CLF-C02 · AWS · Security and Compliance · Bank updated 2026-09-20
CLF-C02 practice questions: Security and Compliance
5 free questions from 22 on this area · answer and explanation for each · no sign-up
These 5 questions come from the Security and Compliance section of our CLF-C02 bank (22 questions on this area, which carries 30% of the real exam). Every question is original, with the correct answer explained and linked to the source it is drawn from.
1/5 · Security and Compliance · easy
An external auditor asks a company for evidence that the AWS infrastructure underlying its workloads has been assessed against SOC and PCI requirements. The company needs to obtain those reports itself. Where should it go?
AAWS Trusted Advisor
BAWS Security Hub
CAWS Artifact
DAWS Config
Show answer & explanation
C is correct. Task Statement 2.2 names AWS Artifact as the place to find AWS compliance information. The AWS Artifact user guide states that it 'provides on-demand downloads of AWS security and compliance documents. For example, reports on compliance with International Organization for Standardization (ISO) standards and Payment Card Industry (PCI) Security Standards, and System and Organization Controls (SOC) reports,' and that you can 'submit AWS Artifact documents to your auditors or regulators as audit artifacts.' It adds that 'AWS provides AWS Artifact documents and agreements to you free of charge.' Every distractor reports on the customer's own environment rather than on AWS.
↗ AWS CLF-C02 Exam Guide — Domain 2: Security and Compliance
2/5 · Security and Compliance
A new engineer is learning how the AWS shared responsibility model is divided. Which pair of phrases does AWS use to name the two halves of the model?
ASecurity at rest, performed by AWS, and security in transit, performed by the customer.
BPhysical security, performed by AWS, and logical security, performed by the customer.
CPreventive controls, performed by AWS, and detective controls, performed by the customer organization.
DSecurity of the cloud, performed by AWS, and security in the cloud, performed by customers.
Show answer & explanation
D is correct. Task Statement 2.1 asks candidates to recognize the components of the model. The AWS shared responsibility model page and the AWS Shield developer guide both state the split as 'security of the cloud and security in the cloud,' with AWS 'responsible for protecting the infrastructure that runs AWS services in the AWS Cloud' and the customer's responsibility 'determined by the AWS service that you use.' The other options pair real security concepts that the model does not use as its top-level division.
↗ AWS CLF-C02 Exam Guide — Domain 2: Security and Compliance
3/5 · Security and Compliance
A company encrypts data held for it in several places on AWS. It must be able to state which identities may use the material that protects that data, to withdraw that permission later, and to see every such use in its audit trail. It does not want to operate cryptographic hardware of its own. Which AWS offering is intended for this?
AAWS Certificate Manager (ACM)
BAWS Systems Manager Parameter Store
CAWS Key Management Service
DAWS CloudHSM clusters
Show answer & explanation
C is correct. Task Statement 2.2 asks candidates to identify encryption options. The AWS KMS developer guide states that it 'is an AWS managed service that makes it easy for you to create and control the keys used to encrypt and sign your data,' and that 'you can create and manage key policies in AWS KMS, ensuring that only trusted users have access to KMS keys.' The AWS CloudHSM user guide draws the boundary itself: 'If you want a managed service for creating and controlling your encryption keys but you don't want or need to operate your own HSMs, consider using AWS Key Management Service.' AWS Certificate Manager covers the certificates that protect data in transit, and Parameter Store encrypts its secure strings with keys that are managed elsewhere.
↗ AWS CLF-C02 Exam Guide — Domain 2: Security and Compliance
4/5 · Security and Compliance
A company is launching a consumer mobile application. It needs a directory that the application's own users sign up and sign in to, the option of signing in with an existing Google or Apple account, and a way to hand the application temporary AWS credentials for the resources it reaches. Which service is built for this?
AAWS IAM Identity Center
BAWS Directory Service
CAWS IAM
DAmazon Cognito
Show answer & explanation
D is correct. Task Statement 2.3 covers types of identity management. The Amazon Cognito developer guide states that Cognito 'is an identity platform for web and mobile apps. It's a user directory, an authentication server, and an authorization service for OAuth 2.0 access tokens and AWS credentials,' that user pools can federate to 'the public OAuth 2.0 identity stores Amazon, Google, Apple and Facebook,' and that an identity pool 'issues AWS credentials for your app to serve resources to users.' The AWS Directory Service guide draws the same boundary from the other side.
↗ AWS CLF-C02 Exam Guide — Domain 2: Security and Compliance
5/5 · Security and Compliance · hard
A compliance officer is building a control matrix and needs to place three controls: patch management, configuration management, and awareness and training. Each control must be marked as an AWS duty, a customer duty, or a duty that both parties carry at their own layer. How should all three be marked?
AAll three belong to AWS and to nobody on the customer's side.
BAll three belong to the customer and to nobody on the AWS side.
CAll three are carried by both parties, each at the layer that it operates.
DPatch management and configuration management are shared; awareness and training is not.
Show answer & explanation
C is correct. Task Statement 2.1 asks candidates to describe responsibilities that the customer and AWS share. The AWS shared responsibility model page lists exactly three shared controls: patch management, where 'AWS is responsible for patching and fixing flaws within the infrastructure' and customers patch guest operating systems and applications; configuration management, where AWS maintains infrastructure configuration and customers configure 'guest operating systems, databases, and applications'; and awareness and training, where 'AWS trains AWS employees' and the customer trains its own staff.
↗ AWS CLF-C02 Exam Guide — Domain 2: Security and Compliance
Other CLF-C02 areas
The same kind of free sample for every other section of the CLF-C02 bank:
Study Security and Compliance with instant feedback
6 free questions · filter study mode by area and difficulty · error log with spaced repetition · no card, no dumps, no ads.
Create your free account →
ExamDeck is an independent study tool, not affiliated with, endorsed by, or sponsored by AWS. CLF-C02 and related marks are trademarks of their respective owners, used for identification only. Exam facts checked against official AWS materials (as of September 2026); always confirm current details with the vendor before booking.