AWS Certified Security - Speciality Free Sample Questions

Create a free account to browse all 17 sample questions. The full practice test includes 275 questions. Use the simulator for timed and flashcard mode. Or, view more alternate versions SCS-C01 223 Questions SCS-C02 71 Questions.

Try Simulator

SCS-C03 Sample Questions

  1. Question 1

    Q1

    A financial institution is implementing a centralized logging architecture to comply with strict regulatory requirements. They need to aggregate security logs from Amazon GuardDuty, AWS Security Hub, and Amazon Route 53 Resolver DNS Firewall across 50 AWS accounts into a central security account. The solution must support the Open Cybersecurity Schema Framework (OCSF) to facilitate integration with a third-party SIEM. The security team prioritizes a solution that minimizes custom transformation logic and operational overhead.

    Which solution should the security architect implement?

    Show answer & explanation

    Correct answer: A

    Amazon Security Lake automatically centralizes security data from AWS environments, SaaS providers, and on-premises sources into a purpose-built data lake stored in your account. It automatically converts incoming log data to the Open Cybersecurity Schema Framework (OCSF) standard, which meets the requirement for minimized transformation logic and SIEM integration.

  2. Question 2

    Q2

    A security engineer is troubleshooting a new Amazon GuardDuty deployment in an Amazon EKS environment. The engineer has enabled GuardDuty EKS Protection, but the security team is not receiving findings related to suspicious process executions within the Kubernetes pods. The Audit logs are being correctly ingested.

    What is the most likely cause of this issue?

    Show answer & explanation

    Correct answer: A

    GuardDuty EKS Protection consists of two parts: Audit Log Monitoring (control plane) and Runtime Monitoring (data plane). Suspicious process executions inside a pod are detected by the Runtime Monitoring agent. If only Audit logs are working, the Runtime Monitoring component is likely missing or disabled.

  3. Question 3

    Q3

    A healthcare organization uses Amazon Macie to detect sensitive patient data in Amazon S3. The organization has specific medical record numbers (MRN) that follow a proprietary format (e.g., HOSP-12345-X). The default managed data identifiers in Macie are not detecting these specific patterns.

    Which action should the security administrator take to ensure these MRNs are discovered?

    Show answer & explanation

    Correct answer: A

    Macie allows users to define custom data identifiers using regular expressions (regex) to detect proprietary or organization-specific data formats that are not covered by the default managed identifiers.

  4. Question 4

    Q4

    A large e-commerce platform wants to monitor high-cardinality security data in real-time. They need to identify the top 10 IP addresses being blocked by AWS WAF across 200 web applications. The solution must provide a visual ranking that updates dynamically without requiring complex log parsing infrastructure.

    Which solution meets these requirements?

    Show answer & explanation

    Correct answer: A

    CloudWatch Contributor Insights is designed specifically for analyzing high-cardinality data, such as identifying 'top-N' contributors (e.g., top blocked IPs) from log data in real-time with built-in visualization.

  5. Question 5

    Q5Multiple answers

    A security team is designing a centralized log ingestion pipeline. They need to collect logs from multiple sources and forward them to a third-party Splunk endpoint. The solution must support buffering, transformation of log data, and automatic retries. Which TWO services should be combined to build this architecture? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

    Kinesis Data Firehose provides buffering, transformation (via Lambda), and direct delivery to third-party destinations like Splunk with retry capabilities.

    Subscription filters are the mechanism to extract logs from CloudWatch and push them to Kinesis Data Firehose.

  6. Question 6

    Q6

    A company requires real-time detection of specific security group changes that open port 22 to the world (0.0.0.0/0). The detection must trigger a remediation Lambda function within seconds. The security team is debating between using AWS Config Rules and Amazon EventBridge rules.

    Which approach provides the fastest reaction time for this specific requirement?

    Show answer & explanation

    Correct answer: A

    EventBridge allows for near real-time reaction to API calls as they happen. AWS Config rules have a recording delay (latency) before evaluation occurs, making EventBridge the faster option for immediate remediation.

  7. Question 7

    Q7

    A developer has deployed a serverless application using AWS Lambda functions. The security team wants to automatically detect software vulnerabilities in the application code and the Lambda function layers. Which AWS service should be enabled to perform these scans automatically?

    Show answer & explanation

    Correct answer: A

    Amazon Inspector supports scanning AWS Lambda functions and layers for software vulnerabilities and network exposure.

  8. Question 8

    Q8

    A security analyst needs to configure VPC Flow Logs to capture specific TCP flag information to diagnose a potential TCP SYN flood attack. The standard flow log format does not include this detail. The analyst creates a custom format.

    Which field must be included in the custom format string to see the TCP flags?

    Show answer & explanation

    Correct answer: A

    The tcp-flags field in VPC Flow Logs custom format records the bitmask value for the TCP flags observed in the traffic.

Register free to unlock 9 more sample questions

Create a free account to continue with the rest of the SCS-C03 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 569 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon