SCS-C02 Exam Questions
470 real SCS-C02 exam questions with expert-verified answers and explanations. Page 3 of 10.
- Question #105
A company's policy requires that all API keys be encrypted and stored separately from source code in a centralized security account. This security account is managed by the company...
- Question #106
A security engineer is asked to update an AWS CloudTrail log file prefix for an existing trail. When attempting to save the change in the CloudTrail console, the security engineer...
- Question #107
A company uses AWS Organizations. The company wants to implement short-term credentials for third-party AWS accounts to use to access accounts within the company's organization. Ac...
- Question #108
A company is evaluating its security posture. In the past, the company has observed issues with specific hosts and host header combinations that affected the company's business. Th...
- Question #109
A security engineer is trying to use Amazon EC2 Image Builder to create an image of an EC2 instance. The security engineer has configured the pipeline to send logs to an Amazon S3...
- Question #110
A security engineer must use AWS Key Management Service (AWS KMS) to design a key management solution for a set of Amazon Elastic Block Store (Amazon EBS) volumes that contain sens...
- Question #111Identity and Access Management
A security engineer is building a Java application that is running on Amazon EC2. The application communicates with an Amazon RDS instance and authenticates with a user name and pa...
Secrets ManagementCredential RotationApplication SecurityDowntime Minimization - Question #112
A company uses SAML federation to grant users access to AWS accounts. A company workload that is in an isolated AWS account runs on immutable infrastructure with no human access to...
- Question #113Identity and Access Management
A security engineer is working with a product team building a web application on AWS. The application uses Amazon S3 to host the static content, Amazon API Gateway to provide RESTf...
Amazon CognitoSAMLAPI GatewayAuthentication - Question #114
A company needs to improve its ability to identify and prevent IAM policies that grant public access or cross-account access to resources. The company has implemented AWS Organizat...
- Question #115Threat Detection and Incident Response
A security engineer is configuring a mechanism to send an alert when three or more failed sign-in attempts to the AWS Management Console occur during a 5-minute period. The securit...
CloudTrailCloudWatch LogsCloudWatch AlarmsFailed Login Detection - Question #116Threat Detection and Incident Response
A company's security engineer is developing an incident response plan to detect suspicious activity in an AWS account for VPC hosted resources. The security engineer needs to provi...
GuardDutyThreat DetectionIncident ResponseCost Optimization - Question #117
A company stores images for a website in an Amazon S3 bucket. The company is using Amazon CloudFront to serve the images to end users. The company recently discovered that the imag...
- Question #118
A company has deployed servers on Amazon EC2 instances in a VPC. External vendors access these servers over the internet. Recently, the company deployed a new application on EC2 in...
- Question #119Infrastructure Security
A company uses infrastructure as code (IaC) to create AWS infrastructure. The company writes the code as AWS CloudFormation templates to deploy the infrastructure. The company has...
Policy as CodeCloudFormation GuardCI/CD SecurityInfrastructure as Code (IaC) - Question #120Infrastructure Security
A company is running an Amazon RDS for MySQL DB instance in a VPC. The VPC must not send or receive network traffic through the internet. A security engineer wants to use AWS Secre...
VPC EndpointsPrivateLinkLambda NetworkingSecrets Manager - Question #121Infrastructure Security
The security engineer is managing a traditional three-tier web application that is running on Amazon EC2 instances. The application has become the target of increasing numbers of m...
Security GroupsVulnerability ManagementAmazon InspectorAttack Surface Reduction - Question #123Data Protection
A company's data scientists want to create artificial intelligence and machine learning (AI/ML) training models by using Amazon SageMaker. The training models will use large datase...
S3 LifecycleData RetentionData DeletionAmazon S3 - Question #124Identity and Access Management
A security engineer is troubleshooting an AWS Lambda function that is named MyLambdaFunction. The function is encountering an error when the function attempts to read the objects i...
S3 Bucket PolicyIAM ResourceLambda AccessAccess Control - Question #125
An IAM user receives an Access Denied message when the user attempts to access objects in an Amazon S3 bucket. The user and the S3 bucket are in the same AWS account. The S3 bucket...
- Question #126Security and Compliance – Implementing data protection and enforcing encryption policies for Amazon S3 using bucket policies and condition keys
A company has a guideline that mandates the encryption of all Amazon S3 bucket data in transit. A security engineer must implement an S3 bucket policy that denies any S3 operations...
S3 Bucket PolicyEncryption in Transitaws:SecureTransportIAM Conditions - Question #127
A security engineer wants to use Amazon Simple Notification Service (Amazon SNS) to send email alerts to a company's security team for Amazon GuardDuty findings that have a High se...
- Question #128Data Protection
A security engineer needs to implement a write-once-read-many (WORM) model for data that a company will store in Amazon S3 buckets. The company uses the S3 Standard storage class f...
S3 Object LockWORMData ImmutabilityCompliance Mode - Question #129
A company needs complete encryption of the traffic between external users and an application. The company hosts the application on a fleet of Amazon EC2 instances that run in an Au...
- Question #130Identity and Access Management
A company has an organization with SCPs in AWS Organizations. The root SCP for the organization is as follows: The company's developers are members of a group that has an IAM polic...
AWS OrganizationsService Control Policies (SCPs)IAM PoliciesPermissions Management - Question #131Infrastructure Security
A company hosts a public website on an Amazon EC2 instance. HTTPS traffic must be able to access the website. The company uses SSH for management of the web server. The website is...
Security GroupsNetwork SecurityEC2 SecurityLeast Privilege - Question #132Identity and Access Management
A security engineer wants to forward custom application-security logs from an Amazon EC2 instance to Amazon CloudWatch. The security engineer installs the CloudWatch agent on the E...
CloudWatch AgentIAM PermissionsEC2 Instance RolesLog Collection Troubleshooting - Question #133
A systems engineer is troubleshooting the connectivity of a test environment that includes a virtual security appliance deployed inline. In addition to using the virtual security a...
- Question #134Identity and Access Management - Implement and manage authorization controls for AWS resources, including writing least-privilege S3 bucket policies with correct Principal definitions
A security engineer needs to create an Amazon S3 bucket policy to grant least privilege read access to IAM user accounts that are named User1, User2, and User3. These IAM user acco...
S3 Bucket PoliciesIAM PrincipalsLeast PrivilegeResource-Based Policies - Question #135
A security engineer recently rotated all IAM access keys in an AWS account. The security engineer then configured AWS Config and enabled the following AWS Config managed rules: mfa...
- Question #136Security Logging and Monitoring
A company is using AWS WAF to protect a customized public API service that is based on Amazon EC instances. The API uses an Application Load Balancer. The AWS WAF web ACL is config...
AWS WAFSecurity LoggingWAF TroubleshootingManaged Rules - Question #137
A security engineer is creating an AWS Lambda function. The Lambda function needs to use a role that is named LambdaAuditRole to assume a role that is named AcmeAuditFactoryRole in...
- Question #138
A company has AWS accounts in an organization in AWS Organizations. The organization includes a dedicated security account. All AWS account activity across all member accounts must...
- Question #139Infrastructure Security
A company is testing its incident response plan for compromised credentials. The company runs a database on an Amazon EC2 instance and stores the sensitive database credentials as...
AWS LambdaSecrets ManagerVPC Security GroupsCredential Rotation - Question #140Identity and Access Management / Security Governance - implementing preventive controls using Service Control Policies (SCPs) to enforce security baselines across an AWS Organization without disrupting existing IAM permissions.
A company deploys a set of standard IAM roles in AWS accounts. The IAM roles are based on job functions within the company. To balance operational efficiency and security, a securi...
AWS Organizations SCPsIAM Security ControlsGuardDutySecurity Hub - Question #141
A company needs to follow security best practices to deploy resources from an AWS CloudFormation template. The CloudFormation template must be able to configure sensitive database...
- Question #142
An international company wants to combine AWS Security Hub findings across all the company's AWS Regions and from multiple accounts. In addition, the company wants to create a cent...
- Question #143Identity and Access Management
An AWS account administrator created an IAM group and applied the following managed policy to require that each individual user authenticate using multi-factor authentication: Afte...
IAMMFAAWS CLISTS - Question #144
A company is developing a mechanism that will help data scientists use Amazon SageMaker to read, process, and output data to an Amazon S3 bucket. Data scientists will have access t...
- Question #145
A company has AWS accounts that are in an organization in AWS Organizations. An Amazon S3 bucket in one of the accounts is publicly accessible. A security engineer must change the...
- Question #146Data Protection
A company is designing a new application stack. The design includes web servers and backend servers that are hosted on Amazon EC2 instances. The design also includes an Amazon Auro...
Encryption at RestEBS EncryptionAurora EncryptionAWS KMS - Question #147
A company uses SAML federation with AWS Identity and Access Management (IAM) to provide internal users with SSO for their AWS accounts. The company's identity provider certificate...
- Question #148
A company is implementing a new application in a new AWS account. A VPC and subnets have been created for the application. The application has been peered to an existing VPC in ano...
- Question #149
A company needs a forensic-logging solution for hundreds of applications running in Docker on Amazon EC2. The solution must perform real-time analytics on the logs, must support th...
- Question #150
A company has many member accounts in an organization in AWS Organizations. The company is concerned about the potential for misuse of the AWS account root user credentials for mem...
- Question #151
An Amazon EC2 Auto Scaling group launches Amazon Linux EC2 instances and installs the Amazon CloudWatch agent to publish logs to Amazon CloudWatch Logs. The EC2 instances launch wi...
- Question #152
A company uses Amazon Elastic Container Service (Amazon ECS) containers that have the Fargate launch type. The containers run web and mobile applications that are written in Java a...
- Question #153Infrastructure Security
A company uses Amazon EC2 Linux instances in the AWS Cloud. A member of the company's security team recently received a report about common vulnerability identifiers on the instanc...
Patch ManagementAWS Systems ManagerVulnerability ManagementEC2 Security - Question #154
A company hosts an application on Amazon EC2 that is subject to specific rules for regulatory compliance. One rule states that traffic to and from the workload must be inspected fo...
- Question #155
A company deploys a distributed web application on a fleet of Amazon EC2 instances. The fleet is behind an Application Load Balancer (ALB) that will be configured to terminate the...