Practice SCS-C03 Detection questions with full explanations on every answer.
Start practicing
Detection — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company wants to detect potential brute-force attacks against their public-facing web applications hosted on EC2 instances. Which TWO measures should the security team implement?
2An organization requires centralized monitoring of security findings from multiple AWS accounts. Which service should be used to aggregate these findings into a single dashboard?
3Which AWS service uses machine learning to detect unusual activity, such as unauthorized access to S3 buckets or atypical API calls?
4Refer to the exhibit. The log entry shows a denied 'DeleteTable' attempt. Which service, if configured, would have automatically triggered an alert based on this specific log entry?
5A security engineer needs to detect if any EC2 instances in an account have been launched with a public IP address. Which service should be used to automate this detection?
6A security team needs to identify which IAM users have not used their credentials for more than 90 days. Which service should be used to provide this information?
7A company wants to aggregate security findings from AWS GuardDuty, AWS Inspector, and AWS Macie into a single dashboard for prioritized viewing. Which service should be used to provide this consolidated view of security alerts?
8An organization is running critical workloads on Amazon EKS and wants to detect suspicious activity at the container runtime level, such as unauthorized process execution or unexpected file access. Which GuardDuty feature should be enabled to achieve this level of visibility?
9During an investigation into an EC2 instance compromise, a security analyst needs to understand the relationship between different AWS resources, such as which IAM roles were used and which IP addresses interacted with the instance. Which service should the analyst use to perform this graph-based investigation?
10An organization wants to improve its vulnerability management posture by ensuring that all Amazon EC2 instances are regularly scanned for software vulnerabilities and unintended network exposure. Which TWO features of Amazon Inspector help achieve this?
11A financial institution requires that all CloudTrail logs be stored for seven years for compliance audits. They also need the ability to run complex SQL queries against these logs to identify specific user actions across all regions. What is the most cost-effective and operationally simple solution?
12Which THREE of the following resource types are currently supported by IAM Access Analyzer to identify potential public or cross-account access?
13Refer to the exhibit. This GuardDuty finding indicates that malware was detected on an EC2 instance. What is the process GuardDuty used to perform this scan without installing an agent on the instance?
14A security engineer wants to enable manual remediation of Security Hub findings directly from the AWS console. They want to be able to select a finding and trigger a specific Lambda function to isolate an instance. What is the correct way to configure this?
15A security team needs to perform deep packet inspection (DPI) on traffic entering and leaving a specific EC2 instance to look for complex attack signatures that VPC Flow Logs cannot detect. Which AWS feature should they use to facilitate this?
16A security analyst needs to detect potential exfiltration of sensitive data from an S3 bucket that has public access blocked. Which Amazon GuardDuty feature should be configured to detect anomalous data access patterns by internal IAM users?
17A company wants to detect when an IAM user executes a command from a suspicious IP address. Which tool can analyze historical CloudTrail data to establish a baseline of normal behavior and trigger alerts upon deviations?
18Which TWO actions should be taken to ensure that Amazon GuardDuty has the necessary data to detect unauthorized cryptocurrency mining instances?
19An organization is concerned about detecting potential SQL injection attacks against their web application hosted on Application Load Balancer. Which service provides the best native detection capability?
20A security engineer needs to detect when an EC2 instance is launched with an unapproved Amazon Machine Image (AMI). Which AWS service should be used to automate this detection?
The Detection domain covers the key concepts tested in this area of the SCS-C03 exam blueprint published by Amazon Web Services. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all SCS-C03 domains — no account required.
The Courseiva SCS-C03 question bank contains 20 questions in the Detection domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Detection domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included