CV0-004 Operations and Support Practice Question
A cloud operations team manages a multi-account AWS environment with AWS Organizations. They need a centralized, near-real-time view of security findings across all accounts and want the ability to automatically suppress findings that match approved exceptions. Which service should they use to aggregate and manage these findings?
⚠ Common exam trap
It's easy for candidates to confuse configuration compliance aggregation from AWS Config with runtime security findings aggregation, which are handled by different services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Security Hub with the organization-wide aggregation feature enabled
Security Hub is designed to aggregate and normalize findings from multiple AWS security services across an organization, and its automation rules and suppression filters allow approved exceptions to be muted. This combination of centralized aggregation with automated suppression matches the operational requirement precisely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config with a central aggregator in the delegated administrator account
Why it's wrong here
AWS Config aggregators collect configuration and compliance data across accounts, which supports governance and drift detection. However, Config records resource configuration state rather than consolidating runtime security findings from detection services. It lacks native suppression of individual security findings, so it does not meet the near-real-time findings management need.
- ✓
AWS Security Hub with the organization-wide aggregation feature enabled
Why this is correct
Security Hub supports designating a delegated administrator account and aggregating findings from all member accounts into a single pane. It integrates findings from services like GuardDuty and Inspector and supports automation rules and suppression filters to mute findings matching approved exceptions, which directly satisfies the centralized visibility and suppression requirements described.
- ✗
Amazon Detective with cross-account data ingestion from member accounts
Why it's wrong here
Detective helps investigate and analyze security findings by building behavior graphs from log data, but it is an investigation tool rather than an aggregation and suppression platform. It does not provide a centralized findings inbox with automated suppression rules, so it cannot fulfill the requirement to manage and mute findings across all accounts.
- ✗
AWS Trusted Advisor with organizational view enabled in the management account
Why it's wrong here
Trusted Advisor provides best-practice checks across cost, security, fault tolerance, and service limits, but it is not a findings aggregation platform for security detections from other services. It cannot ingest GuardDuty or Inspector findings, and it does not provide automated suppression of individual findings based on exception criteria, so it fails the suppression requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.