CLF-C02 Cloud Concepts Practice Question
A company is migrating an on-premises application to AWS. The application will run on Amazon EC2 instances and use an Amazon RDS for MySQL database. The security team needs to understand which security controls remain the company's responsibility after the migration. Under the AWS Shared Responsibility Model, which of the following is the customer's responsibility?
⚠ Common exam trap
Many candidates confuse the responsibility for patching in managed services like RDS versus unmanaged services like EC2, assuming the customer must patch everything in RDS, when in fact AWS handles the database engine and OS patching for RDS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Patching the guest operating system on the Amazon EC2 instances.
Under the AWS Shared Responsibility Model, the customer is responsible for patching the guest operating system on Amazon EC2 instances because EC2 is an Infrastructure as a Service (IaaS) offering where AWS manages the hypervisor and physical infrastructure, but the customer has full control over the OS, applications, and configurations. In contrast, for Amazon RDS, AWS handles patching of the database engine (e.g., MySQL) and the underlying OS, making option A AWS's responsibility. Physical security at AWS data centers is always AWS's responsibility, not the customer's.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Patching the MySQL database engine for the Amazon RDS instance.
Why it's wrong here
Amazon RDS is a fully managed database service, which means AWS handles the operational heavy lifting, including patching of the MySQL database engine itself, whether it is a security fix or a minor version upgrade. You are responsible for your data, managing access with IAM and security groups, and setting the maintenance window, but you never log in to the underlying host or apply engine patches. Attempting to patch the engine yourself would be unnecessary and unsupported because AWS applies and controls those changes as part of the managed service.
When this WOULD be correct
This option would be correct if the question specified a self-managed database on EC2 (e.g., 'Amazon EC2 instances running MySQL') or if the RDS instance was configured for 'custom' or 'self-managed' patching (e.g., RDS Custom). In those cases, the customer is responsible for patching the database engine.
- ✓
Patching the guest operating system on the Amazon EC2 instances.
Why this is correct
Under the AWS shared responsibility model, Amazon EC2 is an Infrastructure-as-a-Service offering, so, while AWS secures the underlying hypervisor and physical hosts, you are entirely accountable for managing and patching the guest operating system on each EC2 instance. This includes applying security updates, configuring the OS with tools like AWS Systems Manager Patch Manager, and maintaining compliance inside the instance. AWS provides the infrastructure, but the OS kernel, system libraries, and applications are your boundary of responsibility.
- ✗
Providing physical security at the AWS data center facilities.
Why it's wrong here
Physical security at AWS data centers, including guards, biometric entry systems, fencing, and surveillance, is exclusively AWS's responsibility, as customers are never granted access to the physical facilities per the shared responsibility model. This obligation protects the underlying hardware that hosts customer workloads, and it is a foundational 'security of the cloud' element. A customer's duty begins only after they authenticate to the AWS API and control plane, not at the facility gate.
When this WOULD be correct
This option would be correct in a question about a customer's responsibility when using a colocation facility (e.g., AWS Direct Connect location) where the customer leases space and must manage physical security for their own equipment.
- ✗
Replacing failed network switches in the AWS global network.
Why it's wrong here
Replacing failed network switches in the AWS global network is a physical layer operation performed by AWS data center engineers, not by customers. The entire networking fabric—switches, routers, cabling, and uplinks—is part of AWS's 'security of the cloud' responsibility, and its failure or replacement never becomes a customer action. Customers only interact with virtual network constructs such as VPCs, subnets, and security groups, so hardware-level switch replacement is categorically outside any customer's operational scope.
When this WOULD be correct
This option would be correct in a question about on-premises data centers or colocation facilities where the customer is responsible for all hardware maintenance, including network switches. For example, in a hybrid setup where the customer manages their own network gear.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓Patching the guest operating system on the Amazon EC2 instances.Correct answer▾
Why this is correct
Under the AWS shared responsibility model, Amazon EC2 is an Infrastructure-as-a-Service offering, so, while AWS secures the underlying hypervisor and physical hosts, you are entirely accountable for managing and patching the guest operating system on each EC2 instance. This includes applying security updates, configuring the OS with tools like AWS Systems Manager Patch Manager, and maintaining compliance inside the instance. AWS provides the infrastructure, but the OS kernel, system libraries, and applications are your boundary of responsibility.
✗Patching the MySQL database engine for the Amazon RDS instance.Wrong answer — click to see why▾
Why this is wrong here
Under the AWS Shared Responsibility Model, AWS manages the database engine patching for Amazon RDS, including MySQL. The customer is responsible for patching the guest OS on EC2 instances, not the RDS database engine.
★ When this WOULD be the correct answer
This option would be correct if the question specified a self-managed database on EC2 (e.g., 'Amazon EC2 instances running MySQL') or if the RDS instance was configured for 'custom' or 'self-managed' patching (e.g., RDS Custom). In those cases, the customer is responsible for patching the database engine.
Why candidates choose this
Candidates may confuse database patching responsibilities, assuming that since the database is customer-managed content, patching the engine is always the customer's job, not realizing AWS handles it for managed services like RDS.
✗Providing physical security at the AWS data center facilities.Wrong answer — click to see why▾
Why this is wrong here
Under the AWS Shared Responsibility Model, AWS is responsible for physical security at its data centers, including access controls, surveillance, and environmental safeguards. Customers are not responsible for physical security of AWS facilities.
★ When this WOULD be the correct answer
This option would be correct in a question about a customer's responsibility when using a colocation facility (e.g., AWS Direct Connect location) where the customer leases space and must manage physical security for their own equipment.
Why candidates choose this
Candidates may confuse physical security with broader security responsibilities, mistakenly believing that all security controls, including physical ones, fall under the customer's purview.
✗Replacing failed network switches in the AWS global network.Wrong answer — click to see why▾
Why this is wrong here
Replacing failed network switches in the AWS global network is an infrastructure maintenance task that AWS handles under the Shared Responsibility Model. The customer has no responsibility for physical hardware or network devices in AWS data centers.
★ When this WOULD be the correct answer
This option would be correct in a question about on-premises data centers or colocation facilities where the customer is responsible for all hardware maintenance, including network switches. For example, in a hybrid setup where the customer manages their own network gear.
Why candidates choose this
Candidates may confuse the Shared Responsibility Model with traditional on-premises operations, assuming they must handle all hardware replacements, or they may think that network switches are part of the customer's virtual network responsibility.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
Courseiva writes every CLF-C02 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.