Use GuardDuty RDS Protection with EventBridge and SNS for least-overhead Aurora unknown-user login alerts

Answer Correct answer: A — GuardDuty RDS Protection findings routed via EventBridge to SNS give least-overhead unknown-user login alerts.

A security engineer must Implement monitoring of a company's Amazon Aurora MySQL DB instances. The company wants to receive email notifications when unknown users try to log in to the database endpoint. Which solution will meet these requirements with the LEAST operational overhead?

  1. Enable Amazon GuardDuty. Enable the Amazon RDS Protection feature in GuardDuty to detect login attempts by unknown users. Create an Amazon EventBridge rule to filter GuardDuty findings. Send email notifications by using Amazon Simple Notification Service (Amazon SNS). Correct Answer
  2. Enable the server_audit_logglng parameter on the Aurora MySQL DB instances. Use AWS Lambda to periodically scan the delivered log files for login attempts by unknown users. Send email notifications by using Amazon Simple Notification Service (Amazon SNS).
  3. Create an Amazon RDS Custom AMI. Include a third-party security agent in the AMI to detect login attempts by unknown users. Deploy RDS Custom DB instances. Migrate data from the existing installation to the RDS Custom DB instances. Configure email notifications from the third-party agent.
  4. Write a stored procedure to detect login attempts by unknown users. Schedule a recurring job inside the database engine. Configure Aurora MySQL to use Amazon Simple Notification Service (Amazon SNS) to send email notifications.

Community Votes

A
75%
B
25%

75% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

GuardDuty RDS Protection is a managed feature that surfaces suspicious login activity on RDS/Aurora, including access by unknown users, as findings. Routing those findings through EventBridge to an SNS email subscription delivers alerts with zero custom Lambda, AMI, or stored-procedure maintenance—the lowest operational overhead option.

The company wants email alerts when unknown users attempt to log in to Amazon Aurora MySQL, with the least operational overhead. GuardDuty RDS Protection detects potentially unauthorized login attempts (including by unknown users) on Aurora and emits findings; an EventBridge rule filters those GuardDuty findings and an SNS topic sends the email notifications, with no custom code or agents to maintain.

Building custom detection with server audit logs + a scanning Lambda (B), a third-party agent on RDS Custom (C), or an in-database stored procedure (D). All require writing and maintaining code/agents and add substantial operational overhead versus the fully managed GuardDuty path.

Community Discussion (6 comments)

grekh001 👍 6
A. https://docs.aws.amazon.com/guardduty/latest/ug/rds-protection.html
Davidng88 👍 1 Selected: A
A has least operational overheads compared to B (write and maintain Lambda), C (customized AMI, 3rd party software agents) and D (write and maintain stored procedure).
heatblur 👍 1 Selected: A
A is correct....a Lambda function to periodically scan the logs is not ideal.
HunkyBunky 👍 1 Selected: A
I guess that A - fits better in that scenario
adit 👍 1 Selected: B
B right answer
sema2232 👍 1
B right answer

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

GuardDuty RDS Protection monitors Aurora MySQL login activity and raises findings for potentially unauthorized or unknown-user login attempts. An EventBridge rule that matches those GuardDuty finding types triggers an SNS email notification. This is fully managed, needs no custom code or agents, and therefore has the least operational overhead of the choices.

Why the Other Options Are Wrong

B requires enabling server audit logging and maintaining a Lambda that periodically scans logs—ongoing code and operational burden. C forces a migration to RDS Custom with a third-party agent baked into a custom AMI, which is heavy and disruptive. D requires writing and maintaining a stored procedure plus in-engine scheduling, also more overhead than the managed service.

Community Comment Notes

Community chose A (75 votes). A top comment linked the GuardDuty RDS Protection doc and noted A has the least overhead versus B's Lambda scanning. A minority picked B, but the least-overhead criterion points to the managed GuardDuty path.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide