CLF-C02 Security and Compliance Practice Question
A company operates multiple AWS accounts under AWS Organizations. The security team needs to record all management events (for example, creating Amazon EC2 instances, modifying security groups, and deleting Amazon S3 buckets) across all accounts. The logs must be delivered to a single Amazon S3 bucket that is encrypted with an AWS KMS key and protected from modification. Which AWS feature should the team enable to achieve this centralized logging requirement?
⚠ Common exam trap
Many exam-takers confuse CloudTrail for management events with AWS Config for configuration changes, or assume CloudWatch Logs can aggregate all account logs, but only CloudTrail provides the required centralized API activity logging across an organization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail
AWS CloudTrail is the correct service because it records all management events (API calls) across AWS accounts, and when configured as an organization trail in AWS Organizations, it automatically logs events from all member accounts to a single S3 bucket. This meets the requirement for centralized logging with encryption using AWS KMS and protection from modification via S3 bucket policies and versioning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail records API calls and can be configured as an organization trail to log activity across all accounts in AWS Organizations. It delivers log files to a specified S3 bucket, where encryption and immutability can be applied.
- ✗
AWS Config
Why it's wrong here
AWS Config records configuration changes and evaluates resource compliance against rules, but it does not capture every API call. It can use CloudTrail as a data source, but it is not the primary service for recording API events.
When this WOULD be correct
A company needs to track changes to AWS resource configurations (e.g., security group rules, S3 bucket policies) across multiple accounts and evaluate them against compliance rules. AWS Config would be the correct service to enable centralized configuration recording and auditing.
- ✗
Amazon CloudWatch Logs
Why it's wrong here
Amazon CloudWatch Logs is used to collect, monitor, and store log files from applications and AWS services. It does not natively record AWS API calls; CloudTrail can stream events to CloudWatch Logs, but CloudTrail itself is the service that captures the API events.
When this WOULD be correct
A company needs to centralize application and system logs (e.g., from EC2 instances, Lambda functions) from multiple accounts into a single S3 bucket for long-term storage and analysis. CloudWatch Logs with cross-account subscription filters would be the correct service to aggregate these logs.
- ✗
AWS Audit Manager
Why it's wrong here
AWS Audit Manager is a managed service that helps you continuously audit your AWS usage to simplify risk assessment and compliance against standards like PCI DSS and HIPAA. It automates the collection of evidence from various AWS services — notably including CloudTrail — and organizes that evidence into assessment reports, but it does not itself capture or record raw API calls. Because Audit Manager depends on CloudTrail as a source of activity data, it is a downstream analysis and reporting tool rather than the service that natively records the API events.
When this WOULD be correct
A company needs to continuously assess compliance against predefined controls (e.g., PCI-DSS) across multiple accounts, with automated evidence collection and report generation. AWS Audit Manager would be the correct service to streamline audit preparation.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓AWS CloudTrailCorrect answer▾
Why this is correct
AWS CloudTrail records API calls and can be configured as an organization trail to log activity across all accounts in AWS Organizations. It delivers log files to a specified S3 bucket, where encryption and immutability can be applied.
✗AWS ConfigWrong answer — click to see why▾
Why this is wrong here
AWS Config records resource configuration changes and evaluates compliance, but it does not capture management events like API calls (e.g., creating EC2 instances). The question specifically requires recording management events, which is CloudTrail's function.
★ When this WOULD be the correct answer
A company needs to track changes to AWS resource configurations (e.g., security group rules, S3 bucket policies) across multiple accounts and evaluate them against compliance rules. AWS Config would be the correct service to enable centralized configuration recording and auditing.
Why candidates choose this
Candidates may confuse AWS Config's configuration tracking with CloudTrail's event logging, or think Config can log all API actions because it records configuration changes that result from those actions.
✗Amazon CloudWatch LogsWrong answer — click to see why▾
Why this is wrong here
Amazon CloudWatch Logs is used for monitoring, storing, and accessing log files from AWS resources, but it does not record management events like API calls across accounts. The requirement to capture management events across all accounts and deliver to a centralized S3 bucket is specifically a CloudTrail feature.
★ When this WOULD be the correct answer
A company needs to centralize application and system logs (e.g., from EC2 instances, Lambda functions) from multiple accounts into a single S3 bucket for long-term storage and analysis. CloudWatch Logs with cross-account subscription filters would be the correct service to aggregate these logs.
Why candidates choose this
Candidates may confuse CloudWatch Logs with CloudTrail because both deal with logging, but CloudWatch Logs focuses on operational logs from applications and services, not on recording API management events for governance and auditing.
✗AWS Audit ManagerWrong answer — click to see why▾
Why this is wrong here
AWS Audit Manager helps audit AWS usage by continuously evaluating controls, but it does not natively record and centralize management events like CloudTrail. It relies on CloudTrail logs for evidence, not as the primary event recorder.
★ When this WOULD be the correct answer
A company needs to continuously assess compliance against predefined controls (e.g., PCI-DSS) across multiple accounts, with automated evidence collection and report generation. AWS Audit Manager would be the correct service to streamline audit preparation.
Why candidates choose this
Candidates may confuse Audit Manager's audit and compliance focus with the logging and monitoring requirements of the question, assuming it can centralize event logs when it actually consumes them from other services.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CLF-C02 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CLF-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company must maintain audit records of all user actions and configuration changes across their AWS accounts. Which AWS service should they enable to capture this information?
medium- A.Amazon CloudWatch Logs
- B.AWS Config
- ✓ C.AWS CloudTrail
- D.VPC Flow Logs
Why C: AWS CloudTrail is the correct service because it records API activity and user actions across AWS accounts, providing a complete audit trail of all management and data plane operations. This includes who made changes, what actions were performed, and when they occurred, which is essential for maintaining audit records of user actions and configuration changes.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.