SAA-C03 Design Secure Architectures Practice Question
A company wants to implement a service that continuously monitors for malicious activity and unauthorized behavior across its AWS accounts, such as cryptocurrency mining or unusual API calls. Which AWS service should they use?
⚠ Common exam trap
The trap is confusing logging and compliance services (CloudTrail, Config) with threat detection — candidates pick CloudTrail because it 'monitors API calls,' but it only records them; GuardDuty is what analyzes them for malicious behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon GuardDuty
Amazon GuardDuty is a managed threat detection service that continuously monitors AWS accounts for malicious activity and unauthorized behavior using machine learning, anomaly detection, and integrated threat intelligence. It specifically detects findings like cryptocurrency mining, unusual API calls, and compromised instances, which matches the requirement exactly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Macie
Why it's wrong here
Amazon Macie is a data privacy and security service that uses machine learning to automatically discover, monitor, and protect sensitive data in Amazon S3. It focuses on identifying PII rather than monitoring general account activity for threats like cryptocurrency mining or unauthorized API calls.
- ✗
AWS Config
Why it's wrong here
AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources. It tracks configuration changes over time for compliance and governance purposes, but it does not perform real-time threat detection or behavioral analysis for malicious activities.
- ✓
Amazon GuardDuty
Why this is correct
Amazon GuardDuty provides intelligent threat detection by analyzing various data sources including AWS CloudTrail event logs and VPC Flow Logs. It can identify specific threats like EC2 instances communicating with known malicious IP addresses or performing cryptocurrency mining, making it the correct choice for this scenario.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records API calls and account activity for auditing and governance. While it provides the data that other services use for analysis, CloudTrail itself is a logging service and does not have the built-in intelligence to detect or alert on malicious behavior patterns automatically.
About these practice questions
One of 149 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.