โ† All CLF-C02 Flashcard Decks

Shared Responsibility Flashcards

7 cards from real CLF-C02 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Shared Responsibility flashcards as text
  1. A security auditor asks about responsibility for DDoS protection on AWS. Which answer is most accurate?

    Answer: AWS Shield Standard automatically protects all AWS resources from common DDoS attacks at no extra cost

    AWS Shield Standard is included automatically for all AWS customers and provides protection against common network and transport layer DDoS attacks.

  2. Under the Shared Responsibility Model, who is responsible for the availability of the AWS global infrastructure?

    Answer: AWS, by maintaining its global network and data centers

    AWS is responsible for the availability and reliability of its global infrastructure, including regions, Availability Zones, and edge locations.

  3. What does 'security IN the cloud' refer to in the AWS Shared Responsibility Model?

    Answer: Customer responsibilities such as data protection, IAM, and OS patching

    'Security IN the cloud' refers to customer responsibilities, including managing data, applications, identity, and operating system configuration.

  4. A company uses AWS Organizations with multiple accounts. Under the Shared Responsibility Model, who manages the AWS account root user credentials?

    Answer: The customer is responsible for securing and restricting root user access

    Customers are fully responsible for securing root user credentials, including enabling MFA and avoiding routine use of the root account.

  5. Which of the following is AWS responsible for under the Shared Responsibility Model?

    Answer: Securing the underlying compute hypervisor

    AWS is responsible for securing the hypervisor layer that supports EC2 instances, as it is part of the foundational infrastructure.

  6. A customer accidentally exposes an S3 bucket to the public. Under the Shared Responsibility Model, who is accountable?

    Answer: The customer, because S3 bucket policies and ACLs are the customer's responsibility

    Configuring S3 bucket access controls is a customer responsibility, so misconfiguration resulting in public exposure is the customer's accountability.

  7. Which statement correctly describes the Shared Responsibility Model for a managed service like Amazon DynamoDB?

    Answer: AWS manages the infrastructure and service; the customer manages data access and table configuration

    For managed services like DynamoDB, AWS handles infrastructure, while customers control data, access policies, and application logic.