Courseiva
Security and CompliancemediumMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A company handles credit card transactions and must comply with the Payment Card Industry Data Security Standard (PCI DSS). The company's compliance officer needs to review AWS's PCI DSS compliance reports and also download and sign the AWS Business Associate Addendum (BAA) for HIPAA eligibility. The company wants a single, managed AWS service that provides on-demand access to these compliance documents and agreements. Which AWS service should the compliance officer use?

⚠ Common exam trap

A common mix-up: candidates confuse AWS Artifact with AWS Config or Trusted Advisor, thinking those services also handle compliance documents, but they are designed for configuration auditing and best-practice recommendations, not document repository and agreement signing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Artifact

AWS Artifact is the correct service because it provides on-demand, self-service access to AWS compliance reports (including PCI DSS reports) and agreements such as the Business Associate Addendum (BAA) for HIPAA. It allows the compliance officer to review, download, and sign these documents directly from the AWS Management Console, meeting the requirement for a single managed service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor is a real-time guidance service that inspects your AWS environment and offers recommendations for cost optimization, security, performance, fault tolerance, and service limits (e.g., flagging unmoderated security groups or unused resources). While it can help you operate securely, it does not store, generate, or provide access to AWS's formal compliance documents such as PCI DSS reports, SOC reports, or a Business Associate Addendum. To satisfy credit card compliance requirements like obtaining AWS's Attestation of Compliance, you need to retrieve those signed artifacts from AWS Artifact, not the advisory recommendations from Trusted Advisor.

    When this WOULD be correct

    A company wants to check its AWS account against AWS best practices for security and cost optimization, and needs automated recommendations to improve its cloud posture. In that scenario, AWS Trusted Advisor would be the correct service.

  • AWS Config

    Why it's wrong here

    AWS Config is a configuration and governance service that records the history of your resource configurations and lets you define rules to evaluate resources against desired policies (e.g., 'S3 buckets must have encryption enabled' or 'security groups must not allow unrestricted SSH'). It is useful for auditing your own account's compliance posture and for maintaining an audit trail of changes, but it neither publishes AWS's own compliance certifications nor hosts agreements like a BAA. For PCI DSS, you rely on AWS Config to prove how your own resources are configured, but the actual AWS compliance reports and signed agreements must be downloaded from the AWS Artifact console.

    When this WOULD be correct

    A question asking which AWS service can be used to track changes to resource configurations and evaluate them against desired policies (e.g., ensuring all S3 buckets are encrypted) would have AWS Config as the correct answer.

  • AWS Artifact

    Why this is correct

    AWS Artifact is the correct service because it provides on-demand access to AWS compliance reports and agreements, including PCI DSS reports and the Business Associate Addendum (BAA). It allows users to review, download, and sign these documents from a single central location.

  • Amazon Inspector

    Why it's wrong here

    Amazon Inspector is an automated vulnerability management and security assessment service that scans compute workloads—such as Amazon EC2 instances, Amazon ECR container images, and AWS Lambda functions—for software vulnerabilities (CVEs) and unintended network exposure. It helps you detect security weaknesses in your own application infrastructure, but it does not provide AWS's externally audited compliance attestations or the ability to sign legal agreements like the Business Associate Addendum. Under PCI DSS, you would use Inspector to strengthen your own workload security, yet the official AWS PCI reports and the responsibility matrix that the auditor requires are only available through AWS Artifact.

    When this WOULD be correct

    A question asking which AWS service can automatically assess applications for vulnerabilities or deviations from best practices, such as checking for unintended network accessibility or compliance with CIS benchmarks.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

AWS ArtifactCorrect answer

Why this is correct

AWS Artifact is the correct service because it provides on-demand access to AWS compliance reports and agreements, including PCI DSS reports and the Business Associate Addendum (BAA). It allows users to review, download, and sign these documents from a single central location.

AWS Trusted AdvisorWrong answer — click to see why

Why this is wrong here

AWS Trusted Advisor provides recommendations for cost optimization, performance, security, and fault tolerance, but it does not provide on-demand access to compliance reports or agreements like PCI DSS reports or BAAs.

★ When this WOULD be the correct answer

A company wants to check its AWS account against AWS best practices for security and cost optimization, and needs automated recommendations to improve its cloud posture. In that scenario, AWS Trusted Advisor would be the correct service.

Why candidates choose this

Candidates may confuse Trusted Advisor's security checks with compliance document access, assuming it covers all security and compliance needs.

AWS ConfigWrong answer — click to see why

Why this is wrong here

AWS Config is a service for evaluating and auditing resource configurations, not for accessing compliance reports or agreements like PCI DSS reports or BAAs.

★ When this WOULD be the correct answer

A question asking which AWS service can be used to track changes to resource configurations and evaluate them against desired policies (e.g., ensuring all S3 buckets are encrypted) would have AWS Config as the correct answer.

Why candidates choose this

Candidates may confuse 'compliance' with 'configuration compliance' and think AWS Config provides compliance documents, when it actually focuses on resource configuration auditing.

Amazon InspectorWrong answer — click to see why

Why this is wrong here

Amazon Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS, but it does not provide on-demand access to compliance reports or agreements like PCI DSS reports or BAAs.

★ When this WOULD be the correct answer

A question asking which AWS service can automatically assess applications for vulnerabilities or deviations from best practices, such as checking for unintended network accessibility or compliance with CIS benchmarks.

Why candidates choose this

Candidates may confuse Inspector's security assessment capabilities with compliance document management, assuming it provides compliance reports rather than just security evaluations.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.