CredenTrek
Blog / AWS Cloud Practitioner / Article 04 of 10
AWS Cloud Practitioner · Prepare

Cloud Practitioner security at 30 per cent: who patches EC2, RDS and Lambda?

By Mustafa K. Al-Dori · Checked against official documents on 11 October 2026 · 6 min read

The short answer

Security and Compliance carry 30 per cent of CLF-C02, so a 40-hour plan gives it 12 hours. Learn the shared responsibility split: with EC2 you patch the operating system, with RDS AWS patches the database software, and with Lambda AWS runs almost everything except your code, data and access settings.

A drawn responsibility chart answers the most common question in this domain.

Why this domain deserves more than a quarter

Security and Compliance carry 30 per cent of the scored questions. In a 40-hour plan that is 12 hours, against 14 for the largest domain, Cloud Technology and Services. Many candidates still give it a quarter of their time.

Four tasks behind the domain

Task What it means Terms to know
2.1 Shared responsibility model What AWS secures, what you secure, and how the split shifts between services EC2, RDS, Lambda
2.2 Security, governance and compliance Compliance reports, encryption options, where logs live AWS Artifact, CloudWatch, CloudTrail, AWS Config, GuardDuty, Inspector, Security Hub, Shield
2.3 Access management Protect the root user, apply least privilege, manage users, groups, roles and policies IAM, IAM Identity Center, MFA, Secrets Manager
2.4 Security components and resources Which security services and documents AWS provides AWS WAF, Firewall Manager, Shield, GuardDuty, Trusted Advisor

Draw the split

Task 2.1 is where questions often turn. Draw three columns, one each for EC2, RDS and Lambda, and write beside each who handles what.

  • EC2. You manage the operating system, patches and firewall settings of your servers.
  • RDS. More shifts to AWS, which patches the database software.
  • Lambda. AWS runs almost everything except your code, data and access settings.

The rule underneath is simple: the more managed the service, the less you carry. Drawing it from memory a few times is a quick test of how well you hold it.

Four habits for Task 2.3

  • Protect the root user with multi-factor authentication.
  • Do not use the root user for daily work.
  • Give each person only the access they need.
  • Create a separate user for yourself.

A practice question might ask for best practice on the root user. The root user does have full permissions, which is exactly why it is not used day to day.

Where to find compliance reports

When an auditor asks for AWS's compliance reports, the place to look is AWS Artifact. AWS Config is the runner-up in that kind of question: it tracks how your own resource settings change, which is a different job. Use that pattern as a habit across the whole domain: the right answer does the job in the question, and the runner-up does a neighbouring one.

A two-week routine for the domain

Week Focus Output
1 Tasks 2.1 and 2.3 A hand-drawn responsibility chart and a root-user checklist
2 Tasks 2.2 and 2.4 A one-line job for each security service

Test yourself afterwards on the three security questions in the practice set, and check the pattern of misses. If you confuse who secures what, redraw the chart. Rating yourself on the four tasks first tells you which week to lengthen.

Questions readers ask

How much of CLF-C02 is security?
Security and Compliance carry 30 per cent of the scored questions.
Who patches the operating system on EC2?
You do. With EC2 you manage the operating system, patches and firewall settings.
Where can I download AWS compliance reports?
In AWS Artifact.
Sources

This article is independent and is not endorsed by AWS. Facts change: confirm them on the official page before you act.