CLF-C02 Security and Compliance Practice Question
A company runs a fleet of Amazon EC2 instances that host a customer-facing web application. The security team wants to automatically identify software vulnerabilities, such as missing patches and common vulnerabilities and exposures (CVEs), in the operating system and applications running on these instances. The team also needs visibility into unintended network accessibility, such as instances with ports open to the internet. The solution must be natively integrated with AWS and should provide findings that can be viewed in a central dashboard. Which AWS service should the security team use?
⚠ Common exam trap
A common mix-up: candidates confuse Amazon GuardDuty (threat detection) with Amazon Inspector (vulnerability scanning), or assume AWS Security Hub performs the scanning itself rather than aggregating findings from other services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Inspector
Amazon Inspector is the correct choice because it is a vulnerability management service that automatically scans EC2 instances for software vulnerabilities (missing patches, CVEs) and unintended network accessibility (e.g., open ports to the internet). It is natively integrated with AWS and provides findings in a central dashboard via the AWS Management Console or AWS Security Hub. This directly matches the security team's requirements for automated identification of OS/application vulnerabilities and network exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a managed threat detection service that consumes AWS CloudTrail event logs, VPC Flow Logs, and Route 53 DNS query logs, then uses machine learning, anomaly detection, and threat intelligence to identify suspicious activity such as crypto-mining, credential theft, or malicious IP connections. It operates passively on network and account telemetry rather than by inspecting the EC2 instance's filesystem, running processes, or installed package manifests. For this reason it complements rather than replaces a CVE/patch scanning tool, because it won't report missing OS updates or known software vulnerabilities by itself.
When this WOULD be correct
A company needs continuous threat detection for malicious activity and unauthorized behavior across AWS accounts and workloads, using VPC Flow Logs, DNS logs, and CloudTrail events, with findings in a central dashboard.
- ✓
Amazon Inspector
Why this is correct
Amazon Inspector is a vulnerability management service that automatically discovers EC2 instances and delivers software vulnerability (CVE) findings by scanning the operating system and installed packages, using data from AWS Systems Manager. It also maps network reachability of the instance to determine which vulnerabilities are actually exposed to the internet or a VPC, and assigns a severity and risk score for each finding. This allows the security team to prioritize patching based on real attack surface rather than just patch status.
- ✗
AWS Security Hub
Why it's wrong here
Incorrect. Security Hub provides a centralized view of security alerts and compliance status across multiple AWS services, but it does not perform vulnerability scanning itself. It would consume findings from Amazon Inspector, not replace it.
When this WOULD be correct
A company already uses multiple AWS security services (e.g., GuardDuty, Inspector, Macie) and needs a single dashboard to view and prioritize all security findings across accounts. Security Hub would be the correct answer for centralizing and correlating findings from these services.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor is an advisory tool that evaluates AWS accounts against a curated set of best practices across cost optimization, performance, security, fault tolerance, and service limits. Its security checks are config-level controls, for example flagging security groups that permit unrestricted SSH/RDP or accounts lacking MFA, but it never authenticates into the installed OS or enumerates application package versions. Consequently, it cannot detect a CVE in a package installed on a fleet of EC2 instances, so it is not the right service for this requirement.
When this WOULD be correct
A company wants a service that automatically checks AWS resource configurations against AWS best practices and provides recommendations to optimize costs, improve performance, and close security gaps (e.g., unused resources, IAM key rotation). The team needs a single dashboard for these checks without deep vulnerability scanning.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓Amazon InspectorCorrect answer▾
Why this is correct
Amazon Inspector is a vulnerability management service that automatically discovers EC2 instances and delivers software vulnerability (CVE) findings by scanning the operating system and installed packages, using data from AWS Systems Manager. It also maps network reachability of the instance to determine which vulnerabilities are actually exposed to the internet or a VPC, and assigns a severity and risk score for each finding. This allows the security team to prioritize patching based on real attack surface rather than just patch status.
✗Amazon GuardDutyWrong answer — click to see why▾
Why this is wrong here
Amazon GuardDuty is a threat detection service that identifies malicious activity and unauthorized behavior using network and account logs, but it does not perform vulnerability assessments for missing patches or CVEs in OS and applications.
★ When this WOULD be the correct answer
A company needs continuous threat detection for malicious activity and unauthorized behavior across AWS accounts and workloads, using VPC Flow Logs, DNS logs, and CloudTrail events, with findings in a central dashboard.
Why candidates choose this
Candidates may confuse GuardDuty's threat detection with vulnerability scanning, or assume it covers software vulnerabilities because it detects some CVE-based threats via network patterns.
✗AWS Security HubWrong answer — click to see why▾
Why this is wrong here
AWS Security Hub aggregates and prioritizes security findings from multiple AWS services (like Inspector, GuardDuty) but does not itself perform vulnerability scanning or network accessibility checks. The question requires a service that directly identifies CVEs and open ports, which is Inspector's function.
★ When this WOULD be the correct answer
A company already uses multiple AWS security services (e.g., GuardDuty, Inspector, Macie) and needs a single dashboard to view and prioritize all security findings across accounts. Security Hub would be the correct answer for centralizing and correlating findings from these services.
Why candidates choose this
Candidates may confuse Security Hub's central dashboard capability with the actual scanning functionality, assuming it can perform vulnerability assessments itself rather than just aggregating results from other services.
✗AWS Trusted AdvisorWrong answer — click to see why▾
Why this is wrong here
AWS Trusted Advisor provides best-practice recommendations across cost, performance, security, and fault tolerance, but it does not perform automated vulnerability scanning for missing patches or CVEs in EC2 instances. It also lacks a central findings dashboard for software vulnerabilities.
★ When this WOULD be the correct answer
A company wants a service that automatically checks AWS resource configurations against AWS best practices and provides recommendations to optimize costs, improve performance, and close security gaps (e.g., unused resources, IAM key rotation). The team needs a single dashboard for these checks without deep vulnerability scanning.
Why candidates choose this
Candidates may confuse Trusted Advisor's security checks (like open ports) with vulnerability scanning, or assume its broad recommendations cover software-level vulnerabilities, not realizing it focuses on infrastructure configuration rather than OS/application CVEs.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
Courseiva writes every CLF-C02 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.