Responsibility Exam Questions 2026–
2027 | Cloud Practitioner Compliance &
Security Prep
1.
A company launches an Amazon EC2 instance running a Linux operating system.
Which responsibility remains with the customer under the AWS Shared
Responsibility Model?
A. Securing the AWS data center
B. Maintaining the physical server
C. Patching the guest operating system
D. Securing the AWS global network
Answer: Patching the guest operating system
Rationale: The customer manages the guest operating system on Amazon EC2,
including applicable updates and security patches. AWS manages the underlying
physical infrastructure, virtualization layer, and facilities.
,2.
Which statement best describes AWS's responsibility under the Shared
Responsibility Model?
A. AWS is responsible for all customer application security
B. AWS is responsible for security of the cloud
C. AWS is responsible for customer IAM policies
D. AWS is responsible for customer data classification
Answer: AWS is responsible for security of the cloud
Rationale: AWS protects the infrastructure that runs AWS services, including the
hardware, software, networking, and facilities. Customers remain responsible
for security in the cloud.
3.
A customer stores confidential documents in Amazon S3. Who is primarily
responsible for determining which users should have permission to access those
documents?
A. AWS physical security team
B. AWS data center administrator
C. The customer
D. AWS Support
Answer: The customer
Rationale: Customers are responsible for managing their data and configuring
appropriate permissions using AWS identity and access management
capabilities.
4.
Which task is an example of AWS's responsibility for security of the cloud?
,A. Configuring an S3 bucket policy
B. Applying patches to an EC2 guest operating system
C. Protecting the physical facilities hosting AWS infrastructure
D. Creating customer IAM users
Answer: Protecting the physical facilities hosting AWS infrastructure
Rationale: Physical security of AWS facilities is part of AWS's security-of-the-
cloud responsibility.
5.
A company uses Amazon EC2 and installs a third-party application on the
instance. Who is responsible for securing that application?
A. AWS
B. The customer
C. The AWS Marketplace seller in all cases
D. AWS Support
Answer: The customer
Rationale: Software installed by the customer on an EC2 instance falls within the
customer's security responsibilities.
6.
Which factor most directly determines how much security configuration a
customer must perform for an AWS service?
A. The customer's AWS Support plan
B. The customer's AWS account age
C. The AWS service selected
D. The AWS Region name
Answer: The AWS service selected
, Rationale: Customer responsibilities vary according to the AWS service being
used. IaaS services generally require more customer management than highly
abstracted managed services.
7.
A customer uses Amazon DynamoDB rather than Amazon EC2. Which statement
is most accurate?
A. The customer must patch the DynamoDB operating system
B. AWS manages more of the underlying infrastructure for DynamoDB
C. The customer must physically secure DynamoDB servers
D. The customer must manage AWS virtualization hosts
Answer: AWS manages more of the underlying infrastructure for DynamoDB
Rationale: DynamoDB is a managed service. AWS manages the underlying
infrastructure and operating environment, while customers remain responsible
for their data, permissions, and service configuration appropriate to their use.
8.
Which responsibility generally remains with the customer regardless of whether
the customer uses highly managed AWS services?
A. Physical security of AWS facilities
B. Hardware maintenance
C. Appropriate management and protection of customer data
D. Maintenance of AWS networking equipment
Answer: Appropriate management and protection of customer data
Rationale: Customers retain responsibility for their data and how it is classified,
accessed, and protected within the AWS environment.
9.