Shared responsibility model Flashcards

1
Q

Which statement is true regarding the AWS Shared Responsibility Model?
Responsibilities vary depending on the services used.
Security of the IaaS services is the responsibility of AWS.
Patching the guest OS is always the responsibility of AWS.
Security of the managed services is the responsibility of the customer.

A

Responsibilities vary depending on the services used.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which activity is a customer responsibility in the AWS Cloud according to the AWS shared responsibility model?
Ensuring network connectivity from AWS to the internet.
Patching and fixing flaws within the AWS Cloud infrastructure.
Ensuring the physical security of cloud data centers.
Ensuring Amazon EBS volumes are backed up.

A

Ensuring Amazon EBS volumes are backed up.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Under the shared responsibility model, which of the following is the responsibility of AWS?
Client-side encryption.
Configuring infrastructure devices.
Server-side encryption.
Filtering traffic with Security Groups.

A

Configuring infrastructure devices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

According to the AWS Shared responsibility model, which of the following are the responsibility of the customer? (Choose TWO)
Managing environmental events of AWS data centers.
Protecting the confidentiality of data in transit in Amazon S3.
Controlling physical access to AWS Regions.
Ensuring that the underlying EC2 host is configured properly.
Patching applications installed on Amazon EC2.

A

Patching applications installed on Amazon EC2.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Based on the AWS Shared Responsibility Model, which of the following are the sole responsibility of AWS? (Choose TWO)
Monitoring network performance.
Installing software on EC2 instances.
Creating hypervisors.
Configuring Access Control Lists (ACLs).
Hardware maintenance.

A

Creating hypervisors.
Hardware maintenance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Using Amazon RDS falls under the shared responsibility model. Which of the following are customer responsibilities? (Choose TWO)
Building the relational database schema.
Performing backups.
Managing the database settings.
Patching the database software.
Installing the database software.

A

Building the relational database schema.
Managing the database settings.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Under the Shared Responsibility Model, which of the following controls do customers fully inherit from AWS? (Choose TWO)
Patch management controls.
Database controls.
Awareness & Training.
Environmental controls.
Physical controls.

A

Environmental controls.
Physical controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which of the following is the responsibility of AWS according to the AWS Shared Responsibility Model?
Securing regions and edge locations.
Performing auditing tasks.
Monitoring AWS resources usage.
Securing access to AWS resources.

A

Securing regions and edge locations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Who is responsible for scaling a DynamoDB database in the AWS Shared Responsibility Model?
Your security team.
Your development team.
AWS.
Your internal DevOps team.

A

AWS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

According to the AWS shared responsibility model, what are the controls that customers fully inherit from AWS? (Choose TWO)
Awareness and Training.
Communications controls.
Data center security controls.
Environmental controls.
Resource Configuration Management.

A

Data center security controls.
Environmental controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which task is AWS responsible for in the shared responsibility model for security and compliance?
Granting access to individuals and services.
Encrypting data in transit.
Updating Amazon EC2 host firmware.
Updating operating systems.

A

Updating Amazon EC2 host firmware.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

According to the AWS shared responsibility model what is the sole responsibility of AWS?
Application security.
Edge location management.
Patch management.
Client-side data.

A

Edge location management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Under the AWS shared responsibility model, which of the following activities are the customer’s responsibility? (Select TWO)
Patching operating system components for Amazon Relational Database Server (Amazon RDS).
Encrypting data on the client-side.
Training the data center staff.
Configuring Network Access Control Lists (ACL).
Maintaining environmental controls within a data center.

A

Encrypting data on the client-side.
Configuring Network Access Control Lists (ACL).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Under the shared responsibility model, which of the following is a shared control between a customer and AWS?
Physical controls.
Patch management.
Zone security.
Data center auditing.

A

Patch management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the AWS customer responsible for according to the AWS shared responsibility model?
Physical access controls.
Data encryption.
Secure disposal of storage devices.
Environmental risk management.

A

Data encryption

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which of the following is the customer’s responsibility under the AWS shared responsibility model?
Patching underlying infrastructure
Physical security
Patching Amazon EC2 instances
Patching network infrastructure

A

Patching Amazon EC2 instances

17
Q

Which of the following is the customer’s responsibility under the AWS shared responsibility model?
Patching underlying infrastructure
Physical security
Patching Amazon EC2 instances
Patching network infrastructure

A
18
Q

According to the AWS shared responsibility model who is responsible for configuration management?
It is solely the responsibility of the customer.
It is solely the responsibility of AWS.
It is shared between AWS and the customer.
It is not part of the AWS shared responsibility model.

A

It is shared between AWS and the customer.

19
Q

Under the shared responsibility model, which of the following tasks are the responsibility of the AWS customer? (Select TWO)
Ensuring that application data is encrypted at rest.
Ensuring that AWS NTP servers are set to the correct time.
Ensuring that users have received security training in the use of AWS services.
Ensuring that access to data centers is restricted.
Ensuring that hardware is disposed of properly.

A

Ensuring that application data is encrypted at rest.
Ensuring that users have received security training in the use of AWS services.

20
Q

Under the shared responsibility model, which of the following is the customer responsible for?
Ensuring that disk drives are wiped after use.
Ensuring that firmware is updated on hardware devices.
Ensuring that data is encrypted at rest.
Ensuring that network cables are category six or higher.

A

Ensuring that data is encrypted at rest.

21
Q

Under the shared responsibility model which of the following areas are the customer’s responsibility? (Select TWO)
Firmware upgrades of network infrastructure.
Patching of operating systems.
Patching of the underlying hypervisor.
Physical security of data centers.
Configuration of the security group.

A

Patching of operating systems.
Patching of the underlying hypervisor.

22
Q

Select TWO examples of the AWS shared controls.
Patch Management.
IAM Management.
VPC Management.
Configuration Management.
Data Center operations.

A

Patch Management.
Configuration Management.

23
Q

What are AWS shared controls?
Controls that are solely the responsibility of the customer based on the application they are deploying within AWS services.
Controls that a customer inherits from AWS.
Controls that apply to both the infrastructure layer and customer layers.
Controls that the customer and AWS collaborate together upon to secure the infrastructure.

A

Controls that apply to both the infrastructure layer and customer layers.

24
Q

Under the shared responsibility model, which of the following is a shared control between a customer and AWS?
Physical controls.
Patch management.
Zone security.
Data center auditing.

A

Patch management.

25
Q

Which statement is true regarding the AWS Shared Responsibility Model?
Responsibilities vary depending on the services used.
Security of the IaaS services is the responsibility of AWS.
Patching the guest OS is always the responsibility of AWS.
Security of the managed services is the responsibility of the customer.

A

Responsibilities vary depending on the services used.

26
Q

Which of the following is a shared control between the customer and AWS?
Providing a key for Amazon S3 client-side encryption.
Configuration of an Amazon EC2 instance.
Environmental controls of physical AWS data centers.
Awareness.

A

Awareness.

27
Q

AWS Shared Responsibility Model

A

AWS Shared Responsibility Model
AWS responsibility - Security of the Cloud
Protecting infrastructure (hardware, software, facilities, and networking) that runs all the AWS services
Managed services like S3, DynamoDB, RDS, etc.
Customer responsibility - Security in the Cloud
For EC2 instance, customer is responsible for management of the guest OS (including security patches and updates), firewall & network configuration, IAM
Encrypting application data
Shared controls:
Patch Management, Configuration Management, Awareness & Training