SCS-C02 Exam Questions
470 real SCS-C02 exam questions with expert-verified answers and explanations. Page 7 of 10.
- Question #308Data Protection
You have an S3 bucket hosted in AWS. This is used to host promotional videos uploaded by yourself. You need to provide access to users for a limited duration of time. How can this...
pre-signed URLsS3 temporary accessobject access controlS3 - Question #309Security Logging and Monitoring
A company's AWS CloudTrail logs are all centrally stored in an Amazon S3 bucket. The security team controls the company's AWS account. The security team must prevent unauthorized a...
CloudTrail log integrityS3 bucket policySSE-KMSlog file validation - Question #310Identity and Access Management
You are deivising a policy to allow users to have the ability to access objects in a bucket called appbucket. You define the below custom bucket policy But when you try to apply th...
S3 bucket policyresource ARNIAM policyS3 object permissions - Question #311Security Logging and Monitoring
Your company has an EC2 Instance that is hosted in an AWS VPC. There is a requirement to ensure that logs files from the EC2 Instance are stored accordingly. The access should also...
CloudWatch LogsEC2 log streamingIAM policylog access control - Question #312Security Logging and Monitoring
You have enabled Cloudtrail logs for your company's AWS account. In addition, the IT Security department has mentioned that the logs need to be encrypted. How can this be achieved?
CloudTrailSSE-S3default encryptionlogs - Question #313Infrastructure Security
l .amazonaws.com. You have some web pages that use Javascript that access resources in another bucket which has web site hosting also enabled. But when users access the web pages ,...
S3 CORScross-originstatic website hostingJavaScript - Question #314Infrastructure Security
Compliance requirements state that all communications between company on-premises hosts and EC2 instances be encrypted in transit. Hosts use custom proprietary protocols for their...
TLS in transitClassic Load BalancerTCP listenercustom protocol - Question #315Infrastructure Security
You have a 2 tier application hosted in AWS. It consists of a web server and database server (SQL Server) hosted on separate EC2 Instances. You are devising the security groups for...
security groupsleast privilegemulti-tier architectureport rules - Question #316Management and Security Governance
A security team must present a daily briefing to the CISO that includes a report of which of the company's thousands of EC2 instances and on-premises servers are missing the latest...
patch managementSystems Managercompliance reportingEC2 - Question #318Infrastructure Security
A company hosts a critical web application on the AWS Cloud. This is a key revenue generating application for the company. The IT Security team is worried about potential DDos atta...
DDoS protectionAWS Shield Advancedincident responseweb application - Question #319Infrastructure Security
A company wants to have an Intrusion detection system available for their VPC in AWS. They want to have complete control over the system. Which of the following would be ideal to i...
IDSVPCAWS Marketplacenetwork security - Question #320Identity and Access Management
You have a vendor that needs access to an AWS resource. You create an AWS user account. You want to restrict access to the resource using a policy for just that user over a brief p...
inline policyIAM policy typesleast privilegetemporary access - Question #321Security Logging and Monitoring
You have just recently set up a web and database tier in a VPC and hosted the application. When testing the app , you are not able to reach the home page for the app. You have veri...
VPC Flow Logsnetwork troubleshootingtraffic analysisdiagnostics - Question #322Infrastructure Security
Which of the following is used as a secure way to log into an EC2 Linux Instance?
EC2key pairsSSH authenticationLinux access - Question #323Data Protection
When you enable automatic key rotation for an existing CMK key where the backing key is managed by AWS, after how long is the key rotated?
KMSCMKautomatic key rotationAWS managed keys - Question #324Incident Response
You have just received an email from AWS Support stating that your AWS account might have been compromised. Which of the following steps would you look to carry out immediately. Ch...
incident responsecompromised accountroot accountIAM access keys - Question #325Infrastructure Security
You have a web site that is sitting behind AWS Cloudfront. You need to protect the web site against threats such as SQL injection and Cross site scripting attacks. Which of the fol...
