Many people assume that when they use AWS, AWS handles all the security. In reality, responsibility is split between AWS and the customer. This is called the Shared Responsibility Model.
It is one of the most frequently tested topics on the CLF-C02 exam.
---
Think of It Like an Apartment
Imagine you live in an apartment building.
The landlord (AWS) is responsible for the building structure, elevators, shared electrical systems, and the exterior walls. But arranging the furniture inside your unit, locking your front door, and protecting your personal belongings is the tenant's (customer's) job.
Even in the best apartment building, if you leave your front door unlocked, a thief can get in. AWS works the same way.
---
The Core Distinction in One Line
AWS responsibility: "Security OF the Cloud"
Customer responsibility: "Security IN the Cloud"
Remember this one line and you can answer the majority of these exam questions.
---
What AWS Is Responsible For
AWS protects the cloud infrastructure itself.
Physical data center security (building, power supply, cooling systems) Server hardware and network infrastructure Virtualization layer (hypervisor) Underlying software updates for managed services
AWS data center locations are not even publicly disclosed. Physical security is entirely AWS's domain.
---
What the Customer Is Responsible For
Customers must protect what they run on top of the cloud.
Data encryption configuration Operating system security patches (for virtual servers like EC2) Firewall rules (Security Groups, Network ACLs) IAM user accounts and permission management Application code security
!The AWS shared responsibility model
Responsibility Changes Depending on the Service
This is the most important point. The service you choose changes how much you are responsible for.
| Service | Customer Responsibility | AWS Responsibility | |---------|------------------------|-------------------| | Amazon EC2 | OS patching, firewall, apps, data | Physical servers, virtualization layer | | Amazon RDS | Data, user access management | OS patching, DB engine patching, backup infrastructure | | AWS Lambda | Code, data, IAM settings | OS, runtime, all infrastructure | | Amazon S3 | Data, bucket policies, encryption settings | Storage infrastructure, availability |
The core rule: the more AWS manages for you (Lambda, RDS), the less you have to worry about.
---
Always the Customer's Responsibility
No matter which service you use, these are always yours to manage:
Classifying and managing your own data IAM user accounts and permission settings Client-side encryption Protecting network traffic
---
Always AWS's Responsibility
Physical data centers (buildings, hardware) Global network infrastructure Virtualization layer (hypervisor) management Physical separation between Availability Zones
---
Exam Key Points
"Physical data center security" -- always AWS responsibility
"OS patching on EC2" -- customer responsibility (AWS does not manage this for you)
"OS patching on RDS" -- AWS responsibility (it is a managed service)
"Data encryption" -- always customer responsibility
"IAM user and permission management" -- always customer responsibility
"DB engine patching (RDS)" -- AWS responsibility
More managed the service, less the customer is responsible for
"Security OF the cloud = AWS" / "Security IN the cloud = Customer" — this one sentence is the key