A security engineer is investigating a potential compromise. The engineer notices that an EC2 instance is sending outbound traffic to an unknown IP address on port 443. The engineer needs to determine if the instance is communicating with a known command and control (C2) server. Which AWS service can the engineer use to check the reputation of the destination IP address?
Amazon GuardDuty is a managed threat detection service that continuously consumes VPC Flow Logs, DNS query logs, CloudTrail events, and S3 data events. It applies integrated threat intelligence from AWS and third-party sources, along with machine learning and anomaly detection, to generate findings when an EC2 instance communicates with a known malicious IP, Bitcoin miner, or Tor node. Its findings include the affected resource, the malicious IP, the protocol and port, and confidence indicators, enabling a security engineer to quickly investigate and respond.
Why this answer
Amazon GuardDuty is a threat detection service that continuously monitors for malicious or unauthorized behavior, including communication with known command and control (C2) servers. It uses threat intelligence feeds, such as those from AWS and third-party partners, to check the reputation of destination IP addresses and alert on suspicious outbound traffic. In this scenario, GuardDuty can directly identify if the EC2 instance is communicating with a known C2 server by analyzing VPC Flow Logs, DNS logs, and other data sources.
Exam trap
The trap here is that candidates often confuse VPC Flow Logs (which only capture raw network metadata) with a security analysis service like GuardDuty, assuming that flow logs alone can determine IP reputation without additional threat intelligence integration.
How to eliminate wrong answers
Option A is wrong because AWS CloudTrail records API calls and management events, not network traffic or IP reputation checks; it cannot analyze outbound traffic to an unknown IP address. Option B is wrong because VPC Flow Logs capture metadata about IP traffic (source/destination IP, ports, protocol) but do not provide threat intelligence or reputation scoring for destination IPs; they only log the raw network flow data. Option C is wrong because AWS Trusted Advisor inspects your AWS environment for best practices in cost, performance, security, and fault tolerance, but it does not perform real-time threat detection or IP reputation checks against C2 servers.