Courseiva
Security and ComplianceeasyMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A company stores financial reports in Amazon S3. The security team needs to automatically detect whether any of these reports contain sensitive data, such as personally identifiable information (PII) like credit card numbers or social security numbers. The team wants a fully managed service that continuously scans the S3 buckets and reports findings in a centralized dashboard. Which AWS service should the security team use to meet these requirements?

⚠ Common exam trap

AWS often tests the distinction between services that inspect resource configurations (AWS Config) versus those that inspect data content (Macie), and candidates may confuse Security Hub as a scanning service when it is actually an aggregator of findings from other services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Amazon Macie

Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data such as PII (e.g., credit card numbers, social security numbers) stored in Amazon S3. It continuously scans S3 buckets and provides a centralized dashboard for findings, meeting the requirement for automated detection and reporting without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Amazon Inspector

    Why it's wrong here

    Amazon Inspector is an automated vulnerability management service that focuses on compute resources, specifically EC2 instances and container images. It uses agent-based and agentless network reachability checks to identify software vulnerabilities, unintended network exposure, and deviations from security best practices at the host and network level. Inspector does not have visibility into the contents of S3 objects, so it cannot detect sensitive data such as PII or financial information stored in object bodies. Instead, Inspector's findings pertain to CVEs in operating systems and packages, not to data classification within storage.

    When this WOULD be correct

    An exam question asking for a service to automatically assess EC2 instances for software vulnerabilities and unintended network exposure would make Amazon Inspector the correct answer.

  • Amazon Macie

    Why this is correct

    Amazon Macie is designed to discover and protect sensitive data in S3. It automatically scans objects using ML and pattern matching to find PII, credentials, and other sensitive content, and provides findings in the Macie dashboard.

  • AWS Config

    Why it's wrong here

    AWS Config is a service that records and evaluates the configuration state of AWS resources against desired policies, enabling compliance auditing and change management. For S3, Config can check bucket-level settings such as public access blocks, bucket policies, encryption, and versioning, but it operates entirely on the control plane, meaning it analyzes metadata and configuration, not the actual data objects. Config does not perform content inspection or pattern matching on object bytes, so it cannot identify sensitive information like social security numbers or account numbers within financial reports. Therefore, while Config helps enforce governance and security posture, it lacks the data-aware detection capability needed for this use case.

    When this WOULD be correct

    AWS Config would be correct if the question asked for a service to monitor and enforce compliance rules on S3 bucket configurations (e.g., ensuring encryption is enabled or public access is blocked) and report non-compliant resources.

  • AWS Security Hub

    Why it's wrong here

    AWS Security Hub aggregates security alerts and compliance findings from multiple AWS services (including Macie) into a single dashboard. However, it does not itself scan S3 objects for sensitive data; it would consume Macie's findings.

    When this WOULD be correct

    A company wants a single dashboard to view and prioritize security alerts from multiple AWS services (e.g., Amazon GuardDuty, Amazon Inspector, Amazon Macie) and needs to enable automated compliance checks against security standards like CIS AWS Foundations. AWS Security Hub would be the correct answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

Amazon MacieCorrect answer

Why this is correct

Amazon Macie is designed to discover and protect sensitive data in S3. It automatically scans objects using ML and pattern matching to find PII, credentials, and other sensitive content, and provides findings in the Macie dashboard.

Amazon InspectorWrong answer — click to see why

Why this is wrong here

Amazon Inspector is designed for vulnerability management and network security assessments of EC2 instances and container workloads, not for scanning S3 objects for sensitive data like PII.

★ When this WOULD be the correct answer

An exam question asking for a service to automatically assess EC2 instances for software vulnerabilities and unintended network exposure would make Amazon Inspector the correct answer.

Why candidates choose this

Candidates may confuse Inspector's security scanning capabilities with data content scanning, assuming it can inspect any AWS resource for security issues.

AWS ConfigWrong answer — click to see why

Why this is wrong here

AWS Config is used for evaluating resource configurations against desired policies, not for scanning S3 objects for sensitive data like PII. It does not perform content inspection of objects.

★ When this WOULD be the correct answer

AWS Config would be correct if the question asked for a service to monitor and enforce compliance rules on S3 bucket configurations (e.g., ensuring encryption is enabled or public access is blocked) and report non-compliant resources.

Why candidates choose this

Candidates may confuse AWS Config's compliance monitoring with data scanning, as both involve 'checking' something, but Config checks resource settings, not object content.

AWS Security HubWrong answer — click to see why

Why this is wrong here

AWS Security Hub aggregates security findings from multiple AWS services but does not perform its own data scanning for sensitive content in S3. It relies on findings from services like Amazon Macie, so it cannot directly detect PII in financial reports.

★ When this WOULD be the correct answer

A company wants a single dashboard to view and prioritize security alerts from multiple AWS services (e.g., Amazon GuardDuty, Amazon Inspector, Amazon Macie) and needs to enable automated compliance checks against security standards like CIS AWS Foundations. AWS Security Hub would be the correct answer.

Why candidates choose this

Candidates may confuse Security Hub's centralized dashboard for security findings with the ability to detect sensitive data, assuming it has built-in scanning capabilities similar to Macie.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.