SCS-C03 · domain
Infrastructure Security
Practise AWS Certified Security - Specialty Infrastructure Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Infrastructure Security questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Infrastructure Security
Infrastructure Security questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Infrastructure Security exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Infrastructure Security questions (16)
Click any question to see the full explanation, or start a practice session above.
An organization is deploying a multi-tier application. Which TWO of the following configurations are required to ensure that the backend application tier in a private subnet can securely communicate with an RDS database instance while preventing direct internet access?
Hard2A company wants to eliminate the need for managing SSH keys and bastion hosts while still allowing administrators to securely access EC2 instances in private subnets. Which AWS service provides this capability and allows for centralized IAM-based access control?
Easy3A security engineer needs to ensure that all EC2 instances are patched against critical vulnerabilities without exposing them to the public internet. Which architecture is most appropriate for this task?
Medium4A company is experiencing a high volume of SQL injection attempts against its web application. The application is behind an Application Load Balancer (ALB). The security team wants to block these attacks while ensuring that legitimate traffic containing technical documentation (which may include SQL-like snippets) is not accidentally blocked. What is the best approach?
Medium5A security engineer must protect a multi-tier web application hosted in Amazon EC2 instances inside a private subnet. The application requires outbound internet access to download software updates, but malicious actors must never be able to initiate inbound connections to the instances. Which architecture satisfies these requirements securely?
Medium6A security engineer is configuring AWS Network Firewall to protect a VPC. They need to implement a rule that inspects the 'Host' header of HTTP traffic to block specific unauthorized domains. Which type of rule group should be used?
Medium7Refer to the exhibit. A security engineer notices that despite the IP restriction, users are still unable to access the S3 bucket from within the corporate network. What is the most likely cause of this issue?
Medium8A company needs to log all DNS queries made by EC2 instances within their VPC to identify potential data exfiltration via DNS tunneling. Which feature should the security engineer enable?
Medium9A company is designing a hub-and-spoke network architecture using AWS Transit Gateway. They want to centralize inbound and outbound internet traffic inspection using a fleet of firewalls in a dedicated 'Security VPC'. Which TWO steps are required to ensure traffic is correctly routed for inspection? (Select TWO.)
Hard10A company requires all outbound internet traffic from its VPC to be inspected by a fleet of third-party firewall appliances. The solution must scale horizontally and ensure that traffic is symmetric, meaning requests and responses pass through the same firewall instance. Which architecture should the security engineer implement?
Hard11A security engineer is hardening an Amazon VPC environment. To achieve defense-in-depth, the engineer needs to implement network filtering mechanisms that apply stateful inspection at the instance level and stateless inspection at the subnet boundary. Which TWO AWS features should the engineer configure to meet these requirements? (Choose two)
Hard12Refer to the exhibit. A security engineer has deployed this AWS WAF rule. If a single IP address sends 1,500 requests in a 5-minute window, what will happen according to this configuration?
Medium13Which THREE actions are essential to harden an Amazon EC2 Linux instance against unauthorized SSH access?
Hard14Refer to the exhibit. This policy is applied to an Amazon S3 bucket named 'sensitive-data'. What is the security implication of this policy configuration?
Hard15Refer to the exhibit. A user is attempting to connect to a web server from the IP address 203.0.113.5 on port 80. Based on the provided Network ACL and Security Group configurations, what will be the result of this connection attempt?
Medium16An enterprise provides a financial data service to clients via AWS PrivateLink. The security architect must ensure that only authorized consumer VPCs can connect to the Interface VPC Endpoint and that all traffic flow metadata is captured for forensic auditing. Which combination of actions meets these requirements?
HardOther domains
All SCS-C03 exam domains
Frequently asked questions
- What does the Infrastructure Security domain cover on the SCS-C03 exam?
- Infrastructure Security questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 16 Infrastructure Security questions in the SCS-C03 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Infrastructure Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.