SCS-C02 Exam Questions
470 real SCS-C02 exam questions with expert-verified answers and explanations. Page 2 of 10.
- Question #52Identity and Access Management
A company uses several AWS CloudFormation stacks to handle the deployment of a suite of applications. The leader of the company's application development team notices that the stac...
CloudFormation service roleIAM PassRolestack deployment permissionsIAM role delegation - Question #53Security Logging and Monitoring
A company used a lift-and-shift approach to migrate from its on-premises data centers to the AWS Cloud. The company migrated on-premises VMs to Amazon EC2 instances. Now the compan...
ELB access logsS3 log storageAthena log queryinglog centralization - Question #54Data Protection
A company is designing a solution to serve content from an Amazon CloudFront distribution that will have an Amazon S3 bucket as the origin. A security engineer needs to encrypt S3...
S3 server-side encryptionKMS customer managed keyCloudFront OACLambda@Edge - Question #55Infrastructure Security
A security engineer is attempting to push a Linux-based container image to an Amazon Elastic Container Registry (Amazon ECR) repository that is in the us-east-1 Region. The securit...
ECR authenticationAWS CLI region configurationcontainer registryDocker login - Question #56Identity and Access Management
A security engineer is trying to use Amazon EC2 Image Builder to create an image of an EC2 instance. The security engineer has configured the pipeline to send logs to an Amazon S3...
EC2 Image BuilderIAM instance profileleast privilegeS3 permissions - Question #57Threat Detection and Incident Response
A company has a legacy application that runs on a single Amazon EC2 instance. A security audit shows that the application has been using an IAM access key within its code to access...
CloudTrail forensicsAthena log analysisaccess key compromiseAmazon Macie PII - Question #59Threat Detection and Incident Response
A company is using Amazon Macie, AWS Firewall Manager, Amazon Inspector, and AWS Shield Advanced in its AWS account. The company wants to receive alerts if a DDoS attack occurs aga...
AWS Shield AdvancedDDoS detectionCloudWatch alarmsDDoS metrics - Question #61Security Logging and Monitoring
A company hosts a web application on an Apache web server. The application runs on Amazon EC2 instances that are in an Auto Scaling group. The company configured the EC2 instances...
CloudWatch Logs Insightslog analysisApache web server logsIP request analysis - Question #62Infrastructure Security
While securing the connection between a company's VPC and its on-premises data center, a security engineer sent a ping command from an on-premises host (IP address 203.0.113.12) to...
VPC flow logsNACL configurationICMP trafficnetwork troubleshooting - Question #63Data Protection
A company developed an application by using AWS Lambda, Amazon S3, Amazon Simple Notification Service (Amazon SNS), and Amazon DynamoDB. An external application puts objects into t...
S3 Lifecycle policyDynamoDB TTLPII data retentiondata expiration - Question #64Identity and Access Management
What are the MOST secure ways to protect the AWS account root user of a recently opened AWS account? (Choose two.)
root user securityMFAaccess key managementaccount security best practices - Question #65Management and Security Governance
A company is expanding its group of stores. On the day that each new store opens, the company wants to launch a customized web application for that store. Each store's application...
AWS Service CatalogAWS Organizationsdeployment governanceCloudFormation templates - Question #66Identity and Access Management
A team is using AWS Secrets Manager to store an application database password. Only a limited number of IAM principals within the account can have access to the secret. The princip...
AWS Secrets Managertag-based access controlresource policyIAM flexibility - Question #67Infrastructure Security
A company is hosting a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application has become the target of a DoS attack. Application logging...
AWS WAFrate-based rulesDoS mitigationALB protection - Question #68Identity and Access Management
A security engineer for a company wants to maintain all IAM users and roles according to the principle of least privilege. The security engineer plans to audit the IAM permissions...
IAM Access Analyzerleast privilegelast accessed informationIAM audit - Question #69Identity and Access Management
A security engineer is working for a parent company that provides hosting and services to client companies. The parent company maintains an organization in AWS Organizations for al...
AWS SSOexternal identity providerAWS Organizationsfederated access - Question #70Threat Detection and Incident Response
A security team has received an alert from Amazon GuardDuty that AWS CloudTrail logging has been disabled. The security team's account has AWS Config, Amazon Inspector, Amazon Dete...
