Network firewall-style rules the city configures on Amazon EC2 security groups for a permitting system are under whose responsibility?
Select an answer to reveal the explanation.
Short Explanation
AWS hands you the lock kit; you still pick which keys open which doors. Security groups are customer-configured controls, so the city owns those allow/deny choices. Having an AWS logo on the feature does not make AWS the author of your rules.
Full Explanation
Security groups and network ACLs that customers configure are part of customer responsibility in the shared responsibility model. AWS provides the capability; customers define the traffic rules for their resources. GuardDuty detects threats and does not own customer security group rule authorship, and Support does not approve routine port changes as a substitute for customer configuration.