Study CLF-C02 Security and Compliance: key concepts, common traps, and exam decision cues.
This is the heaviest CLF-C02 domain after service technology, and it is where many candidates lose easy points by mixing security ideas that sound similar. AWS is not expecting architect-level security design here. It is expecting you to separate shared responsibility, security and compliance concepts, access management, and security resources into clean foundational lanes.
I verified the current CLF-C02 Domain 2 task statements on May 11, 2026. AWS currently expresses this domain as four task statements:
The public guide still uses three teaching pages, but they now map cleanly to those four tasks instead of blending them too loosely.
AWS currently weights Security and Compliance at 30% of scored content.
AWS wants you to prove that you can:
| Lesson | AWS task fit | Why it matters |
|---|---|---|
| 2.1 Shared Responsibility & Protection Boundaries | Task 2.1 | This is the boundary lane: who secures the cloud, who secures what is in it, and how that changes with managed services. |
| 2.2 Identity, Access & Root-Account Protection | Task 2.3 | This is the access lane: IAM, MFA, least privilege, roles, root-account safety, and centralized access. |
| 2.3 Governance, Compliance, Logging & Security Services | Tasks 2.2 and 2.4 | This is the concepts-and-resources lane: compliance evidence, audit trails, logging, configuration tracking, threat detection, and managed protection services. |
| If the question is really about… | Go first to… | What to look for |
|---|---|---|
| who secures hardware, guest OS, data, identities, or patching | 2.1 Shared Responsibility & Protection Boundaries | AWS side vs customer side |
| users, roles, MFA, least privilege, root user, access keys, or workforce sign-in | 2.2 Identity, Access & Root-Account Protection | human access vs workload access |
| Artifact, CloudTrail, CloudWatch, Config, GuardDuty, Security Hub, Shield, WAF, encryption basics, or governance/compliance concepts | 2.3 Governance, Compliance, Logging & Security Services | evidence, monitoring, findings, protection controls |
| Trap | Better thinking |
|---|---|
| “AWS secures everything once the workload is in AWS.” | Shared responsibility still leaves configuration, identity, and data choices with the customer. |
| “CloudTrail, CloudWatch, Config, and Artifact are all basically audit services.” | Each one answers a different kind of question. |
| “Root user is just another admin identity.” | Root is special and should be heavily protected and rarely used. |
| “Security group, WAF, and Shield are interchangeable.” | They protect at different layers. |
If your misses include phrases like shared responsibility, least privilege, compliance, or most secure, protect this chapter first. It is one of the highest-yield near-miss domains on CLF-C02.