SAA-C03 - Design Secure Architectures - Section 1.6

Select managed threat-detection and posture-management services such as Amazon GuardDuty, Amazon Inspector, AWS Security Hub and Amazon Macie.

Describe Amazon GuardDuty as a threat-detection service that analyses logs for malicious activity, Amazon Inspector as a vulnerability scanner for EC2 and container workloads, and Amazon Macie as a data-classification service that detects sensitive data in S3. Recognise AWS Security Hub as the aggregation point that normalises findings from these and other services into a unified security posture view.

Amazon GuardDutyAmazon InspectorAWS Security HubAmazon Macie

Practice question for this objective

Free sampleDesign Secure Architecturesmedium

An organisation runs many AWS accounts under AWS Organizations and has already enabled GuardDuty, Inspector, and Macie. Security engineers are overwhelmed because findings are scattered across services and accounts, and leadership also wants a single view of how well each account conforms to a recognised security standard such as the AWS Foundational Security Best Practices. Which service should the team use to centralise and prioritise these findings and run automated standards checks?

  • AAWS Security Hub, which aggregates findings from GuardDuty, Inspector, and Macie and runs automated checks against security standards Correct
  • BAmazon GuardDuty, which collects findings from Inspector and Macie across all accounts and scores each account against a foundational security standard
  • CAWS Config alone, which aggregates the GuardDuty, Inspector, and Macie findings into one view and scores each account against the security standard
  • DAmazon Macie, which consolidates the GuardDuty and Inspector findings for every account and evaluates each one against the foundational security standard
AWS Security Hub centralises and prioritises findings from services like GuardDuty, Inspector, and Macie and runs automated checks against security standards. Security Hub uses a common finding format to ingest results from GuardDuty, Inspector, Macie, and partner tools across an organisation, then deduplicates and ranks them while continuously evaluating accounts against standards such as the AWS Foundational Security Best Practices, giving one prioritised posture view.

Why A is correct: Security Hub ingests and normalises findings from GuardDuty, Inspector, Macie, and others across the organisation, deduplicates and prioritises them, and runs automated controls against standards such as the AWS Foundational Security Best Practices for a single posture view.

Why B is wrong: GuardDuty is a threat-detection source whose own findings feed elsewhere, so it seems central, but it does not aggregate other services' findings or run posture checks against a foundational security best practices standard.

Why C is wrong: Config records resource configuration and evaluates rules, and it underpins many checks, so it is tempting, but on its own it does not ingest and prioritise security findings from GuardDuty, Inspector, and Macie in a unified console.

Why D is wrong: Macie focuses on sensitive data discovery in S3 and contributes its own findings, so it is a finding producer rather than an aggregator, and it cannot centralise other services' results or run standards-based posture checks.

See more SAA-C03 practice questions, answers explained.

More in this domain

Back to all Design Secure Architectures objectives, or the SAA-C03 cert hub.

Examworthy is not affiliated with or endorsed by Amazon Web Services. Original, blueprint-aligned practice material only.