SCS-C03 Exam Questions
151 real SCS-C03 exam questions with expert-verified answers and explanations. Page 1 of 4.
- Question #1Data Protection
A security administrator is setting up a new AWS account. The security administrator wants to secure the data that a company stores in an Amazon S3 bucket. The security administrat...
S3 Block Public AccessData exposure preventionS3 securityOperational overhead - Question #2Identity and Access Management (IAM)
A company's developers are using AWS Lambda function URLs to invoke functions directly. The company must ensure that developers cannot configure or deploy unauthenticated functions...
AWS OrganizationsService Control Policies (SCPs)AWS Lambda Function URLsAccess Control - Question #3Incident Response
A security engineer receives a notice about suspicious activity from a Linux-based Amazon EC2 instance that uses Amazon Elastic Block Store (Amazon EBS)-based storage. The instance...
Incident ResponseEC2 SecurityNetwork IsolationEBS Forensics - Question #4Infrastructure Security
A company has a VPC that has no internet access and has the private DNS hostnames option enabled. An Amazon Aurora database is running inside the VPC. A security engineer wants to...
VPC interface endpointSecrets Managerprivate subnetLambda rotation - Question #5Security Logging and Monitoring
A security engineer wants to forward custom application-security logs from an Amazon EC2 instance to Amazon CloudWatch. The security engineer installs the CloudWatch agent on the E...
CloudWatch agentEC2 instance rolelog forwardingIAM permissions - Question #6Threat Detection and Incident Response
A company is attempting to conduct forensic analysis on an Amazon EC2 instance, but the company is unable to connect to the instance by using AWS Systems Manager Session Manager. T...
SSM Session ManagerVPC interface endpointssecurity groupsforensic analysis - Question #7Identity and Access Management
A security team manages a company's AWS Key Management Service (AWS KMS) customer managed keys. Only members of the security team can administer the KMS keys. The company's applica...
KMS key grantstemporary accesscustomer managed keyleast operational overhead - Question #8Identity and Access Management
A company is using AWS CloudTrail and Amazon CloudWatch to monitor resources in an AWS account. The company's developers have been using an IAM role in the account for the last 3 m...
IAM Access Analyzerpolicy generationleast privilegeCloudTrail activity - Question #9Identity and Access Management
A company uses AWS IAM Identity Center with SAML 2.0 federation. The company decides to change its federation source from one identity provider (IdP) to another. The underlying dir...
SAML 2.0 federationIdP migrationattribute mappingIAM Identity Center - Question #10Data Protection
A company is running its application on AWS. The company has a multi-environment setup, and each environment is isolated in a separate AWS account. The company has an organization...
Amazon Maciedelegated administratorS3 sensitive dataAWS Organizations - Question #11Security Logging and Monitoring
A company must capture AWS CloudTrail data events and must retain the logs for 7 years. The logs must be immutable and must be available to be searched by complex queries. The comp...
CloudTrail Lakedata event retentionimmutable logslog visualization - Question #12Data Protection
A company is planning to migrate its applications to AWS in a single AWS Region. The company's applications will use a combination of Amazon EC2 instances, Elastic Load Balancing (...
Data EncryptionThreat DetectionAWS KMSAWS ACM - Question #13Data Protection
A company is implementing new compliance requirements to meet customer needs. According to the new requirements, the company must not use any Amazon RDS DB instances or DB clusters...
AWS ConfigAutomated RemediationRDS EncryptionCompliance Enforcement - Question #14Logging and Monitoring
A company uses AWS Organizations to manage an organization that consists of three workload OUs: Production, Development, and Testing. The company uses AWS CloudFormation templates...
CloudTrailTroubleshootingIAM permissionsService Control Policies (SCPs) - Question #15Identity and Access Management
A company stores infrastructure and application code in web-based, third-party, Git-compatible code repositories outside of AWS. The company wants to give the code repositories the...
OIDC identity providerfederated accessIAM role trustexternal repositories - Question #16Data Protection
A company wants to establish separate AWS Key Management Service (AWS KMS) keys to use for different AWS services. The company's security engineer created a key policy to allow the...
KMS key policycondition keysIAM role restrictionEBS encryption - Question #17Identity and Access Management
A consultant agency needs to perform a security audit for a company's production AWS account. Several consultants need access to the account. The consultant agency already has its...
cross-account IAM roleMFA enforcementtemporary credentialstrust policy - Question #18Threat Detection and Incident Response
A company runs an internet-accessible application on several Amazon EC2 instances that run Windows Server. The company used an instance profile to configure the EC2 instances. A se...
EC2 Instance Connect endpointforensic accesssecurity groupsincident response - Question #19Threat Detection and Incident Response
A company recently experienced a malicious attack on its cloud-based environment. The company successfully contained and eradicated the attack. A security engineer is performing in...
RDS point-in-time recoveryautomated backupscluster restoreincident recovery - Question #20Threat Detection and Incident Response
A company has an AWS account that hosts a production application. The company receives an email notification that Amazon GuardDuty has detected an Impact:IAMUser/AnomalousBehavior...
GuardDuty findinganomalous IAM behaviorinvestigation playbookread-only access - Question #21Data Protection
A security engineer needs to control access to data that is encrypted with an AWS Key Management Service (AWS KMS) customer managed key. The security engineer also needs to use add...
KMS encryption contextadditional authenticated dataIAM condition keyciphertext integrity - Question #22Identity and Access Management
A company uses AWS IAM Identity Center to manage access to its AWS accounts. The accounts are in an organization in AWS Organizations. A security engineer needs to set up delegated...
IAM Identity Centerdelegated administrationpermission setsOrganizations management account - Question #23Data Protection
A security engineer needs to implement a solution to identify any sensitive data that is stored in an Amazon S3 bucket. The solution must report on sensitive data in the S3 bucket...
Amazon Maciesensitive data detectionS3 scanningSNS notification - Question #24Identity and Access Management (IAM)
An application is running on an Amazon EC2 instance that has an IAM role attached. The IAM role provides access to an AWS Key Management Service (AWS KMS) customer managed key and...
IAM role session revocationKMS key policyS3 bucket policyleast privilege - Question #25Infrastructure Security
A company needs a cloud-based, managed desktop solution for its workforce of remote employees. The company wants to ensure that the employees can access the desktops only by using...
Amazon WorkSpacesclient certificatestrusted devicesremote access - Question #26Identity and Access Management (IAM)
A company runs an application on an Amazon EC2 instance. The application generates invoices and stores them in an Amazon S3 bucket. The instance profile that is attached to the ins...
pre-signed URLsIAM condition keysSTS temporary credentialsS3 access control - Question #27Data Protection
A company is running an application in the eu-west-1 Region. The application uses an AWS Key Management Service (AWS KMS) customer managed key to encrypt sensitive data. The compan...
KMS cross-regionkey aliasesCMK managementencryption continuity - Question #28Identity and Access Management (IAM)
A company that uses AWS Organizations is using AWS IAM Identity Center to administer access to AWS accounts. A security engineer is creating a custom permission set in IAM Identity...
IAM Identity Centerpermission setscustomer managed policiesmulti-account - Question #29Logging and Monitoring
A company has a single AWS account and uses an Amazon EC2 instance to test application code. The company recently discovered that the instance was compromised and was serving malwa...
Amazon GuardDutyEventBridge rulesSNS notificationscontinuous monitoring - Question #30Data Protection
A company has a PHP-based web application that uses Amazon S3 as an object store for user files. The S3 bucket is configured for server-side encryption with Amazon S3 managed keys...
SSE-KMScustomer managed keyS3 encryption migrationkey management - Question #31Infrastructure Security
A company runs a public web application on Amazon EKS behind Amazon CloudFront and an Application Load Balancer (ALB). A security engineer must send a notification to an existing A...
AWS WAFRate-based ruleCloudFrontDDoS mitigation - Question #32Logging and Monitoring
A company needs to build a code-signing solution using an AWS KMS asymmetric key and must store immutable evidence of key creation and usage for compliance and audit purposes. Whic...
AWS KMSCloudTrailS3 Object LockAuditing and Compliance - Question #33Data Protection
A company's application team needs a new AWS Key Management Service (AWS KMS) customer managed key to use with Amazon S3. The company's security policy requires separate keys for d...
KMS key policykms:ViaService conditionservice-level restrictionleast privilege - Question #34Logging and Monitoring
A company uses AWS to run a web application that manages ticket sales in several countries. The company recently migrated the application to an architecture that includes Amazon AP...
