Courseiva

AWS Certified Security Specialty SCS-C02 (SCS-C02) — Questions 676–750

1205 questions total · 17pages · All types, answers revealed

Page 9

Page 10 of 17

Page 11
676
Multi-Selecteasy

A security engineer is setting up monitoring for AWS API calls. Which TWO AWS services can be used to capture and analyze API activity?

Select 2 answers
A.Amazon CloudWatch Logs
B.AWS Config
C.Amazon Inspector
D.AWS CloudTrail
E.Amazon GuardDuty
AnswersA, D

Amazon CloudWatch Logs is the monitoring and analysis layer that ingests CloudTrail events when a trail is configured to deliver to a log group. It enables real-time and historical inspection of API calls through metric filters, which can trigger CloudWatch Alarms based on specific API activity, and CloudWatch Logs Insights for ad-hoc querying. This makes it the correct service for actively monitoring and alerting on AWS API calls, rather than merely recording them.

Why this answer

Amazon CloudWatch Logs can capture and analyze API activity by ingesting log data from various AWS services, including AWS CloudTrail. You can configure CloudWatch Logs to monitor API calls in real time, set up metric filters to detect specific patterns, and trigger alarms based on API activity. This makes it a valid service for capturing and analyzing API calls, especially when combined with CloudTrail for detailed event records.

Exam trap

The trap here is that candidates often confuse AWS Config (which records resource configuration changes) with CloudTrail (which records API calls), or they think Amazon GuardDuty directly captures API logs, when in fact it only analyzes logs from other services like CloudTrail.

677
MCQhard

A security engineer is investigating a potential compromise. The engineer notices that an EC2 instance is sending outbound traffic to an unknown IP address on port 443. The engineer needs to determine if the instance is communicating with a known command and control (C2) server. Which AWS service can the engineer use to check the reputation of the destination IP address?

A.AWS CloudTrail
B.VPC Flow Logs
C.AWS Trusted Advisor
D.Amazon GuardDuty
AnswerD

Amazon GuardDuty is a managed threat detection service that continuously consumes VPC Flow Logs, DNS query logs, CloudTrail events, and S3 data events. It applies integrated threat intelligence from AWS and third-party sources, along with machine learning and anomaly detection, to generate findings when an EC2 instance communicates with a known malicious IP, Bitcoin miner, or Tor node. Its findings include the affected resource, the malicious IP, the protocol and port, and confidence indicators, enabling a security engineer to quickly investigate and respond.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious or unauthorized behavior, including communication with known command and control (C2) servers. It uses threat intelligence feeds, such as those from AWS and third-party partners, to check the reputation of destination IP addresses and alert on suspicious outbound traffic. In this scenario, GuardDuty can directly identify if the EC2 instance is communicating with a known C2 server by analyzing VPC Flow Logs, DNS logs, and other data sources.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (which only capture raw network metadata) with a security analysis service like GuardDuty, assuming that flow logs alone can determine IP reputation without additional threat intelligence integration.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API calls and management events, not network traffic or IP reputation checks; it cannot analyze outbound traffic to an unknown IP address. Option B is wrong because VPC Flow Logs capture metadata about IP traffic (source/destination IP, ports, protocol) but do not provide threat intelligence or reputation scoring for destination IPs; they only log the raw network flow data. Option C is wrong because AWS Trusted Advisor inspects your AWS environment for best practices in cost, performance, security, and fault tolerance, but it does not perform real-time threat detection or IP reputation checks against C2 servers.

678
MCQmedium

A company uses AWS IAM Identity Center (AWS SSO) to manage access. A user is assigned to a permission set that grants AdministratorAccess. However, when the user tries to access the AWS console, they receive an error that they are not authorized. What is a possible reason?

A.The user is not assigned to the AWS account in Identity Center
B.The user has not set up MFA
C.The permission set does not include the necessary policies
D.The user does not have permissions to manage permission sets
AnswerA

In AWS IAM Identity Center, access to an AWS account is granted only after an account assignment links the user (or a group containing them) to a permission set in that account. The assignment is what provisions the temporary IAM role credentials, so without it the portal might still list the account but authorization fails because no IAM role exists for that user. This missing assignment is exactly the root cause and must be created in the console or CLI before access is possible.

Why this answer

In AWS IAM Identity Center, a user must be assigned to both a permission set and an AWS account. The error occurs when the user has the permission set but not the account assignment. Option B is incorrect because MFA is about authentication, not authorization; the user could be authenticated but still lack access to the account.

Option C is incorrect because the permission set already includes AdministratorAccess, which provides full permissions; the issue is the account assignment. Option D is incorrect because the error is about accessing the console, not about managing permission sets.

679
MCQhard

A company has a VPC with public and private subnets. The private subnets need to access the internet for software updates. The security engineer has set up a NAT gateway in a public subnet and updated the route tables accordingly. However, instances in the private subnets cannot reach the internet. The engineer checks the security group for the NAT gateway and finds that it allows all outbound traffic. What is the most likely cause of the issue?

A.The route table for the private subnet does not have a default route (0.0.0.0/0) pointing to the NAT gateway.
B.The NAT gateway does not have an Elastic IP address assigned.
C.The security group for the NAT gateway does not allow inbound traffic from the private subnets.
D.The network ACL for the private subnet does not allow inbound HTTP/HTTPS traffic.
AnswerA

For instances in a private subnet to reach the internet through a NAT gateway, the subnet's route table must have a default route (0.0.0.0/0) with the NAT gateway as the target. If this route is missing, any outbound internet-bound traffic has no valid next hop and is dropped, causing the connectivity failure. After adding this route, ensure the NAT gateway itself is in a public subnet with an associated Elastic IP and that the public subnet's route table points 0.0.0.0/0 to an internet gateway. This is the most direct and common cause when private instances cannot access the internet.

Why this answer

The most likely cause is that the route table for the private subnet does not have a default route (0.0.0.0/0) pointing to the NAT gateway. Without this route, traffic from private instances cannot reach the NAT gateway, and thus cannot access the internet. Option B is incorrect because a NAT gateway must have an Elastic IP assigned during creation, so it would not be missing.

Option C is incorrect because NAT gateways do not have security groups; they are managed by AWS and the security group concept does not apply. Option D is incorrect because network ACLs are stateless and must allow both inbound and outbound traffic, but the issue here is more likely with routing.

Exam trap

The trap is that the engineer focuses on a non-existent security group for the NAT gateway, while the real issue is the missing default route in the private subnet's route table. Candidates may incorrectly assume security groups apply to NAT gateways or overlook the route table configuration.

How to eliminate wrong answers

Option A is wrong because it is actually the most likely cause of the issue—the private subnet's route table must have a default route (0.0.0.0/0) pointing to the NAT gateway for internet access; without it, traffic cannot be directed to the NAT gateway. Option B is wrong because a NAT gateway requires an Elastic IP address to function; if it were missing, the NAT gateway would not be provisioned correctly, but the question states the NAT gateway is set up, implying an EIP is assigned. Option D is wrong because network ACLs are stateless and must allow both inbound and outbound traffic for ephemeral ports; however, the private subnet's network ACL typically allows outbound HTTP/HTTPS by default, and inbound traffic from the internet is not required for instances initiating outbound connections.

680
Multi-Selecthard

A company wants to restrict access to an S3 bucket so that only requests from a specific VPC endpoint are allowed. The bucket policy must deny all requests that do not come from the VPC endpoint. Which TWO statements are true for this configuration?

Select 2 answers
A.Use the aws:SourceIp condition key to restrict IP addresses.
B.Set the Principal to the VPC endpoint ID.
C.Use the aws:SourceVpce condition key in the bucket policy.
D.Set the Effect to Deny and include a condition for the VPC endpoint.
E.Ensure the bucket policy has an explicit Allow for the VPC endpoint.
AnswersC, D

The aws:SourceVpce condition key is the standard and most direct way to restrict S3 bucket access to a single VPC endpoint. By including this condition in a bucket policy statement, you can match the VPC endpoint ID that appears in the request context, ensuring only requests that come through that endpoint are allowed. For example, you can pair an Allow effect for the endpoint's traffic with Principal '*' and the condition 'StringEquals' on aws:SourceVpce, providing fine-grained control.

Why this answer

Option C is correct because the aws:SourceVpce condition key is the specific global condition key that evaluates the VPC endpoint ID (vpce-xxxxxxxx) from which the request originates, allowing the policy to match traffic coming through that endpoint. Option D is correct because to block everything except the endpoint, the statement must use "Effect": "Deny" combined with a condition such as "StringNotEquals": {"aws:SourceVpce": "vpce-12345678"}, which denies any request whose source VPC endpoint does not match the specified one. Option A is not appropriate because aws:SourceIp matches public IP addresses and cannot reliably identify traffic originating from a VPC endpoint, which uses private IPs and is better identified by its endpoint ID.

Option B is incorrect because the Principal element identifies the AWS identity (account, user, or role) making the request, not the VPC endpoint; the endpoint is referenced through the aws:SourceVpce condition key instead. Option E is incorrect because an explicit Allow is not required for this restriction; a Deny with a negated condition is sufficient to block all non-endpoint requests, and adding an Allow would not by itself enforce the restriction.

Exam trap

The trap here is that candidates often confuse the `aws:SourceVpce` condition key with the `aws:SourceIp` key or incorrectly assume that a VPC endpoint can be set as a Principal, leading them to pick Option A or B, while also missing that a Deny-based policy with the condition is the correct pattern rather than an explicit Allow.

681
MCQmedium

A security engineer notices that an S3 bucket containing sensitive logs is publicly accessible. Which service should be used to automatically remediate this by applying a bucket policy?

A.AWS Config
B.Amazon GuardDuty
C.AWS Trusted Advisor
D.AWS CloudTrail
AnswerA

AWS Config rules continuously evaluate the bucket against your desired state; a remediation action then invokes the bucket policy automatically. This satisfies the automatic remediation requirement, unlike services that only detect or report public access without applying policy changes.

Why this answer

AWS Config is the correct service because it can continuously monitor S3 bucket configurations and automatically remediate non-compliant resources using AWS Config Rules and AWS Systems Manager Automation documents. When a rule detects that an S3 bucket is publicly accessible, it can trigger an automatic remediation action, such as applying a bucket policy that denies all public access, without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Config's monitoring and remediation capabilities with GuardDuty's threat detection or Trusted Advisor's advisory checks, failing to recognize that only AWS Config supports automated, rule-based remediation actions.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events to identify malicious activity, but it cannot automatically remediate S3 bucket policies. Option C is wrong because AWS Trusted Advisor provides best-practice recommendations and security checks, including S3 bucket permissions, but it does not have native automated remediation capabilities; it only generates alerts. Option D is wrong because AWS CloudTrail is a logging service that records API calls for auditing and does not have the ability to apply or modify bucket policies automatically.

682
MCQeasy

Which AWS service can be used to detect and alert on suspicious network traffic patterns within a VPC, such as port scanning or unusual outbound traffic?

A.AWS WAF
B.Amazon GuardDuty
C.AWS Network Firewall
D.VPC Flow Logs
AnswerB

Amazon GuardDuty is a managed threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to continuously monitor VPC Flow Logs, DNS logs, and CloudTrail event logs. It identifies suspicious activity such as reconnaissance, credential compromise, or data exfiltration, and automatically generates findings that can trigger CloudWatch Events. GuardDuty is purpose-built to detect and alert on a wide range of security threats without requiring manual analysis or custom logic.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors VPC Flow Logs, DNS logs, and CloudTrail events to identify suspicious network traffic patterns such as port scanning, unusual outbound traffic, and other malicious activities. It uses machine learning, anomaly detection, and integrated threat intelligence to generate security alerts without requiring manual rules or signatures.

Exam trap

The trap here is that candidates confuse VPC Flow Logs (a raw data source) with a detection service, or assume AWS Network Firewall's stateful inspection includes anomaly-based alerting, when in fact GuardDuty is the only service that provides automated threat detection and alerting for network patterns like port scanning and unusual outbound traffic.

How to eliminate wrong answers

Option A is wrong because AWS WAF is a web application firewall that protects against common web exploits like SQL injection and cross-site scripting at the application layer (HTTP/HTTPS), not for detecting network-level anomalies like port scanning or unusual outbound traffic within a VPC. Option C is wrong because AWS Network Firewall is a stateful managed firewall that enforces network traffic rules (e.g., allow/deny based on IP, port, protocol) but does not perform threat detection or anomaly-based alerting for patterns like port scanning; it requires explicit rule configuration. Option D is wrong because VPC Flow Logs is a raw logging feature that captures metadata about IP traffic (e.g., source/destination IP, port, protocol) but does not analyze, detect, or alert on suspicious patterns; it only provides the data that services like GuardDuty consume.

683
Multi-Selectmedium

A company is designing a VPC with multiple subnets. The security team wants to ensure that traffic between the application tier and database tier is encrypted in transit. Which TWO actions should be taken?

Select 2 answers
A.Attach an internet gateway to the database subnet
B.Enable encryption on the database connections using TLS/SSL
C.Use security group rules to restrict traffic to the database port
D.Configure the application to use an encrypted protocol when connecting to the database
E.Use VPC Peering to connect the subnets
AnswersB, D

Enabling TLS/SSL on the database connections encrypts the entire session between the application and the database, protecting the data from eavesdropping or tampering while it traverses the network. This is a direct, protocol-level mitigation for the lack of encryption between the application and the database, and it can be enforced at the database server (e.g., requiring SSL/TLS for all client connections) and supported by the client driver. It does not change network routing or access control, but it specifically ensures confidentiality and integrity of the data in transit.

Why this answer

Option B is correct because enabling TLS/SSL on the database connections ensures that the data transmitted between the application tier and database tier is encrypted in transit, protecting it from interception or eavesdropping. Option D is correct because configuring the application to use an encrypted protocol (such as TLS/SSL) when connecting to the database is necessary to actually initiate and negotiate the encrypted session, complementing the database-side encryption. Option A is incorrect because an internet gateway only enables internet connectivity for a subnet and does not encrypt traffic between internal tiers.

Option C is incorrect because security group rules restrict which ports and sources can communicate but do not provide encryption in transit. Option E is incorrect because VPC peering connects subnets or VPCs for routing purposes but does not encrypt the traffic between them.

Exam trap

SCS-C02 often tests the misconception that network-level controls like security groups or VPC peering automatically provide encryption, when in fact encryption in transit requires explicit configuration at both the database and application layers.

684
MCQmedium

A company is running a critical application on EC2 instances behind an Application Load Balancer. The security team wants to ensure that only traffic from the ALB reaches the EC2 instances. How can this be achieved?

A.Use the ALB's private IP address in the EC2 security group.
B.Configure a Network ACL to allow only the ALB's subnet.
C.Reference the ALB's security group in the EC2 security group inbound rule.
D.Use the ALB's public IP address in the EC2 security group.
AnswerC

By using the ALB's security group as the source in the instance's inbound rule, the rule matches traffic from any ENI that has that security group attached. As the ALB scales, its new ENIs are automatically covered because they inherit the same security group, so the rule remains current without manual updates. This creates a precise, security-group-to-security-group boundary that ensures only the ALB can initiate traffic to the instances, which is the recommended pattern.

Why this answer

You can reference the ALB's security group as the source in the EC2 instance's security group inbound rule. This allows traffic only from the ALB, regardless of the ALB's IP addresses (which can change if the ALB scales). The security group reference is resolved dynamically by AWS, ensuring that only traffic originating from the ALB's elastic network interfaces (ENIs) is permitted.

Exam trap

The trap here is that candidates often confuse the stateless nature of Network ACLs with the stateful behavior of security groups, leading them to choose Option B, but NACLs cannot filter based on security group IDs and would allow traffic from any source in the subnet, not just the ALB.

How to eliminate wrong answers

Option A is wrong because the ALB's private IP addresses are not static; they can change when the ALB scales or its subnets are modified, making this approach unreliable and requiring constant updates. Option B is wrong because a Network ACL (NACL) is stateless and operates at the subnet level, not the instance level; it would allow traffic from any source in the ALB's subnet, including non-ALB instances or services, and does not provide the granularity of security group references. Option D is wrong because the ALB's public IP addresses are not used for traffic between the ALB and EC2 instances; that traffic flows over the AWS internal network using private IPs, and public IPs are not reliable or secure for this purpose.

685
MCQhard

An IAM policy includes: { "Effect": "Allow", "Action": "iam:PassRole", "Resource": "arn:aws:iam::*:role/MyRole" }. What does this allow?

A.Allows the user to create the role MyRole.
B.Allows the user to pass the role MyRole to an AWS service like Lambda.
C.Allows the user to assume the role MyRole.
D.Allows the user to attach the role to an IAM user.
AnswerB

This is the exact definition of iam:PassRole: it permits a user to specify an existing IAM role as a configuration parameter for an AWS service, such as setting the execution role for a Lambda function or the instance profile for an EC2 instance. The user is not assuming the role themselves, but rather delegating the role to the service so that the service can use its permissions after assuming it via its trust policy.

Why this answer

Iam:PassRole allows a user to pass a role to an AWS service such as Lambda, enabling the service to assume that role. Option A is incorrect because creating a role requires the iam:CreateRole action, not iam:PassRole. Option C is incorrect because assuming a role requires the sts:AssumeRole action.

Option D is incorrect because attaching a role to an IAM user is not a valid operation; roles are attached to services, not users.

686
Multi-Selecthard

Which TWO steps are part of the forensic acquisition process for an EC2 instance suspected of being compromised?

Select 2 answers
A.Stop the instance immediately to prevent further damage.
B.Enable termination protection on the instance.
C.Terminate the instance to ensure the threat is contained.
D.Capture the instance's memory using a forensic tool.
E.Create a snapshot of the root EBS volume.
AnswersD, E

Capturing memory using a forensic tool is a correct forensic acquisition step because RAM contains volatile data such as running processes, open network connections, loaded kernel modules, and decryption keys that are lost when power is removed. In AWS, memory capture must be performed on the live instance, typically using tools like LiME or a memory dump utility, before any shutdown or snapshot. This preserves the most ephemeral evidence first, following the order of volatility.

Why this answer

Capturing the instance's memory using a forensic tool (such as LiME or F-Response) preserves volatile data—including running processes, network connections, and encryption keys—that would be lost if the instance were stopped or terminated. This is a critical step in the forensic acquisition process to gather evidence of compromise without altering the system state.

Exam trap

The trap here is that candidates often confuse incident response containment (stopping or terminating the instance) with forensic acquisition, which requires preserving both volatile memory and disk state before any changes are made.

687
MCQeasy

A company wants to grant temporary credentials to mobile app users to access their own data in an S3 bucket. Which AWS service should be used to achieve this securely?

A.Amazon Cognito identity pools
B.AWS Key Management Service (KMS)
C.IAM users with long-term access keys
D.Amazon CloudFront signed URLs
AnswerA

Amazon Cognito identity pools are purpose-built for granting temporary AWS credentials to mobile app users. When an identity is authenticated (via Cognito User Pools, social providers, or SAML), the identity pool exchanges the user's token for short-lived credentials by assuming an IAM role. These credentials are scoped to that role's permissions and automatically expire, eliminating the need to embed or manage long-term access keys. This is the standard serverless pattern for secure mobile access to AWS APIs.

Why this answer

Cognito Identity Pools can issue temporary AWS credentials for authenticated users. Option B is wrong because IAM users are not suitable for millions of mobile users. Option C is wrong because KMS is for encryption keys.

Option D is wrong because CloudFront is a CDN, not for issuing credentials.

688
MCQeasy

A company wants to ensure that all API calls made to their AWS account are logged and immutable. They have enabled AWS CloudTrail and are delivering logs to an S3 bucket. The security team requires that logs cannot be deleted or modified by anyone, including the root user. What should they do?

A.Enable S3 Object Lock with Compliance retention mode on the bucket.
B.Enable MFA Delete on the S3 bucket.
C.Enable S3 Versioning on the bucket.
D.Add a bucket policy that denies s3:DeleteObject for all principals.
AnswerA

S3 Object Lock in Compliance mode enforces a write-once-read-many retention period that no principal, including the AWS account root user, can shorten or bypass, so CloudTrail log objects cannot be deleted or altered for the mandated duration.

Why this answer

S3 Object Lock in Compliance mode prevents any principal — including the root user and AWS itself — from deleting or overwriting an object version until its retention period expires. This is the only option that provides true WORM (write once, read many) immutability for CloudTrail logs. It satisfies the requirement that logs cannot be deleted or modified by anyone, including root.

Exam trap

SCS-C02 often tests the confusion between MFA Delete, versioning, and Object Lock — candidates must know that only Object Lock Compliance mode is truly immutable against root, while MFA Delete and bucket policies are not.

How to eliminate wrong answers

Option B is wrong because MFA Delete only requires multi-factor authentication for delete operations — a root user with MFA can still delete objects, so it does not meet the 'including root user' requirement. Option C is wrong because S3 Versioning preserves prior versions but does not prevent deletion of the current version or the object entirely. Option D is wrong because a bucket policy denying s3:DeleteObject can be modified or removed by an account administrator or root user, so it is not immutable.

689
Multi-Selecthard

A company wants to enforce encryption in transit for all traffic between its VPC and on-premises data center over AWS Direct Connect. Which TWO configurations can achieve this?

