20+ practice questions focused on Detection — one of the most tested topics on the AWS Certified Security - Specialty exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Detection PracticeA security engineer needs to detect unauthorized API calls originating from an EC2 instance that has an attached IAM role. Which service provides the most granular visibility into the identity and the specific API actions performed?
Explanation: While CloudTrail is the correct service, the explanation should explicitly mention that CloudTrail captures API calls made by the IAM role attached to the EC2 instance. It should also clarify that 'Data events' are specifically required to capture certain API actions (like S3 object-level operations) that are not included in management events.
Refer to the exhibit. A security engineer discovers that an IAM user is successfully accessing data in the 'sensitive-data' bucket despite no explicit Allow rule in their IAM policy for that bucket. Which detective control can identify the source of this permission?
Explanation: IAM Access Analyzer is a tool used to analyze resource-based policies to identify if they grant access to external entities (preventative/analysis). CloudTrail is the primary detective control used to identify the source of an action and the specific credentials/policies used to authorize it. If a user is accessing a bucket without an explicit IAM policy, the permission is likely granted via a resource-based policy (bucket policy) or an inherited SCP. CloudTrail logs the 'eventSource' and 'userIdentity', which allows the engineer to trace the authorization path.
A company is concerned about sensitive data being accidentally exposed via S3 buckets. Which THREE actions should the security team take to improve detection of such risks?
Explanation: The explanation incorrectly describes S3 Block Public Access as a detection mechanism. S3 Block Public Access is a preventative control, not a detection mechanism. The correct options (A, C, D) focus on discovery, monitoring, and logging, which are detection-oriented.
A security auditor needs to track all configuration changes made to VPC Security Groups over the last year. Which service provides a comprehensive, historical audit trail of these changes?
Explanation: While AWS Config is the correct answer for tracking configuration history and state changes, CloudTrail is the service that records the 'who' (the API caller). AWS Config relies on CloudTrail to provide the identity information for configuration changes. The explanation should clarify that Config provides the resource state history, while CloudTrail provides the event history.
A company wants to detect potential insider threats involving unauthorized data access to S3. They already have CloudTrail enabled. What is the next logical step to enhance detection?
Explanation: Amazon GuardDuty S3 Protection analyzes CloudTrail data events and S3 data plane logs (such as GetObject, ListObjects, and DeleteObject) using machine learning and threat intelligence to detect suspicious behavior, such as unusual data access patterns indicative of an insider threat or compromised credentials. GuardDuty acts as the automated threat detection layer built on top of existing CloudTrail logs.
+15 more Detection questions available
Practice all Detection questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Detection. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Detection questions on the SCS-C03 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Detection is tested as part of the AWS Certified Security - Specialty blueprint. Practicing with targeted Detection questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free SCS-C03 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Detection is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Detection practice session with instant scoring and detailed explanations.
Start Detection Practice →