SCS-C03 Exam Questions
151 real SCS-C03 exam questions with expert-verified answers and explanations. Page 2 of 4.
- Question #51Identity and Access Management (IAM)
CloudFormation stack deployments fail for some users due to permission inconsistencies. Which combination of steps will ensure consistent deployments MOST securely? (Select THREE.)
AWS CloudFormationIAM Service Rolesiam:PassRolePermission Delegation - Question #52Logging and Monitoring
A company needs centralized log monitoring with automatic detection across hundreds of AWS accounts. Which solution meets these requirements with the LEAST operational effort?
GuardDutyThreat DetectionMulti-Account SecurityOperational Efficiency - Question #53Logging and Monitoring
A company has decided to move its fleet of Linux-based web server instances to an Amazon EC2 Auto Scaling group. Currently, the instances are static and are launched manually. When...
CloudWatch LogsLog ManagementAuto Scaling GroupsLog Analysis - Question #54Incident Response
A company's security engineer receives an abuse notification from AWS indicating that malware is being hosted from the company's AWS account. The security engineer discovers that a...
Incident ResponseCompromise RemediationIAM SecurityThreat Detection - Question #55Infrastructure Security
A company hosts its public website on Amazon EC2 instances behind an Application Load Balancer (ALB). The website is experiencing a global DDoS attack from a specific IoT device br...
AWS WAFDDoS MitigationWeb Application SecurityString Match Rule - Question #56Incident Response
A company's security team wants to receive near-real-time email notifications about AWS abuse reports related to DoS attacks. An Amazon SNS topic already exists and is subscribed t...
AWS HealthAmazon EventBridgeSecurity NotificationsAbuse Reports - Question #57Identity and Access Management (IAM)
A security engineer discovers that a company's user passwords have no required minimum length. The company uses the following identity providers (IdPs): - AWS Identity and Access M...
AWS IAMAmazon CognitoActive Directory FederationPassword Policies - Question #58Logging and Monitoring
A company's web application runs on Amazon EC2 instances behind an Application Load Balancer (ALB) in an Auto Scaling group. An AWS WAF web ACL is associated with the ALB. Instance...
WAF loggingALB access logsKinesis Data Firehoseattacker identification - Question #59Logging and Monitoring
A company has security requirements for Amazon Aurora MySQL databases regarding encryption, deletion protection, public access, and audit logging. The company needs continuous moni...
AWS Config managed rulesAurora MySQL compliancecontinuous monitoringencryption enforcement - Question #60Infrastructure Security
A company runs a global ecommerce website using Amazon CloudFront. The company must block traffic from specific countries to comply with data regulations. Which solution will meet...
CloudFront geo restrictionWAF geo matchtraffic blockingdata regulations - Question #61Logging and Monitoring
An AWS Lambda function was misused to alter data, and a security engineer must identify who invoked the function and what output was produced. The engineer cannot find any logs cre...
Lambda execution roleCloudWatch Logs permissionsIAM permissionsLambda logging - Question #62Data Protection
A company has an encrypted Amazon Aurora DB cluster in the us-east-1 Region that uses an AWS KMS customer managed key. The company must copy a DB snapshot to the us-west-1 Region b...
KMS cross-regionAurora snapshot encryptioncustomer managed keyRDS snapshot copy - Question #63Incident Response
A security engineer needs to prepare Amazon EC2 instances for quarantine during a security incident. AWS Systems Manager Agent (SSM Agent) is installed, and a script exists to inst...
EC2 quarantineSystems Manager Run Commandincident forensicsSSM Agent - Question #64Incident Response
A company needs to identify the root cause of security findings and investigate IAM roles involved in those findings. The company has enabled VPC Flow Logs, Amazon GuardDuty, and A...
Amazon DetectiveGuardDuty findingsIAM role investigationroot cause analysis - Question #65Data Protection
A company uploads data files as objects into an Amazon S3 bucket. A vendor downloads the objects to perform data processing. A security engineer must implement a solution that prev...
S3 Lifecycle policyobject expirationdata retentionS3 bucket management - Question #66Infrastructure Security
A company experienced a security incident caused by a vulnerable container image that was pushed from an external CI/CD pipeline into Amazon ECR. Which solution will prevent vulner...
ECR image scanningAmazon InspectorCI/CD pipeline securitySBOM - Question #67Logging and Monitoring
AWS Config cannot deliver configuration snapshots to Amazon S3. Which TWO actions will remediate this issue?
AWS Config deliveryS3 bucket policyIAM role permissionsconfiguration snapshots - Question #68Data Protection
A company must inventory sensitive data across all Amazon S3 buckets in all accounts from a single security account.
Amazon MacieSecurity Hub delegated adminsensitive data discoverymulti-account - Question #69Infrastructure Security
A company needs to scan all AWS Lambda functions for code vulnerabilities.
Amazon InspectorLambda code scanningvulnerability assessmentserverless security - Question #70Logging and Monitoring
Notify when IAM roles are modified.
EventBridgeCloudTrail eventsIAM role monitoringchange notification - Question #71Data Protection
A company has several Amazon S3 buckets that do not enforce encryption in transit. A security engineer must implement a solution that enforces encryption in transit for all the com...
S3 encryption in transitAWS Config managed ruless3-bucket-ssl-requests-onlyTLS enforcement - Question #72Infrastructure Security
A company is using AWS Organizations with nested OUs to manage AWS accounts. The company has a custom compliance monitoring service for the accounts. The monitoring service runs as...
CloudFormation StackSetsdelegated administratorAWS Organizationsmulti-account deployment - Question #73Identity and Access Management (IAM)
A company is building a secure solution that relies on an AWS Key Management Service (AWS KMS) customer managed key. The company wants to allow AWS Lambda to use the KMS key. Howev...
KMS key policykms:ViaService conditionservice-specific accessleast privilege - Question #74Identity and Access Management (IAM)
A company has a web application that reads from and writes to an Amazon S3 bucket. The company needs to use AWS credentials to authenticate all S3 API calls to the S3 bucket. Which...
Cognito identity poolsAssumeRoleWithWebIdentityfederated credentialsS3 access - Question #75Identity and Access Management (IAM)
A company is running a new workload across accounts in an organization in AWS Organizations. All running resources must have a tag of CostCenter, and the tag must have one of three...
AWS Organizations tag policiesSCP enforcementresource taggingcost allocation - Question #76Infrastructure Security
A company has AWS accounts in an organization in AWS Organizations. An Amazon S3 bucket in one account is publicly accessible. A security engineer must remove public access and ens...
S3 Block Public AccessSCP denypublic access preventionbucket security - Question #77Identity and Access Management (IAM)
A company uses AWS Organizations and has an SCP at the root that prevents sharing resources with external accounts. The company now needs to allow only the marketing account to sha...
SCP conditionsaccount exclusionAWS Organizationsresource sharing policy - Question #78Logging and Monitoring
A security engineer configured VPC Flow Logs to publish to Amazon CloudWatch Logs. After 10 minutes, no logs appear. The issue is isolated to the IAM role associated with VPC Flow...
VPC Flow LogsIAM trust policyservice principalCloudWatch Logs - Question #79Infrastructure Security
A company requires a specific software application to be installed on all new and existing Amazon EC2 instances across an AWS Organization. SSM Agent is installed and active. How c...
AWS ConfigSSMEC2 complianceAWS Organizations - Question #80Logging and Monitoring
A company sends Apache logs from EC2 Auto Scaling instances to a CloudWatch Logs log group with 1-year retention. A suspicious IP address appears in logs. A security engineer needs...
CloudWatch Logs Insightslog analysisApache logsIP filtering - Question #81Logging and Monitoring
A company needs to detect unauthenticated access to its Amazon Elastic Kubernetes Service (Amazon EKS) clusters. The solution must require no additional configuration of the existi...
Amazon GuardDutyEKS Audit Log MonitoringKubernetes securitythreat detection - Question #82Infrastructure Security
A security engineer is designing security controls for a fleet of Amazon EC2 instances that run sensitive workloads in a VPC. The security engineer needs to implement a solution to...
Amazon InspectorEC2 vulnerability scanningpatch managementsoftware vulnerabilities - Question #83Logging and Monitoring
A company stores sensitive data in AWS Secrets Manager. A security engineer needs to design a solution to generate a notification email when anomalous GetSecretValue API calls occu...
