2.0 Security and Compliance CLF-C02 Practice Quiz

120 exam-style questions covering 30% of the CLF-C02 exam. Instant feedback on every answer, progress tracking, no signup required.

This domain is part of the AWS Certified Cloud Practitioner practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.

Sample Questions

Which description best matches AWS shared responsibility model in AWS Cloud Practitioner Domain 2.0 Security and Compliance?
  • A. The AWS shared responsibility model defines which security responsibilities belong to AWS and which belong to the customer.
  • B. AWS responsibilities include security of the cloud, such as protecting the infrastructure that runs AWS services.
  • C. Customer responsibilities include security in the cloud, such as managing data, identities, access, and customer-controlled configurations.
  • D. Shared responsibilities are security tasks where both AWS and the customer have roles, such as patching or configuration depending on the service used.

The AWS shared responsibility model defines which security responsibilities belong to AWS and which belong to the customer. This is the correct answer.

Which option correctly defines AWS responsibilities?
  • A. Encryption at rest protects stored data in services, databases, file systems, volumes, or backups.
  • B. AWS responsibilities include security of the cloud, such as protecting the infrastructure that runs AWS services.
  • C. Amazon CloudWatch monitors AWS resources and applications by collecting metrics, logs, and alarms.
  • D. AWS CloudTrail records account activity and API calls for auditing, governance, and operational investigation.

AWS responsibilities include security of the cloud, such as protecting the infrastructure that runs AWS services. This is the correct answer.

A company is reviewing who handles a security task in AWS. Which answer best describes AWS shared responsibility model?
  • A. AWS Audit Manager is the best match when the AWS security or compliance scenario requires this meaning: AWS Audit Manager helps automate evidence collection for audits and compliance assessments.
  • B. AWS shared responsibility model is the best match when the AWS security or compliance scenario requires this meaning: The AWS shared responsibility model defines which security responsibilities belong to AWS and which belong to the customer.
  • C. AWS Security Hub is the best match when the AWS security or compliance scenario requires this meaning: AWS Security Hub provides a centralized view of security findings and security posture across AWS accounts.
  • D. Amazon GuardDuty is the best match when the AWS security or compliance scenario requires this meaning: Amazon GuardDuty is a threat detection service that monitors for malicious or unauthorized activity.

The AWS shared responsibility model defines which security responsibilities belong to AWS and which belong to the customer. This matches the AWS security and compliance scenario without confusing shared responsibility, governance, encryption, monitoring, IAM, or AWS security services. This is the correct answer.

A company is reviewing who handles a security task in AWS. Which answer best describes AWS responsibilities?
  • A. IAM groups is the best match when the AWS security or compliance scenario requires this meaning: IAM groups organize IAM users so permissions can be assigned to multiple users together.
  • B. IAM roles is the best match when the AWS security or compliance scenario requires this meaning: IAM roles provide temporary permissions that can be assumed by users, services, or accounts.
  • C. AWS responsibilities is the best match when the AWS security or compliance scenario requires this meaning: AWS responsibilities include security of the cloud, such as protecting the infrastructure that runs AWS services.
  • D. IAM policies is the best match when the AWS security or compliance scenario requires this meaning: IAM policies are JSON permission documents that define allowed or denied actions on AWS resources.

AWS responsibilities include security of the cloud, such as protecting the infrastructure that runs AWS services. This matches the AWS security and compliance scenario without confusing shared responsibility, governance, encryption, monitoring, IAM, or AWS security services. This is the correct answer.

A company is reviewing who handles a security task in AWS. Which answer best describes Customer responsibilities?
  • A. AWS Shield is the best match when the AWS security or compliance scenario requires this meaning: AWS Shield provides protection against distributed denial-of-service attacks.
  • B. AWS Firewall Manager is the best match when the AWS security or compliance scenario requires this meaning: AWS Firewall Manager centrally manages firewall and protection policies across accounts and resources.
  • C. Amazon Inspector is the best match when the AWS security or compliance scenario requires this meaning: Amazon Inspector helps identify software vulnerabilities and unintended network exposure in supported workloads.
  • D. Customer responsibilities is the best match when the AWS security or compliance scenario requires this meaning: Customer responsibilities include security in the cloud, such as managing data, identities, access, and customer-controlled configurations.

