Courseiva

AWS Certified Security Specialty SCS-C02 (SCS-C02) — Questions 1–75

1205 questions total · 17pages · All types, answers revealed

Page 1 of 17

Page 2
1
Multi-Selecthard

A company is designing a data protection strategy for its Amazon S3 bucket that stores sensitive customer data. The bucket must be encrypted at rest using a customer managed key (CMK) that is stored in AWS KMS. The company also needs to ensure that only authorized users can decrypt objects. Which TWO actions should the company take?

Select 2 answers
A.Create a bucket policy that denies s3:GetObject unless the request includes a specific encryption context
B.Modify the KMS key policy to allow only the authorized IAM roles to use the key
C.Attach an IAM policy to the authorized users that grants kms:Decrypt on the CMK
D.Create a VPC endpoint for S3 and use bucket policies to restrict access to the endpoint
E.Use SSE-C with a customer-provided key
AnswersB, C

Modifying the KMS key policy is the correct approach because the key policy is the resource-based policy that directly controls which principals can call kms:Decrypt on the CMK. By explicitly listing only authorized IAM roles as principals with Decrypt permission, you ensure that even if an S3 bucket policy or object ACL grants read access to ciphertext, those roles cannot decrypt it without the key. This is a robust data protection strategy because it combines S3 access control with KMS key-level authorization.

Why this answer

Option B is correct because the KMS key policy is the primary resource-based access control for a customer managed key, so modifying it to allow only the authorized IAM roles to use the key ensures that no other principals can call kms:Decrypt or otherwise use the CMK to access the encrypted S3 objects. Option C is correct because even if the key policy permits a role, the caller still needs an identity-based IAM policy granting kms:Decrypt on that specific CMK, so attaching such a policy to the authorized users is required for them to decrypt the objects. Together, the key policy and the IAM policy satisfy the requirement that only authorized users can decrypt data encrypted with the CMK.

Option A does not belong because S3 server-side encryption with KMS does not use encryption context in the s3:GetObject request in the way described, and denying based on encryption context is not the mechanism for restricting decryption to authorized users. Option D does not belong because a VPC endpoint and bucket policy control network/API access to S3, not who can decrypt with the KMS CMK. Option E does not belong because SSE-C uses a customer-provided key rather than a CMK stored in AWS KMS, which contradicts the stated requirement.

Exam trap

SCS-C02 often tests the dual requirement of KMS key policies and IAM policies — candidates may pick only one, forgetting that both must allow the action for access to be granted.

2
MCQeasy

Which AWS service can be used to centrally manage VPC security groups and network ACLs across multiple accounts in AWS Organizations?

A.AWS Firewall Manager
B.AWS Shield
C.AWS Config
D.AWS WAF
AnswerA

AWS Firewall Manager is the service designed to centrally configure and administer VPC security rules across accounts in an AWS Organization. It lets you create security group policies and network ACL policies that are automatically applied to new and existing VPC resources, enforcing a consistent security posture. This central management capability directly matches the scenario of managing VPC security centrally.

Why this answer

AWS Firewall Manager is the correct service because it provides centralized management of security groups and network ACLs across multiple accounts within AWS Organizations. It allows you to define common security rules and apply them automatically to new and existing accounts, ensuring consistent enforcement of VPC security policies without manual per-account configuration.

Exam trap

The trap here is that candidates confuse AWS Firewall Manager with AWS WAF or AWS Shield, assuming any 'firewall' or 'security' service can manage VPC-level constructs, but only Firewall Manager provides centralized cross-account management of security groups and NACLs.

How to eliminate wrong answers

Option B is wrong because AWS Shield is a managed Distributed Denial of Service (DDoS) protection service, not a tool for managing security groups or network ACLs. Option C is wrong because AWS Config is a service for evaluating and auditing resource compliance against rules, but it does not centrally manage or enforce security group or NACL policies across accounts. Option D is wrong because AWS WAF is a web application firewall that protects HTTP/HTTPS endpoints from common web exploits, and it does not manage VPC-level security groups or network ACLs.

3
MCQeasy

Which IAM entity can be used to grant temporary access to AWS resources for users from a different AWS account?

A.IAM group
B.IAM role
C.IAM policy
D.IAM user
AnswerB

An IAM role is the correct entity for granting temporary access because it is designed to be assumed. When a principal assumes a role, AWS STS returns temporary security credentials with a limited lifetime, governed by the role's trust policy and permissions policy. This is the standard mechanism for federated access, cross-account access, and EC2 instance profiles.

Why this answer

An IAM role is the correct entity because it is specifically designed to grant temporary, cross-account access to AWS resources. When a user from a different AWS account assumes a role, AWS STS (Security Token Service) issues temporary security credentials (access key, secret key, and session token) that are valid for a configurable duration (default 1 hour, max 12 hours). This avoids the need to create permanent IAM users or share long-term credentials across accounts.

Exam trap

The trap here is that candidates often confuse an IAM policy with an IAM role, thinking that attaching a policy directly to an external user grants access, but policies alone cannot be assumed and do not generate temporary credentials.

How to eliminate wrong answers

Option A is wrong because an IAM group is a container for IAM users within the same AWS account and cannot be used to grant access to users from a different AWS account; it has no cross-account trust policy. Option C is wrong because an IAM policy is a document that defines permissions but is not an identity that can be assumed; it must be attached to an IAM user, group, or role to grant permissions, and by itself cannot provide temporary credentials. Option D is wrong because an IAM user is a permanent identity tied to a single AWS account; while you could create a user in your account for an external user, that would require sharing long-term access keys, which violates security best practices and does not provide temporary, scoped credentials.

4
MCQhard

A company's security team discovers that an IAM role has been assumed from an unexpected external AWS account. Which AWS service can be used to analyze the trust policy and identify unintended access?

A.AWS IAM Access Analyzer
B.AWS CloudTrail Insights
C.AWS Config
D.AWS Security Hub
AnswerA

AWS IAM Access Analyzer is correct because it performs automated, semantic analysis of the trust policy attached to the IAM role and identifies whether the role can be assumed by principals outside your AWS account or AWS organization. It generates concrete findings for external access, including the exact external principal and the action that grants access, so your security team can directly review and remediate the role. Other services merely log or aggregate activity; Access Analyzer specifically applies reachability logic to the policy statements.

Why this answer

AWS IAM Access Analyzer analyzes resource-based policies, including IAM role trust policies, to identify resources shared with external entities. It can detect when a role's trust policy allows an unexpected external AWS account to assume it, providing findings that highlight unintended access.

Exam trap

SCS-C02 often tests the specific purpose of IAM Access Analyzer versus CloudTrail Insights or Config — candidates pick CloudTrail Insights because it sounds like it analyzes activity, but Access Analyzer is the service for policy analysis.

How to eliminate wrong answers

Option B is wrong because CloudTrail Insights detects unusual API activity patterns but does not analyze trust policies for external access. Option C is wrong because AWS Config evaluates resource configurations against rules but does not specifically analyze trust policies for external principals. Option D is wrong because Security Hub aggregates findings from various services but does not itself analyze trust policies; it relies on services like Access Analyzer.

5
Multi-Selectmedium

A company uses AWS Organizations and wants to ensure that no member account can disable AWS CloudTrail or delete CloudTrail log files from S3. Which TWO actions should the security team take? (Choose TWO.)

Select 2 answers
A.Create an SCP that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail.
B.Enable MFA delete on the S3 bucket that stores CloudTrail logs.
C.Apply an SCP to the management account to prevent disabling CloudTrail.
D.Add an S3 bucket policy that denies s3:DeleteObject for the CloudTrail log bucket.
E.Create an IAM role for CloudTrail with permissions to write logs only.
AnswersA, D

An SCP that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail is an effective preventive control at the organization level. SCPs are inherited by all member accounts and cannot be bypassed by the account's IAM administrators or even the root user, guaranteeing that the CloudTrail trail remains active and undisputed. This directly addresses the requirement to ensure that no one can stop or remove the audit history, making it a correct answer.

Why this answer

Option A is correct because an AWS Organizations service control policy (SCP) attached to member accounts can explicitly deny the CloudTrail control-plane actions cloudtrail:StopLogging and cloudtrail:DeleteTrail, which are exactly the API calls used to disable a trail, and SCPs are the standard guardrail mechanism for enforcing such restrictions across all accounts in the organization. Option D is correct because a bucket policy on the CloudTrail log bucket that denies s3:DeleteObject (and ideally s3:DeleteObjectVersion) prevents any principal, including account administrators, from deleting the log objects, directly satisfying the requirement to protect the log files. Option B is not correct because MFA Delete only requires additional authentication for deleting object versions; it does not by itself prevent deletion and is not the SCP/bucket-policy guardrail the scenario requires.

Option C is not correct because SCPs do not apply to the management account, so applying one there would not prevent disabling CloudTrail in member accounts. Option E is not correct because an IAM role granting write-only permissions to CloudTrail does not stop member accounts from calling StopLogging/DeleteTrail or deleting S3 log objects.

Exam trap

SCS-C02 often tests the misconception that SCPs can be applied to the management account or that MFA Delete alone protects CloudTrail logs — candidates must remember SCPs never affect the management account and that log immutability requires an S3-layer control.

6
MCQeasy

A developer needs to allow an EC2 instance to access an S3 bucket. Which is the best practice for granting permissions?

A.Store IAM user access keys in a configuration file on the EC2 instance.
B.Use a security group to allow the EC2 instance to access S3.
C.Attach an S3 bucket policy that grants access to the EC2 instance ID.
D.Create an IAM role with S3 access and attach it to the EC2 instance profile.
AnswerD

Create an IAM role with an S3 access policy, then place that role in an instance profile and attach the profile to the EC2 instance at launch or via the console/API. When the instance starts, it uses the role's trust policy to assume the role and receives temporary credentials from the instance metadata service (IMDSv1 or IMDSv2) that are automatically rotated. The SDK then uses these credentials to sign requests to S3 for the duration of the role session, enforcing the exact permissions granted by the role while avoiding the need to embed static keys.

Why this answer

The best practice for granting an EC2 instance access to S3 is to create an IAM role with the necessary S3 permissions and attach it to the EC2 instance via an instance profile. This provides temporary credentials that are automatically rotated, eliminating the need to store long-term access keys on the instance. It follows the principle of least privilege and is the most secure method.

Exam trap

SCS-C02 often tests the misconception that security groups or bucket policies can grant S3 access to EC2 instances — candidates must remember that IAM roles are the correct mechanism.

How to eliminate wrong answers

Option A is wrong because storing IAM user access keys in a configuration file on the instance is insecure — keys can be leaked, are long-term, and require manual rotation. Option B is wrong because security groups control network traffic (IP, port, protocol) and cannot grant IAM permissions to access S3; S3 access is controlled by IAM policies, not security groups. Option C is wrong because S3 bucket policies cannot grant access to an EC2 instance ID; they grant access to IAM principals (users, roles, accounts) or use conditions, but instance IDs are not valid principals.

7
MCQhard

A security engineer notices that an S3 bucket containing sensitive data has been accessed from an IP address outside the allowed range. CloudTrail logs show the access was made using temporary credentials from an assumed role. What additional logging is needed to trace the access back to the original IAM user who assumed the role?

A.Enable CloudTrail to log data events for the S3 bucket.
B.Enable VPC Flow Logs for the VPC where the request originated.
C.Configure CloudWatch Logs to capture the EC2 instance's system logs.
D.Enable S3 server access logging for the bucket.
E.Enable AWS Config to record S3 bucket policies.
AnswerE

AWS Config does not record API calls; CloudTrail already records the session issuer in management events.

Why this answer

The information needed to trace the access back to the original IAM user who assumed the role is already available in CloudTrail management events, which are enabled by default. The AssumeRole API call is logged as a management event and includes the ARN of the IAM user or role that performed the assumption. Therefore, no additional logging is required to identify the original user.

Options A, B, C, D, and E do not provide this specific information: A and D log the S3 access but show only the assumed role; B and C are unrelated; E records configuration changes but not the specific AssumeRole call.

Exam trap

Candidates may assume that data events (A) or S3 server access logs (D) will capture the original user, but they only log the assumed role's ARN. The key is recognizing that management events already contain the AssumeRole call with the original user identity.

How to eliminate wrong answers

Option A is wrong because CloudTrail data events for S3 would log the API calls made to the bucket (e.g., GetObject, PutObject) but would still show the assumed role's ARN, not the original IAM user who assumed the role. Option B is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) but do not include IAM user or role information, so they cannot trace back to the original user. Option C is wrong because EC2 instance system logs (e.g., /var/log/messages) capture OS-level events, not AWS IAM role assumption details, and are irrelevant to tracing the original IAM user.

Option D is wrong because S3 server access logs record requests to the bucket (e.g., requester, IP, operation) but the requester field will show the assumed role's ARN, not the original IAM user who assumed the role.

8
Matchingmedium

Match each AWS service to its primary security function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Web application firewall

DDoS protection

Key management and encryption

Identity and access management

Data discovery and classification

Why these pairings

These are core AWS security services with distinct purposes.

9
MCQhard

A financial services company must ensure that all data at rest in Amazon RDS for PostgreSQL is encrypted. The current database is unencrypted. What is the MOST operationally efficient way to enable encryption?

A.Export the database to S3 using pg_dump, then import into a new encrypted RDS instance.
B.Create a read replica with encryption enabled and promote it to primary.
C.Take a snapshot of the database, copy the snapshot with encryption enabled, and restore the encrypted snapshot to a new DB instance.
D.Enable encryption directly on the existing RDS instance by modifying the DB instance settings.
AnswerC

This is the officially supported AWS method for adding encryption at rest to an existing unencrypted RDS instance. You take a manual snapshot, copy that snapshot while specifying a KMS key (which encrypts the snapshot copy), and then restore the encrypted snapshot to a new DB instance. The restored instance is encrypted at the storage layer, and you can repoint your application to its new endpoint before decommissioning the original instance. After creation, encryption on that restored instance cannot be disabled.

Why this answer

The most operationally efficient way to enable encryption on an existing unencrypted RDS for PostgreSQL database is to take a snapshot, copy the snapshot with encryption enabled, and restore it to a new encrypted DB instance. This method leverages RDS's native snapshot and restore capabilities, minimizing manual intervention and downtime. Other methods like exporting and importing data are more complex and time-consuming, and encryption cannot be enabled directly on an existing instance.

Exam trap

SCS-C02 often tests the method to encrypt an existing unencrypted RDS instance, and candidates may incorrectly believe that encryption can be enabled by modifying the instance or by creating a read replica.

How to eliminate wrong answers

Option A is wrong because exporting and importing via pg_dump is manual, error-prone, and requires significant downtime. Option B is wrong because creating an encrypted read replica is not possible if the source is unencrypted; encryption must be enabled at creation, and you cannot enable encryption on a read replica of an unencrypted instance. Option D is wrong because RDS does not allow enabling encryption on an existing DB instance; encryption can only be enabled at creation or by restoring from an encrypted snapshot.

10
Multi-Selecthard

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The security team wants to allow only HTTP and HTTPS traffic from the internet to the ALB, and only HTTP traffic from the ALB to the EC2 instances. Which THREE security group configurations are required? (Choose three.)

Select 3 answers
A.ALB security group: inbound rule allowing HTTP from 0.0.0.0/0.
B.EC2 security group: inbound rule allowing HTTP from 0.0.0.0/0.
C.EC2 security group: inbound rule allowing HTTP from ALB security group.
D.EC2 security group: inbound rule allowing HTTPS from ALB security group.
E.ALB security group: inbound rule allowing HTTPS from 0.0.0.0/0.
AnswersA, C, E

The ALB is the public entry point for the web application, so its security group must permit inbound HTTP from any IPv4 address. Allowing 0.0.0.0/0 on port 80 is required for clients on the internet to reach the load balancer. The ALB then forwards requests to the EC2 instances, whose own security group controls traffic from the ALB only.

Why this answer

The ALB must accept HTTP traffic from the internet (0.0.0.0/0) to serve web requests. This inbound rule allows the ALB to listen on port 80 for unencrypted HTTP traffic, which is a standard requirement for a public-facing web application. Without this rule, HTTP requests from clients would be dropped by the ALB's security group.

Exam trap

The trap here is that candidates often mistakenly add an HTTPS inbound rule to the EC2 security group (option D) or allow direct internet access to the instances (option B), failing to recognize that the ALB should handle HTTPS termination and only forward HTTP to the backend.

11
Multi-Selecthard

A security engineer wants to detect and alert on AWS account root user activity. Which THREE services can be used together to achieve this? (Select THREE.)

Select 3 answers
A.AWS Config
B.Amazon CloudWatch Events (EventBridge)
C.AWS CloudTrail
D.Amazon CloudWatch Logs
E.Amazon GuardDuty
AnswersB, C, D

EventBridge matches CloudTrail events against a rule pattern, for example filtering on the root account's ARN, and routes matches to an SNS topic or Lambda function. This provides the near-real-time detection and notification mechanism the scenario requires.

Why this answer

Amazon CloudTrail (C) is correct because it records AWS API activity including root user sign-in events and console logins, which are captured as management events in the CloudTrail event history and delivered to an S3 bucket or CloudWatch Logs. Amazon CloudWatch Logs (D) is correct because CloudTrail can be configured to send its trail logs to a CloudWatch Logs log group, where log data can be retained and made available for metric filters and alarms. Amazon CloudWatch Events (EventBridge) (B) is correct because it can match specific CloudTrail API events (for example, events with a userIdentity type of Root) via event patterns and route them to targets such as SNS or Lambda to generate alerts.

AWS Config (A) is not correct because it evaluates resource configuration compliance and records configuration changes, not real-time API activity or root user sign-in events. Amazon GuardDuty (E) is not correct because it is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail management events for malicious or anomalous behavior, but it does not provide the event-matching and alerting pipeline for root user activity described here.

Exam trap

The trap here is that candidates may think Amazon GuardDuty is the correct choice because it detects threats, but it does not provide a native, customizable alerting mechanism for root user activity; instead, the combination of CloudTrail, EventBridge, and CloudWatch Logs is the standard AWS-recommended approach.

12
MCQhard

A company uses AWS Secrets Manager to store database credentials for an application running on EC2 instances. The security engineer needs to ensure that the credentials are automatically rotated every 30 days and that the application can retrieve the credentials without hardcoding them. The engineer has configured a rotation Lambda function and enabled rotation. However, the application is still using hardcoded credentials. What should the engineer do to ensure the application retrieves credentials dynamically?

A.Use AWS AppConfig to deploy the credentials to the EC2 instances and configure the application to read from a local file.
B.Modify the application code to call the Secrets Manager GetSecretValue API using the AWS SDK, and grant the EC2 instance role permission to access the secret.
C.Store the credentials in AWS Systems Manager Parameter Store as a SecureString parameter and modify the application to retrieve them from there.
D.Configure the application to read the credentials from an environment variable that is updated by the rotation Lambda function.
AnswerB

To retrieve credentials dynamically, the application must use the Secrets Manager API to fetch the secret at runtime. This requires code changes to call GetSecretValue and appropriate IAM permissions for the EC2 instance role to access the secret. This approach eliminates hardcoded credentials and allows automatic rotation to take effect without application changes.

Why this answer

The application must be modified to use the Secrets Manager API to retrieve credentials at runtime. This ensures that the application always gets the current credentials after rotation. The EC2 instance role must have permissions to call GetSecretValue on the secret.

This is the standard pattern for dynamic secret retrieval.

Exam trap

The trap here is thinking that enabling rotation in Secrets Manager automatically updates the application's credentials, but the application must be coded to fetch the secret dynamically.

13
MCQhard

A security engineer is reviewing an IAM policy attached to a user. The policy is intended to allow all EC2 actions except deleting volumes in the Production environment. However, the user reports being able to delete volumes that are tagged with Environment=Production. What is the reason for this behavior?

A.The policy is not attached to the correct IAM entity.
B.The Deny statement should use iam:ResourceTag instead of ec2:ResourceTag.
C.The condition in the Deny statement uses StringNotEquals, which denies deletion for non-Production volumes, not Production volumes.
D.The Allow statement uses a wildcard for the action, which overrides the Deny statement.
AnswerC

The StringNotEquals operator evaluates to true when the volume's tag value is anything other than Production, so the Deny applies only to non-Production volumes. Production-tagged volumes fail the negative condition and are therefore allowed by the Deny statement to be deleted. If the goal is to protect Production volumes from deletion, the policy should use StringEquals with the value Production so that only matching volumes are denied.

Why this answer

The Deny statement uses the StringNotEquals condition operator with ec2:ResourceTag/Environment=Production. This means the Deny applies when the tag value is NOT equal to Production, so it denies deletion for non-Production volumes but allows deletion for Production volumes. To deny deletion of Production volumes, the policy should use StringEquals instead of StringNotEquals.

Exam trap

The trap here is that candidates often confuse StringNotEquals with StringEquals, assuming that StringNotEquals will deny the specified tag value, when in fact it denies all other values, allowing the intended target to pass through.

How to eliminate wrong answers

Option A is wrong because the policy is attached to the user, and the user can perform other EC2 actions, so the attachment is correct; the issue is the logic in the policy itself. Option B is wrong because ec2:ResourceTag is the correct condition key for EC2 resource tags; iam:ResourceTag is used for IAM resources, not EC2. Option D is wrong because in IAM policy evaluation, an explicit Deny always overrides any Allow, regardless of wildcards; the problem is that the Deny condition does not match the Production volumes.

14
Multi-Selecteasy

A company is storing sensitive data in Amazon S3. They want to ensure that all data is encrypted at rest using server-side encryption. Which THREE options are available for server-side encryption in S3? (Select THREE.)

Select 3 answers
A.Client-side encryption
B.SSE-KMS
C.SSE-S3
D.SSE-C
E.AWS CloudHSM
AnswersB, C, D

SSE-KMS integrates Amazon S3 with AWS Key Management Service to perform server-side encryption using envelope encryption: S3 calls KMS to generate a data key, encrypts the object with it, and stores the encrypted data key alongside the object. It supports customer-managed KMS keys, enabling granular access control through IAM and KMS policies, automatic key rotation, and audit logs via CloudTrail. This makes it particularly suitable for sensitive data requiring separation of duties and compliance traceability, though it is only one of several valid S3 server-side encryption options.

Why this answer

SSE-KMS (B) is a valid S3 server-side encryption option in which S3 encrypts objects using keys managed by AWS KMS, giving you control over key policies, audit trails via CloudTrail, and separation of permissions. SSE-S3 (C) is also correct: S3 manages the encryption keys entirely with AES-256, and it is the default server-side encryption applied to objects at rest. SSE-C (D) is correct as well: the customer provides the encryption key on each request, and S3 performs the encryption/decryption server-side without storing the key.

Client-side encryption (A) is not server-side encryption because data is encrypted before it reaches S3, so S3 never performs the encryption. AWS CloudHSM (E) is a dedicated hardware security module service, not an S3 server-side encryption option, though it can be used with SSE-C or custom key management.

Exam trap

SCS-C02 often tests the distinction between server-side and client-side encryption — candidates may incorrectly include client-side encryption or CloudHSM as S3 SSE options.

15
MCQmedium

A company is using AWS Organizations with multiple accounts. The security team wants to ensure that no IAM user in any account can create new IAM users. Which approach should be used?

A.Apply an IAM policy to the root user of each account.
B.Use an SCP attached to each IAM user.
C.Use an IAM permissions boundary on each IAM user.
D.Apply a service control policy (SCP) at the root organizational unit that denies IAM:CreateUser.
AnswerD

Service control policies set permission guardrails across an AWS Organizations root, and an explicit deny for iam:CreateUser applies to every principal in every member account, including account administrators. This centrally prevents new IAM users organisation-wide, satisfying the requirement without editing each account individually.

Why this answer

Service control policies (SCPs) are the correct mechanism because they allow you to centrally restrict permissions across all accounts in an AWS Organization. By attaching an SCP at the root organizational unit that denies the `iam:CreateUser` action, you ensure that no IAM user in any member account can create new IAM users, regardless of any IAM policies applied within those accounts. SCPs act as a guardrail that overrides any allow permissions granted by IAM policies.

Exam trap

The trap here is that candidates often confuse SCPs with IAM permissions boundaries or think SCPs can be attached directly to IAM users, but SCPs only apply to accounts or organizational units and are designed for centralized governance across an AWS Organization.

How to eliminate wrong answers

Option A is wrong because the root user of each account is not subject to IAM policies; the root user has full administrative access and cannot be restricted by IAM policies. Option B is wrong because SCPs are attached to AWS accounts or organizational units, not to IAM users; attaching an SCP to an IAM user is not a valid operation. Option C is wrong because an IAM permissions boundary only limits the maximum permissions an IAM user can have, but it does not prevent the user from creating other IAM users if the boundary allows it; it is not a global deny mechanism across accounts.

16
MCQeasy

A security engineer is investigating a potential compromise of an S3 bucket. The engineer needs to determine if any objects were accessed by an unauthorized user. Which AWS service can provide detailed access logs for S3 objects?

A.AWS CloudTrail
B.S3 server access logs
C.AWS Config
D.Amazon Inspector
AnswerB

S3 server access logs provide a comprehensive, per-request record of every call made to a bucket, including requester identity, bucket name, object key, request type, HTTP status, error codes, source IP address, User-Agent, and timestamps. This granular data is exactly what is needed to trace unauthorized access or data exfiltration during a compromise. Unlike CloudTrail, server access logs are enabled directly on the S3 bucket and capture all requests, even those that are denied or made anonymously, making them the most direct evidence source.

Why this answer

S3 server access logs provide detailed records of requests made to an S3 bucket, including the requester, bucket name, request time, action, and response status. This granularity is essential for identifying unauthorized access to specific objects, as it logs every GET, PUT, DELETE, and HEAD request at the object level. AWS CloudTrail, while useful for management events, does not log data-level operations like object reads by default unless data events are explicitly enabled, and even then, it may not capture all object-level access details as comprehensively as server access logs.

Exam trap

The trap here is that candidates often assume AWS CloudTrail is sufficient for all logging needs, but the exam specifically tests the distinction between management events (CloudTrail default) and data-level object access logs (S3 server access logs), and that CloudTrail data events require explicit enablement and still lack the granularity of server access logs.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail primarily logs management events (e.g., bucket creation, policy changes) and, even when data events are enabled for S3, it logs object-level operations at a higher level (e.g., GetObject, PutObject) but does not provide the per-request detail (e.g., HTTP method, object key, response status) that S3 server access logs offer; relying solely on CloudTrail could miss unauthorized access patterns. Option C is wrong because AWS Config is a configuration auditing and compliance service that tracks resource configuration changes (e.g., bucket policies, lifecycle rules) and does not log individual object access requests; it cannot reveal who accessed an object or when. Option D is wrong because Amazon Inspector is a vulnerability assessment service that scans EC2 instances and container workloads for software vulnerabilities and network exposure; it has no capability to log or analyze S3 object access requests.

17
MCQeasy

A company stores sensitive customer data in Amazon S3. They want to ensure that all objects are encrypted at rest using server-side encryption with AWS KMS. Which S3 bucket policy statement should be added to deny uploads that do not request SSE-KMS?

A.Deny PutObject unless 's3:x-amz-server-side-encryption' is 'AES256'
B.Deny PutObject unless 's3:x-amz-server-side-encryption' is 'aws:kms'
C.Deny PutObject unless 'aws:SourceArn' equals the bucket ARN
D.Deny PutObject unless 's3:x-amz-server-side-encryption-aws-kms-key-id' is present
AnswerB

This is the correct condition because it explicitly requires the s3:x-amz-server-side-encryption header to carry the value aws:kms. In a bucket policy, a Deny with this condition rejects any PutObject call that is not using SSE-KMS, thereby enforcing KMS encryption on all stored objects. It targets the encryption mode directly and avoids the ambiguity of key-ID or source-based checks.

Why this answer

The condition 's3:x-amz-server-side-encryption' with value 'aws:kms' enforces that objects are uploaded with SSE-KMS. Option A is incorrect because 'AES256' enforces SSE-S3, not SSE-KMS. Option C is incorrect because 'aws:SourceArn' is used for cross-account access, not encryption enforcement.

Option D is incorrect because requiring the specific KMS key ID is too restrictive; the policy should only require the encryption type, not a particular key.

18
MCQhard

A company uses AWS Shield Advanced to protect its web application from DDoS attacks. The security team wants to receive real-time notifications when a DDoS attack is detected. Which configuration should be used?

A.Use Amazon CloudWatch Events to trigger an AWS Lambda function that sends an Amazon SNS notification when a Shield Advanced event occurs.
B.Enable VPC Flow Logs and create a CloudWatch alarm for high traffic volume.
C.Subscribe an SNS topic to Shield Advanced notifications directly.
D.Enable AWS CloudTrail and create a metric filter for DDoS events.
AnswerA

Shield Advanced is integrated natively with Amazon CloudWatch Events (now Amazon EventBridge), publishing real-time events such as DDoSDetected, AwsShibboleth, and AwsServiceEventNotification. Rather than polling or manual monitoring, you create a CloudWatch Events rule that matches these Shield event types and sets an AWS Lambda function as its target; the Lambda function then formats the event detail and publishes a message to an Amazon SNS topic, enabling timely notifications to your incident-response team. This pattern is the documented, reliable way to automate responses to Shield Advanced findings because it puts the filtering and routing logic in the event bus, not in the notification channel itself.

Why this answer

AWS Shield Advanced integrates with Amazon CloudWatch Events (now Amazon EventBridge) to emit events when DDoS attacks are detected. The standard pattern is to create an EventBridge rule that matches Shield Advanced events and triggers a Lambda function, which then publishes to an SNS topic for real-time notification. This is the documented, supported mechanism for proactive DDoS alerting.

Exam trap

SCS-C02 often tests the misconception that Shield Advanced can publish directly to SNS or that CloudTrail/VPC Flow Logs can detect DDoS events, when EventBridge is the required integration point.

How to eliminate wrong answers

Option B is wrong because VPC Flow Logs capture IP traffic metadata but do not detect or identify DDoS attacks; a high-traffic alarm is a crude proxy that generates false positives and misses attack signatures. Option C is wrong because Shield Advanced does not natively publish directly to SNS topics; it emits events to EventBridge, which must be routed. Option D is wrong because CloudTrail records API activity, not DDoS attack events; metric filters on CloudTrail cannot detect network-layer attacks.

19
Multi-Selectmedium

Which THREE AWS services can be used to detect potentially compromised EC2 instances? (Choose 3.)

Select 3 answers
A.AWS WAF
B.VPC Flow Logs
C.AWS Shield
D.Amazon GuardDuty
E.Amazon Inspector
AnswersB, D, E

VPC Flow Logs record source/destination IPs, ports, and protocol for all traffic in a VPC. Anomalies such as outbound calls to known threat-intel IPs, repeated failed connection attempts, or large data transfers can signal a compromised EC2 instance. However, Flow Logs are raw metadata requiring additional analytics (e.g., Athena queries) to surface threats.

Why this answer

VPC Flow Logs (B) capture IP traffic metadata for ENIs, so you can analyze accepted/rejected flows for signs of compromise such as beaconing to known-bad IPs or unusual outbound traffic. Amazon GuardDuty (D) is a managed threat-detection service that continuously analyzes VPC Flow Logs, CloudTrail events, and DNS logs to identify compromised instances via findings like cryptocurrency mining or communication with malicious hosts. Amazon Inspector (E) scans EC2 instances for software vulnerabilities and unintended network exposure, which helps detect an instance that could be or has been compromised through an exploitable weakness.

AWS WAF (A) is a Layer 7 web application firewall that filters HTTP(S) requests to CloudFront, ALB, or API Gateway, not an EC2 compromise-detection service. AWS Shield (C) provides DDoS protection at the network/transport layer and does not detect compromised EC2 instances.

Exam trap

The trap here is that candidates often confuse AWS WAF (a web-layer filter) or AWS Shield (a DDoS mitigator) with detective services, when the question specifically asks for services that *detect* compromised instances—not prevent attacks or filter traffic.

20
MCQhard

A company uses AWS WAF to protect its web application from common web exploits. The security team wants to block requests that contain SQL injection or cross-site scripting (XSS) in the query string. Which rule type should be used?

A.Custom regex pattern set
B.Managed rule group for SQL injection and XSS
C.Rate-based rule
D.Geographic match rule
AnswerB

AWS WAF managed rule groups such as AWSManagedRulesSQLiRuleSet and AWSManagedRulesCommonRuleSet are purpose-built to detect SQL injection (SQLi) and cross-site scripting (XSS) using context-aware inspection that decodes and normalizes the request. Unlike simple regex matching, these rule groups apply heuristic and signature-based analysis that catches encoded payloads, comment obfuscation, and case variations, and AWS continuously updates them to address new evasion techniques, making them the appropriate, low-maintenance solution for this threat.

