Amazon Web Services · Free Practice Questions · Last reviewed May 2026
36real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
14% of exam · 6 sample questions below
A security engineer is configuring an AWS environment to detect and respond to potential security threats. Which AWS service can be used to automate the remediation of unwanted access to Amazon S3 buckets by invoking AWS Lambda functions?
AWS Config
Amazon GuardDuty
Amazon GuardDuty is a threat detection service that continuously analyzes AWS CloudTrail management and data events, VPC Flow Logs, and DNS logs using machine learning and integrated threat intelligence. It specifically detects suspicious S3 access patterns, such as unusual geographical locations, high-volume downloads, or bucket enumeration, and raises findings that can be sent to Amazon EventBridge. This enables automated remediation, for example a Lambda function that revokes IAM policies or applies a bucket policy, making it the correct choice for detecting and automating response to access threats.
Amazon Inspector
AWS WAF
A security team suspects that an attacker has compromised an EC2 instance and is using it to launch outbound DDoS attacks. The team needs to quickly isolate the instance while preserving forensic data. Which combination of actions should the team take? (Choose TWO.)
Apply a restrictive security group that blocks all outbound traffic.
Applying a restrictive security group that blocks all outbound traffic is the right containment step because security groups act as a stateful instance-level firewall. This prevents the compromised EC2 instance from establishing new outbound connections to a command-and-control server or performing data exfiltration, while leaving the instance running so forensic artifacts like memory and processes can be collected. Inbound rules can still permit limited SSH access from approved forensic workstations, allowing incident responders to investigate without fully disconnecting the instance.
Modify the network ACL for the subnet to deny all outbound traffic.
Create a snapshot of the EBS volumes attached to the EC2 instance.
Creating a snapshot of the EBS volumes attached to the instance is a vital preservation step because snapshots capture a point-in-time, block-level copy of the disk without stopping or interrupting the instance. The snapshot can be mounted and analyzed on a separate forensic instance, allowing investigators to inspect files, malware, and logs without risking the original evidence. Even if the instance is later terminated or reconstructed, the snapshot preserves the exact state of the volumes for legal or investigative purposes.
Detach the instance from the Auto Scaling group.
Terminate the EC2 instance immediately.
A company uses AWS Organizations with multiple accounts. The security team wants to ensure that all API calls in the organization are logged and retained for at least one year. Which AWS services or features should be used to meet these requirements? (Choose TWO.)
Amazon GuardDuty with threat detection enabled.
AWS Config with recording enabled for all resources.
Amazon S3 lifecycle policy to transition logs to S3 Glacier after one year.
An S3 lifecycle policy can transition delivered log objects from frequently accessed storage classes to S3 Glacier after one year, preserving the logs for long-term audit needs while reducing cost. This is a correct component for the retention half of the requirement, provided that a delivery mechanism such as an organization CloudTrail trail first places the logs into the S3 bucket. It does not record any API activity by itself, so it is complementary to CloudTrail rather than a replacement.
VPC Flow Logs for all VPCs.
AWS CloudTrail with organization trail.
An organization trail in AWS CloudTrail records management events—API calls made via the AWS Console, SDKs, CLI, and infrastructure-as-code tools—for all current and future accounts in the AWS Organization, delivering the logs to a centralized S3 bucket. It captures the identity, event time, source IP, user agent, and request/response details, making it the definitive service for cross-account API auditing. This is correct for the API-activity requirement and can be paired with lifecycle policies for long-term, low-cost retention.
A security engineer reviews the CloudTrail log entry in the exhibit. The engineer notices that an EC2 instance was launched using an AdminRole. Which additional information would help determine if this is a legitimate action or a potential compromise?
The AMI ID ami-0abcdef1234567890 is not a standard Amazon-provided AMI.
The source IP address 203.0.113.50 is from an unexpected geographic location not associated with the company.
The source IP address 203.0.113.50 is recorded in the CloudTrail event as sourceIPAddress, and it originates from a geographic region outside the company's known operating footprint. Anomalous source IPs are a well-known indicator of compromised credentials or unauthorized access, especially when combined with API calls that create resources. This is the only option that represents an actual observable anomaly in the log entry itself, making it the strongest sign of suspicious activity.
The instance type m5.xlarge is unusually large compared to previous launches.