AWS Secrets ManagerEventBridgeCloudWatch metric filteranomaly detection - Question #84Data Protection
A security engineer is working with a development team to design a supply chain application that stores sensitive inventory data in an Amazon S3 bucket. The application will use an...
KMS grantscross-account accessS3 encryptionkey management - Question #85Infrastructure Security
A company runs an application on a fleet of Amazon EC2 instances behind an Application Load Balancer (ALB). A security engineer needs to provide secure access to the application wi...
AWS Verified Accessdevice postureALBzero trust access - Question #86Logging and Monitoring
A company needs to retain data that is stored in Amazon CloudWatch Logs log groups. The company must retain this data for 90 days. The company must receive notification in AWS Secu...
AWS Security HubAWS ConfigCloudWatch Logs retentioncompliance monitoring - Question #87Identity and Access Management (IAM)
A company needs to prevent Amazon S3 objects from being shared with IAM identities outside of the company's organization in AWS Organizations. A security engineer is creating and d...
SCPAWS OrganizationsS3 access controlPrincipalOrgID - Question #88Identity and Access Management (IAM)
A security engineer is implementing authentication for a multi-account environment by using federated access with SAML 2.0. The security engineer has configured AWS IAM Identity Ce...
SAML 2.0IAM Identity Centerfederated accessauthentication troubleshooting - Question #89Logging and Monitoring
A company is developing a new serverless application that uses AWS Lambda functions. The company uses AWS CloudFormation to deploy the Lambda functions. The company's developers ar...
Lambda execution roleCloudWatch LogsIAM permissionsCloudFormation - Question #90Logging and Monitoring
A company uses a collaboration application. A security engineer needs to configure automated alerts from AWS Security Hub in the us-west-2 Region for the application. The security...
Security HubEventBridgefinding filteringProductArn - Question #91Identity and Access Management (IAM)
A company has an organization in AWS Organizations. The organization consists of multiple OUs. The company must prevent IAM principals from outside the organization from accessing...
SCPAWS OrganizationsPrincipalOrgIDS3 cross-org access - Question #92Data Protection
A company needs to implement data lifecycle management for Amazon RDS snapshots. The company will use AWS Backup to manage the snapshots. The company must retain RDS automated snap...
AWS BackupRDS snapshotsdata lifecycleretention policy - Question #93Logging and Monitoring
A company's security policy requires all Amazon EC2 instances to use the Amazon Time Sync Service. AWS CloudTrail trails are enabled in all of the company's AWS accounts. VPC flow...
VPC flow logsNTPnetwork traffic monitoringcompliance - Question #94Logging and Monitoring
A company has a multi-account strategy that uses an organization in AWS Organizations with all features enabled. The company has enabled trusted access for AWS Account Management....
AWS Security HubAWS OrganizationsDelegated AdministratorMulti-account strategy - Question #95Logging and Monitoring
A company uses Amazon Elastic Kubernetes Service (Amazon EKS) clusters to run its Kubernetes-based applications. The company uses Amazon GuardDuty to protect the applications. EKS...
GuardDutyEKS control plane logsKubernetes monitoringthreat detection - Question #96Logging and Monitoring
A company needs to log object-level activity in its Amazon S3 buckets. The company also needs to validate the integrity of the log file by using a digital signature. Which solution...
CloudTrail log validationS3 data eventsdigital signaturelog integrity - Question #97Infrastructure Security
A company has a new web-based account management system for an online game. Players create a unique username and password to log in to the system. The company has implemented an AW...
AWS WAFaccount takeover preventioncredential stuffingmanaged rule groups - Question #98Data Protection
A company runs an application that sends logs to a log group in Amazon CloudWatch Logs. The email addresses of the application users are in the logs. The company's developers need...
CloudWatch Logs data protectionPII maskinglog securitymanaged data identifiers - Question #99Data Protection
A security engineer is implementing a logging solution for a company's AWS environment. The security engineer has configured an AWS CloudTrail trail in the company's AWS account. T...
KMS key policyCloudTrail encryptioncustomer managed keykms:Decrypt - Question #100Data Protection
A company must retain backup copies of Amazon RDS DB instances and Amazon Elastic Block Store (Amazon EBS) volumes. The company must retain the backup copies in data centers that a...
AWS Backupcross-region replicationRDS backupEBS backup