Courseiva

SCS-C03 · domain

Detection

Practise AWS Certified Security - Specialty Detection practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

20 questions2 easy11 medium7 hard

Focused practice

Practice Detection questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Detection

Detection questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Detection exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Detection questions (20)

Click any question to see the full explanation, or start a practice session above.

1

A company wants to aggregate security findings from AWS GuardDuty, AWS Inspector, and AWS Macie into a single dashboard for prioritized viewing. Which service should be used to provide this consolidated view of security alerts?

Easy
2

Refer to the exhibit. The log entry shows a denied 'DeleteTable' attempt. Which service, if configured, would have automatically triggered an alert based on this specific log entry?

Hard
3

During an investigation into an EC2 instance compromise, a security analyst needs to understand the relationship between different AWS resources, such as which IAM roles were used and which IP addresses interacted with the instance. Which service should the analyst use to perform this graph-based investigation?

Medium
4

A security team needs to identify which IAM users have not used their credentials for more than 90 days. Which service should be used to provide this information?

Medium
5

A security engineer needs to detect if any EC2 instances in an account have been launched with a public IP address. Which service should be used to automate this detection?

Medium
6

A security engineer wants to enable manual remediation of Security Hub findings directly from the AWS console. They want to be able to select a finding and trigger a specific Lambda function to isolate an instance. What is the correct way to configure this?

Medium
7

Which AWS service uses machine learning to detect unusual activity, such as unauthorized access to S3 buckets or atypical API calls?

Easy
8

An organization is running critical workloads on Amazon EKS and wants to detect suspicious activity at the container runtime level, such as unauthorized process execution or unexpected file access. Which GuardDuty feature should be enabled to achieve this level of visibility?

Hard
9

An organization is concerned about detecting potential SQL injection attacks against their web application hosted on Application Load Balancer. Which service provides the best native detection capability?

Medium
10

A financial institution requires that all CloudTrail logs be stored for seven years for compliance audits. They also need the ability to run complex SQL queries against these logs to identify specific user actions across all regions. What is the most cost-effective and operationally simple solution?

Medium
11

An organization requires centralized monitoring of security findings from multiple AWS accounts. Which service should be used to aggregate these findings into a single dashboard?

Medium
12

A company wants to detect when an IAM user executes a command from a suspicious IP address. Which tool can analyze historical CloudTrail data to establish a baseline of normal behavior and trigger alerts upon deviations?

Medium
13

A security team needs to perform deep packet inspection (DPI) on traffic entering and leaving a specific EC2 instance to look for complex attack signatures that VPC Flow Logs cannot detect. Which AWS feature should they use to facilitate this?

Medium
14

An organization wants to improve its vulnerability management posture by ensuring that all Amazon EC2 instances are regularly scanned for software vulnerabilities and unintended network exposure. Which TWO features of Amazon Inspector help achieve this?

Medium
15

Which TWO actions should be taken to ensure that Amazon GuardDuty has the necessary data to detect unauthorized cryptocurrency mining instances?

Hard
16

A security engineer needs to detect when an EC2 instance is launched with an unapproved Amazon Machine Image (AMI). Which AWS service should be used to automate this detection?

Medium
17

A company wants to detect potential brute-force attacks against their public-facing web applications hosted on EC2 instances. Which TWO measures should the security team implement?

Hard
18

A security analyst needs to detect potential exfiltration of sensitive data from an S3 bucket that has public access blocked. Which Amazon GuardDuty feature should be configured to detect anomalous data access patterns by internal IAM users?

Hard
19

Refer to the exhibit. This GuardDuty finding indicates that malware was detected on an EC2 instance. What is the process GuardDuty used to perform this scan without installing an agent on the instance?

Hard
20

Which THREE of the following resource types are currently supported by IAM Access Analyzer to identify potential public or cross-account access?

Hard

Frequently asked questions

What does the Detection domain cover on the SCS-C03 exam?
Detection questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 20 Detection questions in the SCS-C03 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Detection questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
aws-scs-c03 AWS-SCS-C03 detection Practice Questions