Courseiva
Advanced Topics: Wireless, Cloud, IoT, CryptographymediumMultiple ChoiceObjective-mapped

CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography

In the cloud shared responsibility model, which of the following is typically the responsibility of the customer when using AWS EC2 (IaaS)?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configuring security groups and firewall rules

AWS is responsible for the physical host and network infrastructure; the customer manages the guest OS, applications, and security groups.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configuring security groups and firewall rules

    Why this is correct

    In the cloud shared responsibility model, configuring security groups and firewall rules is a critical customer responsibility, falling under "security in the cloud." Security groups act as virtual firewalls at the instance level, controlling inbound and outbound traffic, while network access control lists (NACLs) operate at the subnet level. Customers must meticulously define these rules to protect their virtual machines, applications, and data from unauthorized network access and potential threats, ensuring proper isolation and secure communication pathways.

  • Patching the hypervisor

    Why it's wrong here

    Patching the hypervisor is exclusively the cloud provider's responsibility, a core component of "security of the cloud." The hypervisor is the virtualization layer that abstracts physical hardware resources, enabling multiple virtual machines to run concurrently. Customers have no access or control over this foundational layer; its maintenance, including applying security patches and updates, is managed entirely by the cloud provider to ensure the stability, security, and integrity of the underlying infrastructure supporting all customer workloads.

  • Network infrastructure redundancy

    Why it's wrong here

    Network infrastructure redundancy, encompassing the design and maintenance of resilient network hardware like routers, switches, and redundant links, is a fundamental "security of the cloud" responsibility belonging to the cloud provider. The provider builds and operates a highly available and fault-tolerant global network fabric to ensure continuous connectivity and minimize service disruptions. Customers consume this robust network without managing its underlying physical or virtual components, relying on the provider to maintain its operational integrity and redundancy.

  • Physical security of data centers

    Why it's wrong here

    The physical security of data centers, including stringent access controls, surveillance systems, environmental monitoring, and perimeter defenses, is entirely the cloud provider's responsibility, falling under "security of the cloud." Customers do not have physical access to the facilities housing their data and infrastructure. The provider is solely accountable for safeguarding the physical assets against unauthorized entry, theft, damage, and environmental hazards, ensuring the foundational security of all hosted resources.

About these practice questions

One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.