Cloud Practitioner security at 30 per cent: who patches EC2, RDS and Lambda?
Security and Compliance carry 30 per cent of CLF-C02, so a 40-hour plan gives it 12 hours. Learn the shared responsibility split: with EC2 you patch the operating system, with RDS AWS patches the database software, and with Lambda AWS runs almost everything except your code, data and access settings.
A drawn responsibility chart answers the most common question in this domain.
Why this domain deserves more than a quarter
Security and Compliance carry 30 per cent of the scored questions. In a 40-hour plan that is 12 hours, against 14 for the largest domain, Cloud Technology and Services. Many candidates still give it a quarter of their time.
Four tasks behind the domain
| Task | What it means | Terms to know |
|---|---|---|
| 2.1 Shared responsibility model | What AWS secures, what you secure, and how the split shifts between services | EC2, RDS, Lambda |
| 2.2 Security, governance and compliance | Compliance reports, encryption options, where logs live | AWS Artifact, CloudWatch, CloudTrail, AWS Config, GuardDuty, Inspector, Security Hub, Shield |
| 2.3 Access management | Protect the root user, apply least privilege, manage users, groups, roles and policies | IAM, IAM Identity Center, MFA, Secrets Manager |
| 2.4 Security components and resources | Which security services and documents AWS provides | AWS WAF, Firewall Manager, Shield, GuardDuty, Trusted Advisor |
Draw the split
Task 2.1 is where questions often turn. Draw three columns, one each for EC2, RDS and Lambda, and write beside each who handles what.
- EC2. You manage the operating system, patches and firewall settings of your servers.
- RDS. More shifts to AWS, which patches the database software.
- Lambda. AWS runs almost everything except your code, data and access settings.
The rule underneath is simple: the more managed the service, the less you carry. Drawing it from memory a few times is a quick test of how well you hold it.
Four habits for Task 2.3
- Protect the root user with multi-factor authentication.
- Do not use the root user for daily work.
- Give each person only the access they need.
- Create a separate user for yourself.
A practice question might ask for best practice on the root user. The root user does have full permissions, which is exactly why it is not used day to day.
Where to find compliance reports
When an auditor asks for AWS's compliance reports, the place to look is AWS Artifact. AWS Config is the runner-up in that kind of question: it tracks how your own resource settings change, which is a different job. Use that pattern as a habit across the whole domain: the right answer does the job in the question, and the runner-up does a neighbouring one.
A two-week routine for the domain
| Week | Focus | Output |
|---|---|---|
| 1 | Tasks 2.1 and 2.3 | A hand-drawn responsibility chart and a root-user checklist |
| 2 | Tasks 2.2 and 2.4 | A one-line job for each security service |
Test yourself afterwards on the three security questions in the practice set, and check the pattern of misses. If you confuse who secures what, redraw the chart. Rating yourself on the four tasks first tells you which week to lengthen.
Questions readers ask
How much of CLF-C02 is security?
Who patches the operating system on EC2?
Where can I download AWS compliance reports?
This article is independent and is not endorsed by AWS. Facts change: confirm them on the official page before you act.