Select 2 answers
A.Use a public virtual interface with Direct Connect and configure an IPsec VPN over it.
B.Use a Site-to-Site VPN connection over the internet.
C.Use a Direct Connect Gateway and configure an IPsec VPN over the private virtual interface.
D.Use a Transit VPC architecture with VPN attachments.
E.Use a private virtual interface with Direct Connect.
AnswersA, C

A Direct Connect public virtual interface links to AWS public services over the dedicated connection, but the traffic on the link itself is unencrypted. By overlaying an IPsec VPN tunnel on that public VIF, you encrypt all traffic while still using the Direct Connect physical link, satisfying both the Direct Connect and encryption-in-transit mandates. This approach is the standard way to add encryption to a Direct Connect connection that also needs access to public AWS endpoints.

Why this answer

A public virtual interface over Direct Connect provides connectivity to public AWS endpoints, and by layering an IPsec VPN on top, you encrypt all traffic between your VPC and on-premises data center. This ensures encryption in transit while leveraging the low latency and reliability of Direct Connect. Option C is correct because a Direct Connect Gateway allows you to connect multiple VPCs to a Direct Connect private virtual interface, and configuring an IPsec VPN over that private virtual interface encrypts traffic end-to-end, meeting the encryption requirement.

Exam trap

The trap here is that candidates often assume a private virtual interface alone provides encryption, but it does not—it only provides a private network path, and encryption must be explicitly added via IPsec or a similar protocol.

690
MCQeasy

A company wants to ensure that all IAM users have multi-factor authentication (MFA) enabled. Which AWS service can be used to detect users without MFA and automatically send a notification?

A.AWS Trusted Advisor
B.AWS CloudTrail
C.AWS Config
D.AWS IAM
AnswerC

AWS Config continuously records configuration items for IAM users and supports the managed rule iam-user-mfa-enabled, which evaluates whether each IAM user has MFA enabled and marks noncompliant users in the Config dashboard. When a user becomes noncompliant, Config can publish evaluation results to Amazon SNS, triggering notifications or automated remediation via Systems Manager Automation. It also provides configuration history and snapshots so you can audit MFA status over time, making it the correct service for continuously verifying that all IAM users have multi-factor authentication.

Why this answer

AWS Config is the correct answer because it provides a managed rule 'iam-user-mfa-enabled' that can evaluate whether IAM users have MFA enabled. When a non-compliant user is detected, AWS Config can trigger an SNS notification to alert administrators. AWS Trusted Advisor (option A) only checks MFA on the root account, not all IAM users.

AWS CloudTrail (option B) records API activity but does not evaluate configuration rules. AWS IAM (option D) itself does not have automatic detection and notification capabilities for MFA status.

691
MCQhard

Refer to the exhibit. This is a line from a VPC Flow Log. A security analyst notices that the log shows an ACCEPT record for a connection from 10.0.1.5 to 10.0.2.10 on port 443. However, the analyst expected the connection to be denied. Which field in the flow log record indicates that the connection was accepted?

A.The action field (ACCEPT)
B.The version field (2)
C.The protocol field (6)
D.The destination port field (443)
AnswerA

The action field in VPC Flow Logs records whether the traffic was accepted or rejected by security groups and network ACLs. A value of ACCEPT confirms that the flow was allowed, making this the only field that directly answers the question of whether the traffic was permitted or blocked. Without evaluating this field, no other field can determine the outcome.

Why this answer

The action field in a VPC Flow Log record explicitly indicates whether the firewall (security group or network ACL) allowed or denied the traffic. In this case, the value 'ACCEPT' confirms that the connection from 10.0.1.5 to 10.0.2.10 on port 443 was permitted, which is why the analyst sees an ACCEPT record despite expecting a denial.

Exam trap

The trap here is that candidates may confuse the protocol or port fields with the action field, mistakenly thinking that the presence of a specific protocol (TCP) or port (443) implies acceptance, when only the action field directly records the firewall's decision.

How to eliminate wrong answers

Option B is wrong because the version field (2) indicates the flow log record format version, not the connection's acceptance or denial. Option C is wrong because the protocol field (6) represents TCP (per IANA protocol numbers), but it only identifies the transport protocol, not whether the traffic was allowed. Option D is wrong because the destination port field (443) shows the target port for HTTPS traffic, but it does not indicate the firewall's decision to accept or reject the connection.

692
MCQeasy

A company's security team wants to detect unauthorized S3 bucket access attempts in real time. Which service should they use to generate alerts when an IAM user attempts to access a bucket without proper permissions?

A.Amazon GuardDuty
B.AWS CloudTrail with CloudWatch alarms
C.S3 server access logs
D.AWS Config
AnswerB

AWS CloudTrail records all S3 API requests as event history, and by enabling data events, it captures object-level operations such as GetObject and PutObject. By delivering these events to CloudWatch Logs, you can create metric filters that match S3 error responses such as AccessDenied (403) or AuthorizationError, and then attach a CloudWatch alarm to trigger SNS notifications. Because CloudTrail pushes events to CloudWatch Logs near real time, it enables immediate detection of unauthorized access attempts. This makes it the most suitable option for real-time alerting on actual access denials.

Why this answer

AWS CloudTrail logs all API calls made to S3, including access denied errors. By creating a CloudWatch alarm on the `S3 AccessDenied` event in CloudTrail logs, the security team can receive real-time alerts when an IAM user attempts to access a bucket without proper permissions. This approach directly captures the unauthorized attempt at the API level, enabling immediate detection.

Exam trap

The trap here is that candidates often choose Amazon GuardDuty because it is associated with threat detection, but they overlook that GuardDuty does not provide real-time, per-user unauthorized access alerts for S3; instead, CloudTrail with CloudWatch alarms directly captures the specific API error event needed for this use case.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events for malicious activity, but it does not generate real-time alerts specifically for individual IAM user unauthorized S3 access attempts; it focuses on broader threat patterns. Option C is wrong because S3 server access logs are delivered on a best-effort basis, typically with a delay of several hours, making them unsuitable for real-time alerting. Option D is wrong because AWS Config is a service for evaluating resource compliance and tracking configuration changes, not for monitoring real-time API access attempts or generating alerts for unauthorized access.

693
MCQmedium

A company uses AWS CloudTrail to log all API activity. The security team needs to retain the logs for 7 years and ensure they are tamper-proof. Additionally, the team must be able to query the logs for investigations. Which solution meets these requirements?

A.Store logs in AWS CloudTrail Lake and use the built-in query feature.
B.Store logs in Amazon CloudWatch Logs with a retention policy of 7 years.
C.Store logs in an Amazon S3 bucket with standard settings and use Amazon S3 Select for querying.
D.Store logs in an Amazon S3 bucket with S3 Object Lock enabled and query using Amazon Athena.
AnswerD

The correct solution combines S3 Object Lock in either governance or compliance mode with Amazon Athena. Object Lock enforces a retention period that prevents any user — including an AWS account root user — from deleting or overwriting log files, and Athena can directly query the partitioned S3 logs using standard SQL through the Glue Data Catalog. This yields a durable, tamper-evident, serverless analytics pipeline for long-term CloudTrail log storage.

Why this answer

Amazon S3 Object Lock provides a write-once-read-many (WORM) model that prevents logs from being deleted or overwritten, ensuring tamper-proof retention for 7 years. Amazon Athena allows querying the logs directly in S3 using standard SQL, meeting the investigation requirement without needing to move data.

Exam trap

The trap here is that candidates often choose CloudTrail Lake (Option A) because it offers built-in querying, but they overlook the tamper-proof requirement, which only S3 Object Lock can guarantee for long-term retention.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail Lake is designed for short-term retention and analysis (up to 7 years but with limited query capabilities and higher cost), and it does not provide native tamper-proof controls like S3 Object Lock. Option B is wrong because Amazon CloudWatch Logs has a maximum retention period of 10 years, but it does not offer tamper-proof features; logs can be deleted or modified by authorized users, and querying is limited to CloudWatch Logs Insights, which is not as flexible as Athena for large-scale analysis. Option C is wrong because storing logs in an S3 bucket with standard settings does not prevent tampering—logs can be overwritten or deleted—and Amazon S3 Select is limited to simple filtering and cannot handle complex SQL queries needed for thorough investigations.

694
Multi-Selectmedium

An IAM policy includes the following statement: 'Effect': 'Allow', 'Action': 's3:GetObject', 'Resource': 'arn:aws:s3:::example-bucket/*', 'Condition': {'IpAddress': {'aws:SourceIp': '192.0.2.0/24'}}. Which TWO statements about this policy are correct?

Select 2 answers
A.The policy allows s3:PutObject from the IP range 192.0.2.0/24.
B.Requests from outside 192.0.2.0/24 will be implicitly denied.
C.The policy allows s3:GetObject only if the bucket owner matches.
D.The policy allows anonymous access.
E.The policy allows s3:GetObject from the IP range 192.0.2.0/24.
AnswersB, E

This is correct because an IAM policy's Allow effect only takes effect when all conditions are satisfied. The IpAddress condition restricts valid source IPs to 192.0.2.0/24; if a request originates outside that range, the condition fails and the Allow does not apply. Since no other statement explicitly allows the action, the request is implicitly denied by default.

Why this answer

Option E is correct because the statement's Action is s3:GetObject and its Condition restricts aws:SourceIp to 192.0.2.0/24, so the allow applies exactly to GetObject requests originating from that CIDR range. Option B is correct because IAM policies are deny-by-default: any request that does not satisfy the IpAddress condition (i.e., comes from outside 192.0.2.0/24) is not matched by this Allow and is therefore implicitly denied, absent another applicable allow. Option A is wrong because s3:PutObject is not listed in the Action, so the policy never grants write access.

Option C is wrong because there is no condition on bucket ownership; the only condition is the source IP. Option D is wrong because the policy grants no anonymous/public access by itself—it only allows GetObject when the request's source IP falls in the specified range, and it does not remove authentication requirements.

Exam trap

SCS-C02 often tests IAM policy evaluation logic — candidates forget that a Condition on an Allow statement means requests failing the condition are implicitly denied, and they confuse GetObject with PutObject or assume the policy grants anonymous access.

695
MCQeasy

A company wants to centrally manage backups for Amazon RDS instances across multiple AWS accounts. Which AWS service should be used to automate the creation and enforcement of backup policies?

A.S3 Lifecycle policies
B.AWS Backup
C.AWS CloudTrail
D.AWS Systems Manager
AnswerB

AWS Backup is the correct service because it provides a centralized, fully managed backup layer that can govern Amazon RDS databases across accounts and Regions. You define backup plans with schedules, lifecycle rules, and a retention period, then assign resources by tags or ID. It also supports cross-account backup copying and integration with AWS Organizations, enabling consistent backup compliance and centralized recovery point management for RDS workloads.

Why this answer

AWS Backup allows centralized backup policies across accounts and regions. Option A is wrong because S3 Lifecycle policies are for object lifecycle, not RDS backups. Option C is wrong because CloudTrail is for auditing API calls.

Option D is wrong because Systems Manager is for operational management, not backup policies.

696
MCQhard

A company uses AWS Organizations with multiple accounts. The security team wants to ensure that all CloudTrail trails are enabled and logging to a central S3 bucket. They need to detect any account that disables or modifies its CloudTrail trail. Which approach meets these requirements with the least operational overhead?

A.Use AWS Config rules with an aggregator in the management account to evaluate CloudTrail configuration across all accounts.
B.Enable CloudTrail Insights in all accounts to detect unusual activity.
C.Enable IAM Access Analyzer in each account to monitor CloudTrail changes.
D.Create a Lambda function that periodically checks CloudTrail status in each account via the API.
AnswerA

AWS Config rules can run managed or custom rules against the configuration of CloudTrail trails, and an aggregator in the management account lets you view compliance results from all member accounts in a single dashboard. When a trail is misconfigured or deleted, the rule evaluates the change and can trigger an Amazon EventBridge event to notify administrators. This is the only option that provides continuous, native, multi-account governance without writing custom monitoring code or relying on external scheduling.

Why this answer

AWS Config rules with an aggregator in the management account can evaluate CloudTrail configuration across all accounts in AWS Organizations without deploying per-account resources. The aggregator collects configuration snapshots and changes from member accounts, allowing a single managed rule (e.g., cloud-trail-enabled) to detect when a trail is disabled or modified. This approach minimizes operational overhead because it uses native AWS services with no custom code or cross-account IAM roles to manage.

Exam trap

The trap here is that candidates may think a custom Lambda function (Option D) is necessary for cross-account monitoring, overlooking that AWS Config with an aggregator natively supports multi-account evaluation with far less operational overhead.

How to eliminate wrong answers

Option B is wrong because CloudTrail Insights detects unusual API activity (e.g., write events with error rates), not configuration changes to the trail itself; it does not monitor whether a trail is enabled or modified. Option C is wrong because IAM Access Analyzer analyzes resource-based policies for external access, not CloudTrail trail configuration or status; it cannot detect trail disablement or modification. Option D is wrong because a Lambda function that periodically checks CloudTrail status via the API requires custom code, cross-account IAM roles, and scheduling infrastructure, resulting in higher operational overhead compared to a managed AWS Config rule with an aggregator.

697
Multi-Selecteasy

A company is using AWS Organizations and wants to restrict the use of specific AWS services in member accounts. Which TWO approaches can be used to enforce these restrictions? (Choose TWO.)

Select 2 answers
A.Use Service Quotas to limit the number of resources per service.
B.Enable AWS CloudTrail to log service usage.
C.Apply a service control policy (SCP) to the organizational unit (OU).
D.Create IAM policies in each member account to deny access to the services.
E.Use AWS Config rules to automatically terminate resources.
AnswersC, D

Applying an SCP to the OU is the correct preventive control at the AWS Organizations level. An SCP can explicitly deny actions for all AWS services or specific services (e.g., ec2:*) across every member account under that OU, and it applies to all IAM principals including the root user. SCPs operate at the account boundary as an allowlist or denylist, and effective permissions are the intersection of the SCP and the IAM identity/resource policies, ensuring that a centrally defined deny cannot be bypassed by per-account IAM policies.

Why this answer

Option C is correct because service control policies (SCPs) in AWS Organizations define the maximum available permissions for accounts in an OU, and an SCP that denies access to specific AWS services will block those services for all principals in the affected member accounts (except the management account). Option D is correct because IAM policies attached to users, groups, or roles in each member account can include explicit Deny statements for the actions of the services to be restricted, thereby enforcing the restriction at the identity level within that account. Option A is not correct because Service Quotas only cap the quantity of resources or API rates per service; they do not block the use of a service.

Option B is not correct because AWS CloudTrail only records API activity for auditing and does not enforce any restriction. Option E is not correct because AWS Config rules evaluate and report on resource compliance; they detect and can trigger remediation, but they do not themselves prevent or terminate service usage as an enforcement mechanism.

Exam trap

SCS-C02 often tests service restriction methods, and candidates may select Service Quotas or CloudTrail, which do not enforce restrictions.

698
MCQhard

An organization has a VPC with public and private subnets. A NAT Gateway is deployed in a public subnet to allow instances in private subnets to access the internet. The security team notices that instances in a private subnet can reach the internet, but cannot initiate connections to an on-premises network connected via AWS Direct Connect. The on-premises network advertises a specific route. What is the most likely cause?

A.The security group assigned to the instances does not allow outbound traffic to the on-premises network.
B.The network ACL on the private subnet is blocking inbound traffic from the on-premises network.
C.The private subnet route table has a route for the on-premises CIDR pointing to the NAT Gateway.
D.The internet gateway is not attached to the VPC.
AnswerC

Route tables in the VPC control where each destination CIDR is sent. If the private subnet route table contains a route for the on-premises CIDR pointing to the NAT Gateway, traffic destined for on-premises is sent to the NAT Gateway, which is designed only for internet-bound traffic and cannot forward it across the Direct Connect or virtual private gateway. Because the route to the NAT Gateway overrides the propagated Direct Connect route, the instances cannot reach on-premises resources. This is the correct root cause.

Why this answer

The most likely cause is that the private subnet's route table has a route for the on-premises CIDR pointing to the NAT Gateway instead of the Direct Connect virtual private gateway (VGW) or transit gateway. A NAT Gateway only translates traffic to the internet — it cannot forward traffic to on-premises networks, so the route is misdirected and the connection fails.

Exam trap

SCS-C02 often tests the limitation that NAT Gateway only handles internet-bound traffic, tricking candidates into thinking a NAT route can reach on-premises — the correct next-hop for on-premises is always the VGW or TGW.

How to eliminate wrong answers

Option A is wrong because security groups are stateful and by default allow all outbound traffic; even if outbound were restricted, the symptom would be a timeout on all outbound traffic, not specifically on-premises. Option B is wrong because the issue is outbound initiation from the private subnet, not inbound from on-premises — and NACLs are stateless but the described symptom points to routing, not filtering. Option D is wrong because the instances can already reach the internet, which proves the IGW is attached and functioning.

699
MCQmedium

A company is designing a data protection solution for Amazon S3 that must prevent any user from accidentally deleting objects. Which combination of S3 features should be used?

A.Use S3 Cross-Region Replication to another bucket.
B.Enable S3 Object Lock with governance mode.
C.Configure S3 default encryption with SSE-KMS.
D.Enable S3 Versioning and MFA Delete.
AnswerD

Enabling S3 Versioning together with MFA Delete is the correct answer because versioning preserves every overwrite and deletion as a previous version, while MFA Delete adds a second-factor requirement for permanently erasing versions or changing the bucket's versioning state. When an object is deleted, S3 simply creates a delete marker and the prior versions remain recoverable; without the MFA token, even the AWS account root user cannot permanently delete a version, which effectively prevents accidental or malicious deletion.

Why this answer

Enabling S3 Versioning preserves all object versions, allowing recovery of deleted objects, and MFA Delete requires multi-factor authentication for permanent deletions, preventing accidental or unauthorized deletions. Option A is wrong because Cross-Region Replication copies objects to another bucket but does not prevent deletion of the source objects. Option B is wrong because Object Lock with governance mode prevents overwrites and deletions only if a retention period is set, but it does not block deletion of the bucket itself or version-level deletions if the lock is not applied.

Option C is wrong because default encryption (SSE-KMS) protects data at rest but does not prevent deletion of objects.

700
MCQmedium

A security engineer is designing a solution to protect data in transit for a web application that uses an Application Load Balancer (ALB) and EC2 instances. The application must use TLS 1.2 or higher and must use a strong cipher suite. The engineer has configured the ALB with a security policy that includes TLS 1.2 and strong ciphers. However, the engineer notices that some clients are still able to connect using TLS 1.0. What is the most likely cause of this issue?

A.The ALB listener is configured with a security policy that includes TLS 1.0, and the engineer's changes were not applied to the correct listener.
B.The EC2 instances behind the ALB are configured to allow TLS 1.0, and the ALB is passing through the TLS connection.
C.The clients are using a proxy that downgrades the TLS version, and the ALB cannot enforce the minimum TLS version.
D.The ALB is configured with a default security policy that allows TLS 1.0.
AnswerA

If the engineer updated the security policy on one listener but the application uses another listener (e.g., a different port), clients connecting to the unchanged listener could still use TLS 1.0. This is a common misconfiguration where changes are applied to the wrong listener or the listener is not updated. The scenario states that some clients can use TLS 1.0, indicating that a listener with a permissive policy is still active.

Why this answer

The most likely cause is that the security policy change was not applied to the correct listener. ALBs can have multiple listeners, and if the application uses a different listener that still has a permissive security policy, clients can connect with TLS 1.0. The engineer should verify all listeners and ensure the restrictive policy is applied to the one handling the traffic.

Exam trap

The trap here is assuming that updating the security policy on one listener automatically applies to all listeners, but each listener must be configured separately.

701
Matchingmedium

Match each AWS security-related acronym to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Center for Internet Security

Payment Card Industry Data Security Standard

Health Insurance Portability and Accountability Act

System and Organization Controls

International standard for information security management

Why these pairings

The correct matches are: SOC with service organization controls, PCI DSS with credit card security, HIPAA with healthcare privacy, and FedRAMP with cloud authorization. Common confusions include mixing HIPAA with SOC and PCI DSS with FedRAMP.

702
MCQhard

A company has a VPC with multiple subnets across multiple Availability Zones. The security team wants to inspect all traffic between subnets for malicious activity. Which AWS service should be used?

A.VPC Flow Logs
B.AWS Network Firewall
C.AWS WAF
D.Security groups
AnswerB

AWS Network Firewall is the correct choice because it is a managed, stateful firewall that can inspect all traffic crossing subnet boundaries within the VPC, including traffic routed between application tiers or from a transit gateway. It combines stateless rule groups with stateful inspection engines (Suricata-compatible) to detect and block malicious payloads, protocol anomalies, and known threat signatures at wire speed. By forcing traffic through firewall endpoints in each Availability Zone and using route tables, you can enforce intrusion prevention and traffic filtering across the VPC, which aligns directly with the requirement for network-level threat detection and blocking.

Why this answer

AWS Network Firewall is a managed stateful firewall service that can inspect all traffic between subnets within a VPC, including east-west traffic, for malicious activity. It provides deep packet inspection (DPI) at Layers 3–7, supporting Suricata-compatible rules to detect and block threats like malware or intrusion attempts. This makes it the correct choice for the security team's requirement to inspect inter-subnet traffic.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (a logging service) with a security inspection service, or assume security groups can inspect traffic content, when in fact only AWS Network Firewall provides the required deep packet inspection for inter-subnet traffic.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs only capture metadata (source/destination IP, ports, protocol, packet count) and do not perform packet inspection or block malicious traffic; they are a logging tool, not a security enforcement point. Option C is wrong because AWS WAF is designed to protect web applications from common web exploits (e.g., SQL injection, XSS) by inspecting HTTP/HTTPS traffic at the application layer, and it cannot inspect non-web traffic or east-west traffic between subnets. Option D is wrong because security groups act as a virtual stateful firewall at the instance level, controlling inbound and outbound traffic based on allow rules, but they lack deep packet inspection capabilities and cannot detect or block malicious payloads within allowed traffic flows.

