Courseiva
Security and CompliancemediumMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A company uses multiple AWS accounts to store data in Amazon S3. The security team wants to enforce a policy that all S3 buckets must have server-side encryption enabled. The team needs a service that can continuously monitor all S3 bucket configurations across all accounts, automatically detect any bucket that does not have encryption enabled, and automatically apply the encryption setting to bring the bucket into compliance. Which AWS service should the team use?

⚠ Common exam trap

It's easy for candidates to confuse AWS Config's monitoring and remediation capabilities with AWS Security Hub's aggregation or Trusted Advisor's advisory checks, forgetting that only AWS Config can both detect and automatically fix non-compliant resource configurations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Config

AWS Config is the correct service because it provides continuous monitoring and evaluation of AWS resource configurations against desired policies. Using a managed rule like 's3-bucket-server-side-encryption-enabled', AWS Config can automatically detect S3 buckets that lack server-side encryption and, through AWS Config rules with auto-remediation (via Systems Manager Automation or Lambda), automatically apply the encryption setting to bring non-compliant buckets into compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Config

    Why this is correct

    AWS Config is the correct service because it continuously records S3 bucket resource configurations and evaluates them against managed or custom rules, such as s3-bucket-server-side-encryption-enabled. When a bucket is non-compliant, AWS Config can trigger automatic remediation using SSM Automation documents to enable encryption, and it can aggregate compliance status across multiple accounts using a multi-account aggregator.

  • AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor is incorrect because it delivers best-practice checks and recommendations, including checks on S3 bucket permissions, but these checks are periodic and point-in-time rather than continuous configuration evaluations. It does not maintain a compliance timeline, does not execute automated remediation actions, and cannot enforce encryption requirements on every existing and newly created S3 bucket across multiple accounts.

    When this WOULD be correct

    A question asks: 'Which AWS service provides a dashboard of best-practice checks for cost optimization, performance, security, and fault tolerance across an AWS account?' In that scenario, AWS Trusted Advisor is the correct answer because it offers those checks and recommendations.

  • AWS Security Hub

    Why it's wrong here

    AWS Security Hub is incorrect because it is a aggregation and prioritization service that ingests security findings from AWS Config, GuardDuty, and other sources, rather than evaluating resource configurations itself. While it can present S3 bucket encryption issues as findings and route them through EventBridge, it depends on AWS Config rules as the underlying detector and cannot directly change bucket encryption or apply remediation.

    When this WOULD be correct

    A company wants a single dashboard to view and prioritize security findings (e.g., from AWS Config, GuardDuty, Inspector) across multiple AWS accounts. Security Hub would be correct for aggregating and correlating security alerts, not for automatic remediation.

  • AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail is incorrect because it focuses on recording API activity, such as PutBucketEncryption or CreateBucket, for security investigation and operational auditing. It does not maintain a current snapshot of resource configuration and has no native mechanism to compare an S3 bucket against a desired compliance state or automatically fix a bucket that lacks encryption.

    When this WOULD be correct

    A question asking which service records all API calls made to S3 buckets for auditing purposes, such as tracking who created a bucket or changed its encryption settings, would have CloudTrail as the correct answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

AWS ConfigCorrect answer

Why this is correct

AWS Config is the correct service because it continuously records S3 bucket resource configurations and evaluates them against managed or custom rules, such as s3-bucket-server-side-encryption-enabled. When a bucket is non-compliant, AWS Config can trigger automatic remediation using SSM Automation documents to enable encryption, and it can aggregate compliance status across multiple accounts using a multi-account aggregator.

AWS Trusted AdvisorWrong answer — click to see why

Why this is wrong here

AWS Trusted Advisor provides best-practice checks and recommendations, but it cannot automatically remediate non-compliant S3 buckets by applying encryption settings. It only offers manual or automated remediation for a limited set of checks, not including S3 bucket encryption.

★ When this WOULD be the correct answer

A question asks: 'Which AWS service provides a dashboard of best-practice checks for cost optimization, performance, security, and fault tolerance across an AWS account?' In that scenario, AWS Trusted Advisor is the correct answer because it offers those checks and recommendations.

Why candidates choose this

Candidates may think Trusted Advisor can enforce security policies because it includes security checks and can perform some automated actions, but they overlook that it does not support automatic remediation for S3 bucket encryption.

AWS Security HubWrong answer — click to see why

Why this is wrong here

AWS Security Hub aggregates security findings from multiple services but does not automatically remediate non-compliant S3 bucket encryption settings. It lacks the ability to automatically apply encryption; it only provides visibility and centralized alerts.

★ When this WOULD be the correct answer

A company wants a single dashboard to view and prioritize security findings (e.g., from AWS Config, GuardDuty, Inspector) across multiple AWS accounts. Security Hub would be correct for aggregating and correlating security alerts, not for automatic remediation.

Why candidates choose this

Candidates may think Security Hub can enforce encryption because it is a central security service, but it is primarily a findings aggregation and prioritization tool, not a configuration enforcement service.

AWS CloudTrailWrong answer — click to see why

Why this is wrong here

AWS CloudTrail records API activity but does not continuously monitor configurations or automatically remediate non-compliant resources like S3 buckets without encryption.

★ When this WOULD be the correct answer

A question asking which service records all API calls made to S3 buckets for auditing purposes, such as tracking who created a bucket or changed its encryption settings, would have CloudTrail as the correct answer.

Why candidates choose this

Candidates may confuse CloudTrail's logging of configuration changes with the ability to monitor and enforce compliance, not realizing it lacks automated remediation capabilities.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.