AWS Cloud Practitioner Security and Compliance: 335 practice questions
12 of the 335 Security and Compliance questions in the Certsqill AWS Cloud Practitioner bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for AWS Cloud Practitioner? Take the free 5-min readiness check →
1. AWS: Which option is the best fit?
- AWS ✓AWS protects physical facilities, hardware, networking, and virtualization supporting AWS cloud infrastructure.
- The customerCustomers protect their data, identities, permissions, and workload configuration, not AWS data center facilities or underlying hardware.
- AWS SupportAWS Support provides assistance, but the shared responsibility model assigns physical facility and hardware protection to AWS itself.
- The application vendorAn application vendor may support its software, but it does not own AWS responsibility for facilities and physical infrastructure.
AWS protects its physical facilities and underlying cloud infrastructure; customers protect their workloads and access configuration.
2. The customer: Which option is the best fit?
- AWS data center operationsAWS manages facilities and underlying infrastructure, but EC2 customers manage the guest operating system running inside their instances.
- The customer ✓For EC2, customers manage the guest operating system, including applying appropriate operating system patches.
- The managed service teamEC2 is not a fully managed application platform; the customer retains responsibility for the guest operating system and applications.
- AWS compliance auditorsCompliance auditors may assess controls, but they do not operate or patch the customer's EC2 guest operating system.
EC2 customers manage guest operating systems and applications, while AWS manages the underlying cloud infrastructure.
3. The customer: Which option is the best fit?
- The AWS network teamAWS manages its networking infrastructure, but the customer remains responsible for application code and appropriate workload configuration.
- The customer ✓Customers control and remain responsible for their application code, data, identities, permissions, and appropriate workload configuration.
- The AWS billing serviceBilling services report or manage charges, but they do not own or maintain customer application code and configuration.
- AWS physical securityAWS physical security covers facilities and infrastructure, not the customer's application code or workload-specific configuration.
Customers remain responsible for application code and workload configuration, even when AWS operates the underlying cloud infrastructure.
4. The customer: Which option is the best fit?
- The RDS service nameRDS provides managed database capabilities, but service availability does not itself own or govern the customer's records and permissions.
- AWS hardware operationsAWS manages underlying hardware and infrastructure for RDS, but the customer remains responsible for its database data and access permissions.
- The physical data center contractorPhysical contractors may support facilities, but they do not control the customer's database records or permissions.
- The customer ✓Customers remain responsible for their data and permissions in RDS, while AWS manages more of the underlying database infrastructure.
RDS shifts more infrastructure operations to AWS, but customers still manage their database data and permissions.
5. AWS Lambda service: Which AWS service is the best fit?
- Amazon S3 storageAmazon S3 stores objects and does not primarily provide general-purpose application-code execution.
- AWS Lambda service ✓AWS Lambda runs application code while AWS manages the underlying servers and infrastructure.
- Amazon RDSAmazon RDS manages relational databases, not general application-code execution without database responsibilities.
- Amazon EC2Amazon EC2 provides virtual servers, so the customer manages more operating-system and instance responsibilities.
AWS Lambda runs code while AWS manages the underlying infrastructure.
6. The customer organization: Which answer is best?
- The customer’s cloud accountAn account identifies resources and billing, but it does not independently classify the information stored within them.
- AWSAWS protects its cloud infrastructure, but it does not classify each customer’s information for the customer.
- The customer organization ✓The customer controls its data and determines classifications and handling requirements according to its business and compliance needs.
- The AWS hosting facilityThe facility protects physical infrastructure, but its location does not determine the customer’s data classification.
The customer organization determines data sensitivity and handling requirements.
7. The travel service must configure the identities: Who must configure permissions so only approved users can ac
- AWS automatically configures the required permissions for every S3 objectS3 encrypts new objects at rest by default, but customers still configure access permissions and policies.
- The travel service must configure the identities, policies, and permissions controlling document access ✓Customers control identities and access configuration, including permissions determining who can access S3 documents.
