope: GuardDuty detects active threats and anomalous behavior, while Amazon Inspector assesses EC2 instances and container images for software vulnerabilities. GuardDuty does not fix anything—it generates findings that can trigger EventBridge rules for automated remediation.
PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →