Shared Responsibility, IAM and Access Control
Security and Compliance questions heavily test the shared responsibility model, IAM users, groups, roles, policies, MFA, and least privilege.
How to study for AWS Cloud Practitioner
Treat each question as a service-selection or responsibility decision: identify the business need, AWS responsibility, customer configuration, and best-fit service.
Core concepts
Concept 1
AWS is responsible for security of the cloud; customers are responsible for security in the cloud.
Exam cue: Classify the task as AWS responsibility or customer responsibility.
Concept 2
IAM controls authentication and authorization for AWS identities and should follow least privilege.
Exam cue: Use IAM policies and least privilege for authorization questions.
Concept 3
Roles are preferred for temporary delegated access by AWS services, applications, federated users, or cross-account use cases.
Exam cue: Use roles for temporary delegated access.
Risk pitfalls and guardrails
Sharing the root account for daily administration.
Guardrail: Avoid answers that ignore customer configuration, choose unmanaged services when managed services fit, or use billing reports when proactive alerts are required.
Granting AdministratorAccess when a narrower policy is enough.
Guardrail: Avoid answers that ignore customer configuration, choose unmanaged services when managed services fit, or use billing reports when proactive alerts are required.
Assuming AWS configures customer IAM permissions automatically.
Guardrail: Avoid answers that ignore customer configuration, choose unmanaged services when managed services fit, or use billing reports when proactive alerts are required.
Memory anchors
Shared Responsibility
AWS secures the cloud infrastructure while customers secure their data, identity, configuration, and workloads.
IAM User
An IAM user is a long-term identity in an AWS account.
IAM Group
An IAM group attaches permissions to multiple IAM users.
IAM Role
An IAM role provides temporary credentials for delegated access.
IAM Policy
An IAM policy defines allowed or denied actions on AWS resources.
Least Privilege
Least privilege grants only the permissions needed for a task.
MFA
Multi-factor authentication adds another verification factor beyond a password.
Root User
The root user has full account access and should be protected and rarely used.
Federation
Federation lets external identities access AWS through trusted identity integration.
Temporary Credentials
Temporary credentials expire and reduce long-term credential exposure.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A company runs an application on Amazon EC2. Who is responsible for patching the guest operating system?
For an Amazon RDS database, which task is AWS responsible for under the shared responsibility model?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
