AWS Cloud Practitioner GuardDuty,
Inspector & Macie Practice Test 2026–
2027 | Threat Detection, Vulnerability &
Data Security Questions
1. A company wants to continuously monitor its AWS environment for
suspicious account activity, compromised credentials, and potentially
malicious behavior. Which AWS service is specifically designed for this
purpose?
A. Amazon Inspector
B. Amazon Macie
C. Amazon GuardDuty
D. AWS Config
Answer: Amazon GuardDuty
Rationale: Amazon GuardDuty is a managed threat-detection service that
continuously analyzes AWS account, workload, and data activity to identify
suspicious or potentially malicious behavior.
, 2. A security team wants to identify vulnerabilities in Amazon EC2 instances,
container images, and supported workloads. Which AWS service should
they primarily use?
A. Amazon GuardDuty
B. Amazon Inspector
C. Amazon Macie
D. AWS Shield
Answer: Amazon Inspector
Rationale: Amazon Inspector is designed to automatically discover and assess
supported workloads for software vulnerabilities and unintended network
exposure.
3. An organization needs to discover sensitive information such as personally
identifiable information stored in Amazon S3. Which AWS service is the
best fit?
A. Amazon Inspector
B. Amazon GuardDuty
C. Amazon Macie
D. AWS WAF
Answer: Amazon Macie
Rationale: Amazon Macie uses machine learning and pattern matching to
discover and help protect sensitive data stored in Amazon S3, including
personally identifiable information.
4. Which statement best distinguishes Amazon GuardDuty from Amazon
Inspector?
A. GuardDuty detects threats, while Inspector identifies vulnerabilities and
exposure
B. GuardDuty encrypts data, while Inspector decrypts data
,C. GuardDuty classifies sensitive data, while Inspector manages encryption keys
D. GuardDuty manages IAM policies, while Inspector manages S3 buckets
Answer: GuardDuty detects threats, while Inspector identifies vulnerabilities
and exposure
Rationale: GuardDuty focuses on threat detection and suspicious activity,
whereas Inspector focuses on vulnerability management and security findings
for supported workloads.
5. A company receives a GuardDuty finding indicating that an EC2 instance
may be communicating with a known malicious IP address. What does this
finding represent?
A. A confirmed billing error
B. A potential security threat
C. An S3 data classification result
D. An EC2 performance metric
Answer: A potential security threat
Rationale: GuardDuty findings identify potentially malicious or suspicious
activity. A finding should be investigated and, where appropriate, remediated
using security response procedures.
6. Which AWS service is most directly associated with detecting sensitive data
in Amazon S3?
A. Amazon Macie
B. Amazon Inspector
C. Amazon GuardDuty
D. AWS Trusted Advisor
Answer: Amazon Macie
Rationale: Amazon Macie is specifically designed to discover and protect
sensitive data in Amazon S3 using automated data discovery and classification
capabilities.
, 7. An organization wants to determine whether EC2 instances are running
software versions with known Common Vulnerabilities and Exposures
(CVEs). Which service is most appropriate?
A. Amazon GuardDuty
B. Amazon Macie
C. Amazon Inspector
D. AWS CloudTrail
Answer: Amazon Inspector
Rationale: Amazon Inspector assesses supported workloads for known software
vulnerabilities, including vulnerabilities associated with published CVEs.
8. Which service would be most appropriate for identifying potentially
compromised AWS credentials?
A. Amazon GuardDuty
B. Amazon Macie
C. Amazon Inspector
D. Amazon S3 Glacier
Answer: Amazon GuardDuty
Rationale: GuardDuty analyzes relevant AWS activity and threat intelligence to
identify suspicious behavior, including activity that may indicate compromised
credentials.
9. A company wants to identify whether sensitive information is
unintentionally stored in an S3 bucket. Which service should the company
consider?
A. Amazon Inspector
B. Amazon Macie
C. Amazon GuardDuty
D. AWS Firewall Manager
Answer: Amazon Macie