Enable GuardDuty EKS Audit Log Monitoring to detect unauthenticated EKS access with least effort

Answer Correct answer: D — enable GuardDuty EKS Audit Log Monitoring; it reads existing EKS audit logs with no cluster changes.

A company needs to detect unauthenticated access to its Amazon Elastic Kubernetes Service (Amazon EKS) clusters. The company needs a solution that requires no additional configuration of the existing EKS deployment. Which solution will meet these requirements with the LEAST operational effort?

  1. Install an Amazon EKS add-on from a security vendor.
  2. Enable AWS Security Hub. Monitor the Kubernetes findings.
  3. Monitor Amazon CloudWatch Container Insights metrics for Amazon EKS.
  4. Enable Amazon GuardDuty. Use EKS Audit Log Monitoring. Correct Answer

Community Votes

D
80%
C
20%

80% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

GuardDuty EKS Audit Log Monitoring consumes the Kubernetes API audit logs that EKS produces by default, so turning it on needs no changes to the cluster deployment. It provides threat detection (including unauthenticated-access attempts) natively, unlike Container Insights (metrics only) or a third-party add-on (extra config).

The company must detect unauthenticated access to existing EKS clusters with no additional EKS configuration and the least operational effort. Amazon GuardDuty's EKS Audit Log Monitoring analyzes the Kubernetes audit logs that EKS already emits and raises findings for suspicious activity such as unauthenticated requests, requiring only enabling the feature—no new add-ons, Sidecars, or manual log pipelines.

Relying on CloudWatch Container Insights (option C), which surfaces performance metrics, not unauthorized-access threat detection. Or installing a vendor EKS add-on (option A), which adds configuration the scenario explicitly wants to avoid.

Community Discussion (5 comments)

IPLogic 👍 1 Selected: D
The best solution to detect unauthenticated access to Amazon EKS clusters with the least operational effort is: D. Enable Amazon GuardDuty. Use EKS Audit Log Monitoring. Amazon GuardDuty provides comprehensive security monitoring for EKS clusters, including the ability to detect unauthenticated access attempts. It requires minimal configuration and integrates seamlessly with existing EKS deployments.
rhsilva 👍 1 Selected: D
https://aws.amazon.com/blogs/security/how-to-detect-security-issues-in-amazon-eks-clusters-using-amazon-guardduty-part-1/
mzeynalli 👍 1 Selected: D
NOT C! CloudWatch Container Insights provides metrics and monitoring for performance but is not ideal for detecting unauthenticated access. It does not provide threat detection capabilities directly related to unauthorized attempts.
siheom 👍 1 Selected: D
VOTE D
asdf1234567 👍 1 Selected: C
CloudWatch Container Insights can be a helpful part of detecting unauthenticated access attempts in an Amazon EKS cluster.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

GuardDuty EKS Audit Log Monitoring reads the Kubernetes audit logs that EKS already generates and produces findings for malicious or unauthorized activity, including unauthenticated access attempts, with no modification to the existing EKS deployment. Enabling it is the least-effort, managed way to meet the detection requirement.

Why the Other Options Are Wrong

A requires installing a third-party EKS add-on, adding configuration the scenario forbids. B (Security Hub) aggregates findings from other services but does not itself monitor EKS audit logs for unauthenticated access without an underlying detector like GuardDuty. C (Container Insights) provides metrics for performance, not threat detection of unauthenticated access.

Community Comment Notes

Community favored D (80 votes). Commenters noted C is wrong because Container Insights is metrics-only, not threat detection, and linked the GuardDuty EKS monitoring blog. A minority picked C but it lacks detection capability.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide