7 min read · about 50 min with practice3 quick checks≈2% of the testFoundational: Foundational: the groundwork the rest of the unit builds on
Reading is free. Sign in to tick off lessons, keep your place and track your mastery.
Security-service questions are some of the fastest points on SAA-C03. Each managed service does one job, and the stem nearly always contains the verb that names it: detect threats, scan for vulnerabilities, discover sensitive data, investigate a finding, or aggregate findings. The harder items pair two services that touch the same resource (GuardDuty and Macie both look at S3; Inspector and GuardDuty both look at containers) or ask you to automate the response.
By the end you’ll be able to
Match a requirement to GuardDuty, Inspector, Macie, Detective, Security Hub or Config
Identify the data sources GuardDuty analyses (CloudTrail, VPC Flow Logs, DNS logs, S3 and EKS protection) without agents
Build automated remediation: finding to EventBridge rule to Lambda or Systems Manager Automation
Enable services organisation-wide with a delegated administrator account
What the exam asks
Pick the right service for a requirement written in business language.
Know what GuardDuty analyzes, and that its foundational sources need no agents and no log setup.
Build automatic remediation: finding ⇒ EventBridge rule ⇒ Lambda or Systems Manager Automation.
Turn a service on for every account in an organization, including new accounts, and view the results centrally.
Core ideas
One verb per service
Service
Job
Looks at
Typical stem phrase
Amazon GuardDuty
Detects active threats with threat intelligence and machine learning
CloudTrail management events, VPC Flow Logs and DNS logs, plus optional protection plans
“compromised instance”, “crypto mining”, “unusual API calls”, “no agents”
Amazon Inspector
Scans for software vulnerabilities (CVEs) and unintended network exposure
The first 3 of 9 cards for this topic. Sign in and finish the lesson to review them with spaced repetition.
PromptCard 1 of 3
Amazon GuardDuty: what does it do, and what are its foundational data sources?
Records
Resource configurations and their change history
“configuration compliance”, “history of changes”, “auto-remediate misconfiguration”
AWS CloudTrail
Logs API calls
Management and data events
“who did what, and when”
Amazon GuardDuty
You turn GuardDuty on per account and Region. It then reads CloudTrail management events, VPC Flow Logs and Route 53 Resolver DNS query logs through its own independent streams. You do not need to create trails, flow logs or query logging first.
Protection plans add coverage:
S3 Protection watches S3 data events such as unusual GetObject patterns.
EKS Protection reads Kubernetes audit logs.
Runtime Monitoring uses a managed security agent on EKS, ECS on Fargate and EC2.
Malware Protection scans the EBS volumes of flagged instances and new S3 uploads.
RDS Protection flags anomalous database logins.
Lambda Protection monitors function network activity.
GuardDuty detects and reports. It does not block traffic or change resources, so the response is up to you.
Trusted IP lists and suppression rules reduce noise.
Amazon Inspector
Inspector automatically discovers and continuously scans three kinds of resource:
EC2 instances, through the SSM Agent or agentless scanning of EBS snapshots
ECR images, which enhanced scanning checks on push and then continuously
Lambda functions and their code
It rescans when a new CVE is published. It also adjusts each finding’s score for your environment, for example lowering it when the instance has no network path. It is not a threat-detection service: an unpatched instance is a vulnerability (Inspector), while an instance that is already compromised is a GuardDuty finding.
Amazon Macie
Macie uses managed data identifiers (PII, financial data, credentials) and custom identifiers you define. Automated sensitive data discovery samples your buckets continuously. Macie also inventories buckets and flags any that are public, unencrypted or shared outside the account. It covers S3 only. It does not look at EBS, RDS or DynamoDB.
Amazon Detective and Security Hub
Detective is where you go after a finding. It links principals, IP addresses, instances and API calls over time, so an analyst can see the scope without writing queries.
Security Hub does three things:
It normalizes findings into the AWS Security Finding Format (ASFF).
It runs controls from standards such as AWS Foundational Security Best Practices, CIS AWS Foundations, PCI DSS and NIST 800-53. These controls need AWS Config recording.
It supports cross-Region aggregation into one home Region.
Automated response
Every service here sends its findings to Amazon EventBridge. The standard pattern has three steps:
An EventBridge rule matches the finding type or severity.
The rule’s target is a Lambda function, a Systems Manager Automation runbook, a Step Functions workflow or an SNS topic.
The target takes action. For example, it swaps the instance’s security groups for an isolation group, snapshots the volumes, disables an access key or opens a ticket.
For misconfigurations rather than threats, use AWS Config rules with automatic remediation through Systems Manager Automation.
Organization-wide operation
From the Organizations management account, designate a delegated administrator for GuardDuty, Inspector, Macie, Detective and Security Hub, usually a security tooling account. Then turn on auto-enable so that new accounts join automatically. SCPs cannot switch services on. They can only stop member accounts from turning them off.
Worked examples
Exam technique
Underline the verb. Detect ⇒ GuardDuty. Scan or CVE ⇒ Inspector. Discover PII ⇒ Macie. Investigate ⇒ Detective. Aggregate or score ⇒ Security Hub. Configuration history ⇒ Config. Who called the API ⇒ CloudTrail.
“Without agents” together with threats points to GuardDuty. “Automatically ... when a finding” points to EventBridge.
“All accounts, including new ones” points to a delegated administrator with auto-enable.
Common mistakes
Quick recap
GuardDuty detects threats from CloudTrail, flow logs and DNS logs without agents. Protection plans extend it to S3, EKS, runtime monitoring, malware scanning, RDS and Lambda.
Inspector continuously scans EC2 instances, ECR images and Lambda functions for CVEs and network exposure.
Macie discovers PII and other sensitive data in S3.
Detective investigates findings with a behavior graph. Security Hub aggregates findings and scores you against standards using AWS Config.
Automate responses with EventBridge rules that target Lambda or Systems Manager Automation.
Run every service across the organization with a delegated administrator and auto-enable.