Courseiva
Security →mediumMultiple Choice

CV0-004 Security Practice Question

A company's compliance team must provide evidence that their cloud environment meets PCI DSS requirements. Which AWS service can aggregate security findings and automate compliance checks?

⚠ Common exam trap

CV0-004 often tests the confusion between AWS Config (configuration recording) and Security Hub (aggregation and compliance), expecting candidates to know that Security Hub is the aggregator for compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Security Hub

AWS Security Hub aggregates security findings from multiple AWS services and third-party tools, and it can run automated compliance checks against standards like PCI DSS. It provides a central dashboard for security posture. AWS Config records resource configurations but does not aggregate findings or automate compliance checks in the same way. Amazon Inspector is for vulnerability assessment, and CloudTrail logs API activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records resource configuration changes and evaluates them against rules, but it does not aggregate findings from GuardDuty, Inspector or Security Hub into a compliance posture. It is tempting because Config conformance packs do automate checks against PCI DSS, yet the aggregation requirement points to Security Hub.

  • ✓

    AWS Security Hub

    Why this is correct

    AWS Security Hub aggregates findings from GuardDuty, Inspector, Macie and Config, then runs automated compliance checks against standards including PCI DSS. This centralised aggregation and automated assessment satisfies the compliance team's evidence requirement, unlike standalone services.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector scans EC2 instances, container images and Lambda functions for vulnerabilities and unintended network exposure, producing findings only for those workloads. It is tempting because it does automate assessment, but it neither aggregates findings from other services nor evaluates PCI DSS controls.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    CloudTrail logs API activity for audit trails, not security findings, and cannot run automated compliance checks against PCI DSS controls. It is tempting because it does supply the evidence trail auditors request, but that is activity logging, not finding aggregation or rule-based evaluation.

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.