Why this answer

AWS WAF managed rule groups, such as the AWS-AWSManagedRulesSQLiRuleSet and AWS-AWSManagedRulesXSSRuleSet, are pre-configured to inspect query strings for SQL injection and cross-site scripting (XSS) patterns. Using a managed rule group is the most efficient and accurate approach because it leverages AWS's continuously updated threat signatures, reducing false positives and administrative overhead compared to custom rules.

Exam trap

The trap here is that candidates may think custom regex rules are necessary for precise control, but AWS WAF managed rule groups are specifically designed to handle SQL injection and XSS with higher accuracy and lower maintenance, making them the recommended choice for this use case.

How to eliminate wrong answers

Option A is wrong because custom regex pattern sets require manual definition of patterns for SQL injection and XSS, which is error-prone, difficult to maintain, and may miss obfuscated attack vectors that managed rules handle. Option C is wrong because rate-based rules are designed to block excessive request rates (e.g., DDoS) and do not inspect query string content for SQLi or XSS. Option D is wrong because geographic match rules filter traffic based on the requester's country or region, not on the content of the query string.

21
MCQmedium

A company wants to allow an IAM user to manage only their own access keys. Which IAM policy should be attached to the user?

A.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"iam:*AccessKey*","Resource":"arn:aws:iam::*:user/*"}]}
B.{"Version":"2012-10-17","Statement":[{"Effect":"Deny","Action":"iam:*AccessKey*","Resource":"*"}]}
C.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"iam:*AccessKey*","Resource":"arn:aws:iam::*:user/${aws:username}"}]}
D.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"iam:*AccessKey*","Resource":"*"}]}
AnswerC

This statement is correct because the resource ARN uses the ${aws:username} variable, which automatically resolves to the IAM user name making the API call. The resulting ARN matches only that user's own IAM user resource, restricting CreateAccessKey, UpdateAccessKey, DeleteAccessKey, and similar key actions to the caller's own keys. This is the standard pattern for delegating self-service access key management while preserving separation of duties.

Why this answer

The IAM policy uses the ${aws:username} variable in the Resource element. When this policy is attached to a user, ${aws:username} resolves to that user's username, thereby restricting the actions to only that user's own access keys. Option A allows access to all users' keys.

Option B denies all AccessKey actions. Option D allows all AccessKey actions without restriction.

22
MCQmedium

A security engineer is configuring AWS KMS to encrypt data in a new Amazon S3 bucket. The company requires that the KMS key used for encryption automatically rotate its key material every year, and that the rotation be transparent to applications. The engineer creates a customer managed key with key spec SYMMETRIC_DEFAULT and key usage ENCRYPT_DECRYPT. What should the engineer do next to meet the requirement?

A.Enable automatic key rotation on the customer managed key.
B.Enable automatic key rotation on the AWS managed key aws/s3.
C.Use an asymmetric KMS key with RSA_2048 and enable automatic rotation.
D.Create a new customer managed key each year and update the S3 bucket policy to use the new key.
AnswerA

Automatic key rotation is a feature of AWS KMS customer managed keys that rotates the backing key material annually while retaining the same key ID and ARN. Applications continue to use the same key identifier, and AWS KMS automatically uses the new material for new encryption operations. This meets the requirement for transparent yearly rotation without application changes. The rotation is managed by AWS KMS and requires no additional infrastructure.

Why this answer

AWS KMS customer managed symmetric keys support automatic annual rotation of the backing key material while preserving the same key ID and ARN. This allows existing applications and policies to continue using the key without modification. Enabling automatic rotation satisfies the requirement for transparent yearly rotation.

Other options either require manual key replacement, use a key type that does not support rotation, or rely on an AWS managed key that cannot be configured by the customer.

Exam trap

The trap here is assuming that automatic key rotation changes the key ID or ARN, or that it is available for all key types.

23
MCQhard

A company uses AWS CloudHSM to generate and store encryption keys for a custom application. The security team needs to ensure high availability and durability of the keys. Which architecture should be recommended?

A.Use AWS KMS instead of CloudHSM for better durability
B.Deploy a single CloudHSM instance in one Availability Zone
C.Deploy CloudHSM in two AWS Regions with automatic replication
D.Deploy a CloudHSM cluster with at least two HSMs in different Availability Zones
AnswerD

Creating a CloudHSM cluster with at least two HSMs in different Availability Zones ensures that if one HSM or AZ becomes unavailable, the other HSM can continue serving cryptographic operations. CloudHSM automatically synchronizes users, keys, and policies across all HSMs in the cluster, so the remaining HSM has the same key material. This architecture provides redundancy, high availability, and aligns with AWS recommended best practices for CloudHSM. Hence, it is the correct answer for improving durability/availability while keeping the HSM-based control.

Why this answer

Deploying a CloudHSM cluster with at least two HSMs in different Availability Zones provides high availability and durability. CloudHSM automatically synchronizes keys across HSMs in the cluster, so if one HSM fails, the others continue to provide access to the keys.

Exam trap

SCS-C02 often tests the misconception that CloudHSM automatically replicates across regions, but it does not; candidates may also think that a single HSM is sufficient for high availability.

How to eliminate wrong answers

Option A is wrong because while KMS provides high durability, the requirement is to use CloudHSM for key generation and storage, so switching to KMS does not meet the requirement. Option B is wrong because a single HSM in one AZ is a single point of failure and does not provide high availability. Option C is wrong because CloudHSM does not support automatic replication across regions; you must manually copy keys or use other methods, and cross-region replication is not automatic.

24
Multi-Selecthard

A company is designing a data protection strategy for Amazon S3. The compliance team requires that all objects be encrypted at rest and that any attempt to upload an unencrypted object be blocked. Which TWO steps should the company take? (Choose TWO.)

Select 2 answers
A.Enable default encryption on the bucket with SSE-S3 or SSE-KMS.
B.Add a bucket policy that denies s3:PutObject unless the request includes the x-amz-server-side-encryption header.
C.Enable S3 Object Lock.
D.Enable S3 Transfer Acceleration.
E.Enable S3 Block Public Access.
AnswersA, B

Enabling default encryption on the bucket with SSE-S3 or SSE-KMS ensures every object placed in S3 is automatically encrypted at rest, even if the client does not send an encryption header. SSE-S3 uses AES-256 managed by AWS, while SSE-KMS uses envelope encryption with a customer-managed KMS key, giving you auditability, key rotation, and fine-grained access control. This is the simplest baseline measure to satisfy typical encryption-at-rest requirements for a new S3 data protection strategy.

Why this answer

Option A is correct because enabling default encryption on the bucket with SSE-S3 or SSE-KMS ensures that every object stored in the bucket is automatically encrypted at rest, satisfying the compliance requirement for encryption of all objects. Option B is correct because a bucket policy that denies s3:PutObject unless the request includes the x-amz-server-side-encryption header actively blocks any attempt to upload an object without server-side encryption, enforcing encryption at upload time. Together, these two steps provide both automatic encryption and a preventive control against unencrypted uploads.

Option C is not correct because S3 Object Lock provides WORM protection and retention, not encryption enforcement. Option D is not correct because S3 Transfer Acceleration only improves upload performance over long distances. Option E is not correct because S3 Block Public Access prevents public exposure of objects, not unencrypted uploads.

Exam trap

SCS-C02 often tests the difference between default encryption and enforced encryption, and candidates may think that enabling default encryption alone blocks unencrypted uploads, but it does not; a bucket policy is required to deny unencrypted PUT requests.

25
MCQhard

A company uses AWS Secrets Manager to store database credentials. The security team needs to ensure that secrets are automatically rotated every 30 days. The rotation function must be implemented with minimal operational overhead. Which approach should be used?

A.Create an Amazon EventBridge rule that triggers a Lambda function to rotate the secret
B.Use AWS CLI to schedule a cron job that runs every 30 days and rotates the secret
C.Use Amazon CloudWatch Events to invoke an AWS Lambda function that updates the secret
D.Enable automatic rotation in Secrets Manager and configure the rotation interval to 30 days
AnswerD

Enabling automatic rotation in Secrets Manager with a 30-day interval is the correct managed solution. Secrets Manager schedules the rotation, invokes the configured Lambda rotation function, and coordinates the change of the database password with the secret's version lifecycle using AWSCURRENT and AWSPREVIOUS staging labels. You simply choose the rotation interval, and the service handles all scheduling, retries, and permissions, providing the lowest operational overhead. This also works with common database services like RDS via the built-in rotation templates.

Why this answer

AWS Secrets Manager has native, built-in rotation support that requires only enabling rotation and specifying a rotation interval and a Lambda rotation function (AWS provides templates for RDS, Redshift, DocumentDB, etc.). Setting the interval to 30 days satisfies the requirement with the least operational overhead because Secrets Manager manages the schedule, invokes the Lambda, and updates the secret version automatically.

Exam trap

SCS-C02 often tests the misconception that you must build custom Lambda/EventBridge automation for rotation, when Secrets Manager's native rotation feature already handles scheduling and versioning.

How to eliminate wrong answers

Option A is wrong because building a custom EventBridge rule plus Lambda duplicates functionality that Secrets Manager already provides natively, adding unnecessary operational overhead. Option B is wrong because a CLI cron job running on an EC2 instance or on-prem host introduces a server to maintain, lacks HA, and does not integrate with Secrets Manager's versioning or staging labels. Option C is wrong because CloudWatch Events (now EventBridge) invoking a Lambda is essentially the same custom approach as option A and ignores the built-in rotation feature.

26
MCQhard

A company has a security group that allows inbound SSH from a specific IP range. A security engineer notices that the security group rule is not being applied to a newly launched EC2 instance. What is the most likely cause?

A.The new EC2 instance was not launched with the correct security group
B.The security group is using the default VPC security group
C.The security group is configured as stateless
D.The network ACL is blocking SSH traffic to the subnet
AnswerA

If the new instance was launched without appending the security group that contains the SSH rule, or was attached to a different security group, the rule never applies to that instance. Security group membership is determined at launch time for the primary ENI, and editing rules on the intended group only affects instances that are actually associated with it. To resolve this, you must attach the correct security group to the running instance or relaunch with the right group selected.

Why this answer

The most likely cause is that the new EC2 instance was not launched with the correct security group. Security groups act as virtual firewalls for instances, and an instance can only be associated with security groups at launch time. If the engineer launched the instance without explicitly selecting the security group that allows inbound SSH from the specific IP range, the instance would default to the VPC's default security group, which typically does not have the same custom SSH rule.

This is a common operational oversight when automating or manually launching instances.

Exam trap

The trap here is that candidates often confuse security group statefulness with network ACL statelessness, or assume that a security group rule applies automatically to all instances in a VPC, when in fact each instance must be explicitly associated with the correct security group at launch.

How to eliminate wrong answers

Option B is wrong because using the default VPC security group is a symptom of not selecting the correct security group, not a separate cause; the default group itself can be modified to allow SSH, but the question states the rule is not being applied, implying the instance is associated with a group lacking that rule. Option C is wrong because security groups are stateful by design (they automatically allow return traffic), and the stateless/stateful distinction applies to network ACLs, not security groups; a stateless security group does not exist in AWS. Option D is wrong because network ACLs operate at the subnet level and can block SSH, but the question specifies that the security group rule is not being applied, which points to a misconfiguration at the instance-level firewall (security group), not the subnet-level ACL; additionally, network ACLs are stateless and would affect all instances in the subnet, not just the newly launched one.

27
Drag & Dropmedium

Drag and drop the steps to set up AWS Certificate Manager (ACM) for a custom domain in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

ACM certificate requires request, DNS validation, issuance, association, and automatic renewal.

28
MCQmedium

A company wants to protect data at rest in Amazon S3 using client-side encryption. The application will run on Amazon EC2 instances. Which approach meets these requirements?

A.Use SSE-S3 and rely on S3 to manage keys
B.Enable S3 default encryption on the bucket
C.Use SSE-KMS with a customer managed key
D.Use the AWS Encryption SDK to encrypt data before uploading to S3
AnswerD

The AWS Encryption SDK encrypts objects on the EC2 instance before upload, so plaintext never reaches S3 and keys remain outside AWS's control. This satisfies the stem's client-side encryption requirement for data at rest in S3.

Why this answer

Client-side encryption requires the encryption process to occur on the client side before data is uploaded to S3. The AWS Encryption SDK is designed for this purpose, allowing you to encrypt data locally on the EC2 instance using your own keys, ensuring that S3 never sees the plaintext data. This meets the requirement to protect data at rest with client-side encryption, as the data is encrypted before leaving the application environment.

Exam trap

The trap here is that candidates confuse server-side encryption options (SSE-S3, SSE-KMS) with client-side encryption, assuming that using a customer managed key (SSE-KMS) satisfies client-side requirements when it actually still encrypts data on the server side.

How to eliminate wrong answers

Option A is wrong because SSE-S3 is a server-side encryption method where S3 manages the keys and encrypts data after it is received, not client-side encryption. Option B is wrong because enabling S3 default encryption on the bucket applies server-side encryption (SSE-S3 or SSE-KMS) to objects at the time of upload, not client-side encryption. Option C is wrong because SSE-KMS with a customer managed key is still server-side encryption; the encryption happens on the S3 side after the data is transmitted, not on the client side.

29
MCQhard

A company runs a critical web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application processes sensitive customer data. The Security team has enabled VPC Flow Logs, CloudTrail, and GuardDuty. Recently, the team received a GuardDuty finding indicating a potential SSH brute force attack originating from an external IP address 203.0.113.50 targeting one of the EC2 instances. The Security Engineer needs to automatically isolate the affected instance and capture forensic evidence for analysis. The company has strict requirements: the instance must be isolated immediately, and a snapshot of the EBS volume must be taken before any remediation actions are taken. The instance is part of an Auto Scaling group, and the Security Engineer wants to minimize manual intervention. The Security Engineer has access to AWS Systems Manager and AWS Lambda. Which combination of steps should the Security Engineer implement to meet the requirements?

A.Use AWS Systems Manager to automatically connect to the instance via EC2 Instance Connect, run commands to capture forensic data, and then modify the security group to deny all inbound traffic.
B.Create a CloudWatch Logs metric filter on the VPC Flow Logs for the attacker IP. When the metric breaches a threshold, trigger an SNS topic that runs an AWS Systems Manager Automation document to isolate the instance and take an EBS snapshot.
C.Configure Amazon EventBridge to detect the GuardDuty finding and invoke an AWS Lambda function. The Lambda function first calls the EC2 CreateSnapshot API to capture a forensic snapshot of the instance's EBS volume. Then, it uses AWS Systems Manager Automation to run a pre-defined automation document that isolates the instance by modifying the instance's security group to only allow traffic from a trusted management IP, and then stops the instance.
D.Configure a CloudWatch Events rule to detect the GuardDuty finding and invoke an AWS Lambda function. The Lambda function terminates the EC2 instance and then takes a snapshot of the EBS volume for forensic analysis.
AnswerC

This is the correct automated response because Amazon EventBridge natively receives GuardDuty findings and can invoke a Lambda function as a target. The Lambda function first calls the EC2 CreateSnapshot API, ensuring a forensic copy of the EBS volume is preserved before any state changes. Then, instead of terminating the instance, it uses AWS Systems Manager Automation with a predefined document to modify the security group to allow only the trusted management IP, and finally stops the instance—which preserves the instance for further analysis and minimizes the risk of losing evidence.

Why this answer

It uses EventBridge to directly detect the GuardDuty finding, which triggers a Lambda function that first takes an EBS snapshot (forensic capture) via the CreateSnapshot API before any remediation. Then it uses Systems Manager Automation to isolate the instance by modifying the security group to allow only a trusted management IP and stops the instance, ensuring isolation without destroying the instance. This sequence satisfies the strict requirement that a snapshot must be taken before any remediation actions, and it minimizes manual intervention by automating the entire response.

Exam trap

The trap here is that candidates may choose Option D because they think termination is the fastest way to stop the attack, but they overlook the requirement to capture forensic evidence before remediation—termination destroys the instance and prevents a proper snapshot of the running state.

How to eliminate wrong answers

Option A is wrong because it relies on EC2 Instance Connect to manually connect and run commands, which is not automated and does not ensure a snapshot is taken before isolation; modifying the security group after connecting does not guarantee the snapshot requirement is met. Option B is wrong because it uses a CloudWatch Logs metric filter on VPC Flow Logs for the attacker IP, which is an indirect detection method that may have latency and does not directly respond to the GuardDuty finding; it also does not specify taking an EBS snapshot before isolation. Option D is wrong because it terminates the EC2 instance first, which destroys the running instance and may prevent capturing volatile forensic data; the snapshot is taken after termination, violating the requirement to capture forensic evidence before remediation actions.

