A city wants continuous detection of anomalous API activity and potentially compromised instances across accounts. Which service should the architect enable as the intelligent threat-detection control?
Select an answer to reveal the explanation.
Short Explanation
CloudTrail is the security camera footage; GuardDuty is the analyst who watches it and raises a hand. Turn on GuardDuty for managed findings about odd API use and sketchy instance behavior. Inventory reports and Snowball orders are not your threat-detection brain.
Full Explanation
Amazon GuardDuty continuously analyzes AWS telemetry such as CloudTrail management events, VPC Flow Logs, and DNS logs to produce actionable threat findings. CloudTrail provides the audit trail but does not by itself score anomalous behavior the way GuardDuty does. S3 Inventory and Snowball logistics address data listing and transfer—not intelligent detection of compromised instances or suspicious API patterns—so they are not substitutes for GuardDuty.