Courseiva
Security and CompliancemediumMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A company operates multiple AWS accounts under AWS Organizations. The security team needs to record all management events (for example, creating Amazon EC2 instances, modifying security groups, and deleting Amazon S3 buckets) across all accounts. The logs must be delivered to a single Amazon S3 bucket that is encrypted with an AWS KMS key and protected from modification. Which AWS feature should the team enable to achieve this centralized logging requirement?

⚠ Common exam trap

Many exam-takers confuse CloudTrail for management events with AWS Config for configuration changes, or assume CloudWatch Logs can aggregate all account logs, but only CloudTrail provides the required centralized API activity logging across an organization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS CloudTrail

AWS CloudTrail is the correct service because it records all management events (API calls) across AWS accounts, and when configured as an organization trail in AWS Organizations, it automatically logs events from all member accounts to a single S3 bucket. This meets the requirement for centralized logging with encryption using AWS KMS and protection from modification via S3 bucket policies and versioning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS CloudTrail

    Why this is correct

    AWS CloudTrail records API calls and can be configured as an organization trail to log activity across all accounts in AWS Organizations. It delivers log files to a specified S3 bucket, where encryption and immutability can be applied.

  • AWS Config

    Why it's wrong here

    AWS Config records configuration changes and evaluates resource compliance against rules, but it does not capture every API call. It can use CloudTrail as a data source, but it is not the primary service for recording API events.

    When this WOULD be correct

    A company needs to track changes to AWS resource configurations (e.g., security group rules, S3 bucket policies) across multiple accounts and evaluate them against compliance rules. AWS Config would be the correct service to enable centralized configuration recording and auditing.

  • Amazon CloudWatch Logs

    Why it's wrong here

    Amazon CloudWatch Logs is used to collect, monitor, and store log files from applications and AWS services. It does not natively record AWS API calls; CloudTrail can stream events to CloudWatch Logs, but CloudTrail itself is the service that captures the API events.

    When this WOULD be correct

    A company needs to centralize application and system logs (e.g., from EC2 instances, Lambda functions) from multiple accounts into a single S3 bucket for long-term storage and analysis. CloudWatch Logs with cross-account subscription filters would be the correct service to aggregate these logs.

  • AWS Audit Manager

    Why it's wrong here

    AWS Audit Manager is a managed service that helps you continuously audit your AWS usage to simplify risk assessment and compliance against standards like PCI DSS and HIPAA. It automates the collection of evidence from various AWS services — notably including CloudTrail — and organizes that evidence into assessment reports, but it does not itself capture or record raw API calls. Because Audit Manager depends on CloudTrail as a source of activity data, it is a downstream analysis and reporting tool rather than the service that natively records the API events.

    When this WOULD be correct

    A company needs to continuously assess compliance against predefined controls (e.g., PCI-DSS) across multiple accounts, with automated evidence collection and report generation. AWS Audit Manager would be the correct service to streamline audit preparation.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

AWS CloudTrailCorrect answer

Why this is correct

AWS CloudTrail records API calls and can be configured as an organization trail to log activity across all accounts in AWS Organizations. It delivers log files to a specified S3 bucket, where encryption and immutability can be applied.

AWS ConfigWrong answer — click to see why

Why this is wrong here

AWS Config records resource configuration changes and evaluates compliance, but it does not capture management events like API calls (e.g., creating EC2 instances). The question specifically requires recording management events, which is CloudTrail's function.

★ When this WOULD be the correct answer

A company needs to track changes to AWS resource configurations (e.g., security group rules, S3 bucket policies) across multiple accounts and evaluate them against compliance rules. AWS Config would be the correct service to enable centralized configuration recording and auditing.

Why candidates choose this

Candidates may confuse AWS Config's configuration tracking with CloudTrail's event logging, or think Config can log all API actions because it records configuration changes that result from those actions.

Amazon CloudWatch LogsWrong answer — click to see why

Why this is wrong here

Amazon CloudWatch Logs is used for monitoring, storing, and accessing log files from AWS resources, but it does not record management events like API calls across accounts. The requirement to capture management events across all accounts and deliver to a centralized S3 bucket is specifically a CloudTrail feature.

★ When this WOULD be the correct answer

A company needs to centralize application and system logs (e.g., from EC2 instances, Lambda functions) from multiple accounts into a single S3 bucket for long-term storage and analysis. CloudWatch Logs with cross-account subscription filters would be the correct service to aggregate these logs.

Why candidates choose this

Candidates may confuse CloudWatch Logs with CloudTrail because both deal with logging, but CloudWatch Logs focuses on operational logs from applications and services, not on recording API management events for governance and auditing.

AWS Audit ManagerWrong answer — click to see why

Why this is wrong here

AWS Audit Manager helps audit AWS usage by continuously evaluating controls, but it does not natively record and centralize management events like CloudTrail. It relies on CloudTrail logs for evidence, not as the primary event recorder.

★ When this WOULD be the correct answer

A company needs to continuously assess compliance against predefined controls (e.g., PCI-DSS) across multiple accounts, with automated evidence collection and report generation. AWS Audit Manager would be the correct service to streamline audit preparation.

Why candidates choose this

Candidates may confuse Audit Manager's audit and compliance focus with the logging and monitoring requirements of the question, assuming it can centralize event logs when it actually consumes them from other services.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CLF-C02 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CLF-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company must maintain audit records of all user actions and configuration changes across their AWS accounts. Which AWS service should they enable to capture this information?

medium
  • A.Amazon CloudWatch Logs
  • B.AWS Config
  • C.AWS CloudTrail
  • D.VPC Flow Logs

Why C: AWS CloudTrail is the correct service because it records API activity and user actions across AWS accounts, providing a complete audit trail of all management and data plane operations. This includes who made changes, what actions were performed, and when they occurred, which is essential for maintaining audit records of user actions and configuration changes.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.