20+ practice questions focused on Infrastructure Security — one of the most tested topics on the AWS Certified Security Specialty SCS-C02 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Infrastructure Security PracticeA company is designing a multi-tier web application on AWS. The web tier must be accessible from the internet, but the application and database tiers must be isolated. The security team requires that all traffic between tiers be encrypted and that the application tier can only be accessed by the web tier. Which architecture should be used?
Explanation: This architecture places the web tier in a public subnet with an Internet Gateway (IGW) for internet-facing access, while the application and database tiers reside in private subnets with no direct internet path. Separate security groups enforce least-privilege: the web tier security group allows inbound HTTP/HTTPS (ports 80/443) from 0.0.0.0/0, the app tier security group allows inbound traffic only from the web tier security group (using a security group reference), and the database tier security group allows inbound traffic only from the app tier security group. This enforces isolation and ensures that the application tier can only be accessed by the web tier. To satisfy the encryption requirement, you must explicitly implement encryption between tiers (e.g., TLS for web-to-app, and database-native encryption like TLS or AWS RDS encryption in transit).
Refer to the exhibit. A security engineer finds the above IAM policy attached to an IAM group. The policy is intended to allow all EC2 actions only from the corporate network (10.0.0.0/8). However, users report that they can perform EC2 actions from outside the corporate network. What is the MOST likely reason?
Explanation: The policy grants access to EC2 actions only when the source IP is in the 10.0.0.0/8 range. If a user attempts an action from outside that range, the condition is not met and the Allow statement does not apply. With no other applicable policies, the action would be denied. The fact that users can perform EC2 actions from outside the corporate network indicates that another policy is granting them access without IP restrictions. The `aws:SourceIp` condition key is available for both API and console requests; for console requests, it reflects the user's client IP. Therefore, if a user accesses from outside, the condition would not be satisfied, and the allow would not apply. So the most likely explanation is an additional IAM policy allowing all EC2 actions.
Match each AWS Storage service encryption feature to its description.
Explanation: AWS storage services offer various encryption options. S3 SSE-S3 and SSE-KMS are server-side encryption methods with different key management approaches. Client-side encryption occurs before data upload. EBS encryption is transparent block-level encryption, and Glacier automatically encrypts data at rest.
A company uses Network Load Balancer (NLB) in front of a fleet of EC2 instances in private subnets. Security team requires that the source IP addresses of clients be preserved in the access logs of the backend instances. Which configuration should the security engineer verify?
Explanation: Network Load Balancer (NLB) preserves the client source IP by default when forwarding traffic to targets in the same VPC. No special configuration is required. Proxy protocol v2 is an optional feature that adds a header with client IP and port, but it does not 'enable' source IP preservation. In fact, enabling proxy protocol v2 without backend application support would cause the source IP in TCP packets to be the NLB's IP, not the client's. None of the listed options are correct for ensuring source IP preservation in this scenario; the security engineer should verify that no explicit override is in place (there is no disable option).
A security engineer is designing a VPC with public and private subnets. The application must be able to send outbound traffic to the internet, but inbound traffic from the internet must be blocked except for a single HTTP load balancer. The application also needs to access an S3 bucket in the same AWS region. Which combination of VPC components meets these requirements? (Choose two.)
Explanation: Option C (NAT Gateway in a public subnet) is correct because instances in private subnets can route outbound internet traffic through a NAT Gateway, which performs source NAT and allows responses to return while preventing unsolicited inbound connections from the internet. Option E (S3 Gateway Endpoint in the VPC) is correct because a gateway endpoint provides private, cost-free access to S3 within the same region via the AWS private network, avoiding the need to traverse the internet or a NAT Gateway for S3 traffic. Option A is incorrect because an S3 Interface Endpoint (powered by PrivateLink) is not the standard, cost-effective choice for same-region S3 access; the gateway endpoint is the intended solution for S3. Option B is incorrect because VPC Peering to a shared services VPC does not by itself provide internet egress or S3 access for this scenario. Option D is incorrect because an Internet Gateway alone would require the application subnets to be public and would not block inbound internet traffic; the requirement is outbound-only access from private subnets.
+15 more Infrastructure Security questions available
Practice all Infrastructure Security questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Infrastructure Security. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Infrastructure Security questions on the SCS-C02 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Infrastructure Security is tested as part of the AWS Certified Security Specialty SCS-C02 blueprint. Practicing with targeted Infrastructure Security questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free SCS-C02 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Infrastructure Security is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Infrastructure Security practice session with instant scoring and detailed explanations.
Start Infrastructure Security Practice →