Home/Practice Test/AWS/AWS SCS-C03 Free Practice Test | 200+ Real Exam Style Questions 2026

AWS SCS-C03 Free Practice Test | 200+ Real Exam Style Questions 2026

Test your ability to secure AWS workloads.
Use this SCS-C03 practice test to review key security decisions.

Real Exam Style
Questions
Detailed
Explanations
All Domains
Covered
Timed
Practice
4.8919 learner reviews across Microsoft, AWS, and CompTIA tracksVerified purchases
Jump Straight to the SCS-C03 Questions (No Sign-Up or Credit Card required)
Why choose us
1
Expert Explanations + Sources Master every concept with clarity.
2
2026-Fresh Questions Always current, never outdated.
3
Real Exam Simulation Practice like you'll test.
4
90-Day Free Updates Stay ahead of changes.
5
Start in 60 Seconds No waiting, instant access.

SCS-C03 exam at a glance

AWS Certified Security – Specialty · Specialty level

Exam codeSCS-C03
CertificationAWS Certified Security – Specialty
LevelSpecialty
Number of questions65 total: 50 scored and 15 unscored
Duration170 minutes
Passing score750 on a scale of 100–1,000
Question formatsMultiple choice, multiple response, ordering, and matching
DeliveryPearson VUE testing center or online proctored exam
Exam costUSD 300; EUR 256; AUD 449; JPY 40,000; KRW 394,575; CNY 2,113; or INR 25,659 for Pearson Mindhub voucher purchases only. Applicable taxes may apply.
LanguagesEnglish, Japanese, Korean, Portuguese (Brazil), Simplified Chinese, and Spanish (Latin America)
Certification validity3 years
Retake policyAfter a failed attempt, candidates must wait 14 calendar days. There is no limit on attempts, and the full registration fee applies to each attempt. After passing, the same exam cannot be retaken for two years unless a new exam guide and exam series code are released.
PrerequisitesNo specific prerequisites are required.
Exam guide versionVersion 1.0, published 26 March 2026

The exam is intended for individuals responsible for securing cloud solutions. The target candidate should have the equivalent of 3–5 years of experience securing cloud solutions.

Skills measured and their weighting

Skill areaWeight
Detection16%
Incident Response14%
Infrastructure Security18%
Identity and Access Management20%
Data Protection18%
Security Foundations and Governance14%

Source: aws.amazon.com — official SCS-C03 exam page. Figures were checked against AWS official documentation and certification policies. Confirm current details there before booking.

Sit the whole exam before you sit the whole exam

The full bank covers every domain, with timed mode and per-domain scoring.

Premium
Timed mode Per-domain score tracking Unlimited free updates PDF + Practice Test
Get the full bank 30-day money back

SCS-C03 Practice Questions By Domains

6 domains covered

6. Security Foundations and Governance

3 free questions available

Start Practice
Premium 30 of 230 free

Practice the full exam, not a sample

Unlock the full bank and practise every domain end to end.

Unlock all 230 questions

Start Here: How to Use This Practice Set 

Preparing for the AWS Certified Security – Specialty exam is easier when every practice question has a clear purpose. An effective SCS-C03 practice test helps you apply AWS security services to realistic situations, check what you understand, and decide which topics need more review. You can also find your certification practice test before building a study schedule for SCS-C03 or another active certification.

SCS-C03 is the current AWS Security – Specialty exam. It replaced SCS-C02, which was used until December 1, 2025; SCS-C03 has been in use since December 2, 2025. The updated version separates detection from incident response, emphasizes identity and access management, and addresses newer security concerns such as generative AI protections, centralized account controls, sensitive data masking, and modern encryption practices. Candidates should therefore check every book, course, and question set for the exact SCS-C03 code.

This page explains what the current exam tests, how its six domains are weighted, how practice questions should be used, and what to expect during registration and exam day. All exam facts were checked against the current AWS certification page, official SCS-C03 exam guide, AWS testing information, and AWS certification policies.

What Is the AWS SCS-C03 Exam?

SCS-C03 is the exam code for AWS Certified Security Specialty. It is designed for professionals responsible for securing cloud solutions. The exam validates whether a candidate can protect AWS workloads, detect suspicious activity, respond to incidents, manage identities and permissions, secure data, and apply governance controls across AWS environments.

