Courseiva
Security and ComplianceeasyMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

Under the AWS Shared Responsibility Model, which scenario correctly demonstrates the customer's responsibility?

⚠ Common exam trap

A common mix-up: candidates confuse 'patching the hypervisor' (AWS responsibility) with 'patching the guest OS' (customer responsibility), leading them to incorrectly assign hypervisor patching to the customer under the Shared Responsibility Model.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A customer configuring security groups to restrict unnecessary inbound traffic to EC2 instances

Configuring security groups to restrict inbound traffic is a customer responsibility under the Shared Responsibility Model. Security groups act as a virtual firewall for EC2 instances, and customers must define rules to control traffic at the instance level. AWS manages the underlying network infrastructure but does not configure customer-specific access controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS ensuring the physical data center is protected from unauthorized entry

    Why it's wrong here

    Under the AWS shared responsibility model, physical data center security—including perimeter fences, guards, biometric access controls, and visitor vetting—is exclusively AWS's responsibility. Customers have no physical access to AWS facilities and cannot configure or influence these controls. Therefore this action cannot be a customer-side security task, making the option incorrect.

  • A customer configuring security groups to restrict unnecessary inbound traffic to EC2 instances

    Why this is correct

    A customer configuring security groups to restrict unnecessary inbound traffic is a classic customer responsibility. Security groups are stateful virtual firewalls attached to EC2 instances, and while AWS provides the mechanism, the customer must create appropriate rules to control allowed source IPs, ports, and protocols. AWS only guarantees the underlying infrastructure; it does not determine which traffic your instances should accept.

  • AWS patching the underlying hypervisor on EC2 hosts

    Why it's wrong here

    Patching the underlying hypervisor on EC2 hosts is performed by AWS as part of its responsibility for the virtualization layer. The hypervisor isolates customer instances from one another and from the host hardware, so customers have no access to it and cannot patch it. AWS applies hypervisor patches to maintain security and availability, making this item incorrect as a customer responsibility.

  • AWS ensuring S3 storage hardware is replaced when it fails

    Why it's wrong here

    AWS ensuring S3 storage hardware is replaced when it fails falls squarely on AWS, not the customer. S3's 99.999999999% durability is achieved through redundant storage across devices and facilities, and AWS automatically detects, replaces, and re-replicates data when underlying hardware fails. Customers interact only with S3 APIs, never with the underlying storage hardware, so this is not a customer responsibility.

About these practice questions

Courseiva writes every CLF-C02 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.