CLF-C02 exam dumps

CLF-C02 practice question 56 of 342

AWS Certified Cloud Practitioner. Free level, Amazon Web Services. Free question with the correct answer and a full explanation.

CLF-C02 Question 56

Select 3

A company is hosting a web application on Amazon EC2 instances and storing user-uploaded files in Amazon S3. According to the AWS shared responsibility model, which of the following is the company responsible for managing?

  1. A

    Configuring security groups to control traffic to the EC2 instances

  2. B

    Ensuring the durability and availability of the files stored in Amazon S3

  3. C

    Applying patches to the operating system of the EC2 instances

  4. D

    Encrypting sensitive data before uploading it to Amazon S3

  5. E

    Maintaining the physical security of the data centers hosting the EC2 instances

Show answer and explanation

Correct answers: A, C, D

Explanation

In the AWS shared responsibility model, AWS is responsible for the security 'of' the cloud, including physical security and the underlying infrastructure. Customers are responsible for the security 'in' the cloud, which includes tasks like configuring security groups, managing operating system patches, and encrypting sensitive data before uploading it to services like Amazon S3. This ensures a clear division of responsibilities between AWS and its customers.

  • A. Correct.

    The company is responsible for configuring security groups to control inbound and outbound traffic to their EC2 instances. This is part of the customer's responsibility for securing their resources.

  • B. Incorrect.

    AWS is responsible for ensuring the durability and availability of the infrastructure that supports Amazon S3, so this is not the customer's responsibility.

  • C. Correct.

    The company is responsible for managing and applying patches to the operating system of their EC2 instances, as this falls under the customer’s control in the shared responsibility model.

  • D. Correct.

    The company is responsible for encrypting sensitive data before uploading it to Amazon S3. While Amazon S3 offers server-side encryption options, ensuring data security is a shared responsibility and encrypting data before uploading is the customer's choice and responsibility.

  • E. Incorrect.

    AWS manages the physical security of the data centers, so the customer is not responsible for this aspect.

Timed practice exam

Take a CLF-C02 practice test under exam conditions

65 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam