This shows up on every AWS exam, and it’s free points once the split clicks: AWS secures the cloud; you secure what you put in it.
Where the line sits
AWS handles security OF the cloud — data centers, hardware, networking, the hypervisor. You handle security IN the cloud — your data, IAM permissions, OS patches on EC2, firewall rules, encryption. The line moves by service: with EC2 you patch the OS; with managed services like RDS or Lambda, AWS handles more.
Test yourself
Who is responsible for applying operating-system security patches on an EC2 instance?
- AWS, in all cases
- The customer
- The customer only for Windows instances
- Neither — patches are automatic
👉 Click to reveal the answer & explanation
Correct answer: B. EC2 is infrastructure you manage, so OS patching is on the customer side. AWS patches the underlying host but not your guest OS. (Contrast RDS, where AWS patches the database engine for you.)
Related topics
AWS IAM · AWS CloudTrail · AWS KMS
Ready to pass the AWS Cloud Practitioner (CLF-C02)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the CLF-C02 Practice Exams →or try 25 free questions first