AWS Service for ML-based Log Analysis and Security Investigation
A company wants to use machine learning capabilities to analyze log data from its Amazon EC2 instances and efficiently conduct security investigations. Which AWS service will meet these requirements?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the distinction between threat detection (GuardDuty) and security investigation/analysis (Detective), with the trap being their shared use of ML on logs.
Amazon Detective is the correct AWS service for analyzing log data with machine learning to conduct security investigations. This page clarifies why it is preferred over GuardDuty for investigation tasks.
Many learners choose Amazon GuardDuty because it uses ML and analyzes logs, but they miss that GuardDuty detects threats while Detective investigates root causes.
Community Discussion (11 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Amazon Detective is a fully managed service that automatically collects log data from your AWS resources and uses machine learning, statistical analysis, and graph theory to build a linked set of data that enables you to easily conduct security investigations. It helps identify the root cause of suspicious activities by visualizing relationships between entities in your environment.Why the Other Options Are Wrong
Amazon Inspector is an automated security assessment service that finds vulnerabilities in EC2 instances, not for general log analysis or investigation. Amazon QuickSight is a business intelligence tool for creating dashboards and reports, not a specialized security investigation service. Amazon GuardDuty is a threat detection service that identifies potential unauthorized activity using ML, but its primary role is detection and alerting rather than deep investigation and root cause analysis.Community Comment Notes
Community consensus strongly supports Amazon Detective, with most users citing its ability to 'automatically collect log data' and 'identify root cause'. One user noted that while GuardDuty detects threats, Detective provides the interactive visualizations needed for investigation. Another user clarified that Detective builds a 'linked set of data' which is key for investigating complex issues.Official Reference
Exam Strategy
When a question mentions 'investigation', 'root cause', or 'visualizing relationships' in a security context, think of Detective. When it mentions 'continuous monitoring' or 'alerting' for threats, think of GuardDuty.
Frequently Asked Questions
Why not Amazon GuardDuty for this scenario?
GuardDuty detects threats and sends alerts, but Detective investigates the root cause using ML and graph theory on collected logs.
Does Detective replace GuardDuty?
No, Detective can analyze findings from GuardDuty, but it is designed for investigation, not continuous threat detection.
Related Analysis
Practice All CLF-C02 Questions
Access 120 questions with complete answers and detailed explanations.
View Full CLF-C02 Practice Test →