The security group sg-0123456789abcdef0 allows inbound SSH from 0.0.0.0/0.
A security engineer is analyzing the VPC Flow Logs entry in the exhibit. The log shows traffic from an internal IP to an external IP. Which potential security concern should the engineer investigate?
The instance is participating in a DDoS attack against the external IP.
An EC2 instance is attempting to connect to an external host on port 3389 (RDP).
Outbound RDP from an internal EC2 instance to an external host on port 3389 is inherently suspicious because RDP is a remote administration protocol and is not a normal outbound service. This direction of traffic can indicate a compromised instance serving as a pivot, data exfiltration, or an attacker maintaining persistent control. The flow log shows source 10.0.1.5 (private) to destination 203.0.113.50 on port 3389, so the correct interpretation is that the instance is attempting an outbound RDP connection.
An external host is scanning the internal network on port 443.
The security group allows inbound RDP from 0.0.0.0/0.
A company has a security rule that all S3 buckets must have server access logging enabled. A security engineer uses AWS Config to evaluate compliance. The engineer configures a managed rule but notices that the rule does not evaluate all buckets. What is the most likely reason?
The rule only evaluates buckets in the us-east-1 region.
The rule only evaluates buckets that have a specific tag.
The AWS Config managed rule `s3-bucket-server-access-logging-enabled` can be configured with a `tag` parameter. When a tag is specified, the rule only evaluates S3 buckets that have that exact tag. If the engineer did not apply the required tag to all buckets, or if the rule was configured with a tag that does not match all buckets, some buckets will be excluded.
The rule excludes buckets that have a bucket policy denying access to AWS Config.
The rule requires the logging target bucket to be in the same account.
Want more Threat Detection and Incident Response practice?
Practice this domain16% of exam · 6 sample questions below
A developer needs to grant an IAM user read-only access to an S3 bucket named 'my-bucket'. Which policy should be attached to the IAM user?
{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:ListBucket","Resource":"arn:aws:s3:::my-bucket"}]}
{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:*","Resource":"*"}]}
{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:PutObject","Resource":"arn:aws:s3:::my-bucket/*"}]}
{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:GetObject","Resource":"arn:aws:s3:::my-bucket/*"}]}
This policy exactly implements read-only object access by allowing the s3:GetObject action on the objects within the bucket. The resource ARN arn:aws:s3:::my-bucket/* correctly scopes the action to object keys under my-bucket, rather than the bucket itself or all buckets. This grants the user the ability to retrieve object data and metadata while denying writes, deletions, or bucket-level administrative changes.
A security engineer notices that an IAM role has a trust policy allowing any AWS account to assume it. Which attack is this misconfiguration most likely to enable?
Logging bypass via CloudTrail
Cross-service confused deputy attack
Unauthorized access by an external attacker
This is correct: an overly broad trust policy—for example `"Principal": "*"` without restrictive conditions—allows any AWS principal from any account to call `sts:AssumeRole` and obtain the role's temporary security credentials. Once assumed, the attacker receives all permissions attached to the role, enabling unauthorized actions in the account. In the absence of conditions like `aws:PrincipalArn`, `aws:PrincipalAccount`, or an external ID, there is no mechanism to distinguish legitimate principals from external attackers, so the role effectively exposes its permissions to the entire AWS ecosystem.
Privilege escalation by attaching additional policies
A company wants to allow users from its corporate Active Directory to access AWS resources. The company has set up an IAM identity provider for SAML. What must be created in IAM to map users to permissions?
An IAM role with a trust policy for the SAML provider
For SAML federation, the correct pattern is an IAM role with a trust policy that grants sts:AssumeRoleWithSAML to the SAML identity provider you create in IAM. The corporate Active Directory is the external IdP (for example, AD FS or Shibboleth), and the trust policy uses the IAM SAML provider's ARN as the principal, often with an audience condition of urn:amazon:webservices. When a user authenticates to AD, the IdP issues a SAML assertion, AWS validates it against the SAML provider, and the user receives temporary credentials scoped by that role's permissions. This achieves single sign-on without creating or maintaining AWS credentials for each AD user.
