SCS-C03 Exam Questions
151 real SCS-C03 exam questions with expert-verified answers and explanations. Page 3 of 4.
- Question #101Incident Response
A company runs workloads that are spread across hundreds of Amazon EC2 instances. During a recent security incident, an EC2 instance was compromised and ran malware code until the...
GuardDutyAutomated Incident ResponseAWS LambdaAmazon EventBridge - Question #102Infrastructure Security
A public subnet contains two Amazon EC2 instances. The subnet has a custom network ACL. A security engineer is designing a solution to improve the subnet security. The solution mus...
network ACLstateless rulesephemeral portsport filtering - Question #103Identity and Access Management (IAM)
A company is investigating actions that an IAM role performed. The company must find out when the role last accessed AWS Security Hub and when the role last used the DeleteInsight...
IAM Access Advisorlast accessed informationIAM role activitySecurity Hub - Question #104Logging and Monitoring
A company is migrating container workloads from a data center to Amazon Elastic Container Service (Amazon ECS) clusters. The company must implement a solution to detect potential t...
GuardDuty Runtime MonitoringECS securitycontainer threat detectionruntime security - Question #105Logging and Monitoring
A security engineer needs to implement a solution to determine whether a company's Amazon EC2 instances are being used to mine cryptocurrency. The solution must provide notificatio...
GuardDutyCryptoCurrency findingEventBridgeSNS notification - Question #106Data Protection
A company must create annual snapshots of Amazon Elastic Block Store (Amazon EBS) volumes. The company must retain the snapshots for 10 years. The company will use AWS Key Manageme...
KMS key rotationEBS snapshot encryptioncustomer managed keysymmetric key - Question #107Identity and Access Management (IAM)
A company has hundreds of AWS accounts and uses AWS Organizations. The company plans to create many different IAM roles and policies for its product team, security team, and platfo...
IAM pathSCPAWS Organizationsiam:PassRole restriction - Question #108Logging and Monitoring
A security engineer wants to evaluate configuration changes to a specific AWS resource to ensure that the resource meets compliance standards. However, the security engineer is con...
AWS Configconfiguration recordingcompliance monitoringresource configuration - Question #109Data Protection
A company hosts a web-based application that captures and stores sensitive data in an Amazon DynamoDB table. The company needs to implement a solution that provides end-to-end data...
DynamoDB Encryption Clientclient-side encryptiondigital signingdata integrity - Question #110Infrastructure Security
A security engineer is designing a solution that will provide end-to-end encryption between clients and Docker containers running in Amazon Elastic Container Service (Amazon ECS)....
NLB TLS passthroughend-to-end encryptionECS containersload balancer - Question #111Infrastructure Security
A company has a large fleet of Amazon Linux 2 Amazon EC2 instances that run an application. The application processes sensitive data and has the following compliance requirements:...
SSM Session ManagerIAM Identity Centerno open portssession recording - Question #112Infrastructure Security
A company runs a global ecommerce website that is hosted on AWS. The company uses Amazon CloudFront to serve content to its user base. The company wants to block inbound traffic fr...
CloudFront geo restrictioncountry blockingWAF comparisoncost optimization - Question #113Infrastructure Security
A company hosts its public website on Amazon EC2 instances behind an Application Load Balancer (ALB). The website is experiencing a global DDoS attack by a specific IoT device bran...
AWS WAFstring match ruleuser agent filteringDDoS mitigation - Question #114Incident Response
A company runs an application on a fleet of Amazon EC2 instances. The company can remove instances from the fleet without risk to the application. All EC2 instances use the same se...
GuardDutyEventBridgeLambda automationincident response - Question #115Logging and Monitoring
A security engineer for a company is investigating suspicious traffic on a web application in the AWS Cloud. The web application is protected by an Application Load Balancer (ALB)...
X-Forwarded-For headerWAF logsCloudFrontclient IP identification - Question #116Infrastructure Security
A company's security engineer receives an alert that indicates that an unexpected principal is accessing a company-owned Amazon Simple Queue Service (Amazon SQS) queue. All the com...
VPC interface endpointSQS access controlendpoint policyAWS Organizations - Question #117Incident Response
A healthcare company stores more than 1 million patient records in an Amazon S3 bucket. The patient records include personally identifiable information (PII). The S3 bucket contain...
credential revocationtemporary credentialsdata exfiltrationGuardDuty finding - Question #118Infrastructure Security
A company is expanding its group of stores. On the day that each new store opens, the company wants to launch a customized web application for that store. Each store's application...
AWS Service CatalogCloudFormationdeployment governanceAWS Organizations - Question #119Identity and Access Management (IAM)
A company runs an online game on AWS. When players sign up for the game, their username and password credentials are stored in an Amazon Aurora database. The number of users has gr...
Amazon Cognitoidentity federationthird-party IdPpassword management - Question #120Incident Response
A security engineer needs to prepare a company's Amazon EC2 instances for quarantine during a security incident. The AWS Systems Manager Agent (SSM Agent) has been deployed to all...
EC2 quarantineSystems ManagerSSM Agentincident response - Question #121Incident Response
A company runs workloads in an AWS account. A security engineer observes some unusual findings in Amazon GuardDuty. The security engineer wants to investigate a specific IAM role a...
Amazon DetectiveGuardDutyIAM investigationanomalous behavior - Question #122Logging and Monitoring
A company's web application is hosted on Amazon EC2 instances running behind an Application Load Balancer (ALB) in an Auto Scaling group. An AWS WAF web ACL is associated with the...
WAF loggingAmazon Data Firehoselog preservationS3 logging - Question #123Logging and Monitoring
A company's security team wants to receive email notification from AWS about any abuse reports regarding DoS attacks. A security engineer needs to implement a solution that will pr...
AWS HealthEventBridgeabuse reportsSNS notifications - Question #124Logging and Monitoring
Hotspot Question A security engineer needs to prepare for a security audit of an AWS account. Select the correct AWS resource from the following list to meet each requirement. Sele...
AWS Audit ManagerIAM Access AnalyzerAWS ArtifactCompliance Reporting - Question #125Logging and Monitoring
A company has the following security policy for its Amazon Aurora MySQL databases for a single AWS account: - Database storage must be encrypted at rest. - Deletion protection must...
AWS ConfigAurora MySQLcompliance monitoringmanaged rules - Question #126Incident Response
A company operates an Amazon EC2 instance that is registered as a target of a Network Load Balancer (NLB). The NLB is associated with a security group. The security group allows in...
network ACLNLBSSH access controlincident containment - Question #127Data Protection
A company has an encrypted Amazon Aurora DB cluster in the us-east-1 Region. The DB cluster is encrypted with an AWS Key Management Service (AWS KMS) customer managed key. To meet...
KMS cross-regionAurora snapshotcustomer managed keyencryption - Question #128Infrastructure Security
A company has a large fleet of Amazon Linux 2 Amazon EC2 instances that run an application. The application processes sensitive data and has the following compliance requirements:...
Systems Manager Session ManagerIAM Identity Centerremote accesssession recording - Question #129Infrastructure Security
A company is running a containerized application on an Amazon Elastic Container Service (Amazon ECS) cluster that uses AWS Fargate. The application runs as several ECS services. Th...
CloudFront WAF bypassALB listener rulescustom headerorigin protection - Question #130Infrastructure Security
A security engineer has designed a VPC to segment private traffic from public traffic. The VPC includes two Availability Zones. The security engineer has provisioned each Availabil...
VPC routingNAT gatewayroute tablesprivate subnets - Question #131Incident Response
A security engineer is responding to an incident that is affecting an AWS account. The ID of the account is 123456789012. The attack created workloads that are distributed across m...
KMS key deletionkey policyroot userincident response - Question #132Infrastructure Security
A company is using AWS to run a long-running analysis process on data that is stored in Amazon S3 buckets. The process runs on a fleet of Amazon EC2 instances in an Auto Scaling gr...
S3 gateway endpointdata exfiltrationendpoint policyResourceOrgId - Question #133Data Protection
A company's data scientists want to create artificial intelligence and machine learning (AI/ML) training models by using Amazon SageMaker. The training models will use large datase...