703
MCQeasy

A security engineer is reviewing CloudTrail logs and notices an event with the key 'eventType' set to 'AwsServiceEvent'. What does this indicate?

A.The event was initiated by an IAM user via the AWS Management Console.
B.The event was initiated by an AWS service.
C.The event was a sign-in event from the AWS Management Console.
D.The event type is an error in the log.
AnswerB

When the eventType is AwsServiceEvent, it means the event was generated by an AWS service performing an action on a resource, often on behalf of a customer or as part of automatic operations. The userIdentity is typically null or represents a service role, and the eventSource field identifies the service (e.g., ec2.amazonaws.com, s3.amazonaws.com). This is the correct explanation because AwsServiceEvent is the only eventType that directly maps to an action initiated by an AWS service, not by a user or a console sign-in.

Why this answer

In AWS CloudTrail, the 'eventType' field indicates the source of the event. When set to 'AwsServiceEvent', it means the event was generated by an AWS service on behalf of the customer, such as automatic backups, scaling actions, or health checks. This is distinct from events initiated by a user or federated identity, which would have 'eventType' set to 'AwsApiCall' or 'AwsConsoleSignIn'.

Exam trap

The trap here is that candidates confuse 'AwsServiceEvent' with API calls made by a user or assume it indicates an error, when in fact it specifically denotes actions initiated by AWS services themselves, not by human users or errors.

How to eliminate wrong answers

Option A is wrong because events initiated by an IAM user via the AWS Management Console have 'eventType' set to 'AwsConsoleSignIn' or 'AwsApiCall', not 'AwsServiceEvent'. Option C is wrong because sign-in events from the AWS Management Console are captured with 'eventType' set to 'AwsConsoleSignIn', not 'AwsServiceEvent'. Option D is wrong because 'AwsServiceEvent' is a valid event type indicating a service-initiated action, not an error; errors are indicated by the 'errorCode' and 'errorMessage' fields within the event record.

704
MCQeasy

A security engineer needs to ensure that all IAM policies in an AWS account are evaluated for overly permissive access, such as wildcard actions or resources, before they are attached to IAM roles. The engineer wants to automate this check and receive alerts when noncompliant policies are detected. Which AWS service should the engineer use?

A.Amazon GuardDuty
B.AWS Identity and Access Management Access Analyzer
C.AWS Security Hub
D.AWS Trusted Advisor
AnswerB

IAM Access Analyzer analyzes resource policies and IAM policies to identify overly permissive access, including wildcard actions and resources. It can generate findings and provide alerts, helping automate the detection of noncompliant policies. This directly addresses the requirement to evaluate policies before attachment.

Why this answer

IAM Access Analyzer is designed to analyze IAM policies and resource policies to identify overly permissive access, including wildcard actions and resources. It provides findings and can be integrated with other services for alerts, making it the correct choice for automating policy evaluation.

Exam trap

The trap here is confusing IAM Access Analyzer with AWS Security Hub, which aggregates findings but does not perform the policy analysis itself.

705
MCQmedium

A company uses AWS KMS to encrypt data in Amazon S3. The security team wants to ensure that when an object is retrieved, it is automatically decrypted. They have configured the S3 bucket to use SSE-KMS with a customer managed key. However, when a user downloads an object using the AWS CLI, the object is still encrypted. The IAM policy for the user includes kms:Decrypt permission. What is the MOST likely reason for this issue?

A.The KMS key policy does not allow the user to decrypt.
B.The user is using SSE-C instead of SSE-KMS.
C.The user does not have s3:GetObject permission.
D.The user is not specifying the correct encryption context in the request.
AnswerA

With SSE-KMS, S3 invokes kms:Decrypt using the requesting user's credentials every time an encrypted object is read. The KMS key policy is the resource-based policy that controls which principals can use the key; if it does not grant the user (or the user's role) kms:Decrypt, the KMS call is denied even when the user's IAM policy allows s3:GetObject. That denial manifests as an AccessDenied error during object retrieval.

Why this answer

The most likely reason is that the KMS key policy does not allow the user to decrypt. Even though the user's IAM policy includes kms:Decrypt, KMS requires that both the IAM policy and the key policy grant permission. Since the key policy is separate, it may not include the user as a principal.

Option B is incorrect because SSE-C is not indicated. Option C is incorrect because s3:GetObject is needed but the issue is decryption. Option D is incorrect because encryption context is not required for automatic decryption via S3; S3 manages it transparently.

Exam trap

Candidates often forget that KMS key policies can override IAM permissions. Even with IAM kms:Decrypt, the key policy must explicitly allow the user.

706
MCQmedium

A company has a requirement to automatically rotate secrets for an RDS database every 90 days. The secrets are stored in AWS Secrets Manager. Which resource should be configured to perform the rotation?

A.CloudWatch Logs subscription filter
B.Amazon EventBridge scheduled rule
C.AWS Config rule
D.AWS Lambda function
AnswerD

AWS Secrets Manager uses a Lambda function as the compute engine for its native rotation feature. When rotation is triggered, Secrets Manager invokes the Lambda function with different stages (createSecret, setSecret, testSecret, finishSecret) to generate and store a new secret value and update the associated service or database. You must provide the Lambda function with an IAM role that has permissions to access the secret and the target resource, and for private resources, it must be attached to a VPC. This is why the correct answer is the Lambda function, not a scheduling or compliance service.

Why this answer

AWS Secrets Manager uses a Lambda function to perform the actual rotation of secrets. When you configure rotation for a secret, you specify a Lambda function that implements the rotation logic, including creating a new secret version, updating the database credentials, and testing the new credentials. The Lambda function is invoked by Secrets Manager on the schedule you define (e.g., every 90 days).

Thus, the resource that performs the rotation is the Lambda function.

Exam trap

SCS-C02 often tests the misconception that EventBridge or other services directly rotate secrets, when in fact Secrets Manager relies on a Lambda function to perform the rotation logic.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs subscription filters are used to route log events to other services like Lambda or Kinesis, not to perform secret rotation. Option B is wrong because an EventBridge scheduled rule can trigger actions on a schedule, but it does not itself rotate secrets; it could be used to invoke a Lambda function, but the rotation logic still resides in the Lambda function. Option C is wrong because AWS Config rules evaluate resource configurations for compliance, they do not perform active rotation of secrets.

707
MCQeasy

A company is using Amazon S3 to store sensitive data. They want to ensure that all objects uploaded to a specific bucket are encrypted using server-side encryption with AWS KMS. Which bucket policy condition should be used to enforce this?

A.Condition: 's3:x-amz-server-side-encryption-customer-algorithm': 'AES256'
B.Condition: 's3:x-amz-server-side-encryption': 'aws:kms'
C.Condition: 's3:x-amz-server-side-encryption-aws-kms-key-id': 'arn:aws:kms:...'
D.Condition: 's3:x-amz-server-side-encryption': 'AES256'
AnswerB

This is the correct condition because the x-amz-server-side-encryption request header, when set to 'aws:kms', explicitly instructs S3 to encrypt the object with an AWS KMS-managed CMK upon upload. A bucket policy or IAM policy condition that checks this key and value will deny requests that specify a different encryption mode, but note that a robust enforcement policy should also explicitly deny requests that omit the header entirely (using a StringNotEquals condition) to prevent unencrypted uploads.

Why this answer

The bucket policy condition `s3:x-amz-server-side-encryption` with value `aws:kms` enforces that any PutObject request must include the `x-amz-server-side-encryption` header set to `aws:kms`. This ensures that objects are encrypted using SSE-KMS. The condition key is specific to the encryption algorithm, not the KMS key ID.

Exam trap

SCS-C02 often tests the difference between SSE-S3, SSE-KMS, and SSE-C condition keys. Candidates may confuse the condition key for the encryption algorithm with the one for the KMS key ID, or mistakenly use the customer algorithm key for KMS.

How to eliminate wrong answers

Option A is wrong because `s3:x-amz-server-side-encryption-customer-algorithm` is used for SSE-C (customer-provided keys) and expects values like `AES256`, not for KMS. Option C is wrong because `s3:x-amz-server-side-encryption-aws-kms-key-id` checks for a specific KMS key ID, but the requirement is to enforce KMS encryption, not a particular key. Option D is wrong because `AES256` corresponds to SSE-S3 (Amazon S3-managed keys), not SSE-KMS.

708
MCQeasy

A company uses Amazon CloudFront to distribute content from an S3 bucket. The security team wants to ensure that only CloudFront can access the S3 bucket. Which configuration should be used?

A.Set the bucket policy to allow all principals and rely on CloudFront to restrict access.
B.Configure the bucket policy to allow access only from CloudFront's IP addresses.
C.Create an Origin Access Identity (OAI) and grant it read access to the S3 bucket.
D.Use CloudFront trusted signers to restrict access to the S3 bucket.
AnswerC

An Origin Access Identity (OAI) is a dedicated CloudFront user identity that CloudFront uses to authenticate to S3 when fetching objects. By granting the OAI read permission (e.g., s3:GetObject) in the bucket policy and removing public access, the bucket becomes private and only requests authenticated as that OAI can succeed. This ensures direct S3 access by anonymous users is denied while CloudFront can still retrieve and distribute the content.

Why this answer

An Origin Access Identity (OAI) is a special CloudFront user that you can associate with a distribution, and then the S3 bucket policy can grant read access to that OAI, ensuring that only CloudFront can access the bucket. Option A is incorrect because allowing all principals is too permissive. Option B is incorrect because CloudFront IP addresses can change, so this is not a reliable method.

Option D is incorrect because trusted signers are used for signed URLs/cookies to control who can access content, not to restrict origin access.

709
MCQhard

Your organization uses AWS Organizations with 50 member accounts. You are the security administrator for the root account. You have enabled AWS CloudTrail in all accounts and centralized the logs in an S3 bucket in the root account. You also enabled Amazon GuardDuty in the root account and have delegated an administrator account. Recently, you received an alert from GuardDuty about a potential credential compromise in a member account. The finding indicates that an IAM user in that account made an API call from an unusual IP address. You need to quickly gather all CloudTrail events for that user from the last 30 days across all accounts. The logs are stored in a single S3 bucket with a prefix structure like 'AWSLogs/<account-id>/CloudTrail/<region>/<year>/<month>/<day>'. What is the MOST efficient way to query these logs?

