Courseiva

SCS-C03 · domain

Infrastructure Security

Practise AWS Certified Security - Specialty Infrastructure Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

16 questions1 easy8 medium7 hard

Focused practice

Practice Infrastructure Security questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Infrastructure Security

Infrastructure Security questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Infrastructure Security exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Infrastructure Security questions (16)

Click any question to see the full explanation, or start a practice session above.

1

An organization is deploying a multi-tier application. Which TWO of the following configurations are required to ensure that the backend application tier in a private subnet can securely communicate with an RDS database instance while preventing direct internet access?

Hard
2

A company wants to eliminate the need for managing SSH keys and bastion hosts while still allowing administrators to securely access EC2 instances in private subnets. Which AWS service provides this capability and allows for centralized IAM-based access control?

Easy
3

A security engineer needs to ensure that all EC2 instances are patched against critical vulnerabilities without exposing them to the public internet. Which architecture is most appropriate for this task?

Medium
4

A company is experiencing a high volume of SQL injection attempts against its web application. The application is behind an Application Load Balancer (ALB). The security team wants to block these attacks while ensuring that legitimate traffic containing technical documentation (which may include SQL-like snippets) is not accidentally blocked. What is the best approach?

Medium
5

A security engineer must protect a multi-tier web application hosted in Amazon EC2 instances inside a private subnet. The application requires outbound internet access to download software updates, but malicious actors must never be able to initiate inbound connections to the instances. Which architecture satisfies these requirements securely?

Medium
6

A security engineer is configuring AWS Network Firewall to protect a VPC. They need to implement a rule that inspects the 'Host' header of HTTP traffic to block specific unauthorized domains. Which type of rule group should be used?

Medium
7

Refer to the exhibit. A security engineer notices that despite the IP restriction, users are still unable to access the S3 bucket from within the corporate network. What is the most likely cause of this issue?

Medium
8

A company needs to log all DNS queries made by EC2 instances within their VPC to identify potential data exfiltration via DNS tunneling. Which feature should the security engineer enable?

Medium
9

A company is designing a hub-and-spoke network architecture using AWS Transit Gateway. They want to centralize inbound and outbound internet traffic inspection using a fleet of firewalls in a dedicated 'Security VPC'. Which TWO steps are required to ensure traffic is correctly routed for inspection? (Select TWO.)

Hard
10

A company requires all outbound internet traffic from its VPC to be inspected by a fleet of third-party firewall appliances. The solution must scale horizontally and ensure that traffic is symmetric, meaning requests and responses pass through the same firewall instance. Which architecture should the security engineer implement?

Hard
11

A security engineer is hardening an Amazon VPC environment. To achieve defense-in-depth, the engineer needs to implement network filtering mechanisms that apply stateful inspection at the instance level and stateless inspection at the subnet boundary. Which TWO AWS features should the engineer configure to meet these requirements? (Choose two)

Hard
12

Refer to the exhibit. A security engineer has deployed this AWS WAF rule. If a single IP address sends 1,500 requests in a 5-minute window, what will happen according to this configuration?

Medium
13

Which THREE actions are essential to harden an Amazon EC2 Linux instance against unauthorized SSH access?

Hard
14

Refer to the exhibit. This policy is applied to an Amazon S3 bucket named 'sensitive-data'. What is the security implication of this policy configuration?

Hard
15

Refer to the exhibit. A user is attempting to connect to a web server from the IP address 203.0.113.5 on port 80. Based on the provided Network ACL and Security Group configurations, what will be the result of this connection attempt?

Medium
16

An enterprise provides a financial data service to clients via AWS PrivateLink. The security architect must ensure that only authorized consumer VPCs can connect to the Interface VPC Endpoint and that all traffic flow metadata is captured for forensic auditing. Which combination of actions meets these requirements?

Hard

Frequently asked questions

What does the Infrastructure Security domain cover on the SCS-C03 exam?
Infrastructure Security questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 16 Infrastructure Security questions in the SCS-C03 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Infrastructure Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
AWS Certified Security - Specialty SCS-C03 Infrastructure Security Practice Questions