S3 Lifecycledata retentionobject expirationcompliance - Question #134Identity and Access Management (IAM)
A company uses several AWS CloudFormation stacks to handle the deployment of a suite of applications. The leader of the company's application development team notices that the stac...
CloudFormation service roleIAM PassRolestack deploymentleast privilege - Question #135Incident Response
A company needs the ability to identify the root cause of security findings in an AWS account. The company has enabled VPC Flow Logs, Amazon GuardDuty, and AWS CloudTrail. The comp...
Amazon DetectiveIAM investigationGuardDuty findingssecurity visualization - Question #136Logging and Monitoring
A company runs its microservices architecture in Kubernetes containers on AWS by using Amazon Elastic Kubernetes Service (Amazon EKS) and Amazon Aurora. The company has an organiza...
GuardDutyAWS Organizationscentralized monitoringmulti-account - Question #137Logging and Monitoring
A company begins to use AWS WAF after experiencing an increase in traffic to the company's public web applications. A security engineer needs to determine if the increase in traffi...
WAF loggingAmazon Athenapartition projectionlog analysis - Question #138Incident Response
A company runs a web application on a fleet of Amazon EC2 instances that are in an Auto Scaling group. The EC2 instances are in the same VPC subnet as other workloads. A security e...
incident response automationEC2 isolationGuardDutySecurity Hub - Question #139Incident Response
A company's security engineer is designing an isolation procedure for Amazon EC2 instances as part of an incident response plan. The security engineer needs to isolate a target ins...
EC2 isolationnetwork ACLforensicsincident response - Question #140Identity and Access Management (IAM)
A company is expanding its group of stores. On the day that each new store opens, the company wants to launch a customized web application for that store. Each store's application...
AWS Service CatalogCloudFormationAWS Organizationsdeployment governance - Question #141Data Protection
A company needs to follow security best practices to deploy resources from an AWS CloudFormation template. The CloudFormation template must be able to configure sensitive database...
Secrets ManagerCloudFormation dynamic referencesKMScredential management - Question #142Incident Response
A company runs a web application on a fleet of Amazon EC2 instances that are in an Auto Scaling group. The EC2 instances are in the same VPC subnet as other workloads. A security e...
GuardDutyEventBridgeautomated remediationSecurity Hub - Question #143Logging and Monitoring
A company uses an organization in AWS Organizations to manage its 250 member accounts. The company also uses AWS IAM Identity Center with a SAML external identity provider (IdP). I...
CloudTrailIAM Identity Centeraudit logsOrganizations - Question #144Logging and Monitoring
A company has configured an organization in AWS Organizations for its AWS accounts. AWS CloudTrail is enabled in all AWS Regions. A security engineer must implement a solution to p...
CloudTrailSCPOrganizationslog protection - Question #145Logging and Monitoring
A company is developing an application that runs across a combination of Amazon EC2 On- Demand Instances and Spot Instances. A security engineer needs to provide a logging solution...
CloudWatch LogsS3Athenacentralized logging - Question #146Infrastructure Security
A company runs an application on a fleet of Amazon EC2 instances. The application is accessible to users around the world. The company associates an AWS WAF web ACL with an Applica...
WAFrate-based rulesDDoS mitigationALB - Question #147Incident Response
A security engineer for a company needs to design an incident response plan that addresses compromised IAM user account credentials. The company uses an organization in AWS Organiz...
IAM Identity Centercompromised credentialsCloudTrailincident response plan - Question #148Infrastructure Security
A security engineer needs to configure DDoS protection for a Network Load Balancer (NLB) with an Elastic IP address. The security engineer wants to set up an AWS WAF web ACL with a...
WAFrate-based rulesNLBDDoS protection - Question #149Incident Response
A company's security engineer receives an abuse notification from AWS. The notification indicates that someone is hosting malware from the company's AWS account. After investigatio...
GuardDutyaccess key rotationS3 remediationaccount compromise - Question #150Logging and Monitoring
A company has AWS accounts in an organization in AWS Organizations. The organization includes a dedicated security account. All AWS account activity across all member accounts must...
CloudTrailS3 Object LockOrganizationslog retention