Enable EKS control plane logs and ingest them into CloudWatch for GuardDuty to monitor

Answer Correct answer: D — enable EKS control plane logs and ingest them into CloudWatch so GuardDuty EKS Protection can monitor the cluster.

A company uses Amazon Elastic Kubernetes Service (Amazon EKS) clusters to run its Kubernetes-based applications. The company uses Amazon GuardDuty to protect the applications. EKS Protection is enabled in GuardDuty. However, the corresponding GuardDuty feature is not monitoring the Kubernetes-based applications. Which solution will cause GuardDuty to monitor the Kubernetes-based applications?

  1. Enable VPC flow logs for the VPC that hosts the EKS clusters.
  2. Assign the CloudWatchEventsFullAccess AWS managed policy to the EKS clusters.
  3. Ensure that the AmazonGuardDutyFullAccess AWS managed policy is attached to the GuardDuty service role.
  4. Enable the control plane logs in Amazon EKS. Ensure that the logs are ingested into Amazon CloudWatch. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

GuardDuty EKS Protection requires the EKS control plane (audit) logs to be enabled and flowing to CloudWatch; once present, GuardDuty ingests them for Kubernetes threat detection (D). VPC Flow Logs (A) cover network, not K8s API audit; GuardDuty managed policies (B/C) grant permissions but do not supply the logs GuardDuty needs. D is correct.

GuardDuty EKS Protection is enabled but not monitoring the Kubernetes workloads. GuardDuty's Kubernetes protection analyzes the EKS control plane (audit) logs; those logs must be enabled on the cluster and sent to CloudWatch so GuardDuty can ingest them for continuous threat detection. Without the control plane logs, GuardDuty has nothing to analyze.

Enabling VPC Flow Logs (A)—useful for network visibility but not the Kubernetes audit logs GuardDuty EKS Protection consumes. Attaching GuardDuty managed policies (B/C)—those grant service permissions but do not create the control plane logs GuardDuty analyzes. The missing piece is enabling and ingesting the EKS control plane logs (D).

Community Discussion (3 comments)

Pat9595 👍 1 Selected: D
For GuardDuty to monitor Kubernetes-based applications in Amazon EKS, EKS Protection in GuardDuty requires the integration of control plane logs. These logs contain critical information about the health and security of the EKS clusters, which GuardDuty uses to detect potential threats and vulnerabilities.
m_ch333 👍 1 Selected: D
When you enable EKS Protection, GuardDuty will be able to access your Amazon EKS audit logs only for continuous threat detection. So you need to ensure the audit logs is enabled first. https://docs.aws.amazon.com/eks/latest/userguide/integration-guardduty.html
DewDrop 👍 1
https://docs.aws.amazon.com/guardduty/latest/ug/kubernetes-protection.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

GuardDuty's EKS Protection performs continuous threat detection on Amazon EKS by analyzing the cluster's control plane (Kubernetes audit) logs. Those logs must be enabled on the EKS cluster and ingested into CloudWatch; once available, GuardDuty can monitor the Kubernetes-based applications. Without them, EKS Protection has no data to analyze.

Why the Other Options Are Wrong

A enables VPC Flow Logs, which capture network flow records, not the Kubernetes API audit logs GuardDuty needs. B and C attach GuardDuty/IAM managed policies, which provide permissions but do not generate the control plane logs. D is the correct action that supplies the logs GuardDuty consumes.

Community Comment Notes

Community voted D (100). Commenters explained GuardDuty EKS Protection needs the cluster's audit/control plane logs enabled and ingested into CloudWatch to monitor Kubernetes applications. D confirmed.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide