Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 39 pages
Exam (elaborations)

AWS Cloud Practitioner GuardDuty, Inspector & Macie Practice Test 2026–2027 | Threat Detection, Vulnerability & Data Security Questions

Document preview thumbnail
Preview 4 out of 39 pages

Prepare for the AWS Certified Cloud Practitioner CLF-C02 2026–2027 exam with focused practice on AWS GuardDuty, Amazon Inspector, and Amazon Macie. Review the distinct security capabilities of threat detection, vulnerability assessment, and sensitive-data discovery and protection. Practice realistic certification-style questions covering suspicious activity detection, workload vulnerabilities, software exposure, S3 data security, sensitive information discovery, and AWS security monitoring. Detailed answers and rationales explain when each service is appropriate and how their capabilities differ. Ideal for AWS Cloud Practitioner candidates, students, IT professionals, cybersecurity learners, and cloud certification candidates.

Content preview

___________________________________________________________________


AWS Cloud Practitioner GuardDuty,
Inspector & Macie Practice Test 2026–
2027 | Threat Detection, Vulnerability &
Data Security Questions

1. A company wants to continuously monitor its AWS environment for
suspicious account activity, compromised credentials, and potentially
malicious behavior. Which AWS service is specifically designed for this
purpose?

A. Amazon Inspector
B. Amazon Macie
C. Amazon GuardDuty
D. AWS Config

Answer: Amazon GuardDuty

Rationale: Amazon GuardDuty is a managed threat-detection service that
continuously analyzes AWS account, workload, and data activity to identify
suspicious or potentially malicious behavior.

, 2. A security team wants to identify vulnerabilities in Amazon EC2 instances,
container images, and supported workloads. Which AWS service should
they primarily use?

A. Amazon GuardDuty
B. Amazon Inspector
C. Amazon Macie
D. AWS Shield

Answer: Amazon Inspector

Rationale: Amazon Inspector is designed to automatically discover and assess
supported workloads for software vulnerabilities and unintended network
exposure.

3. An organization needs to discover sensitive information such as personally
identifiable information stored in Amazon S3. Which AWS service is the
best fit?

A. Amazon Inspector
B. Amazon GuardDuty
C. Amazon Macie
D. AWS WAF

Answer: Amazon Macie

Rationale: Amazon Macie uses machine learning and pattern matching to
discover and help protect sensitive data stored in Amazon S3, including
personally identifiable information.

4. Which statement best distinguishes Amazon GuardDuty from Amazon
Inspector?

A. GuardDuty detects threats, while Inspector identifies vulnerabilities and
exposure
B. GuardDuty encrypts data, while Inspector decrypts data

,C. GuardDuty classifies sensitive data, while Inspector manages encryption keys
D. GuardDuty manages IAM policies, while Inspector manages S3 buckets

Answer: GuardDuty detects threats, while Inspector identifies vulnerabilities
and exposure

Rationale: GuardDuty focuses on threat detection and suspicious activity,
whereas Inspector focuses on vulnerability management and security findings
for supported workloads.

5. A company receives a GuardDuty finding indicating that an EC2 instance
may be communicating with a known malicious IP address. What does this
finding represent?

A. A confirmed billing error
B. A potential security threat
C. An S3 data classification result
D. An EC2 performance metric

Answer: A potential security threat

Rationale: GuardDuty findings identify potentially malicious or suspicious
activity. A finding should be investigated and, where appropriate, remediated
using security response procedures.

6. Which AWS service is most directly associated with detecting sensitive data
in Amazon S3?

A. Amazon Macie
B. Amazon Inspector
C. Amazon GuardDuty
D. AWS Trusted Advisor

Answer: Amazon Macie

Rationale: Amazon Macie is specifically designed to discover and protect
sensitive data in Amazon S3 using automated data discovery and classification
capabilities.

, 7. An organization wants to determine whether EC2 instances are running
software versions with known Common Vulnerabilities and Exposures
(CVEs). Which service is most appropriate?

A. Amazon GuardDuty
B. Amazon Macie
C. Amazon Inspector
D. AWS CloudTrail

Answer: Amazon Inspector

Rationale: Amazon Inspector assesses supported workloads for known software
vulnerabilities, including vulnerabilities associated with published CVEs.

8. Which service would be most appropriate for identifying potentially
compromised AWS credentials?

A. Amazon GuardDuty
B. Amazon Macie
C. Amazon Inspector
D. Amazon S3 Glacier

Answer: Amazon GuardDuty

Rationale: GuardDuty analyzes relevant AWS activity and threat intelligence to
identify suspicious behavior, including activity that may indicate compromised
credentials.

9. A company wants to identify whether sensitive information is
unintentionally stored in an S3 bucket. Which service should the company
consider?

A. Amazon Inspector
B. Amazon Macie
C. Amazon GuardDuty
D. AWS Firewall Manager

Answer: Amazon Macie

Document information

Uploaded on
September 1, 2026
Number of pages
39
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$27.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
mml1030
2.6
(5)
Sold
8
Followers
0
Items
1207
Last sold
5 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions