SaveMyCert
Log in
5 of 5 free questions left today·for 30 a day
CLF-C02 · Domain 2

Security and Compliance practice questions

Security and Compliance is worth 30% of the CLF-C02 exam — the 2nd-heaviest of the 4 domains. The shared responsibility model, AWS security and governance concepts, identity and access management, and security resources. 6 fully worked examples are further down this page, answers included.

Exam weight
30%
the 2nd-heaviest of the 4 domains
Questions
80
across 4 topics
Free, no account
5/day
sign up free to remove the cap
Explanations
Every option
right and wrong

Build a practice session

5 free questions left today.

Domains

How many?

Mode

Ready when you are

10 fresh questions drawn across 1 of 4 domains, in Learn mode.

Focused review

Every question you answer incorrectly, and every question you flag while practising, is saved here automatically. Finish a session and you can come back to re-drill just those.

6 sample Security and Compliance questions, fully explained

Questions from the CLF-C02 bank mapped to domain 2, with the answer key and the reasoning behind every option. None of them repeat the examples on the main CLF-C02 practice page.

Question 1Security and Compliance

Under the AWS shared responsibility model, which activity is an example of security IN the cloud?

Choose one.

  • a
    Applying security patches to the hypervisor

    The hypervisor is part of the virtualization software AWS operates, and customers never patch it on any service.

  • b
    Destroying storage media that is retired from a data center

    Media disposal is part of the hardware lifecycle that AWS manages; customers never handle physical devices.

  • c
    Operating the network links that connect Availability Zones

    The global infrastructure of Regions, Availability Zones, and the cabling between them is built and secured by AWS.

  • d
    Configuring network ACLs and subnet routing for a workload Correct

    Network and firewall configuration for customer resources reflects the customer's decisions about allowed traffic, so it is security IN the cloud.

The concept

Security IN the cloud is everything the customer creates, configures, or grants access to: data, identities, guest operating systems, network configuration, and encryption choices.

Why that’s the answer

Configuring network ACLs and routing is the customer's job because only the customer knows which traffic their workload should permit; AWS supplies the virtual networking, but the rules encode customer intent. The three distractors all live in layers the customer can never touch. The hypervisor is host virtualization software AWS operates, retiring and destroying physical disks is part of AWS's hardware and media-disposal process, and the network connecting Availability Zones is AWS's global infrastructure. A reliable test is whether the activity requires access to AWS hardware or host software: all three distractors do, so all three are security OF the cloud.

How to reason it out
  1. Recall that IN the cloud means the customer's data, access, and configuration layers.
  2. Check each option for whether it requires access to AWS hardware, host software, or facilities.
  3. Hypervisor patching, media destruction, and inter-AZ networking all require infrastructure access, so they are AWS's.
  4. Network ACL and routing configuration expresses the customer's traffic decisions, so it is the customer's responsibility.

Exam tip: Network and firewall configuration for your resources is always your responsibility, even though AWS provides the networking features.

AWS Shared Responsibility Model: Security OF the Cloud vs IN the Cloud — the lesson that teaches this.

Question 2Security and Compliance

Which TWO statements about the AWS shared responsibility model are accurate? (Select TWO.)

Choose TWO.

  • a
    The customer is responsible for maintaining the host operating systems on AWS physical servers.

    Host operating systems run on AWS's physical machines and are always maintained by AWS; customers only ever manage guest operating systems.

  • b
    The model applies only to Amazon EC2 and other infrastructure services.

    The model applies to every AWS service; managed and serverless services simply place more responsibility on AWS's side of the line.

  • c
    The division of responsibilities shifts depending on how managed the AWS service is. Correct

    The boundary moves with the service: on EC2 the customer manages the guest OS, while on RDS and Lambda, AWS manages the OS and platform layers.

  • d
    AWS becomes responsible for customer data once it is stored in a managed service.

    Customer data is always the customer's responsibility, no matter how managed the service is.

  • e
    Some controls are shared, with AWS and the customer each acting in their own layer. Correct

    Patch management, configuration management, and awareness and training are shared controls where both parties perform the control at their own layer.

The concept

The shared responsibility model has three components: AWS responsibilities, customer responsibilities, and shared responsibilities, and the boundary between them shifts with the service's management level.

Why that’s the answer

The two accurate statements capture the model's defining traits. First, the dividing line is not fixed: the more managed the service, the more AWS takes on, which is why OS patching belongs to the customer on EC2 but to AWS on RDS. Second, a small set of controls, patch management, configuration management, and awareness and training, are genuinely shared, with each party acting at its own layer. The distractors each violate an anchor of the model: customers never touch host operating systems on AWS's physical servers because that is host software AWS operates, the model governs every AWS service rather than only infrastructure services, and customer data never becomes AWS's responsibility regardless of the service's management level.

How to reason it out
  1. Recall the model's three components: AWS responsibilities, customer responsibilities, and shared responsibilities.
  2. Confirm the boundary shifts by service: EC2 versus RDS versus Lambda place the line at different heights.
  3. Confirm the three shared controls exist, with each party acting in its own layer.
  4. Eliminate options that contradict the anchors: host OS and hypervisor are always AWS's, and customer data is always the customer's.

Exam tip: The responsibility line moves with the service, but shared controls and the two absolutes (data = customer, infrastructure = AWS) never change.

AWS Shared Responsibility Model: Security OF the Cloud vs IN the Cloud — the lesson that teaches this.

Question 3Security and Compliance

Under the AWS shared responsibility model, who is responsible for the secure disposal of decommissioned storage devices that previously held customer data?

Choose one.

  • a
    The customer

    Customers never have physical access to AWS hardware, so they cannot dispose of storage devices.

  • b
    A third-party auditor contracted by the customer

    Auditors verify that AWS meets its obligations; they do not perform hardware disposal themselves.

  • c
    AWS Correct

    Hardware lifecycle management, including destroying retired disks according to a media-disposal process, is part of AWS's responsibility for the physical infrastructure.

  • d
    Responsibility is shared between AWS and the customer

    Media disposal has no customer layer; it is performed entirely by AWS, so it is not a shared control.

The concept

AWS is responsible for the full hardware lifecycle of its infrastructure, including procuring, maintaining, and securely decommissioning servers and storage media.

Why that’s the answer

When a disk that held customer data is retired, AWS destroys it according to its media-disposal process, because the physical device is AWS property inside an AWS facility. The customer option fails on a physical impossibility: customers can never enter a data center or touch the hardware. The auditor option confuses verification with execution; third-party audits confirm AWS performs disposal correctly but do not carry it out. The shared option fails because sharing requires both parties to act in their own layer, and there is no customer layer in physically destroying a disk. Note the subtle point the question tests: even though the disk held customer data, the physical device is infrastructure, so disposal is AWS's, while protecting the data logically (encryption, access) remains the customer's.

How to reason it out
  1. Identify the layer: a physical storage device inside an AWS data center is hardware.
  2. Apply the anchor: hardware and facilities are always AWS's responsibility.
  3. Do not be misled by the mention of customer data; the physical device belongs to AWS even when the logical data belongs to the customer.
  4. Reject shared responsibility because the customer performs no part of physical media destruction.

Exam tip: Hardware and media disposal is always AWS's job; customers never handle physical devices.

AWS Shared Responsibility Model: Security OF the Cloud vs IN the Cloud — the lesson that teaches this.

Question 4Security and Compliance

A company stores confidential documents in Amazon S3. Under the AWS shared responsibility model, who is responsible for protecting the contents of those documents and controlling who can access them?

Choose one.

  • a
    AWS

    AWS secures the storage infrastructure beneath the data but never decides how customer data should be protected or who may see it.

  • b
    AWS for public buckets and the customer for private buckets

    Whether a bucket is public is itself a customer configuration decision; data responsibility does not change with the bucket's access setting.

  • c
    The customer Correct

    Customer data is always the customer's responsibility, including classifying it, controlling access to it, and choosing whether to encrypt it, on every AWS service.

  • d
    Responsibility is shared equally between AWS and the customer

    Data protection is not one of the shared controls; the contents of and access to customer data belong entirely to the customer.

The concept

Customer data is one of the responsibilities that never moves: on every AWS service, the customer owns its classification, protection, encryption, and access control.

Why that’s the answer

AWS operates the S3 service and secures the infrastructure it runs on, but it cannot know which documents are sensitive, which users deserve access, or whether encryption should be applied, so those decisions and their consequences belong to the customer. The AWS option fails because operating a storage service is different from owning the data in it. The public-versus-private split is a fabricated rule: bucket access settings are themselves customer configurations, so they cannot transfer responsibility to AWS. The shared option fails because the only shared controls are patch management, configuration management, and awareness and training; data protection is a purely customer-side, customer-specific concern.

How to reason it out
  1. Identify the subject of the question: the customer's data and access to it, not the storage infrastructure.
  2. Apply the anchor: customer data is always the customer's responsibility, without exception.
  3. Reject any option that makes data responsibility conditional on a configuration setting or service type.
  4. Reject shared responsibility because data protection is not among the three shared controls.

Exam tip: Your data is always your responsibility; no AWS service, however managed, takes ownership of protecting its contents.

AWS Shared Responsibility Model: Security OF the Cloud vs IN the Cloud — the lesson that teaches this.

Question 5Security and Compliance

A security team asks who applies security patches to the hypervisor that isolates Amazon EC2 instances belonging to different customers. What is the correct answer?

Choose one.

  • a
    The customer patches the hypervisor because EC2 is an infrastructure service.

    Even on EC2, the customer's responsibility starts at the guest operating system; the hypervisor beneath it is never customer-managed.

  • b
    Patching the hypervisor is a shared control split between AWS and the customer.

    Patch management is shared only in the sense that each party patches its own layer, and the hypervisor layer belongs entirely to AWS.

  • c
    Customers with dedicated instances patch their own hypervisor.

    No purchasing option gives customers access to the hypervisor; AWS operates the virtualization layer in every case.

  • d
    AWS patches the hypervisor on all services, without exception. Correct

    The hypervisor is virtualization software running on AWS's physical hosts, and maintaining it is always AWS's responsibility.

The concept

The hypervisor and host operating systems are part of the virtualization and host software layer that AWS always operates, on every service and every deployment option.

Why that’s the answer

The hypervisor isolates one customer's instances from another's, which means it must be controlled by the infrastructure operator; customers never see or patch it. The EC2 distractor exploits the true fact that customers manage the most on EC2, but that management starts at the guest OS, one layer above the hypervisor. The shared-control distractor misapplies patch management: patching is shared across the whole model because each party patches its own layer, but any single layer has exactly one owner, and the hypervisor's owner is AWS. The dedicated-instance distractor invents an exception that does not exist; hardware dedication changes tenancy, not the responsibility for virtualization software.

How to reason it out
  1. Locate the hypervisor in the stack: it sits below the guest OS, on AWS's physical hosts.
  2. Apply the anchor: virtualization and host software are always AWS's responsibility.
  3. Recognize that EC2 giving customers the most control still stops at the guest operating system.
  4. Reject shared or conditional ownership because a single layer always has one owner, and this layer is AWS's.

Exam tip: You never patch a hypervisor or host OS on AWS; the customer's patching duty begins at the guest OS.

AWS Shared Responsibility Model: Security OF the Cloud vs IN the Cloud — the lesson that teaches this.

Question 6Security and Compliance

A company runs its entire workload on fully managed serverless services. Under the AWS shared responsibility model, who is responsible for creating IAM roles and granting permissions to those services?

Choose one.

