Courseiva
Security and Compliance →easyMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company wants to automatically detect and respond to suspicious activity in their AWS account. Which service should be used to generate alerts based on threat intelligence?

⚠ Common exam trap

The trap is conflating security services: candidates often pick Inspector for 'security' or CloudWatch for 'alerts,' but only GuardDuty is purpose-built for threat-intelligence-driven detection of suspicious activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon GuardDuty

Amazon GuardDuty is a managed threat detection service that continuously monitors AWS accounts for malicious activity using machine learning, anomaly detection, and integrated threat intelligence feeds. It analyzes CloudTrail management events, VPC Flow Logs, and DNS logs to generate findings and can trigger alerts via CloudWatch Events or Security Hub. This directly matches the requirement to detect and respond to suspicious activity based on threat intelligence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Amazon GuardDuty

    Why this is correct

    Amazon GuardDuty is a managed threat detection service that continuously analyzes VPC Flow Logs, AWS CloudTrail management events, DNS logs, and, when enabled, EKS audit logs and S3 data events. It uses built-in threat intelligence feeds and machine learning to identify suspicious activity such as unusual API calls, reconnaissance behavior, or cryptocurrency mining, and produces findings that can trigger automated response via Amazon EventBridge. This makes it the purpose-built AWS service for automatically detecting and responding to suspicious activity.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a governance and compliance service that records resource configurations and evaluates them against customer-defined rules to detect configuration drift. It does not ingest security telemetry like API call patterns, network traffic, or DNS queries, and it lacks threat intelligence or machine learning anomaly detection capabilities. While it can invoke remediation on noncompliant configurations, it is not designed to identify malicious behavior or threats, so it does not satisfy the requirement to detect suspicious activity.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that performs automated security assessments for known CVEs, software weaknesses, and unintentional network exposure in EC2 instances, container images, and Lambda functions. It scans for vulnerabilities and configuration issues at the environment level rather than analyzing real-time operational telemetry for ongoing attack indicators. Inspector is proactive in nature, assessing the attack surface but not detecting active threats or anomalous user/API behavior, so it is not a threat detection service.

  • ✗

    Amazon CloudWatch

    Why it's wrong here

    Amazon CloudWatch is an observability service that collects operational metrics, logs, and custom events, and it can trigger alarms based on threshold conditions or custom expressions. It does not have built-in threat intelligence, anomaly detection models, or the ability to natively analyze behavioral patterns in AWS account activity. You could build a custom detection pipeline by feeding logs into CloudWatch Logs Insights and coding heuristics, but that would require significant custom logic and still lack the curated, continuously updated threat intelligence that a dedicated threat detection service provides.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.