CLF-C02 Security and Compliance Practice Question
Which AWS service helps detect unusual API activity and potential security threats by analyzing AWS CloudTrail, VPC Flow Logs, and DNS logs?
⚠ Common exam trap
Test-takers frequently confuse AWS CloudTrail (the logging service) with GuardDuty (the threat detection service), assuming that simply enabling CloudTrail provides threat detection, when in fact CloudTrail only records events and requires a separate analysis engine like GuardDuty to identify malicious patterns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon GuardDuty
Amazon GuardDuty is a threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to identify malicious activity. It analyzes data sources including AWS CloudTrail management and data events, VPC Flow Logs, and DNS logs to detect unusual API calls, potentially compromised instances, and other security threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Security Hub
Why it's wrong here
AWS Security Hub is a centralized security posture management and aggregation service that consolidates findings from multiple AWS services and third-party tools into a single dashboard. It does not perform its own log-based threat detection; instead, it ingests findings from services like GuardDuty to enable prioritization, remediation, and compliance checks. If a Security Hub finding shows a threat, the underlying detection engine is GuardDuty, not Security Hub, because Security Hub merely aggregates and correlates existing detections.
- ✗
Amazon Macie
Why it's wrong here
Amazon Macie is a data security and privacy service that uses machine learning and pattern matching to discover, classify, and protect sensitive data such as personally identifiable information (PII) stored in Amazon S3. It focuses on data classification and exposure, not on analyzing CloudTrail event logs, VPC Flow Logs, or DNS logs for malicious activity or unauthorized behavior. GuardDuty's threat detection is log-driven and covers workloads beyond S3, making Macie incorrect for the described role.
- ✓
Amazon GuardDuty
Why this is correct
Amazon GuardDuty is a fully managed threat detection service that continuously ingests and analyzes AWS CloudTrail event logs, VPC Flow Logs, and DNS query logs using machine learning, anomaly detection, and integrated threat intelligence feeds. It identifies suspicious activity such as compromised credentials, crypto mining, lateral movement, and reconnaissance, then produces security findings for downstream response. GuardDuty is specifically designed to detect threats from these log sources, making it the correct answer to the question's scenario.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail is an auditing and governance service that records API activity across AWS accounts, delivering raw event logs for compliance, security investigation, and troubleshooting. Its purpose is to provide a history of API calls, not to analyze those logs for anomalous or malicious behavior; analysis requires a separate detection mechanism. GuardDuty consumes CloudTrail logs as one of its data inputs to perform threat detection, so CloudTrail alone cannot serve the described detection role.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CLF-C02 question from scratch — 993 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.