Skip to content
BytePatterns

CLF-C02 · Domain 2: Security and Compliance · 30% of the exam

Task 2.1: Understand the AWS shared responsibility model.

Where AWS's job ends and yours begins, and how that line moves between a virtual machine, a managed database and a serverless function.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A company runs its web application on Amazon EC2 instances. Under the AWS shared responsibility model, which task belongs to the company?

  1. AMaintaining the physical servers that host the instances
  2. BSecuring the data center buildings
  3. CPatching flaws in the AWS infrastructure
  4. DPatching the instances' guest operating system
Show the answer and why
  • AMaintaining the physical servers that host the instances

    Incorrect

    AWS is responsible for protecting the infrastructure that runs its services, which includes the hardware.

  • BSecuring the data center buildings

    Incorrect

    Facilities are part of the infrastructure AWS protects — security of the cloud.

  • CPatching flaws in the AWS infrastructure

    Incorrect

    Under patch management, a shared control, AWS patches and fixes flaws within its infrastructure.

  • DPatching the instances' guest operating system

    Correct

    For EC2, the customer manages the guest operating system, including its updates and security patches, plus any software installed on the instances.

AWS secures the cloud itself; the customer secures what runs in it. With EC2 the customer's side starts at the guest operating system.

Question 2 · choose 1

A team stores customer records in Amazon DynamoDB, a service where AWS operates the infrastructure, the operating system and the platform. Which responsibility stays with the team?

  1. ADeciding who may read the table, by applying IAM permissions
  2. BPatching the operating system of the servers that run DynamoDB
  3. CReplacing failed disks in the DynamoDB fleet
  4. DInstalling new versions of the DynamoDB software
Show the answer and why
  • ADeciding who may read the table, by applying IAM permissions

    Correct

    For abstracted services such as DynamoDB, customers still manage their data, classify it, and use IAM to apply the right permissions.

  • BPatching the operating system of the servers that run DynamoDB

    Incorrect

    For services like DynamoDB, AWS operates the operating system, and DynamoDB needs no patching from the customer at all.

  • CReplacing failed disks in the DynamoDB fleet

    Incorrect

    Hardware is part of the infrastructure AWS protects; DynamoDB handles hardware provisioning as a fully managed service.

  • DInstalling new versions of the DynamoDB software

    Incorrect

    DynamoDB has no versions to install and no maintenance windows; there is no software for the customer to install or maintain.

The more AWS manages, the less you patch, but your data and who may access it are always on your side of the line.

Question 3 · choose 1

A team runs an AWS Lambda function on a managed runtime with the Auto runtime update mode. The function's deployment package includes several open-source libraries. Under the shared responsibility model, which task belongs to the team?

  1. APatching the open-source libraries in the deployment package
  2. BApplying security patches to the function's managed runtime
  3. CPatching the operating system of the servers that run the function
  4. DReplacing failed hardware in the data centers where Lambda runs
Show the answer and why
  • APatching the open-source libraries in the deployment package

    Correct

    Whatever the runtime update mode, the customer is responsible for the function code and its dependencies, including applying their updates and security patches.

  • BApplying security patches to the function's managed runtime

    Incorrect

    In Auto mode, Lambda publishes new runtime versions with the latest patches and applies them to existing functions.

  • CPatching the operating system of the servers that run the function

    Incorrect

    Lambda is a service where AWS operates the infrastructure, the operating system and the platform; there is no server for the team to patch.

  • DReplacing failed hardware in the data centers where Lambda runs

    Incorrect

    Hardware and facilities are part of the infrastructure AWS protects in every service.

With Lambda the line sits very high: AWS runs everything up to and including a patched runtime, and the customer owns its code, the libraries it ships with that code, its data and its permissions.

Question 4 · choose 1

A company moves its PostgreSQL database from a self-managed Amazon EC2 instance to Amazon RDS for PostgreSQL. Which task does the company hand over to AWS with this move?

  1. AChoosing which database users may read each table
  2. BWriting the security group rules that decide which servers can connect
  3. CApplying operating system patches to the database host
  4. DTuning slow SQL queries
Show the answer and why
  • AChoosing which database users may read each table

    Incorrect

    Database users and their permissions stay with the customer; RDS uses the security features of the database engine to control who can log in.

  • BWriting the security group rules that decide which servers can connect

    Incorrect

    The customer uses security groups to control which IP addresses or EC2 instances can connect to a DB instance.

  • CApplying operating system patches to the database host

    Correct

    On EC2 the customer installs and patches the operating system and the database software. With Amazon RDS, AWS does both.

  • DTuning slow SQL queries

    Incorrect

    Query tuning remains the customer's job on RDS; it depends on the customer's own data, schema and query patterns.

A managed database moves the operating system, database software patching, backups and high availability to AWS. Access to the data and the queries run against it stay with the customer.

Question 5 · choose 1

The AWS shared responsibility model describes some IT controls as shared, where AWS and the customer each have a part. Which of the following is one of those shared controls?

  1. APhysical and environmental controls
  2. BConfiguration management
  3. CRouting or zoning data within specific security environments
  4. DProtecting the hardware of the AWS global infrastructure
Show the answer and why
  • APhysical and environmental controls

    Incorrect

    These are inherited controls: the customer fully inherits them from AWS.

  • BConfiguration management

    Correct

    AWS maintains the configuration of its infrastructure devices, and the customer configures its own guest operating systems, databases and applications.

  • CRouting or zoning data within specific security environments

    Incorrect

    Service and communications protection, or zone security, is listed as a customer-specific control, entirely the customer's.

  • DProtecting the hardware of the AWS global infrastructure

    Incorrect

    Protecting the hardware, software, networking and facilities that run AWS services is AWS's responsibility alone.

The three shared controls are patch management, configuration management, and awareness and training: in each, AWS does its part for the infrastructure and the customer does the same for what it runs.

Practise domain 2 →Practise all domains →