CLF-C02 - Security and Compliance (30% of the exam) - Section 2.8

Identify components and resources for security, including AWS Trusted Advisor checks, third-party products in AWS Marketplace and where to find AWS security documentation.

Identify AWS Trusted Advisor as a service that surfaces security, cost, and performance recommendations including checks for open security groups and unused credentials. Recognise AWS Marketplace as a source of third-party security products, and AWS Security Hub as the aggregation point for findings across multiple security services and partner tools.

AWS Trusted AdvisorAWS MarketplaceSecurity documentationAWS Security Hub

Practice question for this objective

Free sampleSecurity and Compliancemedium

A security team is using GuardDuty, Inspector and Macie across several accounts and wants one place that aggregates the findings from these services and checks the environment against security standards. Which AWS service provides this central view?

  • AAWS Security Hub, which aggregates findings from multiple security services and checks against security standards Correct
  • BAmazon CloudWatch, which collects metrics and logs so teams can watch the operational health of their workloads
  • CAWS CloudTrail, which records the API calls made within an account so user actions can be reviewed later
  • DAmazon GuardDuty, which continuously analyses account and network logs to detect malicious or unusual behaviour
AWS Security Hub centralises findings from multiple security services and checks the environment against security standards. Security Hub acts as the aggregation point for findings produced by services such as GuardDuty, Inspector and Macie, normalising them and running automated checks against frameworks like the AWS Foundational Security Best Practices, giving a single posture view rather than the narrower roles of monitoring, auditing or a single detection source.

Why A is correct: Security Hub is the central security posture service that consolidates findings from GuardDuty, Inspector and Macie and runs automated checks against standards, which is the single pane the team wants.

Why B is wrong: CloudWatch monitors performance and stores logs, but it does not aggregate security findings from services like GuardDuty or check them against security standards, so it is not the central console.

Why C is wrong: CloudTrail logs API activity for auditing, yet it does not consolidate findings from other security services or measure them against standards, so it cannot give the central view.

Why D is wrong: GuardDuty produces its own threat findings, but it is one source feeding into a central view rather than the service that aggregates findings from Inspector and Macie too.

See more CLF-C02 practice questions, answers explained.

Exam traps in Security and Compliance

Answers that look right on this material and are not. Each one is a distractor from a different question in the CLF-C02 bank for this domain.

  • Amazon Inspector, which automatically scans workloads for software vulnerabilities and unintended network exposure

    Why it is wrong: Inspector finds vulnerabilities inside the customer workload, but it does not review the whole account across cost and service limits, so it does not match this need.

  • Continuously analyse VPC flow logs and DNS logs with threat intelligence to detect compromised instances.

    Why it is wrong: This describes Amazon GuardDuty threat detection, not the best-practice advisory checks that Trusted Advisor performs.

  • AWS Artifact, which provides on-demand access to AWS compliance reports and the legal agreements customers accept

    Why it is wrong: Artifact supplies audit documents about AWS itself, so it does not inspect the account for missing root MFA or open security groups.

Examworthy is not affiliated with or endorsed by Amazon Web Services. Original, blueprint-aligned practice material only.