Courseiva
Security and CompliancemediumMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A company requires all IAM users to have multi-factor authentication (MFA) enabled for AWS Management Console access. The security team needs an automated way to continuously detect any IAM user without an MFA device and generate a compliance report. The solution must not require custom code. Which AWS service should the team use?

⚠ Common exam trap

Candidates often confuse AWS Trusted Advisor's root account MFA check with the broader requirement to check all IAM users, or they mistakenly think IAM Access Analyzer can audit user-level security settings like MFA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Config

AWS Config is correct because it provides a managed, rules-based evaluation of AWS resource configurations. By enabling the 'iam-user-mfa-enabled' managed rule, AWS Config continuously checks all IAM users for the presence of an MFA device and can automatically trigger remediation actions or generate compliance reports via AWS Config aggregators, all without any custom code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Config

    Why this is correct

    AWS Config is the appropriate service because it offers a managed rule named iam-user-mfa-enabled, which evaluates each IAM user and returns a non-compliant result if MFA is not activated. Config continuously records changes to IAM users and, when paired with conformance packs, can provide automated compliance reports and even trigger remediation actions. This satisfies the requirement without requiring any custom code.

  • IAM Access Analyzer

    Why it's wrong here

    IAM Access Analyzer is designed to identify resources, such as S3 buckets, IAM roles, or KMS keys, that are shared with external principals by analyzing resource-based policies. It does not inspect the authentication configuration of IAM users, including whether multi-factor authentication is enabled. Access Analyzer's purpose is to pinpoint unintended external access, not to enforce or audit MFA requirements for identities.

    When this WOULD be correct

    A company wants to identify IAM roles or resources that are accessible from outside its AWS account (e.g., to detect unintended public access). IAM Access Analyzer would be the correct service to generate findings about such external access.

  • AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor includes a security check titled 'MFA on Root Account,' which only verifies that the account root user has MFA enabled. It does not evaluate MFA status for individual IAM users and does not provide customizable compliance reporting or alerting for identity configurations. Trusted Advisor is a best-practice dashboard, not a continuous, account-wide configuration compliance service, so it does not meet this requirement.

    When this WOULD be correct

    A company wants a high-level security assessment of their AWS account, including checks for MFA on the root account, open security groups, and other best practices, without needing to set up custom rules or manage resources. AWS Trusted Advisor would be the correct service for this out-of-the-box dashboard.

  • Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that continuously scans Amazon EC2 instances, container images in Amazon ECR, and Lambda functions for software vulnerabilities and unintended network exposure. It has no integration with IAM identity configuration and cannot read or evaluate user-level authentication settings such as MFA status. Therefore, while Inspector is useful for workload security, it is not a mechanism for enforcing or reporting on IAM user MFA compliance.

    When this WOULD be correct

    A company needs to automatically assess EC2 instances for common software vulnerabilities and network exposures. Amazon Inspector would be the correct service to run automated security assessments and generate findings reports without custom code.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

AWS ConfigCorrect answer

Why this is correct

AWS Config is the appropriate service because it offers a managed rule named iam-user-mfa-enabled, which evaluates each IAM user and returns a non-compliant result if MFA is not activated. Config continuously records changes to IAM users and, when paired with conformance packs, can provide automated compliance reports and even trigger remediation actions. This satisfies the requirement without requiring any custom code.

IAM Access AnalyzerWrong answer — click to see why

Why this is wrong here

IAM Access Analyzer is designed to analyze resource policies to identify resources shared with external entities, not to detect IAM users without MFA devices. It does not provide continuous compliance monitoring or reporting for MFA status.

★ When this WOULD be the correct answer

A company wants to identify IAM roles or resources that are accessible from outside its AWS account (e.g., to detect unintended public access). IAM Access Analyzer would be the correct service to generate findings about such external access.

Why candidates choose this

Candidates may confuse 'Access Analyzer' with a tool that analyzes IAM user configurations, including MFA status, because the name suggests it analyzes access settings. They overlook that its actual purpose is external access analysis.

AWS Trusted AdvisorWrong answer — click to see why

Why this is wrong here

AWS Trusted Advisor provides best-practice checks, including MFA on root account, but it does not continuously detect IAM users without MFA devices or generate custom compliance reports. It lacks the granularity to check all IAM users and cannot be configured for automated remediation or custom rules.

★ When this WOULD be the correct answer

A company wants a high-level security assessment of their AWS account, including checks for MFA on the root account, open security groups, and other best practices, without needing to set up custom rules or manage resources. AWS Trusted Advisor would be the correct service for this out-of-the-box dashboard.

Why candidates choose this

Candidates may confuse Trusted Advisor's security checks with the ability to monitor all IAM users, or assume it can be used for continuous compliance monitoring because it provides recommendations.

Amazon InspectorWrong answer — click to see why

Why this is wrong here

Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and unintended network exposure, not for IAM user MFA compliance. It cannot detect or report on IAM user MFA status.

★ When this WOULD be the correct answer

A company needs to automatically assess EC2 instances for common software vulnerabilities and network exposures. Amazon Inspector would be the correct service to run automated security assessments and generate findings reports without custom code.

Why candidates choose this

Candidates may confuse 'security assessment' with 'compliance checking' and assume Inspector can evaluate IAM configurations, or they may not know the specific capabilities of each AWS security service.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This CLF-C02 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.