Courseiva
Security and CompliancemediumMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A company uses AWS Organizations to manage multiple accounts. The security team needs to enforce a consistent set of security group rules across all accounts. For example, they want to ensure that no security group in any account allows inbound SSH (port 22) from the internet (0.0.0.0/0). If a non-compliant security group is created, the service should automatically remediate by removing the offending rule or by applying a corrective policy. The company wants a managed AWS service that centrally applies these rules and requires no custom scripting. Which AWS service should the security team use?

⚠ Common exam trap

Test-takers frequently confuse AWS Config's compliance evaluation and remediation capabilities with Firewall Manager's centralized policy enforcement, forgetting that Config requires custom scripting for automatic remediation, whereas Firewall Manager provides it as a managed service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Firewall Manager

AWS Firewall Manager is the correct service because it provides a centralized, managed way to apply security group rules across all accounts in an AWS Organization. It can automatically detect non-compliant security groups (e.g., those allowing SSH from 0.0.0.0/0) and remediate them by removing the offending rule or applying a corrective policy, all without custom scripting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Firewall Manager

    Why this is correct

    AWS Firewall Manager is the correct service because it centralizes security policy management across all accounts in AWS Organizations. You can create a security group policy that defines an allowed inbound SSH CIDR baseline, and Firewall Manager will automatically enforce it by updating any non-compliant security groups, including those on newly created resources. It provides continuous monitoring and built-in remediation without requiring custom code or manual intervention, which exactly matches the need to enforce and remediate restrictive SSH access.

  • AWS Config

    Why it's wrong here

    Incorrect. AWS Config can evaluate resource configurations against rules and detect non-compliant security groups, but it does not provide automatic remediation out of the box without custom AWS Config rules and Lambda functions. The scenario requires a managed service that automatically enforces and remediates, which is a core capability of Firewall Manager.

    When this WOULD be correct

    AWS Config would be correct if the question required detecting non-compliant security group rules across accounts and optionally triggering custom remediation via AWS Systems Manager Automation or Lambda, but explicitly allowed custom scripting for remediation.

  • AWS Organizations

    Why it's wrong here

    Incorrect. AWS Organizations is a service for centrally managing multiple AWS accounts, including consolidated billing and policy-based management (Service Control Policies), but it does not directly enforce security group rules across accounts. Security group policies are handled by Firewall Manager.

    When this WOULD be correct

    A company needs to centrally manage multiple AWS accounts, apply service control policies (SCPs) to restrict permissions, or consolidate billing. In such a scenario, AWS Organizations would be the correct service.

  • AWS Shield Advanced

    Why it's wrong here

    Incorrect. AWS Shield Advanced is a managed DDoS protection service. It does not have capabilities to enforce or remediate security group rules. The scenario is about controlling inbound SSH access, not protecting against distributed denial-of-service attacks.

    When this WOULD be correct

    A company wants to protect its applications running on AWS from DDoS attacks, requiring advanced detection and mitigation, including cost protection against scaling charges. AWS Shield Advanced would be the correct choice.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

AWS Firewall ManagerCorrect answer

Why this is correct

AWS Firewall Manager is the correct service because it centralizes security policy management across all accounts in AWS Organizations. You can create a security group policy that defines an allowed inbound SSH CIDR baseline, and Firewall Manager will automatically enforce it by updating any non-compliant security groups, including those on newly created resources. It provides continuous monitoring and built-in remediation without requiring custom code or manual intervention, which exactly matches the need to enforce and remediate restrictive SSH access.

AWS ConfigWrong answer — click to see why

Why this is wrong here

AWS Config can detect non-compliant security group rules via managed rules, but it cannot automatically remediate them without custom AWS Config rules and custom Lambda functions, which violates the 'no custom scripting' requirement.

★ When this WOULD be the correct answer

AWS Config would be correct if the question required detecting non-compliant security group rules across accounts and optionally triggering custom remediation via AWS Systems Manager Automation or Lambda, but explicitly allowed custom scripting for remediation.

Why candidates choose this

Candidates often associate AWS Config with compliance monitoring and think its auto-remediation feature (SSM Automation) can fix rules without scripting, but that still requires custom automation documents, not a managed service.

AWS OrganizationsWrong answer — click to see why

Why this is wrong here

AWS Organizations is a service for centrally managing multiple AWS accounts, but it does not provide security group rule enforcement or remediation. It lacks the ability to automatically detect and fix non-compliant security groups.

★ When this WOULD be the correct answer

A company needs to centrally manage multiple AWS accounts, apply service control policies (SCPs) to restrict permissions, or consolidate billing. In such a scenario, AWS Organizations would be the correct service.

Why candidates choose this

Candidates may think that since AWS Organizations manages accounts centrally, it can also enforce security rules across accounts, but it only provides policy-based guardrails (SCPs) for IAM actions, not for security group configurations.

AWS Shield AdvancedWrong answer — click to see why

Why this is wrong here

AWS Shield Advanced is a managed DDoS protection service, not a service for centrally enforcing security group rules across accounts. It does not provide security group compliance or remediation capabilities.

★ When this WOULD be the correct answer

A company wants to protect its applications running on AWS from DDoS attacks, requiring advanced detection and mitigation, including cost protection against scaling charges. AWS Shield Advanced would be the correct choice.

Why candidates choose this

Candidates may confuse 'security' services and think Shield Advanced provides broader security management, or they may misread the question as focusing on network security rather than compliance enforcement.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CLF-C02 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.