GuardDuty is a threat-detection service. It continuously watches your account for malicious or unauthorized activity — unusual API calls, compromised instances, crypto-mining — using machine learning and threat intelligence.
What makes it distinct
GuardDuty detects threats by analyzing logs (CloudTrail, VPC Flow Logs, DNS) — it doesn’t sit inline. Compare with Inspector (scans for vulnerabilities), Macie (finds sensitive data in S3), and WAF (blocks web requests). “Detect unusual/malicious activity in the account” → GuardDuty.
Test yourself
A security team wants continuous, intelligent detection of unusual or malicious activity across their AWS account, like unexpected API calls or compromised instances. Which service?
- Amazon Inspector
- Amazon GuardDuty
- AWS WAF
- Amazon Macie
👉 Click to reveal the answer & explanation
Correct answer: B. GuardDuty continuously analyzes account logs to detect threats and anomalous behavior. Inspector (A) scans workloads for vulnerabilities; WAF (C) blocks web exploits inline; Macie (D) finds sensitive data in S3.
Related topics
Amazon Inspector · Amazon Macie · AWS CloudTrail
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first