  • a
    AWS, because serverless services are fully managed

    Managed means AWS operates the platform layers; it never means AWS decides which identities get which permissions in the customer's account.

  • b
    AWS creates the roles and the customer only reviews them

    AWS provides IAM as a tool but does not author the customer's permission policies; every grant is a customer decision.

  • c
    It is a shared control, with AWS managing roles and the customer managing users

    IAM is not one of the shared controls; all identity and permission management in the customer's account belongs to the customer.

  • d
    The customer, because access management is always the customer's responsibility Correct

    IAM users, roles, and permissions encode who the customer allows to act, and this responsibility never transfers to AWS regardless of service type.

The concept

Identity and access management is one of the responsibilities that never moves: the customer creates users and roles, assigns permissions, enforces least privilege, and manages credentials on every service.

Why that’s the answer

Even on the most fully managed service AWS offers, only the customer knows who in their organization deserves which access, so IAM permissions remain security IN the cloud. The fully-managed distractor tests the trap that managed does not mean AWS owns everything: management moves operational layers like OS and runtime patching to AWS, but never access decisions. The review-only distractor misstates how IAM works; AWS supplies the service, but the customer authors every policy. The shared-control distractor fabricates a split that does not exist; the shared controls are patch management, configuration management, and awareness and training, and IAM appears in none of them.

How to reason it out
  1. Identify the task: granting permissions, which is identity and access management.
  2. Apply the anchor: IAM is always the customer's responsibility, on every service.
  3. Recognize that a service being serverless or managed shifts operational layers to AWS, never access decisions.
  4. Reject any option that assigns AWS a role in authoring the customer's permissions.

Exam tip: IAM permissions are always the customer's responsibility; no level of service management changes that.

AWS Shared Responsibility Model: Security OF the Cloud vs IN the Cloud — the lesson that teaches this.

What CLF-C02 domain 2 tests, topic by topic

The official exam guide breaks Security and Compliance into 4 topics. The question bank follows the same split, so a weak topic shows up as a cluster of misses you can go back and read.

Published CLF-C02 practice questions per topic in Security and Compliance
TopicWhat it coversQuestions
Understand the AWS shared responsibility modelExam guide task 2.1. Recognizing the components of the shared responsibility model: what the customer is responsible for, what AWS is responsible for, what is shared, and how responsibilities shift depending on the service used (e.g. EC2 vs RDS vs Lambda).20
Understand AWS Cloud security, governance, and compliance conceptsExam guide task 2.2. Where to find compliance information (AWS Artifact) and how compliance needs vary by geography/industry; security logs and encryption in transit vs at rest; services customers use to secure resources (Amazon Inspector, Security Hub, GuardDuty, Shield); governance services — monitoring with CloudWatch, auditing with CloudTrail and Config, and reporting with access reports; compliance requirements that vary among AWS services.20
Identify AWS access management capabilitiesExam guide task 2.3. IAM fundamentals: protecting the root user, the principle of least privilege, IAM Identity Center; access keys and password policies; credential storage (Secrets Manager, Systems Manager); MFA, cross-account IAM roles, federated identity; groups and users, custom vs managed policies, and root-user-only tasks.20
Identify components and resources for securityExam guide task 2.4. AWS security features and services (AWS WAF, Firewall Manager, Shield, GuardDuty); third-party security products from AWS Marketplace; where to find security guidance (AWS Knowledge Center, Security Center, Security Blog); recognizing security issues with Trusted Advisor.20
Total80

Revise Security and Compliance before you drill it

Other CLF-C02 domains

Security and Compliance: your questions

Security and Compliance is domain 2 of the CLF-C02 exam guide and carries 30% of the scored content — the 2nd-heaviest of the 4 domains. On a 65-question paper that works out to roughly 20 questions, though AWS does not publish an exact per-domain count and individual exam forms vary.

Source

The domain weight and topic list on this page come from the official CLF-C02 exam guide.