Shared Responsibility Model
The split of security duties between AWS and the customer, which shifts by service type.
The Shared Responsibility Model splits security duties between AWS and the customer. AWS handles security “of” the cloud — physical data centers, hardware, networking, and the hypervisor. Customers handle security “in” the cloud — guest OS patches on EC2, IAM permissions, data encryption choices, and security-group rules. The boundary shifts by service type, a common exam trap. With EC2 (IaaS) the customer owns the guest OS and above; with a managed service like RDS, AWS patches the database engine, shrinking customer scope toward access rules and encryption.
PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →