CLF-C02 Security and Compliance Practice Question
A financial services company is preparing for an annual compliance audit. The compliance team needs to continuously assess whether their AWS environment adheres to industry standards such as PCI DSS. They want to automate the collection of evidence, such as IAM policy changes and S3 bucket configurations, and generate audit-ready reports. They also need to identify gaps in their controls and receive remediation recommendations. Which AWS service should the company use?
⚠ Common exam trap
It's easy for candidates to confuse AWS Audit Manager with AWS Config or AWS Security Hub, but Audit Manager is the only service that combines automated evidence collection, framework-specific assessments, and remediation recommendations for compliance audits.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Audit Manager
AWS Audit Manager is the correct choice because it is specifically designed to continuously assess compliance with industry standards like PCI DSS. It automates the collection of evidence (e.g., IAM policy changes, S3 bucket configurations) and generates audit-ready reports, while also identifying control gaps and providing remediation recommendations. This directly matches the company's need for automated evidence collection and gap analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config
Why it's wrong here
AWS Config is a service for resource inventory, configuration change tracking, and compliance checks against rules, but it does not provide the automated evidence collection, framework mapping, or audit-ready reporting that Audit Manager offers. It can be part of an audit strategy but is not the primary service for this use case.
When this WOULD be correct
AWS Config would be correct if the question asked for a service that continuously monitors and records AWS resource configuration changes, evaluates them against custom or managed rules, and provides a configuration history for compliance auditing, without the need for automated report generation or remediation recommendations.
- ✓
AWS Audit Manager
Why this is correct
AWS Audit Manager helps you continuously assess your AWS usage to simplify risk assessment and compliance with regulations and industry standards. It automatically collects evidence from various AWS services, maps it to controls in frameworks like PCI DSS, and generates audit-ready reports. It also identifies control gaps and provides remediation recommendations.
- ✗
AWS Artifact
Why it's wrong here
AWS Artifact is a self-service portal for on-demand access to AWS compliance reports and agreements (e.g., SOC 2, PCI DSS). It does not collect evidence from the customer's own AWS environment or assess internal controls.
When this WOULD be correct
A company needs to download AWS compliance reports (e.g., SOC, PCI) or review and accept AWS agreements (e.g., Business Associate Addendum) for their own compliance documentation.
- ✗
AWS Security Hub
Why it's wrong here
AWS Security Hub provides a comprehensive view of security alerts and compliance status across accounts, aggregating findings from other services. While it offers some compliance checks, it is not designed for the detailed, automated evidence collection and reporting required for an audit, nor does it provide remediation recommendations tailored to control gaps for specific frameworks.
When this WOULD be correct
A company wants a single place to view and prioritize security findings from multiple AWS services (like Amazon GuardDuty, Amazon Inspector, and AWS Config) and check compliance against common standards like CIS AWS Foundations. They need a dashboard for security posture, not audit evidence collection.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓AWS Audit ManagerCorrect answer▾
Why this is correct
AWS Audit Manager helps you continuously assess your AWS usage to simplify risk assessment and compliance with regulations and industry standards. It automatically collects evidence from various AWS services, maps it to controls in frameworks like PCI DSS, and generates audit-ready reports. It also identifies control gaps and provides remediation recommendations.
✗AWS ConfigWrong answer — click to see why▾
Why this is wrong here
AWS Config is a service for evaluating resource configurations against rules, but it does not generate audit-ready reports or provide remediation recommendations for compliance frameworks like PCI DSS. The question specifically requires automated evidence collection and report generation, which is the purpose of AWS Audit Manager.
★ When this WOULD be the correct answer
AWS Config would be correct if the question asked for a service that continuously monitors and records AWS resource configuration changes, evaluates them against custom or managed rules, and provides a configuration history for compliance auditing, without the need for automated report generation or remediation recommendations.
Why candidates choose this
Candidates may confuse AWS Config's ability to track resource changes and evaluate rules with the more comprehensive compliance reporting and evidence collection capabilities of AWS Audit Manager, especially since both services are used in compliance scenarios.
✗AWS ArtifactWrong answer — click to see why▾
Why this is wrong here
AWS Artifact is a service for downloading compliance reports and agreements, not for automating evidence collection, continuous assessment, or generating audit-ready reports with remediation recommendations.
★ When this WOULD be the correct answer
A company needs to download AWS compliance reports (e.g., SOC, PCI) or review and accept AWS agreements (e.g., Business Associate Addendum) for their own compliance documentation.
Why candidates choose this
Candidates confuse Artifact's compliance reports with the automated evidence collection and gap analysis provided by Audit Manager, assuming Artifact can generate custom audit reports.
✗AWS Security HubWrong answer — click to see why▾
Why this is wrong here
AWS Security Hub provides a comprehensive view of security alerts and compliance status across AWS accounts, but it does not automate the collection of evidence for audit reports or generate audit-ready reports with remediation recommendations as required by the question.
★ When this WOULD be the correct answer
A company wants a single place to view and prioritize security findings from multiple AWS services (like Amazon GuardDuty, Amazon Inspector, and AWS Config) and check compliance against common standards like CIS AWS Foundations. They need a dashboard for security posture, not audit evidence collection.
Why candidates choose this
Candidates may confuse Security Hub's compliance checks (e.g., against CIS benchmarks) with the audit evidence collection and report generation capabilities of Audit Manager, especially since both involve compliance and security standards.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This CLF-C02 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.