CLF-C02 Shared Responsibility 4 — Questions and Answers
Question 1: A cloud architect is reviewing compliance requirements. Under the Shared Responsibility Model, who is responsible for ensuring the customer's application meets regulatory requirements?
- AWS is responsible for all compliance certifications
- The customer is responsible for their application's compliance, using AWS compliance programs as a foundation (Correct answer)
- A third-party auditor contracted by AWS
- Compliance is automatically ensured by deploying on AWS
Correct answer: The customer is responsible for their application's compliance, using AWS compliance programs as a foundation
While AWS provides compliance certifications for its infrastructure, customers are responsible for ensuring their applications and data handling meet applicable regulations.
Question 2: Which task is the customer responsible for when using Amazon EC2?
- Replacing failed physical hard drives
- Patching the guest operating system (Correct answer)
- Managing the virtualization layer
- Maintaining power and cooling in the data center
Correct answer: Patching the guest operating system
With EC2, customers are responsible for patching and maintaining the guest operating system running on their instances.
Question 3: How does the Shared Responsibility Model apply to AWS-managed services compared to unmanaged services?
- Managed services eliminate all customer security responsibilities
- AWS assumes more responsibility for managed services, reducing but not eliminating customer duties (Correct answer)
- Unmanaged services have no customer responsibilities
- The model does not distinguish between managed and unmanaged services
Correct answer: AWS assumes more responsibility for managed services, reducing but not eliminating customer duties
Managed services shift more operational and security tasks to AWS, but customers remain responsible for their data, access controls, and application-level security.
Question 4: Under the Shared Responsibility Model, who is responsible for configuring Multi-Factor Authentication (MFA) for AWS IAM users?
- AWS enables MFA automatically for all IAM users
- The customer must configure and enforce MFA for their IAM users (Correct answer)
- MFA is managed by AWS Security Hub automatically
- AWS Support configures MFA during account setup
Correct answer: The customer must configure and enforce MFA for their IAM users
Enabling and enforcing MFA for IAM users is a customer responsibility under the identity and access management category.
Question 5: A company is evaluating whether to use AWS for storing health data subject to HIPAA. What does the Shared Responsibility Model imply about HIPAA compliance?
- Using AWS automatically makes the application HIPAA-compliant
- AWS provides HIPAA-eligible services, but customers must configure and use them correctly to achieve compliance (Correct answer)
- AWS handles all HIPAA requirements on behalf of the customer
- HIPAA compliance is not possible on public cloud platforms
Correct answer: AWS provides HIPAA-eligible services, but customers must configure and use them correctly to achieve compliance
AWS offers HIPAA-eligible services and signs a BAA, but customers must properly configure those services and implement appropriate safeguards to be compliant.
Question 6: Which of the following best describes 'security OF the cloud' in the AWS Shared Responsibility Model?
- Customer responsibility for securing their data stored on AWS
- AWS responsibility for protecting the underlying hardware, software, networking, and facilities (Correct answer)
- The shared task of maintaining encryption across all services
- The customer's obligation to use AWS security services like GuardDuty
Correct answer: AWS responsibility for protecting the underlying hardware, software, networking, and facilities
'Security OF the cloud' is AWS's responsibility and includes protecting the physical and virtual infrastructure that runs all AWS services.
Question 7: A customer wants to understand who is responsible for applying security patches to an AWS managed NAT Gateway. Who handles this?
- The customer, because network components are the customer's responsibility
- AWS, because NAT Gateway is a managed service maintained by AWS (Correct answer)
- The customer and AWS share patching responsibility equally
- AWS provides patches but the customer must apply them
Correct answer: AWS, because NAT Gateway is a managed service maintained by AWS
NAT Gateway is a fully managed AWS service, so AWS is responsible for patching and maintaining the underlying infrastructure.
A cloud architect is reviewing compliance requirements.
Under the Shared Responsibility Model, who is responsible for ensuring the customer's application meets regulatory requirements?