AWS Certified Security – Specialty (SCS-C02) — Question 214

A company uses Amazon Elastic Kubernetes Service (Amazon EKS) clusters to run its Kubernetes-based applications. The company uses Amazon GuardDuty to protect the applications.

EKS Protection is enabled in GuardDuty. However, the corresponding GuardDuty feature is not monitoring the Kubernetes-based applications.

Which solution will cause GuardDuty to monitor the Kubernetes-based applications?

Answer options

Correct answer: D

Explanation

Enabling control plane logs in Amazon EKS and ensuring they are ingested into Amazon CloudWatch allows GuardDuty to access the necessary data for monitoring Kubernetes applications. The other options, while useful for different purposes, do not directly enable GuardDuty to monitor EKS applications.