AWS Certified Security – Specialty (SCS-C02) — Question 246

A company runs its microservices architecture in Kubernetes containers on AWS by using Amazon Elastic Kubernetes Service (Amazon EKS) and Amazon Aurora The company has an organization in AWS Organizations to manage hundreds of AWS accounts that host different microservices.

The company needs to implement a monitoring solution for logs from all AWS resources across all accounts. The solution must include automatic detection of security-related issues.

Which solution will meet these requirements with the LEAST operational effort?

Answer options

Correct answer: A

Explanation

The correct answer is A because Amazon GuardDuty provides automated threat detection and requires minimal operational effort when enabled across accounts. Options B and D involve more complex setups with additional services for log processing, while option C requires managing an S3 bucket and analyzing logs with Athena, which increases operational overhead.