Amazon GuardDutyAmazon DetectiveCloudTrail logging disabledincident investigation - Question #71Infrastructure Security
A company has a requirement that none of its Amazon RDS resources can be publicly accessible. A security engineer needs to set up monitoring for this requirement and must receive a...
AWS Config managed ruleRDS public accessEventBridge notificationscompliance monitoring - Question #72Data Protection
A company's security engineer has configured a client account to capture AWS CloudTrail logs that are then sent to an Amazon S3 bucket. The S3 bucket that stores these CloudTrail l...
KMS key policyS3 encryptionCloudTrail logsdecrypt permissions - Question #73Data Protection
A company sends Amazon RDS snapshots to two accounts as part of its disaster recovery (DR) plan. The snapshots must be encrypted. However, each account needs to be able to decrypt...
RDS snapshotsKMS customer managed keycross-account encryptiondisaster recovery - Question #74Infrastructure Security
A company plans to use AWS CodeDeploy to deploy code to multiple Amazon EC2 instances in a VPC at the same time. The company needs to allow the CodeDeploy service to communicate wi...
VPC endpointinterface endpointCodeDeployprivate connectivity - Question #75Data Protection
A company released a new software-as-a-service (SaaS) application that is receiving significant adoption by end users. The rds-storage-encrypted AWS Config managed rule generates a...
RDS encryptionAWS DMSCDC migrationAWS Config - Question #76Security Logging and Monitoring
A company's security engineer must record when specific AWS Lambda functions are invoked. The logs must include the AWS principal that invoked the function. External sources and th...
CloudTrailLambda data eventsaudit loggingexecution principal - Question #77Infrastructure Security
A company wants to use AWS Systems Manager Patch Manager to patch Amazon EC2 instances that run Amazon Linux 2. The EC2 instances are running in a single AWS account. No internet c...
VPC endpointsSystems ManagerS3 gateway endpointprivate subnet - Question #78Security Logging and Monitoring
A company hosts business-critical applications on Amazon EC2 instances in a VPC. The VPC uses default DHCP options sets. A security engineer needs to log all DNS queries that inter...
Route 53 ResolverDNS query loggingVPC DNSCloudWatch Logs - Question #79Infrastructure Security
A company uses Amazon Route 53 to create a public DNS zone for the domain example.com in Account A. The company creates another public DNS zone for the subdomain dev.example.com in...
ACM certificateDNS validationRoute 53 delegationNS records - Question #80Management and Security Governance
A company is implementing new compliance requirements to meet customer needs. According to the new requirements, the company must not use any Amazon RDS DB instances or DB clusters...
AWS ConfigRDS encryptionautomated remediationEventBridge - Question #81Identity and Access Management
A company is using AWS to run a long-running analysis process on data that is stored in Amazon S3 buckets. The process runs on a fleet of Amazon EC2 instances that are in an Auto S...
S3 gateway endpointSCPIAM policy conditionsVPC endpoint policy - Question #82Management and Security Governance
A company that operates in a hybrid cloud environment must meet strict compliance requirements. The company wants to create a report that includes evidence from on-premises workloa...
AWS Audit Managercompliance evidencehybrid cloudframeworks - Question #83Security and Compliance - Implement and manage IAM policies with condition keys to enforce regulatory and organizational guardrails on AWS resource usage
To meet regulatory requirements, a security engineer needs to implement an IAM policy that restricts the use of AWS services to the us-east-1 Region. What policy should the enginee...
IAM PoliciesRegion RestrictionAWS Condition KeysService Control Policies - Question #84Infrastructure Security
A company has a web server in the AWS Cloud. The company will store the content for the web server in an Amazon S3 bucket. A security engineer must use an Amazon CloudFront distrib...
CloudFront OACS3 private contentorigin access controlbucket policy - Question #85Identity and Access Management
A security engineer logs in to the AWS Lambda console with administrator permissions. The security engineer is trying to view logs in Amazon CloudWatch for a Lambda function that i...
Lambda execution roleCloudWatch Logs permissionsIAM policyCreateLogStream - Question #86Data Protection
A company has a new partnership with a vendor. The vendor will process data from the company's customers. The company will upload data files as objects into an Amazon S3 bucket. Th...
S3 Lifecycleobject expirationdata retentionS3 - Question #88Threat Detection and Incident Response
A company purchased a subscription to a third-party cloud security scanning solution that integrates with AWS Security Hub. A security engineer needs to implement a solution that w...
Security HubEventBridgeautomated remediationthird-party findings - Question #89Threat Detection and Incident Response
An application is running on an Amazon EC2 instance that has an IAM role attached. The IAM role provides access to an AWS Key Management Service (AWS KMS) customer managed key and...
IAM role session revocationincident responseS3 bucket policyKMS key - Question #90Data Protection
A company is building an application on AWS that will store sensitive information. The company has a support team with access to the IT infrastructure, including databases. The com...
Secrets Managercredential rotationRDS encryptionleast privilege - Question #91Security Logging and Monitoring
A company is using Amazon Route 53 Resolver for its hybrid DNS infrastructure. The company has set up Route 53 Resolver forwarding rules for authoritative domains that are hosted o...
Route 53 Resolver query logginghybrid DNSforwarding ruleson-premises DNS - Question #92Identity and Access Management
A security engineer is configuring account-based access control (ABAC) to allow only specific principals to put objects into an Amazon S3 bucket. The principals already have access...
ABACS3 bucket policyIAM policy evaluationtag-based conditions - Question #93Infrastructure Security
A company is hosting multiple applications within a single VPC in its AWS account. The applications are running behind an Application Load Balancer that is associated with an AWS W...
AWS WAFIP set ruleweb ACLport scan blocking - Question #94Identity and Access Management
A company has contracted with a third party to audit several AWS accounts. To enable the audit, cross-account IAM roles have been created in each account targeted for audit. The au...
cross-account IAMsts:AssumeRoleexternal IDrole ARN - Question #95Infrastructure Security – Implementing secure access controls for S3 using VPC endpoint restrictions and IAM condition keys (AWS Security Specialty / AWS Solutions Architect)
A security engineer needs to configure an Amazon S3 bucket policy to restrict access to an S3 bucket that is named DOC-EXAMPLE-BUCKET. The policy must allow access to only DOC- EXA...
S3 Bucket PolicyVPC EndpointsIAM Policy ConditionsData Perimeter Security - Question #96Security Logging and Monitoring
A company has a group of Amazon EC2 instances in a single private subnet of a VPC with no internet gateway attached. A security engineer has installed the Amazon CloudWatch agent o...
CloudWatch agentVPC endpointsinstance profile permissionsCloudWatch Logs - Question #97Infrastructure Security
A company uses AWS Signer with all of the company's AWS Lambda functions. A developer recently stopped working for the company. The company wants to ensure that all the code that t...
AWS Signersigning profileLambda code signingrevocation - Question #98Data Protection
A company plans to use AWS Key Management Service (AWS KMS) to implement an encryption strategy to protect data at rest. The company requires client-side encryption for company pro...
data key cachingAWS Encryption SDKKMS throttlingclient-side encryption - Question #99Security Logging and Monitoring
A security team is working on a solution that will use Amazon EventBridge to monitor new Amazon S3 objects. The solution will monitor for public access and for changes to any S3 bu...
CloudTrail data eventsS3 monitoringEventBridgeAPI call logging - Question #100Threat Detection and Incident Response
A company uses Amazon GuardDuty. The company's security team wants all High severity findings to automatically generate a ticket in a third-party ticketing system through email int...
GuardDuty findingsSNS notificationsautomated alertingHigh severity - Question #101Infrastructure Security
A company is using AWS Organizations to implement a multi-account strategy. The company does not have on-premises infrastructure. All workloads run on AWS. The company currently ha...
AWS RAMVPC subnet sharingAWS Organizationscentralized networking - Question #102Identity and Access Management
A company's security team needs to receive a notification whenever an AWS access key has not been rotated in 90 or more days. A security engineer must develop a solution that provi...
AWS ConfigIAM access key rotationmanaged rulescompliance monitoring - Question #103Incident Response
A company maintains an open-source application that is hosted on a public GitHub repository. While creating a new commit to the repository, an engineer uploaded their AWS access ke...
credential exposureIAM credential reportaccess key assessmentincident investigation - Question #104Security Logging and Monitoring
A company plans to create individual child accounts within an existing organization in AWS Organizations for each of its DevOps teams. AWS CloudTrail has been enabled and configure...
SCPCloudTrail protectionAWS Organizationsaudit log integrity