Courseiva
Security and CompliancemediumMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A company's security team is concerned about the risk of compromised Amazon EC2 instances being used for crypto-mining activities. They want a managed AWS service that can automatically detect unusual outbound network traffic patterns that are characteristic of crypto-mining, without requiring the installation of any agents on the instances. The team needs continuous monitoring and the ability to receive findings that include details about the suspicious activity. Which AWS service should the security team use?

⚠ Common exam trap

Candidates often confuse Amazon Detective's investigative capabilities with proactive detection, but Detective requires existing findings to analyze and does not perform continuous monitoring for crypto-mining traffic patterns on its own.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Amazon GuardDuty

Amazon GuardDuty is a managed threat detection service that uses machine learning and integrated threat intelligence to continuously monitor for malicious activity, including unusual outbound network traffic patterns like those associated with crypto-mining. It operates at the AWS account and VPC level by analyzing DNS logs, VPC Flow Logs, and CloudTrail events, and it does not require any agents to be installed on EC2 instances. When suspicious activity is detected, GuardDuty generates detailed findings that include information about the affected resource, the type of threat, and recommended remediation steps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Amazon GuardDuty

    Why this is correct

    Amazon GuardDuty is a continuous, agentless threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to monitor VPC Flow Logs, DNS query logs, and AWS CloudTrail management events. It can detect crypto-mining behavior by identifying anomalous traffic patterns, such as connections to known cryptocurrency mining pools or unusually high outbound traffic, without requiring any software agents on your EC2 instances. Findings are automatically sent to Amazon EventBridge, enabling automated responses.

  • Amazon Macie

    Why it's wrong here

    Amazon Macie is a data security service that uses machine learning and pattern matching to discover, classify, and protect sensitive data, primarily in Amazon S3 buckets, such as personally identifiable information (PII) or proprietary data. It does not analyze network traffic, DNS queries, or API activity for signs of crypto-mining, because its focus is on data visibility and compliance, not on infrastructure-level threat detection. Therefore, Macie would not be the appropriate tool for identifying crypto-mining attacks.

    When this WOULD be correct

    A company needs to automatically identify and classify sensitive data stored in Amazon S3, such as personally identifiable information (PII) or financial records, to meet compliance requirements.

  • AWS Config

    Why it's wrong here

    AWS Config is a configuration assessment and compliance service that records the state of AWS resources, tracks configuration changes, and evaluates resource settings against desired policies or rules. It can flag misconfigurations like overly permissive security groups or improper S3 bucket policies, but it does not perform real-time threat detection, nor does it analyze network traffic or logs for suspicious activity such as crypto-mining. AWS Config is designed for governance and auditing, not for detecting malicious behavior.

    When this WOULD be correct

    A company needs to ensure that all EC2 instances have specific security groups attached and that no security group allows unrestricted inbound SSH access. They want continuous monitoring and compliance alerts when configurations drift from the desired state.

  • Amazon Detective

    Why it's wrong here

    Incorrect. Amazon Detective helps you analyze and investigate security findings by automatically collecting and correlating log data from multiple AWS sources. However, it does not proactively detect threats; it is used after a finding is surfaced by another service like GuardDuty.

    When this WOULD be correct

    A company has already detected suspicious activity (e.g., via GuardDuty) and needs to perform in-depth forensic investigation to understand the scope and root cause of a potential compromise. Amazon Detective would be the correct choice for this analysis.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

Amazon GuardDutyCorrect answer

Why this is correct

Amazon GuardDuty is a continuous, agentless threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to monitor VPC Flow Logs, DNS query logs, and AWS CloudTrail management events. It can detect crypto-mining behavior by identifying anomalous traffic patterns, such as connections to known cryptocurrency mining pools or unusually high outbound traffic, without requiring any software agents on your EC2 instances. Findings are automatically sent to Amazon EventBridge, enabling automated responses.

Amazon MacieWrong answer — click to see why

Why this is wrong here

Amazon Macie is designed for discovering and protecting sensitive data (e.g., PII, credentials) in S3, not for detecting network-based threats like crypto-mining traffic from EC2 instances.

★ When this WOULD be the correct answer

A company needs to automatically identify and classify sensitive data stored in Amazon S3, such as personally identifiable information (PII) or financial records, to meet compliance requirements.

Why candidates choose this

Candidates may confuse Macie's 'anomaly detection' and 'security' focus with network threat detection, or assume it covers EC2 because it's a security service.

AWS ConfigWrong answer — click to see why

Why this is wrong here

AWS Config is a service for evaluating resource configurations against desired policies, not for detecting network traffic patterns or security threats like crypto-mining. It does not analyze outbound network traffic for suspicious activity.

★ When this WOULD be the correct answer

A company needs to ensure that all EC2 instances have specific security groups attached and that no security group allows unrestricted inbound SSH access. They want continuous monitoring and compliance alerts when configurations drift from the desired state.

Why candidates choose this

Candidates may confuse AWS Config's compliance monitoring with security threat detection, thinking it can monitor network traffic patterns when it actually only tracks configuration changes.

Amazon DetectiveWrong answer — click to see why

Why this is wrong here

Amazon Detective analyzes and visualizes security data to investigate the root cause of findings, but it does not automatically detect unusual outbound traffic patterns for crypto-mining without agents; it relies on data from other services like GuardDuty.

★ When this WOULD be the correct answer

A company has already detected suspicious activity (e.g., via GuardDuty) and needs to perform in-depth forensic investigation to understand the scope and root cause of a potential compromise. Amazon Detective would be the correct choice for this analysis.

Why candidates choose this

Candidates may confuse Detective's investigative capabilities with GuardDuty's threat detection, assuming Detective can also detect threats proactively, when in fact it is designed for post-detection analysis.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every CLF-C02 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.