AWS Cloud Practitioner Security practice questions
7-day money-back guarantee — full refund within 7 days of purchase if you've completed under 20% of the questions. See pricing →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

Language

✓ EnglishDeutschEspañolFrançaisPortuguês
Check readiness — free →

AWS Cloud Practitioner Security and Compliance: 335 practice questions

AWS Cloud Practitioner 335 questions 12 shown free

12 of the 335 Security and Compliance questions in the Certsqill AWS Cloud Practitioner bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.

Preparing for AWS Cloud Practitioner? Take the free 5-min readiness check →

1. AWS: Which option is the best fit?

Easy
A logistics provider asks who protects AWS data center buildings, physical hardware, and underlying networking. Which option is the best fit?
  1. AWS
    AWS protects physical facilities, hardware, networking, and virtualization supporting AWS cloud infrastructure.
  2. The customer
    Customers protect their data, identities, permissions, and workload configuration, not AWS data center facilities or underlying hardware.
  3. AWS Support
    AWS Support provides assistance, but the shared responsibility model assigns physical facility and hardware protection to AWS itself.
  4. The application vendor
    An application vendor may support its software, but it does not own AWS responsibility for facilities and physical infrastructure.
The trap
Assigns AWS infrastructure protection to the customer. Confuses application support with cloud infrastructure ownership. Confuses a support offering with the underlying security owner.

AWS protects its physical facilities and underlying cloud infrastructure; customers protect their workloads and access configuration.

2. The customer: Which option is the best fit?

Hard
A travel service runs applications on Amazon EC2 and asks who must patch the guest operating system. Which option is the best fit?
  1. AWS data center operations
    AWS manages facilities and underlying infrastructure, but EC2 customers manage the guest operating system running inside their instances.
  2. The customer
    For EC2, customers manage the guest operating system, including applying appropriate operating system patches.
  3. The managed service team
    EC2 is not a fully managed application platform; the customer retains responsibility for the guest operating system and applications.
  4. AWS compliance auditors
    Compliance auditors may assess controls, but they do not operate or patch the customer's EC2 guest operating system.
The trap
Confuses infrastructure maintenance with guest operating system maintenance. Applies managed-service responsibilities to customer-managed EC2 instances. Confuses assessment activities with operational responsibility.

EC2 customers manage guest operating systems and applications, while AWS manages the underlying cloud infrastructure.

3. The customer: Which option is the best fit?

Easy
A new cloud learner deploys an application and asks who owns responsibility for the application's code and configuration. Which option is the best fit?
  1. The AWS network team
    AWS manages its networking infrastructure, but the customer remains responsible for application code and appropriate workload configuration.
  2. The customer
    Customers control and remain responsible for their application code, data, identities, permissions, and appropriate workload configuration.
  3. The AWS billing service
    Billing services report or manage charges, but they do not own or maintain customer application code and configuration.
  4. AWS physical security
    AWS physical security covers facilities and infrastructure, not the customer's application code or workload-specific configuration.
The trap
Confuses physical infrastructure protection with application ownership. Confuses AWS networking operations with customer application responsibilities. Confuses financial administration with workload ownership.

Customers remain responsible for application code and workload configuration, even when AWS operates the underlying cloud infrastructure.

4. The customer: Which option is the best fit?

Medium
A finance department uses Amazon RDS and asks who is responsible for protecting its database records and permissions. Which option is the best fit?
  1. The RDS service name
    RDS provides managed database capabilities, but service availability does not itself own or govern the customer's records and permissions.
  2. AWS hardware operations
    AWS manages underlying hardware and infrastructure for RDS, but the customer remains responsible for its database data and access permissions.
  3. The physical data center contractor
    Physical contractors may support facilities, but they do not control the customer's database records or permissions.
  4. The customer
    Customers remain responsible for their data and permissions in RDS, while AWS manages more of the underlying database infrastructure.
The trap
Confuses managed infrastructure with customer data protection. Treats a service capability as the responsible party. Confuses facility support with workload data and access responsibility.

RDS shifts more infrastructure operations to AWS, but customers still manage their database data and permissions.

5. AWS Lambda service: Which AWS service is the best fit?

Easy
A regional distributor wants to run application code without managing the underlying servers. Which AWS service is the best fit?
  1. Amazon S3 storage
    Amazon S3 stores objects and does not primarily provide general-purpose application-code execution.
  2. AWS Lambda service
    AWS Lambda runs application code while AWS manages the underlying servers and infrastructure.
  3. Amazon RDS
    Amazon RDS manages relational databases, not general application-code execution without database responsibilities.
  4. Amazon EC2
    Amazon EC2 provides virtual servers, so the customer manages more operating-system and instance responsibilities.
The trap
Confuses virtual server access with serverless execution. Selects a managed database service for a compute requirement. Confuses object storage with compute.

AWS Lambda runs code while AWS manages the underlying infrastructure.

6. The customer organization: Which answer is best?

Hard
A new cloud learner asks who decides whether business records are confidential and what protections they require. Which answer is best?
  1. The customer’s cloud account
    An account identifies resources and billing, but it does not independently classify the information stored within them.
  2. AWS
    AWS protects its cloud infrastructure, but it does not classify each customer’s information for the customer.
  3. The customer organization
    The customer controls its data and determines classifications and handling requirements according to its business and compliance needs.
  4. The AWS hosting facility
    The facility protects physical infrastructure, but its location does not determine the customer’s data classification.
The trap
Confuses AWS infrastructure protection with customer data governance. Treats an account boundary as a data-classification authority. Confuses facility security with information classification.

The customer organization determines data sensitivity and handling requirements.

