SAA-C03 · Secure Access to AWS Resources
21 cards
AWS Shared Responsibility Model
-
Quick check
A team is deciding who owns which control before designing an AWS workload. Which split matches the model?
AAWS and the customer configure each workload control together.
Joint configuration of every control is not the split: the customer keeps control of the protections for its own content, applications, systems, and networks.
BAWS secures the cloud itself; the customer secures what it runs in the cloud.
Right. AWS manages security of the cloud, and the customer is responsible for security in the cloud.
CThe customer secures the cloud; AWS secures the customer's applications.
The two sides are reversed. AWS protects the infrastructure, not the customer's applications and content.
3 / 21
-
Quick check
Which item does a customer no longer manage after moving a workload to AWS?
AThe physical servers and storage devices under the service
Right. Customers do not manage physical servers or storage devices; that layer stays with AWS.
BThe access rules chosen for its own application
Access control for the customer's own application is a workload decision and stays with the customer.
CThe monitoring applied to traffic entering and leaving its resources
Watching information flow into and out of its cloud resources is exactly what the customer keeps doing.
5 / 21
-
Quick check
What does a customer inherit from AWS before configuring anything?
AA least-privilege permission set built automatically for each of its applications
Permissions for a specific application are workload configuration, and the customer designs them.
BOwnership of the data centers and hardware that host its workloads
Customers do not own or manage the facilities and hardware; AWS operates that layer.
CAWS policies, architecture, and operational processes
Right. The inherited protection is the set of AWS policies, architecture, and operational processes that guard the infrastructure.
8 / 21
-
Keep your progress in the app
That’s 3 of 8 quick checks. In the app they stay answered, and every lesson remembers where you left off.
-
Quick check
A team switches on AWS access-control and encryption features for its application. What is still true?
AThe team still chooses and applies its own workload controls.
Right. These features are mechanisms the customer selects; responsibility for the workload's controls stays with the customer.
BAWS now owns the content of the application and the rules protecting it.
Content and application rules remain under the customer's control whatever features are enabled.
CThe features hand application and network security to AWS operations.
AWS controls complement the customer's workload controls rather than replacing them.
11 / 21
-
Quick check
How should compliance be treated when reviewing an AWS architecture?
AAs an AWS duty, since its environments are audited and certified
Infrastructure certification covers part of the obligation, not the customer's own workload controls.
BAs shared work: inherited infrastructure controls plus customer controls
Right. Compliance is shared: AWS infrastructure programs cover part of it, and the customer's workload configuration covers the rest.
CAs work owned entirely by the accreditation body that issues the certificate
Accreditation bodies certify environments; they do not take on either side's operating duties.
14 / 21
-
Quick check
An audit lists two controls: data-center operations and permissions for a customer analytics platform. How should they be assigned?
ABoth to AWS, since certified infrastructure runs the platform
Certified infrastructure does not absorb the platform's permissions, which the customer chooses and operates.
BBoth to the customer, since it owns the analytics data
Owning the data does not make the customer the operator of AWS data centers.
CData-center operations to AWS, platform permissions to the customer
Right. Infrastructure operations sit with AWS while workload permissions sit with the customer, so both kinds of control are preserved.
16 / 21
-
Quick check
After an incident a company must fix an application access rule and confirm facility safeguards, without operating hardware. Which plan fits?
AFix the access rule; rely on AWS for the facilities.
Right. Workload remediation stays with the company, and facility protection stays with AWS.
BAsk AWS to fix the access rule while the company inspects the facilities.
The access rule is the company's own workload control, so handing it to AWS reverses the boundary.
CFix the access rule and also reconfigure the physical servers involved.
Reconfiguring physical servers takes on hardware operations the customer never manages in AWS.
19 / 21
-
Quick check
Which statement keeps the boundary in the right place?
AEnabling AWS security features moves workload decisions to AWS.
Features are tools the customer applies; the decision and the responsibility stay with the customer.
BAWS protects the cloud; the customer protects what it builds there.
Right. That is the boundary, and it holds at design time, at audit time, and during an incident.
CCertificates from accreditation bodies replace the customer's own controls.
Certification covers the infrastructure and completes part of the compliance work; it does not remove the customer's workload controls.
21 / 21
-
8 quick checks · then the test
In the app, finishing the quick checks opens this lesson’s 10-question test, and the ones you miss come back exactly when you’re about to forget them.
The whole course, on your phone
Lessons you can read, audio you can listen to on the way to work, and practice that remembers what you got wrong.