Courseiva
Security and Compliance →mediumMultiple Select

CLF-C02 Security and Compliance Practice Question

A security team wants to strengthen the detection and investigation posture of its AWS environment without deploying third-party tooling. The team needs a managed service that continuously monitors for malicious activity and unauthorized behavior using machine learning and threat intelligence, and it needs a service that aggregates and organizes security findings from multiple AWS services into a single console. (Choose two.)

⚠ Common exam trap

The trap here is substituting logging or vulnerability scanning for threat detection and findings aggregation, which are distinct capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon GuardDuty

GuardDuty provides the continuous, machine-learning-driven threat detection layer by analyzing account and network activity, while Security Hub provides the aggregation layer that normalizes and displays findings from GuardDuty and other AWS security services. Together they deliver detection and centralized investigation without third-party tools.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    Trusted Advisor inspects an account against best-practice checks in categories like cost, performance, and security, but it does not perform continuous threat detection with machine learning or aggregate findings from other security services. It offers recommendations rather than an investigation console.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    CloudTrail records API activity for auditing and governance, which is valuable evidence, but it does not analyze that activity for threats or consolidate findings from other services into a unified dashboard. It is a logging service, not a detection or aggregation service.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Inspector is a vulnerability management service that scans EC2 instances, container images, and Lambda functions for software vulnerabilities and unintended network exposure. It does not continuously detect active malicious behavior using threat intelligence, nor does it serve as a findings aggregation console.

  • ✓

    Amazon GuardDuty

    Why this is correct

    GuardDuty is the managed threat detection service that continuously analyzes CloudTrail management events, VPC Flow Logs, and DNS logs, applying machine learning and integrated threat intelligence. It surfaces findings such as compromised instances or unusual API calls without requiring agents or infrastructure to manage, matching the detection need in the scenario.

  • ✓

    AWS Security Hub

    Why this is correct

    Security Hub collects findings from services such as GuardDuty, Amazon Inspector, and AWS Config, normalizes them to the AWS Security Finding Format, and presents them alongside compliance checks in one place. That aggregation and prioritization is exactly the single-console requirement described by the security team.

About these practice questions

Courseiva writes every CLF-C02 question from scratch — 993 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.