Courseiva
Security and ComplianceeasyMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A company's compliance officer needs to provide an external auditor with copies of AWS SOC 2 reports and a PCI DSS attestation of compliance. The officer needs a self-service portal to download these documents directly, without contacting AWS Support. The solution must provide the most current versions of these reports. Which AWS service should the officer use?

⚠ Common exam trap

Many exam-takers confuse AWS Artifact (a document repository for compliance reports) with AWS Audit Manager (a tool for creating and managing audit evidence), leading them to select Audit Manager for downloading reports instead of Artifact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Artifact

AWS Artifact is the correct service because it provides a self-service portal for on-demand access to AWS compliance reports, including SOC 2 reports and PCI DSS attestations of compliance. It ensures the most current versions are always available without needing to contact AWS Support, directly meeting the compliance officer's requirement for a self-service download solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Artifact

    Why this is correct

    AWS Artifact is a self-service portal that provides on-demand access to AWS compliance reports, such as SOC 2, SOC 3, PCI DSS, ISO certifications, and FedRAMP, as well as the ability to review, accept, and manage AWS agreements like the Business Associate Addendum. It allows customers to download these reports directly from the AWS Management Console without needing to contact AWS Support or open a case, making it the correct destination for an external compliance officer.

  • AWS Audit Manager

    Why it's wrong here

    AWS Audit Manager helps you automate the generation of audit evidence for your own internal or external audits by continuously collecting user activity and configuration data from your AWS resources. You can map that evidence to controls from frameworks like CIS or ISO, but this is a custom evidence-collection tool, not a publisher of pre-existing AWS compliance reports. The official AWS certifications and attests remain accessible solely through AWS Artifact.

    When this WOULD be correct

    A company needs to continuously assess and collect evidence of its AWS resource configurations against PCI DSS or SOC 2 controls, and generate audit-ready reports automatically. AWS Audit Manager would be the correct service to schedule evidence collection and produce custom audit reports.

  • Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that automatically scans AWS workloads for software vulnerabilities and unintended network exposure. It assesses EC2 instances, container images in Amazon ECR, and Lambda functions, but it does not store or serve AWS's own compliance attestation reports. Its output is an assessment report about your resources, not an official third-party certification document for AWS.

    When this WOULD be correct

    A question asking which AWS service automatically assesses applications for vulnerabilities or deviations from security best practices, such as scanning EC2 instances for known CVEs or unintended network access.

  • AWS Config

    Why it's wrong here

    AWS Config is a service that records and evaluates the configuration state of your AWS resources against specified rules, providing a detailed inventory and history of resource configurations. It can help you assess your internal compliance with your own policies via managed or custom rules, but it does not hold or deliver AWS's externally published compliance reports such as SOC or PCI DSS. Its purpose is to monitor your environment, not to act as a repository for AWS's audited framework documentation.

    When this WOULD be correct

    A company needs to continuously monitor and evaluate the compliance of their AWS resource configurations against internal policies or industry standards (e.g., PCI DSS). AWS Config would be the correct service to track configuration changes and assess compliance rules.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

AWS ArtifactCorrect answer

Why this is correct

AWS Artifact is a self-service portal that provides on-demand access to AWS compliance reports, such as SOC 2, SOC 3, PCI DSS, ISO certifications, and FedRAMP, as well as the ability to review, accept, and manage AWS agreements like the Business Associate Addendum. It allows customers to download these reports directly from the AWS Management Console without needing to contact AWS Support or open a case, making it the correct destination for an external compliance officer.

AWS Audit ManagerWrong answer — click to see why

Why this is wrong here

AWS Audit Manager helps audit evidence collection and report generation, but it does not provide a self-service portal to download pre-existing compliance reports like SOC 2 or PCI DSS attestations. Those reports are available only through AWS Artifact.

★ When this WOULD be the correct answer

A company needs to continuously assess and collect evidence of its AWS resource configurations against PCI DSS or SOC 2 controls, and generate audit-ready reports automatically. AWS Audit Manager would be the correct service to schedule evidence collection and produce custom audit reports.

Why candidates choose this

The name 'Audit Manager' sounds like it would manage audit reports, leading candidates to assume it provides compliance documents directly, rather than understanding it is a tool for evidence collection and assessment.

Amazon InspectorWrong answer — click to see why

Why this is wrong here

Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, not a repository for compliance reports like SOC 2 or PCI DSS attestations.

★ When this WOULD be the correct answer

A question asking which AWS service automatically assesses applications for vulnerabilities or deviations from security best practices, such as scanning EC2 instances for known CVEs or unintended network access.

Why candidates choose this

Candidates may confuse 'compliance' with 'security scanning' and assume Inspector provides compliance reports, or they may think Inspector's findings can substitute for formal attestation documents.

AWS ConfigWrong answer — click to see why

Why this is wrong here

AWS Config is used for resource inventory, configuration history, and compliance rule evaluation, not for downloading compliance reports like SOC 2 or PCI DSS attestations.

★ When this WOULD be the correct answer

A company needs to continuously monitor and evaluate the compliance of their AWS resource configurations against internal policies or industry standards (e.g., PCI DSS). AWS Config would be the correct service to track configuration changes and assess compliance rules.

Why candidates choose this

Candidates may confuse 'compliance' broadly and think AWS Config, which deals with compliance rules, can also provide compliance reports, not realizing that AWS Artifact is the dedicated service for downloading AWS compliance documents.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every CLF-C02 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.