An OIDC identity provider
An IAM user for each Active Directory user
A federation role type
An IAM policy has the following statement: {"Effect":"Deny","Action":"*","Resource":"*","Condition":{"Bool":{"aws:SecureTransport":"false"}}}. What does this policy achieve?
Denies all actions that are not made over HTTPS
This IAM policy statement uses a Deny effect with the aws:SecureTransport condition key set to 'false', so it blocks any API call that was not transmitted over a TLS/HTTPS connection. Because an explicit Deny takes precedence over all Allow statements, the policy stops every non-HTTPS request to any AWS service, while leaving HTTPS requests unaffected. The condition applies to the transport-layer security of the request itself, not to the specific action or resource, making the statement a global enforcement of HTTPS for all AWS API operations.
Allows all actions only when using HTTPS
Enforces HTTPS for S3 bucket policies only
Blocks all actions for a specific AWS service
A solutions architect needs to design a system where an EC2 instance can write logs to CloudWatch Logs. Which IAM entity should be used to grant permissions to the EC2 instance?
A resource-based policy on the EC2 instance
An IAM role with an instance profile
An IAM role with an instance profile is the correct approach because it provides temporary credentials to the EC2 instance through the instance metadata service (IMDSv2). The EC2 service assumes the role on behalf of the instance, and the credentials are automatically rotated and never stored as static secrets on disk. This follows the AWS security best practice of using temporary credentials for all applications running on EC2.
An IAM user with access keys stored on the instance
An IAM group
A security administrator discovers that an IAM user has been deleted accidentally. What is the correct way to restore the user's access?
Contact AWS Support to undo the deletion
Use the AWS IAM console to undelete the user
Restore the user from a backup of IAM
Create a new IAM user with the same name and attach the same policies
The only viable recovery is to create a new IAM user with the same name and reattach the same managed or inline policies, group memberships, and permissions boundaries, because the deleted user object is permanently irrecoverable. Be aware that the new user receives a different internal unique ID and you must reset the console password and generate new access keys, since all prior credentials—including the old secret access key—were destroyed at deletion and cannot be recovered.
Want more Identity and Access Management practice?
Practice this domain18% of exam · 6 sample questions below
A security engineer wants to capture all DNS queries made by EC2 instances to detect potential data exfiltration. Which AWS service should be used to log the DNS requests?
Use Route 53 Resolver DNS Firewall with query logging
Route 53 Resolver DNS Firewall query logging captures every DNS query that instances resolve through the Amazon-provided VPC resolver, publishing records to CloudWatch Logs, S3, or Kinesis Data Firehose. This satisfies the requirement to log all EC2 DNS requests for exfiltration detection, since instances use that resolver by default.
Use Amazon GuardDuty
Enable VPC Flow Logs
Enable AWS CloudTrail
A company uses AWS CloudTrail to log management events in all regions. The security team notices that some API calls made by an IAM user are not appearing in the CloudTrail event history. What is the most likely reason?
The user used the AWS Management Console, not the CLI
The trail is configured for a single region only
The API calls were read-only and excluded by default
CloudTrail event history only retains events for 90 days; older events are not visible
CloudTrail event history is a built-in feature that provides a view of the last 90 days of account activity, and this retention period is not configurable. Once an event is older than 90 days, it is no longer visible in event history, and the only way to retain it is to configure a trail that delivers CloudTrail log files to Amazon S3 (and optionally CloudWatch Logs) with a suitable lifecycle policy. This 90-day limit applies uniformly to all management events, regardless of the client, region scope, or whether the calls are read-only or write-only.
A company requires real-time analysis of AWS CloudTrail logs to detect unauthorized API calls. The logs are stored in Amazon S3. Which architecture minimizes latency and cost?
Use AWS Glue to crawl S3 and load into Amazon Redshift for analysis
Send CloudTrail logs to Amazon CloudWatch Logs, then use a subscription filter to Amazon Kinesis Data Firehose delivering to Amazon OpenSearch Service
CloudTrail can be configured to deliver events to Amazon CloudWatch Logs within minutes, and a subscription filter can immediately forward matching events to Amazon Kinesis Data Firehose. Firehose then buffers and delivers a continuous stream to Amazon OpenSearch Service, which indexes documents as they arrive for near-real-time search and visualization with OpenSearch Dashboards/Kibana. This managed pipeline gives the low-latency ingestion and querying the requirement asks for.
Query CloudTrail logs directly using Amazon Athena
Configure S3 event notifications to invoke an AWS Lambda function that writes to Amazon OpenSearch Service
A security engineer needs to be alerted when an IAM user attempts to modify an S3 bucket policy. Which method is the MOST efficient?
Enable VPC Flow Logs and analyze for S3 API traffic
Configure an AWS Config rule to detect changes and invoke a Lambda function
Create an Amazon CloudWatch Events rule that matches the PutBucketPolicy API call and triggers an SNS notification
Create an Amazon CloudWatch Events (now Amazon EventBridge) rule with an event pattern matching the `detail-type` of `AWS API Call via CloudTrail`, the `eventSource` as `s3.amazonaws.com`, and `eventName` as `PutBucketPolicy`. When CloudTrail logs that IAM API call, the rule triggers an SNS topic to notify the security engineer in near real time. This is the native AWS approach for reacting to control-plane actions.
Enable S3 server access logs and parse them for PutBucketPolicy entries
A company stores sensitive data in Amazon S3 and wants to detect and alert on any public read access to objects. Which combination of services provides the most comprehensive solution?
Enable VPC Flow Logs and analyze for S3 traffic
Use AWS Config rules to check for public bucket policies and alert via SNS
Enable S3 server access logging and use Amazon Athena to query logs, with CloudWatch Events to alert on specific patterns
S3 server access logging produces detailed log records containing the requester, bucket name, object key, action string (e.g., REST.GET.OBJECT), and response status for each API call. Querying these logs with Amazon Athena lets you filter for the 'Anonymous' requester and identify specific objects being read publicly. A scheduled Athena query orchestrated via CloudWatch Events (now Amazon EventBridge) can publish findings to SNS or Lambda, enabling alerting on suspicious read patterns.
Enable S3 event notifications for all object-level events and send to Amazon SNS
A security engineer needs to centrally collect and analyze AWS CloudTrail logs from multiple accounts. Which service is designed for this purpose?
Configure each account to send logs to a central S3 bucket
Enable Amazon GuardDuty in each account and aggregate findings
Use Amazon CloudWatch Logs to stream logs from each account to a central account
Use AWS Organizations to create a CloudTrail trail that applies to all accounts
Using AWS Organizations, you can create an organization trail from the management account that automatically logs CloudTrail management events for every account in the organization, including future accounts, with no per-account configuration. The trail delivers log files to a single designated S3 bucket in the management account, enabling centralized collection and analysis through Athena, QuickSight, or other tools. This is the native, designed method for centralizing CloudTrail logs across multiple accounts.
Want more Security Logging and Monitoring practice?
Practice this domain14% of exam · 6 sample questions below
A security engineer needs to grant cross-account read access to an S3 bucket in Account A to a user in Account B. What is the correct combination of actions?
Attach an IAM policy to the user in Account B allowing the action; no bucket policy needed
Apply a bucket policy in Account A granting access to the user in Account B; no user policy needed
Use S3 bucket ACLs to grant READ access to the Account B user
Apply a bucket policy in Account A granting access to the principal in Account B, and attach an IAM policy to the user in Account B allowing the action
This is the correct and complete solution. For cross-account S3 access, AWS requires that both the resource-based policy (bucket policy) in Account A and the identity-based policy (IAM policy) attached to the user in Account B explicitly allow the s3:GetObject action. The bucket policy grants the Account B principal access to the bucket, while the IAM policy provisions that principal with the necessary action permissions in its own account. Without either side, the request is denied. This dual-policy requirement ensures both the resource owner and the caller's account are aligned.
A company uses AWS Config to evaluate resource compliance. The security team notices that the AWS::IAM::Group resource type is not supported by AWS Config managed rules. What is the best way to detect IAM groups that have an inline policy allowing 'iam:CreateUser'?
Create a custom AWS Config rule using a Lambda function that evaluates IAM groups
AWS Config does not natively record IAM groups, so a Lambda-backed custom rule is required. The Lambda function can call the IAM API to retrieve a group's policies and evaluate them against your compliance logic, then report compliance via PutEvaluations. This approach gives you full flexibility to assess inline and attached managed policies for groups, which no managed Config rule can do.
Use IAM Access Analyzer to identify policies that grant broad access
Use AWS CloudTrail Insights to detect CreateUser events
Enable AWS Config advanced query and run a query on IAM groups
A company wants to use AWS CloudTrail to log all API activity across multiple accounts in AWS Organizations. Which configuration meets the requirement of centralized logging with minimal operational overhead?
Create a CloudTrail trail in each account and aggregate logs to a common S3 bucket
Enable CloudTrail in each account and use cross-account roles to centralize logs
Use AWS Config to record API calls and send to CloudWatch Logs
Create an organization trail in the management account that applies to all accounts
When you create a CloudTrail trail in the management account with the 'Apply trail to my organization' option enabled, CloudTrail automatically creates and configures trails in every member account, delivering all management events to a single S3 bucket. The trail is managed centrally by the organization management account, and any new accounts that join the organization are automatically included without additional manual setup. This provides the lowest operational overhead and ensures comprehensive, centralized logging of API activity across the entire AWS organization, which is exactly what the requirement demands.
A security team needs to audit all changes to IAM policies in their AWS account. Which AWS service should they use to record policy changes?
Amazon Inspector
AWS CloudTrail
AWS CloudTrail is the correct service because it provides a continuous, immutable audit log of every API call made in your AWS account, including the IAM actions that modify policies such as PutRolePolicy, AttachUserPolicy, and DeletePolicy. Each event captures the identity of the caller, the source IP, the time, and the request parameters, making it the definitive source for security audits of IAM changes. CloudTrail's event history is viewable for 90 days, and you can extend retention with a trail that delivers events to an S3 bucket or CloudWatch Logs for long-term compliance.
Amazon GuardDuty
AWS Config
A company uses AWS Organizations with SCPs. The security team wants to ensure that no IAM user can be created without MFA. Which SCP should be applied at the root OU?
Deny iam:CreateUser unconditionally
Use an IAM policy to require MFA for API calls
Deny iam:CreateUser unless the request includes a condition for MFA
This SCP denies iam:CreateUser when the aws:MultiFactorAuthPresent condition key evaluates to false, effectively allowing the action only for callers who authenticated with MFA. Because SCPs apply to all principals in an AWS organization, this check is enforced regardless of the permissions granted by an individual IAM policy. The Deny statement with a Bool condition is the precise, organizational-level mechanism that prevents creation of users without an MFA requirement.
Attach an IAM policy to all users requiring MFA
A security engineer needs to ensure that all EC2 instances launched in a development account are tagged with a cost center. What is the most effective way to enforce this?
Use AWS Config to detect untagged instances and send alerts
Use AWS Systems Manager to tag instances after launch
Create a tag policy in AWS Organizations requiring the cost center tag
Use an IAM policy that denies ec2:RunInstances unless the request includes the cost center tag
An IAM policy can explicitly deny ec2:RunInstances when a condition key such as ec2:RequestTag/cost-center is absent from the API request—for example, by using a Null condition set to true. Because IAM policies are evaluated before the API call is executed, any launch attempt that omits the cost-center tag is immediately rejected, before any instance is created. This is a true preventive control and is the only listed option that stops the launch itself.
Want more Management and Security Governance practice?
Practice this domain20% of exam · 6 sample questions below
A security engineer is troubleshooting connectivity issues between an Amazon EC2 instance in a VPC and an on-premises server over a Direct Connect virtual interface. The EC2 instance has a security group that allows outbound traffic to the on-premises CIDR block (10.0.0.0/16). The VPC has a route table entry pointing the on-premises CIDR to the virtual private gateway. The on-premises firewall shows that packets are received from the EC2 instance but responses are not reaching the instance. What is the most likely cause?
The on-premises router does not have a route pointing the VPC CIDR back to the Direct Connect interface.
The VPC has a route for the on-premises CIDR pointing to the virtual private gateway, so outbound packets traverse the Direct Connect virtual interface. However, for successful two-way communication, the on-premises router must have a route for the VPC CIDR that points back to the same Direct Connect interface. Because this return route is missing, response packets are either sent to a default route or dropped, so hosts in the VPC see no replies. This is a classic asymmetric routing failure.
The network ACL for the subnet is blocking outbound traffic to the on-premises CIDR.
The virtual private gateway is not attached to the VPC.
The security group does not allow inbound traffic from the on-premises server.
A company uses AWS Organizations with multiple accounts. The security team wants to enforce that all Amazon S3 buckets across the organization have server-side encryption (SSE-S3 or SSE-KMS) enabled. Which approach should be used to enforce this policy?
Create an S3 bucket policy in each account to deny access to unencrypted buckets.
Use AWS Config rules to detect buckets without encryption and send alerts.
Create an IAM role in each account that requires encryption when creating buckets.
Create a service control policy (SCP) that denies s3:CreateBucket if the bucket does not have encryption enabled.
An SCP in AWS Organizations can apply a deny to s3:CreateBucket for every principal in the organization by using the condition key s3:x-amz-server-side-encryption to require an encryption header such as AES256 or aws:kms. Because service control policies are evaluated before any IAM policy and apply across the root, OU, or account level, they act as a centrally managed preventive control that blocks the creation of unencrypted buckets in all member accounts. With the correct condition, any request that omits or misconfigures the encryption parameter will be denied, meeting the company's objective.
A company is migrating a legacy application to AWS. The application requires two-way communication between the web servers and the database servers using TCP port 3306. The security team wants to follow the principle of least privilege. Which TWO actions should be taken to secure the traffic?
Create a security group for the web servers that allows outbound traffic on port 3306 to the database security group.
This is correct because security groups are stateful: when the web server initiates a TCP connection to the database on port 3306, the corresponding return traffic is automatically allowed back into the web server without an explicit inbound rule. By setting the destination to the database security group ID rather than an IP range, the rule dynamically applies to every instance currently associated with that security group, which simplifies management if the database fleet scales or changes. This outbound rule scopes traffic to the specific database tier and avoids opening port 3306 to the whole VPC.
Create a security group for the database servers that allows inbound traffic on port 3306 from the web subnet CIDR.
Place the database servers in a public subnet for easier connectivity.
Configure the network ACL for the database subnet to allow inbound traffic on port 3306 from the web subnet CIDR.
Create a security group for the database servers that allows inbound traffic on port 3306 from the web security group ID.
This is the correct security group design: by specifying the web security group’s ID as the source for inbound port 3306, only instances that are members of that web security group can initiate connections to the database servers. The rule is dynamic—if new web servers are launched and added to that security group, they are instantly allowed, and if an instance is removed, its access is revoked automatically. Because security groups are stateful, the response traffic from the database back to the web server is automatically permitted, so no separate outbound rule is needed on the database security group.
A security engineer is reviewing the SQS queue policy shown in the exhibit. The queue is subscribed to an SNS topic in the same account. The security team has a requirement that only the SNS topic should be allowed to send messages to the queue. What is the issue with this policy?
The second statement allows any principal in the 10.0.0.0/8 range to receive messages from the queue.
The second statement grants ReceiveMessage to Principal '*' but limits the request to the 10.0.0.0/8 network via aws:SourceIp. That condition only restricts the caller's IP address; it does not restrict which IAM principal or account can call, so any authenticated principal originating from that CIDR may receive messages. Production should scope the principal to a specific account or IAM role, or add aws:SourceArn if the intent is to allow only a single source service.
The policy does not specify a principal, so it will not work.
The aws:SourceArn condition uses ArnLike which is deprecated.
The aws:SourceIp condition cannot be used with SQS queue policies.
A financial services company runs a critical application on Amazon EC2 instances in a VPC. The application processes sensitive financial data and must meet strict compliance requirements. The security team recently discovered that an EC2 instance was compromised due to an unpatched vulnerability. The attacker used the instance's IAM role to access an S3 bucket containing customer data and exfiltrated the data. The security team needs to prevent such incidents in the future. They have implemented the following controls: - All EC2 instances are launched in private subnets. - The IAM roles used by EC2 instances follow the principle of least privilege. - Security groups restrict inbound and outbound traffic. - AWS Systems Manager Patch Manager is used to patch instances. - AWS CloudTrail is enabled and logs are sent to a centralized S3 bucket. - Amazon GuardDuty is enabled.
Despite these controls, the team is concerned about the blast radius if an instance is compromised again. Which additional measure would MOST effectively limit the blast radius of a compromised EC2 instance?
