Courseiva
Security and CompliancemediumMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A company uses AWS Organizations to manage multiple AWS accounts. The security team must ensure that all API activity across all accounts, including any new accounts added in the future, is recorded and delivered to a centralized S3 bucket for auditing. The solution should require minimal ongoing manual effort. Which AWS feature should the security team use?

⚠ Common exam trap

Many exam-takers confuse AWS Config (which records configuration history) with CloudTrail (which records API activity), or assume that individual account trails with cross-account access are simpler, overlooking the automatic future-account coverage of an organization trail.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create an AWS CloudTrail organization trail that logs events for all accounts in the organization.

AWS CloudTrail organization trails automatically log events for all accounts in an AWS Organization, including any new accounts added in the future, and deliver them to a single S3 bucket without requiring per-account configuration. This satisfies the requirement for minimal ongoing manual effort and centralized auditing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable AWS CloudTrail in each account individually and configure the S3 bucket to allow cross-account access from the audit account.

    Why it's wrong here

    Individually enabling CloudTrail in every member account and configuring each trail to deliver to a shared S3 bucket does not scale to AWS Organizations. This approach requires manual setup and ongoing maintenance per account, including cross-account S3 bucket policies, and it will silently miss newly created accounts unless you remember to enable CloudTrail in each one. An organization trail, by contrast, is created once in the management account and automatically captures API activity for every current and future member account, eliminating the operational overhead.

    When this WOULD be correct

    If the company does not use AWS Organizations or needs to enable CloudTrail only for a subset of accounts that are not part of an organization, enabling per-account trails with cross-account S3 access would be appropriate.

  • Create an AWS CloudTrail organization trail that logs events for all accounts in the organization.

    Why this is correct

    An organization trail is a single trail that logs API activity for all current and future member accounts in AWS Organizations, automatically delivering logs to a centralized S3 bucket. This meets the requirements with minimal ongoing manual effort.

  • Use AWS Config to record API calls and deliver configuration history to an S3 bucket.

    Why it's wrong here

    AWS Config is a service for recording and evaluating changes to resource configurations over time; it is not an API activity logger. While AWS Config can integrate with AWS CloudTrail to supply some event data for rule evaluation, its primary output is configuration history and configuration snapshots, not a complete audit of every API call made in the account. Relying on AWS Config would therefore leave you without a centralized, authoritative record of who called which API, when, and with what result.

    When this WOULD be correct

    A question asks: 'A company needs to track configuration changes to AWS resources across multiple accounts and automatically remediate noncompliant resources. Which service should be used?' In that case, AWS Config with multi-account aggregation would be correct.

  • Set up Amazon GuardDuty to monitor API activity and send findings to a centralized S3 bucket.

    Why it's wrong here

    Amazon GuardDuty is a threat detection service that continuously monitors for suspicious behavior using VPC Flow Logs, DNS logs, and CloudTrail management events to generate security findings. It does not store or export the full set of raw API calls to an S3 bucket, and its findings are curated security alerts rather than a complete, tamper-evident audit trail. GuardDuty complements CloudTrail, but it cannot replace it for compliance-oriented auditing of all API activity.

    When this WOULD be correct

    A company wants to detect and alert on suspicious API activity across multiple accounts, with findings centralized in an S3 bucket for analysis. GuardDuty would be the correct choice for threat detection, not for comprehensive audit logging.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

Create an AWS CloudTrail organization trail that logs events for all accounts in the organization.Correct answer

Why this is correct

An organization trail is a single trail that logs API activity for all current and future member accounts in AWS Organizations, automatically delivering logs to a centralized S3 bucket. This meets the requirements with minimal ongoing manual effort.

Enable AWS CloudTrail in each account individually and configure the S3 bucket to allow cross-account access from the audit account.Wrong answer — click to see why

Why this is wrong here

This option requires manual effort to enable CloudTrail in each account individually and does not automatically include new accounts added in the future, violating the 'minimal ongoing manual effort' requirement.

★ When this WOULD be the correct answer

If the company does not use AWS Organizations or needs to enable CloudTrail only for a subset of accounts that are not part of an organization, enabling per-account trails with cross-account S3 access would be appropriate.

Why candidates choose this

Candidates may think that enabling CloudTrail per account and configuring cross-account access is a straightforward way to centralize logs, overlooking the automation benefits of an organization trail.

Use AWS Config to record API calls and deliver configuration history to an S3 bucket.Wrong answer — click to see why

Why this is wrong here

AWS Config records resource configuration changes, not API activity. It does not capture all API calls like CloudTrail, and it cannot guarantee delivery of all API events to a centralized S3 bucket for auditing.

★ When this WOULD be the correct answer

A question asks: 'A company needs to track configuration changes to AWS resources across multiple accounts and automatically remediate noncompliant resources. Which service should be used?' In that case, AWS Config with multi-account aggregation would be correct.

Why candidates choose this

Candidates may confuse AWS Config's ability to record configuration history with CloudTrail's API logging, or think Config can capture API calls because it integrates with CloudTrail for some features.

Set up Amazon GuardDuty to monitor API activity and send findings to a centralized S3 bucket.Wrong answer — click to see why

Why this is wrong here

Amazon GuardDuty is a threat detection service that monitors for malicious activity, not a service for recording all API activity for auditing. It does not deliver a complete log of all API calls to an S3 bucket.

★ When this WOULD be the correct answer

A company wants to detect and alert on suspicious API activity across multiple accounts, with findings centralized in an S3 bucket for analysis. GuardDuty would be the correct choice for threat detection, not for comprehensive audit logging.

Why candidates choose this

Candidates may confuse GuardDuty's monitoring capabilities with CloudTrail's logging, or think that 'monitor API activity' implies recording all API calls, when GuardDuty only analyzes for threats.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This CLF-C02 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.