The exam is not limited to remembering security-service definitions. A typical scenario may describe a multi-account organization, an unusual security finding, a missing log source, an exposed workload, an authorization failure, or an encryption requirement. You must select the response that solves the problem while meeting technical, security, cost, and operational requirements.

According to the official SCS-C03 exam guide, candidates should understand how to:

  • Apply data classifications and AWS data-protection mechanisms
  • Implement encryption methods and AWS encryption services
  • Use secure internet protocols and related AWS controls
  • Secure production environments with AWS services and features
  • Balance security, cost, and deployment complexity
  • Understand security operations, threats, and risk

Who Should Take the SCS-C03 Exam?

SCS-C03 is intended for experienced security and cloud professionals. The public AWS certification page describes the target as someone with five years of IT security experience, including two or more years of hands-on experience securing AWS workloads. The exam guide describes the target candidate as having the equivalent of three to five years of experience securing cloud solutions.

Likely candidates include:

  • Cloud security engineers
  • Security architects
  • DevSecOps engineers
  • Incident-response professionals working with AWS
  • Solutions architects with security responsibilities
  • IAM specialists
  • Cloud governance and compliance professionals
  • Network or platform engineers who secure AWS workloads

AWS does not require another certification before SCS-C03. However, candidates commonly earn AWS Certified Solutions Architect – Associate or Professional first because those paths build useful knowledge of AWS architecture, networking, storage, compute, and shared responsibility.

You are more likely to be ready for SCS-C03 if you can explain not only what an AWS security service does, but also when to choose it, how it integrates with other services, what evidence it produces, and how to troubleshoot it.

Why Use an SCS-C03 Practice Test?

A practice test turns study notes into decisions. It gives you a situation, several possible actions, and a limited amount of time. That process reveals whether you can apply knowledge instead of only recognizing service names.

Practice questions can help you:

  • Check your starting level before creating a study plan
  • Learn the four response formats used in the current exam guide
  • Identify weak domains and misunderstood services
  • Practice separating detection, investigation, containment, and recovery actions
  • Compare authentication and authorization controls
  • Recognize the correct encryption or key-management option
  • Build speed for long, scenario-based questions
  • Reduce uncertainty about the proctored testing experience

For additional cloud-security and AWS preparation, View all AWS practice tests and select material that matches the exact active exam code.

Do not use practice questions only to memorize a correct letter. Review the explanation and identify the security principle behind the answer. A memorized option may not help when a new scenario changes the account structure, data classification, threat, compliance rule, or operational requirement.

SCS-C03 Domains and Exam Weightings

The scored portion of SCS-C03 is organized into six domains:

Domain 1: Detection — 16%

Detection covers the monitoring, logging, alerting, and analysis needed to identify security problems. You should know how to collect the right evidence, centralize findings, create alerts, and troubleshoot missing or incorrect security data.

Important topics include:

  • Amazon GuardDuty, AWS Security Hub, Amazon Macie, and Amazon Security Lake
  • AWS CloudTrail, CloudWatch Logs, VPC Flow Logs, and Route 53 Resolver logs
  • Organization-wide logging and dedicated security accounts
  • Metrics, alerts, health checks, dashboards, and automated assessments
  • Log storage, normalization, correlation, and integration with third-party security tools
  • CloudWatch Logs Insights, Amazon Athena, OpenSearch Service, and Lambda-based processing
  • Troubleshooting missing logs, incorrect permissions, and agent configuration

Practice tip: decide what evidence is needed before choosing a logging or detection service. A network-flow question, API-activity question, sensitive-data question, and workload-threat question usually require different sources.

Domain 2: Incident Response — 14%

Incident Response begins after a potential security event has been identified. It covers preparation, investigation, containment, threat removal, recovery, and root-cause analysis.

Focus on:

  • Response plans, runbooks, playbooks, and testing procedures
  • Preparing access and security tools before an incident
  • Reducing blast radius through account and network design
  • Automated remediation using Systems Manager, Step Functions, and Lambda
  • Capturing logs and system evidence for investigation
  • Validating Security Hub, GuardDuty, Inspector, and other service findings
  • Containing affected resources and restoring known-good data
  • Using Amazon Detective and correlated logs for root-cause analysis

Practice tip: identify the response phase. A question asking how to prepare for an event needs a different answer from one asking how to preserve evidence, isolate a resource, remove a threat, or recover a workload.

Domain 3: Infrastructure Security — 18%

Infrastructure Security covers security at the network edge, inside networks, and across compute workloads. It also includes vulnerability management and secure administrative access.

Study these areas:

  • Amazon CloudFront, AWS WAF, AWS Shield Advanced, and rate-based protections
  • OWASP threats, edge rules, geographic restrictions, and third-party WAF integrations
  • Open Cybersecurity Schema Framework integrations
  • Hardened EC2 AMIs and container images
  • Amazon Inspector, GuardDuty runtime monitoring, Systems Manager Patch Manager, and EC2 Image Builder
  • Service roles, execution roles, and instance profiles for workloads
  • Systems Manager Session Manager and EC2 Instance Connect
  • Security groups, network ACLs, AWS Network Firewall, and network segmentation
  • Site-to-Site VPN, Direct Connect, MAC Security, and AWS Verified Access
  • Security protections for generative AI applications

SCS-C03 specifically includes protections and guardrails for generative AI applications. Candidates do not need to train machine-learning models, but they should understand security concerns such as controlling access, protecting data, filtering unsafe interactions, and reducing risks described by recognized GenAI security guidance.

Domain 4: Identity and Access Management — 20%

Identity and Access Management is the largest SCS-C03 domain. It covers authentication—proving who or what an identity is—and authorization—deciding what that identity may do.

Key topics include:

  • IAM Identity Center, Amazon Cognito, MFA, and external identity providers
  • Human, application, and system authentication
  • AWS STS temporary credentials and S3 presigned URLs
  • Permission sets, AWS Directory Service, and authentication troubleshooting
  • IAM roles, trust policies, resource policies, and cross-account access
  • Attribute-based and role-based access control
  • Permission boundaries, session policies, and least privilege
  • IAM Access Analyzer, IAM Policy Simulator, and authorization troubleshooting
  • Amazon Verified Permissions and IAM Roles Anywhere

Practice tip: first decide whether a scenario is an authentication or authorization problem. If an identity cannot sign in or receive credentials, investigate authentication. If the identity is known but an action is allowed or denied incorrectly, investigate authorization and policy evaluation.

Domain 5: Data Protection — 18%

Data Protection covers data in transit, data at rest, backups, secrets, certificates, and cryptographic key materials.

Study:

  • TLS policies, private access, VPC endpoints, PrivateLink, Client VPN, and Verified Access
  • Inter-resource encryption for services such as EKS, EMR, and SageMaker AI
  • AWS KMS, AWS CloudHSM, client-side encryption, and server-side encryption
  • S3 Object Lock, S3 Glacier Vault Lock, versioning, and code signing
  • Data lifecycle, retention, secure replication, AWS Backup, and ransomware protection
  • AWS Secrets Manager and credential rotation
  • Imported key material, external key stores, and AWS-generated key material
  • Sensitive-data masking in CloudWatch Logs and Amazon SNS
  • Multi-Region keys and certificate management with AWS Private CA

Practice tip: write down the exact requirement. “Encrypt data,” “customer controls keys,” “keys remain outside AWS,” “protect against deletion,” “rotate credentials,” and “mask sensitive values” point to different services and configurations.

Domain 6: Security Foundations and Governance — 14%

This domain covers the controls used to manage security consistently across accounts and evaluate compliance.

Focus on:

  • AWS Organizations and AWS Control Tower
  • Service control policies, resource control policies, AI service opt-out policies, and declarative policies
  • Delegated administrator accounts for security services
  • Root-user protection, centralized root access, MFA, and break-glass procedures
  • Infrastructure as code, CloudFormation StackSets, CloudFormation Guard, and cfn-lint
  • Central policy deployment with AWS Firewall Manager
  • Secure resource sharing with AWS RAM and AWS Service Catalog
  • AWS Config rules, conformance packs, aggregation, and automated remediation
  • AWS Audit Manager, AWS Artifact, Security Hub, and the AWS Well-Architected Tool

Practice tip: account-level governance questions usually need a central solution. Repeating manual changes in every member account is rarely the best long-term design when AWS Organizations, Control Tower, delegated administration, StackSets, or Firewall Manager can enforce consistent controls.

What Changed from SCS-C02 to SCS-C03?

SCS-C03 is not simply SCS-C02 with a new code. AWS reorganized the domains and added or expanded several current security topics.

Major changes include:

  • Detection and Incident Response are now separate domains.
  • Identity and Access Management increased from 16% to 20%.
  • The governance domain was renamed Security Foundations and Governance.
  • SCS-C03 adds validation of security-service findings during incidents.
  • It adds OCSF and third-party WAF integration examples.
  • It includes protections for generative AI applications.
  • Data Protection includes inter-resource encryption, imported key material, sensitive-data masking, and key or certificate management across Regions.
  • Governance includes newer organization-wide policies and centralized controls.

The official AWS comparison of SCS-C02 and SCS-C03 confirms that SCS-C03 has been in use since December 2, 2025. If practice material still uses the old six-domain names and weights, do not assume it fully covers the current test.

AWS Services to Prioritize for SCS-C03 Practice

The official service list is broad because security affects almost every AWS workload. Organize your review by security purpose:

Security purposeServices and features to understand
Detection and findingsGuardDuty, Security Hub, Macie, Inspector, Security Lake
Logging and analysisCloudTrail, CloudWatch, Athena, OpenSearch Service, VPC Flow Logs
Incident responseSystems Manager, Step Functions, Lambda, Detective, AWS Backup
Edge and network securityWAF, Shield Advanced, Network Firewall, CloudFront, Verified Access
IdentityIAM, IAM Identity Center, STS, Cognito, Directory Service, Verified Permissions
Data securityKMS, CloudHSM, Secrets Manager, ACM, AWS Private CA, S3 Object Lock
GovernanceOrganizations, Control Tower, Config, Audit Manager, Artifact, Firewall Manager

AWS notes that its SCS-C03 in-scope service list is non-exhaustive and may change. Learn the security role of each service rather than attempting to memorize a large list without context.

How Is the SCS-C03 Exam Scored?

The exam reports a scaled score from 100 to 1,000, and the minimum passing score is 750. A scaled score is not a raw percentage. A score of 750 does not necessarily mean exactly 75% of the questions were answered correctly.

AWS uses scaled scoring because candidates may receive different exam forms with small differences in question difficulty. Statistical scaling allows the result to represent the same performance standard across forms.

Of the 65 questions, 50 affect your score and 15 are unscored. AWS uses the unscored questions to evaluate possible future scored items. They are not identified, so answer every question seriously.

Unanswered questions are scored as incorrect, and there is no penalty for guessing. If time is nearly finished, choose your best answer instead of leaving an item blank.

What Question Types Appear on SCS-C03?

The current exam guide documents four response types:

  1. Multiple choice: Choose one correct answer from four options.
  2. Multiple response: Choose two or more correct answers from at least five options.
  3. Ordering: Select the required steps and place them in the correct sequence.
  4. Matching: Match each prompt with its correct response.

The public AWS exam overview summarizes the format as multiple choice or multiple response, while the more detailed current exam guide also documents ordering and matching. Practice all four formats so the interface and response method do not distract you from the security problem.

For ordering questions, identify the required starting condition, dependency, and final outcome. For matching questions, solve the most certain pair first, then use the remaining choices to complete the set.

Can I Take the SCS-C03 Exam Online?

Yes. SCS-C03 can be taken through Pearson VUE online proctoring or at a Pearson VUE testing center. AWS says online proctoring is available for all AWS Certification exams.

For an online appointment, you need:

  • A compatible computer with a webcam and microphone
  • A stable internet connection
  • A quiet, private, well-lit room
  • A clear desk without notes, mobile devices, or extra screens
  • Identification that meets the requirements in your confirmation email

Run the Pearson VUE system test on the same computer and connection you plan to use. Avoid relying on a work-managed computer unless you know its security settings allow the exam application. The proctor will monitor the room, your webcam, and your screen during the session.

