20+ practice questions focused on Infrastructure Security — one of the most tested topics on the AWS Certified Security - Specialty exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Infrastructure Security PracticeA security engineer must monitor and record all rejected TCP connection attempts to a fleet of EC2 instances within a private subnet. The logs must be stored in a durable manner for three years to meet regulatory compliance. Which solution meets these requirements with the least operational overhead?
Explanation: VPC Flow Logs must be specifically configured to capture 'REJECT' traffic (or 'ALL' traffic) to meet the requirement. Simply enabling Flow Logs is insufficient if the default 'ACCEPT' setting is used. The explanation should clarify that the log configuration must include the REJECT action.
A company uses an Application Load Balancer (ALB) to route traffic to EC2 instances. A security engineer needs to ensure that only traffic originating from a specific Amazon CloudFront distribution can reach the ALB. What is the most secure way to implement this restriction?
Explanation: AWS supports SigV4 for requests from CloudFront to an Application Load Balancer. By configuring CloudFront to sign requests using AWS Signature Version 4 (SigV4), the ALB can natively authenticate that the traffic originates from the specified CloudFront distribution, without requiring custom header management or reliance on frequently changing IP ranges. While custom headers (Option C) were historically common, SigV4 is the most secure and modern native method for ALB origins.
A financial services company is concerned about large-scale DDoS attacks affecting its public-facing DNS and web applications. Which TWO AWS services or features provide automatic protection or mitigation against Layer 3, Layer 4, and Layer 7 DDoS attacks? (Select TWO.)
Explanation: AWS Shield Advanced provides managed protection for L3/L4 and L7 attacks. AWS WAF is specifically designed for L7 (application layer) protection. While they are often used together, AWS WAF does not provide L3/L4 protection. The question asks for services that provide protection against L3, L4, AND L7. Shield Advanced covers all three, while WAF covers L7. The combination is the correct answer, but the explanation should clarify that WAF is specifically for L7.
A security engineer is tasked with restricting access to Amazon S3 and Amazon DynamoDB so that traffic never leaves the AWS private network. Which TWO types of VPC endpoints should be used to achieve this for these specific services? (Select TWO.)
Explanation: While Gateway endpoints are the traditional and cost-effective way to access S3 and DynamoDB, both services now support Interface endpoints (AWS PrivateLink). The explanation incorrectly states that DynamoDB only supports Gateway endpoints, which is false. Furthermore, the stem asks for the two types of endpoints that ensure traffic never leaves the AWS private network; while both types achieve this, Gateway endpoints are the standard architectural recommendation for these specific services to avoid NAT Gateway costs.
A security engineer wants to ensure that all EC2 instances are launched only with approved, encrypted AMIs and that any instance with an unencrypted volume is automatically flagged. Which service is best suited for this continuous compliance monitoring?
Explanation: AWS Config is the correct service for continuous compliance. The explanation should explicitly mention that AWS Config can evaluate EC2 instance configurations against custom or managed rules to verify that the AMI ID matches an approved list and that EBS volumes are encrypted.
+15 more Infrastructure Security questions available
Practice all Infrastructure Security questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Infrastructure Security. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Infrastructure Security questions on the SCS-C03 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Infrastructure Security is tested as part of the AWS Certified Security - Specialty blueprint. Practicing with targeted Infrastructure Security questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free SCS-C03 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Infrastructure Security is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Infrastructure Security practice session with instant scoring and detailed explanations.
Start Infrastructure Security Practice →