SCS-C02 Management and Security Governance Practice Question
A company wants to automate the enforcement of security best practices across all AWS accounts. Which AWS service provides pre-built rules for security compliance?
⚠ Common exam trap
It's easy for candidates to confuse AWS Config's managed rules (which evaluate resource configurations) with Security Hub's pre-built security compliance standards, but Security Hub is specifically designed for aggregating and automating security best practices across accounts, while Config is a configuration auditing tool without built-in security compliance frameworks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Security Hub
AWS Security Hub is the correct answer because it provides a comprehensive view of security alerts and compliance status across AWS accounts, and it includes pre-built security standards and automated compliance checks based on frameworks such as the AWS Foundational Security Best Practices (FSBP), CIS AWS Foundations Benchmark, and PCI DSS. These pre-built rules allow you to automate the enforcement of security best practices without manual configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is a threat detection service that uses machine learning and anomaly detection to identify suspicious activity such as unusual API calls or potential crypto-mining, but it does not enforce security best practices or run compliance checks against standards. It produces findings about potential threats rather than pass/fail compliance results, so it cannot automate the enforcement of a security best-practice framework.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is designed to assess workloads for software vulnerabilities and unintended network exposure by running vulnerability scans and network reachability tests. It does not evaluate an account's configuration against compliance standards like CIS or AWS Foundational Best Practices; instead, it focuses on host-level risks, making it insufficient for automating broad security best-practice enforcement.
- ✓
AWS Security Hub
Why this is correct
AWS Security Hub aggregates security findings from across AWS accounts and services and runs automated, continuous compliance checks against standards such as CIS AWS Foundations, AWS Foundational Best Practices, and PCI DSS. It provides a consolidated security score and actionable insights, enabling automated enforcement of security best practices. This integration and standard-based evaluation make it the correct service for the stated requirement.
- ✗
AWS Config
Why it's wrong here
AWS Config tracks resource configuration changes and allows you to evaluate resource settings against custom or managed rules for compliance, but it is not the primary service for aggregating and automating multi-standard security best-practice checks. Security Hub—not Config—centralizes those automated compliance checks and consolidates findings, so using Config alone would not fully automate the enforcement of security best practices.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.