Courseiva
Security →mediumMultiple Choice

CV0-004 Security Practice Question

A company uses AWS and wants to centralize security monitoring across multiple accounts. Which service should they use to aggregate security findings and check compliance against standards like CIS AWS Foundations?

⚠ Common exam trap

CV0-004 often tests whether candidates confuse Security Hub (aggregation and compliance) with GuardDuty (threat detection) or Config (configuration assessment) — each serves a distinct role in the AWS security ecosystem.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Security Hub

AWS Security Hub is a centralized security and compliance service that aggregates findings from multiple AWS services (like GuardDuty, Inspector, Macie) and third-party tools across accounts, and it runs automated compliance checks against standards such as CIS AWS Foundations, AWS Foundational Security Best Practices, and PCI DSS. It is purpose-built for cross-account security aggregation and compliance monitoring, making it the correct choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    CloudTrail records API activity as audit logs; it does not evaluate findings against CIS AWS Foundations controls or aggregate them across accounts. It is tempting because CloudTrail can deliver logs to a central account and is often confused with compliance tooling. Security Hub performs that aggregation and standards-based compliance checking.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    GuardDuty detects threats from VPC flow logs, DNS and CloudTrail events, but it does not check configuration compliance against CIS AWS Foundations benchmarks. It is tempting because GuardDuty findings do appear in Security Hub, yet GuardDuty itself generates threat detections rather than standards-based compliance evaluations across accounts.

  • ✓

    AWS Security Hub

    Why this is correct

    AWS Security Hub aggregates findings from GuardDuty, Inspector, Macie and other accounts into one view, and runs automated compliance checks against standards including CIS AWS Foundations Benchmark. This satisfies the requirement to centralise security monitoring and compliance across multiple accounts.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records resource configuration changes and can evaluate rules, but it does not aggregate findings across accounts into a central compliance dashboard against CIS AWS Foundations. It is tempting because Config conformance packs assess controls; however, Security Hub is the service that centralises findings and runs those standards checks.

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.