A.Use Amazon Athena to query the CloudTrail logs by creating a table partitioned by account, region, and date.
B.Enable AWS CloudTrail Lake and create a new event data store that includes the historical logs.
C.Download all log files from the S3 bucket for the last 30 days and parse them locally.
D.Use Amazon CloudWatch Logs Insights to query the logs from the member account.
AnswerA

Athena is the correct choice because CloudTrail logs are stored as gzipped JSON objects in an S3 bucket, and Athena can directly query that data with standard SQL through a table defined in the AWS Glue Data Catalog. Partitioning the table by account, region, and date lets Athena perform partition pruning, so only the relevant log files are scanned, which minimizes both cost and query latency. Because the logs for all member accounts are centrally delivered to a single S3 bucket in the management account, Athena provides a serverless, cross-account query capability without needing to move or transform the data.

Why this answer

Amazon Athena is the most efficient way to query CloudTrail logs stored in S3 because it allows you to run SQL queries directly on the data without moving or downloading it. By creating a table partitioned by account, region, and date, you can quickly filter for the specific IAM user's events across all 50 accounts for the last 30 days, leveraging partition pruning to scan only the relevant log files. This approach minimizes data scanned and cost, while providing near-instant results.

Exam trap

The trap here is that candidates may think CloudTrail Lake (Option B) is the only way to query CloudTrail logs efficiently, but Athena is actually the native, cost-effective solution for querying CloudTrail logs stored in S3 without additional ingestion steps.

How to eliminate wrong answers

Option B is wrong because CloudTrail Lake requires you to create a new event data store, which would need to ingest the historical logs from S3, incurring additional costs and time for data ingestion and indexing, making it less efficient than directly querying the existing S3 logs with Athena. Option C is wrong because downloading all log files for 30 days from a multi-account S3 bucket would be extremely time-consuming, bandwidth-intensive, and impractical for 50 accounts, and parsing them locally would require significant manual effort and storage. Option D is wrong because CloudWatch Logs Insights can only query logs that are sent to CloudWatch Logs, but the CloudTrail logs are stored in S3, not in CloudWatch Logs, and even if they were, CloudWatch Logs Insights cannot query logs across multiple accounts from a single query.

710
MCQhard

A security engineer notices that S3 server access logs are not being delivered to the specified destination bucket. The source bucket has a bucket policy that grants s3:PutObject permission to the Log Delivery group. The destination bucket is in the same AWS account but a different region. What is the most likely cause of the failure?

A.The destination bucket does not have versioning enabled.
B.The destination bucket is in a different AWS account.
C.The Log Delivery group does not have an IAM role assigned.
D.The destination bucket is in a different AWS region.
AnswerD

S3 server access logs must be delivered to a destination bucket in the same AWS Region as the source bucket. The S3 logging infrastructure delivers log objects using regional endpoints, and cross-region log delivery is not supported for server access logging. If you attempt to use a destination bucket in a different Region, the configuration may fail validation in the console or, in some cases, the logs will not be delivered. This Region mismatch is precisely why the security engineer observes no server access logs flowing to the destination bucket.

Why this answer

S3 server access logs are delivered by the Log Delivery group, which is a special AWS service principal. When the destination bucket is in a different AWS region, the Log Delivery group cannot write logs cross-region because S3 server access logging only supports delivering logs to a bucket in the same region as the source bucket. This is a hard limitation of the S3 service, not a permission or configuration issue.

Exam trap

The trap here is that candidates often assume cross-region S3 operations are always supported (e.g., cross-region replication), but S3 server access logging has a specific regional restriction that is easy to overlook.

How to eliminate wrong answers

Option A is wrong because versioning on the destination bucket is not required for S3 server access log delivery; versioning is optional and unrelated to the delivery failure. Option B is wrong because the destination bucket is explicitly stated to be in the same AWS account, so cross-account issues do not apply. Option C is wrong because the Log Delivery group is a built-in AWS service principal that does not require an IAM role; it uses the bucket policy's s3:PutObject permission to write logs directly.

711
MCQeasy

A company wants to centrally collect and analyze logs from multiple AWS accounts. Which AWS service should be used to aggregate logs from various sources for monitoring and alerting?

A.Amazon S3
B.AWS Config
C.AWS CloudTrail
D.Amazon CloudWatch Logs
AnswerD

CloudWatch Logs accepts log streams from many sources, including CloudTrail, VPC Flow Logs and application agents, and supports metric filters, alarms and cross-account subscriptions. That aggregation plus alerting capability satisfies the centralised collection requirement across accounts.

Why this answer

Amazon CloudWatch Logs is the correct service because it provides a centralized platform for collecting, monitoring, and analyzing log data from multiple AWS accounts and on-premises sources. It supports cross-account log aggregation via subscription filters and cross-account destinations, enabling real-time monitoring and alerting through CloudWatch Logs Insights and metric filters. This makes it the appropriate choice for the stated requirement of central log aggregation for monitoring and alerting.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which records API calls) with a log aggregation service, but CloudTrail is a log source, not a centralized aggregation and analysis platform like CloudWatch Logs.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is an object storage service, not a log aggregation and analysis service; while logs can be stored in S3, it lacks native real-time monitoring, alerting, and query capabilities required for centralized analysis. Option B is wrong because AWS Config is a service for evaluating and auditing resource configurations against desired policies, not for collecting and analyzing logs from multiple sources. Option C is wrong because AWS CloudTrail is specifically designed to record API activity within an AWS account, but it does not aggregate logs from other services or accounts for centralized monitoring and alerting; it is a source of logs, not an aggregation platform.

712
MCQmedium

A security engineer is configuring an S3 bucket policy to restrict access to only requests that originate from a specific VPC endpoint. Which condition key should be used?

A.aws:VpcSourceIp
B.aws:SourceVpc
C.aws:SourceIp
D.aws:SourceVpce
AnswerD

aws:SourceVpce is the correct condition key because it directly evaluates the VPC endpoint ID (for example, vpce-0123abc) from which the S3 request originated. Combining a bucket policy that allows a principal like "*" with the condition "aws:SourceVpce": "vpce-0123abc" ensures the bucket is accessible only via that specific gateway or interface endpoint. Requests from the internet, other endpoints, or on-premises networks do not have the matching SourceVpce value and are denied, giving you precise, endpoint-level access control.

Why this answer

The aws:SourceVpce condition key is the correct choice because it evaluates the VPC endpoint ID (e.g., vpce-12345678) through which the request reached S3. When you attach a bucket policy that includes a condition like "aws:SourceVpce": "vpce-abc123", S3 only allows requests that traverse that specific endpoint, effectively locking the bucket to your private VPC endpoint and blocking all public internet access. This is the standard pattern for enforcing private-only access to S3 from a VPC.

Exam trap

SCS-C02 often tests the confusion between aws:SourceVpc (the VPC ID) and aws:SourceVpce (the endpoint ID), tricking candidates into choosing the broader VPC-level condition when the question specifically asks to restrict to a VPC endpoint.

How to eliminate wrong answers

Option A is wrong because aws:VpcSourceIp is not a valid AWS global condition key — the correct key for the source IP of a request coming through a VPC endpoint is aws:SourceIp, and even that does not identify the endpoint itself. Option B is wrong because aws:SourceVpc identifies the VPC ID (e.g., vpc-abc123) that owns the endpoint, not the endpoint itself; it is broader and would allow any endpoint in that VPC, which is less restrictive than pinning to a specific endpoint. Option C is wrong because aws:SourceIp matches the public or private IP address of the requester, not the VPC endpoint; it cannot distinguish traffic that arrived via a specific endpoint and is easily spoofed or misapplied in NAT/proxy scenarios.

713
MCQeasy

A security engineer needs to monitor for unauthorized changes to security group rules in an AWS account. The engineer wants to receive real-time notifications when a security group rule is added, modified, or removed. Which AWS service should the engineer use to capture these API calls?

A.Amazon GuardDuty
B.AWS CloudTrail
C.VPC Flow Logs
D.AWS Config
AnswerB

AWS CloudTrail records every API call, including AuthorizeSecurityGroupIngress, RevokeSecurityGroupIngress and ModifySecurityGroupRules, delivering events to CloudWatch Logs or EventBridge for real-time alerting. This satisfies the requirement to capture the specific management events that change security group rules, which CloudWatch metrics alone cannot identify.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to the AWS environment, including EC2 APIs such as AuthorizeSecurityGroupIngress, RevokeSecurityGroupIngress, AuthorizeSecurityGroupEgress, RevokeSecurityGroupEgress, CreateSecurityGroup, and DeleteSecurityGroup. By enabling CloudTrail trail with management events and optionally data events for EC2, the security engineer can capture these API calls in near real-time and stream them to Amazon CloudWatch Logs or Amazon EventBridge to trigger notifications for unauthorized changes to security group rules.

Exam trap

The trap here is that candidates often confuse AWS Config's ability to detect configuration changes (like security group rule drift) with the real-time API call capture requirement, but AWS Config relies on CloudTrail for change notifications and has inherent latency, whereas CloudTrail directly captures the API call at the moment it occurs.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail management events for malicious activity, but it does not directly capture or provide real-time notifications for specific API calls like security group rule changes. Option C is wrong because VPC Flow Logs capture metadata about network traffic (IP addresses, ports, protocols) at the network interface level, not API calls that modify security group rules. Option D is wrong because AWS Config is a configuration auditing and compliance service that evaluates resource configurations against rules and can detect drift, but it operates on a periodic or event-driven basis (typically minutes delay) and does not capture API calls in real-time; it relies on CloudTrail for change notifications.

714
MCQmedium

A company stores sensitive data in Amazon S3 and requires that objects are automatically encrypted using server-side encryption with AWS KMS. The bucket policy must deny any PUT request that does not include the x-amz-server-side-encryption header with value aws:kms. Which bucket policy condition key should be used?

A.s3:x-amz-server-side-encryption
B.aws:SourceIp
C.aws:RequestedRegion
D.kms:EncryptionContext
AnswerA

The s3:x-amz-server-side-encryption condition key is the correct way to enforce encryption in an S3 bucket policy, as it directly evaluates the x-amz-server-side-encryption header that clients must include in PutObject requests. You can combine it with StringEquals to require a specific value such as aws:kms or AES256, and use a Deny effect to reject any upload lacking the required encryption header. This condition key is evaluated by S3 during the request, making it a precise, application-level control that cannot be bypassed by network or regional context.

Why this answer

The condition key s3:x-amz-server-side-encryption can be used to check the header value. Condition key aws:SourceIp is for source IP; aws:RequestedRegion is for region; kms:EncryptionContext is for KMS encryption context. Option A is correct.

715
MCQeasy

A security engineer needs to ensure that all API calls made in an AWS account are captured and retained for auditing purposes. The engineer must be able to query the logs for specific user activity over the past 90 days. Which AWS service should the engineer use to meet these requirements?

