Courseiva

SCS-C03 · domain

Security Foundations and Governance

Practise AWS Certified Security - Specialty Security Foundations and Governance practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

15 questions3 easy9 medium3 hard

Focused practice

Practice Security Foundations and Governance questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Security Foundations and Governance

Security Foundations and Governance questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Security Foundations and Governance exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Security Foundations and Governance questions (15)

Click any question to see the full explanation, or start a practice session above.

1

A company wants to implement a governance strategy that prevents any member account in the organization from disabling CloudTrail or deleting the organization-level trail. What is the most effective way to implement this while allowing account administrators to manage their own local resources?

Medium
2

Which AWS IAM best practice ensures that users have only the permissions necessary to perform their specific business roles?

Easy
3

A company wants to implement a robust governance framework for their AWS accounts using AWS Control Tower. They need to ensure that specific security guardrails are applied to their 'Financial-Apps' Organizational Unit (OU). Which TWO types of guardrails can be applied within Control Tower?

Hard
4

Which AWS service is best suited for providing a comprehensive, searchable audit trail of every API call made in an AWS account?

Easy
5

According to the AWS Shared Responsibility Model, which of the following security tasks is the sole responsibility of the customer when using Amazon EC2 instances?

Easy
6

An organization wants to enforce encryption at rest for all S3 buckets using AWS Organizations. Which TWO actions should the security team perform to ensure consistent governance?

Medium
7

A company is preparing for an annual regulatory audit and needs to collect evidence of their compliance with the SOC 2 framework across multiple AWS accounts. Which TWO AWS services or features should the security team use to automate the collection of evidence and download official compliance reports?

Medium
8

A security engineer must ensure that no developer in a specific AWS Organizations member account can delete Amazon S3 buckets, even if they have AdministratorAccess. Which governance mechanism provides the most efficient and centralized way to enforce this restriction across the organizational unit?

Medium
9

A security auditor requires a centralized view of security findings across all AWS accounts in an organization. Which service should be enabled to aggregate and prioritize these findings?

Medium
10

A company requires that all cloud resources be tagged with a 'Department' code for cost allocation and security reporting. How should they enforce this?

Medium
11

An organization wants to centralize the management of Amazon GuardDuty across 50 AWS accounts. They want the security team to be able to view and manage findings for all accounts from a single dashboard. What is the recommended governance approach?

Medium
12

Refer to the exhibit. An administrator applied this policy to a bucket, but users are still able to upload unencrypted objects. Why is this occurring?

Hard
13

A security engineer needs to verify if all AWS accounts in the organization are compliant with the CIS AWS Foundations Benchmark. Which service provides a centralized compliance dashboard and the ability to run automated checks against this specific benchmark?

Medium
14

Refer to the exhibit. Why might a user in the 192.168.1.0/24 range still be denied access to the S3 bucket?

Hard
15

Which service should be used to securely store and automatically rotate database credentials?

Medium

Frequently asked questions

What does the Security Foundations and Governance domain cover on the SCS-C03 exam?
Security Foundations and Governance questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 15 Security Foundations and Governance questions in the SCS-C03 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security Foundations and Governance questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
aws-scs-c03 AWS-SCS-C03 security foundations and governance Practice Questions