Courseiva
Security and CompliancemediumMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A company wants to automatically detect potential security threats such as compromised credentials, unauthorized access attempts, and communication with known malicious IP addresses across its AWS environment. The company has enabled AWS CloudTrail, VPC Flow Logs, and DNS logs. Which AWS service should the company use to continuously analyze these logs and generate actionable security findings without requiring manual setup of data sources?

⚠ Common exam trap

A common mix-up: candidates confuse Amazon Inspector (which scans for vulnerabilities) with GuardDuty (which detects threats from logs), or assume AWS Config's compliance rules can detect security threats, when in fact Config only checks configuration drift, not log-based anomalies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Amazon GuardDuty

Amazon GuardDuty is a threat detection service that continuously analyzes AWS CloudTrail, VPC Flow Logs, and DNS logs using machine learning and anomaly detection to identify compromised credentials, unauthorized access, and communication with known malicious IP addresses. It operates without requiring manual setup of data sources because it automatically ingests these logs once enabled, generating actionable security findings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Amazon GuardDuty

    Why this is correct

    Amazon GuardDuty is a managed threat detection service that continuously ingests CloudTrail management events, VPC Flow Logs, and DNS query logs. It applies anomaly detection, machine learning, and integrated threat intelligence to uncover suspicious activity such as credential compromise, cryptocurrency mining, or unauthorized network behavior. Because its entire purpose is to analyze these telemetry sources and produce prioritized security findings, it directly matches the scenario's requirement.

  • AWS Config

    Why it's wrong here

    AWS Config records the configuration state of AWS resources over time and evaluates that state against compliance rules for governance and auditing. It can flag a resource as noncompliant when its configuration deviates from a policy, such as an open security group, but it does not inspect log streams for signs of an active attack. It is therefore inaccurate to use it as a threat detector; it is a configuration history and compliance assessment service.

    When this WOULD be correct

    A company needs to evaluate resource configurations for compliance with internal policies (e.g., ensuring S3 buckets are not publicly accessible) and track configuration changes over time. AWS Config would be the correct service to continuously monitor and record resource configurations and evaluate them against desired rules.

  • AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor performs account-level best-practice checks and gives recommendations across categories like cost optimization, service quotas, and security. It reviews existing configurations, such as whether MFA is enabled or a bucket is publicly accessible, but does not monitor logs in real time nor detect new threats. Its output is advisory rather than investigative, so it cannot produce the kind of continuous threat findings described in the question.

    When this WOULD be correct

    A company wants to review its AWS account against AWS best practices for security, cost, performance, and fault tolerance, and receive recommendations for improvement without manual setup. AWS Trusted Advisor would be the correct service to provide these checks and recommendations.

  • Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that scans EC2 instances and container images for software vulnerabilities and unintended network exposure. It does not analyze CloudTrail, VPC Flow Logs, or DNS logs for threat detection.

    When this WOULD be correct

    A company wants to automatically assess EC2 instances for common vulnerabilities and exposures (CVEs) and network reachability issues, and needs a service that integrates with AWS Systems Manager to perform agent-based scans without manual setup.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

Amazon GuardDutyCorrect answer

Why this is correct

Amazon GuardDuty is a managed threat detection service that continuously ingests CloudTrail management events, VPC Flow Logs, and DNS query logs. It applies anomaly detection, machine learning, and integrated threat intelligence to uncover suspicious activity such as credential compromise, cryptocurrency mining, or unauthorized network behavior. Because its entire purpose is to analyze these telemetry sources and produce prioritized security findings, it directly matches the scenario's requirement.

AWS ConfigWrong answer — click to see why

Why this is wrong here

AWS Config is designed for resource inventory, configuration history, and compliance auditing, not for analyzing logs to detect security threats like compromised credentials or malicious IPs. It does not continuously analyze CloudTrail, VPC Flow Logs, or DNS logs for threat detection.

★ When this WOULD be the correct answer

A company needs to evaluate resource configurations for compliance with internal policies (e.g., ensuring S3 buckets are not publicly accessible) and track configuration changes over time. AWS Config would be the correct service to continuously monitor and record resource configurations and evaluate them against desired rules.

Why candidates choose this

Candidates may confuse AWS Config's ability to detect configuration changes with threat detection, or assume that any security-related service can analyze logs for threats, overlooking the specialized purpose of GuardDuty.

AWS Trusted AdvisorWrong answer — click to see why

Why this is wrong here

AWS Trusted Advisor provides best-practice recommendations for cost optimization, performance, security, and fault tolerance, but it does not continuously analyze logs like CloudTrail, VPC Flow Logs, and DNS logs to detect threats such as compromised credentials or malicious IPs. It relies on periodic checks of AWS configurations, not real-time log analysis.

★ When this WOULD be the correct answer

A company wants to review its AWS account against AWS best practices for security, cost, performance, and fault tolerance, and receive recommendations for improvement without manual setup. AWS Trusted Advisor would be the correct service to provide these checks and recommendations.

Why candidates choose this

Candidates may confuse Trusted Advisor's security checks (e.g., for open ports or IAM use) with threat detection, assuming it can analyze logs for security threats, but it does not perform log analysis or generate findings from CloudTrail, VPC Flow Logs, or DNS logs.

Amazon InspectorWrong answer — click to see why

Why this is wrong here

Amazon Inspector is designed for vulnerability management, scanning workloads for software vulnerabilities and unintended network exposure, not for analyzing CloudTrail, VPC Flow Logs, or DNS logs to detect threats like compromised credentials or malicious IP communications.

★ When this WOULD be the correct answer

A company wants to automatically assess EC2 instances for common vulnerabilities and exposures (CVEs) and network reachability issues, and needs a service that integrates with AWS Systems Manager to perform agent-based scans without manual setup.

Why candidates choose this

Candidates may confuse Inspector's security scanning capabilities with threat detection, assuming it can analyze logs for security threats, but Inspector focuses on host-level vulnerabilities rather than log-based threat detection.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.