CLF-C02 Security and Compliance Practice Question
A company stores financial reports in Amazon S3. The security team needs to automatically detect whether any of these reports contain sensitive data, such as personally identifiable information (PII) like credit card numbers or social security numbers. The team wants a fully managed service that continuously scans the S3 buckets and reports findings in a centralized dashboard. Which AWS service should the security team use to meet these requirements?
⚠ Common exam trap
AWS often tests the distinction between services that inspect resource configurations (AWS Config) versus those that inspect data content (Macie), and candidates may confuse Security Hub as a scanning service when it is actually an aggregator of findings from other services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Macie
Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data such as PII (e.g., credit card numbers, social security numbers) stored in Amazon S3. It continuously scans S3 buckets and provides a centralized dashboard for findings, meeting the requirement for automated detection and reporting without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is an automated vulnerability management service that focuses on compute resources, specifically EC2 instances and container images. It uses agent-based and agentless network reachability checks to identify software vulnerabilities, unintended network exposure, and deviations from security best practices at the host and network level. Inspector does not have visibility into the contents of S3 objects, so it cannot detect sensitive data such as PII or financial information stored in object bodies. Instead, Inspector's findings pertain to CVEs in operating systems and packages, not to data classification within storage.
When this WOULD be correct
An exam question asking for a service to automatically assess EC2 instances for software vulnerabilities and unintended network exposure would make Amazon Inspector the correct answer.
- ✓
Amazon Macie
Why this is correct
Amazon Macie is designed to discover and protect sensitive data in S3. It automatically scans objects using ML and pattern matching to find PII, credentials, and other sensitive content, and provides findings in the Macie dashboard.
- ✗
AWS Config
Why it's wrong here
AWS Config is a service that records and evaluates the configuration state of AWS resources against desired policies, enabling compliance auditing and change management. For S3, Config can check bucket-level settings such as public access blocks, bucket policies, encryption, and versioning, but it operates entirely on the control plane, meaning it analyzes metadata and configuration, not the actual data objects. Config does not perform content inspection or pattern matching on object bytes, so it cannot identify sensitive information like social security numbers or account numbers within financial reports. Therefore, while Config helps enforce governance and security posture, it lacks the data-aware detection capability needed for this use case.
When this WOULD be correct
AWS Config would be correct if the question asked for a service to monitor and enforce compliance rules on S3 bucket configurations (e.g., ensuring encryption is enabled or public access is blocked) and report non-compliant resources.
- ✗
AWS Security Hub
Why it's wrong here
AWS Security Hub aggregates security alerts and compliance findings from multiple AWS services (including Macie) into a single dashboard. However, it does not itself scan S3 objects for sensitive data; it would consume Macie's findings.
When this WOULD be correct
A company wants a single dashboard to view and prioritize security alerts from multiple AWS services (e.g., Amazon GuardDuty, Amazon Inspector, Amazon Macie) and needs to enable automated compliance checks against security standards like CIS AWS Foundations. AWS Security Hub would be the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓Amazon MacieCorrect answer▾
Why this is correct
Amazon Macie is designed to discover and protect sensitive data in S3. It automatically scans objects using ML and pattern matching to find PII, credentials, and other sensitive content, and provides findings in the Macie dashboard.
✗Amazon InspectorWrong answer — click to see why▾
Why this is wrong here
Amazon Inspector is designed for vulnerability management and network security assessments of EC2 instances and container workloads, not for scanning S3 objects for sensitive data like PII.
★ When this WOULD be the correct answer
An exam question asking for a service to automatically assess EC2 instances for software vulnerabilities and unintended network exposure would make Amazon Inspector the correct answer.
Why candidates choose this
Candidates may confuse Inspector's security scanning capabilities with data content scanning, assuming it can inspect any AWS resource for security issues.
✗AWS ConfigWrong answer — click to see why▾
Why this is wrong here
AWS Config is used for evaluating resource configurations against desired policies, not for scanning S3 objects for sensitive data like PII. It does not perform content inspection of objects.
★ When this WOULD be the correct answer
AWS Config would be correct if the question asked for a service to monitor and enforce compliance rules on S3 bucket configurations (e.g., ensuring encryption is enabled or public access is blocked) and report non-compliant resources.
Why candidates choose this
Candidates may confuse AWS Config's compliance monitoring with data scanning, as both involve 'checking' something, but Config checks resource settings, not object content.
✗AWS Security HubWrong answer — click to see why▾
Why this is wrong here
AWS Security Hub aggregates security findings from multiple AWS services but does not perform its own data scanning for sensitive content in S3. It relies on findings from services like Amazon Macie, so it cannot directly detect PII in financial reports.
★ When this WOULD be the correct answer
A company wants a single dashboard to view and prioritize security alerts from multiple AWS services (e.g., Amazon GuardDuty, Amazon Inspector, Amazon Macie) and needs to enable automated compliance checks against security standards like CIS AWS Foundations. AWS Security Hub would be the correct answer.
Why candidates choose this
Candidates may confuse Security Hub's centralized dashboard for security findings with the ability to detect sensitive data, assuming it has built-in scanning capabilities similar to Macie.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.