Asterrr's Handbook

Domain 1 · Detection

16% of the exam. Choosing what to watch, where the logs land, how findings become alerts, and why a monitoring pipeline goes quiet.

Domain 1 questions give you an account or an organization and ask how you would know something bad happened: which service detects it, which log proves it, where the evidence is stored, and who gets paged. A growing share of questions describe monitoring that already exists but stopped working, and ask for the one misconfiguration.

TaskWhat it's really askingPages
1.1 Monitoring and alertingWhich managed detector covers the threat, how findings are aggregated across accounts, and how they turn into alarms, notifications and dashboardsThreat detection, Security findings hub, Alerting and dashboards
1.2 LoggingWhich log source answers the question, how to collect it org-wide into a separate account, and how to query or normalize itLogging strategy, Log analysis
1.3 TroubleshootingMissing logs, silent alarms, rules that never fire, agents that don't ship, and the permission or key policy behind eachTroubleshooting monitoring

What connects Domain 1 to the rest of the exam:

Building your own detector

Options that write a Lambda function to parse CloudTrail for "suspicious" behaviour, or run an IDS on EC2 to catch crypto-mining, are rarely right. If a managed service already detects the threat (GuardDuty for threats, Macie for sensitive data, Inspector for vulnerabilities), the answer is to turn it on everywhere through a delegated administrator and route its findings.