Security, Identity, and Compliance
Amazon GuardDuty
A threat-detection service that analyzes supported AWS data sources to identify suspicious or malicious activity.
Key points
- GuardDuty produces security findings from threat intelligence and behavioral analysis.
- It is managed detection; customers decide how to investigate and respond to findings.
- It does not scan software packages for known vulnerabilities.
Best-known use cases
- Detect suspicious account or workload activity.
- Surface signs such as anomalous access patterns or credential misuse.
What candidates often confuse it with
- GuardDuty detects threats from activity and signals; Inspector assesses workload vulnerabilities and exposure.
- Security Hub aggregates and prioritizes findings from several security services.
Key Cloud Practitioner takeaway
Threat activity points to GuardDuty; vulnerability assessment points to Inspector.
Related services
- Amazon Inspector
- AWS Security Hub
Relevant exam tasks
- D2.2
- D2.4