Courseiva

CCSP Cloud Security Operations Practice Question

Which AWS service uses machine learning to detect threats such as crypto mining activity on EC2 instances and compromised IAM credentials?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon GuardDuty

Amazon GuardDuty is a threat detection service that uses machine learning and anomaly detection to identify malicious activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Shield

    Why it's wrong here

    AWS Shield provides DDoS protection at the network and transport layers, not machine-learning threat detection of EC2 or IAM activity. It is tempting because it is an AWS security service, but Shield mitigates volumetric attacks, whereas GuardDuty identifies crypto mining and compromised credentials.

  • ✗

    AWS WAF

    Why it's wrong here

    AWS WAF filters HTTP traffic at the application layer against web exploits; it does not analyse EC2 runtime behaviour or IAM credential usage. It is tempting because it is a managed security service, but GuardDuty is the threat-detection service using machine learning for those findings.

  • ✗

    AWS Inspector

    Why it's wrong here

    Inspector performs vulnerability scanning of EC2 instances and container images against CVE databases; it does not analyse IAM credential usage or detect crypto-mining behaviour. It is tempting because Inspector does assess EC2 security posture, but that is agent-based package and network assessment, not behavioural threat detection, which GuardDuty provides.

  • ✓

    Amazon GuardDuty

    Why this is correct

    Amazon GuardDuty continuously analyses CloudTrail, VPC Flow Logs and DNS logs with managed machine learning and threat intelligence to surface findings including cryptocurrency mining on EC2 instances and compromised IAM credentials. It satisfies the stem's requirement for an AWS-native, ML-driven threat detection service without deploying agents.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.