Courseiva
Security and Compliance →easyMultiple Choice

CLF-C02 Security and Compliance Practice Question

Which AWS service continuously assesses your AWS resources for security vulnerabilities, unintended network exposure, and deviations from security best practices?

⚠ Common exam trap

Candidates often confuse AWS Security Hub (a central dashboard for findings) with the actual scanning service, leading them to choose Security Hub instead of Inspector, even though Security Hub does not perform the underlying vulnerability assessments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Inspector

Amazon Inspector is a vulnerability management service that continuously scans AWS workloads for software vulnerabilities and unintended network exposure. It uses a combination of network reachability analysis and agent-based or agentless assessments to detect deviations from security best practices, such as missing patches or open ports to the internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Security Hub

    Why it's wrong here

    AWS Security Hub is a central security platform that aggregates findings from other AWS security services — including Amazon Inspector, GuardDuty, and IAM Access Analyzer — into a single dashboard. It applies security best-practice standards and enables automated response, but it does not execute any underlying vulnerability scans on its own. The actual detection of CVEs and network exposure is performed by Inspector and then forwarded to Security Hub. Depending on Security Hub for vulnerability scanning would miss the source data entirely.

  • ✓

    Amazon Inspector

    Why this is correct

    Amazon Inspector is the correct choice because it is purpose-built for continuously scanning EC2 instances and Amazon ECR container images for software vulnerabilities (CVEs) and unintended network exposure. It uses an agent-based or agentless assessment to gather package inventory and compare versions against known CVE databases, then produces a prioritized list of findings with severity and remediation guidance. Inspector also integrates with AWS Systems Manager and AWS Security Hub, making it the underlying service that performs the vulnerability assessment in the AWS environment.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a configuration recorder and compliance checker, not a vulnerability scanner. It tracks resource state changes and evaluates them against rules such as 'S3 bucket should have encryption enabled' or 'EC2 instances should use approved AMIs'. These rules detect configuration drift, not software flaws or CVEs. While Config can be used to detect non-compliant resources, it lacks the agent-based deep inspection required to identify exploitable vulnerabilities.

  • ✗

    Amazon Macie

    Why it's wrong here

    Amazon Macie is an ML-powered data security service that automatically discovers and classifies sensitive data like PII, PHI, and financial information stored in Amazon S3. It alerts on unauthorized access or potential data exfiltration, but its scope is data in object storage, not EC2 instances or container images. Macie cannot inspect the operating system packages, application libraries, or runtime environments that Inspector evaluates. Therefore it is unsuitable for the vulnerability assessment described.

About these practice questions

Courseiva writes every CLF-C02 question from scratch — 993 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.