Security, Identity, and Compliance
CoreAmazon GuardDuty
Managed threat detection that analyzes AWS telemetry for suspicious activity and produces security findings.
Key points
- GuardDuty detects threats; it does not patch vulnerabilities or block every finding automatically.
- Multi-account administration can centralize findings while accounts retain workload context.
- Findings need prioritization, investigation, and response through Security Hub or operational workflows.
Best-known use cases
- Detect suspicious account, workload, network, or data-access activity from supported sources.
- Centralize threat findings across an organization.
What candidates often confuse it with
- GuardDuty detects suspicious activity; Inspector assesses vulnerabilities and exposure.
- Security Hub aggregates findings; GuardDuty is one producing detection service.
Key takeaway
Choose GuardDuty when the requirement is managed threat detection from AWS telemetry.
Related services
- AWS Security Hub
- Amazon Inspector
- Amazon Detective
Relevant exam tasks
- D1.2