CLF-C02 Security and Compliance Practice Question
A company stores sensitive customer data in multiple Amazon S3 buckets. The security team wants to proactively identify any buckets that have been configured to allow unintended access from external AWS accounts or from the public internet. The team needs a service that continuously analyzes the resource-based policies attached to these buckets and generates findings when such unintended access is detected. Which AWS service should the security team use to meet this requirement?
⚠ Common exam trap
Watch out — candidates often confuse AWS Config's ability to monitor resource configurations with IAM Access Analyzer's specific purpose of analyzing resource-based policies for cross-account and public access, leading them to choose Config when the requirement explicitly mentions 'resource-based policies' and 'unintended access from external AWS accounts or the public internet.'
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS IAM Access Analyzer
AWS IAM Access Analyzer is the correct service because it continuously analyzes resource-based policies (such as S3 bucket policies) to identify resources that are shared with external AWS accounts or publicly accessible. It generates findings for any policy that grants access to a principal outside of its AWS account, including the 'Principal': '*' condition that allows public internet access. This directly meets the requirement for proactive, continuous monitoring of unintended access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS IAM Access Analyzer
Why this is correct
AWS IAM Access Analyzer continuously analyzes resource-based policies—including S3 bucket policies, bucket ACLs, and access point policies—and uses automated reasoning to identify resources that are accessible from outside your intended account boundary. Unlike periodic checks, it generates a live, actionable list of findings for public access and cross-account access, updating as policies change, which makes it purpose-built for detecting unintended external access. It also provides policy recommendations to help you narrow over-permissive access, directly addressing the requirement in the scenario.
- ✗
AWS Config
Why it's wrong here
Incorrect. AWS Config evaluates your AWS resource configurations against desired rules and tracks configuration changes over time. While it can be used to detect non-compliant S3 bucket policies, it does not proactively analyze policies for unintended cross-account or public access in the same way as IAM Access Analyzer. Access Analyzer is more targeted for this specific requirement.
- ✗
AWS Trusted Advisor
Why it's wrong here
Incorrect. AWS Trusted Advisor provides a check for S3 buckets with open access permissions, but it is a point-in-time check that updates periodically, not a continuous, findings-based service. It also does not analyze access from specific external AWS accounts. IAM Access Analyzer offers more granular and continuous detection.
When this WOULD be correct
A company wants a one-time review of their AWS account to identify cost optimization opportunities, performance improvements, security gaps (like public S3 buckets), and service limits. AWS Trusted Advisor would be the correct service for this advisory assessment.
- ✗
Amazon Macie
Why it's wrong here
Incorrect. Amazon Macie uses machine learning and pattern matching to discover and protect sensitive data within S3 buckets, such as personally identifiable information (PII). It does not analyze resource policies for unintended access permissions. The requirement is about policy analysis, not content inspection.
When this WOULD be correct
A company needs to automatically discover and classify sensitive data (e.g., PII, financial data) stored in S3 buckets and monitor for data leaks or policy violations. Macie would be the correct service to use.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓AWS IAM Access AnalyzerCorrect answer▾
Why this is correct
AWS IAM Access Analyzer continuously analyzes resource-based policies—including S3 bucket policies, bucket ACLs, and access point policies—and uses automated reasoning to identify resources that are accessible from outside your intended account boundary. Unlike periodic checks, it generates a live, actionable list of findings for public access and cross-account access, updating as policies change, which makes it purpose-built for detecting unintended external access. It also provides policy recommendations to help you narrow over-permissive access, directly addressing the requirement in the scenario.
✗AWS Trusted AdvisorWrong answer — click to see why▾
Why this is wrong here
AWS Trusted Advisor checks S3 bucket permissions for public access but does not continuously analyze resource-based policies for unintended access from external AWS accounts; it only provides a point-in-time check for public access.
★ When this WOULD be the correct answer
A company wants a one-time review of their AWS account to identify cost optimization opportunities, performance improvements, security gaps (like public S3 buckets), and service limits. AWS Trusted Advisor would be the correct service for this advisory assessment.
Why candidates choose this
Candidates may confuse Trusted Advisor's security checks for S3 bucket public access with the continuous, policy-based analysis needed for unintended access from external accounts, assuming it covers all access scenarios.
✗Amazon MacieWrong answer — click to see why▾
Why this is wrong here
Amazon Macie is designed to discover and protect sensitive data using machine learning and pattern matching, not to analyze resource-based policies for unintended access from external accounts or the public internet.
★ When this WOULD be the correct answer
A company needs to automatically discover and classify sensitive data (e.g., PII, financial data) stored in S3 buckets and monitor for data leaks or policy violations. Macie would be the correct service to use.
Why candidates choose this
Candidates may associate Macie with S3 security and data protection, mistakenly thinking it also handles policy analysis for unintended access.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CLF-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company's security team wants to identify all Amazon S3 buckets that are shared with external AWS accounts or publicly accessible. The team needs a continuous evaluation that reports findings in a centralized dashboard and sends alerts when new unintended external shares are created. Which AWS service should the security team use to meet these requirements?
medium- A.AWS Config
- ✓ B.IAM Access Analyzer
- C.AWS Trusted Advisor
- D.Amazon GuardDuty
Why B: IAM Access Analyzer is the correct choice because it continuously monitors resource policies, including S3 bucket policies, to identify resources shared with external AWS accounts or publicly. It provides a centralized dashboard in the IAM console to view findings and integrates with Amazon EventBridge to send alerts via Amazon SNS when new unintended external shares are created, meeting all stated requirements.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.