Enable VPC Flow Logs to monitor traffic to S3.
Use S3 VPC Endpoints with a bucket policy that only allows access from the VPC endpoint, and use Systems Manager Session Manager instead of SSH.
Creating an S3 VPC endpoint and attaching a bucket policy that denies all access unless the request originates from that endpoint confines S3 traffic to the AWS internal network, removing exposure to the public internet. This, combined with replacing SSH with AWS Systems Manager Session Manager, eliminates inbound SSH ports and relies on IAM-based, auditable session access instead of static keys. Together, these controls shrink the attack surface and provide preventive, policy-enforced protection against both network-level exfiltration and credential compromise.
Deploy AWS WAF in front of the S3 bucket.
Create an AWS Config rule to detect S3 access from EC2 instances.
A security engineer is designing a VPC with public and private subnets. The application servers in the private subnets need to access the internet for software updates, but must not be directly reachable from the internet. Which TWO actions satisfy these requirements?
Configure the private subnet's security group to allow inbound traffic from 0.0.0.0/0.
Add a route in the private subnet's route table pointing to the NAT gateway.
A NAT gateway performs source network address translation for outbound traffic, letting private subnet instances initiate internet connections for updates while remaining unreachable inbound. The private route table's 0.0.0.0/0 route to the NAT gateway satisfies both requirements.
Attach an internet gateway to the private subnet's route table.
Create a VPC gateway endpoint for Amazon S3.
Deploy a NAT gateway in a public subnet.
A NAT gateway placed in a public subnet performs source NAT for outbound traffic from private subnets, letting instances reach the internet for updates while remaining unreachable inbound. This satisfies the constraint that private-subnet servers initiate outbound connections without exposing themselves to inbound internet access.
Want more Infrastructure Security practice?
Practice this domainA financial services company uses AWS KMS to encrypt sensitive data. The security team has a requirement to rotate the CMK every 90 days and to maintain a record of all previous key versions for decryption of historical data. The team creates a new CMK every 90 days and manually updates applications to use the new key. This process is error-prone and causes downtime. What is the MOST operationally efficient solution that meets the requirements?
Enable automatic key rotation on the existing CMK.
Create a new CMK every 90 days and update the alias to point to the new key. Applications reference the alias.
Creating a new CMK every 90 days and then updating the alias to reference the new key provides a stable abstraction because applications point to the alias, not the key ID. The alias update is immediate and atomic, requiring no application changes, restarts, or downtime; the old CMK remains enabled to decrypt data encrypted under previous keys. This pattern is the recommended AWS KMS approach for custom rotation periods and satisfies crypto-period separation.
Use a CMK with imported key material and rotate the material every 90 days.
Continue creating new CMKs but use a script to update the application configuration files.
A company is designing a data protection strategy for its Amazon S3 bucket that stores sensitive documents. The security team requires that all data be encrypted in transit and at rest, and that any accidental deletion of objects can be reversed within 30 days. Additionally, the company must be able to audit all access attempts to the bucket, including failed attempts. Which TWO actions should the company take to meet these requirements? (Choose two.)
Enable default encryption on the bucket using SSE-S3.
Enable AWS CloudTrail with data events for S3.
Enabling CloudTrail with data events for an S3 bucket records object-level operations such as GetObject, PutObject, DeleteObject, and HeadObject, capturing the IAM principal, source IP, and whether the request succeeded or failed. This creates an authoritative, queryable audit trail that can be searched in CloudTrail Lake or Athena and is essential for incident investigation, compliance reporting, and detecting compromised credentials. Unlike server access logs, CloudTrail data events reliably include failed attempts.
Enable S3 Versioning on the bucket.
Versioning causes every PutObject to create a new version rather than overwrite, and a DeleteObject operation inserts a delete marker while retaining all prior versions. If the marker is removed, the original object returns, enabling recovery after accidental deletion, ransomware overwrites, or application errors. This is the primary recovery control because it preserves data itself; however, lifecycle rules may permanently delete old versions, so expiration policies must match your recovery point objectives.
Enable S3 server access logs and send them to a separate bucket.
Enable MFA Delete on the bucket.
A healthcare company runs a HIPAA-compliant application on AWS. The application uses Amazon S3 to store Protected Health Information (PHI). The company has implemented the following controls: (1) All S3 buckets are configured with default encryption using SSE-S3. (2) Bucket policies restrict access to only authorized IAM roles. (3) S3 access logs are enabled and sent to a centralized logging account. (4) MFA Delete is enabled on all buckets. (5) Object lock is not enabled. Recently, an internal auditor discovered that when an authorized user deletes an object, the object is permanently deleted and cannot be recovered. The company's data retention policy requires that deleted PHI be recoverable for at least 30 days after deletion. A review of the IAM policies shows that users have s3:DeleteObject permission. The auditor also notes that the bucket versioning is not enabled. The security team needs to implement a solution that allows authorized users to delete objects but ensures that deleted objects can be recovered within 30 days. Which of the following is the MOST effective course of action?
Enable S3 Object Lock in Governance mode with a retention period of 30 days.
Enable S3 Versioning on the buckets and ensure that the IAM policies include s3:DeleteObjectVersion where appropriate.
S3 Versioning is the correct data-protection mechanism because a regular DELETE on a versioned object only inserts a null-version delete marker while preserving all prior versions, allowing recovery by deleting that marker. Granting the s3:DeleteObjectVersion permission (only where appropriate) enables administrators to permanently purge specific object versions when retention or compliance demands actual deletion, while ordinary deletions remain reversible. This creates a two-tier deletion model where accidental deletes can be untangled and legitimate permanent deletes are still possible, exactly matching the requirement.
Remove the s3:DeleteObject permission from all IAM policies and use S3 Lifecycle policies to expire objects after 30 days.
Change the default encryption from SSE-S3 to SSE-C and use a separate key for each object.
A company uses AWS KMS to encrypt data at rest in Amazon S3. The security team requires that all encryption keys be automatically rotated every year. Which solution meets this requirement?
Use an AWS managed key and enable automatic rotation.
Use a customer managed key with imported key material and enable automatic rotation.
Use a customer managed key and enable automatic rotation with a yearly rotation period.
A customer managed key provides the administrative control needed to satisfy the requirement, and KMS supports automatic rotation with a configurable period between 90 and 2560 days for symmetric keys generated in KMS. By creating a customer managed key with KMS-generated key material and setting its automatic rotation period to 365 days, the company achieves seamless annual rotation while decrypting data with previous key versions as needed.
Use an AWS managed key and manually rotate it every year.
Refer to the exhibit. An AWS KMS key policy includes the statement shown. The AdminRole tries to decrypt a ciphertext that was encrypted using the same KMS key with encryption context 'department=engineering'. What will happen?
The decrypt operation succeeds because the role has kms:Decrypt permission.
The decrypt operation succeeds because the encryption context is ignored during decryption.
The decrypt operation fails because the policy does not allow kms:Decrypt without matching context.
The decrypt operation fails because the encryption context does not match the condition.
The key policy scopes kms:Decrypt to calls whose encryption context contains department=finance. The decrypt request supplies a different encryption context, so the kms:EncryptionContext:department condition key does not match. As a result, the condition in the key policy is false and KMS denies the Decrypt operation. This is expected behavior: encryption context conditions are a way to limit key usage to specific data or workloads.
Drag and drop the steps to configure a VPC with private subnets and NAT gateway for outbound internet access in the correct order.
Create VPC, then create subnets, then create and attach Internet Gateway, then create NAT Gateway, then update route tables.
This order ensures that the VPC exists, subnets are available for resources, the Internet Gateway is attached to allow public access, the NAT Gateway is deployed in a public subnet, and finally route tables are configured to route private subnet traffic through the NAT Gateway for outbound internet access.
Create VPC, then create subnets, then create NAT Gateway, then create and attach Internet Gateway, then update route tables.
Create VPC, then create subnets, then create and attach Internet Gateway, then update route tables, then create NAT Gateway.
Create VPC, then create NAT Gateway, then create subnets, then create and attach Internet Gateway, then update route tables.
Want more Data Protection practice?
Practice this domainThe SCS-C02 exam has 65 questions and must be completed in 170 minutes. The passing score is 750/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 6 domains: Threat Detection and Incident Response, Identity and Access Management, Security Logging and Monitoring, Management and Security Governance, Infrastructure Security, Data Protection. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Amazon Web Services SCS-C02 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.