Courseiva
Security and CompliancemediumMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A company's security team needs to investigate a potential security incident. They want to determine which IAM user launched a new, unauthorized Amazon EC2 instance two days ago. The team needs to see the exact timestamp, the source IP address, and the instance type that was launched. Which AWS service should the security team use to find this information?

⚠ Common exam trap

It's easy for candidates to confuse AWS Config (which tracks configuration changes) with CloudTrail (which tracks who made the change and when), leading them to pick Config because they think 'configuration change' includes user identity, but Config does not log the principal or source IP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS CloudTrail

AWS CloudTrail is the correct service because it records API activity in your AWS account, including the exact timestamp, source IP address, and details (such as instance type) for every RunInstances API call. This allows the security team to trace the unauthorized EC2 launch back to the specific IAM user who made the request, as CloudTrail logs include the user identity, request parameters, and response elements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Config

    Why it's wrong here

    AWS Config evaluates resource configurations against desired policies and records configuration changes, but it does not record the identity of the user who made the change. Therefore, it cannot provide the specific IAM user who launched the instance.

    When this WOULD be correct

    A question asking: 'Which AWS service can be used to track configuration changes to EC2 instances over time and evaluate compliance against rules?' AWS Config would be correct for auditing resource configurations and detecting drift.

  • AWS CloudTrail

    Why this is correct

    AWS CloudTrail records all API calls, including the caller identity, timestamp, source IP address, and request parameters. This enables the security team to determine which IAM user launched the EC2 instance, when, and from where.

  • Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a continuous security monitoring service that detects threats such as unusual API activity or compromised instances. However, it does not provide a comprehensive audit log of all API calls with caller identity and timestamps for historical investigation.

    When this WOULD be correct

    A security team needs to detect and alert on suspicious API activity in real time, such as an unusual number of failed login attempts or a known malicious IP address launching an EC2 instance. GuardDuty would be the correct service to generate findings for such threats.

  • AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor inspects your AWS environment and provides best-practice recommendations in areas like cost, performance, security, and fault tolerance. It does not log or track API calls, so it cannot show who launched a specific instance.

    When this WOULD be correct

    A security team wants to check if their AWS account follows security best practices, such as whether MFA is enabled on the root account, whether security groups allow unrestricted access, or whether S3 buckets are publicly accessible. In that scenario, AWS Trusted Advisor would be the correct service to use.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

AWS CloudTrailCorrect answer

Why this is correct

AWS CloudTrail records all API calls, including the caller identity, timestamp, source IP address, and request parameters. This enables the security team to determine which IAM user launched the EC2 instance, when, and from where.

AWS ConfigWrong answer — click to see why

Why this is wrong here

AWS Config records resource configuration changes and compliance, but does not capture detailed API call logs like timestamps, source IPs, or instance types for specific actions. It cannot provide the exact timestamp and source IP of the launch event.

★ When this WOULD be the correct answer

A question asking: 'Which AWS service can be used to track configuration changes to EC2 instances over time and evaluate compliance against rules?' AWS Config would be correct for auditing resource configurations and detecting drift.

Why candidates choose this

Candidates may confuse AWS Config's ability to track resource changes with CloudTrail's API activity logging, thinking Config records all details of who made changes, when, and from where.

Amazon GuardDutyWrong answer — click to see why

Why this is wrong here

Amazon GuardDuty is a threat detection service that monitors for malicious activity, but it does not provide a historical audit trail of API calls like launching an EC2 instance. It cannot show the exact timestamp, source IP, and instance type for a specific past event.

★ When this WOULD be the correct answer

A security team needs to detect and alert on suspicious API activity in real time, such as an unusual number of failed login attempts or a known malicious IP address launching an EC2 instance. GuardDuty would be the correct service to generate findings for such threats.

Why candidates choose this

Candidates may think GuardDuty can investigate past incidents because it detects threats, but they confuse its real-time detection capabilities with CloudTrail's historical logging of API calls.

AWS Trusted AdvisorWrong answer — click to see why

Why this is wrong here

AWS Trusted Advisor provides best practice checks and recommendations for cost optimization, performance, security, and fault tolerance, but it does not log or provide detailed event history like API calls or user actions. It cannot show the exact timestamp, source IP, or instance type for a specific EC2 launch.

★ When this WOULD be the correct answer

A security team wants to check if their AWS account follows security best practices, such as whether MFA is enabled on the root account, whether security groups allow unrestricted access, or whether S3 buckets are publicly accessible. In that scenario, AWS Trusted Advisor would be the correct service to use.

Why candidates choose this

Candidates may think Trusted Advisor can help investigate incidents because it has a security category, but they confuse its advisory role with the detailed auditing and logging capabilities of CloudTrail.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.