Courseiva
Security and Compliance →easyMultiple Choice

CLF-C02 Security and Compliance Practice Question

Which AWS service provides automated security assessments of EC2 instances against a library of security best practices and common vulnerabilities?

⚠ Common exam trap

A common mix-up: candidates confuse AWS Security Hub (which aggregates findings) with the service that actually performs the vulnerability scan, leading them to pick Security Hub instead of Amazon Inspector.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Inspector

Amazon Inspector is the correct AWS service because it is specifically designed to perform automated security assessments of EC2 instances. It uses a library of rules mapped to common security best practices (e.g., CIS benchmarks) and common vulnerabilities (e.g., CVEs) to scan the instance's OS and network configuration, generating a detailed findings report.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor delivers real-time guidance to help you provision resources following AWS best practices, covering cost optimization, performance, service limits, and a limited set of security checks (e.g., permissive security group rules or MFA on the root account). It operates at the configuration and account level rather than deep inside running operating systems, so it cannot identify CVEs in installed applications or packages. Thus, while it might flag some risky settings, it is not a vulnerability scanner for software CVEs.

  • ✓

    Amazon Inspector

    Why this is correct

    Amazon Inspector is the correct answer because it is purpose-built to perform automated vulnerability discovery on EC2 instances and container images in Amazon ECR, referencing CVE databases to detect software vulnerabilities and also assessing network exposure for the workloads. It continuously monitors and can be scheduled on a recurring basis, generating findings that integrate with Security Hub and EventBridge for responsive actions. Its agentless and agent-based scanning options give broad coverage of the compute environment, which is precisely what the scenario requires.

  • ✗

    AWS Security Hub

    Why it's wrong here

    AWS Security Hub acts as a central security posture management and findings aggregation service, ingesting results from many sources and normalizing them into the AWS Security Finding Format (ASFF). It does not perform its own vulnerability scanning; instead, it relies on services like Amazon Inspector to generate the underlying CVE findings. Therefore, choosing Security Hub alone would not identify software vulnerabilities on EC2 instances or container images, making it incorrect for this question.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a service for tracking resource inventory and evaluating configurations against compliance rules, such as whether a security group allows SSH from anywhere or whether a bucket has versioning enabled. It continuously records changes to resource properties and compares them against managed or custom rules, but it does not inspect the runtime software stack against CVE databases or verify patch levels. Because the question asks about scanning for known software vulnerabilities, AWS Config is not the correct answer.

About these practice questions

This CLF-C02 question is part of Courseiva's 993-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.