A.AWS CloudTrail
B.Amazon VPC Flow Logs
C.Amazon CloudWatch Logs
D.AWS Config
AnswerA

AWS CloudTrail is the native API auditing service: it records user activity and API calls across the account as CloudTrail events, capturing the identity, source IP, timestamp, request parameters, and response elements. These events can be delivered to Amazon S3 for long-term retention and queried with Athena, or sent to CloudWatch Logs for alerting. To fully meet an "all API calls" requirement, both management and data events must be enabled across all regions.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made in an AWS account, including the identity, source IP, request parameters, and response elements. By default, CloudTrail stores event history for the last 90 days, which can be queried via the Event History console or API, meeting the requirement to query logs for specific user activity over the past 90 days without additional configuration.

Exam trap

The trap here is that candidates may confuse CloudTrail's default 90-day Event History with the need to create a trail and store logs in S3, but the question explicitly states 'captured and retained for auditing purposes' and 'query the logs for specific user activity over the past 90 days,' which is exactly what the built-in Event History provides without additional configuration.

How to eliminate wrong answers

Option B is wrong because Amazon VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol) at the network interface level, not API calls or user activity, so they cannot be used to audit API-level actions. Option C is wrong because Amazon CloudWatch Logs is a service for storing, monitoring, and accessing log files from various sources (e.g., applications, AWS services), but it does not natively capture all AWS API calls; CloudTrail logs must be explicitly sent to CloudWatch Logs for that purpose, and the requirement is for a service that directly captures and retains API calls, not a downstream log destination. Option D is wrong because AWS Config evaluates and records resource configuration changes and compliance, not API calls; it tracks the state of resources over time but does not capture the API requests that caused those changes.

716
MCQmedium

A company uses AWS CloudFormation to deploy infrastructure. The security team needs to ensure that all CloudFormation stacks include a specific tag with a value that complies with corporate policies. Which AWS service can enforce this requirement?

A.AWS Config
B.AWS Identity and Access Management (IAM)
C.AWS Service Catalog
D.AWS CloudTrail
AnswerC

AWS Service Catalog acts as a governed provisioning layer for CloudFormation templates, allowing administrators to create portfolios of approved products and attach tag options, stack constraints, and IAM roles to those products. When a user provisions a product, Service Catalog automatically applies the configured tag options to the stack and all resources within it, and can reject deployment if required tags are missing. This makes it the only option here that prevents non-compliant infrastructure from being created while still allowing users to deploy via CloudFormation.

Why this answer

AWS Service Catalog allows administrators to create and manage a portfolio of approved products (e.g., CloudFormation templates) with predefined constraints. One such constraint is a tag option, which enforces that every provisioned product (i.e., CloudFormation stack) includes a specific tag key and value, ensuring compliance with corporate policies. This is the only service among the options that can directly enforce mandatory tagging on CloudFormation stacks at provisioning time.

Exam trap

The trap here is that candidates often assume AWS Config can enforce tagging because it can detect and remediate non-compliant tags, but Config is a detective control, not a preventive one, and cannot block stack creation without the required tags.

How to eliminate wrong answers

Option A is wrong because AWS Config can detect and report non-compliant tags on existing resources via rules, but it cannot enforce tagging at the time of stack creation or prevent a stack from being created without the required tag. Option B is wrong because IAM can control who can create stacks via permissions, but it cannot enforce specific tag key-value pairs on the stacks themselves; IAM conditions can check for tags but not enforce their presence during CloudFormation stack creation. Option D is wrong because AWS CloudTrail is an auditing service that records API calls for governance and compliance, but it has no capability to enforce tagging requirements on CloudFormation stacks.

717
MCQmedium

A security engineer is investigating a potential security incident involving an EC2 instance that was used to launch an outbound DDoS attack. The engineer needs to determine the source of the attack and the commands executed on the instance. Which logs should be analyzed?

A.VPC Flow Logs and Network ACL logs
B.EC2 instance OS logs (e.g., /var/log/secure) and CloudTrail logs for API calls that launched the instance
C.S3 server access logs and CloudWatch Logs
D.AWS CloudTrail and AWS Config history
AnswerB

This is correct because the two data sources complement each other: EC2 OS logs (e.g., /var/log/secure on Linux, or Windows Event Logs) record interactive logins, sudo usage, and command execution on the guest OS, while CloudTrail logs the RunInstances API call, identifying the IAM principal, source IP, and timestamp of instance launch. Together they give you both the actor who created the instance and the subsequent commands run within it, enabling a full forensic timeline of the security incident.

Why this answer

The EC2 instance's OS logs (e.g., auditd logs, bash history) contain the exact commands executed and user authentication events, which are essential for identifying the source and actions of the attacker. CloudTrail logs for API calls that launched the instance provide the identity of the principal (IAM user/role), source IP, and the time the instance was created, linking the instance to the initiating entity. Together, these logs allow the engineer to trace both the operational commands on the instance and the administrative actions that created it.

Exam trap

The trap here is that candidates assume VPC Flow Logs or CloudTrail alone are sufficient, but they fail to recognize that OS-level logs are required to see actual commands executed on the instance, which CloudTrail never captures.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) but do not log OS-level commands or API calls; Network ACL logs do not exist as a separate AWS service (Network ACLs themselves generate no logs). Option C is wrong because S3 server access logs record requests made to an S3 bucket, not EC2 instance activity or API calls; CloudWatch Logs can store logs but are a destination, not a source of the specific logs needed (OS logs and CloudTrail). Option D is wrong because AWS CloudTrail logs API calls (including instance launches) but does not capture OS-level commands executed inside the instance; AWS Config history records resource configuration changes over time, not command execution or API call details.

718
MCQeasy

A company wants to centrally manage and enforce backup policies for all EC2 instances across multiple AWS accounts. Which AWS service should be used?

A.AWS Config
B.AWS CloudFormation StackSets
C.AWS Backup
D.AWS Systems Manager
AnswerC

AWS Backup is the fully managed, policy-based backup service that centralizes and automates backup scheduling, retention, and cross-region/cross-account copying across AWS services. You define backup plans with rules for frequency and retention, assign resources via tags or resource IDs, and AWS Backup enforces those policies continuously—including creating backups on schedule and enforcing lifecycle transitions to cold storage or expiration. This meets the requirement to centrally manage and enforce backup policies.

Why this answer

AWS Backup is the correct service because it provides a centralized, policy-based solution to define and enforce backup policies across multiple AWS accounts and regions. It integrates with AWS Organizations to manage backups for EC2 instances and other supported resources, ensuring compliance with governance requirements without needing custom scripts or manual processes.

Exam trap

The trap here is that candidates often confuse AWS Config's compliance evaluation (which can detect missing backups) with actual backup enforcement, or they mistakenly think CloudFormation StackSets can schedule backups, but neither service provides the centralized backup lifecycle management that AWS Backup offers.

How to eliminate wrong answers

Option A is wrong because AWS Config is a service for evaluating resource configurations against desired policies (e.g., compliance rules), not for creating or enforcing backup schedules. Option B is wrong because AWS CloudFormation StackSets deploy and manage infrastructure as code across accounts, but they do not natively provide backup lifecycle management or automated backup policies. Option D is wrong because AWS Systems Manager is an operations hub for patch management, automation, and inventory, but it lacks native backup policy enforcement for EC2 instances across multiple accounts.

719
MCQeasy

A security engineer needs to grant a third-party auditor read-only access to all resources in an AWS account for a limited time. The auditor should not be able to make any changes. Which AWS service should the engineer use to provide temporary credentials?

A.AWS IAM Identity Center (successor to AWS Single Sign-On)
B.AWS Identity and Access Management (IAM) with long-term access keys
C.Amazon Cognito identity pools
D.AWS Security Token Service (AWS STS) with AssumeRole
AnswerD

AWS STS AssumeRole provides temporary security credentials with a specified duration. The engineer can create an IAM role with read-only permissions and allow the auditor to assume it, granting time-limited access without long-term credentials. This meets the requirement for temporary, read-only access.

Why this answer

AWS STS AssumeRole is the correct choice because it allows the creation of temporary credentials with a defined expiration and specific permissions. The engineer can create a role with read-only policies and allow the auditor to assume it. This provides secure, time-limited access without distributing long-term credentials.

Other options either provide long-term credentials or are not designed for this use case.

Exam trap

The trap here is thinking that IAM Identity Center is the default for temporary access, but it is intended for workforce SSO and not for external third-party auditors who need direct AWS API access.

720
MCQhard

A company is implementing a data loss prevention (DLP) solution for data stored in Amazon S3. The data includes personally identifiable information (PII). The company wants to automatically identify and classify PII objects, then apply encryption using AWS KMS with a customer-managed key. Which AWS service should be used to identify PII?

A.AWS CloudTrail
B.Amazon Macie
C.Amazon GuardDuty
D.AWS Config
AnswerB

Amazon Macie is a fully managed data security and privacy service that uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data in Amazon S3, including PII, PHI, and financial information. It supports DLP by generating custom findings and sending alerts via Amazon EventBridge or AWS Security Hub, and it can integrate with AWS Organizations to scale across multiple accounts. Macie provides both managed data identifiers and custom identifiers so customers can detect proprietary or regulatory data types.

Why this answer

Amazon Macie is the correct service because it uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data such as PII in Amazon S3. AWS CloudTrail (Option A) logs API calls and does not inspect data content. Amazon GuardDuty (Option C) detects threats and unauthorized behavior, not data classification.

AWS Config (Option D) evaluates resource configurations and compliance, not data content. Therefore, Option B is correct.

721
Multi-Selecteasy

Which TWO are best practices for securing an AWS account's root user? (Choose two.)

Select 2 answers
A.Share the root user credentials with the security team.
B.Delete the root user account.
C.Enable multi-factor authentication (MFA) on the root user.
D.Delete any access keys associated with the root user.
E.Use the root user for daily administrative tasks.
AnswersC, D

Enabling multi-factor authentication (MFA) on the root user is a critical AWS security best practice because the root user bypasses all IAM policies and has unrestricted access to all services and resources. A stolen or guessed root password alone is insufficient for an attacker if MFA is present; they would also need the MFA device, which is typically a hardware token or virtual authenticator app. AWS explicitly lists root-user MFA as the first step in account hardening, and it also reduces the risk of accidental destructive actions by requiring a second factor.

Why this answer

Enabling multi-factor authentication (MFA) on the root user adds a second layer of security beyond the password and is the single most effective control to prevent unauthorized access to the most privileged account in an AWS environment. AWS strongly recommends MFA for the root user as it mitigates the risk of credential theft or compromise, which could lead to full account takeover and irreversible damage.

Exam trap

The trap here is that candidates may think deleting the root user (Option B) is possible or that sharing credentials with a team (Option A) is a valid security practice, when in fact AWS prohibits deletion of the root user and sharing credentials violates security best practices.

722
MCQeasy

An IAM policy includes the following statement: 'Effect': 'Deny', 'Action': 's3:*', 'Resource': '*', 'Condition': {'Bool': {'aws:SecureTransport': 'false'}}. What does this policy do?

