Courseiva
Security and ComplianceeasyMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A company's internal audit team needs to download the latest AWS SOC 2 Type II report and ISO 27001 certificate to include in their compliance documentation for an upcoming external audit. The team requires a centralized, self-service portal where they can access these reports and any other relevant AWS compliance artifacts. They do not want to contact AWS Support or manage any infrastructure to obtain these documents. Which AWS service should the audit team use?

⚠ Common exam trap

Many candidates confuse AWS Audit Manager's role in audit evidence collection with the ability to download pre-existing AWS compliance reports, but AWS Artifact is the only service designed specifically for self-service access to those artifacts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Artifact

AWS Artifact is the correct service because it provides a centralized, self-service portal for on-demand access to AWS compliance reports, such as SOC 2 Type II and ISO 27001 certificates, without requiring any infrastructure management or contacting AWS Support. The audit team can simply log in, browse the available artifacts, and download the latest versions directly, meeting their requirement for a no-touch, self-service solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Config

    Why it's wrong here

    AWS Config is incorrect because it records resource configuration changes and evaluates them against custom or managed rules to help you see whether your environment is aligned with best practices. Its compliance view shows whether specific resources pass or fail those rules, but it is not a repository for official AWS compliance certifications. Therefore, it cannot be used to download the latest AWS compliance reports.

    When this WOULD be correct

    A company needs to continuously monitor and record changes to AWS resource configurations, and automatically evaluate them against desired policies (e.g., ensuring S3 buckets are not publicly accessible). AWS Config would be the correct service for this scenario.

  • AWS Artifact

    Why this is correct

    AWS Artifact is the correct choice because it is a self-service portal that gives on-demand access to AWS compliance reports, including SOC, ISO, PCI, and FedRAMP documents. Customers can download these official reports directly without contacting AWS Support or provisioning any infrastructure. It also provides access to AWS agreements, such as the Business Associate Addendum (BAA), which are often required by audit teams.

  • AWS Audit Manager

    Why it's wrong here

    AWS Audit Manager is incorrect because it is a service for automating evidence collection and mapping AWS usage to compliance frameworks for your own internal assessments. While it can generate audit reports based on the resources you define, it does not host or distribute AWS's own compliance certifications like SOC or ISO reports. The reports you need from AWS itself are found in AWS Artifact, not in Audit Manager's assessment outputs.

    When this WOULD be correct

    A company needs to automate evidence collection for internal audits and continuously monitor compliance against frameworks like SOC 2 or ISO 27001. They want to schedule assessments and generate audit reports without manual effort.

  • AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor is incorrect because it provides automated recommendations across cost optimization, performance, security, and fault tolerance, as well as some service limit checks. These best-practice checks give guidance on your account usage, but they do not produce or provide downloadable compliance certifications and formal reports. Official compliance artifacts, such as SOC reports and ISO certifications, are only available through AWS Artifact.

    When this WOULD be correct

    A company wants to check their AWS account against AWS best practices for security and receive actionable recommendations to improve their security posture, such as enabling MFA or closing security groups that are too permissive.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

AWS ArtifactCorrect answer

Why this is correct

AWS Artifact is the correct choice because it is a self-service portal that gives on-demand access to AWS compliance reports, including SOC, ISO, PCI, and FedRAMP documents. Customers can download these official reports directly without contacting AWS Support or provisioning any infrastructure. It also provides access to AWS agreements, such as the Business Associate Addendum (BAA), which are often required by audit teams.

AWS ConfigWrong answer — click to see why

Why this is wrong here

AWS Config is used for evaluating and auditing resource configurations, not for downloading compliance reports like SOC 2 or ISO 27001. It does not provide a centralized portal for accessing AWS compliance artifacts.

★ When this WOULD be the correct answer

A company needs to continuously monitor and record changes to AWS resource configurations, and automatically evaluate them against desired policies (e.g., ensuring S3 buckets are not publicly accessible). AWS Config would be the correct service for this scenario.

Why candidates choose this

Candidates may confuse 'audit' in the question with AWS Config's auditing capabilities, not realizing that AWS Artifact is the specific service for downloading compliance reports.

AWS Audit ManagerWrong answer — click to see why

Why this is wrong here

AWS Audit Manager helps continuously audit AWS usage to assess risk and compliance, but it does not provide a self-service portal to download AWS compliance reports like SOC 2 or ISO 27001. Those reports are obtained via AWS Artifact.

★ When this WOULD be the correct answer

A company needs to automate evidence collection for internal audits and continuously monitor compliance against frameworks like SOC 2 or ISO 27001. They want to schedule assessments and generate audit reports without manual effort.

Why candidates choose this

The name 'Audit Manager' suggests it manages audit-related documents, leading candidates to assume it provides compliance reports, but it focuses on automating audit evidence collection, not distributing AWS's own compliance artifacts.

AWS Trusted AdvisorWrong answer — click to see why

Why this is wrong here

AWS Trusted Advisor provides recommendations for cost optimization, performance, security, and fault tolerance, but it does not provide access to compliance reports like SOC 2 or ISO 27001 certificates.

★ When this WOULD be the correct answer

A company wants to check their AWS account against AWS best practices for security and receive actionable recommendations to improve their security posture, such as enabling MFA or closing security groups that are too permissive.

Why candidates choose this

Candidates may confuse Trusted Advisor's security checks with compliance documentation, assuming it provides reports needed for audits.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every CLF-C02 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

5 more ways this is tested on CLF-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company is preparing for a SOC 2 Type II audit and needs to provide its auditor with evidence of AWS's operational security controls. The security team has been asked to download the latest SOC 2 Type II report published by AWS. The team must access the report through a self-service portal without needing to contact AWS Support. Which AWS service should the security team use to meet this requirement?

medium
  • A.AWS Artifact
  • B.AWS Audit Manager
  • C.AWS Config
  • D.AWS Trusted Advisor

Why A: AWS Artifact is the correct service because it provides a self-service portal for downloading AWS compliance reports, including SOC 2 Type II reports, without needing to contact AWS Support. It offers on-demand access to AWS’s security and compliance documents, directly meeting the requirement for auditor evidence.

Variation 2. A company is preparing for a third-party security audit. The auditors require the company to provide up-to-date AWS compliance reports, such as the SOC 2 report and the ISO 27001 certificate, as part of the evidence. The company needs to access these documents from a centralized, self-service portal within their AWS account. They also need to accept the terms and conditions for the reports. Which AWS service should the company use to meet these requirements?

medium
  • A.AWS Config
  • B.AWS Artifact
  • C.AWS Security Hub
  • D.AWS CloudTrail

Why B: AWS Artifact is the correct service because it provides a centralized, self-service portal for accessing AWS compliance reports, such as SOC 2 and ISO 27001 certificates, directly within the AWS Management Console. It also allows users to accept the terms and conditions for these reports, fulfilling the audit requirements without needing to contact AWS support.

Variation 3. A company's compliance team is preparing documentation for a third-party audit. The auditor requires a copy of the AWS SOC 3 report, which provides an overview of AWS's security controls and is intended for public distribution. The team needs to securely download the most recent version of this report directly from AWS. Which AWS service should the team use?

easy
  • A.AWS Artifact
  • B.AWS Trusted Advisor
  • C.AWS Config
  • D.AWS CloudTrail

Why A: AWS Artifact is the correct service because it provides on-demand access to AWS compliance reports, including SOC reports, PCI reports, and ISO certifications. The SOC 3 report is specifically designed for public distribution, and AWS Artifact allows users to securely download the most recent version directly from AWS without needing to contact support or navigate third-party sites.

Variation 4. A company's external auditor requires the company to provide evidence that the AWS infrastructure used by the company meets SOC 2 and ISO 27001 standards. The company needs to download the latest AWS SOC 2 report and ISO 27001 certification to share with the auditor. Which AWS service or feature should the company use to retrieve these documents?

medium
  • A.AWS Audit Manager
  • B.AWS Artifact
  • C.AWS Config
  • D.AWS Trusted Advisor

Why B: AWS Artifact is the correct service because it provides on-demand access to AWS security and compliance reports, including SOC 2 and ISO 27001 certifications. The company can download the latest versions directly from the AWS Artifact console or API, satisfying the auditor's request for evidence without needing to configure any additional resources.

Variation 5. A company's compliance officer needs to provide an external auditor with copies of AWS SOC 2 reports and a PCI DSS attestation of compliance. The officer needs a self-service portal to download these documents directly, without contacting AWS Support. The solution must provide the most current versions of these reports. Which AWS service should the officer use?

easy
  • A.AWS Artifact
  • B.AWS Audit Manager
  • C.Amazon Inspector
  • D.AWS Config

Why A: AWS Artifact is the correct service because it provides a self-service portal for on-demand access to AWS compliance reports, including SOC 2 reports and PCI DSS attestations of compliance. It ensures the most current versions are always available without needing to contact AWS Support, directly meeting the compliance officer's requirement for a self-service download solution.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.