Online proctor languages and available hours are not identical to exam languages. Confirm that a suitable proctoring option is available when scheduling.

How to Register for SCS-C03

  1. Sign in to your AWS Certification Account.
  2. Select the option to schedule a new exam.
  3. Find AWS Certified Security – Specialty (SCS-C03).
  4. Continue to Pearson VUE.
  5. Choose online proctoring or a testing center.
  6. Select your preferred date, time, and exam language.
  7. Review the name, ID requirements, time zone, price, and delivery option.
  8. Pay the fee and read the confirmation email carefully.

AWS allows candidates to reschedule or cancel up to 24 hours before the appointment. Each appointment may be rescheduled twice. Inside the 24-hour period, changes are generally unavailable and the exam fee may be lost. Check the current AWS before-testing policy before changing an appointment.

Six-Week SCS-C03 Study Plan

This plan is designed for candidates who already understand basic AWS architecture and security. Add more time if IAM, networking, logging, or encryption is new to you.

Week 1: Baseline, Detection, and Logging

Take a short diagnostic test without using notes. Study Detection, including CloudTrail, CloudWatch, GuardDuty, Security Hub, Macie, Security Lake, VPC Flow Logs, and log-analysis choices. Create an error log for missed questions.

Week 2: Incident Response

Review preparation, runbooks, evidence collection, finding validation, containment, threat removal, recovery, and root-cause analysis. Practice placing response actions in the correct order.

Week 3: Infrastructure Security

Study edge protections, WAF, Shield Advanced, workload hardening, Inspector, patching, secure administration, network controls, segmentation, hybrid connectivity, and generative AI guardrails.

Week 4: Identity and Access Management

Spend a full week on the largest domain. Review federation, Identity Center, Cognito, STS, roles, trust policies, cross-account access, permission boundaries, session policies, ABAC, RBAC, Access Analyzer, and policy troubleshooting.

Week 5: Data Protection and Governance

Study encryption in transit and at rest, KMS, CloudHSM, Secrets Manager, certificates, backups, retention, imported keys, and data masking. Then review Organizations, Control Tower, SCPs, RCPs, Config, Firewall Manager, Audit Manager, and Artifact.

Week 6: Timed Practice and Final Review

Use Mock Tests Online under closed-book, timed conditions. Complete at least two mixed simulations. Review every mistake, revisit weak objectives in the official guide, and avoid heavy last-minute study on the day before the exam.

How to Use SCS-C03 Practice Questions Effectively

Use practice in three stages:

Stage 1: Learn without time pressure

Answer domain-based questions with documentation available. Focus on understanding why one service or action fits the requirement.

Stage 2: Build speed by domain

Set a time limit for short sets. Track whether errors come from missing knowledge, misreading the scenario, confusing similar services, or rushing.

Stage 3: Simulate the exam

Complete mixed questions in a quiet room without notes. Use the same time-management approach you plan to follow on exam day.

After every set, review:

  • Incorrect answers
  • Correct answers that were guesses
  • Questions that took too long
  • Services you confused
  • Requirements you overlooked

A useful error log can include the topic, your incorrect assumption, the correct security principle, the official source reviewed, and the date for a second attempt.

SCS-C03 Question-Answering Strategy

Follow a consistent process:

  1. Read the final sentence first. Determine what action or design the question requests.
  2. Identify the security phase. Is the problem detection, investigation, response, prevention, identity, protection, or governance?
  3. Mark the hard requirements. Look for multi-account, least privilege, encryption, evidence retention, automatic remediation, or minimal operational work.
  4. Remove partial solutions. Some answers solve one part but ignore another requirement.
  5. Prefer the correct scope. Account-level, organization-level, network-level, workload-level, and data-level controls are not interchangeable.
  6. Check the order. Detection, evidence preservation, containment, eradication, and recovery should not be mixed without considering the scenario.
  7. Answer every item. There is no penalty for guessing.

For long IAM questions, separate identity, authentication, authorization, policy scope, and policy evaluation. For data questions, separate confidentiality, integrity, retention, backup, deletion protection, secrets, and key control.

