Shared Responsibility Flashcards
7 cards from real CLF-C02 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Shared Responsibility flashcards as text
A cloud architect is reviewing compliance requirements. Under the Shared Responsibility Model, who is responsible for ensuring the customer's application meets regulatory requirements?
Answer: The customer is responsible for their application's compliance, using AWS compliance programs as a foundation
While AWS provides compliance certifications for its infrastructure, customers are responsible for ensuring their applications and data handling meet applicable regulations.
Which task is the customer responsible for when using Amazon EC2?
Answer: Patching the guest operating system
With EC2, customers are responsible for patching and maintaining the guest operating system running on their instances.
How does the Shared Responsibility Model apply to AWS-managed services compared to unmanaged services?
Answer: AWS assumes more responsibility for managed services, reducing but not eliminating customer duties
Managed services shift more operational and security tasks to AWS, but customers remain responsible for their data, access controls, and application-level security.
Under the Shared Responsibility Model, who is responsible for configuring Multi-Factor Authentication (MFA) for AWS IAM users?
Answer: The customer must configure and enforce MFA for their IAM users
Enabling and enforcing MFA for IAM users is a customer responsibility under the identity and access management category.
A company is evaluating whether to use AWS for storing health data subject to HIPAA. What does the Shared Responsibility Model imply about HIPAA compliance?
Answer: AWS provides HIPAA-eligible services, but customers must configure and use them correctly to achieve compliance
AWS offers HIPAA-eligible services and signs a BAA, but customers must properly configure those services and implement appropriate safeguards to be compliant.
Which of the following best describes 'security OF the cloud' in the AWS Shared Responsibility Model?
Answer: AWS responsibility for protecting the underlying hardware, software, networking, and facilities
'Security OF the cloud' is AWS's responsibility and includes protecting the physical and virtual infrastructure that runs all AWS services.
A customer wants to understand who is responsible for applying security patches to an AWS managed NAT Gateway. Who handles this?
Answer: AWS, because NAT Gateway is a managed service maintained by AWS
NAT Gateway is a fully managed AWS service, so AWS is responsible for patching and maintaining the underlying infrastructure.