SAA-C03 Design Secure Architectures Practice Question
A company is concerned about unauthorized access and potential data exfiltration within their AWS environment. They need a service that can continuously monitor VPC Flow Logs, AWS CloudTrail management events, and DNS logs to identify suspicious activities using machine learning. Which solution should the architect recommend for centralized threat detection?
⚠ Common exam trap
SAA-C03 often tests the confusion between GuardDuty (threat detection) and Inspector (vulnerability assessment) or Config (configuration compliance), causing candidates to select a service that doesn't analyze logs for threats.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Amazon GuardDuty and integrate it with AWS Organizations for cross-account visibility.
Amazon GuardDuty is a threat detection service that continuously monitors VPC Flow Logs, AWS CloudTrail management events, and DNS logs using machine learning and threat intelligence to identify suspicious activities. Integrating it with AWS Organizations enables centralized threat detection across all accounts, matching the requirement for cross-account visibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable Amazon GuardDuty and integrate it with AWS Organizations for cross-account visibility.
Why this is correct
Amazon GuardDuty continuously monitors for malicious activity and unauthorized behavior using machine learning and threat intelligence. It analyzes data sources like VPC Flow Logs and CloudTrail to identify anomalies. This managed service provides a comprehensive view of the security posture across multiple AWS accounts through integration with AWS Organizations.
- ✗
Configure AWS Inspector to perform network reachability assessments on all EC2 instances.
Why it's wrong here
AWS Inspector is an automated vulnerability management service that scans EC2 instances, container images, and Lambda functions for software vulnerabilities and unintended network exposure. While it provides deep insights into host-level security, it does not analyze network flow patterns or DNS logs to detect real-time behavioral anomalies.
- ✗
Deploy AWS Shield Advanced to protect all public-facing endpoints from DDoS attacks.
Why it's wrong here
AWS Shield Advanced provides expanded DDoS protection for applications running on EC2, ELB, and CloudFront. While it protects against infrastructure and application layer attacks, it does not provide the behavioral analysis of VPC flow logs or DNS queries required to identify compromised internal resources or data exfiltration.
- ✗
Use AWS Config to monitor changes in security group rules and VPC configurations.
Why it's wrong here
AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources. While it is excellent for ensuring compliance with security best practices, it does not perform behavioral analysis or threat detection based on network traffic logs or active DNS queries.
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 149 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.