📖 What is AWS Config?

AWS Config is a service that enables you to assess, audit, and evaluate the configurations of your AWS resources. It continuously monitors and records resource configuration changes, allowing you to track compliance against desired settings over time.

🥋 Sensei Says:

"Think of AWS Config as a 'flight recorder' for your infrastructure. It tells you what changed, when it changed, and if it violates your rules."

📚 Certification: AWS Certified Cloud Practitioner (CLF-C02)

🔑 What are the Key Concepts of AWS Config?

  • Configuration History: Tracks changes over time, allowing users to see exactly how a resource was configured at a specific point in the past.
  • AWS Config Rules: Predefined or custom rules that automatically evaluate resource configurations to check for compliance with organizational policies.
  • Compliance Monitoring: Flags resources as 'compliant' or 'non-compliant' based on rules, enabling quick identification of security risks or misconfigurations.
  • Resource Relationship Mapping: Visualizes how resources are connected, helping administrators understand the impact of changes across the entire AWS environment.
  • Continuous Auditing: Automates the process of auditing infrastructure, replacing manual checks with real-time monitoring of configuration changes.

🎯 How does AWS Config appear on the CLF-C02 Exam?

You may be asked to identify the service that provides a detailed history of configuration changes for an EC2 instance to determine exactly when a specific security group rule was modified.

A scenario might describe a company needing to ensure all S3 buckets remain encrypted; you must select the service that automatically monitors resource states and reports any non-compliant buckets.

Expect questions where you must differentiate between a service that logs API calls to see who made a change (CloudTrail) and a service that tracks configuration states (AWS Config).

❓ Frequently Asked Questions

How does AWS Config differ from AWS CloudTrail?

CloudTrail records 'who' did 'what' by logging API calls, whereas AWS Config records 'what' the resource looks like and 'how' its configuration changed over time. Think of CloudTrail as the activity log and Config as the state history.


Can AWS Config automatically fix a non-compliant resource?

Yes, by using AWS Config Rules in conjunction with AWS Systems Manager Automation documents, you can trigger automatic remediation to bring a non-compliant resource back into a compliant state without manual intervention.

Related Terms from AWS Certified Cloud Practitioner

📝 Related Study Guides

Study Guide 8 min read

AWS Cloud Practitioner (CLF-C02): Complete 2026 Study Guide

The AWS Cloud Practitioner CLF-C02 certification validates foundational cloud knowledge across four domains: Cloud Concepts, Security and Compliance, Cloud Technology and Services, and Billing and Pricing. Prepare with a 4-week study plan focusing on core AWS services like EC2, S3, IAM, and Lambda, combined with scenario-based practice questions to build exam confidence.

Study Guide 10 min read

AWS Cloud Practitioner (CLF-C02) Study Guide for 2026

The AWS Cloud Practitioner (CLF-C02) exam validates overall understanding of the AWS Cloud platform. To pass, you must master four domains: Cloud Concepts, Security and Compliance, Technology, and Billing and Pricing. A successful strategy combines official AWS documentation with rigorous practice exams to benchmark your knowledge across all service categories.

Deep Dive 8 min read

AWS Support Plans & Pricing: CLF-C02 Exam Guide

AWS offers four support plans—Basic, Developer, Business, and Enterprise—differing by response time, access to engineers, and the inclusion of a Technical Account Manager (TAM). For the CLF-C02 exam, you must distinguish these tiers and understand pricing models like On-Demand, Reserved, Spot, and Savings Plans to optimize cloud costs.

🧠

Test Your Knowledge

Think you understand AWS Config? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium