CV0-004 Security Practice Question
A company's compliance team must provide evidence that their cloud environment meets PCI DSS requirements. Which AWS service can aggregate security findings and automate compliance checks?
⚠ Common exam trap
CV0-004 often tests the confusion between AWS Config (configuration recording) and Security Hub (aggregation and compliance), expecting candidates to know that Security Hub is the aggregator for compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Security Hub
AWS Security Hub aggregates security findings from multiple AWS services and third-party tools, and it can run automated compliance checks against standards like PCI DSS. It provides a central dashboard for security posture. AWS Config records resource configurations but does not aggregate findings or automate compliance checks in the same way. Amazon Inspector is for vulnerability assessment, and CloudTrail logs API activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config
Why it's wrong here
AWS Config records resource configuration changes and evaluates them against rules, but it does not aggregate findings from GuardDuty, Inspector or Security Hub into a compliance posture. It is tempting because Config conformance packs do automate checks against PCI DSS, yet the aggregation requirement points to Security Hub.
- ✓
AWS Security Hub
Why this is correct
AWS Security Hub aggregates findings from GuardDuty, Inspector, Macie and Config, then runs automated compliance checks against standards including PCI DSS. This centralised aggregation and automated assessment satisfies the compliance team's evidence requirement, unlike standalone services.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector scans EC2 instances, container images and Lambda functions for vulnerabilities and unintended network exposure, producing findings only for those workloads. It is tempting because it does automate assessment, but it neither aggregates findings from other services nor evaluates PCI DSS controls.
- ✗
AWS CloudTrail
Why it's wrong here
CloudTrail logs API activity for audit trails, not security findings, and cannot run automated compliance checks against PCI DSS controls. It is tempting because it does supply the evidence trail auditors request, but that is activity logging, not finding aggregation or rule-based evaluation.
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.