DOP-C02 Security and Compliance Practice Question
A company wants to automatically detect and respond to suspicious activity in their AWS account. Which service should be used to generate alerts based on threat intelligence?
⚠ Common exam trap
The trap is conflating security services: candidates often pick Inspector for 'security' or CloudWatch for 'alerts,' but only GuardDuty is purpose-built for threat-intelligence-driven detection of suspicious activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon GuardDuty
Amazon GuardDuty is a managed threat detection service that continuously monitors AWS accounts for malicious activity using machine learning, anomaly detection, and integrated threat intelligence feeds. It analyzes CloudTrail management events, VPC Flow Logs, and DNS logs to generate findings and can trigger alerts via CloudWatch Events or Security Hub. This directly matches the requirement to detect and respond to suspicious activity based on threat intelligence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon GuardDuty
Why this is correct
Amazon GuardDuty is a managed threat detection service that continuously analyzes VPC Flow Logs, AWS CloudTrail management events, DNS logs, and, when enabled, EKS audit logs and S3 data events. It uses built-in threat intelligence feeds and machine learning to identify suspicious activity such as unusual API calls, reconnaissance behavior, or cryptocurrency mining, and produces findings that can trigger automated response via Amazon EventBridge. This makes it the purpose-built AWS service for automatically detecting and responding to suspicious activity.
- ✗
AWS Config
Why it's wrong here
AWS Config is a governance and compliance service that records resource configurations and evaluates them against customer-defined rules to detect configuration drift. It does not ingest security telemetry like API call patterns, network traffic, or DNS queries, and it lacks threat intelligence or machine learning anomaly detection capabilities. While it can invoke remediation on noncompliant configurations, it is not designed to identify malicious behavior or threats, so it does not satisfy the requirement to detect suspicious activity.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is a vulnerability management service that performs automated security assessments for known CVEs, software weaknesses, and unintentional network exposure in EC2 instances, container images, and Lambda functions. It scans for vulnerabilities and configuration issues at the environment level rather than analyzing real-time operational telemetry for ongoing attack indicators. Inspector is proactive in nature, assessing the attack surface but not detecting active threats or anomalous user/API behavior, so it is not a threat detection service.
- ✗
Amazon CloudWatch
Why it's wrong here
Amazon CloudWatch is an observability service that collects operational metrics, logs, and custom events, and it can trigger alarms based on threshold conditions or custom expressions. It does not have built-in threat intelligence, anomaly detection models, or the ability to natively analyze behavioral patterns in AWS account activity. You could build a custom detection pipeline by feeding logs into CloudWatch Logs Insights and coding heuristics, but that would require significant custom logic and still lack the curated, continuously updated threat intelligence that a dedicated threat detection service provides.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.