AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceEasy

A startup is deploying its first workload on AWS and wants to understand which security tasks AWS handles automatically versus which tasks the startup must handle. Under the AWS shared responsibility model, which task is always the customer's responsibility?

  1. APatching the underlying hypervisor software
  2. BMaintaining physical security of the data center facilities
  3. CDecommissioning and destroying failed storage hardware
  4. DConfiguring security groups and network access control lists for EC2 instances
Show answer & explanation

Correct answer: D. Configuring security groups and network access control lists for EC2 instances

AWS is responsible for security 'of' the cloud (hardware, hypervisor, facilities), while the customer is responsible for security 'in' the cloud, including configuring security groups and network ACLs.

Why the other options are wrong

  • A. Hypervisor patching is AWS's responsibility as part of infrastructure security.
  • B. Physical data center security is managed entirely by AWS.
  • C. Hardware decommissioning is handled by AWS, not the customer.

Shared Responsibility Model

A framework defining that AWS secures the cloud infrastructure while customers secure what they put in the cloud.

  • AWS: hardware, facilities, hypervisor, global infrastructure
  • Customer: data, IAM, OS patching (for EC2), network configuration
  • Responsibility split varies by service (e.g., managed vs unmanaged)

Memory trick: AWS locks the building, you lock your office door.

More Security and Compliance questions