Courseiva
Security and CompliancemediumMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A healthcare company is migrating its application and patient data to AWS. To meet HIPAA requirements, the compliance officer must review and accept the AWS Business Associate Addendum (BAA). Additionally, the auditor requires the company to provide the latest AWS SOC 2 Type II report. The compliance officer needs a single self-service portal to access both documents directly from AWS. Which AWS service should the company use?

⚠ Common exam trap

Many candidates confuse AWS Artifact with AWS Config or Security Hub, thinking those services also provide compliance documentation, but only Artifact offers direct access to signed BAAs and third-party audit reports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Artifact

AWS Artifact is the correct service because it provides a self-service portal for on-demand access to AWS compliance reports, including the Business Associate Addendum (BAA) and SOC 2 Type II reports. This directly meets the compliance officer's requirement to review and accept the BAA and provide the latest SOC 2 report from a single AWS portal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Config

    Why it's wrong here

    AWS Config records and evaluates configuration changes of your AWS resources against custom or managed rules, enabling you to audit your resource configurations over time. While it can help you assess your internal compliance with your own policies, it does not give you access to AWS's third-party audit reports or legal agreements like the HIPAA BAA. It is a configuration management and governance tool, not a compliance document delivery service.

    When this WOULD be correct

    A company needs to continuously monitor and evaluate the configuration of its AWS resources against HIPAA security rules and receive automated notifications of non-compliant changes. AWS Config rules can assess resource configurations for compliance.

  • AWS Artifact

    Why this is correct

    AWS Artifact is the correct service. It is a self-service portal that provides on-demand access to AWS compliance reports (e.g., SOC, PCI) and allows customers to review and accept agreements such as the HIPAA Business Associate Addendum (BAA).

  • AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor provides best-practice recommendations for cost optimization, performance, security, fault tolerance, and service limits by inspecting your AWS environment. Its security checks focus on operational hygiene (e.g., MFA on root accounts, open network ports) rather than providing compliance evidence. It does not offer a catalog of AWS compliance reports, nor does it enable you to review and accept legal agreements such as the HIPAA BAA.

    When this WOULD be correct

    A company wants to check its AWS account against AWS best practices for security and cost optimization, and needs a dashboard that provides recommendations to improve its cloud posture. In that scenario, AWS Trusted Advisor would be the correct answer.

  • AWS Security Hub

    Why it's wrong here

    AWS Security Hub aggregates security findings and alerts from multiple AWS services and performs automated compliance checks against standards like CIS AWS Foundations and AWS Foundational Security Best Practices. It gives a unified view of your security posture but does not serve as a repository for AWS's own compliance reports or contractual documents. Accepting a Business Associate Addendum requires a separate portal dedicated to agreements and compliance artifacts, which Security Hub does not provide.

    When this WOULD be correct

    A company needs to centrally view and manage security findings from multiple AWS services, automate compliance checks against standards like CIS or PCI DSS, and receive aggregated security alerts. In that scenario, AWS Security Hub would be the correct service.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

AWS ArtifactCorrect answer

Why this is correct

AWS Artifact is the correct service. It is a self-service portal that provides on-demand access to AWS compliance reports (e.g., SOC, PCI) and allows customers to review and accept agreements such as the HIPAA Business Associate Addendum (BAA).

AWS ConfigWrong answer — click to see why

Why this is wrong here

AWS Config is used for resource inventory, configuration history, and compliance auditing of AWS resources, but it does not provide access to AWS Business Associate Addendum (BAA) or SOC reports.

★ When this WOULD be the correct answer

A company needs to continuously monitor and evaluate the configuration of its AWS resources against HIPAA security rules and receive automated notifications of non-compliant changes. AWS Config rules can assess resource configurations for compliance.

Why candidates choose this

Candidates may associate 'compliance' with AWS Config because it offers compliance checks, but they overlook that the question specifically requires a portal for accessing BAA and SOC reports, which is AWS Artifact's function.

AWS Trusted AdvisorWrong answer — click to see why

Why this is wrong here

AWS Trusted Advisor provides best practice recommendations for cost optimization, performance, security, and fault tolerance, but it does not provide access to compliance documents like the AWS BAA or SOC reports.

★ When this WOULD be the correct answer

A company wants to check its AWS account against AWS best practices for security and cost optimization, and needs a dashboard that provides recommendations to improve its cloud posture. In that scenario, AWS Trusted Advisor would be the correct answer.

Why candidates choose this

Candidates may confuse Trusted Advisor's security checks with compliance document access, assuming it covers all security and compliance needs in one place.

AWS Security HubWrong answer — click to see why

Why this is wrong here

AWS Security Hub provides a comprehensive view of security alerts and compliance status across AWS accounts, but it does not offer direct access to AWS Business Associate Addendum (BAA) or SOC 2 Type II reports. Those documents are available only through AWS Artifact.

★ When this WOULD be the correct answer

A company needs to centrally view and manage security findings from multiple AWS services, automate compliance checks against standards like CIS or PCI DSS, and receive aggregated security alerts. In that scenario, AWS Security Hub would be the correct service.

Why candidates choose this

Candidates may associate 'compliance' and 'security' with Security Hub, mistakenly thinking it provides access to compliance documents like BAA and SOC reports, rather than understanding that AWS Artifact is the dedicated portal for such documents.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This CLF-C02 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.