Q: 8
A company needs centralized log monitoring with automatic detection across hundreds of AWS
accounts.
Which solution meets these requirements with the LEAST operational effort?
Options
Discussion
Option A fits since GuardDuty handles detection automatically and scales across accounts with Organizations. If you want detection, Inspector or Athena won’t do it for you. Only caveat: if you need detailed custom rules, you might have to layer other solutions, but for least effort, A wins. Agree?
A beats D here. GuardDuty is fully managed, supports multi-account orgs, and is practically set-and-forget for detection so barely any hands-on ops. Official AWS exam guides and practice tests highlight this for least operational effort. Pretty sure A is what they're looking for here but open if someone has seen otherwise.
GuardDuty really handles the auto detection plus centralization with almost no heavy lifting, so A is the way to go here. None of the others provide managed threat detection at org scale with such low ongoing work, as far as I know.
Option A B's a trap since Inspector isn’t for org-wide auto detection, so GuardDuty makes more sense.
Its A, since GuardDuty is managed and integrates with org accounts for auto detection, barely any ongoing admin. I checked some practice exams and that's the main angle they stress. Not totally sure if log analytics was wanted, but here A fits best.
A had something like this in a mock and GuardDuty was the clear pick for auto detection across org accounts.
Option A. GuardDuty does the auto detection part right out of the box, just set it as admin for all accounts and you're set. Not totally sure if Inspector plus CloudWatch in B could get close, but I think A needs the least setup overall.
Probably A, since GuardDuty is built for managed detection across multiple accounts. C looks attractive, but no auto detection there.
C vs A
I get why C is tempting, but it only centralizes logs, doesn't do any auto detection. A (GuardDuty) is made for exactly this scenario and manages everything across accounts for you. Pretty sure A is the intended pick here, but open to hearing counterpoints.
I get why C is tempting, but it only centralizes logs, doesn't do any auto detection. A (GuardDuty) is made for exactly this scenario and manages everything across accounts for you. Pretty sure A is the intended pick here, but open to hearing counterpoints.
A since GuardDuty covers centralized and automated detection, way less effort than the others. Pretty sure that's what they're looking for.
Be respectful. No spam.