AWS Shared Responsibility Model
Learn how AWS splits security duties with you: security of the cloud versus security in the cloud, what each side owns layer by layer, and how the boundary shifts from EC2 to managed and abstracted services.
The AWS Shared Responsibility Model is the framework that draws the line between what AWS secures and what you secure. Move a workload from your own data center to AWS and some security duties become AWS's job, while others stay yours. This topic shows you exactly where that line falls, and why it is the single most important security idea on the exam.
The topic has 3 lessons. They start with the core split between security of the cloud and security in the cloud, then map who owns what layer by layer, and finish with how your share of the work changes as you move from raw infrastructure to fully managed services.
What This Topic Covers
- the definition of the Shared Responsibility Model and why AWS shares the work
- security of the cloud (AWS) versus security in the cloud (the customer)
- what AWS secures: hardware, software, networking, and physical facilities
- what you secure: your data, IAM and access, operating system config, and network settings
- the three control types AWS describes: inherited, shared, and customer-specific
- how the responsibility boundary shifts across infrastructure (EC2), managed (RDS), and abstracted (S3) services
- the two responsibilities that always stay with you: your data and who can access it
Why It Matters
Almost every security question on the CLF-C02 exam comes back to this model. Once you can say where AWS's job ends and yours begins, you can reason through scenarios instead of memorizing answers. That skill carries into the rest of the Security and Compliance domain, where IAM, encryption, and compliance all build on the same split.
It matters beyond the exam too. The first decisions you make in a real AWS account, like who can reach a resource and how your data is protected, sit squarely on your side of the line. Knowing the model keeps you from assuming AWS covers work that is actually yours.