AWS Audit ManagerPCI DSS v4.0compliance reportingmanual evidence - Question #35Logging and Monitoring
A company is planning to deploy a new log analysis environment. The company needs to analyze logs from multiple AWS services in near real time. The solution must provide the abilit...
Amazon OpenSearchlog analysisSNS alertingdetection rules - Question #36Identity and Access Management (IAM)
A company uses an organization in AWS Organizations to manage multiple AWS accounts. The company wants to centrally give users the ability to access Amazon Q Developer. Which solut...
IAM Identity CenterAmazon Q DeveloperAWS Organizationsmanaged application - Question #37Data Protection
A company stores sensitive data in an Amazon S3 bucket. The company encrypts the data at rest by using server-side encryption with Amazon S3 managed keys (SSE-S3). A security engin...
S3 Object Lockcompliance modebucket versioningimmutable storage - Question #38Infrastructure Security
A company is operating an open-source software platform that is internet facing. The legacy software platform no longer receives security updates. The software platform operates us...
AWS WAFSQL injection protectionApplication Load Balancerweb application firewall - Question #39Infrastructure Security
A company has a large fleet of Amazon Linux 2 Amazon EC2 instances that run an application processing sensitive data. Compliance requirements include no exposed management ports, f...
Systems Manager Session ManagerIAM Identity Centersession loggingno exposed management ports - Question #40Data Protection
A company's data scientists use Amazon SageMaker with datasets stored in Amazon S3. Data older than 45 days must be removed according to policy. Which action should enforce this po...
S3 Lifecycle rulesdata retention policyautomated deletioncompliance - Question #41Identity and Access Management (IAM)
A company has a web application that reads from and writes to an Amazon S3 bucket. The company needs to authenticate all S3 API calls with AWS credentials. Which solution will prov...
Amazon Cognito identity poolsAssumeRoleWithWebIdentitytemporary credentialsS3 authentication - Question #42Infrastructure Security
A company runs ECS services behind an internet-facing ALB that is the origin for CloudFront. An AWS WAF web ACL is associated with CloudFront, but clients can bypass it by accessin...
CloudFront Origin SecurityApplication Load Balancer (ALB)WAF Bypass PreventionCustom Headers - Question #43Infrastructure Security
A company creates AWS Lambda functions from container images that are stored in Amazon Elastic Container Registry (Amazon ECR). The company needs to identify any software vulnerabi...
Vulnerability ManagementAmazon InspectorContainer SecurityServerless Security - Question #44Infrastructure Security
A security engineer is designing a solution that will provide end-to-end encryption between clients and Docker containers running in Amazon Elastic Container Service (Amazon ECS)....
Network Load BalancerTLS pass-throughend-to-end encryptionECS containers - Question #45Infrastructure Security
A security engineer has designed a VPC to segment private traffic from public traffic. The VPC includes two Availability Zones. Each Availability Zone contains one public subnet an...
VPC routingNAT gatewayroute tablespublic vs private subnets - Question #46Incident Response
A company runs a web application on a fleet of Amazon EC2 instances in an Auto Scaling group. Amazon GuardDuty and AWS Security Hub are enabled. The security engineer needs an auto...
GuardDuty findingsEventBridge automationLambda remediationAuto Scaling group - Question #47Infrastructure Security
A company's security engineer receives an alert that indicates that an unexpected principal is accessing a company-owned Amazon Simple Queue Service (Amazon SQS) queue. All the com...
SQS access controlVPC endpointsaws:SourceVpce conditionnetwork-level restriction - Question #48Data Protection
A company needs to deploy AWS CloudFormation templates that configure sensitive database credentials. The company already uses AWS Key Management Service (AWS KMS) and AWS Secrets...
CloudFormationSecrets ManagerDynamic ReferencesSecrets Management - Question #49Identity and Access Management (IAM)
A company must immediately disable compromised IAM users across all AWS accounts and collect all actions performed by the user in the last 7 days. Which solution will meet these re...
IAM Identity CenterCloudTrail LakeMulti-account IAMSecurity Auditing - Question #50Identity and Access Management (IAM)
A company detects bot activity targeting Amazon Cognito user pool endpoints. The solution must block malicious requests while maintaining access for legitimate users. Which solutio...
Amazon CognitoThreat ProtectionBot MitigationIdentity Security