Under the AWS shared responsibility model, which activity is an example of security IN the cloud?
Choose one.
Security IN the cloud is everything the customer creates, configures, or grants access to: data, identities, guest operating systems, network configuration, and encryption choices.
Configuring network ACLs and routing is the customer's job because only the customer knows which traffic their workload should permit; AWS supplies the virtual networking, but the rules encode customer intent. The three distractors all live in layers the customer can never touch. The hypervisor is host virtualization software AWS operates, retiring and destroying physical disks is part of AWS's hardware and media-disposal process, and the network connecting Availability Zones is AWS's global infrastructure. A reliable test is whether the activity requires access to AWS hardware or host software: all three distractors do, so all three are security OF the cloud.
- Recall that IN the cloud means the customer's data, access, and configuration layers.
- Check each option for whether it requires access to AWS hardware, host software, or facilities.
- Hypervisor patching, media destruction, and inter-AZ networking all require infrastructure access, so they are AWS's.
- Network ACL and routing configuration expresses the customer's traffic decisions, so it is the customer's responsibility.
Exam tip: Network and firewall configuration for your resources is always your responsibility, even though AWS provides the networking features.
AWS Shared Responsibility Model: Security OF the Cloud vs IN the Cloud — the lesson that teaches this.