CLF-C02 Security and Compliance Practice Question
A company's security team needs to receive near-real-time notifications whenever an IAM user in their AWS account performs an action that violates a defined baseline of expected behavior. Examples include launching an Amazon EC2 instance in an unauthorized AWS Region or modifying a security group to allow public SSH access from the internet. The solution must analyze continuous streams of AWS API activity to identify suspicious patterns and known malicious IP addresses. Which AWS service should the security team use?
⚠ Common exam trap
Candidates often confuse AWS CloudTrail's logging capability with GuardDuty's threat detection, assuming that simply recording API calls is sufficient for near-real-time security analysis, but CloudTrail lacks the built-in machine learning and threat intelligence needed to identify suspicious patterns or malicious IPs automatically.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon GuardDuty
Amazon GuardDuty is a threat detection service that continuously monitors AWS API activity, including CloudTrail management events, VPC Flow Logs, and DNS logs, to identify suspicious patterns and known malicious IP addresses. It uses machine learning and integrated threat intelligence to detect anomalous behavior such as launching EC2 instances in unauthorized regions or modifying security groups for public SSH access, and can deliver near-real-time notifications via Amazon EventBridge or SNS. This makes it the correct choice for analyzing continuous streams of API activity and alerting on violations of a defined baseline.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon GuardDuty
Why this is correct
Correct. Amazon GuardDuty uses threat intelligence and machine learning to analyze continuous streams of AWS API activity (via CloudTrail), VPC Flow Logs, and DNS logs. It detects suspicious patterns, unauthorized behavior, and known malicious IP addresses, and can send near-real-time alerts.
- ✗
AWS CloudTrail
Why it's wrong here
Incorrect. AWS CloudTrail records API activity for auditing, governance, and compliance purposes. It does not analyze the recorded events for threats or provide near-real-time notifications about suspicious patterns. It is a source of data for analysis, not a detection service itself.
When this WOULD be correct
A question asking for a service that provides a record of all API calls for auditing, compliance, or security analysis, without requiring real-time threat detection or behavioral analysis, would make CloudTrail correct.
- ✗
AWS Config
Why it's wrong here
Incorrect. AWS Config evaluates and records resource configuration changes against predefined rules, but it does not analyze API activity streams for suspicious patterns or known malicious IP addresses. It focuses on configuration compliance, not threat detection.
When this WOULD be correct
AWS Config would be correct if the question asked for a service to continuously monitor and evaluate changes to AWS resource configurations (e.g., security group rules) against compliance rules, and trigger notifications when configurations drift from defined baselines.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is a vulnerability management service that performs automated security assessments of AWS workloads, primarily EC2 instances and container images, to identify software vulnerabilities and unintended network exposure. It does not ingest or analyze AWS API activity, CloudTrail events, VPC Flow Logs, or DNS query logs, so it cannot detect suspicious IAM user behavior or alert on known malicious IP addresses in near real time. Inspector's assessments are typically periodic or on-demand scans, not continuous real-time threat detection streams.
When this WOULD be correct
A question asking: 'Which AWS service can automatically assess applications for vulnerabilities or deviations from best practices, such as open ports to the internet or insecure software versions?' would make Amazon Inspector the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓Amazon GuardDutyCorrect answer▾
Why this is correct
Correct. Amazon GuardDuty uses threat intelligence and machine learning to analyze continuous streams of AWS API activity (via CloudTrail), VPC Flow Logs, and DNS logs. It detects suspicious patterns, unauthorized behavior, and known malicious IP addresses, and can send near-real-time alerts.
✗AWS CloudTrailWrong answer — click to see why▾
Why this is wrong here
AWS CloudTrail records API activity but does not analyze streams for suspicious patterns or known malicious IP addresses in near-real-time; it lacks built-in threat detection and anomaly identification.
★ When this WOULD be the correct answer
A question asking for a service that provides a record of all API calls for auditing, compliance, or security analysis, without requiring real-time threat detection or behavioral analysis, would make CloudTrail correct.
Why candidates choose this
Candidates know CloudTrail logs API activity, so they may mistakenly think it can be used directly for threat detection, overlooking that it requires additional services like GuardDuty to analyze the logs for suspicious behavior.
✗AWS ConfigWrong answer — click to see why▾
Why this is wrong here
AWS Config is a service for evaluating resource configurations against desired policies, not for analyzing continuous streams of API activity or identifying malicious IP addresses. It does not provide near-real-time threat detection based on API behavior.
★ When this WOULD be the correct answer
AWS Config would be correct if the question asked for a service to continuously monitor and evaluate changes to AWS resource configurations (e.g., security group rules) against compliance rules, and trigger notifications when configurations drift from defined baselines.
Why candidates choose this
Candidates may confuse AWS Config's ability to detect configuration changes (like modified security groups) with the need for real-time threat detection, overlooking that GuardDuty is specifically designed for analyzing API activity and threat intelligence.
✗Amazon InspectorWrong answer — click to see why▾
Why this is wrong here
Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and unintended network exposure, not for analyzing real-time API activity streams to detect anomalous user behavior or known malicious IP addresses.
★ When this WOULD be the correct answer
A question asking: 'Which AWS service can automatically assess applications for vulnerabilities or deviations from best practices, such as open ports to the internet or insecure software versions?' would make Amazon Inspector the correct answer.
Why candidates choose this
Candidates may confuse 'security assessment' with 'threat detection' and think Inspector's vulnerability scanning includes monitoring API behavior, or they may misremember Inspector's capabilities as broader than they actually are.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
This CLF-C02 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.