GregLab | Exam Prep

Security and Compliance

Governance, Compliance, Encryption, and Audit Evidence

Core

Connect compliance evidence, data protection, resource governance, operational monitoring, API history, configuration history, and security findings to the right AWS capability.

Aligned to the current CLF-C02 exam guide, verified August 15, 2026.

Why this matters

CLF-C02 expects high-level service selection and sound compliance reasoning. Learners should know both where AWS evidence is found and which responsibilities remain with the customer.

Must Know

  • AWS Artifact is the self-service location for AWS compliance documents such as third-party reports and certifications.
  • The customer must determine whether a service, Region, configuration, and operating process satisfy the relevant geographic or industry requirement.
  • AWS KMS manages encryption keys used by integrated AWS services; AWS Certificate Manager manages supported public and private certificates; AWS CloudHSM supplies dedicated hardware security modules.
  • CloudWatch answers how a resource or application is behaving. CloudTrail answers who or what called an AWS API. Config answers how a supported resource was configured and whether it meets a rule.
  • GuardDuty, Inspector, Security Hub, and Shield address different security needs: threat detection, vulnerability management, consolidated posture/findings, and DDoS protection.
  • Governance capabilities help establish, observe, and evaluate controls; they do not remove the customer's accountability for configuration and compliance.

Compare and Distinguish

  • Artifact vs Config: Artifact supplies AWS compliance reports; Config records customer resource configurations and evaluates them against rules.
  • CloudWatch vs CloudTrail vs Config: operational behavior, AWS API activity, and resource configuration history are three different evidence types.
  • KMS vs ACM vs CloudHSM: KMS manages encryption keys, ACM manages certificates, and CloudHSM provides customer-controlled dedicated hardware security modules.
  • GuardDuty vs Inspector vs Security Hub: suspicious activity, vulnerabilities/exposure, and aggregated findings/posture are neighboring but distinct jobs.
  • AWS certification vs customer compliance: AWS evidence supports a customer assessment, but the customer must configure and operate its workload in accordance with applicable requirements.

Scenario examples

  • Scenario: An assessor requests an AWS SOC report. Think: Retrieve the AWS report from AWS Artifact, then evaluate the customer controls separately.
  • Scenario: A security analyst wants to know which identity deleted a resource. Think: AWS CloudTrail records the relevant AWS API activity.
  • Scenario: A team wants an alarm when CPU utilization crosses a threshold. Think: Amazon CloudWatch monitors metrics and alarms.
  • Scenario: A company must determine when a security group stopped meeting an approved rule. Think: AWS Config records configuration history and evaluates configuration rules.
  • Scenario: Stored data needs encryption with centrally controlled keys. Think: AWS KMS manages keys and integrates with many AWS services.

Exam traps

  • Artifact is a document portal, not a continuous resource-control or findings service.
  • CloudTrail is not the default answer for performance metrics, and CloudWatch is not the default answer for the identity behind an API call.
  • AWS service eligibility for one program or Region does not imply that every service and Region has identical compliance coverage.
  • Security Hub consolidates findings; it does not replace the source services that detect threats or vulnerabilities.
  • Backups and access controls complement encryption but are not synonyms for encryption at rest or in transit.

Key takeaways

  • Artifact provides AWS compliance documents; customers retain workload compliance duties.
  • At rest means stored; in transit means moving.
  • CloudWatch monitors, CloudTrail records API activity, and Config records/evaluates configuration.
  • GuardDuty detects threats, Inspector finds vulnerabilities, and Security Hub consolidates posture and findings.
  • Verify service, Region, and program eligibility for the workload at hand.
How it works
  • AWS publishes compliance program and service eligibility information and makes applicable reports available through Artifact.
  • Customers select eligible services and Regions, configure controls, and collect evidence appropriate to their obligations.
  • Monitoring, activity, configuration, detection, and posture services generate different signals that can be combined for governance and security.
When to use it
  • Use Artifact when the requirement is an AWS compliance report or agreement.
  • Use KMS for managed encryption keys, ACM for certificates, and CloudHSM when dedicated hardware security modules are specifically required.
  • Use CloudWatch for operational signals, CloudTrail for AWS API activity, and Config for resource configuration history or rule evaluation.
  • Use the relevant AWS compliance pages to confirm whether a service and Region are eligible for a named program.
Security and governance implications
  • Limit access to compliance evidence, logs, configurations, findings, and encryption keys according to job need.
  • Protect log and evidence retention from unauthorized alteration or deletion.
  • Treat encryption key administration and data access as separate permissions where practical.
Troubleshooting signals
  • If evidence appears to be missing, first identify whether the requirement calls for a metric, application log, API event, configuration record, compliance report, or security finding.
  • If a compliance claim is uncertain, verify the named program, service, Region, and customer configuration instead of assuming coverage.
More detail
  • Compliance is a combination of AWS controls and customer controls. AWS documentation can demonstrate how AWS operates its part, while customer evidence must cover identities, data, configurations, processes, and use of the service.
  • Governance asks whether resources and activity remain within intended boundaries. Config rules, CloudTrail activity records, CloudWatch telemetry, and access reports can provide complementary evidence rather than one universal compliance record.
  • Encryption has both a data state and a key or certificate mechanism. CLF-C02 focuses on recognizing needs and services, not implementing cryptography.
  • Security findings are different from operational and compliance records. A finding communicates a detected risk or issue; a metric, API event, or configuration snapshot answers a different question.

Ready for the quiz?

  • Where would you obtain an AWS compliance report?
  • How do CloudWatch, CloudTrail, and Config answer different questions?
  • When would KMS be a better fit than ACM?
  • Why can an AWS compliance certification not guarantee customer compliance?
  • How do GuardDuty, Inspector, and Security Hub differ?

Related objectives

  • D2.2

Learn more

Free AWS Certified Cloud Practitioner prep

Build focused CLF-C02 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Build a quiz

Exam Weights

Exam snapshot

CLF-C02 at a glance

Category
Foundational
Duration
90 minutes
Questions
65 total; 50 scored and 15 unidentified unscored
Formats
Multiple choice and multiple response
Scoring
100–1,000 scaled score; 700 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: AWS documents 65 questions in 90 minutes: 50 scored and 15 unidentified unscored, using multiple-choice and multiple-response formats. This site's practice accuracy and readiness do not reproduce AWS's 100–1,000 scaled scoring or identify unscored items. Difficulty labels describe this site's foundational scenario complexity, not an AWS-published question rating.

Reference

CLF-C02 topics and reference map

Study links

CLF-C02 resources