Courseiva
Security and CompliancemediumMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A company uses multiple AWS accounts within AWS Organizations. The security team needs to automatically check that no Amazon S3 bucket in any account has public read or write access. They want to define a security rule once and have it evaluated continuously across all accounts. The team also needs to view the overall compliance status from a single dashboard. Which AWS service should they use to meet these requirements?

⚠ Common exam trap

Many candidates confuse AWS Config (which evaluates resource configurations against rules) with AWS Trusted Advisor (which provides best-practice checks but lacks custom rule definition and multi-account aggregation), leading them to select Trusted Advisor because it also checks S3 bucket permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Config

AWS Config is the correct service because it provides managed rules (such as 's3-bucket-public-read-prohibited' and 's3-bucket-public-write-prohibited') that can be defined once in a delegated administrator account and automatically evaluated across all member accounts in AWS Organizations. It continuously monitors S3 bucket configurations and aggregates compliance results into a single dashboard (the AWS Config aggregator), meeting the requirement for a unified view of overall compliance status.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Config

    Why this is correct

    AWS Config is the correct answer because it provides continuous, detailed monitoring and evaluation of AWS resource configurations against desired policies and rules you define. It natively integrates with AWS Organizations, letting you deploy Config rules centrally across all member accounts and aggregate compliance results into a single dashboard via multi-account aggregators. This includes custom rules that can evaluate S3 bucket policies or any resource type, giving you enforcement clarity rather than just best-practice recommendations.

  • AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor offers best-practice checks, including S3 bucket permissions, but it does not allow you to define custom rules or aggregate compliance results across multiple accounts in a single dashboard. It provides recommendations, not continuous enforcement or custom policy evaluation.

    When this WOULD be correct

    A company wants a quick, no-configuration overview of their AWS account's adherence to AWS best practices, including S3 bucket public access checks, and they only need a summary report without custom rules or cross-account aggregation.

  • Amazon Inspector

    Why it's wrong here

    Amazon Inspector is wrong because it is a vulnerability management service focused on scanning Amazon EC2 instances and container images for software vulnerabilities and unintended network exposure. It does not inspect S3 bucket policies, nor does it provide centralized, multi-account compliance aggregation for resource configuration drift. Its role is proactive security assessment of compute workloads, not governance of account-wide resource settings.

    When this WOULD be correct

    An exam question where the requirement is to automatically assess EC2 instances for software vulnerabilities, unintended network exposure, or deviations from security best practices, and you need to view findings in a single dashboard.

  • AWS Shield

    Why it's wrong here

    AWS Shield is wrong because it is a managed Distributed Denial of Service (DDoS) protection service that safeguards applications from network and transport layer attacks. It operates at the edge and network layers, and while it can protect S3-backed static content, it never evaluates S3 bucket access policies or resource configurations for compliance. There is no mechanism in Shield to define custom rules, aggregate compliance, or report on configuration drift across accounts.

    When this WOULD be correct

    A company wants to protect its web applications from DDoS attacks and needs a managed service that provides always-on detection and automatic mitigations. AWS Shield would be the correct answer in that scenario.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

AWS ConfigCorrect answer

Why this is correct

AWS Config is the correct answer because it provides continuous, detailed monitoring and evaluation of AWS resource configurations against desired policies and rules you define. It natively integrates with AWS Organizations, letting you deploy Config rules centrally across all member accounts and aggregate compliance results into a single dashboard via multi-account aggregators. This includes custom rules that can evaluate S3 bucket policies or any resource type, giving you enforcement clarity rather than just best-practice recommendations.

AWS Trusted AdvisorWrong answer — click to see why

Why this is wrong here

AWS Trusted Advisor provides best-practice checks, including S3 bucket permissions, but it does not allow you to define custom rules or evaluate compliance continuously across all accounts from a single dashboard. It also does not integrate with AWS Organizations to aggregate compliance status.

★ When this WOULD be the correct answer

A company wants a quick, no-configuration overview of their AWS account's adherence to AWS best practices, including S3 bucket public access checks, and they only need a summary report without custom rules or cross-account aggregation.

Why candidates choose this

Candidates may confuse Trusted Advisor's security checks (like S3 bucket permissions) with the ability to define and enforce custom rules, and they might overlook the requirement for custom rules and cross-account dashboard aggregation.

Amazon InspectorWrong answer — click to see why

Why this is wrong here

Amazon Inspector is designed for vulnerability management and network security assessments of EC2 instances and container workloads, not for evaluating S3 bucket policies or compliance across multiple accounts.

★ When this WOULD be the correct answer

An exam question where the requirement is to automatically assess EC2 instances for software vulnerabilities, unintended network exposure, or deviations from security best practices, and you need to view findings in a single dashboard.

Why candidates choose this

Candidates may confuse Inspector's security assessment capabilities with the broader compliance evaluation needed for S3 bucket policies, or assume it can check all AWS resources.

AWS ShieldWrong answer — click to see why

Why this is wrong here

AWS Shield is a managed DDoS protection service, not a configuration compliance or auditing tool. It does not check S3 bucket policies for public access or provide a compliance dashboard across multiple accounts.

★ When this WOULD be the correct answer

A company wants to protect its web applications from DDoS attacks and needs a managed service that provides always-on detection and automatic mitigations. AWS Shield would be the correct answer in that scenario.

Why candidates choose this

Candidates may confuse AWS Shield with a security service that monitors all types of security threats, including misconfigurations, due to its name implying broad protection.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CLF-C02 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.