Courseiva

SAA-C03 Design Secure Architectures Practice Question

A company wants to implement a service that continuously monitors for malicious activity and unauthorized behavior across its AWS accounts, such as cryptocurrency mining or unusual API calls. Which AWS service should they use?

⚠ Common exam trap

The trap is confusing logging and compliance services (CloudTrail, Config) with threat detection — candidates pick CloudTrail because it 'monitors API calls,' but it only records them; GuardDuty is what analyzes them for malicious behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon GuardDuty

Amazon GuardDuty is a managed threat detection service that continuously monitors AWS accounts for malicious activity and unauthorized behavior using machine learning, anomaly detection, and integrated threat intelligence. It specifically detects findings like cryptocurrency mining, unusual API calls, and compromised instances, which matches the requirement exactly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon Macie

    Why it's wrong here

    Amazon Macie is a data privacy and security service that uses machine learning to automatically discover, monitor, and protect sensitive data in Amazon S3. It focuses on identifying PII rather than monitoring general account activity for threats like cryptocurrency mining or unauthorized API calls.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources. It tracks configuration changes over time for compliance and governance purposes, but it does not perform real-time threat detection or behavioral analysis for malicious activities.

  • ✓

    Amazon GuardDuty

    Why this is correct

    Amazon GuardDuty provides intelligent threat detection by analyzing various data sources including AWS CloudTrail event logs and VPC Flow Logs. It can identify specific threats like EC2 instances communicating with known malicious IP addresses or performing cryptocurrency mining, making it the correct choice for this scenario.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail records API calls and account activity for auditing and governance. While it provides the data that other services use for analysis, CloudTrail itself is a logging service and does not have the built-in intelligence to detect or alert on malicious behavior patterns automatically.

About these practice questions

One of 149 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.