Shared Responsibility Flashcards
7 cards from real CLF-C02 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Shared Responsibility flashcards as text
A startup uses Amazon EKS (Elastic Kubernetes Service). Under the Shared Responsibility Model, who is responsible for securing the Kubernetes control plane?
Answer: AWS manages the EKS control plane; customers manage their worker nodes and workloads
AWS manages and secures the EKS control plane, while customers are responsible for their worker nodes, pod security, and application workloads.
Under the Shared Responsibility Model, which of the following is always the customer's responsibility regardless of which AWS service is used?
Answer: Controlling who has access to their AWS account and resources
Access management — including IAM users, roles, and policies — is always the customer's responsibility across all AWS services.
An enterprise asks whether AWS is responsible for preventing data breaches caused by a customer's weak IAM password policy. What does the Shared Responsibility Model say?
Answer: No, configuring IAM password policies is the customer's responsibility
IAM password policies are configured by the customer, so the responsibility for enforcing strong passwords rests entirely with the customer.
Which of the following infrastructure components is AWS responsible for under the Shared Responsibility Model?
Answer: Fiber optic cables and networking hardware connecting AWS regions
The physical network hardware and fiber connections between AWS facilities are part of the global infrastructure that AWS is fully responsible for.
A team uses AWS Config to monitor resource configurations. Under the Shared Responsibility Model, who is responsible for setting up and interpreting AWS Config rules?
Answer: The customer is responsible for defining and managing AWS Config rules
AWS Config is a customer-configured service; customers define the rules and are responsible for evaluating and acting on compliance findings.
Under the Shared Responsibility Model, who is responsible for ensuring high availability of a web application deployed on AWS?
Answer: The customer is responsible for designing the application for high availability using AWS services
While AWS provides highly available infrastructure, customers must architect their applications to use multiple AZs and fault-tolerant design patterns.
Which of the following best describes how the Shared Responsibility Model applies to AWS Elastic Beanstalk?
Answer: AWS manages the environment infrastructure; customers are responsible for their application code and data
Elastic Beanstalk is a managed platform where AWS handles the provisioning and management of infrastructure, but customers own and are responsible for their application code and data.