7. The travel service must configure the identities: Who must configure permissions so only approved users can ac

Medium
A travel service stores private customer documents in Amazon S3. Who must configure permissions so only approved users can access them?
  1. AWS automatically configures the required permissions for every S3 object
    S3 encrypts new objects at rest by default, but customers still configure access permissions and policies.
  2. The travel service must configure the identities, policies, and permissions controlling document access
    Customers control identities and access configuration, including permissions determining who can access S3 documents.
  3. AWS Support approves each individual user before document access becomes possible
    AWS Support does not approve routine customer users; the customer manages identities and authorization settings.
  4. The S3 storage hardware determines which approved users may retrieve documents
    Storage hardware supports the service, but it does not replace customer-managed identities and access configuration.
The trap
Confuses default encryption with automatic authorization. Confuses infrastructure operation with authorization management. Treats support personnel as workload access administrators.

The travel service remains responsible for identities and S3 permissions, even though AWS operates the storage infrastructure.

8. The customer must evaluate requirements and configure: What should it conclude about whether its workload is c

Medium
A regional distributor uses AWS services with relevant certifications. What should it conclude about whether its workload is compliant?
  1. The customer must evaluate requirements and configure the workload appropriately
    Customers remain responsible for assessing applicable requirements and configuring their workloads to address them.
  2. AWS certifications automatically make every customer workload compliant
    AWS certification addresses AWS controls and scope; it does not automatically validate every customer workload.
  3. The workload is compliant whenever it runs in an AWS Region
    Region selection does not by itself establish compliance with the customer’s legal, regulatory, or business requirements.
  4. AWS Support determines compliance after the workload is deployed
    AWS Support does not automatically certify customer workloads; customers must assess and manage their own compliance responsibilities.
The trap
Confuses provider certification with customer workload compliance. Treats geographic hosting location as complete compliance evidence. Assigns customer compliance evaluation to support personnel.

AWS certifications do not automatically certify customer workloads; customers must evaluate requirements and configure workloads appropriately.

9. Amazon RDS: Which service is the best fit?

Easy
An online retailer needs a managed relational database and wants AWS to handle more database infrastructure operations. Which service is the best fit?
  1. Amazon RDS
    Amazon RDS is a managed relational database service that shifts more infrastructure operations from the customer to AWS.
  2. Amazon S3
    Amazon S3 provides object storage rather than relational database capabilities and database-engine management.
  3. AWS Lambda
    AWS Lambda runs event-driven code and is not primarily a managed relational database service.
  4. Amazon EC2
    Amazon EC2 supplies virtual servers, leaving the retailer with more database operating and maintenance responsibilities.
The trap
Chooses flexible compute when managed database operations are preferred. Confuses managed compute with managed relational databases. Confuses object storage with relational data services.

Amazon RDS provides managed relational databases, shifting more database infrastructure operations to AWS than Amazon EC2.

10. Customer configures network settings: Which responsibility remains with the customer?

Easy
A finance department uses AWS networking services. Which responsibility remains with the customer?
  1. AWS chooses the customer’s access policies
    Customers control identities and access configuration, including policies governing access to their resources.
  2. AWS protects its physical facilities
    AWS protects physical facilities as part of infrastructure security, rather than treating that activity as customer responsibility.
  3. Customer configures network settings
    Customers configure appropriate workload settings, including network configuration governing how their resources communicate.
  4. AWS manages the customer’s data classifications
    Customers control and classify their data according to their own business and compliance requirements.
The trap
Reverses the physical infrastructure responsibility boundary. Assigns customer data governance to AWS. Confuses AWS infrastructure operation with customer authorization.

Customers configure their workload networking, while AWS protects the underlying physical facilities and infrastructure.

11. Customer credentials: Which item remains the customer’s responsibility?

Medium
An IT procurement team is reviewing an AWS deployment. Which item remains the customer’s responsibility?
  1. AWS hardware
    AWS protects and operates the physical hardware supporting its cloud infrastructure.
  2. AWS physical facilities
    AWS is responsible for securing the physical facilities where its cloud infrastructure operates.
  3. AWS virtualization layer
    AWS manages the virtualization layer supporting its cloud infrastructure under the shared responsibility model.
  4. Customer credentials
    Customers manage their identities and credentials, including appropriate protection and access control for AWS resources.
The trap
Confuses customer account control with AWS hardware ownership. Assigns facility security to the customer. Confuses workload administration with underlying virtualization security.

Customers manage credentials and identities, while AWS protects hardware, facilities, and the virtualization layer.

12. AWS: Which answer is correct?

Medium
A customer support team asks who is responsible for securing the physical facilities that host AWS infrastructure. Which answer is correct?
  1. AWS
    AWS protects the physical facilities, hardware, networking, and virtualization forming its cloud infrastructure.
  2. The customer’s application team
    Application teams configure workloads and applications, but AWS secures the physical facilities hosting the cloud infrastructure.
  3. The customer’s data owners
    Data owners govern information and access needs, but they do not secure AWS physical facilities.
  4. AWS Support agents individually
    Physical facility security is an AWS infrastructure responsibility, not an individual support-agent activity.
The trap
Confuses application responsibility with facility security. Confuses data governance with physical infrastructure protection. Narrows an organizational responsibility to support personnel.

AWS secures the physical facilities and infrastructure underlying its cloud, while customers secure their workloads and data.

323 more Security and Compliance questions

The remaining 323 questions in this domain are part of the full AWS Cloud Practitioner bank — 1119 questions, every option explained. Start with the free five-minute check and see your score per domain.

Test your AWS Cloud Practitioner readiness — free

Other AWS Cloud Practitioner domains

Part of the Certsqill AWS Cloud Practitioner question bank · Security and Compliance · Every answer, right and wrong, comes with its own explanation.