CLF-C02 Security and Compliance Practice Question
A company runs a web application on Amazon EC2 instances. Under the AWS Shared Responsibility Model, who is responsible for patching the operating system on the EC2 instances?
⚠ Common exam trap
It's easy for candidates to assume AWS handles all patching for EC2 because it is a managed service, but the Shared Responsibility Model clearly assigns guest OS patching to the customer for IaaS services like EC2.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The customer, because OS patching is in the customer's area of responsibility for IaaS services
Under the AWS Shared Responsibility Model, for Infrastructure as a Service (IaaS) like EC2, the customer is responsible for managing the guest operating system, including patching and security updates. AWS is responsible for the physical infrastructure and the hypervisor layer, but not for the OS running inside the EC2 instance. Therefore, option B is correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS, because they own and operate all EC2 infrastructure
Why it's wrong here
AWS does own and operate the physical data centers, hardware, and the hypervisor that isolates EC2 instances, but infrastructure ownership does not extend to the guest operating system. The service boundary for EC2 is explicit: once an instance is launched, the OS, applications, and their patches are under the customer's control. Therefore, AWS's ownership of the physical infrastructure is irrelevant to the specific duty of OS patching, making this answer incorrect.
- ✓
The customer, because OS patching is in the customer's area of responsibility for IaaS services
Why this is correct
EC2 is an Infrastructure as a Service (IaaS) offering, and the shared responsibility model places the guest OS squarely in the customer's domain. The customer selects the AMI, configures the OS, and must apply security patches, updates, and compliance fixes. AWS's responsibility ends at the hypervisor and physical hardware, so the correct party is the customer.
- ✗
Both AWS and the customer equally share this responsibility
Why it's wrong here
The shared responsibility model is not a 50/50 split; it is a layered boundary. For EC2, AWS manages everything below the hypervisor—physical hosts, storage, networking—while the customer manages everything from the guest OS upward, including patches. Saying 'equally share' implies both parties co-own the same component, but OS patching is an exclusively customer-owned task, so this option misstates the model.
- ✗
A third-party managed service provider designated by AWS
Why it's wrong here
AWS never designates a third-party provider to perform OS patching on a customer's EC2 instance. The customer may choose to use a managed service provider or AWS's own Systems Manager Patch Manager, but that is a licensed, delegated tool—not a default responsibility transfer. The underlying obligation remains with the customer, and any third-party help is a contractual arrangement, meaning this option misidentifies the accountable party.
Go deeper
Related to this question
About these practice questions
This CLF-C02 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.