CLF-C02 Security and Compliance Practice Question
A company uses AWS Organizations to manage multiple AWS accounts. The security team must ensure that all API activity across all accounts, including any new accounts added in the future, is recorded and delivered to a centralized S3 bucket for auditing. The solution should require minimal ongoing manual effort. Which AWS feature should the security team use?
⚠ Common exam trap
Many exam-takers confuse AWS Config (which records configuration history) with CloudTrail (which records API activity), or assume that individual account trails with cross-account access are simpler, overlooking the automatic future-account coverage of an organization trail.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an AWS CloudTrail organization trail that logs events for all accounts in the organization.
AWS CloudTrail organization trails automatically log events for all accounts in an AWS Organization, including any new accounts added in the future, and deliver them to a single S3 bucket without requiring per-account configuration. This satisfies the requirement for minimal ongoing manual effort and centralized auditing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable AWS CloudTrail in each account individually and configure the S3 bucket to allow cross-account access from the audit account.
Why it's wrong here
Individually enabling CloudTrail in every member account and configuring each trail to deliver to a shared S3 bucket does not scale to AWS Organizations. This approach requires manual setup and ongoing maintenance per account, including cross-account S3 bucket policies, and it will silently miss newly created accounts unless you remember to enable CloudTrail in each one. An organization trail, by contrast, is created once in the management account and automatically captures API activity for every current and future member account, eliminating the operational overhead.
When this WOULD be correct
If the company does not use AWS Organizations or needs to enable CloudTrail only for a subset of accounts that are not part of an organization, enabling per-account trails with cross-account S3 access would be appropriate.
- ✓
Create an AWS CloudTrail organization trail that logs events for all accounts in the organization.
Why this is correct
An organization trail is a single trail that logs API activity for all current and future member accounts in AWS Organizations, automatically delivering logs to a centralized S3 bucket. This meets the requirements with minimal ongoing manual effort.
- ✗
Use AWS Config to record API calls and deliver configuration history to an S3 bucket.
Why it's wrong here
AWS Config is a service for recording and evaluating changes to resource configurations over time; it is not an API activity logger. While AWS Config can integrate with AWS CloudTrail to supply some event data for rule evaluation, its primary output is configuration history and configuration snapshots, not a complete audit of every API call made in the account. Relying on AWS Config would therefore leave you without a centralized, authoritative record of who called which API, when, and with what result.
When this WOULD be correct
A question asks: 'A company needs to track configuration changes to AWS resources across multiple accounts and automatically remediate noncompliant resources. Which service should be used?' In that case, AWS Config with multi-account aggregation would be correct.
- ✗
Set up Amazon GuardDuty to monitor API activity and send findings to a centralized S3 bucket.
Why it's wrong here
Amazon GuardDuty is a threat detection service that continuously monitors for suspicious behavior using VPC Flow Logs, DNS logs, and CloudTrail management events to generate security findings. It does not store or export the full set of raw API calls to an S3 bucket, and its findings are curated security alerts rather than a complete, tamper-evident audit trail. GuardDuty complements CloudTrail, but it cannot replace it for compliance-oriented auditing of all API activity.
When this WOULD be correct
A company wants to detect and alert on suspicious API activity across multiple accounts, with findings centralized in an S3 bucket for analysis. GuardDuty would be the correct choice for threat detection, not for comprehensive audit logging.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓Create an AWS CloudTrail organization trail that logs events for all accounts in the organization.Correct answer▾
Why this is correct
An organization trail is a single trail that logs API activity for all current and future member accounts in AWS Organizations, automatically delivering logs to a centralized S3 bucket. This meets the requirements with minimal ongoing manual effort.
✗Enable AWS CloudTrail in each account individually and configure the S3 bucket to allow cross-account access from the audit account.Wrong answer — click to see why▾
Why this is wrong here
This option requires manual effort to enable CloudTrail in each account individually and does not automatically include new accounts added in the future, violating the 'minimal ongoing manual effort' requirement.
★ When this WOULD be the correct answer
If the company does not use AWS Organizations or needs to enable CloudTrail only for a subset of accounts that are not part of an organization, enabling per-account trails with cross-account S3 access would be appropriate.
Why candidates choose this
Candidates may think that enabling CloudTrail per account and configuring cross-account access is a straightforward way to centralize logs, overlooking the automation benefits of an organization trail.
✗Use AWS Config to record API calls and deliver configuration history to an S3 bucket.Wrong answer — click to see why▾
Why this is wrong here
AWS Config records resource configuration changes, not API activity. It does not capture all API calls like CloudTrail, and it cannot guarantee delivery of all API events to a centralized S3 bucket for auditing.
★ When this WOULD be the correct answer
A question asks: 'A company needs to track configuration changes to AWS resources across multiple accounts and automatically remediate noncompliant resources. Which service should be used?' In that case, AWS Config with multi-account aggregation would be correct.
Why candidates choose this
Candidates may confuse AWS Config's ability to record configuration history with CloudTrail's API logging, or think Config can capture API calls because it integrates with CloudTrail for some features.
✗Set up Amazon GuardDuty to monitor API activity and send findings to a centralized S3 bucket.Wrong answer — click to see why▾
Why this is wrong here
Amazon GuardDuty is a threat detection service that monitors for malicious activity, not a service for recording all API activity for auditing. It does not deliver a complete log of all API calls to an S3 bucket.
★ When this WOULD be the correct answer
A company wants to detect and alert on suspicious API activity across multiple accounts, with findings centralized in an S3 bucket for analysis. GuardDuty would be the correct choice for threat detection, not for comprehensive audit logging.
Why candidates choose this
Candidates may confuse GuardDuty's monitoring capabilities with CloudTrail's logging, or think that 'monitor API activity' implies recording all API calls, when GuardDuty only analyzes for threats.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This CLF-C02 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.