Courseiva
Cloud Security Operations →mediumMultiple Choice

CCSP Cloud Security Operations Practice Question

A security team is using AWS and wants to monitor for changes to security groups that could expose resources to the internet. They need to receive an alert when a security group rule is modified to allow inbound traffic from 0.0.0.0/0 on port 22. Which AWS service should they use to detect this change?

⚠ Common exam trap

The trap here is assuming CloudTrail alone can detect insecure configurations, but it only records API activity without evaluating the resulting state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config

AWS Config is designed to monitor resource configurations and evaluate them against desired settings. It can detect when a security group rule is changed to allow inbound SSH from 0.0.0.0/0 and trigger an alert. The other services either log API calls without evaluation, focus on threat detection, or provide periodic checks, making them less suitable for this specific requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    GuardDuty is a threat detection service that analyzes events like VPC Flow Logs, CloudTrail logs, and DNS logs to identify malicious activity. It does not monitor for configuration changes like security group modifications. While it can alert on unusual behavior, it would not detect a security group rule change that allows SSH from the internet unless that change leads to actual malicious activity.

  • ✗

    AWS Trusted Advisor

    Why it's wrong here

    Trusted Advisor provides recommendations based on AWS best practices, including security group checks. It can flag security groups with rules that allow unrestricted access, but it does not provide real-time detection of changes. It runs periodic checks and does not trigger alerts immediately upon modification. Therefore, it is not suitable for continuous monitoring of security group changes.

  • ✓

    AWS Config

    Why this is correct

    AWS Config records changes to resource configurations, including security groups. You can create a custom rule or use a managed rule to evaluate security group configurations and trigger an alert when a rule allows inbound SSH from 0.0.0.0/0. AWS Config can also send notifications via Amazon SNS, enabling the security team to respond promptly.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    CloudTrail logs API calls, including modifications to security groups, but it does not evaluate the configuration state. It can tell you that a change occurred, but not whether the resulting configuration is insecure. To detect that a security group now allows 0.0.0.0/0 on port 22, you would need to parse the CloudTrail logs and analyze the request parameters, which is not natively supported for continuous compliance monitoring.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.