SCS-C03 Exam-Day Checklist

Before an online exam

  • Run the required system test.
  • Confirm the appointment time and time zone.
  • Prepare valid identification.
  • Clear the desk and remove prohibited devices.
  • Close unnecessary programs.
  • Make sure nobody enters the room.
  • Join early enough to complete check-in.

Before a test-center exam

  • Confirm the address and travel time.
  • Review identification requirements.
  • Arrive early for check-in.
  • Store personal belongings as instructed.

During the exam

  • Maintain a steady pace across 170 minutes.
  • Flag difficult questions and return later.
  • Read multiple-response instructions carefully.
  • Check the full sequence in ordering questions.
  • Complete every pair in matching questions.
  • Submit an informed guess rather than leaving a blank response.

AWS says final results are normally available in the AWS Certification Account within five business days, unless a result requires security or technical review.

What Happens If You Do Not Pass SCS-C03?

AWS requires candidates who fail an exam to wait 14 calendar days before taking it again. There is no general limit on attempts, but the full exam fee must be paid for each attempt.

Use a failed attempt as diagnostic information. Review the score report, compare it with your practice error log, and select the two or three areas that need the most improvement. Do not restart every subject automatically. Target the misunderstanding, complete focused questions, and then use another timed simulation to confirm progress.

SCS-C03 Frequently Asked Questions

Is SCS-C03 the current AWS Security Specialty exam?

Yes. SCS-C03 has been in use since December 2, 2025. SCS-C02 was used until December 1, 2025.

How many questions are on SCS-C03?

The exam has 65 questions. According to the current exam guide, 50 affect your score and 15 are unscored.

How long is the SCS-C03 exam?

The exam duration is 170 minutes.

What is the SCS-C03 passing score?

The minimum passing score is 750 on a scale from 100 to 1,000. This is a scaled score, not a simple percentage.

How much does SCS-C03 cost?

AWS lists the fee as USD $300. Taxes, exchange rates, and local pricing can affect the final checkout amount.

Can SCS-C03 be taken online?

Yes. You can choose Pearson VUE online proctoring or a Pearson VUE testing center.

What question types appear on SCS-C03?

The current exam guide lists multiple-choice, multiple-response, ordering, and matching questions.

Is another AWS certification required first?

No. AWS does not require a previous certification, although candidates commonly earn Solutions Architect – Associate or Professional before taking Security – Specialty.

How long is the certification valid?

AWS Certified Security – Specialty is valid for three years. You must complete an eligible recertification option before it expires to keep the certification active.

Is SCS-C03 difficult?

SCS-C03 is an advanced exam because it combines security operations with AWS service selection, troubleshooting, architecture, and policy decisions. It becomes more manageable when you study the exact current domains and practice applying services to scenarios.

Are practice tests enough to pass?

Practice tests are useful for identifying gaps, learning response formats, and improving time management. They work best with the official exam guide, AWS documentation, hands-on configuration, security labs, and real cloud experience.