30
MCQhard

A company uses Amazon GuardDuty and AWS Security Hub. The security team has configured a custom insight in Security Hub to track findings related to S3 bucket exposures. They want to automatically remediate these findings by applying an S3 bucket policy that blocks public access. The team has created a Lambda function that applies the bucket policy and configured Security Hub to send findings to the Lambda function via a custom action. However, when a new finding is generated, the Lambda function is invoked but fails to apply the policy because it does not have permission to modify the S3 bucket. The Lambda function's execution role has permissions to modify S3 bucket policies, but the function is in the same account as the bucket. What should the team check?

A.Add the Lambda function's execution role to the bucket's Access Control List (ACL).
B.Ensure that the Lambda function's execution role has a trust policy that allows Security Hub to assume it.
C.Check the S3 bucket policy for any explicit deny statements that might block the Lambda function's role.
D.Verify that the S3 bucket's block public access settings are not preventing the policy update.
AnswerC

An explicit `Deny` in the bucket policy overrides the execution role's `Allow`, so the Lambda invocation fails despite having `s3:PutBucketPolicy`. Because the function and bucket share an account, cross-account trust is irrelevant; the blocking constraint is the bucket policy's explicit deny, which must be reviewed and removed.

Why this answer

The Lambda function's execution role already has IAM permissions to modify S3 bucket policies, and it operates in the same account as the bucket, so cross-account trust is not the issue. An explicit Deny statement in the S3 bucket policy overrides any Allow granted by IAM policies, including the Lambda role's permissions. Therefore, the team must inspect the bucket policy for explicit denies that block the role from calling PutBucketPolicy.

This is the only remaining cause consistent with the symptoms.

Exam trap

SCS-C02 often tests the misconception that IAM permissions alone determine access, causing candidates to overlook explicit Deny statements in resource-based policies like S3 bucket policies, which override any Allow.

How to eliminate wrong answers

Option A is wrong because S3 ACLs control access to objects and buckets for certain legacy or cross-account scenarios, not IAM role permissions for API actions like PutBucketPolicy; adding a role to an ACL is not a supported or effective way to grant policy-modification rights. Option B is wrong because Security Hub does not assume the Lambda execution role; it invokes the function via a custom action, and the function then uses its own execution role to call S3, so a trust policy for Security Hub is irrelevant. Option D is wrong because S3 Block Public Access settings prevent making buckets or objects public, but they do not prevent an authorized principal from updating a bucket policy; the Lambda role's PutBucketPolicy call would still be allowed unless an explicit deny exists.

31
Multi-Selecthard

A company uses AWS Organizations and wants to implement a centralized incident response process. Which THREE steps should be taken to ensure that security teams can respond to incidents across all accounts effectively?

Select 3 answers
A.Create IAM roles in each member account that grant incident responders cross-account access from the security account
B.Set up AWS Systems Manager Incident Manager in each account independently
C.Create a single CloudTrail trail in the management account to log events from all accounts
D.Configure a centralized S3 bucket to store CloudTrail logs from all accounts using an organization trail
E.Designate a delegated administrator account for Amazon GuardDuty to centralize threat detection findings
AnswersA, D, E

Creating IAM roles in each member account that allow incident responders in the security account to assume those roles is a standard centralized access pattern. This grants the responders the exact permissions needed to investigate and remediate incidents in any affected account, while maintaining least privilege and full auditability. It avoids the need for shared credentials or per-account logins, and ensures that every cross-account assumption is recorded in CloudTrail for accountability.

Why this answer

Creating IAM roles in each member account with trust policies that allow the security account's incident responders to assume those roles enables centralized, cross-account access for incident response. This follows the principle of least privilege and allows the security team to perform actions (e.g., stopping instances, collecting forensic data) in any affected account without needing separate credentials or direct logins.

Exam trap

The trap here is that candidates often think a single CloudTrail trail in the management account automatically aggregates logs from all accounts, but without configuring it as an organization trail (which requires enabling trusted access and specifying the organization ID), it only logs events from the management account itself.

32
MCQeasy

A security engineer needs to audit all changes to AWS resources in an account. Which AWS service should be enabled?

A.Amazon Inspector
B.AWS CloudTrail
C.AWS Config
D.Amazon GuardDuty
AnswerB

AWS CloudTrail records every AWS API call as an event, capturing the identity of the caller, the source IP address, the request parameters, and the response elements. For an audit of all resource changes, CloudTrail is the authoritative source because nearly every modification to an AWS resource is implemented through a management-plane API call that gets logged.

Why this answer

AWS CloudTrail is the correct service because it records API activity and changes to AWS resources as events, providing an audit log of who made what change, when, and from where. This directly meets the requirement to audit all changes, as every AWS API call (e.g., CreateInstance, ModifySecurityGroup) is captured in a CloudTrail event history or delivered to an S3 bucket for long-term analysis.

Exam trap

The trap here is that candidates confuse AWS Config's configuration tracking (which shows what changed) with CloudTrail's API audit trail (which shows who changed it and how), leading them to pick AWS Config when the question explicitly asks for auditing all changes, which requires the API-level logging only CloudTrail provides.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability assessment service that scans EC2 instances and container images for software vulnerabilities and unintended network exposure, not a change audit service. Option C is wrong because AWS Config evaluates resource configurations against desired rules and tracks configuration changes over time, but it does not capture who made the change or the API call details—it focuses on resource state, not the API audit trail. Option D is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events for malicious activity, not a service that audits all resource changes.

33
MCQeasy

A company wants to protect data in transit between an EC2 instance and an S3 bucket. Which method should be used?

A.Use a VPN connection with IPsec
B.Install an SSL certificate on the EC2 instance
C.Use SSH to transfer files
D.Use HTTPS endpoints for S3 API calls
AnswerD

Using HTTPS endpoints for S3 API calls means every request and response is encrypted with TLS, preventing attackers from reading or tampering with data in transit between an EC2 instance and S3. All AWS SDKs and the AWS CLI are configured to use HTTPS by default when sending S3 operations, and S3's TLS endpoints provide server authentication via AWS-managed certificates. This is the correct, native mechanism to meet the data-in-transit protection requirement for EC2-to-S3 communication.

Why this answer

To protect data in transit between an EC2 instance and an S3 bucket, you must use HTTPS endpoints for S3 API calls, which encrypts traffic using TLS. S3 supports HTTPS natively via its REST API endpoints, and this is the standard method to ensure encryption in transit for S3 access from EC2.

Exam trap

SCS-C02 often tests the confusion between network-layer encryption (VPN/IPsec) and application-layer TLS, leading candidates to choose VPN when the question specifically asks about protecting S3 API traffic.

How to eliminate wrong answers

Option A is wrong because a VPN with IPsec encrypts traffic at the network layer between sites or VPCs, but it does not provide the application-layer TLS encryption required for S3 API calls and is not the recommended method for securing EC2-to-S3 traffic. Option B is wrong because installing an SSL certificate on the EC2 instance secures inbound connections to that instance, not outbound API calls to S3 — the certificate must be on the S3 endpoint side, which AWS already manages. Option C is wrong because SSH is used for remote shell access and SFTP, not for S3 API operations; S3 does not support SSH as a transfer protocol.

34
MCQeasy

An administrator needs to grant an IAM user the ability to change their own password without allowing them to change other users' passwords. Which IAM action should be included in the policy?

A.iam:CreateLoginProfile
B.iam:UpdateAccountPasswordPolicy
C.iam:UpdateServiceSpecificCredential
D.iam:ChangePassword
AnswerD

iam:ChangePassword is the precise self-service action that enables a user to update their own console password (or password used for programmatic access via the password-based APIs). When a user calls ChangePassword, IAM verifies the existing password and then replaces it, with the permission scoped to the principal's own identity. It is the only action among these options that directly corresponds to the requirement of letting a user change their own password.

Why this answer

The IAM action iam:ChangePassword allows a user to change their own password, but only if the policy is attached to that user and the request is for their own password. It does not grant permission to change other users' passwords. This is the correct action for self-service password change.

Exam trap

SCS-C02 often tests the confusion between iam:ChangePassword (self-service) and iam:CreateLoginProfile (admin creating password for others), causing candidates to pick the admin action.

How to eliminate wrong answers

Option A is wrong because iam:CreateLoginProfile is used to create a password for a user, typically an admin action for other users. Option B is wrong because iam:UpdateAccountPasswordPolicy is for setting the account password policy, an admin-level action. Option C is wrong because iam:UpdateServiceSpecificCredential is for managing service-specific credentials (e.g., for CodeCommit), not for console passwords.

35
MCQmedium

A company uses AWS KMS to manage encryption keys for sensitive data stored in S3. The security team wants to ensure that keys are rotated automatically every year. What should they do?

A.Enable automatic key rotation on a customer managed key.
B.Use a custom key store and rotate keys manually.
C.Use a CloudHSM to store keys and rotate them manually.
D.Use an AWS managed key, which rotates automatically every year.
AnswerA

Enabling automatic key rotation on a customer managed key lets AWS KMS rotate the backing key material annually without changing the key ID or ARN, so existing ciphertext and applications continue working. This satisfies the yearly rotation requirement.

Why this answer

Automatic key rotation is a native feature of AWS KMS customer managed keys (CMKs). Enabling it causes KMS to generate new backing key material every year (or a custom period of 90-2560 days) while retaining the same key ID, so existing ciphertext remains decryptable without re-encryption. This satisfies the 'rotate automatically every year' requirement with no manual intervention.

Exam trap

SCS-C02 often tests the distinction between customer managed keys (configurable rotation) and AWS managed keys (automatic but not controllable) — candidates who pick the AWS managed key option miss the governance requirement.

How to eliminate wrong answers

Option B is wrong because a custom key store backed by CloudHSM does not support automatic rotation — rotation must be performed manually, which contradicts the requirement. Option C is wrong for the same reason: CloudHSM-stored keys require manual rotation and add operational overhead. Option D is wrong because AWS managed keys do rotate automatically every year, but the security team cannot control or audit the rotation schedule, and AWS managed keys cannot be used for cross-account access or custom key policies — customer managed keys are the correct choice for a security team that needs governance.

36
MCQmedium

A company is using AWS CloudTrail to log API calls. The security team needs to ensure that log files are not tampered with and can be used to verify integrity. Which feature should be enabled?

A.Enable MFA delete on the log bucket.
B.Enable log file integrity validation in CloudTrail.
C.Enable server-side encryption with AWS KMS on the log bucket.
D.Enable S3 versioning on the log bucket.
AnswerB

CloudTrail log file integrity validation employs a SHA-256 hash chain to detect any modification, deletion, or forgery of log files. CloudTrail periodically creates signed digest files that list the hash of every log file delivered in that period along with the hash of the previous digest, and each digest is signed with a private key held by AWS. You can verify the signature using the publicly available key and recompute hashes to confirm the logs have not been altered, which directly addresses the need to ensure the API call history is trustworthy and tamper-evident.

Why this answer

CloudTrail log file integrity validation uses a hash chain (SHA-256) to create a digest file that proves log files have not been modified, deleted, or tampered with since delivery. This feature allows you to verify that CloudTrail log files have remained unchanged, meeting the security team's requirement for integrity verification.

Exam trap

The trap here is that candidates often confuse data protection features (encryption, versioning, MFA delete) with integrity verification, which specifically requires cryptographic hash validation to detect tampering.

How to eliminate wrong answers

Option A is wrong because MFA delete on the S3 bucket protects against accidental or unauthorized deletion of objects, but does not provide cryptographic verification of log file integrity. Option C is wrong because server-side encryption with AWS KMS protects data at rest from unauthorized access, but does not provide a mechanism to detect tampering or verify that log files have not been altered. Option D is wrong because S3 versioning preserves previous versions of objects to protect against overwrites and deletions, but does not offer cryptographic proof of file integrity or tamper detection.

37
MCQeasy

A security engineer is reviewing a CloudTrail log entry (exhibit). What is the most immediate security concern indicated by this event?

A.The source IP address 203.0.113.5 is from a known malicious IP range.
B.A security group rule was added allowing SSH access from any IP address.
C.The API call was made from the AWS CLI, which may indicate a compromised access key.
D.The user JohnDoe did not use multi-factor authentication (MFA) for this API call.
AnswerB

The CloudTrail event shows eventName AuthorizeSecurityGroupIngress with request parameters that add a security group ingress rule. Specifically, it opens port 22 (SSH) to 0.0.0.0/0, meaning all IPv4 addresses on the internet can attempt SSH connections to the associated EC2 instance. This is a well-known misconfiguration that exposes administrative access externally and is the correct security finding to investigate.

Why this answer

The CloudTrail log shows an AuthorizeSecurityGroupIngress API call that added a security group rule with the CIDR 0.0.0.0/0 for port 22 (SSH). This effectively opens SSH access to the entire internet, creating a severe exposure that could allow any attacker to attempt brute-force or credential-stuffing attacks against any EC2 instance associated with that security group. This is the most immediate security concern because it directly introduces a wide-open attack surface.

Exam trap

The trap here is that candidates focus on the user identity or authentication details (like MFA or CLI usage) instead of recognizing that the actual API action—opening SSH to 0.0.0.0/0—is the most immediate and dangerous security concern.

How to eliminate wrong answers

Option A is wrong because the source IP 203.0.113.5 is a TEST-NET-1 address (RFC 5735) reserved for documentation and examples, not a known malicious IP range; real CloudTrail logs would show a routable IP. Option C is wrong because the event source is 'ec2.amazonaws.com' and the user agent indicates the AWS Management Console, not the AWS CLI; a CLI call would show 'aws-cli' or 'botocore' in the user agent field. Option D is wrong because while MFA is a best practice, the absence of MFA alone is not the most immediate concern—the critical issue is the actual security group rule change that opens SSH to the world, not the authentication method used for the API call.

38
Multi-Selecthard

Which THREE are benefits of using AWS CloudTrail for security governance? (Choose three.)

Select 3 answers
A.Enables real-time log analysis with Amazon CloudWatch Logs
B.Automatically remediates noncompliant resources
C.Supports compliance audits by providing event history
D.Provides a record of API activity in the account
E.Allows security analysis of user activity
AnswersC, D, E

CloudTrail’s event history is designed as a durable, tamper-evident record of account activity, which auditors can use as evidence for compliance controls. It captures management events for 90 days in the console and can deliver to S3 or CloudTrail Lake for long-term retention, enabling organizations to satisfy audit requirements across frameworks like SOC 2, PCI DSS, and HIPAA. This audit trail is a core reason CloudTrail is considered essential for compliance.

Why this answer

Option C is correct because CloudTrail retains a searchable history of management and data events that auditors can use to demonstrate who did what and when, satisfying compliance audit requirements. Option D is correct because CloudTrail's core function is to record AWS API activity (management events, and optionally data and insight events) in the account and deliver them as log files to Amazon S3 and/or CloudWatch Logs. Option E is correct because those API activity records include the identity (IAM user, role, federated user) and source IP, enabling security teams to analyze user behavior and detect anomalous or unauthorized actions.

Option A is not correct as stated because CloudTrail itself does not perform real-time log analysis; it can deliver events to CloudWatch Logs, but the analysis is done by CloudWatch Logs metric filters/alarms, not by CloudTrail. Option B is not correct because CloudTrail is an auditing and logging service and does not automatically remediate noncompliant resources; remediation requires services such as AWS Config rules with remediation actions or Lambda-based automation.

Exam trap

SCS-C02 often tests CloudTrail benefits, and candidates may incorrectly select real-time analysis or automatic remediation, which are not native CloudTrail features.

39
MCQmedium

A company wants to ensure that all S3 buckets in their AWS account have encryption enabled. Which AWS service can continuously evaluate compliance and automatically remediate non-compliant buckets?

A.AWS CloudTrail
B.AWS Config
C.AWS IAM
D.Amazon S3
AnswerB

AWS Config continuously records the configuration of each S3 bucket and evaluates the recorded state against managed rules such as s3-bucket-server-side-encryption-enabled. When a bucket is noncompliant, Config can trigger Auto Remediation via a Systems Manager Automation document to append or modify the bucket's encryption configuration. This works on existing buckets in near-real time, and also on any new bucket created, making it a direct enforcement mechanism.

Why this answer

AWS Config is the service that continuously evaluates resource configurations against desired policies and can automatically remediate non-compliant resources. It can monitor S3 bucket encryption settings and trigger remediation actions (e.g., via SSM Automation) to enable encryption. AWS Config rules can be configured to check for encryption and automatically remediate using remediation actions.

Exam trap

SCS-C02 often tests the difference between detective and preventive controls; candidates may choose CloudTrail for compliance monitoring, but CloudTrail only logs API calls and does not evaluate compliance or remediate.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity and does not evaluate compliance or remediate resources. Option C is wrong because AWS IAM manages identities and permissions, not continuous compliance evaluation of resource configurations. Option D is wrong because Amazon S3 itself does not provide continuous compliance evaluation or automatic remediation; it is the resource being monitored, not the monitoring service.

40
MCQeasy

A security engineer notices that an Amazon S3 bucket has been accessed from an IP address outside the company's allowed range. The engineer needs to identify the IAM user who made the request. Which AWS service should be used to find this information?

A.S3 server access logs
B.AWS CloudTrail
C.VPC Flow Logs
D.Amazon CloudWatch Logs
AnswerB

CloudTrail captures management-plane and (with data events) object-level API calls. Each event includes the IAM user, role, or federated user that made the request, along with source IP, access key, timestamp, and request/response details. For S3, enabling data events on the bucket records GetObject/PutObject with full caller identity, making it the definitive audit source for identifying which IAM principal performed an action.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to AWS services, including S3 operations, and captures the identity of the IAM user or role that made the request. By examining CloudTrail logs, the security engineer can find the specific IAM user associated with the source IP address that accessed the bucket, as CloudTrail logs include both the user identity and the source IP address for each event.

Exam trap

The trap here is that candidates often confuse S3 server access logs with CloudTrail, assuming that server access logs include IAM user details, when in fact they only log the requester's AWS account ID or anonymous access, not the specific IAM user identity.

How to eliminate wrong answers

Option A is wrong because S3 server access logs provide detailed records of requests made to an S3 bucket, including source IP and object accessed, but they do not include IAM user identity information; they only log the requester's AWS account ID or anonymous access, not the specific IAM user. Option C is wrong because VPC Flow Logs capture information about IP traffic to and from network interfaces within a VPC, but they do not log IAM user identity or API-level details; they only show network-level metadata such as source/destination IP, ports, and protocol. Option D is wrong because Amazon CloudWatch Logs is a service for storing, monitoring, and accessing log files, but it does not generate logs itself; it can be used to store CloudTrail logs or other logs, but it is not the service that records IAM user identity for S3 API calls.

41
MCQmedium

A company hosts a web application on EC2 instances behind an Application Load Balancer. The security team wants to ensure that only traffic from the ALB can reach the EC2 instances. Which configuration should be applied?

A.Configure the instances' security group to allow traffic from the ALB's security group.
B.Configure the instances' security group to allow traffic from the client's source IP addresses.
C.Configure a network ACL on the subnet to allow traffic from the ALB's private IP addresses.
D.Assign an IAM role to the instances that allows traffic only from the ALB.
AnswerA

Referencing the ALB's security group as the source in the instances' inbound rule allows traffic only from ENIs belonging to that group, and it tracks ALB IP changes automatically. This satisfies the requirement that only ALB traffic reaches the instances.

Why this answer

Security groups support referencing other security groups as a source. By configuring the EC2 instances' security group to allow inbound traffic from the ALB's security group, only traffic originating from the ALB (which uses the ALB's security group) is permitted. This ensures that traffic from any other source, including direct internet traffic, is blocked at the instance level.

Exam trap

The trap here is that candidates often confuse network ACLs (stateless, IP-based) with security groups (stateful, group-based) and mistakenly choose option C, not realizing that security group referencing is the correct and more secure method for this scenario.

How to eliminate wrong answers

Option B is wrong because allowing traffic from client source IP addresses would permit direct access to the EC2 instances, bypassing the ALB and defeating the purpose of restricting traffic to only the ALB. Option C is wrong because network ACLs are stateless and operate at the subnet level; they cannot reference security groups and would require manual management of ALB private IP addresses, which can change over time. Option D is wrong because IAM roles control API-level permissions for AWS services, not network traffic; they cannot filter or allow inbound traffic to EC2 instances.

42
MCQeasy

A company wants to encrypt data at rest for an Amazon S3 bucket. Which action should be taken?

A.Use client-side encryption before uploading objects.
B.Enable default encryption on the S3 bucket.
C.Enable SSL/TLS for the bucket.
D.Use AWS CloudHSM to encrypt the bucket.
AnswerB

Enabling default encryption on the S3 bucket automatically applies server-side encryption to every object written to it. You can choose SSE-S3 (AES-256) or SSE-KMS (with a customer managed CMK), and S3 encrypts objects at rest without any client-side changes. Any PUT request that omits encryption headers receives the bucket's default encryption, ensuring a consistent security posture for all stored data.

Why this answer

Enabling default encryption on the S3 bucket ensures that all objects stored in the bucket are automatically encrypted at rest using server-side encryption (SSE-S3, SSE-KMS, or SSE-C). This meets the requirement for encrypting data at rest without requiring any client-side changes, as the encryption is applied by S3 upon write.

Exam trap

The trap here is confusing encryption at rest (server-side encryption) with encryption in transit (SSL/TLS), leading candidates to select Option C, which only protects data during transfer, not while stored.

How to eliminate wrong answers

Option A is wrong because client-side encryption encrypts data before upload, which is a valid approach but not the action the question asks for—it requires client-side changes and does not leverage S3's native server-side encryption. Option C is wrong because SSL/TLS encrypts data in transit between the client and S3, not data at rest within the bucket. Option D is wrong because AWS CloudHSM provides hardware security modules for key storage and cryptographic operations, but it does not directly encrypt an S3 bucket; you would need to integrate it with AWS KMS (via custom key store) to use it for S3 server-side encryption, and even then the action is to enable default encryption with SSE-KMS, not to use CloudHSM directly.

43
MCQeasy

A company wants to protect sensitive data stored in Amazon S3 by encrypting it at rest. Which AWS service can be used to manage the encryption keys?

A.AWS Secrets Manager
B.AWS CloudHSM
C.AWS S3-managed keys (SSE-S3)
D.AWS Key Management Service (AWS KMS)
AnswerD

AWS KMS is a fully managed service for creating and controlling the encryption keys used across AWS services, and it natively integrates with Amazon S3 through SSE-KMS. You can create a customer managed key, define key policies and grants, set automatic annual rotation, and control access via IAM policies and key conditions. With envelope encryption, KMS protects each S3 object with a unique data key that is encrypted by your KMS key, allowing you to centrally manage, monitor, and revoke the master key while still receiving CloudTrail logs for every decrypt operation.

Why this answer

AWS Key Management Service (AWS KMS) is the AWS service designed to create, manage, rotate, and audit encryption keys used to protect data at rest in AWS services including Amazon S3. S3 server-side encryption with AWS KMS keys (SSE-KMS) integrates directly with KMS, giving the company centralized key management, granular IAM policies, key rotation, and CloudTrail audit logs of key usage. This is the correct answer for managing encryption keys for S3 data at rest.

Exam trap

SCS-C02 often tests the distinction between SSE-S3 (AWS-managed keys, no customer control) and SSE-KMS (customer-managed keys via KMS), and candidates must recognize that 'manage the encryption keys' implies KMS, not Secrets Manager or CloudHSM.

How to eliminate wrong answers

Option A is wrong because AWS Secrets Manager is for storing and rotating secrets such as database credentials and API keys, not for managing encryption keys for S3 data at rest. Option B is wrong because AWS CloudHSM is a dedicated hardware security module for customers with strict compliance requirements who need single-tenant key storage; it is overkill and not the standard service for S3 encryption key management. Option C is wrong because SSE-S3 uses S3-managed keys, which means AWS manages the keys entirely and the customer has no control over key management — the question asks which service can be used to manage the encryption keys, implying customer-managed control.

44
MCQmedium

A company runs a web application on Amazon EC2 instances that processes credit card data. The application must store the data in an encrypted format. The security team wants to minimize the performance impact of encryption and offload the encryption operations to a dedicated hardware security module (HSM). Which solution should the architect choose?

A.Use Amazon EBS encryption on the EC2 instance's root volume.
B.Use the Linux dm-crypt utility to encrypt the data at the application level.
C.Use AWS CloudHSM to perform encryption operations from the application.
D.Use AWS KMS with a customer-managed key to encrypt the data in the application.
AnswerC

CloudHSM provides a dedicated HSM, offloading encryption.

Why this answer

AWS CloudHSM provides dedicated hardware security modules that can perform cryptographic operations, including encryption, offloading the work from the application's CPU. It is designed for applications that require dedicated HSM hardware for compliance or performance reasons. Using CloudHSM allows the application to call the HSM for encryption, minimizing performance impact on the EC2 instance.

Exam trap

SCS-C02 often tests the confusion between AWS KMS and CloudHSM, where candidates think KMS provides dedicated HSM offload, but KMS is a multi-tenant service and does not offload encryption operations from the application.

How to eliminate wrong answers

Option A is wrong because EBS encryption encrypts data at rest on the volume but does not offload encryption operations to a dedicated HSM; it uses AWS-managed keys and the encryption is handled by the EC2 instance's CPU. Option B is wrong because dm-crypt is a software-based encryption tool that uses the instance's CPU, not a dedicated HSM. Option D is wrong because AWS KMS is a managed service that uses HSMs internally but does not provide a dedicated HSM for the application to offload encryption; KMS is for key management and encryption of small data, not for bulk encryption offload.

45
MCQeasy

A security team wants to detect unauthorized API calls in real time and automatically block the source IP address using network ACLs. Which AWS service should be used for detection?

A.Amazon GuardDuty
B.AWS CloudTrail
C.AWS WAF
D.AWS Config
AnswerA

Amazon GuardDuty continuously analyses CloudTrail management events, VPC Flow Logs and DNS logs using threat intelligence to surface findings such as unauthorised API calls. It satisfies the real-time detection constraint, and its findings can trigger EventBridge rules that invoke Lambda to update network ACLs, delivering the automated IP blocking the team requires.

Why this answer

Amazon GuardDuty is the correct choice because it is a threat detection service that continuously monitors for malicious activity and unauthorized behavior, including API calls from unusual or known-bad IP addresses. It uses machine learning, anomaly detection, and integrated threat intelligence to generate findings that can trigger automated remediation, such as updating network ACLs via AWS Lambda and Amazon EventBridge. This aligns with the requirement for real-time detection and automated blocking of source IPs.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail's logging capability with real-time threat detection, overlooking that GuardDuty is specifically designed for proactive security monitoring and automated response, while CloudTrail is purely a logging and auditing service.

How to eliminate wrong answers

Option B (AWS CloudTrail) is wrong because it is an auditing service that records API call history for compliance and governance, but it does not perform real-time threat detection or generate alerts for unauthorized activity; it lacks built-in anomaly detection or threat intelligence. Option C (AWS WAF) is wrong because it is a web application firewall that protects against common web exploits like SQL injection and cross-site scripting at the application layer, not for detecting unauthorized API calls or blocking IPs via network ACLs; it operates on HTTP/HTTPS traffic, not all API calls. Option D (AWS Config) is wrong because it is a configuration management and compliance service that evaluates resource configurations against rules, not a threat detection service; it cannot detect unauthorized API calls or trigger network ACL updates in real time.

46
MCQeasy

A security engineer needs to identify which IAM users have been inactive for the past 90 days. Which AWS service should the engineer use?

A.AWS IAM Credential Report
B.Amazon CloudWatch Logs
C.AWS Config
D.AWS CloudTrail
AnswerA

The IAM Credential Report is the purpose-built tool for this task because it generates a CSV containing every IAM user in the account along with password and access key metadata, including the last-used dates. By reviewing the 'password_last_used' and 'access_key_last_used' columns, you can immediately identify users who have never signed in or never used their keys. This report can also be refreshed programmatically via AWS CLI or the IAM console, making it the most direct audit mechanism.

Why this answer

AWS IAM Credential Report is the correct service because it provides a CSV report that lists all IAM users in an account and includes the `password_last_used` and `access_key_last_used_date` fields. By examining these fields, a security engineer can determine which users have not authenticated or used their access keys for more than 90 days, directly meeting the requirement to identify inactive IAM users.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which records API calls) with the IAM Credential Report, assuming CloudTrail can directly identify inactive users, but CloudTrail logs do not aggregate per-user last activity dates and require extensive post-processing to derive inactivity, whereas the Credential Report is the purpose-built, single-source solution for this exact use case.

How to eliminate wrong answers

Option B is wrong because Amazon CloudWatch Logs is used for monitoring, storing, and accessing log files from AWS resources, but it does not natively track IAM user activity or generate reports on user inactivity; it would require custom metric filters and logs from CloudTrail to infer inactivity, which is indirect and not the intended service. Option C is wrong because AWS Config is a service for evaluating resource configurations against desired policies and tracking configuration changes, not for tracking IAM user login activity or credential usage; it lacks the specific fields like `password_last_used` needed for inactivity analysis. Option D is wrong because AWS CloudTrail records API activity for auditing, but it does not provide a consolidated report of all IAM users' last activity dates; extracting inactive users from CloudTrail logs would require complex queries across millions of events and is not the purpose-built solution for this task.

47
Multi-Selectmedium

A security engineer is troubleshooting an issue where CloudTrail is not delivering logs to an S3 bucket. The bucket policy appears correct. Which TWO additional steps should the engineer take to diagnose the issue? (Choose TWO.)

Select 2 answers
A.Verify that the S3 bucket exists and is in the correct region.
B.Check CloudWatch Logs for CloudTrail errors.
C.Create an IAM role for CloudTrail with S3 write permissions.
D.Enable S3 server access logging on the bucket.
E.Review the CloudTrail configuration in the AWS Management Console for error messages.
AnswersA, E

CloudTrail can only write log files to an S3 bucket that already exists and is located in the same AWS Region as the trail. If the bucket was accidentally deleted, renamed, or created in another Region, every delivery attempt fails, and the trail's status shows a delivery error. Confirming this prerequisite is therefore the correct first troubleshooting step, because no policy or role change can compensate for a missing or misregioned destination.

Why this answer

If the S3 bucket does not exist or is in a different region, CloudTrail cannot deliver log files to it. CloudTrail requires the bucket to be in the same region as the trail (for a single-region trail) or in the designated bucket region for a multi-region trail. Verifying the bucket's existence and region ensures the delivery path is valid.

Option E is correct because the CloudTrail configuration in the AWS Management Console displays error messages related to delivery failures, such as bucket policy issues or permission errors. Reviewing this console can provide immediate insight into why logs are not being delivered, without needing to check other logs manually.

Exam trap

The trap here is that candidates often assume CloudTrail uses an IAM role for S3 access (like many other AWS services), but CloudTrail relies solely on a resource-based bucket policy, so creating an IAM role (Option C) is unnecessary and incorrect.

48
MCQmedium

A security engineer runs the IAM policy simulator with a custom policy. The output shows the above. Which statement is true about the policy?

A.The policy allows iam:DeleteUser but denies iam:CreateUser.
B.The policy allows all actions by default.
C.The policy contains a statement that explicitly denies iam:DeleteUser.
D.The policy has no effect because the simulator returned errors.
AnswerC

The simulator's explicitDeny result for iam:DeleteUser can only be produced by a Deny statement within the policy. In IAM's evaluation logic, an explicit Deny always overrides any Allow, making the action undeniably forbidden regardless of other permissions. This matches the correct interpretation of the simulation output, as the policy visibly contains a statement that rejects DeleteUser.

Why this answer

The policy simulator shows an explicit deny for iam:DeleteUser, confirming that a deny statement exists in the policy. Option C is correct because the explicit deny means the policy explicitly denies iam:DeleteUser. Option A is incorrect because the simulator does not indicate that iam:CreateUser is denied.

Option B is incorrect because the explicit deny overrides any default allow. Option D is incorrect because the simulator returned an explicit deny, not errors.

49
MCQhard

A company uses AWS CloudTrail to log all API activity. They want to ensure that log files are tamper-proof and can be validated for forensic purposes. Which of the following should they enable?

A.AWS KMS server-side encryption on the S3 bucket
B.CloudTrail log file integrity validation
C.S3 bucket versioning
D.S3 Object Lock with governance mode
AnswerB

CloudTrail log file integrity validation creates a SHA-256 hash of each log file, chains that hash to the previous file's hash, and signs the resulting digest with a private key. The public key is distributed by AWS, so you can independently verify both the signature and the hash chain to detect any modification, deletion, or reordering of log files. It is the only option listed that provides cryptographic proof of log integrity.

