Courseiva

CCSP Cloud Security Operations Practice Question

A cloud security team is designing a detective control strategy for a multi-account AWS organization. The team wants to continuously evaluate resource configurations against CIS AWS Foundations Benchmark controls across all accounts and receive alerts when a resource drifts from the desired state. The team also wants to automatically remediate noncompliant resources where possible. Which TWO AWS services should be combined to meet these requirements? (Choose two.)

⚠ Common exam trap

The trap here is assuming AWS Security Hub alone enforces CIS compliance and remediates drift, when it aggregates findings and depends on AWS Config for evaluation and on Systems Manager Automation for remediation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config with conformance packs

Continuous configuration evaluation against CIS controls across an organization is delivered by AWS Config conformance packs, which package standards-mapped rules and support multi-account deployment through a delegated administrator. Automatic remediation of noncompliant resources is delivered by AWS Config remediation actions that invoke AWS Systems Manager Automation runbooks. Security Hub and Trusted Advisor provide visibility or advice but do not perform the configuration recording and automated remediation this design requires.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor provides best-practice checks and recommendations but does not continuously evaluate custom or standards-mapped rules across every account, nor does it automatically remediate resources. It is advisory and limited in scope compared to AWS Config. It does not provide the CIS-mapped, organization-wide continuous compliance evaluation or automated remediation the scenario requires.

  • ✓

    AWS Config with conformance packs

    Why this is correct

    AWS Config continuously records resource configurations and evaluates them against rules. Conformance packs bundle AWS Config rules mapped to standards such as the CIS AWS Foundations Benchmark and can be deployed across an organization using a delegated administrator account. This provides the continuous compliance evaluation and drift detection the team requires across all accounts.

  • ✓

    AWS Systems Manager Automation runbooks

    Why this is correct

    AWS Config remediation actions invoke AWS Systems Manager Automation runbooks to automatically correct noncompliant resources, such as enabling S3 bucket encryption or restricting security group rules. This satisfies the automatic remediation requirement. Combined with AWS Config conformance packs, it delivers both continuous compliance evaluation and automated correction across the organization.

  • ✗

    AWS Security Hub with CIS AWS Foundations Benchmark standard

    Why it's wrong here

    AWS Security Hub aggregates findings and can run the CIS AWS Foundations Benchmark standard, but it relies on AWS Config rules for the underlying evaluations and does not itself perform automatic remediation. It provides a consolidated compliance view rather than the configuration recording and remediation engine. The remediation requirement is met by Config remediation actions, not Security Hub alone.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events for malicious activity. It does not evaluate resource configurations against CIS controls or perform configuration remediation. While valuable for threat detection, GuardDuty does not fulfill the continuous configuration compliance and automatic remediation requirements described.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.