Top 10 Most Challenging SCS-C03 Questions

Question 1
Domain: Identity and Access Management
An admin tried to launch an encrypted-boot EC2 instance using a new AWS KMS customer-managed key. The launch appeared successful but the instance was terminated. The admin’s IAM role allows Describe, security group ingress, and several KMS actions, but one grant-related permission is missing. Which IAM permission is absent?
  • A. kms:GetKeyRotationStatus
  • B. kms:CreateGrant
  • C. kms:GenerateRandom
  • D. kms:EnableKey
Question 2
Domain: Detection
To block abusive bot traffic against Cognito user pool endpoints while preserving legitimate users’ access, which approach is appropriate?
  • A. Enable Amazon Cognito threat protection
  • B. Restrict access to authenticated users only
  • C. Link Cognito with the user pool for authentication
  • D. Monitor requests with CloudWatch.
Question 3
Domain: Incident Response
A company needs to determine the root cause of security findings and visualize them. With VPC Flow Logs, GuardDuty, and CloudTrail enabled, how should IAM roles involved in findings be investigated?
  • A. Use Amazon Detective to conduct IAM role investigations and visualize results.
  • B. Use Amazon Inspector to investigate IAM roles and visualize findings.
  • C. Export GuardDuty findings to S3 and analyze with Amazon Athena.
  • D. Enable AWS Security Hub and use custom actions to investigate IAM roles.
These are the hard ones. There are 220 more. Every question explains why the wrong answers are wrong, with a link to official docs.
Get all 230 questions
Question 4
Domain: Security Foundations and Governance
To restrict certain services and enforce a minimum TLS version 1.2 across all S3 buckets in an AWS Organization, what central solution will apply to existing and future accounts?
  • A. Create an SCP denying restricted services and an SCP to deny s3:* under TLS
  • B. Create an SCP denying restricted services and an RCP denying s3:* under TLS
  • C. Create an SCP statement denying s3:* under TLS
  • D. Create an SCP denying restricted services and a declarative policy denying s3:* under TLS
Question 5
Domain: Identity and Access Management
A web app reads from and writes to an S3 bucket and needs AWS credentials for API calls. How should the app obtain AWS credentials for S3 access?
  • A. Use Cognito identity pools and GetId to obtain credentials.
  • B. Use Cognito identity pools and AssumeRoleWithWebIdentity to obtain credentials.
  • C. Use Cognito user pools and the ID token to obtain credentials.
  • D. Use Cognito user pools and an access token to obtain credentials.
Question 6
Domain: Detection
To identify EC2 instances trying to reach non-standard NTP servers on the internet, given CloudTrail, VPC Flow Logs, and Time Sync requirements, which monitoring approach works?
  • A. Monitor CloudTrail for API calls to non-standard time servers.
  • B. Monitor CloudTrail for API calls to the Amazon Time Sync Service.
  • C. Monitor VPC Flow Logs for traffic to non-standard time servers.
  • D. Monitor VPC Flow Logs for traffic to the Amazon Time Sync Service.
Question 7
Domain: Data Protection
How can you create and manage symmetric keys in a custom key store backed by CloudHSM, use KMS for data keys locally, support asymmetric keys, and audit usage?
  • A. Create keys with AWS KMS using custom key stores and audit with Amazon Athena.
  • B. Create keys with S3 using custom key stores and audit with AWS CloudTrail.
  • C. Create keys with AWS KMS using custom key stores and audit with Amazon GuardDuty.
  • D. Create keys with AWS KMS using custom key stores and audit with AWS CloudTrail.
Question 8
Domain: Security Foundations and Governance
In AWS Organizations, a root SCP blocks external sharing. To allow only the marketing account to share externally while others cannot, what approach fits?
  • A. Create a new SCP in the marketing account allowing sharing.
  • B. Modify the existing SCP to exclude the marketing account with a condition.
  • C. Add an Allow statement for the marketing account in the SCP.
  • D. Use a permissions boundary in the marketing account.
Question 9
Domain: Identity and Access Management
To establish a new KMS key with KMSAdmin allowed to create/disable and KMSUser allowed to decrypt, which key policy satisfies this requirement?
  • A. Policy: KMSAdmin can kms:Create and kms:Disable*, KMSUser can kms:Decrypt.
  • B. Policy: KMSAdmin can kms:Create* and kms:Disable*, KMSUser can kms:Decrypt.
  • C. Policy: KMSAdmin and KMSUser can kms:CreateGrant, but KMSUser cannot kms:Decrypt.
  • D. Policy: Both KMSAdmin and KMSUser can kms:Decrypt* only.
Question 10
Domain: Detection
You want to investigate a specific IAM role and build an investigation report with incident details and indicators of compromise. What tool should you use?
  • A. Amazon Detective for the IAM role investigation.
  • B. AWS Audit Manager for an assessment and report.
  • C. Amazon Inspector for an assessment and report.
  • D. Amazon Inspector for an on-demand IAM role scan.
Disclaimer: Edurely is an independent educational platform. We are not affiliated with, authorized by, endorsed by, or in any way officially connected to AWS . Full disclaimer
Edurely
Curated By Edurely Team

The Edurely Team comprises certified professionals and subject matter experts dedicated to delivering accurate, up-to-date exam preparation materials. We rigorously review every resource to ensure it aligns with the latest industry standards and certification objectives to help you succeed.