Skip to content
awsnewbies.com
awsnewbies.com

amazon web services for newbies

  • Home
  • CLF-C02 Exam
    • Exam Guide
    • Domain 1
    • Domain 2
    • Domain 3
    • Domain 4
    • Mnemonics
  • Core Services
  • Tutorials
  • LinkedIn Learning
  • Book
  • Resources
  • About
awsnewbies.com

amazon web services for newbies

AWS Certified Cloud Practitioner Exam

AWS CLF-C02 Domain 2: Security and Compliance

Posted on May 23, 2026May 23, 2026 By Hiroko Nishimura

The second of the four domains in the AWS Certified Cloud Practitioner Exam (AWS CLF-C02) is “Security and Compliance.” This domain makes up 30% of the scored content.

If you want to follow along with my online course, “AWS Certified Cloud Practitioner (CLF-C02) Cert Prep,” you can access the course here: LinkedIn Learning.

Don’t forget to download my unofficial study guide, as well as AWS’s official study guide!

Table of Contents

Toggle
  • Security and Compliance
    • 2.1: Understand the AWS Shared Responsibility Model
    • 2.2: Understand AWS Cloud security, governance, and compliance concepts
    • 2.3: Identity AWS access management capabilities
    • 2.4: Identify components and resources for security

Security and Compliance

2.1: Understand the AWS Shared Responsibility Model

AWS Shared Responsibility Model (source):

  • AWS is responsible for security OF the Cloud
  • Customer is responsible for security IN the Cloud
  • Responsibilities shift between AWS and customer depending on the services used
  • Both AWS and the customer are responsible for training and educating

2.2: Understand AWS Cloud security, governance, and compliance concepts

  • Compliance requirements change depending on industries and geographic locations, which AWS accounts for with dozens of compliance programs (source)
  • You need to encrypt data in transit (while it’s moving from one place to another) and at rest (while it’s residing in a location)
  • Governance is process of creating and enforcing decisions within an organization
  • Security in the Cloud is composed of identity and access management, detective controls, infrastructure protection, data protection, and incident response (Security Pillar of the Well-Architected Framework)
  • There are many services to help you secure resources on AWS, like Amazon Inspector, AWS Security Hub, Amazon GuardDuty, AWS Shield
  • AWS Artifact helps you locate on-demand compliance information relevant to your IT infrastructure
  • There are many services that aid in governance and compliance like Amazon CloudWatch, AWS CloudTrail, AWS Audit Manager, and AWS Config
  • Compliance requirements varies depending on the AWS service being used

2.3: Identity AWS access management capabilities

  • Identity and Access Management (IAM) and IAM Identity Center provide granular control over permissions for identities, generally dealing with defining WHO has access to WHAT
  • Principle of Least Privilege (source): give only the least amount of access for an entity to do perform its tasks
    • Utilize groups, users, custom policies, and manage policies in compliance with the Principle of Least Privilege
  • There are multiple ways of authentication in AWS such as MFA, IAM Identity Center, cross-account IAM roles, federated users
  • When you create an AWS account, that account is a root user account, which should not be utilized unless absolutely necessary (make sure to secure it with MFA); know how to secure it, and what specific tasks you need the root account for
  • Access keys, password policies, credential storage (AWS Secrets Manager, AWS Systems Manager)

2.4: Identify components and resources for security

  • You can utilize network access control lists (NACLs) and security groups to control the traffic coming in and out of your resources (compare NACLs vs security groups)
  • There are many security services that help you protect your infrastructure, like AWS WAF, Amazon Inspector, AWS Shield, and Amazon GuardDuty
  • There are third-party security products (provided by other companies) on the AWS Marketplace
  • You can find AWS security-related information in AWS Knowledge Center, AWS Security Center, AWS Security Blog, etc.
  • You can utilize AWS Trusted Advisor to identify security issues

Next Domain: Cloud Technology and Services
Go back to AWS CLF-C02 Exam Guide

Exam Prep clf-c02domainsecurity

Post navigation

Previous post
Next post

Related Posts

Exam Prep AWS Certified Cloud Practitioner Exam

AWS CLF-C02 Domain 3: Cloud Technology and Services

Posted on May 23, 2026May 23, 2026

The third of the four domains in the AWS Certified Cloud Practitioner Exam (AWS CLF-C02) is “Cloud Technology and Services.” This domain makes up 34% of the scored content. If you want to follow along with my online course, “AWS Certified Cloud Practitioner (CLF-C02) Cert Prep,” you can access the…

Read More
Exam Prep AWS Certified Cloud Practitioner Exam

AWS CLF-C02 Domain 4: Billing, Pricing, and Support

Posted on May 23, 2026May 23, 2026

The last of the four domains in the AWS Certified Cloud Practitioner Exam (AWS CLF-C02) is “Billing, Pricing, and Support.” This domain makes up 12% of the scored content. If you want to follow along with my online course, “AWS Certified Cloud Practitioner (CLF-C02) Cert Prep,” you can access the…

Read More
Exam Prep AWS Certified Cloud Practitioner Exam

AWS Cloud Practitioner Exam Study Mnemonics

Posted on May 23, 2026May 23, 2026

When I first created AWS Cloud Practitioner Exam’s study mnemonics, it was mostly as a joke (and also because I thrive on having little tricks to memorize things). Surprisingly, I’ve had A LOT of people commenting about them, and how they have helped them memorize important concepts for studying for…

Read More

Comment

  1. Pingback: AWS CLF-C02 Domain 1: Cloud Concepts - awsnewbies.com

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

awsnewbies.com

awsnewbies.com is a resource website for anyone looking to learn about Amazon Web Services (AWS),  jargon free.

We strive to make Cloud Computing and Amazon Web Services “newbie friendly,” and have many resources available to help you get started!

Check out our popular video courses or introductory book! Looking for some beginner friendly tutorials?

Or study for the AWS Certified Cloud Practitioner Exam!

Top Posts

awsnewbies.comawsnewbies.comMay 10, 2026Hiroko Nishimura
AWS Certified Cloud Practitioner ExamAWS Certified Cloud Practitioner ExamMay 10, 2026Hiroko Nishimura
AWS Resources | Amazon Web ServicesAWS Resources | Amazon Web ServicesMay 10, 2026Hiroko Nishimura

Tags

clf-c02 domain lightsail openclaw route 53 security services wordpress

Hiroko Nishimura

Technical Instructor at LinkedIn Learning
Introduction to AWS for Non-Engineers (AWS Certified Cloud Practitioner Cert Prep)

Author of AWS for Non-Engineers
Manning Publications

AWS Community Hero
Since 2020

©2026 awsnewbies.com | WordPress Theme by SuperbThemes