CV0-004 Security Practice Question
A company uses AWS and wants to centralize security monitoring across multiple accounts. Which service should they use to aggregate security findings and check compliance against standards like CIS AWS Foundations?
⚠ Common exam trap
CV0-004 often tests whether candidates confuse Security Hub (aggregation and compliance) with GuardDuty (threat detection) or Config (configuration assessment) — each serves a distinct role in the AWS security ecosystem.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Security Hub
AWS Security Hub is a centralized security and compliance service that aggregates findings from multiple AWS services (like GuardDuty, Inspector, Macie) and third-party tools across accounts, and it runs automated compliance checks against standards such as CIS AWS Foundations, AWS Foundational Security Best Practices, and PCI DSS. It is purpose-built for cross-account security aggregation and compliance monitoring, making it the correct choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail
Why it's wrong here
CloudTrail records API activity as audit logs; it does not evaluate findings against CIS AWS Foundations controls or aggregate them across accounts. It is tempting because CloudTrail can deliver logs to a central account and is often confused with compliance tooling. Security Hub performs that aggregation and standards-based compliance checking.
- ✗
Amazon GuardDuty
Why it's wrong here
GuardDuty detects threats from VPC flow logs, DNS and CloudTrail events, but it does not check configuration compliance against CIS AWS Foundations benchmarks. It is tempting because GuardDuty findings do appear in Security Hub, yet GuardDuty itself generates threat detections rather than standards-based compliance evaluations across accounts.
- ✓
AWS Security Hub
Why this is correct
AWS Security Hub aggregates findings from GuardDuty, Inspector, Macie and other accounts into one view, and runs automated compliance checks against standards including CIS AWS Foundations Benchmark. This satisfies the requirement to centralise security monitoring and compliance across multiple accounts.
- ✗
AWS Config
Why it's wrong here
AWS Config records resource configuration changes and can evaluate rules, but it does not aggregate findings across accounts into a central compliance dashboard against CIS AWS Foundations. It is tempting because Config conformance packs assess controls; however, Security Hub is the service that centralises findings and runs those standards checks.
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.