CLF-C02 - Security and Compliance - Section 2.2

Identify AWS governance and compliance concepts, including where to find compliance reports with AWS Artifact and how compliance needs vary by geography and industry.

Describe AWS Artifact as the self-service portal for accessing on-demand AWS compliance reports and agreements, and recognise that applicable compliance frameworks vary by industry and geography. Use this understanding to identify which AWS tool to consult when a workload must meet a specific regulatory standard.

AWS ArtifactAWS ComplianceGovernanceCompliance programmes

Practice question for this objective

Free sampleSecurity and Compliancemedium

A legal team needs to download AWS audit artefacts such as the latest SOC 2 report and review and accept the AWS GDPR Data Processing Addendum, all on a self-service basis without contacting AWS sales. Which AWS service is designed to provide these compliance documents and agreements on demand?

  • AAWS Config, which records the configuration of account resources and reports whether each one complies with the rules the team has defined for governance
  • BAWS Trusted Advisor, which inspects the account and recommends improvements across cost, security, fault tolerance and service limits for the customer
  • CAWS CloudTrail, which records the API calls made in the account so the team can audit who performed each action and exactly when it happened
  • DAWS Artifact, the central portal where customers can review, download and accept AWS security and compliance reports and online agreements on demand Correct
AWS Artifact is the self-service portal for downloading AWS compliance reports and reviewing and accepting AWS legal agreements. AWS Artifact gives customers no-cost, on-demand access to AWS security and compliance documentation, including audit reports like SOC 2 and online agreements such as the GDPR Data Processing Addendum, so teams can satisfy auditors and accept terms without contacting AWS directly.

Why A is wrong: AWS Config governs internal resource configuration and compliance rules, but it does not host AWS audit reports or legal agreements such as the GDPR addendum for download.

Why B is wrong: Trusted Advisor produces best-practice recommendations about the customer's own account, not AWS third-party audit reports or signed compliance agreements.

Why C is wrong: CloudTrail logs account API activity for auditing actions, but it does not supply AWS compliance reports or legal agreements such as a data processing addendum.

Why D is correct: AWS Artifact is the self-service portal that gives customers on-demand access to AWS compliance reports such as SOC 2 and to agreements such as the AWS GDPR Data Processing Addendum.

See more CLF-C02 practice questions, answers explained.

More in this domain

Back to all Security and Compliance objectives, or the CLF-C02 cert hub.

Examworthy is not affiliated with or endorsed by Amazon Web Services. Original, blueprint-aligned practice material only.