CLF-C02 - Security and Compliance (30% of the exam) - Section 2.2

Identify AWS governance and compliance concepts, including where to find compliance reports with AWS Artifact and how compliance needs vary by geography and industry.

Describe AWS Artifact as the self-service portal for accessing on-demand AWS compliance reports and agreements, and recognise that applicable compliance frameworks vary by industry and geography. Use this understanding to identify which AWS tool to consult when a workload must meet a specific regulatory standard.

AWS ArtifactAWS ComplianceGovernanceCompliance programmes

Practice question for this objective

Free sampleSecurity and Compliancemedium

A legal team needs to download AWS audit artefacts such as the latest SOC 2 report and review and accept the AWS GDPR Data Processing Addendum, all on a self-service basis without contacting AWS sales. Which AWS service is designed to provide these compliance documents and agreements on demand?

  • AAWS Config, which records the configuration of account resources and reports whether each one complies with the rules the team has defined for governance
  • BAWS Trusted Advisor, which inspects the account and recommends improvements across cost, security, fault tolerance and service limits for the customer
  • CAWS CloudTrail, which records the API calls made in the account so the team can audit who performed each action and exactly when it happened
  • DAWS Artifact, the central portal where customers can review, download and accept AWS security and compliance reports and online agreements on demand Correct
AWS Artifact is the self-service portal for downloading AWS compliance reports and reviewing and accepting AWS legal agreements. AWS Artifact gives customers no-cost, on-demand access to AWS security and compliance documentation, including audit reports like SOC 2 and online agreements such as the GDPR Data Processing Addendum, so teams can satisfy auditors and accept terms without contacting AWS directly.

Why A is wrong: AWS Config governs internal resource configuration and compliance rules, but it does not host AWS audit reports or legal agreements such as the GDPR addendum for download.

Why B is wrong: Trusted Advisor produces best-practice recommendations about the customer's own account, not AWS third-party audit reports or signed compliance agreements.

Why C is wrong: CloudTrail logs account API activity for auditing actions, but it does not supply AWS compliance reports or legal agreements such as a data processing addendum.

Why D is correct: AWS Artifact is the self-service portal that gives customers on-demand access to AWS compliance reports such as SOC 2 and to agreements such as the AWS GDPR Data Processing Addendum.

See more CLF-C02 practice questions, answers explained.

Exam traps in Security and Compliance

Answers that look right on this material and are not. Each one is a distractor from a different question in the CLF-C02 bank for this domain.

  • Amazon CloudWatch supplies the third-party audit reports and certifications that auditors require to confirm AWS meets recognised standards.

    Why it is wrong: CloudWatch sounds plausible as a monitoring tool, but it collects metrics and logs and does not supply AWS audit reports or certifications.

  • AWS Artifact continuously evaluates the configuration of the customer's resources and flags any that drift away from the organisation's approved internal rules

    Why it is wrong: Continuously evaluating resource configuration against internal rules describes AWS Config, not AWS Artifact, so this confuses the two governance services.

  • AWS Trusted Advisor, which inspects an account and recommends fixes for cost, security and fault tolerance

    Why it is wrong: Trusted Advisor gives best-practice checks on the account, but it does not host AWS audit reports, so it cannot supply the SOC 2 or PCI DSS documents.

Examworthy is not affiliated with or endorsed by Amazon Web Services. Original, blueprint-aligned practice material only.