CLF-C02 Security and Compliance Practice Question
A company uses multiple AWS accounts to store data in Amazon S3. The security team wants to enforce a policy that all S3 buckets must have server-side encryption enabled. The team needs a service that can continuously monitor all S3 bucket configurations across all accounts, automatically detect any bucket that does not have encryption enabled, and automatically apply the encryption setting to bring the bucket into compliance. Which AWS service should the team use?
⚠ Common exam trap
It's easy for candidates to confuse AWS Config's monitoring and remediation capabilities with AWS Security Hub's aggregation or Trusted Advisor's advisory checks, forgetting that only AWS Config can both detect and automatically fix non-compliant resource configurations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config is the correct service because it provides continuous monitoring and evaluation of AWS resource configurations against desired policies. Using a managed rule like 's3-bucket-server-side-encryption-enabled', AWS Config can automatically detect S3 buckets that lack server-side encryption and, through AWS Config rules with auto-remediation (via Systems Manager Automation or Lambda), automatically apply the encryption setting to bring non-compliant buckets into compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Config
Why this is correct
AWS Config is the correct service because it continuously records S3 bucket resource configurations and evaluates them against managed or custom rules, such as s3-bucket-server-side-encryption-enabled. When a bucket is non-compliant, AWS Config can trigger automatic remediation using SSM Automation documents to enable encryption, and it can aggregate compliance status across multiple accounts using a multi-account aggregator.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor is incorrect because it delivers best-practice checks and recommendations, including checks on S3 bucket permissions, but these checks are periodic and point-in-time rather than continuous configuration evaluations. It does not maintain a compliance timeline, does not execute automated remediation actions, and cannot enforce encryption requirements on every existing and newly created S3 bucket across multiple accounts.
When this WOULD be correct
A question asks: 'Which AWS service provides a dashboard of best-practice checks for cost optimization, performance, security, and fault tolerance across an AWS account?' In that scenario, AWS Trusted Advisor is the correct answer because it offers those checks and recommendations.
- ✗
AWS Security Hub
Why it's wrong here
AWS Security Hub is incorrect because it is a aggregation and prioritization service that ingests security findings from AWS Config, GuardDuty, and other sources, rather than evaluating resource configurations itself. While it can present S3 bucket encryption issues as findings and route them through EventBridge, it depends on AWS Config rules as the underlying detector and cannot directly change bucket encryption or apply remediation.
When this WOULD be correct
A company wants a single dashboard to view and prioritize security findings (e.g., from AWS Config, GuardDuty, Inspector) across multiple AWS accounts. Security Hub would be correct for aggregating and correlating security alerts, not for automatic remediation.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail is incorrect because it focuses on recording API activity, such as PutBucketEncryption or CreateBucket, for security investigation and operational auditing. It does not maintain a current snapshot of resource configuration and has no native mechanism to compare an S3 bucket against a desired compliance state or automatically fix a bucket that lacks encryption.
When this WOULD be correct
A question asking which service records all API calls made to S3 buckets for auditing purposes, such as tracking who created a bucket or changed its encryption settings, would have CloudTrail as the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓AWS ConfigCorrect answer▾
Why this is correct
AWS Config is the correct service because it continuously records S3 bucket resource configurations and evaluates them against managed or custom rules, such as s3-bucket-server-side-encryption-enabled. When a bucket is non-compliant, AWS Config can trigger automatic remediation using SSM Automation documents to enable encryption, and it can aggregate compliance status across multiple accounts using a multi-account aggregator.
✗AWS Trusted AdvisorWrong answer — click to see why▾
Why this is wrong here
AWS Trusted Advisor provides best-practice checks and recommendations, but it cannot automatically remediate non-compliant S3 buckets by applying encryption settings. It only offers manual or automated remediation for a limited set of checks, not including S3 bucket encryption.
★ When this WOULD be the correct answer
A question asks: 'Which AWS service provides a dashboard of best-practice checks for cost optimization, performance, security, and fault tolerance across an AWS account?' In that scenario, AWS Trusted Advisor is the correct answer because it offers those checks and recommendations.
Why candidates choose this
Candidates may think Trusted Advisor can enforce security policies because it includes security checks and can perform some automated actions, but they overlook that it does not support automatic remediation for S3 bucket encryption.
✗AWS Security HubWrong answer — click to see why▾
Why this is wrong here
AWS Security Hub aggregates security findings from multiple services but does not automatically remediate non-compliant S3 bucket encryption settings. It lacks the ability to automatically apply encryption; it only provides visibility and centralized alerts.
★ When this WOULD be the correct answer
A company wants a single dashboard to view and prioritize security findings (e.g., from AWS Config, GuardDuty, Inspector) across multiple AWS accounts. Security Hub would be correct for aggregating and correlating security alerts, not for automatic remediation.
Why candidates choose this
Candidates may think Security Hub can enforce encryption because it is a central security service, but it is primarily a findings aggregation and prioritization tool, not a configuration enforcement service.
✗AWS CloudTrailWrong answer — click to see why▾
Why this is wrong here
AWS CloudTrail records API activity but does not continuously monitor configurations or automatically remediate non-compliant resources like S3 buckets without encryption.
★ When this WOULD be the correct answer
A question asking which service records all API calls made to S3 buckets for auditing purposes, such as tracking who created a bucket or changed its encryption settings, would have CloudTrail as the correct answer.
Why candidates choose this
Candidates may confuse CloudTrail's logging of configuration changes with the ability to monitor and enforce compliance, not realizing it lacks automated remediation capabilities.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.