Bird
0
0

Why does GuardDuty not require you to deploy agents on your EC2 instances to detect threats?

hard📝 Conceptual Q10 of 15
AWS - Advanced Security
Why does GuardDuty not require you to deploy agents on your EC2 instances to detect threats?
AGuardDuty only monitors S3 buckets, so agents are unnecessary
BGuardDuty uses Lambda functions installed on each instance instead
CGuardDuty analyzes network and account activity logs centrally without needing agents
DGuardDuty requires manual log uploads, so agents are redundant
Step-by-Step Solution
Solution:
  1. Step 1: Understand GuardDuty architecture

    GuardDuty analyzes VPC flow logs, CloudTrail, and DNS logs centrally, so no agents are needed on instances.
  2. Step 2: Exclude incorrect options

    GuardDuty does not use Lambda on instances, does not only monitor S3, and does not require manual log uploads.
  3. Final Answer:

    GuardDuty analyzes network and account activity logs centrally without needing agents -> Option C
  4. Quick Check:

    Agentless detection = A [OK]
Quick Trick: GuardDuty is agentless, using centralized log analysis [OK]
Common Mistakes:
  • Thinking agents or Lambda must be installed on instances
  • Confusing GuardDuty with host-based security tools

Want More Practice?

15+ quiz questions · All difficulty levels · Free

Free Signup - Practice All Questions
More AWS Quizzes