AWS Certified Security - Specialty Free Sample Questions

20 free sample questions223 in the full practice test Other versions: SCS-C03(275),SCS-C02(71)

Try simulator

SCS-C01 Sample Questions

  1. Question 1

    Multiple answers

    Developers in an organization have moved from a standard application deployment to containers. The Security Engineer is tasked with ensuring that containers are secure.

    Which strategies will reduce the attack surface and enhance the security of the containers? (Choose two.)

    Answer and explanation

    Correct answers: B, D

    B, D

  2. Question 2

    During a recent internal investigation, it was discovered that all API logging was disabled in a production account, and the root user had created new API keys that appear to have been used several times.
    What could have been done to detect and automatically remediate the incident?

    Answer and explanation

    Correct answer: C

    C

  3. Question 3

    Multiple answers

    A Security Administrator has a website hosted in Amazon S3. The Administrator has been given the following requirements:

    . Users may access the website by using an Amazon CloudFront distribution.
    . Users may not access the website directly by using an Amazon S3 URL.

    Which configurations will support these requirements? (Choose two.)

    Answer and explanation

    Correct answers: A, C

    A, C

  4. Question 4

    Multiple answers

    A company has a forensic logging use case whereby several hundred applications running on Docker on EC2 need to send logs to a central location. The Security Engineer must create a logging solution that is able to perform real-time analytics on the log files, grants the ability to replay events, and persists data.

    Which AWS Services, together, can satisfy this use case? (Choose two.)

    Answer and explanation

    Correct answers: B, D

    B, D

  5. Question 5

    A Security Engineer is implementing a solution to allow users to seamlessly encrypt Amazon S3 objects without having to touch the keys directly. The solution must be highly scalable without requiring continual management. Additionally, the organization must be able to immediately delete the encryption keys.

    Which solution meets these requirements?

    Answer and explanation

    Correct answer: B

    B

  6. Question 6

    A Security Engineer accidentally deleted the imported key material in an AWS KMS CMK.

    What should the Security Engineer do to restore the deleted key material?

    Answer and explanation

    Correct answer: B

  7. Question 7

    A Security Engineer discovers that developers have been adding rules to security groups that allow SSH and RDP traffic from 0.0.0.0/0 instead of the organization firewall IP.

    What is the most efficient way to remediate the risk of this activity?

    Answer and explanation

    Correct answer: B

    B

  8. Question 8

    Auditors for a health care company have mandated that all data volumes be encrypted at rest. Infrastructure is deployed mainly via AWS CloudFormation; however, third-party frameworks and manual deployment are required on some legacy systems.

    What is the BEST way to monitor, on a recurring basis, whether all EBS volumes are encrypted?

    Answer and explanation

    Correct answer: B

    Explanation:
    Using AWS Config Rules, you can run continuous assessment checks on your resources to verify that they comply with your own security policies, industry best practices, and compliance regimes such as PCI/HIPAA. For example, AWS Config provides a managed AWS Config Rules to ensure that encryption is turned on for all EBS volumes in your account. You can also write a custom AWS Config Rule to essentially “codify” your own corporate security policies. AWS Config alerts you in real time when a resource is misconfigured, or when a resource violates a particular security policy. -- Reference:
    https://d1.awsstatic.com/whitepapers/aws-security-whitepaper.pdf

  9. Question 9

    Multiple answers

    A company plans to move most of its IT infrastructure to AWS. The company wants to leverage its existing on-premises Active Directory as an identity provider for AWS.

    Which steps should be taken to authenticate to AWS services using the company’s on-premises Active Directory? (Choose three.)

    Answer and explanation

    Correct answers: A, C, E

  10. Question 10

    A company wants to deploy a distributed web application on a fleet of EC2 instances. The fleet will be fronted by a Classic Load Balancer that will be configured to terminate the TLS connection. The company wants to make sure that all past and current TLS traffic to the Classic Load Balancer stays secure, even if the certificate private key is leaked.

    To ensure the company meets these requirements, a Security Engineer can configure a Classic Load Balancer with:

    Answer and explanation

    Correct answer: B

    B

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 569 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon