Courseiva

SCS-C03 · topic practice

Infrastructure Security practice questions

Practise AWS Certified Security - Specialty Infrastructure Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Infrastructure Security

What the exam tests

What to know about Infrastructure Security

Infrastructure Security questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Infrastructure Security exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Infrastructure Security questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Review the full subnetting walkthrough →

A security engineer must monitor and record all rejected TCP connection attempts to a fleet of EC2 instances within a private subnet. The logs must be stored in a durable manner for three years to meet regulatory compliance. Which solution meets these requirements with the least operational overhead?

Question 2hardmultiple choice
Review the full routing breakdown →

A company uses an Application Load Balancer (ALB) to route traffic to EC2 instances. A security engineer needs to ensure that only traffic originating from a specific Amazon CloudFront distribution can reach the ALB. What is the most secure way to implement this restriction?

Question 3mediummulti select
Read the full DNS explanation →

A financial services company is concerned about large-scale DDoS attacks affecting its public-facing DNS and web applications. Which TWO AWS services or features provide automatic protection or mitigation against Layer 3, Layer 4, and Layer 7 DDoS attacks? (Select TWO.)

A security engineer is tasked with restricting access to Amazon S3 and Amazon DynamoDB so that traffic never leaves the AWS private network. Which TWO types of VPC endpoints should be used to achieve this for these specific services? (Select TWO.)

A security engineer wants to ensure that all EC2 instances are launched only with approved, encrypted AMIs and that any instance with an unencrypted volume is automatically flagged. Which service is best suited for this continuous compliance monitoring?

An organization is using AWS Direct Connect to link their on-premises data center to their AWS VPC. They have a strict requirement that all data in transit over the Direct Connect link must be encrypted at the network layer. Which solution should they implement?

An enterprise organization runs critical databases in Amazon RDS within a private VPC. Compliance mandates that traffic traversing between the application servers and the database must be encrypted in transit using strict mutual TLS authentication and strong cipher suites. Which configuration should the security engineer implement?

A security engineer must restrict access to an Amazon S3 bucket so that only requests originating from a specific VPC are permitted. Which policy approach should be implemented to ensure this constraint is enforced effectively?

Question 9mediummultiple choice
Review the full subnetting walkthrough →

A company requires all traffic between two EC2 instances in different subnets to be encrypted in transit. Which solution provides the most secure and scalable way to achieve this at the infrastructure level?

Which service should be used to protect a web application hosted on an Application Load Balancer from Layer 7 DDoS attacks and common web exploits like SQL injection?

A security auditor requires that all EBS volumes in an AWS account be encrypted. Which THREE actions should the security team perform to enforce this requirement effectively across the organization?

An organization uses AWS PrivateLink to connect VPCs. A security engineer wants to ensure that the interface VPC endpoint is only accessible from within the local VPC. How should the engineer configure the endpoint policy?

An application is experiencing unauthorized access via an Elastic Load Balancer (ELB). The security team wants to restrict access so that only requests originating from a specific CloudFront distribution are accepted. How should this be implemented?

A company is migrating to a multi-VPC architecture. To ensure secure cross-VPC communication, the company wants to use a Transit Gateway. What is the most appropriate configuration to minimize the risk of unauthorized lateral movement?

An organization requires that their API Gateway instances only accept requests from a specific private VPC. Which strategy should be used to enforce this network-level constraint?

A security auditor discovers that an S3 bucket is accessible to anyone with the account ID. What is the most likely cause of this configuration, and how should it be remediated?

A company hosts a static website on Amazon S3 and uses Amazon CloudFront for content delivery. The security team must ensure that the website is only accessible to users in specific European countries and that users cannot bypass CloudFront to access the S3 bucket directly. Which configuration fulfills these requirements most securely?

A company is evaluating AWS Shield to protect its public-facing web applications from Distributed Denial of Service (DDoS) attacks. Which TWO features are provided exclusively by AWS Shield Advanced that are not available in the Standard tier?

Refer to the exhibit. A security engineer is configuring VPC Traffic Mirroring to inspect traffic for an application server. Based on the provided Traffic Mirror Filter configuration, what traffic will be mirrored to the target?

Exhibit

{
  "NetworkInterfaceId": "eni-0123456789abcdef0",
  "TrafficMirrorTargetId": "tmt-0123456789abcdef0",
  "TrafficMirrorFilterId": "tmf-0123456789abcdef0",
  "Rules": [
    {
      "TrafficDirection": "ingress",
      "RuleNumber": 10,
      "RuleAction": "accept",
      "Protocol": 6,
      "DestinationPortRange": { "FromPort": 443, "ToPort": 443 },
      "SourceCidrBlock": "0.0.0.0/0",
      "DestinationCidrBlock": "10.0.1.0/24"
    }
  ]
}
Question 20hardmulti select
Read the full VPN explanation →

A large organization needs to connect its on-premises data center to 50 different VPCs across multiple AWS accounts. The solution must support encrypted transit, centralize outbound internet traffic through a security VPC for inspection, and minimize the number of VPN connections. Which TWO components are essential to this architecture?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Infrastructure Security sessions

Start a Infrastructure Security only practice session

Every question in these sessions is drawn from the Infrastructure Security domain — nothing else.

Related practice questions

Related SCS-C03 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SCS-C03 exam test about Infrastructure Security?
Infrastructure Security questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Infrastructure Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Infrastructure Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SCS-C03 topics?
Use the topic links above to move to related areas, or go back to the SCS-C03 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SCS-C03 exam covers. They are not copied from any real exam or dump site.