SAA-C03 · Practice set 5 of 9
AWS Shared Responsibility Model: 10 practice questions
10 free SAA-C03 practice questions on AWS Shared Responsibility Model, with an explanation for every answer. Untimed. The full mock exam and the timed version are in the app.
-
Question 1 of 10
How does the AWS shared responsibility model divide security?
- AThe customer secures the cloud; AWS secures customer content and applications.
- BAWS secures customer workloads; the customer secures AWS facilities.
- CAWS and the customer jointly configure every workload security control.
- DAWS secures the cloud; the customer secures what it operates in the cloud.
Show the answer
The deciding boundary is infrastructure versus workload: AWS protects the cloud, and the customer protects its own use of that cloud.
Next → 1 / 10 -
Question 2 of 10
Which item is outside the customer's physical management responsibility in AWS?
- AThe monitoring applied to the customer's information flows
- BThe physical servers and storage devices used by the cloud infrastructure
- CAll application access controls selected for customer workloads across every AWS account
- DThe network protections configured for the customer's systems
Show the answer
AWS removes the need for customers to maintain physical servers and storage, while workload-level monitoring and access controls stay with the customer.
Next → 2 / 10 -
Question 3 of 10
Who retains control of security for customer content and applications running in AWS?
- AAWS, which operates the underlying facilities
- BThe accreditation body that certifies the AWS environment
- CThe hardware vendor that supplies AWS storage devices
- DThe customer that owns and operates the workload
Show the answer
Customer control follows the workload: content, applications, systems, and networks are security-in-the-cloud responsibilities.
Next → 3 / 10 -
Question 4 of 10
A team enables AWS access-control and encryption features for its application. What remains true?
- AThe team remains responsible for choosing and applying controls to its workload.
- BThe accreditation body now configures the workload because the features are certified.
- CAWS becomes responsible for the application's content after those features are enabled.
- DThe features transfer application and network security entirely to AWS operations.
Show the answer
Managed security features are mechanisms the customer selects; they do not change ownership of security decisions for the workload.
Next → 4 / 10 -
Question 5 of 10
Which security benefit does a customer inherit from AWS?
- AOwnership of the physical data centers that host customer workloads
- BAutomatic replication of every customer resource across geographic areas
- CA complete least-privilege permission set automatically tailored to every customer application and workload
- DAWS policies, architecture, and operational processes that protect the infrastructure
Show the answer
Inherited controls are the protections AWS applies to its infrastructure, distinct from the customer's application-specific configuration.
Next → 5 / 10 -
Keep the ones you got wrong
In the app, every question you miss comes back exactly when you’re about to forget it.
-
Question 6 of 10
How should compliance be treated in an AWS architecture review?
- AAs a third-party duty transferred to the organization issuing the accreditation
- BAs a shared responsibility built on AWS infrastructure controls and customer controls
- CAs an AWS-only operating duty because AWS maintains infrastructure certifications for every customer workload
- DAs a customer-only duty because the customer owns the application content
Show the answer
Infrastructure assurance can satisfy part of a compliance obligation, while customer workload configuration supplies the remaining controls.
Next → 6 / 10 -
Question 7 of 10
A review item concerns protection of traffic entering and leaving a customer application. Which side owns the control choice?
- AThe customer, using software-based controls for its cloud resources
- BThe auditor, because continuous AWS audits include application configuration
- CThe storage-device manufacturer, because traffic eventually reaches storage
- DAWS, because all traffic protection is part of physical data-center security
Show the answer
Traffic around customer resources belongs to security in the cloud, even though AWS supplies software-based security features.
Next → 7 / 10 -
Question 8 of 10
A startup wants to avoid owning facilities and physical storage, but it must still control protection for its application code and network. Which responsibility map fits both constraints?
- AThe startup manages physical storage, while AWS configures its application network.
- BThe startup and AWS jointly operate each server and jointly configure each network rule.
- CAWS manages the physical cloud; the startup secures its application and network.
- DAWS manages the physical cloud and also chooses the startup's application controls.
Show the answer
The architecture gets facility management from AWS without surrendering responsibility for controls around customer code, systems, and networks.
Next → 8 / 10 -
Question 9 of 10
An audit maps two controls: data-center operations and permissions for a customer analytics platform. The map must preserve provider assurance and customer control. Which assignment is correct?
- AAssign both controls to AWS because the platform runs on certified infrastructure.
- BAssign data-center operations to the customer and platform permissions to AWS.
- CAssign both controls to the customer because the customer owns the analytics data.
- DAssign data-center operations to AWS and platform permissions to the customer.
Show the answer
The audit should combine inherited AWS infrastructure controls with customer-operated permissions rather than collapsing both into one owner.
Next → 9 / 10 -
Question 10 of 10
After an incident, a company must remediate an application access rule and verify the provider's facility safeguards without taking over hardware operations. What plan matches the model?
- AThe company fixes the access rule and relies on AWS controls for the facilities.
- BAWS fixes the customer access rule while the company inspects and operates the facilities.
- CAWS fixes both areas because the workload uses AWS security features.
- DThe company fixes both the application rule and the physical server configuration.
Show the answer
Remediation follows the same boundary during an incident: customer workload configuration stays with the company, while AWS facility protection stays with AWS.
Next → 10 / 10 -
You’ve finished this set
That’s 10 questions on AWS Shared Responsibility Model. In the app the ones you miss come back exactly when you’re about to forget them.
The whole course, on your phone
Lessons you can read, audio you can listen to on the way to work, and practice that remembers what you got wrong.