CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography
In the cloud shared responsibility model, which of the following is typically the responsibility of the customer when using AWS EC2 (IaaS)?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configuring security groups and firewall rules
AWS is responsible for the physical host and network infrastructure; the customer manages the guest OS, applications, and security groups.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configuring security groups and firewall rules
Why this is correct
In the cloud shared responsibility model, configuring security groups and firewall rules is a critical customer responsibility, falling under "security in the cloud." Security groups act as virtual firewalls at the instance level, controlling inbound and outbound traffic, while network access control lists (NACLs) operate at the subnet level. Customers must meticulously define these rules to protect their virtual machines, applications, and data from unauthorized network access and potential threats, ensuring proper isolation and secure communication pathways.
- ✗
Patching the hypervisor
Why it's wrong here
Patching the hypervisor is exclusively the cloud provider's responsibility, a core component of "security of the cloud." The hypervisor is the virtualization layer that abstracts physical hardware resources, enabling multiple virtual machines to run concurrently. Customers have no access or control over this foundational layer; its maintenance, including applying security patches and updates, is managed entirely by the cloud provider to ensure the stability, security, and integrity of the underlying infrastructure supporting all customer workloads.
- ✗
Network infrastructure redundancy
Why it's wrong here
Network infrastructure redundancy, encompassing the design and maintenance of resilient network hardware like routers, switches, and redundant links, is a fundamental "security of the cloud" responsibility belonging to the cloud provider. The provider builds and operates a highly available and fault-tolerant global network fabric to ensure continuous connectivity and minimize service disruptions. Customers consume this robust network without managing its underlying physical or virtual components, relying on the provider to maintain its operational integrity and redundancy.
- ✗
Physical security of data centers
Why it's wrong here
The physical security of data centers, including stringent access controls, surveillance systems, environmental monitoring, and perimeter defenses, is entirely the cloud provider's responsibility, falling under "security of the cloud." Customers do not have physical access to the facilities housing their data and infrastructure. The provider is solely accountable for safeguarding the physical assets against unauthorized entry, theft, damage, and environmental hazards, ensuring the foundational security of all hosted resources.
Go deeper
Related to this question
About these practice questions
One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.