CLF-C02 Security and Compliance Practice Question
A financial services company uses AWS CloudTrail to log all API calls in its AWS account. The company must demonstrate to auditors that the CloudTrail log files have not been tampered with after they were delivered to the Amazon S3 bucket. The company wants to use a feature that automatically creates digest files containing a hash of each log file, allowing the auditor to mathematically verify the integrity of the logs. Which AWS feature should the company enable to meet this requirement?
⚠ Common exam trap
Candidates often confuse S3 Object Lock's write-once-read-many (WORM) protection with cryptographic integrity validation, but Object Lock only prevents deletion/modification at the S3 layer and does not provide the hash-based digest chain needed for auditor verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CloudTrail log file integrity validation
CloudTrail log file integrity validation is the correct feature because it automatically creates digest files that contain a hash of each log file. These digest files are themselves signed using a private key, and the corresponding public key is published by AWS, enabling auditors to mathematically verify that the log files have not been tampered with after delivery to S3.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
S3 Object Lock
Why it's wrong here
S3 Object Lock prevents objects from being deleted or overwritten for a fixed retention period. While it helps with immutability, it does not generate cryptographic digest files that allow auditors to independently verify that log files have not been tampered with after delivery. The company needs a feature that provides verifiable integrity evidence, not just write-once-read-many (WORM) protection.
When this WOULD be correct
A company needs to prevent modification or deletion of critical S3 objects for a fixed retention period to meet regulatory compliance requirements, such as SEC Rule 17a-4.
- ✓
CloudTrail log file integrity validation
Why this is correct
CloudTrail log file integrity validation is a feature that automatically creates digest files containing the hash of each log file. These digests are signed using private keys from AWS Key Management Service (AWS KMS), enabling an auditor to verify that log files have not been altered or deleted. This feature is specifically designed for compliance scenarios that require cryptographic proof of log integrity.
- ✗
AWS Config conformance packs
Why it's wrong here
AWS Config conformance packs are collections of AWS Config rules and remediation actions used to evaluate whether resource configurations comply with internal policies or external regulations. They do not provide cryptographic verification of CloudTrail log files. They are used for ongoing compliance checks of resource configurations, not for post-delivery log integrity.
When this WOULD be correct
An organization needs to ensure that its AWS resources, such as EC2 instances or S3 buckets, comply with internal security policies (e.g., encryption enabled, tags applied). The auditor requires automated compliance checks and remediation. Enabling conformance packs would be the correct answer.
- ✗
Amazon Detective
Why it's wrong here
Amazon Detective analyzes AWS security data (e.g., VPC Flow Logs, CloudTrail logs, GuardDuty findings) to identify the root cause of potential security issues. It does not generate cryptographic digests or provide integrity verification for the log files themselves. Its purpose is investigation and analysis, not tamper-proof logging.
When this WOULD be correct
A company wants to automatically analyze and visualize security data to identify the root cause of suspicious activities across AWS resources, such as finding the source of an unauthorized API call. In that scenario, Amazon Detective would be the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓CloudTrail log file integrity validationCorrect answer▾
Why this is correct
CloudTrail log file integrity validation is a feature that automatically creates digest files containing the hash of each log file. These digests are signed using private keys from AWS Key Management Service (AWS KMS), enabling an auditor to verify that log files have not been altered or deleted. This feature is specifically designed for compliance scenarios that require cryptographic proof of log integrity.
✗S3 Object LockWrong answer — click to see why▾
Why this is wrong here
S3 Object Lock prevents objects from being deleted or overwritten, but it does not create digest files or provide cryptographic verification of log file integrity after delivery.
★ When this WOULD be the correct answer
A company needs to prevent modification or deletion of critical S3 objects for a fixed retention period to meet regulatory compliance requirements, such as SEC Rule 17a-4.
Why candidates choose this
Candidates may confuse data protection features, thinking that locking files ensures integrity, but integrity validation requires cryptographic hashing, not just write-once storage.
✗AWS Config conformance packsWrong answer — click to see why▾
Why this is wrong here
AWS Config conformance packs are used to evaluate whether your AWS resources comply with custom or predefined rules, not to verify the integrity of CloudTrail log files after delivery.
★ When this WOULD be the correct answer
An organization needs to ensure that its AWS resources, such as EC2 instances or S3 buckets, comply with internal security policies (e.g., encryption enabled, tags applied). The auditor requires automated compliance checks and remediation. Enabling conformance packs would be the correct answer.
Why candidates choose this
Candidates may confuse conformance packs with integrity validation because both involve auditing and compliance, but conformance packs focus on resource configuration rules, not log file tamper detection.
✗Amazon DetectiveWrong answer — click to see why▾
Why this is wrong here
Amazon Detective is used for analyzing and investigating security incidents by correlating data from multiple sources, but it does not create digest files or provide cryptographic verification of CloudTrail log file integrity.
★ When this WOULD be the correct answer
A company wants to automatically analyze and visualize security data to identify the root cause of suspicious activities across AWS resources, such as finding the source of an unauthorized API call. In that scenario, Amazon Detective would be the correct answer.
Why candidates choose this
Candidates may confuse Detective's security analysis capabilities with integrity validation, assuming it can verify log tampering because it deals with security data.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This CLF-C02 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CLF-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses AWS CloudTrail to log all API calls in their AWS account for compliance and security auditing. Their compliance officer needs to prove to an external auditor that the CloudTrail log files have not been altered or deleted after they were created. The company must use the most cost-effective and built-in AWS feature to detect any tampering with the log files. What should the company enable?
medium- ✓ A.Enable CloudTrail log file integrity validation
- B.Enable server-side encryption for the CloudTrail log file S3 bucket using SSE-KMS
- C.Configure CloudTrail to send logs to CloudWatch Logs and set a metric filter for changes
- D.Enable multi-factor authentication (MFA) delete on the S3 bucket
Why A: CloudTrail log file integrity validation uses a hash chain (SHA-256) to create a digest file that is signed with a private key, allowing you to verify that log files have not been modified, deleted, or tampered with after delivery. This is a built-in, no-cost feature that directly meets the compliance officer's requirement to prove log integrity to an external auditor without additional services or costs.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.