- AWS Support approves each individual user before document access becomes possibleAWS Support does not approve routine customer users; the customer manages identities and authorization settings.
- The S3 storage hardware determines which approved users may retrieve documentsStorage hardware supports the service, but it does not replace customer-managed identities and access configuration.
The travel service remains responsible for identities and S3 permissions, even though AWS operates the storage infrastructure.
8. The customer must evaluate requirements and configure: What should it conclude about whether its workload is c
- The customer must evaluate requirements and configure the workload appropriately ✓Customers remain responsible for assessing applicable requirements and configuring their workloads to address them.
- AWS certifications automatically make every customer workload compliantAWS certification addresses AWS controls and scope; it does not automatically validate every customer workload.
- The workload is compliant whenever it runs in an AWS RegionRegion selection does not by itself establish compliance with the customer’s legal, regulatory, or business requirements.
- AWS Support determines compliance after the workload is deployedAWS Support does not automatically certify customer workloads; customers must assess and manage their own compliance responsibilities.
AWS certifications do not automatically certify customer workloads; customers must evaluate requirements and configure workloads appropriately.
9. Amazon RDS: Which service is the best fit?
- Amazon RDS ✓Amazon RDS is a managed relational database service that shifts more infrastructure operations from the customer to AWS.
- Amazon S3Amazon S3 provides object storage rather than relational database capabilities and database-engine management.
- AWS LambdaAWS Lambda runs event-driven code and is not primarily a managed relational database service.
- Amazon EC2Amazon EC2 supplies virtual servers, leaving the retailer with more database operating and maintenance responsibilities.
Amazon RDS provides managed relational databases, shifting more database infrastructure operations to AWS than Amazon EC2.
10. Customer configures network settings: Which responsibility remains with the customer?
- AWS chooses the customer’s access policiesCustomers control identities and access configuration, including policies governing access to their resources.
- AWS protects its physical facilitiesAWS protects physical facilities as part of infrastructure security, rather than treating that activity as customer responsibility.
- Customer configures network settings ✓Customers configure appropriate workload settings, including network configuration governing how their resources communicate.
- AWS manages the customer’s data classificationsCustomers control and classify their data according to their own business and compliance requirements.
Customers configure their workload networking, while AWS protects the underlying physical facilities and infrastructure.
11. Customer credentials: Which item remains the customer’s responsibility?
- AWS hardwareAWS protects and operates the physical hardware supporting its cloud infrastructure.
- AWS physical facilitiesAWS is responsible for securing the physical facilities where its cloud infrastructure operates.
- AWS virtualization layerAWS manages the virtualization layer supporting its cloud infrastructure under the shared responsibility model.
- Customer credentials ✓Customers manage their identities and credentials, including appropriate protection and access control for AWS resources.
Customers manage credentials and identities, while AWS protects hardware, facilities, and the virtualization layer.
12. AWS: Which answer is correct?
- AWS ✓AWS protects the physical facilities, hardware, networking, and virtualization forming its cloud infrastructure.
- The customer’s application teamApplication teams configure workloads and applications, but AWS secures the physical facilities hosting the cloud infrastructure.
- The customer’s data ownersData owners govern information and access needs, but they do not secure AWS physical facilities.
- AWS Support agents individuallyPhysical facility security is an AWS infrastructure responsibility, not an individual support-agent activity.
AWS secures the physical facilities and infrastructure underlying its cloud, while customers secure their workloads and data.
323 more Security and Compliance questions
The remaining 323 questions in this domain are part of the full AWS Cloud Practitioner bank — 1119 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your AWS Cloud Practitioner readiness — freeOther AWS Cloud Practitioner domains
- Cloud Technology and Services — 381 questions →
- Cloud Concepts — 269 questions →
- Billing, Pricing, and Support — 134 questions →
- All 1119 AWS Cloud Practitioner questions →