What's changed: Deepened SOA-C02 Chapter 4 to Associate depth (tables, scenarios, FAQ, traps; localized figures)
4.3Compliance and Threat Detection (Config, GuardDuty)
Understand governance operations: AWS Config for configuration recording, rule evaluation, and auto-remediation; GuardDuty for threat detection; and Trusted Advisor best-practice checks.
In operations, continuously verify compliance with rules and absence of threats. AWS Config, GuardDuty, and Trusted Advisor are the staple tools.
4.3.1Config, GuardDuty, and Trusted Advisor
- AWS Config: records resource config and evaluates compliance via rules; can auto-remediate non-compliance.
- GuardDuty: analyzes CloudTrail, VPC flow logs, and DNS logs to detect threats.
- Trusted Advisor: best-practice checks for security, cost, performance, and service limits.
Common on SOA: is config compliant = AWS Config (+ auto-remediation), detect suspicious activity = GuardDuty, best-practice/service-limit checks = Trusted Advisor. Watch for swapped roles.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

