CLF-C02 - Security and Compliance - Section 2.8

Identify components and resources for security, including AWS Trusted Advisor checks, third-party products in AWS Marketplace and where to find AWS security documentation.

Identify AWS Trusted Advisor as a service that surfaces security, cost, and performance recommendations including checks for open security groups and unused credentials. Recognise AWS Marketplace as a source of third-party security products, and AWS Security Hub as the aggregation point for findings across multiple security services and partner tools.

AWS Trusted AdvisorAWS MarketplaceSecurity documentationAWS Security Hub

Practice question for this objective

Free sampleSecurity and Compliancemedium

A security team is using GuardDuty, Inspector and Macie across several accounts and wants one place that aggregates the findings from these services and checks the environment against security standards. Which AWS service provides this central view?

  • AAWS Security Hub, which aggregates findings from multiple security services and checks against security standards Correct
  • BAmazon CloudWatch, which collects metrics and logs so teams can watch the operational health of their workloads
  • CAWS CloudTrail, which records the API calls made within an account so user actions can be reviewed later
  • DAmazon GuardDuty, which continuously analyses account and network logs to detect malicious or unusual behaviour
AWS Security Hub centralises findings from multiple security services and checks the environment against security standards. Security Hub acts as the aggregation point for findings produced by services such as GuardDuty, Inspector and Macie, normalising them and running automated checks against frameworks like the AWS Foundational Security Best Practices, giving a single posture view rather than the narrower roles of monitoring, auditing or a single detection source.

Why A is correct: Security Hub is the central security posture service that consolidates findings from GuardDuty, Inspector and Macie and runs automated checks against standards, which is the single pane the team wants.

Why B is wrong: CloudWatch monitors performance and stores logs, but it does not aggregate security findings from services like GuardDuty or check them against security standards, so it is not the central console.

Why C is wrong: CloudTrail logs API activity for auditing, yet it does not consolidate findings from other security services or measure them against standards, so it cannot give the central view.

Why D is wrong: GuardDuty produces its own threat findings, but it is one source feeding into a central view rather than the service that aggregates findings from Inspector and Macie too.

See more CLF-C02 practice questions, answers explained.

More in this domain

Back to all Security and Compliance objectives, or the CLF-C02 cert hub.

Examworthy is not affiliated with or endorsed by Amazon Web Services. Original, blueprint-aligned practice material only.