Why this answer

CloudTrail log file integrity validation uses a SHA-256 hash chain to detect if log files have been modified, deleted, or altered after delivery. When enabled, CloudTrail delivers a digest file that includes the hash of each log file and the hash of the previous digest, creating an immutable chain that can be used to verify log integrity for forensic purposes.

Exam trap

The trap here is that candidates often confuse data protection mechanisms (encryption, versioning, object lock) with integrity validation, which specifically requires cryptographic hash verification to prove that log files have not been tampered with.

How to eliminate wrong answers

Option A is wrong because AWS KMS server-side encryption protects log files at rest from unauthorized access, but does not provide any mechanism to detect tampering or validate the integrity of the log files after they have been written. Option C is wrong because S3 bucket versioning preserves previous versions of objects, which can help recover from accidental deletion or overwrite, but it does not cryptographically verify that log files have not been altered. Option D is wrong because S3 Object Lock with governance mode prevents objects from being deleted or overwritten for a specified retention period, but it does not provide a hash-based integrity check to detect if the content of a log file was modified before being locked.

50
MCQmedium

A security engineer is configuring a Network ACL for a public subnet that hosts a web server. The web server must accept HTTPS (TCP 443) traffic from the internet and respond. It must also be able to initiate outbound connections to the internet for software updates (HTTPS). What is the MINIMUM set of rules required for the inbound and outbound Network ACL?

A.Inbound: allow TCP 443 from 0.0.0.0/0 and TCP 22 from a management IP; Outbound: allow all traffic to 0.0.0.0/0.
B.Inbound: allow TCP 443 from 0.0.0.0/0; Outbound: allow TCP 443 to a specific software update server IP.
C.Inbound: allow TCP 443 from 0.0.0.0/0; Outbound: allow all traffic to 0.0.0.0/0.
D.Inbound: allow TCP 443 from 0.0.0.0/0; Outbound: allow TCP 1024-65535 to 0.0.0.0/0 (for return traffic) and allow TCP 443 to 0.0.0.0/0 (for updates).
AnswerD

This rule set meets the requirement by allowing inbound HTTPS on 443 for public clients and providing the minimal outbound rules needed for stateful-like behavior in a stateless NACL. The outbound TCP 1024-65535 rule allows responses to return to clients' ephemeral source ports, while the outbound TCP 443 rule permits the instance to fetch software updates. Together they allow required traffic while blocking unnecessary outbound communication, aligning with least privilege and the scenario's goal.

Why this answer

Network ACLs are stateless, meaning they require explicit rules for both inbound and outbound traffic. For the web server to accept HTTPS requests from the internet, an inbound rule allowing TCP 443 from 0.0.0.0/0 is needed. For the server to respond to those requests, an outbound rule allowing ephemeral ports (TCP 1024-65535) to 0.0.0.0/0 is required to handle return traffic.

Additionally, to allow the server to initiate outbound HTTPS connections for software updates, a separate outbound rule allowing TCP 443 to 0.0.0.0/0 is necessary.

Exam trap

The trap here is that candidates often forget that Network ACLs are stateless and assume that allowing inbound HTTPS automatically permits the return traffic, leading them to choose option C instead of the more precise option D that includes ephemeral port rules.

How to eliminate wrong answers

Option A is wrong because it includes an unnecessary inbound rule for SSH (TCP 22) that is not required by the question, and it does not explicitly allow outbound ephemeral ports for return traffic, which is essential for stateless NACLs. Option B is wrong because it restricts outbound traffic to a specific software update server IP, which is not the minimum set; the question requires the ability to initiate outbound connections to the internet, not a specific IP, and it also omits the outbound ephemeral port rule for return traffic. Option C is wrong because while it allows all outbound traffic, it does not include the specific outbound rule for TCP 443 to 0.0.0.0/0 for software updates; the 'allow all' rule would work, but the question asks for the minimum set, and option C is overly permissive and not the most restrictive correct answer.

51
Multi-Selecthard

Which FOUR are valid ways to restrict access to an S3 bucket using IAM policies? (Choose 4.)

Select 4 answers
A.Requiring server-side encryption using the 's3:x-amz-server-side-encryption' condition key
B.Using the 'aws:PrincipalOrgID' condition key
C.Restricting access to a specific VPC using the 'aws:SourceVpc' condition key
D.Using the 's3:ResourceAccount' condition key to restrict access to a specific bucket
E.Limiting access to specific IP addresses using the 'aws:SourceIp' condition key
AnswersA, B, C, E

Requiring server-side encryption via the 's3:x-amz-server-side-encryption' condition key is a valid access restriction because it makes the presence and value of the x-amz-server-side-encryption header a precondition for the S3 operation. For example, you can require that the header equals AES256 or aws:kms, which denies requests that do not carry an encryption header even if the principal otherwise has s3:PutObject permission. This condition key is evaluated per request, giving you fine-grained, attribute-based control that enforces encryption compliance on all uploads.

Why this answer

Options A, B, C, and E are all valid ways to restrict access to an S3 bucket using IAM policies. A: The 's3:x-amz-server-side-encryption' condition key can enforce server-side encryption in IAM policies. B: The 'aws:PrincipalOrgID' global condition key can be used in IAM identity-based policies to restrict access to principals from a specific AWS Organization.

C: The 'aws:SourceVpc' condition key restricts requests to those originating from a specific VPC. E: The 'aws:SourceIp' condition key restricts access to specific IP addresses. Option D is incorrect because 's3:ResourceAccount' checks the account ID of the resource, not a specific bucket; bucket-specific restriction is done via the Resource element.

52
MCQmedium

A company is migrating on-premises databases to Amazon RDS for MySQL. The security team requires that data be encrypted at rest and in transit. Which combination of steps should the team take to meet these requirements?

A.Use an RDS proxy with TLS termination and enable encryption at rest.
B.Enable encryption at rest on the RDS instance and set the rds.force_ssl parameter to 1 in the DB parameter group.
C.Enable encryption at rest on the RDS instance and use a client-side encryption library.
D.Enable encryption at rest and configure the security group to allow only HTTPS traffic.
AnswerB

Enabling encryption at rest on the RDS instance protects data files and automated backups using AWS KMS-managed keys, addressing the at-rest requirement. Setting rds.force_ssl=1 in the DB parameter group configures the MySQL/PostgreSQL engine to accept only TLS/SSL-encrypted connections, forcing all clients to negotiate an encrypted transport. Applying this parameter group requires a reboot, and after that every connection—including from read replicas—must use SSL, thereby satisfying both at-rest and in-transit encryption.

Why this answer

Enabling encryption at rest on the RDS instance (which can be done during creation or via a snapshot copy with encryption enabled) and requiring SSL for connections (by setting the rds.force_ssl parameter to 1 in the DB parameter group) ensures data is encrypted both at rest and in transit. Option A is incorrect because an RDS proxy with TLS termination does not enforce encryption for direct connections to the database, and encryption at rest alone does not cover in-transit. Option C is incorrect because using a client-side encryption library is not a standard RDS feature and would require application changes; it does not provide at-rest encryption managed by RDS.

Option D is incorrect because configuring the security group to allow only HTTPS traffic is for HTTP-based services, not for MySQL connections; MySQL uses a different protocol, and HTTPS does not apply to database connections.

53
Multi-Selecteasy

Which TWO AWS services can be used to detect anomalous API activity in an AWS account? (Choose two.)

Select 2 answers
A.Amazon GuardDuty
B.AWS CloudTrail
C.VPC Flow Logs
D.AWS Config
E.Amazon Inspector
AnswersA, B

Amazon GuardDuty continuously analyses CloudTrail management and data events, VPC Flow Logs and DNS logs using machine learning and threat intelligence to surface anomalous API activity. It satisfies the stem's detection requirement without agents or manual rule authoring, unlike CloudWatch alarms, which need explicit metric thresholds you define yourself.

Why this answer

Amazon GuardDuty (A) is correct because it is a managed threat-detection service that continuously analyzes CloudTrail management and data events, VPC Flow Logs, and DNS logs using machine learning and threat intelligence to identify anomalous or malicious API activity in the account. AWS CloudTrail (B) is correct because it records API calls as events and, through CloudTrail Insights, automatically detects unusual operational API activity such as spikes in write or error rates by baselining normal behavior. VPC Flow Logs (C) capture IP traffic metadata for network interfaces but do not analyze API calls, so they cannot detect anomalous API activity on their own.

AWS Config (D) evaluates resource configuration compliance and changes, not API call behavior, so it is not a detection service for anomalous API activity. Amazon Inspector (E) scans EC2 instances, container images, and Lambda functions for software vulnerabilities and unintended network exposure, not anomalous API usage.

Exam trap

The trap is that candidates may select VPC Flow Logs or AWS Config because they are associated with security monitoring, but they do not directly detect anomalous API activity. Additionally, some candidates might think only GuardDuty is a threat detection service and overlook that CloudTrail Insights also provides anomaly detection.

54
Multi-Selecthard

Which TWO of the following are valid methods to enforce encryption at rest for an Amazon RDS for PostgreSQL DB instance? (Choose 2.)

Select 2 answers
A.Enable encryption on an existing unencrypted DB instance
B.Restore a DB instance from an encrypted snapshot
C.Take a snapshot of the unencrypted instance and enable encryption on the snapshot
D.Create an encrypted read replica and promote it
E.Create a new encrypted DB instance from the start
AnswersB, E

Restoring a DB instance from an encrypted snapshot creates a new instance that is automatically encrypted using the KMS key that encrypted the snapshot. This process preserves the data while transferring encryption settings to the restored instance, making it a valid method for both new deployments and migrations from existing encrypted data. You may optionally choose a different customer-managed key during the restore, but encryption is guaranteed to be enabled.

Why this answer

Option B is correct because restoring from an encrypted snapshot is a supported way to obtain an encrypted DB instance: you can encrypt a snapshot copy (or use an already encrypted snapshot) and restore it, producing a DB instance with encryption at rest enabled via KMS. Option E is correct because encryption at rest for Amazon RDS for PostgreSQL must be specified at creation time; when you create a new DB instance you can enable encryption, and the underlying storage, automated backups, read replicas, and snapshots are then encrypted with the selected AWS KMS key. Option A is not valid because you cannot enable encryption on an existing unencrypted RDS DB instance in place; you must create an encrypted copy/restore.

Option C is not valid because you cannot take a snapshot of an unencrypted instance and simply 'enable encryption on the snapshot' in place; you must copy the snapshot with encryption enabled. Option D is not valid because an encrypted read replica cannot be created from an unencrypted source instance, so this method cannot enforce encryption at rest for the original unencrypted DB instance.

Exam trap

The trap is thinking you can enable encryption on an existing instance or snapshot; encryption must be set at creation or via an encrypted snapshot copy.

55
Multi-Selecteasy

Which TWO methods can be used to encrypt data at rest in Amazon S3? (Choose 2.)

Select 2 answers
A.Set a bucket policy that denies uploads without encryption.
B.Use SSE-S3 to have Amazon S3 manage the encryption keys.
C.Enable encryption in transit using HTTPS.
D.Enable MFA Delete on the S3 bucket.
E.Encrypt the objects client-side before uploading to S3.
AnswersB, E

SSE-S3 (Server-Side Encryption with Amazon S3-managed keys) encrypts each object using AES-256 with a unique key, and that key is then protected by a regularly rotated master key owned by S3. When enabled, S3 automatically encrypts data as it writes to disk and decrypts it transparently on retrieval, with no additional key management burden for the customer. This is a fully managed, low-overhead method for encrypting data at rest in S3.

Why this answer

Option B is correct because SSE-S3 (server-side encryption with Amazon S3-managed keys, AES-256) encrypts objects at rest, with AWS fully managing the key material and rotation. Option E is correct because client-side encryption means data is encrypted before it leaves the client and is stored in S3 already encrypted, so the objects are protected at rest. Option A is not a valid answer because a bucket policy denying unencrypted uploads only enforces that encryption is used; it does not itself encrypt data.

Option C is incorrect because HTTPS/TLS provides encryption in transit, not at rest. Option D is incorrect because MFA Delete only adds an authentication requirement for deleting objects or changing versioning state; it does not encrypt data.

Exam trap

The trap here is conflating encryption in transit (HTTPS) or access controls (bucket policies, MFA Delete) with encryption at rest — candidates must recognize that only SSE variants and client-side encryption actually encrypt stored data.

56
MCQeasy

A company wants to use AWS WAF to protect its web application from common web exploits. Which AWS service must be integrated with AWS WAF to provide this protection?

A.Security Groups
B.Application Load Balancer or Amazon CloudFront
C.Amazon Route 53
D.Network ACLs
AnswerB

AWS WAF is a managed Layer 7 web application firewall that you attach by associating a web access control list (ACL) with a supported resource, specifically an Application Load Balancer for regional HTTP/S requests or Amazon CloudFront for edge-based delivery. An ALB terminates HTTP/HTTPS and forwards requests to targets, giving WAF a point to inspect URI, headers, and body; CloudFront provides the same inspection at CloudFront edge locations before origin processing. This is the supported integration path, along with API Gateway and App Runner, so the correct target is an ALB or CloudFront.

Why this answer

AWS WAF is a web application firewall that inspects HTTP/HTTPS traffic at Layer 7. It must be integrated with a service that can terminate HTTP/HTTPS connections and forward the traffic to WAF for inspection. Both Application Load Balancer (ALB) and Amazon CloudFront support this integration, allowing WAF to filter requests based on rules such as SQL injection or cross-site scripting.

Security Groups and Network ACLs operate at the network and transport layers (Layers 3/4) and cannot provide Layer 7 inspection.

Exam trap

The trap here is that candidates often confuse network-layer controls (Security Groups, NACLs) with application-layer protection, assuming any firewall can be used with WAF, but only ALB and CloudFront provide the necessary Layer 7 integration for AWS WAF.

How to eliminate wrong answers

Option A is wrong because Security Groups act as a virtual firewall for EC2 instances at the instance level, operating at Layer 3/4 (IP and port) and cannot inspect HTTP/HTTPS payloads or integrate with AWS WAF. Option C is wrong because Amazon Route 53 is a DNS service that resolves domain names to IP addresses and does not handle HTTP traffic or provide a point for WAF rule evaluation. Option D is wrong because Network ACLs are stateless Layer 3/4 filters applied at the subnet level, which cannot perform Layer 7 inspection or be associated with AWS WAF.

57
Multi-Selecteasy

A company uses AWS Systems Manager Patch Manager to patch EC2 instances. During a security incident, the security team needs to quickly patch a critical vulnerability across all Windows instances in a specific AWS region. Which steps should the team take? (Choose TWO.)

Select 2 answers
A.Assign the patch baseline to the instances by specifying a patch group.
B.Tag all instances with 'PatchGroup=Critical' to include them in the patching.
C.Create a custom patch baseline that includes the required patch.
D.Use the AWS-provided default patch baseline for Windows.
E.Use SSM Run Command to execute a script that downloads and installs the patch.
AnswersA, C

Patch groups in Systems Manager Patch Manager are defined by tagging managed nodes with the key `Patch Group` (case-sensitive) and then associating that group to a patch baseline using `Register-PatchBaselineForPatchGroup`. This association is what directs Patch Manager to evaluate and apply the baseline, including approval rules and custom patches, to every instance in that group. Without the explicit patch-group-to-baseline registration, simply having a tag on instances does not change which baseline is applied; the baseline must be knowingly assigned to the group.

Why this answer

Assigning a custom patch baseline to instances via a patch group allows the security team to target specific Windows instances for patching. Patch Manager uses patch groups to associate instances with a specific patch baseline, ensuring only the desired instances receive the critical patch. This approach provides granular control over which instances are patched during an incident.

Exam trap

The trap here is that candidates often confuse tagging instances with a patch group (which is necessary for association) with the actual patching action, or they assume the default patch baseline will automatically include all critical patches, when in fact custom baselines are required for targeted incident response.

58
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team needs to centralize CloudTrail logs from all accounts into a single S3 bucket in the management account. Which configuration ensures that only the management account can delete the log files?

A.Enable S3 Object Lock on the bucket with governance mode.
B.Use an S3 bucket policy that denies s3:DeleteObject for all principals.
C.Enable MFA Delete on the S3 bucket.
D.Configure CloudTrail to automatically delete logs older than 90 days.
E.Use an S3 bucket policy that denies s3:DeleteObject unless the principal is the management account.
AnswerE

The correct approach is to add a bucket policy with a Deny effect for s3:DeleteObject that includes a Condition such as StringNotEquals on aws:PrincipalAccount with the management account's ID. This denies deletion for every principal that is not in the management account, while excluding the management account itself from the Deny so that its principals can delete. By using this resource-based policy and the aws:PrincipalAccount condition key, you enforce that only users or roles from the management account can delete objects from the S3 bucket.

Why this answer

It uses an S3 bucket policy with a conditional deny that explicitly restricts the s3:DeleteObject action to only the management account. This ensures that even if an IAM user or role in a member account has S3 permissions, they cannot delete log files unless they are from the management account. The policy leverages the aws:PrincipalOrgID or a specific account ID condition to enforce this restriction.

Exam trap

The trap here is that candidates often confuse MFA Delete (option C) with account-level access control, but MFA Delete only adds an authentication factor and does not restrict deletion to a specific AWS account.

How to eliminate wrong answers

Option A is wrong because S3 Object Lock in governance mode prevents objects from being deleted or overwritten by most users, but it can be bypassed by users with the s3:BypassGovernanceRetention permission, which could be granted to the management account or others, and it does not exclusively restrict deletion to the management account. Option B is wrong because denying s3:DeleteObject for all principals would prevent even the management account from deleting log files, which is not the requirement; the goal is to allow only the management account to delete. Option C is wrong because MFA Delete requires multi-factor authentication for delete operations but does not restrict deletion to a specific account; any principal with MFA could delete objects if they have the necessary permissions.

Option D is wrong because CloudTrail's automatic log deletion feature (e.g., via lifecycle policies) does not control which principals can delete logs; it simply removes old logs based on age, and it does not prevent unauthorized deletion by other accounts.

59
MCQhard

A security engineer must ensure that cross-account access to an S3 bucket is restricted to only accounts that are part of a specific AWS organization. Which IAM policy condition key should be used in the bucket policy?

A.aws:SourceIp
B.aws:MultiFactorAuthPresent
C.aws:PrincipalOrgID
D.aws:SourceVpce
AnswerC

The aws:PrincipalOrgID condition key is a global condition that checks the organization ID associated with the principal's account, allowing you to require that the principal comes from an account that is a member of a specified AWS organization. In a resource-based policy, it directly validates organizational membership for cross-account access, making it the appropriate choice for ensuring that only principals from your organization can access the resource.

Why this answer

The `aws:PrincipalOrgID` condition key allows you to restrict access to only principals (accounts) that belong to a specific AWS organization. By specifying the organization ID in the bucket policy, you ensure that only accounts within that organization can access the S3 bucket, regardless of whether they are from the same account or cross-account. This key is evaluated against the organization ID of the principal's account, making it ideal for cross-account access control based on organizational membership.

Exam trap

The trap here is that candidates often confuse `aws:PrincipalOrgID` with `aws:SourceAccount` or `aws:SourceOrgID` (which does not exist), or mistakenly think `aws:SourceVpce` can restrict based on account identity, when in reality it only restricts based on network path.

How to eliminate wrong answers

Option A is wrong because `aws:SourceIp` restricts access based on the client's IP address, not the AWS account or organization, so it cannot enforce cross-account restrictions based on organization membership. Option B is wrong because `aws:MultiFactorAuthPresent` checks whether the request was authenticated with multi-factor authentication, but it does not identify the account or organization of the principal, so it cannot restrict access to specific organization accounts. Option D is wrong because `aws:SourceVpce` restricts access based on the source VPC endpoint ID, which controls network-level access but does not verify the principal's account or organization membership.

60
MCQhard

A company runs a multi-account AWS environment using AWS Organizations. The security team uses AWS Config to monitor compliance. Recently, they noticed that a developer in the 'development' account created an S3 bucket that is publicly accessible. The security team wants to prevent this in the future by automatically remediating any public S3 bucket. They have an SCP that denies s3:PutBucketPublicAccessBlock, but developers are still making buckets public by using bucket ACLs. The security team wants to implement a solution that automatically fixes any bucket that becomes public. Which solution should they choose?

A.Use CloudTrail to detect PutBucketAcl events and send to SNS for manual remediation
B.Use AWS Config with the s3-bucket-public-read-prohibited managed rule and an automatic remediation action using AWS Systems Manager Automation
C.Update the SCP to deny s3:PutBucketAcl with a condition for public access
D.Attach an IAM policy to all users that denies s3:PutBucketAcl
AnswerB

AWS Config continuously evaluates bucket configurations against the s3-bucket-public-read-prohibited managed rule, which checks both bucket ACLs and bucket policies for public read access. When a violation is detected, an automatic remediation action invokes an AWS Systems Manager Automation runbook (e.g., AWS-DisableS3BucketPublicRead) to remove the public grant or apply a deny. This is a fully automated lifecycle: detect, remediate, and re-evaluate until compliant, without human intervention, making it the correct solution.

Why this answer

AWS Config's s3-bucket-public-read-prohibited managed rule evaluates S3 bucket ACLs and policies for public read access. When a noncompliant bucket is detected, an automatic remediation action using AWS Systems Manager Automation can invoke a custom SSM document (e.g., AWS-DisableS3BucketPublicReadWrite) to remove public ACLs or apply a bucket policy that denies public access. This provides automated, event-driven remediation without relying on manual intervention or incomplete SCPs.

Exam trap

The trap here is that candidates often assume an SCP or IAM policy that denies the specific API call (s3:PutBucketAcl) is the best solution, but the question requires automatic remediation of already-public buckets, not prevention—and SCPs cannot remediate existing noncompliant resources, only block future actions.

How to eliminate wrong answers

Option A is wrong because using CloudTrail to detect PutBucketAcl events and sending to SNS for manual remediation does not automatically fix the bucket; it requires human action, which is slow and error-prone, and does not meet the requirement for automatic remediation. Option C is wrong because updating the SCP to deny s3:PutBucketAcl with a condition for public access would prevent developers from setting public ACLs in the first place, but the question states that developers are already bypassing the existing SCP (which denies s3:PutBucketPublicAccessBlock) by using ACLs; an SCP that denies s3:PutBucketAcl could be effective, but the question explicitly asks for a solution that automatically fixes any bucket that becomes public, not one that prevents the action—furthermore, SCPs cannot retroactively remediate already-public buckets. Option D is wrong because attaching an IAM policy to all users that denies s3:PutBucketAcl is not scalable in a multi-account environment (IAM policies are account-specific and cannot be applied across all accounts via AWS Organizations), and it also does not provide automatic remediation for buckets that are already public.

61
MCQeasy

A company wants to encrypt data at rest in Amazon S3 using server-side encryption with Amazon S3-managed keys (SSE-S3). What is the minimum permission required for an IAM user to upload an object that will be encrypted with SSE-S3?

A.s3:PutObjectAcl
B.kms:Decrypt
C.s3:PutObject
D.kms:GenerateDataKey
AnswerC

This is the correct permission needed to upload any object to S3, regardless of whether server-side encryption is enabled. When using SSE-S3, S3 automatically encrypts the object with a unique key that is itself wrapped by a master key managed by S3, all happening transparently in the service. The caller only needs the standard s3:PutObject permission; no separate KMS or encryption-specific permissions are required for the upload to succeed with encryption.

Why this answer

For SSE-S3, Amazon S3 manages the encryption keys entirely, so the IAM user does not need any AWS KMS permissions. The only permission required to upload an object with SSE-S3 is s3:PutObject, which allows the upload operation. S3 automatically encrypts the object with an S3-managed key when the request specifies SSE-S3 or when default encryption is enabled.

Exam trap

SCS-C02 often tests the confusion between SSE-S3 and SSE-KMS permission requirements, tempting candidates to select KMS permissions (kms:GenerateDataKey, kms:Decrypt) for SSE-S3 when S3 manages keys internally and no KMS permissions are needed.

How to eliminate wrong answers

Option A is wrong because s3:PutObjectAcl controls the ability to set an object's ACL, which is unrelated to encryption and not required for SSE-S3 uploads. Option B is wrong because kms:Decrypt is a KMS permission needed when using SSE-KMS to decrypt data keys, not for SSE-S3 where S3 manages keys internally. Option D is wrong because kms:GenerateDataKey is a KMS permission required for SSE-KMS to generate data keys, not for SSE-S3, which uses S3-managed keys and does not call KMS.

62
Multi-Selecthard

A company is using AWS CloudTrail and wants to detect when an IAM user performs a specific action, such as stopping an EC2 instance. The security engineer needs to set up a real-time notification. Which THREE steps should the engineer take? (Choose THREE.)

Select 3 answers
A.Create a metric filter in CloudWatch Logs to match the StopInstances event
B.Create a CloudTrail trail that delivers logs to CloudWatch Logs
C.Use Amazon QuickSight to visualize CloudTrail logs
D.Create a CloudWatch alarm on the metric and configure it to send an SNS notification
E.Use Amazon Athena to query CloudTrail logs in S3
AnswersA, B, D

A metric filter in CloudWatch Logs inspects incoming log events and matches patterns such as { $.eventName = "StopInstances" }. Each matching event increments a custom metric (e.g., StopInstancesCount), which is what turns raw log data into a numeric measure that a CloudWatch alarm can monitor. Without this metric filter, CloudWatch Logs data remains unstructured and cannot directly trigger alerts.

Why this answer

A metric filter in CloudWatch Logs can parse CloudTrail log events for the 'StopInstances' API call and convert it into a CloudWatch metric. This metric can then trigger an alarm for real-time notification, enabling the security engineer to detect the specific action as required.

Exam trap

The trap here is that candidates may confuse services like QuickSight or Athena for real-time monitoring, but they are designed for historical analysis and visualization, not for triggering real-time notifications.

63
Multi-Selecthard

A security engineer is configuring Amazon GuardDuty in a multi-account environment using AWS Organizations. The engineer needs to ensure that all findings from member accounts are visible in the administrator account. Additionally, the engineer wants to receive real-time notifications for high-severity findings. Which TWO actions should the engineer take? (Choose TWO.)

Select 2 answers
A.Enable Amazon Detective to analyze GuardDuty findings.
B.Designate an administrator account in GuardDuty to manage the multi-account environment.
C.Create an Amazon EventBridge rule that triggers an SNS notification for high-severity GuardDuty findings.
D.Enable AWS CloudTrail in all member accounts to log GuardDuty API calls.
E.Use AWS Config to monitor GuardDuty configuration.
AnswersB, C

GuardDuty multi-account architecture requires you to designate an administrator account (via AWS Organizations delegated administrator or invitation) that owns the GuardDuty detectors and manages all member accounts. The administrator account aggregates findings from every member account, giving you a single-pane-of-glass view and allowing you to configure threat lists and managed rules centrally. This designated administrator is the foundation for cross-account management and is mandatory for any multi-account GuardDuty setup.

Why this answer

Designating an administrator account in GuardDuty is the required step to centrally manage findings from all member accounts in an AWS Organizations multi-account setup. This configuration enables the administrator account to view and aggregate all findings from member accounts without needing to log into each account individually.

Exam trap

The trap here is that candidates may think Amazon Detective or AWS Config are needed for real-time notifications, but Detective is for post-incident analysis and Config is for compliance drift, not for triggering alerts on security findings.

64
Multi-Selectmedium

A company is using AWS CloudTrail to monitor API activity in its AWS account. The security team needs to be alerted when unauthorized API calls are made to delete Amazon S3 buckets. Which TWO steps should the security team take to meet this requirement? (Choose TWO.)

Select 2 answers
A.Enable Amazon VPC Flow Logs to capture API calls and use Amazon Athena to query for DeleteBucket events.
B.Create an AWS CloudTrail trail that monitors Amazon CloudWatch Logs for DeleteBucket API calls.
C.Create an AWS Config rule to detect DeleteBucket API calls and send an SNS notification.
D.Configure CloudTrail to deliver logs to Amazon CloudWatch Logs and create a metric filter for the DeleteBucket API call.
E.Create an Amazon CloudWatch Events rule that matches the DeleteBucket API call and triggers an Amazon SNS notification.
AnswersD, E

CloudTrail delivers API activity to CloudWatch Logs, where a metric filter counts DeleteBucket events and drives an alarm. This satisfies the requirement to detect unauthorised delete calls, since CloudTrail alone records but does not alert.

Why this answer

Option D is correct because CloudTrail can be configured to deliver management event logs to an Amazon CloudWatch Logs log group, where a metric filter can be created to match the DeleteBucket API call (for example, filtering on eventName = DeleteBucket and errorCode = AccessDenied), and a CloudWatch alarm on that metric can then trigger an SNS notification to alert the security team. Option E is correct because CloudWatch Events (now Amazon EventBridge) can match CloudTrail API activity by event pattern, such as {"eventSource":"s3.amazonaws.com","eventName":"DeleteBucket"}, and route the matching event directly to an Amazon SNS topic to notify the team. Option A is not correct because VPC Flow Logs capture IP traffic metadata at the ENI level, not API calls, so they cannot identify DeleteBucket events.

Option B is not correct because a CloudTrail trail does not 'monitor CloudWatch Logs'; the correct direction is CloudTrail delivering logs to CloudWatch Logs, and a trail alone does not generate alerts. Option C is not correct because AWS Config rules evaluate resource configuration compliance and cannot detect or alert on individual DeleteBucket API calls.

Exam trap

The trap here is that candidates may confuse AWS Config (which evaluates resource configurations) with CloudTrail (which records API activity), or think VPC Flow Logs can capture API-level events instead of network flows.

65
MCQmedium

During an incident response, a security engineer needs to collect memory forensics from a running EC2 instance without shutting it down. The instance is running Amazon Linux 2. Which tool is MOST appropriate?

A.tcpdump
B.Volatility
C.LiME (Linux Memory Extractor)
D.dd command to capture /dev/mem
AnswerC

LiME is a loadable kernel module designed specifically for Linux memory acquisition. Loading it on the target system grants direct access to the kernel's physical address space, allowing a full RAM image to be written to a file or over the network; unloading it restores the system to a usable state.

Why this answer

LiME (Linux Memory Extractor) is the most appropriate tool for capturing volatile memory from a running Amazon Linux 2 EC2 instance without shutting it down. It is specifically designed to dump RAM contents to a file or over a network, minimizing the footprint on the target system and ensuring the integrity of the forensic acquisition.

Exam trap

The trap here is that candidates confuse memory acquisition tools (LiME) with memory analysis frameworks (Volatility), or mistakenly believe that dd /dev/mem still works on modern Linux kernels for full memory capture.

How to eliminate wrong answers

Option A is wrong because tcpdump is a network packet capture tool, not a memory forensics tool; it captures network traffic, not RAM contents. Option B is wrong because Volatility is a memory analysis framework used to examine memory dumps, not a tool to acquire memory from a live system. Option D is wrong because the dd command to capture /dev/mem is deprecated and restricted in modern Linux kernels (including Amazon Linux 2) due to security hardening; /dev/mem provides access to physical memory but is typically limited to the first 1 MB, making it unsuitable for full RAM acquisition.

66
MCQmedium

A security engineer is troubleshooting an issue where an Amazon RDS for MySQL DB instance encrypted at rest with AWS KMS is failing to launch. The error message indicates a KMS access issue. Which IAM role or policy is most likely missing?

A.The RDS subnet group is in a private subnet without a NAT gateway
B.The DB instance's security group does not allow outbound traffic to KMS
C.The KMS key policy does not grant access to the root account
D.The AWSServiceRoleForRDS service-linked role is missing
AnswerD

The AWSServiceRoleForRDS service-linked role is a predefined IAM role that gives RDS the ability to call AWS services, including KMS, on your behalf for tasks such as encrypting and decrypting database storage. When this role is missing, RDS cannot assume it to perform kms:Encrypt, kms:Decrypt, or kms:GenerateDataKey operations, causing failures when you create, modify, or start an encrypted instance. This is the root cause in this scenario; you can verify or create the role with the AWS CLI command aws iam create-service-linked-role --aws-service-name rds.amazonaws.com.

Why this answer

The AWSServiceRoleForRDS service-linked role is required for RDS to call AWS KMS on your behalf to manage encryption keys for encrypted DB instances. If this role is missing, RDS cannot obtain the necessary permissions to decrypt the KMS key during instance launch, resulting in a KMS access error. This role is automatically created the first time you create an RDS resource, but if it was deleted or not present, you must recreate it to resolve the issue.

Exam trap

The trap here is that candidates often focus on KMS key policies or network configurations, but the real issue is the missing service-linked role that grants RDS the service-level permissions to interact with KMS, which is a common oversight in encrypted RDS troubleshooting scenarios.

How to eliminate wrong answers

Option A is wrong because the subnet group configuration (private subnet without NAT gateway) affects network connectivity, not KMS permissions; RDS can launch in a private subnet without a NAT gateway as long as it has a VPC endpoint or proper routing to KMS. Option B is wrong because security groups control network traffic at the instance level, but KMS access is managed via IAM policies and key policies, not outbound traffic rules; RDS uses AWS KMS over HTTPS, which does not require a specific security group rule for outbound traffic to KMS. Option C is wrong because the KMS key policy granting access to the root account is a default best practice, but the missing element is the service-linked role that allows RDS to assume the necessary permissions; the root account already has full access by default.

67
MCQhard

A company has a security rule that all S3 buckets must have server access logging enabled. A security engineer uses AWS Config to evaluate compliance. The engineer configures a managed rule but notices that the rule does not evaluate all buckets. What is the most likely reason?

A.The rule only evaluates buckets in the us-east-1 region.
B.The rule only evaluates buckets that have a specific tag.
C.The rule excludes buckets that have a bucket policy denying access to AWS Config.
D.The rule requires the logging target bucket to be in the same account.
AnswerB

The AWS Config managed rule `s3-bucket-server-access-logging-enabled` can be configured with a `tag` parameter. When a tag is specified, the rule only evaluates S3 buckets that have that exact tag. If the engineer did not apply the required tag to all buckets, or if the rule was configured with a tag that does not match all buckets, some buckets will be excluded.

Why this answer

The AWS Config managed rule `s3-bucket-server-access-logging-enabled` can be configured with a `tag` parameter. When a tag is specified, the rule only evaluates S3 buckets that have that exact tag key-value pair. If the security engineer did not apply the required tag to all buckets, or if the rule was configured with a tag that does not match all buckets, some buckets will be excluded from evaluation, causing the observed behavior.

Exam trap

The trap here is that candidates often assume AWS Config managed rules evaluate all resources of a given type by default, overlooking the fact that many rules support optional tag-based filtering that can silently limit the scope of evaluation.

How to eliminate wrong answers

Option A is wrong because the managed rule `s3-bucket-server-access-logging-enabled` evaluates buckets across all regions where AWS Config is enabled, not just us-east-1; the rule is regional in scope but can be deployed in each region. Option C is wrong because bucket policies that deny access to AWS Config would cause the rule to report a non-compliant result (e.g., 'INSUFFICIENT_DATA' or 'NON_COMPLIANT') rather than silently skip evaluation; the rule still attempts to evaluate the bucket. Option D is wrong because the rule does not require the logging target bucket to be in the same account; cross-account logging is supported as long as the necessary permissions are in place, and the rule checks the bucket's logging configuration, not the target bucket's account.

68
MCQeasy

A company wants to ensure that data stored in Amazon EBS volumes is encrypted at rest. What is the easiest way to achieve this?

A.Use AWS KMS to rotate the EBS encryption key
B.Use a script to encrypt each volume after creation
C.Enable EBS encryption by default in the AWS Region
D.Use application-level encryption
AnswerC

Enabling EBS encryption by default in the Region is the easiest and most reliable method because it instructs the EC2 service to always encrypt newly created volumes and snapshots at the storage layer. When enabled, every new EBS volume and every new snapshot is encrypted with your default AWS KMS key (either the aws/ebs managed key or a customer-managed key you designate). This setting applies to all volumes created in that Region, including root volumes launched from unencrypted AMIs, without requiring you to modify applications or remember to check an encryption box.

Why this answer

Enabling EBS encryption by default in the AWS Region automatically encrypts all new EBS volumes and snapshots with no additional effort. Option A is incorrect: KMS key rotation does not enable encryption; it rotates the key used for encryption. Option B is incorrect: while you can encrypt individual volumes after creation, the easiest method is to enable default encryption.

Option D is incorrect: application-level encryption is not needed for EBS volumes and is more complex to implement.

69
MCQeasy

A security engineer needs to detect unauthorized API calls in an AWS account. Which AWS service should be used to record and monitor API activity for auditing?

A.AWS CloudTrail
B.Amazon CloudWatch Logs
C.AWS Config
D.Amazon GuardDuty
AnswerA

AWS CloudTrail is the native audit service that records every API call and user activity as CloudTrail event history. Each event includes the identity of the caller, source IP, time, request parameters, and response, allowing engineers to detect unauthorized API calls by analyzing management and data events. This event history can be delivered to an S3 bucket and queried with Athena, or streamed to CloudWatch Logs for real-time alerting.

Why this answer

AWS CloudTrail is the correct service because it is specifically designed to record API activity across AWS services, capturing details such as the identity of the caller, the time of the call, the source IP address, and the request parameters. This audit log is essential for detecting unauthorized API calls, as it provides a complete history of all management and data plane operations for security analysis and compliance.

Exam trap

The trap here is that candidates often confuse CloudWatch Logs (which stores logs) with CloudTrail (which records API activity), or they assume GuardDuty's threat detection capability includes native API logging, when in fact GuardDuty consumes CloudTrail logs rather than generating them.

How to eliminate wrong answers

Option B (Amazon CloudWatch Logs) is wrong because it is a service for monitoring, storing, and accessing log files from various sources (e.g., applications, EC2 instances), but it does not natively record AWS API calls; it can only ingest CloudTrail logs if configured as a destination. Option C (AWS Config) is wrong because it evaluates and records resource configuration changes and compliance rules, not API activity; it focuses on the state of resources rather than the actions that modify them. Option D (Amazon GuardDuty) is wrong because it is a threat detection service that analyzes CloudTrail logs, VPC Flow Logs, and DNS logs for malicious activity, but it does not itself record or store API call history for auditing purposes.

70
MCQmedium

Refer to the exhibit. A security engineer attaches this S3 bucket policy to an S3 bucket. What is the effect of this policy?

A.Requests over HTTP are denied, but HTTPS requests are allowed.
B.The policy has no effect because there is no Allow statement.
C.All requests over HTTPS are allowed.
D.All requests to the bucket are denied.
AnswerA

The bucket policy includes a Deny statement with a Bool condition on aws:SecureTransport set to "false". This condition matches only when the request is made over plain HTTP, not TLS/SSL. Consequently, HTTP requests are explicitly denied, while HTTPS requests do not match the condition and therefore are not blocked by this statement. Any valid allow from another policy can therefore permit HTTPS access.

Why this answer

The policy contains a Deny statement conditioned on 'aws:SecureTransport' being false, which blocks all HTTP requests while allowing HTTPS requests to proceed (subject to other permissions). Because Deny only triggers when the condition matches, HTTPS requests are unaffected by this statement and can be allowed by other policies or ACLs.

Exam trap

SCS-C02 often tests the misconception that a policy needs an Allow statement to have any effect, causing candidates to select 'no effect' when a Deny-only policy is actually fully enforceable.

How to eliminate wrong answers

Option B is wrong because a bucket policy with only a Deny statement is fully effective — Deny statements do not require a matching Allow to take effect; they explicitly block matching requests. Option C is wrong because the policy does not grant any Allow; it only denies HTTP, so HTTPS requests are not automatically allowed unless another policy grants permission. Option D is wrong because the Deny is conditional on SecureTransport being false, so HTTPS requests are not denied by this policy.

71
MCQmedium

A company uses AWS KMS to encrypt data in S3 buckets. The security team needs to ensure that KMS keys can only be used by specific IAM roles within the same account. Which key policy should be applied?

A."Principal": {"AWS": "arn:aws:iam::123456789012:*"}
B."Principal": {"AWS": "*"}
C."Principal": {"AWS": "arn:aws:iam::123456789012:root"}
D."Principal": {"AWS": "arn:aws:iam::123456789012:role/AllowedRole"}
AnswerD

This principal ARN explicitly identifies the IAM role 'AllowedRole' in the account. When the role is assumed (by an EC2 instance, Lambda, or an STS AssumeRole call), the role's temporary credentials include the role's ARN as the principal, so the KMS key policy exactly matches it. This is the correct least-privilege configuration because no other IAM user or role can use the key unless the role allows it, and the key policy does not expose the key to the entire account. You could further restrict it by adding a condition like kms:ViaService to limit it to S3, but this is the best answer among the options.

Why this answer

A KMS key policy that names a specific IAM role ARN as the principal grants key usage only to that role, which directly satisfies the requirement to restrict key usage to specific IAM roles within the account. The key policy is the primary access control for a KMS key, and explicit role ARNs enforce least privilege at the key level.

Exam trap

SCS-C02 often tests the misconception that specifying the account root ARN restricts access to the account — candidates must remember that root ARN delegates to IAM and does not limit usage to specific roles.

How to eliminate wrong answers

Option A is wrong because arn:aws:iam::123456789012:* is not a valid principal ARN — the wildcard in the role/user path position does not match all principals and would not grant the intended access; it is syntactically invalid for a principal element. Option B is wrong because "AWS": "*" grants access to every principal in every account, which is the opposite of restricting usage. Option C is wrong because specifying the account root ARN delegates permission to the account, allowing any principal in the account with the right IAM permissions to use the key, which does not restrict usage to specific roles.

72
MCQhard

A financial services company has a production AWS account with hundreds of EC2 instances running a mix of Linux and Windows workloads. The security team is responsible for detecting and responding to security incidents. They have enabled CloudTrail, VPC Flow Logs, and GuardDuty. Recently, GuardDuty generated a finding indicating that an EC2 instance is communicating with a known malicious IP address. The security engineer needs to investigate the incident. The engineer examines the GuardDuty finding and sees the affected resource is an EC2 instance ID. The engineer wants to identify which user or role launched the instance and what security groups were associated with it at launch time. Which approach should the engineer take to gather this information?

A.Log in to the EC2 console and view the instance details under the 'Security' tab.
B.Use AWS Systems Manager Inventory to collect metadata about the instance.
C.Search CloudTrail logs for the RunInstances event that created the instance, using the instance ID to filter.
D.Use AWS Config to view the configuration history of the EC2 instance and check the security group changes.
AnswerC

The correct method is to filter CloudTrail management events for eventName='RunInstances' (eventSource='ec2.amazonaws.com') and match the target instance ID, which appears in the responseElements.instancesSet.items field because the ID is generated when the instance is created. Each event's userIdentity block contains the ARN of the IAM user or role, access key ID, session context, and source IP, giving a definitive audit answer. For large accounts, use Athena or CloudTrail Lake to query the logs by instance ID rather than manually browsing Event history.

Why this answer

CloudTrail records every EC2 API call, including RunInstances, with the identity of the caller (user or role), the request parameters (including security group IDs), and the response (including the instance ID). By searching CloudTrail logs for the RunInstances event and filtering by the instance ID in the response elements, the engineer can determine who launched the instance and which security groups were specified at launch.

Exam trap

SCS-C02 often tests the difference between CloudTrail (API caller identity and request parameters) and AWS Config (resource configuration history) — candidates frequently pick Config because it shows security group changes but miss that it does not identify the launching principal.

How to eliminate wrong answers

Option A is wrong because the EC2 console's Security tab shows current security groups, not the security groups at launch time, and it does not reveal the launching identity. Option B is wrong because Systems Manager Inventory collects OS-level metadata (installed applications, network config) and does not record the API caller or launch-time security groups. Option D is wrong because AWS Config records configuration history and can show security group changes over time, but it does not directly identify the IAM principal that launched the instance — CloudTrail is the authoritative source for API caller identity.

73
Multi-Selectmedium

Which TWO actions are best practices for securing an AWS account root user? (Select TWO.)

Select 2 answers
A.Use the root user for everyday administrative tasks.
B.Create access keys for the root user.
C.Delete the root user to prevent unauthorized access.
D.Create an IAM user with administrative privileges and use it instead of the root user.
E.Enable MFA on the root user.
AnswersD, E

Creating an IAM user with administrative privileges and using that user for day-to-day management reduces the exposure of the root user credentials, which is a core AWS account security best practice. This allows you to enforce MFA, assign permissions via IAM policies, rotate credentials, and audit actions through CloudTrail, none of which are possible with the root user in a least-privilege manner. While AWS now recommends using IAM Identity Center with roles for human access, an admin IAM user protected by MFA is still a valid baseline for root-user credential protection.

Why this answer

Option D is correct because AWS best practice is to create an IAM user (or federated identity) with the required administrative permissions and use that identity for day-to-day administration, reserving the root user only for the few tasks that specifically require it, such as changing the account name, closing the account, or changing the support plan. Option E is correct because enabling multi-factor authentication (MFA) on the root user adds a second authentication factor, so a compromised root password alone is insufficient to sign in; AWS strongly recommends a hardware MFA device for the root user. Option A is wrong because using the root user for everyday administrative tasks violates least privilege and greatly increases the blast radius if those credentials are compromised.

Option B is wrong because AWS advises against creating access keys for the root user; if root access keys already exist, they should be deleted, since long-lived root keys are a major security risk. Option C is wrong because the root user cannot be deleted; it is permanently tied to the account and can only be secured by protecting its credentials and limiting its use.

Exam trap

SCS-C02 often tests root user security; candidates may think the root user can be deleted or that access keys are acceptable, but the root user cannot be deleted and access keys should be avoided.

74
Multi-Selectmedium

A security engineer is tasked with securing an Amazon RDS for MySQL database. The database must be accessible only from a specific set of EC2 instances. Which THREE steps should the engineer take?

Select 3 answers
A.Disable encryption at rest to improve performance.
B.Enable encryption at rest for the RDS instance.
C.Launch the RDS instance in a private subnet.
D.Create a security group that allows inbound traffic on port 3306 from the EC2 instances' security group.
E.Associate the RDS instance with a public subnet for easier access.
AnswersB, C, D

Enabling encryption at rest protects the database by encrypting data files in the underlying block storage, along with automated backups, snapshots, and read replicas, using an AWS KMS customer master key (AES-256). This satisfies compliance requirements such as PCI DSS or HIPAA and defends against theft of physical storage or unauthorized access to snapshots. Must be configured at instance creation time; to encrypt an existing unencrypted instance, you have to create an encrypted snapshot and restore from it.

Why this answer

Enabling encryption at rest for the RDS instance ensures that data stored on the underlying storage is encrypted using AWS Key Management Service (KMS). This is a security best practice for protecting sensitive data at rest, and it does not conflict with the requirement to restrict network access. Encryption at rest is independent of network access controls and is essential for compliance with many security frameworks.

Exam trap

The trap here is that candidates may focus solely on network-level controls (security groups and subnets) and overlook encryption at rest as a required security step, or they may incorrectly believe that encryption at rest degrades performance significantly for MySQL workloads.

75
MCQhard

A security team has enabled AWS CloudTrail in all regions and is delivering logs to an S3 bucket. The team has also enabled S3 server access logging for the CloudTrail bucket. The team needs to detect any unauthorized access to the CloudTrail logs. Which combination of services should the team use to achieve near-real-time detection?

A.AWS CloudTrail Insights and Amazon CloudWatch
B.Amazon GuardDuty and Amazon CloudWatch Events
C.Amazon Athena and Amazon QuickSight
D.AWS Config and Amazon SNS
AnswerB

Amazon GuardDuty is a continuous threat detection service that consumes AWS CloudTrail S3 data events, VPC flow logs, and DNS logs to identify suspicious S3 access, such as requests from unusual geographies, compromised credentials, or bucket exfiltration attempts. When a finding is generated, GuardDuty publishes it to Amazon CloudWatch Events (now part of Amazon EventBridge), enabling automated notification through SNS or invocation of Lambda for remediation. This end-to-end pipeline provides the real-time, actionable alerting required for S3 access anomalies.

Why this answer

Amazon GuardDuty continuously monitors S3 data plane events, including CloudTrail log delivery and S3 server access logs, to detect suspicious API calls or unauthorized access patterns. Amazon CloudWatch Events (now part of Amazon EventBridge) can trigger near-real-time alerts when GuardDuty generates findings, enabling immediate response. This combination provides the required near-real-time detection without relying on batch analysis or configuration rules.

Exam trap

The trap here is that candidates confuse AWS CloudTrail Insights (which analyzes management events for anomalies) with GuardDuty (which provides broader threat detection including S3 data events), leading them to choose Option A despite its lack of near-real-time S3 access detection.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail Insights analyzes management event trails for unusual activity but does not provide near-real-time detection of unauthorized access to S3 objects; it operates on a delayed basis and focuses on API call anomalies, not S3 data events. Option C is wrong because Amazon Athena and Amazon QuickSight are query and visualization tools that require you to first store logs and then run queries, which is not near-real-time detection; they are used for post-incident analysis and reporting. Option D is wrong because AWS Config evaluates resource configuration compliance against rules and can trigger SNS notifications, but it does not detect unauthorized access to CloudTrail logs; it is designed for configuration auditing, not threat detection on data plane operations.

Page 1 of 17

Page 2