CLF-C02 Security and Compliance Practice Question
A company's compliance officer needs to provide an external auditor with copies of AWS SOC 2 reports and a PCI DSS attestation of compliance. The officer needs a self-service portal to download these documents directly, without contacting AWS Support. The solution must provide the most current versions of these reports. Which AWS service should the officer use?
⚠ Common exam trap
Many exam-takers confuse AWS Artifact (a document repository for compliance reports) with AWS Audit Manager (a tool for creating and managing audit evidence), leading them to select Audit Manager for downloading reports instead of Artifact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Artifact
AWS Artifact is the correct service because it provides a self-service portal for on-demand access to AWS compliance reports, including SOC 2 reports and PCI DSS attestations of compliance. It ensures the most current versions are always available without needing to contact AWS Support, directly meeting the compliance officer's requirement for a self-service download solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Artifact
Why this is correct
AWS Artifact is a self-service portal that provides on-demand access to AWS compliance reports, such as SOC 2, SOC 3, PCI DSS, ISO certifications, and FedRAMP, as well as the ability to review, accept, and manage AWS agreements like the Business Associate Addendum. It allows customers to download these reports directly from the AWS Management Console without needing to contact AWS Support or open a case, making it the correct destination for an external compliance officer.
- ✗
AWS Audit Manager
Why it's wrong here
AWS Audit Manager helps you automate the generation of audit evidence for your own internal or external audits by continuously collecting user activity and configuration data from your AWS resources. You can map that evidence to controls from frameworks like CIS or ISO, but this is a custom evidence-collection tool, not a publisher of pre-existing AWS compliance reports. The official AWS certifications and attests remain accessible solely through AWS Artifact.
When this WOULD be correct
A company needs to continuously assess and collect evidence of its AWS resource configurations against PCI DSS or SOC 2 controls, and generate audit-ready reports automatically. AWS Audit Manager would be the correct service to schedule evidence collection and produce custom audit reports.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is a vulnerability management service that automatically scans AWS workloads for software vulnerabilities and unintended network exposure. It assesses EC2 instances, container images in Amazon ECR, and Lambda functions, but it does not store or serve AWS's own compliance attestation reports. Its output is an assessment report about your resources, not an official third-party certification document for AWS.
When this WOULD be correct
A question asking which AWS service automatically assesses applications for vulnerabilities or deviations from security best practices, such as scanning EC2 instances for known CVEs or unintended network access.
- ✗
AWS Config
Why it's wrong here
AWS Config is a service that records and evaluates the configuration state of your AWS resources against specified rules, providing a detailed inventory and history of resource configurations. It can help you assess your internal compliance with your own policies via managed or custom rules, but it does not hold or deliver AWS's externally published compliance reports such as SOC or PCI DSS. Its purpose is to monitor your environment, not to act as a repository for AWS's audited framework documentation.
When this WOULD be correct
A company needs to continuously monitor and evaluate the compliance of their AWS resource configurations against internal policies or industry standards (e.g., PCI DSS). AWS Config would be the correct service to track configuration changes and assess compliance rules.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓AWS ArtifactCorrect answer▾
Why this is correct
AWS Artifact is a self-service portal that provides on-demand access to AWS compliance reports, such as SOC 2, SOC 3, PCI DSS, ISO certifications, and FedRAMP, as well as the ability to review, accept, and manage AWS agreements like the Business Associate Addendum. It allows customers to download these reports directly from the AWS Management Console without needing to contact AWS Support or open a case, making it the correct destination for an external compliance officer.
✗AWS Audit ManagerWrong answer — click to see why▾
Why this is wrong here
AWS Audit Manager helps audit evidence collection and report generation, but it does not provide a self-service portal to download pre-existing compliance reports like SOC 2 or PCI DSS attestations. Those reports are available only through AWS Artifact.
★ When this WOULD be the correct answer
A company needs to continuously assess and collect evidence of its AWS resource configurations against PCI DSS or SOC 2 controls, and generate audit-ready reports automatically. AWS Audit Manager would be the correct service to schedule evidence collection and produce custom audit reports.
Why candidates choose this
The name 'Audit Manager' sounds like it would manage audit reports, leading candidates to assume it provides compliance documents directly, rather than understanding it is a tool for evidence collection and assessment.
✗Amazon InspectorWrong answer — click to see why▾
Why this is wrong here
Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, not a repository for compliance reports like SOC 2 or PCI DSS attestations.
★ When this WOULD be the correct answer
A question asking which AWS service automatically assesses applications for vulnerabilities or deviations from security best practices, such as scanning EC2 instances for known CVEs or unintended network access.
Why candidates choose this
Candidates may confuse 'compliance' with 'security scanning' and assume Inspector provides compliance reports, or they may think Inspector's findings can substitute for formal attestation documents.
✗AWS ConfigWrong answer — click to see why▾
Why this is wrong here
AWS Config is used for resource inventory, configuration history, and compliance rule evaluation, not for downloading compliance reports like SOC 2 or PCI DSS attestations.
★ When this WOULD be the correct answer
A company needs to continuously monitor and evaluate the compliance of their AWS resource configurations against internal policies or industry standards (e.g., PCI DSS). AWS Config would be the correct service to track configuration changes and assess compliance rules.
Why candidates choose this
Candidates may confuse 'compliance' broadly and think AWS Config, which deals with compliance rules, can also provide compliance reports, not realizing that AWS Artifact is the dedicated service for downloading AWS compliance documents.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
Courseiva writes every CLF-C02 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.