Courseiva
Security and CompliancemediumMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A healthcare company is migrating patient records to Amazon S3. The company must comply with HIPAA and needs to automatically identify any S3 buckets that contain protected health information (PHI) and generate alerts. The solution must be fully managed and require no manual effort to scan the data. Which AWS service should the company use?

⚠ Common exam trap

A common mix-up: candidates confuse Amazon Inspector (which sounds like it 'inspects' data) with Macie, but Inspector only scans for vulnerabilities in compute resources, not for sensitive data content in S3 objects.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Amazon Macie

Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to discover, classify, and protect sensitive data in Amazon S3. It automatically identifies protected health information (PHI) such as medical record numbers, diagnosis codes, and patient names, and can generate alerts when such data is found in S3 buckets, meeting HIPAA compliance requirements without any manual scanning effort.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Amazon Macie

    Why this is correct

    Amazon Macie is the correct choice because it is a fully managed data security service that uses machine learning and managed data identifiers to automatically discover, classify, and protect sensitive data stored in Amazon S3. It can detect protected health information (PHI) without requiring manual scanning or custom pattern definitions, and it integrates with AWS Security Hub to centralize findings and alerting. Macie continuously monitors S3 buckets for anomalies and produces actionable findings, making it the only service here that directly inspects object content for sensitive data.

  • Amazon Inspector

    Why it's wrong here

    Amazon Inspector is incorrect because it is a vulnerability management service designed to scan Amazon EC2 instances and container images for software vulnerabilities, unintended network accessibility, and deviations from security best practices. It does not have the capability to examine the actual contents of S3 objects for PHI or any other sensitive data. Inspector's agent-based or agentless scans target compute workloads, not object storage, so it cannot fulfill the requirement to detect sensitive patient records during the S3 migration.

    When this WOULD be correct

    An exam question asking which AWS service can automatically assess EC2 instances for software vulnerabilities and unintended network exposure, with no manual scanning required.

  • AWS Config

    Why it's wrong here

    Incorrect. AWS Config is a service that evaluates and records the configuration of AWS resources, such as whether an S3 bucket is publicly accessible. It does not analyze the contents of S3 objects for sensitive data like PHI.

    When this WOULD be correct

    A company needs to continuously monitor and record changes to S3 bucket policies and ensure they comply with a custom rule (e.g., requiring encryption or blocking public access). AWS Config would be the correct service to track configuration changes and trigger alerts for non-compliant resources.

  • AWS Security Hub

    Why it's wrong here

    Incorrect. AWS Security Hub provides a centralized view of security alerts and compliance status across multiple AWS accounts. It can aggregate findings from Amazon Macie, but by itself it does not discover sensitive data in S3.

    When this WOULD be correct

    A company wants a single pane of glass to view and prioritize security alerts across multiple AWS accounts and services, including findings from Amazon GuardDuty, Amazon Inspector, and AWS Config. AWS Security Hub would be the correct service to aggregate and manage these findings centrally.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

Amazon MacieCorrect answer

Why this is correct

Amazon Macie is the correct choice because it is a fully managed data security service that uses machine learning and managed data identifiers to automatically discover, classify, and protect sensitive data stored in Amazon S3. It can detect protected health information (PHI) without requiring manual scanning or custom pattern definitions, and it integrates with AWS Security Hub to centralize findings and alerting. Macie continuously monitors S3 buckets for anomalies and produces actionable findings, making it the only service here that directly inspects object content for sensitive data.

Amazon InspectorWrong answer — click to see why

Why this is wrong here

Amazon Inspector is designed for vulnerability management and network security assessments of EC2 instances and container workloads, not for discovering or classifying sensitive data in S3 buckets.

★ When this WOULD be the correct answer

An exam question asking which AWS service can automatically assess EC2 instances for software vulnerabilities and unintended network exposure, with no manual scanning required.

Why candidates choose this

Candidates may confuse 'automatically identify' with vulnerability scanning, assuming Inspector's automated assessment extends to data classification in S3.

AWS ConfigWrong answer — click to see why

Why this is wrong here

AWS Config evaluates resource configurations against rules but does not automatically scan data content for PHI. It cannot identify protected health information within S3 objects, which is required for HIPAA compliance.

★ When this WOULD be the correct answer

A company needs to continuously monitor and record changes to S3 bucket policies and ensure they comply with a custom rule (e.g., requiring encryption or blocking public access). AWS Config would be the correct service to track configuration changes and trigger alerts for non-compliant resources.

Why candidates choose this

Candidates may confuse AWS Config's ability to monitor resource configurations with the need to scan data content, assuming that 'identify' includes data classification, but Config only checks metadata and settings, not object contents.

AWS Security HubWrong answer — click to see why

Why this is wrong here

AWS Security Hub aggregates security findings from multiple services but does not automatically scan S3 buckets for PHI. It relies on other services like Amazon Macie to provide such findings, so it cannot directly identify PHI in S3.

★ When this WOULD be the correct answer

A company wants a single pane of glass to view and prioritize security alerts across multiple AWS accounts and services, including findings from Amazon GuardDuty, Amazon Inspector, and AWS Config. AWS Security Hub would be the correct service to aggregate and manage these findings centrally.

Why candidates choose this

Candidates may think Security Hub provides comprehensive security monitoring including data classification, but it is a centralized dashboard that requires other services to generate findings, not a data scanning service itself.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CLF-C02 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.