AWS Certified Cloud Practitioner · Free Practice Question Medium
Question 34
According to the AWS Shared Responsibility Model, which of the following are responsibilities of the customer for AWS Identity and Access Management (AWS IAM)? (Select two)
-
A
Enable multi-factor authentication (MFA) on all accounts
-
B
Manage global network security infrastructure
-
C
Compliance validation for the underlying software infrastructure
-
D
Analyze user access patterns and review AWS Identity and Access Management (AWS IAM) permissions
-
E
Configuration and vulnerability analysis for the underlying software infrastructure
Reveal correct answers
Correct answers: A, D
Explanation
Correct options:
Security and Compliance is a shared responsibility between AWS and the customer. This shared model can help relieve the customer’s operational burden as AWS operates, manages and controls the components from the host operating system and virtualization layer down to the physical security of the facilities in which the service operates.
Enable multi-factor authentication (MFA) on all accounts
Analyze user access patterns and review AWS Identity and Access Management (AWS IAM) permissions
Under the AWS Shared Responsibility Model, customers are responsible for enabling multi-factor authentication (MFA) on all accounts, analyzing access patterns and reviewing permissions for AWS Identity and Access Management (AWS IAM) entities.
AWS Shared Responsibility Model Overview:

Incorrect options:
Manage global network security infrastructure
Configuration and vulnerability analysis for the underlying software infrastructure
Compliance validation for the underlying software infrastructure
According to the AWS Shared Responsibility Model, AWS is responsible for "Security of the Cloud". This includes protecting the infrastructure that runs all of the services offered in the AWS Cloud. This infrastructure is composed of the hardware, software, networking, and facilities that run AWS Cloud services. Therefore these three options fall under the responsibility of AWS.
Reference:
https://aws.amazon.com/compliance/shared-responsibility-model/
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
