DOP-C02 Security and Compliance Practice Question
Which THREE are components of the AWS Shared Responsibility Model? (Choose THREE.)
⚠ Common exam trap
DOP-C02 often tests the Shared Responsibility Model; candidates may incorrectly assume AWS manages IAM roles or patches customer applications, but those are customer responsibilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Customers are responsible for managing IAM users and permissions
Option B is correct because under the AWS Shared Responsibility Model, identity and access management — including creating, managing, and rotating IAM users, groups, roles, and policies — is a customer responsibility in the cloud. Option D is correct because customers are always responsible for the security and classification of their own data, including encryption choices and access controls, regardless of which AWS service is used. Option E is correct because AWS is responsible for security OF the cloud, meaning the physical facilities, hardware, networking, and foundational services that underpin the AWS global infrastructure. Option A is incorrect because patching guest operating systems and customer applications on EC2 is the customer's responsibility, not AWS's. Option C is incorrect because managing customer IAM roles is a customer task; AWS only provides and secures the IAM service itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS is responsible for patching customer applications on EC2
Why it's wrong here
Under the Shared Responsibility Model, AWS is responsible for patching the underlying host operating system and hypervisor that run EC2, but it explicitly does not patch the guest OS, runtime, or applications that customers install on their EC2 instances. Customers control the AMI and any software they deploy, so applying security updates to applications such as web servers, databases, or custom code is entirely the customer's obligation. Misidentifying this boundary is a common cause of vulnerable workloads, because an unpatched application layer remains exploitable even when AWS keeps the physical infrastructure current.
- ✓
Customers are responsible for managing IAM users and permissions
Why this is correct
IAM is a customer-controlled service: customers define users, groups, roles, policies, and permission boundaries, and they are accountable for the identity and access management decisions they implement. AWS provides the IAM service itself and keeps its control plane available, but it does not create, modify, or assume customer identities or make authorization decisions on the customer's behalf. Correctly scoping least-privilege IAM policies, enabling multi-factor authentication, and rotating credentials are customer responsibilities that directly impact the security of everything deployed in the account.
- ✗
AWS is responsible for managing customer IAM roles
Why it's wrong here
AWS does not manage customer IAM roles; roles are identity constructs that customers create, configure, and trust, and AWS only provides the mechanism for assuming them. If AWS were to manage customer IAM roles, it would effectively control who can access customer resources, which would defeat the customer's ability to define its own security posture. Even AWS service-linked roles, while created by AWS on the customer's behalf, are still customer-scoped and must be configured appropriately, so the responsibility for their permissions remains with the customer.
- ✓
Customers are responsible for securing their data in the cloud
Why this is correct
Customers are responsible for protecting their content in the cloud, including data classification, encryption key management, retention, and access controls. AWS offers tools such as KMS, S3 SSE, CloudTrail, and Macie, but the customer decides which data requires protection, which keys are used, and who can decrypt or read it. Because AWS cannot see or interpret customer data on the customer's behalf, any failure to encrypt sensitive data at rest or in transit is the customer's liability, not AWS's.
- ✓
AWS is responsible for the security of the cloud infrastructure
Why this is correct
AWS is responsible for securing the global infrastructure that runs all AWS services, including data centers, hardware, software, networking, and the physical environment. This includes patching the hypervisor, managing the virtualization layer, maintaining the physical network, and implementing environmental controls like power and cooling. Customers inherit protections from this model but must still secure their own guest operating systems, applications, and data, since AWS's infrastructure security does not extend into customer-controlled configurations.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.