CLF-C02 Security and Compliance Practice Question
A security team wants to automatically scan their Amazon EC2 instances for known software vulnerabilities (CVEs) and assess whether any instances have unintended network access paths open. Which AWS service performs these automated security assessments?
⚠ Common exam trap
Candidates often confuse Amazon GuardDuty's threat detection with vulnerability scanning, but GuardDuty focuses on behavioral anomalies and known malicious IPs, not on identifying software CVEs or network configuration exposures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Inspector
Amazon Inspector is the correct service because it is specifically designed to perform automated vulnerability scans (including CVEs) and network reachability assessments on EC2 instances. It uses a combination of AWS security best practices and common vulnerability databases to identify software vulnerabilities and unintended network access paths, such as open ports or overly permissive security groups.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that consumes VPC Flow Logs, AWS CloudTrail management and data events, and DNS query logs. It applies machine learning and threat intelligence to identify active threats such as compromised credentials, cryptocurrency mining, or malicious API activity, rather than inspecting operating system packages or comparing installed versions to a CVE database. GuardDuty's findings point to suspicious behavior, not to missing security patches, so it cannot deliver the automated software vulnerability assessment described.
- ✗
Amazon Macie
Why it's wrong here
Amazon Macie is a data security service focused exclusively on protecting sensitive data stored in Amazon S3. Using managed data identifiers and machine learning, it identifies content such as personally identifiable information, protected health information, or financial credentials, and it monitors for types of access to those S3 objects. Macie has no mechanism to examine packages inside an EC2 instance's guest OS or assess network reachability at the instance level, so it cannot perform software vulnerability scanning. This makes it unsuitable for the required EC2 security assessment.
- ✓
Amazon Inspector
Why this is correct
Amazon Inspector is the native AWS vulnerability management service. It continuously scans EC2 instances (and optionally workloads in Amazon ECR and AWS Lambda) for software vulnerabilities and unintended network exposure. Agent-based or agentless assessments identify missing patches and CVEs using the Common Vulnerability Scoring System, then rank findings by severity and risk score. This matches the required automated security assessment of an EC2 instance's software vulnerabilities and network reachability.
- ✗
AWS Shield
Why it's wrong here
AWS Shield is a managed DDoS mitigation service that always-on monitors network traffic and applies inline mitigation at AWS edge locations. Shield Advanced offers enhanced detection, response, and cost protection for DDoS events, but the service only protects availability at layers 3 and 4 (and some layer 7 cases with Advanced). It does not inspect filesystem content, installed packages, or CVE data on EC2 instances. Therefore, while Shield is a security service, it is not the correct tool for identifying software vulnerabilities or network reachability issues.
Go deeper
Related to this question
About these practice questions
One of 993 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.