Courseiva
Security and Compliance →mediumMultiple Choice

CLF-C02 Security and Compliance Practice Question

Which AWS service helps detect unusual API activity and potential security threats by analyzing AWS CloudTrail, VPC Flow Logs, and DNS logs?

⚠ Common exam trap

Test-takers frequently confuse AWS CloudTrail (the logging service) with GuardDuty (the threat detection service), assuming that simply enabling CloudTrail provides threat detection, when in fact CloudTrail only records events and requires a separate analysis engine like GuardDuty to identify malicious patterns.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon GuardDuty

Amazon GuardDuty is a threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to identify malicious activity. It analyzes data sources including AWS CloudTrail management and data events, VPC Flow Logs, and DNS logs to detect unusual API calls, potentially compromised instances, and other security threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Security Hub

    Why it's wrong here

    AWS Security Hub is a centralized security posture management and aggregation service that consolidates findings from multiple AWS services and third-party tools into a single dashboard. It does not perform its own log-based threat detection; instead, it ingests findings from services like GuardDuty to enable prioritization, remediation, and compliance checks. If a Security Hub finding shows a threat, the underlying detection engine is GuardDuty, not Security Hub, because Security Hub merely aggregates and correlates existing detections.

  • ✗

    Amazon Macie

    Why it's wrong here

    Amazon Macie is a data security and privacy service that uses machine learning and pattern matching to discover, classify, and protect sensitive data such as personally identifiable information (PII) stored in Amazon S3. It focuses on data classification and exposure, not on analyzing CloudTrail event logs, VPC Flow Logs, or DNS logs for malicious activity or unauthorized behavior. GuardDuty's threat detection is log-driven and covers workloads beyond S3, making Macie incorrect for the described role.

  • ✓

    Amazon GuardDuty

    Why this is correct

    Amazon GuardDuty is a fully managed threat detection service that continuously ingests and analyzes AWS CloudTrail event logs, VPC Flow Logs, and DNS query logs using machine learning, anomaly detection, and integrated threat intelligence feeds. It identifies suspicious activity such as compromised credentials, crypto mining, lateral movement, and reconnaissance, then produces security findings for downstream response. GuardDuty is specifically designed to detect threats from these log sources, making it the correct answer to the question's scenario.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail is an auditing and governance service that records API activity across AWS accounts, delivering raw event logs for compliance, security investigation, and troubleshooting. Its purpose is to provide a history of API calls, not to analyze those logs for anomalous or malicious behavior; analysis requires a separate detection mechanism. GuardDuty consumes CloudTrail logs as one of its data inputs to perform threat detection, so CloudTrail alone cannot serve the described detection role.

About these practice questions

Courseiva writes every CLF-C02 question from scratch — 993 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.