Courseiva
Back to AWS Certified Security - Specialty questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise AWS Certified Security - Specialty practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
SCS-C03
exam code
Amazon Web Services
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related SCS-C03 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummulti select
Full question →

An organization wants to improve its vulnerability management posture by ensuring that all Amazon EC2 instances are regularly scanned for software vulnerabilities and unintended network exposure. Which TWO features of Amazon Inspector help achieve this?

Question 2hardmulti select
Full question →

Which THREE of the following resource types are currently supported by IAM Access Analyzer to identify potential public or cross-account access?

Question 3mediummulti select
Full question →

An organization wants to improve their ability to respond to security incidents. Which TWO of the following services provide centralized visibility and management for security findings?

Question 4hardmulti select
Full question →

Which THREE actions are essential to harden an Amazon EC2 Linux instance against unauthorized SSH access?

A security engineer is hardening an Amazon VPC environment. To achieve defense-in-depth, the engineer needs to implement network filtering mechanisms that apply stateful inspection at the instance level and stateless inspection at the subnet boundary. Which TWO AWS features should the engineer configure to meet these requirements? (Choose two)

Question 6hardmulti select
Full question →

A security incident indicates an EC2 instance is likely compromised and communicating with a C2 server. The security team needs to perform memory forensics and isolate the instance while preserving evidence. Which TWO actions should the team perform?

Question 7hardmulti select
Full question →

An organization is migrating to AWS and needs to enforce security guardrails across multiple accounts. Which TWO actions should the security team perform to ensure compliance? (Select TWO)

Question 8hardmulti select
Full question →

Which THREE actions are best practices for managing root user account security? (Select THREE)

Question 9hardmulti select
Full question →

A developer in Account A needs to use an AWS KMS customer managed key (CMK) located in Account B to encrypt data. Which TWO configuration steps are necessary to allow this cross-account access?

Question 10mediummulti select
Full question →

A company is setting up SAML 2.0 federation to allow employees to log into the AWS Management Console using their corporate credentials. Which TWO components are required to establish this trust relationship in AWS?

Question 11hardmulti select
Full question →

A large enterprise wants to implement SAML 2.0-based federation to allow employees to access the AWS Management Console using their existing corporate credentials. Which TWO steps are required to establish this trust relationship and enable user access?

Question 12mediummulti select
Full question →

A company is migrating a legacy database to Amazon RDS for MySQL and must ensure the data is protected according to strict compliance standards. The security team requires that the data at rest is encrypted and that the encryption cannot be disabled after the instance is created. Which TWO statements accurately describe RDS encryption behavior?

Question 13hardmulti select
Full question →

A company stores sensitive PII in RDS MySQL databases. The security team wants to ensure that data is encrypted at rest and that the encryption keys are rotated annually. Which TWO actions fulfill these requirements?

Question 14mediummulti select
Full question →

An organization wants to enforce encryption at rest for all S3 buckets using AWS Organizations. Which TWO actions should the security team perform to ensure consistent governance?

Question 15mediummulti select
Full question →

An organization is using Amazon Macie to protect sensitive data in S3. They want to ensure they are alerted to the presence of PII across all buckets. Which TWO actions are required to configure Macie to identify sensitive data effectively?

Question 16mediummulti select
Full question →

A company is preparing for an annual regulatory audit and needs to collect evidence of their compliance with the SOC 2 framework across multiple AWS accounts. Which TWO AWS services or features should the security team use to automate the collection of evidence and download official compliance reports?

Question 17hardmulti select
Full question →

A company wants to implement a robust governance framework for their AWS accounts using AWS Control Tower. They need to ensure that specific security guardrails are applied to their 'Financial-Apps' Organizational Unit (OU). Which TWO types of guardrails can be applied within Control Tower?

Question 18hardmulti select
Full question →

A company wants to detect potential brute-force attacks against their public-facing web applications hosted on EC2 instances. Which TWO measures should the security team implement?

Question 19hardmulti select
Review the full routing breakdown →

A company is designing a hub-and-spoke network architecture using AWS Transit Gateway. They want to centralize inbound and outbound internet traffic inspection using a fleet of firewalls in a dedicated 'Security VPC'. Which TWO steps are required to ensure traffic is correctly routed for inspection? (Select TWO.)

During a security incident involving suspected data exfiltration from an S3 bucket, which THREE sources provide the most relevant telemetry to determine what files were accessed?

These SCS-C03 practice questions are part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style SCS-C03 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.