Courseiva
Security and Compliance →mediumMultiple Choice

CLF-C02 Security and Compliance Practice Question

A security team wants to automatically detect unusual activity in their AWS account, such as EC2 instances communicating with known malicious IP addresses, unusual API calls indicating credential compromise, or cryptocurrency mining activity. Which AWS service uses machine learning to detect these threats?

⚠ Common exam trap

A common mix-up: candidates confuse Amazon GuardDuty with Amazon Inspector or AWS Security Hub, mistakenly thinking that vulnerability scanning or centralized security findings equate to active threat detection, whereas GuardDuty is the only service that continuously monitors for malicious behavior using machine learning and threat intelligence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon GuardDuty

Amazon GuardDuty is a threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to continuously monitor for malicious or unauthorized behavior in AWS accounts and workloads. It specifically analyzes VPC Flow Logs, AWS CloudTrail management and data events, and DNS logs to detect patterns such as EC2 instances communicating with known malicious IP addresses, unusual API calls indicative of credential compromise, and cryptocurrency mining activity. This makes it the correct choice for the described use case.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities, unintended network exposure, and deviations from security best practices. It performs agent-based and agentless assessments of EC2 instances and container images, producing a list of findings about CVEs, missing patches, and overly permissive network configurations. Inspector does not continuously analyze streaming logs or apply threat intelligence feeds to detect real-time malicious behavior like crypto mining, credential theft, or command-and-control communication; those activities are the domain of a dedicated threat detection service.

  • ✗

    AWS Security Hub

    Why it's wrong here

    AWS Security Hub is a cloud security posture management (CSPM) service that aggregates, normalizes, and prioritizes security findings from multiple AWS services (such as GuardDuty, Inspector, and Macie) and third-party tools into a single compliance and remediation dashboard. It provides a centralized view and enables automated response workflows, but it does not perform its own detection by analyzing raw logs or applying threat intelligence. Security Hub's role is to collect and correlate findings—it relies on GuardDuty and other detectors to generate the underlying threat alerts, making it a consumer, not a producer, of threat detection.

  • ✓

    Amazon GuardDuty

    Why this is correct

    Amazon GuardDuty is a continuous, intelligent threat detection service that analyzes a stream of AWS foundational data sources—including AWS CloudTrail management and data events, VPC Flow Logs, and DNS query logs—using integrated machine learning, anomaly detection, and curated threat intelligence feeds. It detects a wide range of threats such as compromised EC2 instances exhibiting crypto mining behavior, unusual API calls from suspicious IPs, and communication with known malicious domains or command-and-control servers. When GuardDuty identifies a finding, it raises an alert in the console, optionally publishes to Amazon EventBridge or CloudWatch, and integrates with AWS Security Hub for centralized visibility—making it the correct answer for detecting this type of activity.

  • ✗

    Amazon Macie

    Why it's wrong here

    Amazon Macie is a managed data security service that uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data such as personally identifiable information (PII) or financial data stored in Amazon S3. While Macie does leverage ML, its focus is on data classification, data privacy, and compliance—not on analyzing behavioral telemetry like VPC Flow Logs or DNS query logs to identify adversarial activity. The question describes a threat where an EC2 instance is communicating with a known malicious IP and showing signs of crypto mining, which is outside Macie's scope because Macie does not inspect network traffic or API activity for threat detection.

About these practice questions

This CLF-C02 question is part of Courseiva's 993-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CLF-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which AWS service helps detect unusual API activity and potential security threats by analyzing AWS CloudTrail, VPC Flow Logs, and DNS logs?

medium
  • A.AWS Security Hub
  • B.Amazon Macie
  • ✓ C.Amazon GuardDuty
  • D.AWS CloudTrail

Why C: Amazon GuardDuty is a threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to identify malicious activity. It analyzes data sources including AWS CloudTrail management and data events, VPC Flow Logs, and DNS logs to detect unusual API calls, potentially compromised instances, and other security threats.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.