CLF-C02 Security and Compliance Practice Question
A company uses multiple AWS accounts within AWS Organizations. The security team needs to automatically check that no Amazon S3 bucket in any account has public read or write access. They want to define a security rule once and have it evaluated continuously across all accounts. The team also needs to view the overall compliance status from a single dashboard. Which AWS service should they use to meet these requirements?
⚠ Common exam trap
Many candidates confuse AWS Config (which evaluates resource configurations against rules) with AWS Trusted Advisor (which provides best-practice checks but lacks custom rule definition and multi-account aggregation), leading them to select Trusted Advisor because it also checks S3 bucket permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config
AWS Config is the correct service because it provides managed rules (such as 's3-bucket-public-read-prohibited' and 's3-bucket-public-write-prohibited') that can be defined once in a delegated administrator account and automatically evaluated across all member accounts in AWS Organizations. It continuously monitors S3 bucket configurations and aggregates compliance results into a single dashboard (the AWS Config aggregator), meeting the requirement for a unified view of overall compliance status.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Config
Why this is correct
AWS Config is the correct answer because it provides continuous, detailed monitoring and evaluation of AWS resource configurations against desired policies and rules you define. It natively integrates with AWS Organizations, letting you deploy Config rules centrally across all member accounts and aggregate compliance results into a single dashboard via multi-account aggregators. This includes custom rules that can evaluate S3 bucket policies or any resource type, giving you enforcement clarity rather than just best-practice recommendations.
- ✗
AWS Trusted Advisor
Why it's wrong here
AWS Trusted Advisor offers best-practice checks, including S3 bucket permissions, but it does not allow you to define custom rules or aggregate compliance results across multiple accounts in a single dashboard. It provides recommendations, not continuous enforcement or custom policy evaluation.
When this WOULD be correct
A company wants a quick, no-configuration overview of their AWS account's adherence to AWS best practices, including S3 bucket public access checks, and they only need a summary report without custom rules or cross-account aggregation.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is wrong because it is a vulnerability management service focused on scanning Amazon EC2 instances and container images for software vulnerabilities and unintended network exposure. It does not inspect S3 bucket policies, nor does it provide centralized, multi-account compliance aggregation for resource configuration drift. Its role is proactive security assessment of compute workloads, not governance of account-wide resource settings.
When this WOULD be correct
An exam question where the requirement is to automatically assess EC2 instances for software vulnerabilities, unintended network exposure, or deviations from security best practices, and you need to view findings in a single dashboard.
- ✗
AWS Shield
Why it's wrong here
AWS Shield is wrong because it is a managed Distributed Denial of Service (DDoS) protection service that safeguards applications from network and transport layer attacks. It operates at the edge and network layers, and while it can protect S3-backed static content, it never evaluates S3 bucket access policies or resource configurations for compliance. There is no mechanism in Shield to define custom rules, aggregate compliance, or report on configuration drift across accounts.
When this WOULD be correct
A company wants to protect its web applications from DDoS attacks and needs a managed service that provides always-on detection and automatic mitigations. AWS Shield would be the correct answer in that scenario.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓AWS ConfigCorrect answer▾
Why this is correct
AWS Config is the correct answer because it provides continuous, detailed monitoring and evaluation of AWS resource configurations against desired policies and rules you define. It natively integrates with AWS Organizations, letting you deploy Config rules centrally across all member accounts and aggregate compliance results into a single dashboard via multi-account aggregators. This includes custom rules that can evaluate S3 bucket policies or any resource type, giving you enforcement clarity rather than just best-practice recommendations.
✗AWS Trusted AdvisorWrong answer — click to see why▾
Why this is wrong here
AWS Trusted Advisor provides best-practice checks, including S3 bucket permissions, but it does not allow you to define custom rules or evaluate compliance continuously across all accounts from a single dashboard. It also does not integrate with AWS Organizations to aggregate compliance status.
★ When this WOULD be the correct answer
A company wants a quick, no-configuration overview of their AWS account's adherence to AWS best practices, including S3 bucket public access checks, and they only need a summary report without custom rules or cross-account aggregation.
Why candidates choose this
Candidates may confuse Trusted Advisor's security checks (like S3 bucket permissions) with the ability to define and enforce custom rules, and they might overlook the requirement for custom rules and cross-account dashboard aggregation.
✗Amazon InspectorWrong answer — click to see why▾
Why this is wrong here
Amazon Inspector is designed for vulnerability management and network security assessments of EC2 instances and container workloads, not for evaluating S3 bucket policies or compliance across multiple accounts.
★ When this WOULD be the correct answer
An exam question where the requirement is to automatically assess EC2 instances for software vulnerabilities, unintended network exposure, or deviations from security best practices, and you need to view findings in a single dashboard.
Why candidates choose this
Candidates may confuse Inspector's security assessment capabilities with the broader compliance evaluation needed for S3 bucket policies, or assume it can check all AWS resources.
✗AWS ShieldWrong answer — click to see why▾
Why this is wrong here
AWS Shield is a managed DDoS protection service, not a configuration compliance or auditing tool. It does not check S3 bucket policies for public access or provide a compliance dashboard across multiple accounts.
★ When this WOULD be the correct answer
A company wants to protect its web applications from DDoS attacks and needs a managed service that provides always-on detection and automatic mitigations. AWS Shield would be the correct answer in that scenario.
Why candidates choose this
Candidates may confuse AWS Shield with a security service that monitors all types of security threats, including misconfigurations, due to its name implying broad protection.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CLF-C02 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.