SCS-C03 · domain
Data Protection
Practise AWS Certified Security - Specialty Data Protection practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Data Protection questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Data Protection
Data Protection questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Data Protection exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Data Protection questions (15)
Click any question to see the full explanation, or start a practice session above.
An organization wants to rotate their KMS customer-managed keys every 90 days. What is the most effective way to implement this?
Medium2An organization is using Amazon Macie to protect sensitive data in S3. They want to ensure they are alerted to the presence of PII across all buckets. Which TWO actions are required to configure Macie to identify sensitive data effectively?
Medium3A financial institution requires that all data stored in S3 buckets be immutable for five years to comply with regulatory requirements. They also need to ensure that even the root user cannot delete the data or shorten the retention period. Which configuration should the security engineer implement?
Hard4A security architect is designing a cross-account data sharing solution. Account A owns a KMS Customer Managed Key (CMK) that must be used by an IAM role in Account B to decrypt S3 objects. Which TWO steps are required to enable this cross-account access?
Hard5A company is implementing a new internal web application and needs to use SSL/TLS certificates. Due to regulatory requirements, the certificates must be issued by a private Certificate Authority (CA) managed by the company, rather than a public CA. Which AWS service should be used to meet this requirement?
Medium6A security engineer needs to identify and protect Personally Identifiable Information (PII) stored in thousands of S3 buckets across multiple AWS accounts. The solution must provide a centralized dashboard and use machine learning to classify data. Which service is best suited for this task?
Hard7An organization is using AWS Secrets Manager to store database credentials. The security policy requires that these credentials be rotated every 30 days. The database is hosted on Amazon RDS. What is the most secure and automated way to implement this requirement?
Medium8Refer to the exhibit. A developer is attempting to upload an object to 'my-secure-bucket' using the AWS CLI but receives an 'Access Denied' error. The developer's command was: 'aws s3 cp file.txt s3://my-secure-bucket/file.txt'. What is the most likely cause of the failure?
Hard9A company is setting up a private Public Key Infrastructure (PKI) on AWS to issue certificates for internal microservices. They need to ensure that the private keys of the CA are protected by a FIPS 140-2 Level 3 validated Hardware Security Module (HSM). Which service should they use?
Medium10A company wants to ensure that all new Amazon EBS volumes created in their account are automatically encrypted, regardless of whether the developer specifies encryption during the volume creation process. Which AWS feature should be used?
Easy11Which service should be used to protect sensitive data from being exfiltrated via API calls to unauthorized services?
Medium12A company stores sensitive PII in RDS MySQL databases. The security team wants to ensure that data is encrypted at rest and that the encryption keys are rotated annually. Which TWO actions fulfill these requirements?
Hard13A company is migrating a legacy database to Amazon RDS for MySQL and must ensure the data is protected according to strict compliance standards. The security team requires that the data at rest is encrypted and that the encryption cannot be disabled after the instance is created. Which TWO statements accurately describe RDS encryption behavior?
Medium14A company needs to share an encrypted EBS volume snapshot with a partner's AWS account. The snapshot is encrypted with a customer-managed KMS key. What must the company do to enable this sharing?
Medium15An application in Account A needs to decrypt S3 objects in Account B using a KMS key in Account B. What is the minimal configuration required?
HardOther domains
All SCS-C03 exam domains
Frequently asked questions
- What does the Data Protection domain cover on the SCS-C03 exam?
- Data Protection questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 15 Data Protection questions in the SCS-C03 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Data Protection questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.