AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceEasy

A company's Trusted Advisor dashboard flags several IAM users that do not have MFA enabled and an S3 bucket that is publicly accessible. Which category of Trusted Advisor checks generated these findings?

  1. APerformance
  2. BService Limits
  3. CSecurity
  4. DCost Optimization
Show answer & explanation

Correct answer: C. Security

Trusted Advisor's Security category checks for issues such as missing MFA on the root account, open security groups, and public S3 bucket access, helping customers identify potential security gaps in their environment.

Why the other options are wrong

  • A. Performance checks evaluate service limits and configuration for optimal performance.
  • B. Service Limits checks warn when usage approaches account quotas, unrelated to MFA or bucket exposure.
  • D. Cost Optimization checks focus on identifying idle or underutilized resources.

Trusted Advisor Security Checks

A category of AWS Trusted Advisor recommendations that identifies security gaps like open ports, public S3 buckets, and missing MFA.

  • One of five Trusted Advisor categories
  • Checks include MFA on root, security groups, public S3 access
  • Full checks require Business/Enterprise support plan

Memory trick: Trusted Advisor's 5 categories: Cost, Performance, Security, Fault Tolerance, Service Limits.

More Security and Compliance questions