AWS WAFSQL injectionXSSCloudFront - Question #326Infrastructure Security
You have an Ec2 Instance in a private subnet which needs to access the KMS service. Which of the following methods can help fulfil this requirement, keeping security in perspective
VPC endpointKMSprivate subnetnetwork isolation - Question #327Infrastructure Security
A company hosts a popular web application that connects to an Amazon RDS MySQL DB instance running in a private VPC subnet that was created with default ACL settings. The IT Securi...
NACLDDoS mitigationIP blockingstateless rules - Question #328Infrastructure Security
You are trying to use the AWS Systems Manager run command on a set of Instances. The run command on a set of Instances. What can you do to diagnose the issue? Choose 2 answers from...
AWS Systems ManagerSSM AgentRun CommandTroubleshooting - Question #329Data Protection
A user has enabled versioning on an S3 bucket. The user is using server side encryption for data at Rest. If the user is supplying his own keys for encryption SSE-C, which of the b...
SSE-CS3 versioningcustomer-provided keysencryption at rest - Question #330Infrastructure Security
An application running on EC2 instances in a VPC must access sensitive data in the data center. The access must be encrypted in transit and have consistent low latency. Which hybri...
Direct ConnectVPNhybrid architectureencryption in transit - Question #331Identity and Access Management
Which technique can be used to integrate AWS IAM (Identity and Access Management) with an on- premise LDAP (Lightweight Directory Access Protocol) directory service?
SAML federationLDAPIAM identity providerSSO - Question #332Data Protection
Your company has an external web site. This web site needs to access the objects in an S3 bucket. Which of the following would allow the web site to access the objects in the most...
S3 bucket policyaws:Referer conditioncross-origin accessconditional access control - Question #333Infrastructure Security
You have an EC2 instance with the following security configured:
VPC flow logssecurity groupsNACLstateless vs stateful - Question #334Infrastructure Security
There are currently multiple applications hosted in a VPC. During monitoring it has been noticed that multiple port scans are coming in from a specific IP Address block. The intern...
NACLIP blockingport scanningnetwork access control - Question #335Identity and Access Management
An organization has launched 5 instances: 2 for production and 3 for testing. The organization wants that one particular group of IAM users should only access the test instances an...
IAM policiesresource taggingEC2 access controlcondition keys - Question #336Data Protection
You company has mandated that all data in AWS be encrypted at rest. How can you achieve this for EBS volumes? Choose 2 answers from the options given below
EBS encryptionBitLockerdata at restvolume encryption - Question #337Security Logging and Monitoring
You currently operate a web application In the AWS US-East region. The application runs on an auto- scaled layer of EC2 instances and an RDS Multi-AZ database. Your IT security com...
CloudTrailS3 log storagelog integrityglobal services - Question #338Infrastructure Security
You need to create a Linux EC2 instance in AWS. Which of the following steps is used to ensure secure authentication the EC2 instance from a windows machine. Choose 2 answers from...
EC2 key pairsPuTTYSSH authenticationLinux access - Question #339Data Protection
You have an S3 bucket defined in AWS. You want to ensure that you encrypt the data before sending it across the wire. What is the best way to achieve this?
client-side encryptionS3 encryptionAWS Encryption CLIdata in transit - Question #340Identity and Access Management
You are working for a company and been allocated the task for ensuring that there is a federated authentication mechanism setup between AWS and their On-premise Active Directory. W...
Federated IdentityActive Directory Federation Services (AD FS)IAM RolesSAML - Question #341Logging and Monitoring
In your LAMP application, you have some developers that say they would like access to your logs. However, since you are using an AWS Auto Scaling group, your instances are constant...
centralized loggingauto scalingS3 log storagelog management - Question #342Security Logging and Monitoring
Your company has defined a set of S3 buckets in AWS. They need to monitor the S3 buckets and know the source IP address and the person who make requests to the S3 bucket. How can t...
CloudTrailS3 API loggingsource IP trackingaudit logging - Question #343Security Logging and Monitoring
A company has set up the following structure to ensure that their S3 buckets always have logging enabled If there are any changes to the configuration to an S3 bucket, a config rul...
Lambda permissionsIAM rolesAWS ConfigS3 remediation - Question #344Data Protection
A company needs to encrypt all of its data stored in Amazon S3. The company wants to use AWS Key Management Service (AWS KMS) to create and manage its encryption keys. The company'...
AWS KMSKey ManagementData EncryptionCustom Key Store - Question #345Infrastructure Security
An application running on EC2 instances in a VPC must call an external web service via TLS (port 443). The instances run in public subnets. Which configurations below allow the app...
NACLsecurity groupsephemeral portsTLS port 443 - Question #346Identity and Access Management
A company wishes to enable Single Sign On (SSO) so its employees can login to the management console using their corporate directory identity. Which steps below are required as par...
SSOidentity federationIAM rolescorporate directory - Question #347Identity and Access Management
A company hosts data in S3. There is a requirement to control access to the S3 buckets. Which are the 2 ways in which this can be achieved?
S3 bucket policiesIAM user policiesS3 access control - Question #348Infrastructure Security
A company needs to use HTTPS when connecting to its web applications to meet compliance requirements. These web applications run in Amazon VPC on Amazon EC2 instances behind an App...
ALB securityHTTPS enforcementsecurity groupsport 443 - Question #349Threat Detection and Incident Response
Your company currently has a set of EC2 Instances hosted in a VPC. The IT Security department is suspecting a possible DDos attack on the instances. What can you do to zero in on t...
VPC flow logsDDoS detectionIP address monitoringincident investigation - Question #350Threat Detection and Incident Response
You need to inspect the running processes on an EC2 Instance that may have a security issue. How can you achieve this in the easiest way possible. Also you need to ensure that the...
SSM Run Commandprocess inspectionsecurity investigationEC2 management - Question #351Data Protection
Which of the following is the responsibility of the customer? Choose 2 answers from the options given below
Shared Responsibility ModelCustomer ResponsibilityEncryption At RestEncryption In Transit - Question #352Infrastructure Security
You are planning on hosting a web application on AWS. You create an EC2 Instance in a public subnet. This instance needs to connect to an EC2 Instance that will host an Oracle data...
VPC subnetsdatabase securitysecurity groupsmulti-tier architecture - Question #353Data Protection
A company hosts data in S3. There is now a mandate that going forward all data in the S3 bucket needs to encrypt at rest. How can this be achieved? Please select:
S3 server-side encryptionSSEdata at restencryption - Question #354Identity and Access Management
A security engineer must troubleshoot an administrator's inability to make an existing Amazon S3 bucket public in an account that is part of an organization n AWS Organizations. Th...
S3 PermissionsAWS OrganizationsIAM RolesAccess Control Troubleshooting - Question #355Data Protection
Your company has created a set of keys using the AWS KMS service. They need to ensure that each key is only used for certain services. For example , they want one key to be used on...
KMS key policyViaService conditionservice-specific encryptionkey management - Question #356Data Protection
A company has a set of EC2 instances hosted in AWS. These instances have EBS volumes for storing critical information. There is a business continuity requirement and in order to bo...
EBS snapshotsdata durabilitybusiness continuityEBS lifecycle policies - Question #357Incident Response
A company's Security Team received an email notification from the Amazon EC2 Abuse team that one or more of the company's Amazon EC2 instances may have been compromised Which combi...
Incident ResponseEC2 SecurityNetwork ContainmentResource Eradication - Question #358Security Logging and Monitoring
A company has been using the AW5 KMS service for managing its keys. They are planning on carrying out housekeeping activities and deleting keys which are no longer in use. What are...
KMS key managementCloudTrail auditkey permissionskey usage