nerdexam
Amazon

SOA-C02 · Question #647

A company is using a single AWS account to support a workload. A SysOps administrator is responsible for the security of the AWS account. The SysOps administrator must implement a solution to…

The correct answer is A. Enable Amazon GuardDuty on the account. Review GuardDuty findings to identify anomalous. Enabling Amazon GuardDuty provides automated detection of anomalous activity, including unusual API usage, by continuously analyzing AWS CloudTrail logs (and other data sources) without requiring manual log analysis or additional infrastructure. This managed service minimizes…

Submitted by fatema_kw· Mar 30, 2026Security and Compliance

Question

A company is using a single AWS account to support a workload. A SysOps administrator is responsible for the security of the AWS account. The SysOps administrator must implement a solution to identify unusual API usage behavior by AWS users. Which solution will meet this requirement with the LEAST operational overhead?

Options

  • AEnable Amazon GuardDuty on the account. Review GuardDuty findings to identify anomalous
  • BCreate an AWS CloudTrail trail. Export CloudTrail logs to Amazon S3. Query the logs for
  • CCreate VPC flow logs for all VPCs in the account. Use Amazon CloudWatch Logs Insights to
  • DGenerate an IAM credential report for the account. Review the results to identify anomalous user

How the community answered

(30 responses)
  • A
    73% (22)
  • B
    17% (5)
  • C
    7% (2)
  • D
    3% (1)

Explanation

Enabling Amazon GuardDuty provides automated detection of anomalous activity, including unusual API usage, by continuously analyzing AWS CloudTrail logs (and other data sources) without requiring manual log analysis or additional infrastructure. This managed service minimizes operational overhead while meeting the requirement to identify unusual API behavior.

Topics

#GuardDuty#anomaly detection#API behavior#threat detection

Community Discussion

No community discussion yet for this question.

Full SOA-C02 Practice