Enable GuardDuty EKS Audit Log Monitoring to detect unauthenticated EKS access with least effort
A company needs to detect unauthenticated access to its Amazon Elastic Kubernetes Service (Amazon EKS) clusters. The company needs a solution that requires no additional configuration of the existing EKS deployment. Which solution will meet these requirements with the LEAST operational effort?
Community Votes
80% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
GuardDuty EKS Audit Log Monitoring consumes the Kubernetes API audit logs that EKS produces by default, so turning it on needs no changes to the cluster deployment. It provides threat detection (including unauthenticated-access attempts) natively, unlike Container Insights (metrics only) or a third-party add-on (extra config).
The company must detect unauthenticated access to existing EKS clusters with no additional EKS configuration and the least operational effort. Amazon GuardDuty's EKS Audit Log Monitoring analyzes the Kubernetes audit logs that EKS already emits and raises findings for suspicious activity such as unauthenticated requests, requiring only enabling the feature—no new add-ons, Sidecars, or manual log pipelines.
Relying on CloudWatch Container Insights (option C), which surfaces performance metrics, not unauthorized-access threat detection. Or installing a vendor EKS add-on (option A), which adds configuration the scenario explicitly wants to avoid.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.