CLF-C02 Security and Compliance Practice Question
After GuardDuty generates a security finding about potentially compromised EC2 instances, a security analyst needs to investigate the full context of the threat — understanding which users, IPs, and resources were involved and how they relate to each other. Which AWS service helps investigators analyse and visualise these relationships?
⚠ Common exam trap
Test-takers frequently confuse Security Hub's aggregation and prioritization of findings with Detective's investigative and visualization capabilities, leading them to choose Security Hub when the question specifically asks for analyzing and visualizing relationships between users, IPs, and resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Detective
Amazon Detective is designed specifically to analyze, investigate, and quickly identify the root cause of security findings by automatically collecting log data from AWS resources and building a graph model that shows relationships between users, IPs, and resources. When GuardDuty generates a finding about a potentially compromised EC2 instance, Detective can ingest that finding and provide a visual, interactive view of the entire resource interaction timeline, including network connections, API calls, and user activity, enabling investigators to understand the full context of the threat.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that uses machine learning and threat intelligence to generate security findings for suspicious API calls, network connections, or credentials. While Detective consumes GuardDuty findings as input, GuardDuty itself does not provide the investigative graph, entity relationship mapping, or historical context needed to trace the full scope of an incident; it answers 'what is suspicious?' rather than 'how did the attack happen?'
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail records a raw history of API activity, including user identity, event time, source IP, and request/response details, which analysts could manually query. But CloudTrail events are flat, time-ordered logs; they do not automatically correlate related entities or produce interactive visualizations of resource relationships, role assumptions, and lateral movement. Detective ingests CloudTrail logs and builds that graph, turning raw log data into a structured investigation workflow.
- ✓
Amazon Detective
Why this is correct
Detective analyses security data from CloudTrail, VPC Flow Logs, and GuardDuty to automatically build a behaviour graph. Analysts use the visual interface to trace the timeline of an incident, identify affected resources, and understand attacker lateral movement.
- ✗
AWS Security Hub
Why it's wrong here
AWS Security Hub is a central security posture management service that aggregates and normalizes findings from GuardDuty, Inspector, Macie, and third-party tools, producing dashboards and compliance scores. However, it does not build a temporal behavior graph or visually map relationships between entities; it shows a consolidated list of findings, not an investigative timeline of how an attacker moved through resources.
Go deeper
Related to this question
About these practice questions
This CLF-C02 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.