GuardDuty is a threat-detection service. It continuously watches your account for malicious or unauthorized activity — unusual API calls, compromised instances, crypto-mining — using machine learning and threat intelligence.

What makes it distinct

GuardDuty detects threats by analyzing logs (CloudTrail, VPC Flow Logs, DNS) — it doesn’t sit inline. Compare with Inspector (scans for vulnerabilities), Macie (finds sensitive data in S3), and WAF (blocks web requests). “Detect unusual/malicious activity in the account” → GuardDuty.

Test yourself

Practice question

A security team wants continuous, intelligent detection of unusual or malicious activity across their AWS account, like unexpected API calls or compromised instances. Which service?

  1. Amazon Inspector
  2. Amazon GuardDuty
  3. AWS WAF
  4. Amazon Macie
👉 Click to reveal the answer & explanation

Correct answer: B. GuardDuty continuously analyzes account logs to detect threats and anomalous behavior. Inspector (A) scans workloads for vulnerabilities; WAF (C) blocks web exploits inline; Macie (D) finds sensitive data in S3.

Related topics

Amazon Inspector · Amazon Macie · AWS CloudTrail

CloudExamPro Premium

Ready to pass the AWS Solutions Architect Associate (SAA-C03)?

Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.

  • ✓  6 full-length practice exams
  • ✓  A detailed explanation for every single question
  • ✓  Realistic, scenario-based questions — not memory dumps
  • ✓  Lifetime access, kept current for 2026

Get the SAA-C03 Practice Exams →or try 25 free questions first

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access