Threat Detection and Response
What GuardDuty and Inspector each detect, how Security Hub turns scattered findings into one prioritized queue, and how to remediate them automatically with automation rules and EventBridge.
An instance starts talking to an IP address in a country where you run nothing, and the same instance has been carrying a published CVE for 5 weeks. Those are 2 different questions, and AWS answers them with 2 different services. This topic covers both detectors, then the layer that ranks their output and acts on it without waiting for a human.
It closes exam skill 4.2.5, which asks you to configure reports and remediate findings from AWS Security Hub, Amazon GuardDuty, AWS Config, Amazon Inspector, and AWS Security Agent. The remediate half of that sentence is where most of the exam questions live.
What This Topic Covers
- The split between behavior-based threat detection and state-based vulnerability management, and which service answers which question
- The 3 GuardDuty foundational data sources, why none of them require you to enable logging first, and the one real dependency that DNS monitoring carries
- GuardDuty protection plans, Extended Threat Detection attack sequences, and how to read a finding type from its name
- Finding aggregation, suppression rules, and the export frequency that delays automation on an ongoing attack
- Amazon Inspector scan types, the agent-based against agentless decision, and the 3 finding types with their schedules
- Why suppression means 2 different things in GuardDuty and Inspector
- Security Hub CSPM aggregation in ASFF, security standards, and how the security score responds to suppressed findings
- Cross-Region aggregation with a home Region, and central configuration against local configuration for an organization
- Automation rules and EventBridge as 2 separate tools, and the full remediation loop that ends with a closed workflow status
- Where AWS Security Agent and Security Hub exposure findings sit against the runtime detectors
Why It Matters
Detection questions on the exam rarely ask what a service is. They hand you a symptom and 4 services that all sound plausible, and the answer turns on a boundary: Config records configuration drift while GuardDuty watches behavior, Inspector finds what is exploitable while Security Hub ranks what everyone else found. Getting those borders wrong costs you points across the whole domain, because the same services reappear in compliance and data protection questions.
On the job the stake is different. Detection without response is a queue that grows until nobody reads it. The teams that get value out of these services are the ones that wired the finding to an action and then closed the finding when the action succeeded, and that loop is exactly what this topic builds.