Customer responsibilities include security in the cloud, such as managing data, identities, access, and customer-controlled configurations. This matches the AWS security and compliance scenario without confusing shared responsibility, governance, encryption, monitoring, IAM, or AWS security services. This is the correct answer.

A workload uses EC2, Lambda, or a managed AWS service, and the team must assign the correct security responsibility. Which scenario best matches AWS shared responsibility model?
  • A. A scenario points to MFA when the responsibility, access, governance, or security-service decision depends on this distinction: Multi-factor authentication adds an additional verification factor beyond a password to strengthen account security.
  • B. A scenario points to IAM Identity Center when the responsibility, access, governance, or security-service decision depends on this distinction: AWS IAM Identity Center provides centralized workforce access to AWS accounts and applications.
  • C. A scenario points to AWS shared responsibility model when the responsibility, access, governance, or security-service decision depends on this distinction: The AWS shared responsibility model defines which security responsibilities belong to AWS and which belong to the customer.
  • D. A scenario points to AWS WAF when the responsibility, access, governance, or security-service decision depends on this distinction: AWS WAF helps protect web applications from common web exploits by filtering HTTP and HTTPS requests.

The AWS shared responsibility model defines which security responsibilities belong to AWS and which belong to the customer. This distinction matters because choosing a nearby concept would lead to the wrong responsibility assignment, access-control decision, compliance resource, or security service. This is the correct answer.

A workload uses EC2, Lambda, or a managed AWS service, and the team must assign the correct security responsibility. Which scenario best matches AWS responsibilities?
  • A. A scenario points to AWS shared responsibility model when the responsibility, access, governance, or security-service decision depends on this distinction: The AWS shared responsibility model defines which security responsibilities belong to AWS and which belong to the customer.
  • B. A scenario points to Customer responsibilities when the responsibility, access, governance, or security-service decision depends on this distinction: Customer responsibilities include security in the cloud, such as managing data, identities, access, and customer-controlled configurations.
  • C. A scenario points to Shared responsibilities when the responsibility, access, governance, or security-service decision depends on this distinction: Shared responsibilities are security tasks where both AWS and the customer have roles, such as patching or configuration depending on the service used.
  • D. A scenario points to AWS responsibilities when the responsibility, access, governance, or security-service decision depends on this distinction: AWS responsibilities include security of the cloud, such as protecting the infrastructure that runs AWS services.

AWS responsibilities include security of the cloud, such as protecting the infrastructure that runs AWS services. This distinction matters because choosing a nearby concept would lead to the wrong responsibility assignment, access-control decision, compliance resource, or security service. This is the correct answer.

A leadership team needs the correct shared-responsibility explanation for an AWS workload. Which answer applies AWS shared responsibility model most accurately?
  • A. AWS Artifact is the correct foundational AWS interpretation when the security, identity, compliance, or governance decision depends on this exact meaning: AWS Artifact provides on-demand access to AWS compliance reports and certain agreements.
  • B. AWS compliance requirements is the correct foundational AWS interpretation when the security, identity, compliance, or governance decision depends on this exact meaning: AWS compliance requirements vary by geography, industry, regulation, and service use.
  • C. Encryption in transit is the correct foundational AWS interpretation when the security, identity, compliance, or governance decision depends on this exact meaning: Encryption in transit protects data while it moves across networks or between systems.
  • D. AWS shared responsibility model is the correct foundational AWS interpretation when the security, identity, compliance, or governance decision depends on this exact meaning: The AWS shared responsibility model defines which security responsibilities belong to AWS and which belong to the customer.

The AWS shared responsibility model defines which security responsibilities belong to AWS and which belong to the customer. This applies the concept at the point where a foundational AWS candidate must choose the best security, identity, governance, or compliance explanation for the scenario. This is the correct answer.

Key Terms in This Domain

Link to this quiz

Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:

https://quizbuffet.com/aws-cloud-practitioner/security-and-compliance/

<a href="https://quizbuffet.com/aws-cloud-practitioner/security-and-compliance/">AWS Cloud Practitioner Security and Compliance practice quiz on QuizBuffet</a>

Other CLF-C02 Domains

← Back to CLF-C02 practice test overview

Questions are written against the published CLF-C02 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.