[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"cheat-sheet---en":3,"domain-info---en":3,"topic-info----en":3,"lesson-aws-certified-cloud-practitioner-security-and-compliance-shared-responsibility-model-shared-responsibility-overview-en":4,"prev-aws-certified-cloud-practitioner-security-and-compliance-shared-responsibility-model-shared-responsibility-overview-en":191,"next-aws-certified-cloud-practitioner-security-and-compliance-shared-responsibility-model-shared-responsibility-overview-en":202},null,{"locked":5,"reason":3,"meta":6,"item":17},false,{"title":7,"description":8,"isFree":9,"estimatedMinutes":10,"difficulty":11,"learningObjectives":12},"The AWS Shared Responsibility Model","Learn what the AWS Shared Responsibility Model is, how it splits security duties between AWS and you, and why that split is the foundation of cloud security.",true,12,"beginner",[13,14,15,16],"Explain what the AWS Shared Responsibility Model is","Distinguish security of the cloud from security in the cloud","Explain why AWS uses a shared model","Recognize that the split depends on the service you choose",{"id":18,"title":7,"body":19,"description":8,"difficulty":11,"estimatedMinutes":10,"extension":136,"infographics":137,"isFree":9,"learningObjectives":149,"meta":150,"navigation":9,"path":151,"quiz":152,"seo":188,"stem":189,"__hash__":190},"courses/courses/aws-certified-cloud-practitioner/en/domains/02-security-and-compliance/01-shared-responsibility-model/01-shared-responsibility-overview.md",{"type":20,"value":21,"toc":125},"minimark",[22,27,31,34,38,41,48,54,59,62,66,69,72,75,79,82,85,89,92,95,99],[23,24,26],"h2",{"id":25},"security-is-a-shared-job","Security is a shared job",[28,29,30],"p",{},"When you run a workload in your own data center, you secure everything: the building, the servers, the network, the operating system, the application, and the data. Move that workload to AWS and some of those duties become AWS's job, while others stay yours. The AWS Shared Responsibility Model is the framework that draws this line. It says, for any given setup, who secures what.",[28,32,33],{},"This is the single most important security idea on the exam, and the most useful one in real work. Almost every security question on the AWS Certified Cloud Practitioner exam comes back to it. Once you can say where AWS's job ends and yours begins, you can reason through scenarios instead of memorizing answers.",[23,35,37],{"id":36},"security-of-the-cloud-versus-security-in-the-cloud","Security of the cloud versus security in the cloud",[28,39,40],{},"AWS describes the split with two short phrases.",[28,42,43,47],{},[44,45,46],"strong",{},"Security of the cloud"," is AWS's responsibility. AWS protects the infrastructure that runs every AWS service: the hardware, the software, the networking, and the physical facilities. This reaches from the host operating system and the virtualization layer down to the physical security of the buildings. You never touch these layers, and you cannot secure them yourself.",[28,49,50,53],{},[44,51,52],{},"Security in the cloud"," is your responsibility. You secure what you put on top of that infrastructure: your data, your applications, your operating system configuration (when the service exposes one), your network and firewall settings, and who is allowed to access your resources. The exact list depends on the service you use.",[55,56],"infographic",{"alt":57,"slug":58},"A two-column comparison showing AWS responsible for security of the cloud, the underlying infrastructure, and the customer responsible for security in the cloud, the data and configuration on top.","security-of-vs-in-the-cloud",[28,60,61],{},"A simple way to hold the two phrases apart: AWS secures the cloud itself, and you secure your stuff inside it.",[23,63,65],{"id":64},"why-aws-shares-the-responsibility","Why AWS shares the responsibility",[28,67,68],{},"The model is not a way for AWS to avoid work. It reflects a basic fact: each side can only secure the parts it can reach.",[28,70,71],{},"AWS can lock the data center doors, patch the hypervisor, and replace failed hardware, because AWS owns and runs all of it. You cannot. But AWS cannot decide who in your company should read a file, choose a password policy for your users, or classify which of your records are sensitive. Only you can. The model gives each task to the side that is actually able to do it.",[28,73,74],{},"Sharing the work this way has a clear benefit. AWS takes on the heavy, repetitive infrastructure security that every customer would otherwise have to build and run alone, which lowers your operational burden. You keep control over your data and access, which is where your specific risks live.",[23,76,78],{"id":77},"the-model-extends-to-it-controls","The model extends to IT controls",[28,80,81],{},"The same shared logic applies to IT controls, the formal checks that prove a system is secure and compliant. Some controls you inherit fully from AWS, such as physical and environmental controls. Some are shared, where AWS handles the infrastructure side and you handle your side. And some are entirely yours.",[28,83,84],{},"You do not need the full control catalog for the exam. The point to remember is that the shared model is not only about day-to-day security tasks. It also shapes how compliance responsibilities are divided, which is why AWS gives customers documentation to verify the controls AWS runs on their behalf.",[23,86,88],{"id":87},"the-line-moves-with-the-service","The line moves with the service",[28,90,91],{},"One detail trips people up, so fix it early: the boundary between AWS and you is not in a fixed place. It slides depending on the service.",[28,93,94],{},"Run a virtual server with Amazon EC2 and you manage the operating system, patches, and firewall rules yourself. Use a managed service instead and AWS takes over more of that work. Pick a fully abstracted service like Amazon S3 and AWS runs almost everything beneath your data. The next two lessons map this out: first the detailed split of who owns what, then how that split shifts as you move from raw infrastructure to fully managed services.",[23,96,98],{"id":97},"exam-tips","Exam tips",[100,101,102,110,116,119,122],"ul",{},[103,104,105,106,109],"li",{},"Security ",[44,107,108],{},"of"," the cloud is AWS's job: hardware, software, networking, and physical facilities.",[103,111,105,112,115],{},[44,113,114],{},"in"," the cloud is your job: your data, access (IAM), operating system config, and network settings.",[103,117,118],{},"A memory hook: AWS secures the cloud, you secure what you put in it.",[103,120,121],{},"The split is not fixed. Your share depends on the service you choose.",[103,123,124],{},"Your data and who can access it are always your responsibility, on every service.",{"title":126,"searchDepth":127,"depth":127,"links":128},"",3,[129,131,132,133,134,135],{"id":25,"depth":130,"text":26},2,{"id":36,"depth":130,"text":37},{"id":64,"depth":130,"text":65},{"id":77,"depth":130,"text":78},{"id":87,"depth":130,"text":88},{"id":97,"depth":130,"text":98},"md",[138],{"slug":58,"concept":139,"style":140,"aspectRatio":141,"labels":142},"Two columns showing the split between security OF the cloud (AWS, the underlying infrastructure) and security IN the cloud (the customer, everything they put on top)","comparison","16:9",[143,144,145,146,147,148],"Security OF the Cloud","Security IN the Cloud","AWS","Customer","Infrastructure","Your data and config",[13,14,15,16],{},"/courses/aws-certified-cloud-practitioner/en/domains/02-security-and-compliance/01-shared-responsibility-model/01-shared-responsibility-overview",{"passingScore":153,"questions":154},70,[155,164,172,178],{"question":156,"type":157,"options":158,"correctAnswer":161,"explanation":163},"What does security \"of the cloud\" refer to in the AWS Shared Responsibility Model?","single",[159,160,161,162],"The encryption a customer applies to data before uploading it","A paid AWS add-on that handles all security for you","AWS protecting the hardware, software, networking, and facilities that run AWS services","The firewall rules a customer sets on each EC2 instance","Security of the cloud is AWS's job: the physical data centers, hardware, and the software and networking that run AWS services. The other options describe security in the cloud, which is the customer's responsibility.",{"question":165,"type":157,"options":166,"correctAnswer":167,"explanation":171},"Why does AWS describe cloud security as a shared responsibility?",[167,168,169,170],"Because AWS secures the underlying infrastructure while you secure what you run on it","Because AWS is unable to secure any part of the cloud on its own","Because the model shifts every security task onto the customer","Because customers pay an extra fee for AWS to handle all security","The model splits the work: AWS handles the parts only it can reach, like the physical facilities and hypervisor, and you handle what you put in the cloud, like your data and access settings. Neither side can secure the whole system alone.",{"question":173,"type":157,"options":174,"correctAnswer":176,"explanation":177},"The division of duties in the Shared Responsibility Model is fixed and never changes, no matter which AWS service you use.",[175,176],"True","False","Your share of the work depends on the service you choose. A raw compute service like EC2 leaves you more to configure, while a managed service hands more of that work to AWS.",{"question":179,"type":180,"options":181,"correctAnswers":186,"explanation":187},"Which of the following statements about the Shared Responsibility Model are accurate? (Select all that apply.)","multiple",[182,183,184,185],"Customer responsibility depends on which AWS services the customer selects","AWS manages the physical security of its data centers","The model also extends to IT controls shared between AWS and the customer","Customers are responsible for the physical security of AWS facilities",[182,183,184],"Your responsibility shifts with the services you pick, AWS owns physical data center security, and the model extends to shared IT controls. The physical security of AWS facilities is always AWS's job, never the customer's.",{"title":7,"description":8},"courses/aws-certified-cloud-practitioner/en/domains/02-security-and-compliance/01-shared-responsibility-model/01-shared-responsibility-overview","OxLrQldF8pc0Yb_xGxUa0vCXIypWBsWSZqBMlOlCk7M",{"locked":9,"reason":192,"meta":193,"item":3},"paywall",{"title":194,"description":195,"isFree":5,"estimatedMinutes":196,"difficulty":11,"learningObjectives":197},"Automation and Economies of Scale","Learn how automation and managed services cut operational cost, and how the shared scale of AWS lowers the price you pay through economies of scale.",14,[198,199,200,201],"Explain how economies of scale lower the price AWS charges","Describe how automation and managed services reduce operational cost","Identify the AWS pricing principles that reward reserving and using more","Connect automation, managed services, and scale to lower total cost",{"locked":9,"reason":192,"meta":203,"item":3},{"title":204,"description":205,"isFree":5,"estimatedMinutes":206,"difficulty":11,"learningObjectives":207},"Customer vs AWS Responsibilities","See exactly what AWS secures and what you secure, layer by layer, plus the three types of controls AWS uses to describe inherited, shared, and customer-only duties.",15,[208,209,210,211],"List the responsibilities AWS owns under security of the cloud","List the responsibilities the customer owns under security in the cloud","Compare AWS and customer duties across the stack","Describe inherited, shared, and customer-specific controls"]