CCSP Cloud Security Operations Practice Question
An organization is implementing a cloud SIEM solution to centralize security monitoring across multiple AWS accounts. Which service should be used to aggregate security findings and send them to a third-party SIEM like Splunk?
⚠ Common exam trap
CCSP often tests the distinction between services that generate findings (like GuardDuty) versus services that aggregate and normalize findings (like Security Hub), leading candidates to pick GuardDuty because they confuse detection with centralization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Security Hub
AWS Security Hub is the correct service because it is designed to aggregate security findings from multiple AWS services (e.g., GuardDuty, Inspector, Macie) and AWS accounts, and then forward them to third-party SIEM solutions like Splunk via AWS EventBridge or direct integration. This centralizes security alerts into a single dashboard and stream, enabling efficient monitoring across a multi-account environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudTrail
Why it's wrong here
CloudTrail records API activity as event logs, not aggregated security findings, so it cannot feed Splunk the curated findings the stem requires. It is tempting because CloudTrail is the standard source for audit trails and multi-account log aggregation, and would be correct if the requirement were capturing API call history rather than findings.
- ✓
AWS Security Hub
Why this is correct
AWS Security Hub aggregates findings across accounts and Regions via a single pane, then forwards them to third-party SIEMs such as Splunk through native integrations or EventBridge. This satisfies the requirement to centralise findings from multiple AWS accounts before onward delivery.
- ✗
AWS GuardDuty
Why it's wrong here
GuardDuty generates its own threat findings from VPC flow logs, DNS and CloudTrail, but it does not aggregate findings from other AWS detection services into one feed for Splunk. It is tempting because GuardDuty is a findings producer, and would be correct if the question asked which service detects threats rather than aggregates them.
- ✗
AWS Config
Why it's wrong here
AWS Config records resource configuration changes and compliance against rules; it does not aggregate security findings for forwarding to Splunk. It is tempting as a central visibility service, and it would be the correct choice when assessing resource configuration drift or compliance posture rather than consolidating findings.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.