Enable GuardDuty EKS Audit Log Monitoring and Amazon Detective with EKS audit logs as a source
A company's video streaming platform usage has increased from 10,000 users each day to 50,000 users each day in multiple countries. The company deploys the streaming platform on Amazon Elastic Kubernetes Service (Amazon EKS). The EKS workload scales up to thousands of nodes during peak viewing time. The company's users report occurrences of unauthorized logins. Users also report sudden interruptions and logouts from the platform. The company wants additional security measures for the entire platform. The company also needs a summarized view of the resource behaviors and interactions across the company's entire AWS environment. The summarized view must show login attempts, API calls, and network traffic. The solution must permit network traffic analysis while minimizing the overhead of managing logs. The solution must also quickly investigate any potential malicious behavior that is associated with the EKS workload. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Amazon Detective is the service that produces a summarized view of how resources behave and interact across accounts, and it accepts EKS audit logs as a source package alongside CloudTrail and VPC Flow Logs, which is how login attempts, API calls, and network traffic all appear in one place without the team building and curating log pipelines itself (B). That directly satisfies the low log-management-overhead and fast-investigation requirements. GuardDuty EKS Audit Log Monitoring supplies the detection of malicious activity on the cluster, and the two integrate so GuardDuty findings feed Detective's investigation (B).
The platform needs additional security for unauthorized logins and abrupt logouts on EKS, plus a summarized view of resource behaviour across the environment covering login attempts, API calls, and network traffic, with minimal log-management overhead and fast investigation of malicious behavior. GuardDuty EKS Audit Log Monitoring analyzes the Kubernetes audit logs for malicious activity, and Amazon Detective ingests those logs as a source alongside its other data sources, automatically building the behavior graph and producing the summarized visual view and the investigation tooling without the team managing log pipelines.
Storing EKS audit logs and CloudTrail files in S3 and building an Athena external table with a QuickSight dashboard (A and C) — this requires the team to own a log ingestion, cataloging, and dashboard pipeline, which directly contradicts the requirement to minimize the overhead of managing logs, and it provides no investigation tooling for malicious behavior. Enabling CloudWatch Container Insights with CloudTrail logs and the same Athena and QuickSight stack (C) — Container Insights provides cluster performance and health metrics rather than a cross-account security behavior summary, so it does not satisfy the summarized security view. Adding Container Insights and VPC Flow Logs to GuardDuty without Detective (D) — this collects more log sources but still leaves the team without the summarized behavioral view and the investigation capability that the requirement asks for.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement has two halves. First, additional security for the EKS workload is delivered by Amazon GuardDuty EKS Audit Log Monitoring, which analyzes the Kubernetes audit logs for malicious activity and can surface threats such as unauthorized access (B). Second, the summarized view of resource behaviour and interactions across the environment showing login attempts, API calls, and network traffic, with minimal log-management overhead and rapid investigation, is delivered by Amazon Detective. Detective is purpose-built to generate visualizations representing how resources behave and interact across accounts, and it ingests EKS audit logs as a source package in addition to CloudTrail and network flow data, so all three categories appear in one view. Because Detective builds and maintains the underlying data processing itself, the team does not manage log pipelines, which satisfies the low-overhead requirement, and GuardDuty findings integrate with Detective to support fast investigation (B). B is the correct answer.Why the Other Options Are Wrong
A enables GuardDuty EKS Audit Log Monitoring and CloudTrail logs, stores the EKS audit logs and CloudTrail files in Amazon S3, creates an Athena external table, and builds a QuickSight dashboard. This makes the team responsible for log ingestion, cataloging, table maintenance, and dashboard construction, which is precisely the log-management overhead the requirement says to minimize, and an Athena table with QuickSight provides no investigation tooling for malicious behavior. C enables CloudWatch Container Insights along with CloudTrail logs and the same Athena and QuickSight pipeline. Container Insights delivers cluster performance, health, and capacity metrics rather than a cross-account security behavior summary, so the summarized view of login attempts, API calls, and network traffic is not produced, and the same self-managed pipeline objection applies. D enables GuardDuty EKS Audit Log Monitoring together with CloudWatch Container Insights and VPC Flow Logs, plus CloudTrail logs. This gathers additional telemetry but still leaves the team without the summarized behavioral view across the environment and without a dedicated investigation capability, so it does not meet the stated requirements. B is correct.Community Comment Notes
Community voted B unanimously. jamesf quoted the Amazon Detective documentation, explaining that Detective helps quickly analyze and investigate security events across one or more accounts by generating data visualizations representing how resources behave and interact. trungtd cited both the GuardDuty Detective integration page and the Detective EKS source-data documentation, confirming that EKS audit logs are a supported Detective source. TEC1 linked GuardDuty's EKS findings for the detection half and Detective for the summarized view. getadroit supported D with a GuardDuty blog link, but D does not include the summarized view and investigation capability the question requires. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →