Courseiva
Security and ComplianceeasyMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A retail company processes credit card payments and must comply with the Payment Card Industry Data Security Standard (PCI DSS). The company's compliance officer needs to obtain an official document from AWS that details the security controls AWS has implemented to support PCI DSS compliance for services such as Amazon RDS and Amazon EC2. The document must be downloadable as a PDF for review and audit purposes. Which AWS service should the compliance officer use to retrieve this document?

⚠ Common exam trap

Many exam-takers confuse AWS Security Hub’s ability to run PCI DSS automated checks with the need to obtain the official AWS PCI DSS attestation document, which is only available through AWS Artifact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Artifact

AWS Artifact is the correct service because it provides on-demand access to AWS compliance reports and security documents, including the PCI DSS compliance attestation and responsibility summary. The compliance officer can download the AWS PCI DSS compliance package as a PDF directly from the AWS Artifact console, which is specifically designed for audit and review purposes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Security Hub

    Why it's wrong here

    AWS Security Hub provides a centralized view of security alerts and compliance status across AWS accounts, but it does not produce or provide downloadable compliance reports from AWS itself. It aggregates findings from other services like Amazon GuardDuty and AWS Config.

    When this WOULD be correct

    A company wants to centrally view and manage security findings from multiple AWS services, such as Amazon GuardDuty and Amazon Inspector, and check overall compliance against standards like CIS AWS Foundations. AWS Security Hub would be the correct service to aggregate and prioritize these security alerts.

  • AWS Artifact

    Why this is correct

    AWS Artifact is the correct service because it is the central repository for AWS's own compliance reports, including PCI DSS, SOC 1/2/3, ISO 27001, and FedRAMP. Users can browse and download these PDF documents on demand, and also manage agreements like the Business Associate Addendum (BAA) for regulated workloads. This directly satisfies the audit requirement to obtain AWS's certifications and attestations without needing to request them from support or search through scattered documentation.

  • AWS Config

    Why it's wrong here

    AWS Config continuously evaluates AWS resource configurations against desired policies and generates compliance snapshots. However, it does not provide AWS's own compliance certifications or reports. It is used for monitoring resource compliance, not for retrieving AWS compliance documentation.

    When this WOULD be correct

    A company needs to continuously monitor and evaluate the configuration of their AWS resources against internal policies or regulatory standards (e.g., ensuring EC2 instances have encryption enabled). AWS Config would be the correct service to set up rules and receive compliance notifications.

  • AWS Trusted Advisor

    Why it's wrong here

    AWS Trusted Advisor is incorrect because it does not produce or issue any AWS compliance certifications or reports. Rather, it inspects your specific AWS account and resources, using a set of checks to flag potential cost savings, performance bottlenecks, security misconfigurations, and service limit usage. It provides real-time recommendations about your own environment, but it cannot generate the PCI DSS or SOC documentation that an auditor requires, so it is not a substitute for AWS Artifact.

    When this WOULD be correct

    A company wants to check its AWS account against AWS best practices for security (e.g., whether security groups are overly permissive) and receive actionable recommendations. The compliance officer would use AWS Trusted Advisor to identify potential security risks and improve the account's security posture.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

AWS ArtifactCorrect answer

Why this is correct

AWS Artifact is the correct service because it is the central repository for AWS's own compliance reports, including PCI DSS, SOC 1/2/3, ISO 27001, and FedRAMP. Users can browse and download these PDF documents on demand, and also manage agreements like the Business Associate Addendum (BAA) for regulated workloads. This directly satisfies the audit requirement to obtain AWS's certifications and attestations without needing to request them from support or search through scattered documentation.

AWS Security HubWrong answer — click to see why

Why this is wrong here

AWS Security Hub provides a comprehensive view of security alerts and compliance status across accounts, but it does not offer downloadable PDFs of AWS compliance reports like PCI DSS. The question specifically requires an official document that can be downloaded as a PDF, which is a feature of AWS Artifact.

★ When this WOULD be the correct answer

A company wants to centrally view and manage security findings from multiple AWS services, such as Amazon GuardDuty and Amazon Inspector, and check overall compliance against standards like CIS AWS Foundations. AWS Security Hub would be the correct service to aggregate and prioritize these security alerts.

Why candidates choose this

Candidates may associate Security Hub with compliance because it provides compliance checks and security best practice scores, leading them to mistakenly believe it can generate official compliance documents like PCI DSS reports.

AWS ConfigWrong answer — click to see why

Why this is wrong here

AWS Config is used for resource inventory, configuration history, and compliance auditing against custom rules, not for providing official AWS compliance reports or downloadable PDFs like PCI DSS documentation.

★ When this WOULD be the correct answer

A company needs to continuously monitor and evaluate the configuration of their AWS resources against internal policies or regulatory standards (e.g., ensuring EC2 instances have encryption enabled). AWS Config would be the correct service to set up rules and receive compliance notifications.

Why candidates choose this

Candidates may confuse 'compliance' in the question with AWS Config's compliance evaluation feature, not realizing that AWS Artifact is the specific service for accessing official compliance reports and agreements.

AWS Trusted AdvisorWrong answer — click to see why

Why this is wrong here

AWS Trusted Advisor provides recommendations for cost optimization, performance, security, and fault tolerance, but it does not provide downloadable compliance reports or official documents like PCI DSS attestation PDFs.

★ When this WOULD be the correct answer

A company wants to check its AWS account against AWS best practices for security (e.g., whether security groups are overly permissive) and receive actionable recommendations. The compliance officer would use AWS Trusted Advisor to identify potential security risks and improve the account's security posture.

Why candidates choose this

Candidates may think Trusted Advisor covers compliance because it includes security checks, but it does not produce official compliance documents like AWS Artifact does.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.