Developers find a vulnerability in city-written API code running on Amazon EC2. Who is responsible for fixing that application security issue?
Select an answer to reveal the explanation.
Short Explanation
If the city wrote the API, the city owns the bug fix — cloud hosting does not rewrite your code for you. AWS secures the infrastructure underneath EC2; application vulnerabilities in customer software stay on the customer side. Downloadable compliance PDFs do not patch app flaws.
Full Explanation
Under the shared responsibility model, customers are responsible for their applications and code. On Amazon EC2, AWS does not automatically remediate vulnerabilities in customer-written software. Artifact provides compliance documentation, and Support does not assume ownership of rewriting municipal application logic as a standard shared-responsibility outcome.