SCS-C03 Security Foundations and Governance Practice Question
According to the AWS Shared Responsibility Model, which of the following security tasks is the sole responsibility of the customer when using Amazon EC2 instances?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Managing and patching the guest operating system installed on the instance.
The Shared Responsibility Model distinguishes between security 'of' the cloud (AWS) and security 'in' the cloud (customer). For infrastructure services like EC2, AWS manages the physical hardware, virtualization layer, and facility security. The customer is responsible for everything from the operating system up, including patching the OS, managing firewall rules, and protecting their data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Patching the underlying virtualization software on the physical host.
Why it's wrong here
AWS is responsible for the 'security of the cloud,' which includes the physical infrastructure and the virtualization layer (hypervisor) that runs EC2 instances. Customers do not have access to this layer. AWS ensures that the hypervisor is secure and updated to protect all tenants on the physical host.
- ✗
Maintaining the physical security of the data centers where instances reside.
Why it's wrong here
Physical security is a core component of AWS's responsibility. They manage access controls, surveillance, and environmental protections for their global data center infrastructure. Customers benefit from these controls without needing to manage them, as part of the managed infrastructure services provided by the platform.
- ✓
Managing and patching the guest operating system installed on the instance.
Why this is correct
When a customer launches an EC2 instance, they have full administrative control over the guest operating system. Therefore, the customer is responsible for installing security updates, managing user access, and configuring the OS-level firewall. This is a primary example of security 'in' the cloud.
- ✗
Disposing of decommissioned physical storage drives in a secure manner.
Why it's wrong here
AWS manages the lifecycle of all physical hardware used in their data centers. This includes the secure decommissioning and destruction of storage media according to industry standards like NIST 800-88. Customers are responsible for logically deleting their data, but AWS handles the physical destruction of the hardware.
About these practice questions
This SCS-C03 question is part of Courseiva's 99-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C03 exam.