A.Denies all S3 actions when the request is not using HTTPS.
B.Denies all S3 actions to a specific bucket.
C.Denies all S3 actions for all users.
D.Allows all S3 actions only when using HTTPS.
AnswerA

The policy statement uses "Effect": "Deny" with a condition key "aws:SecureTransport" set to "false". Since "Resource" is "*", it denies every S3 API action—on any bucket or object—when the request is transmitted over HTTP without TLS. This is a standard pattern to enforce HTTPS: any request where the secure transport boolean is false is blocked, while HTTPS requests remain unaffected by this statement.

Why this answer

The policy statement has an explicit Deny effect for all S3 actions on all resources, with a condition that the request must have aws:SecureTransport set to false. aws:SecureTransport is a global condition key that evaluates to true if the request uses SSL/TLS, and false otherwise. Therefore, the policy denies all S3 actions when the request is not using HTTPS (i.e., when SecureTransport is false).

Exam trap

SCS-C02 often tests the difference between explicit Deny and Allow, and candidates may misinterpret the condition as allowing HTTPS instead of denying HTTP.

How to eliminate wrong answers

Option B is wrong because the Resource is '*', meaning it applies to all resources, not a specific bucket. Option C is wrong because the policy only denies requests that meet the condition; it does not deny all S3 actions for all users unconditionally—requests using HTTPS are not denied by this statement (though they might be allowed or denied by other policies). Option D is wrong because the effect is Deny, not Allow; the policy does not allow any actions, it only denies when the condition is met.

723
MCQeasy

A company wants to automatically detect and remediate S3 buckets that are publicly accessible. Which AWS service can be used to evaluate bucket policies against a defined rule and trigger an automated response?

A.Amazon GuardDuty
B.AWS CloudTrail
C.Amazon Inspector
D.AWS Config
AnswerD

AWS Config is the correct service because it continuously records configuration changes for resources like AWS::S3::Bucket and evaluates each bucket policy against managed rules (e.g., s3-bucket-public-read-prohibited) or custom rules written in AWS Lambda. On detecting a noncompliant policy, Config can invoke an automatic remediation action, such as running an SSM Automation document or a custom Lambda function to revert or fix the policy. This gives you native detect-and-remediate capabilities rather than just an audit trail or a threat alert.

Why this answer

AWS Config evaluates resource configurations against rules and can trigger automatic remediation via SSM Automation documents. For S3 public access, the managed rule s3-bucket-public-read-prohibited or s3-bucket-public-write-prohibited can detect noncompliant buckets and invoke a remediation action to block public access.

Exam trap

The trap is confusing GuardDuty (threat detection) with AWS Config (configuration compliance and remediation) — only Config evaluates policies against rules and triggers automated responses.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that identifies malicious activity, not a configuration compliance service that evaluates bucket policies against rules. Option B is wrong because AWS CloudTrail logs API activity for auditing, but does not evaluate configurations or trigger remediation. Option C is wrong because Amazon Inspector assesses vulnerabilities in EC2 instances and container images, not S3 bucket policies.

724
MCQhard

A company is designing a shared services VPC architecture with multiple VPCs connected via a transit gateway. The security engineer needs to ensure that all traffic between VPCs is inspected by a centralized firewall appliance deployed in the shared services VPC. What configuration is required?

A.Create VPC peering connections between each VPC and the shared services VPC.
B.Configure transit gateway route tables to route all inter-VPC traffic through the firewall appliance.
C.Use security groups to route traffic through the firewall.
D.Deploy a Gateway Load Balancer (GWLB) in the shared services VPC and register the firewall as a target.
AnswerB

A transit gateway with carefully designed route tables is the standard way to enforce centralized inspection: attach all VPCs to the transit gateway, then configure a route in each spoke VPC's propagation that sends inter-VPC destination CIDRs to the firewall appliance's elastic network interface in the shared services VPC. The firewall inspects and forwards the traffic back to the transit gateway, which delivers it to the destination VPC. This enables deterministic, high-availability routing through the security appliance.

Why this answer

A transit gateway can use separate route tables to control traffic flow. By configuring the transit gateway route tables to point the default route (0.0.0.0/0) or specific inter-VPC CIDR ranges to a network interface of the centralized firewall appliance in the shared services VPC, all traffic between VPCs is forced through the firewall for inspection. This design ensures that the firewall acts as a central inspection point without requiring VPC peering or complex routing.

Exam trap

The trap here is that candidates often confuse the role of a Gateway Load Balancer (GWLB) with routing, assuming that deploying a GWLB alone will automatically route traffic through the firewall, when in fact the transit gateway route tables must be explicitly configured to direct traffic to the GWLB endpoint or the firewall ENI.

How to eliminate wrong answers

Option A is wrong because VPC peering connections do not support transitive routing; each peering connection is a one-to-one link, so traffic between two peered VPCs cannot be routed through a third VPC without additional complex routing and would not force inspection through the firewall. Option C is wrong because security groups are stateful virtual firewalls that control traffic at the instance level based on rules, not routing; they cannot route traffic through a separate appliance or enforce traffic inspection paths. Option D is wrong because a Gateway Load Balancer (GWLB) is used to distribute traffic to a fleet of third-party appliances (e.g., firewalls) for inline inspection, but it does not by itself route inter-VPC traffic through the firewall; the transit gateway route tables must still be configured to direct traffic to the GWLB endpoint, making this an incomplete solution without the correct routing configuration.

725
MCQeasy

A company uses Amazon GuardDuty to monitor for malicious activity in their AWS account. The security team receives a GuardDuty finding that indicates an EC2 instance is communicating with a known cryptocurrency mining pool. The team needs to investigate the finding and determine which security group rules allowed the outbound traffic. The EC2 instance is in a VPC with a single security group attached. Which AWS service should the security team use to review the outbound traffic details?

A.AWS CloudTrail
B.VPC Flow Logs
C.AWS Config
D.Amazon GuardDuty
AnswerB

VPC Flow Logs capture metadata about every IP traffic flow accepted or rejected by a VPC network interface, including source/destination IP, source/destination port, protocol, packets, and bytes transferred. By enabling these logs for the subnets or ENIs and publishing to CloudWatch Logs or S3, you can query for outbound traffic to suspicious IP addresses, unusual ports, or high data transfer volumes. This raw flow-level data is exactly what is needed to supplement a GuardDuty finding and trace which EC2 instance initiated the malicious connection.

Why this answer

VPC Flow Logs capture IP traffic metadata — including source/destination IP, ports, protocol, and ACCEPT/REJECT action — for network interfaces in a VPC. Reviewing flow logs for the EC2 instance's ENI reveals which outbound traffic was allowed and, combined with the security group rules, identifies the rule that permitted the connection to the mining pool.

Exam trap

SCS-C02 often tests the distinction between CloudTrail (API activity) and VPC Flow Logs (network traffic) — candidates pick CloudTrail because it is the default 'audit' answer, but it cannot show packet-level outbound connections.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity (who called which AWS API), not network packet flows — it cannot show outbound traffic to an external IP. Option C is wrong because AWS Config tracks resource configuration changes and compliance, not network traffic. Option D is wrong because GuardDuty is the detection service that generated the finding; it does not provide the granular network flow details needed to identify the specific security group rule.

726
MCQmedium

A security engineer runs the command shown in the exhibit. What is the primary purpose of this command?

A.To generate a data key without plaintext.
B.To re-encrypt an existing encrypted file under a new key.
C.To decrypt the file secret.txt using a KMS key.
D.To encrypt the contents of secret.txt using a KMS key and store the result in encrypted_secret.txt.
AnswerD

The command invokes the KMS Encrypt API by taking the plaintext bytes from secret.txt, sending them with the specified key ID, and writing the returned base64-encoded `CiphertextBlob` to encrypted_secret.txt. This is the direct encryption of the file's contents under the given KMS key, producing ciphertext that can later be decrypted only with the same key (and any required encryption context). Because KMS Encrypt accepts plaintext up to only 4 KB, this approach is appropriate for small secrets like passwords or configuration values, not for large files.

Why this answer

The command shown in the exhibit is 'aws kms encrypt --key-id <key-id> --plaintext fileb://secret.txt --output text --query CiphertextBlob | base64 --decode > encrypted_secret.txt'. This command uses the AWS KMS Encrypt API to encrypt the contents of secret.txt with the specified KMS key, then decodes the base64-encoded ciphertext and writes it to encrypted_secret.txt. Therefore, the primary purpose is to encrypt the file contents using a KMS key and store the result in encrypted_secret.txt.

Exam trap

The trap is confusing the KMS Encrypt API with other KMS operations like GenerateDataKey or ReEncrypt. Candidates might think the command is for generating a data key or re-encrypting, but the presence of '--plaintext fileb://' clearly indicates encryption of plaintext data.

How to eliminate wrong answers

Option A is wrong because generating a data key without plaintext is done with 'aws kms generate-data-key-without-plaintext', not the encrypt command. Option B is wrong because re-encrypting an existing encrypted file under a new key would use 'aws kms re-encrypt', which takes a ciphertext blob as input, not a plaintext file. Option C is wrong because decrypting a file would use 'aws kms decrypt' with a ciphertext blob, not encrypt.

727
MCQeasy

A company uses Amazon RDS for its database. The security team needs to detect when a database instance is started or stopped outside of maintenance windows. Which AWS service should the team use to monitor these API calls?

A.Amazon CloudWatch
B.Amazon GuardDuty
C.AWS CloudTrail
D.AWS Config
AnswerC

AWS CloudTrail is the correct service because it records all management events, including every RDS API call such as StartDBInstance and StopDBInstance. Each CloudTrail event contains the identity of the caller, the time of the action, the source IP address, and request parameters, enabling a complete audit trail. You can also configure CloudTrail to deliver logs to Amazon S3 and set up EventBridge rules to trigger real-time alerts whenever a specific RDS API action occurs. This makes CloudTrail the definitive source for monitoring and alerting on RDS instance lifecycle changes.

Why this answer

AWS CloudTrail is the correct service because it records API activity in your AWS account, including StartDBInstance and StopDBInstance calls from the RDS service. By monitoring CloudTrail logs, the security team can detect when a database instance is started or stopped outside of maintenance windows, as each API call is logged with a timestamp and user identity. CloudTrail is specifically designed for auditing API calls, making it the appropriate tool for this use case.

Exam trap

The trap here is that candidates confuse CloudWatch's ability to create alarms on CloudTrail events with CloudWatch itself being the service that records API calls, but CloudWatch only processes logs delivered by CloudTrail and cannot natively capture API activity without CloudTrail as the source.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch is a monitoring service for metrics, logs, and alarms, but it does not natively capture or record API calls like StartDBInstance or StopDBInstance; it can only alert on CloudTrail-delivered events via a metric filter, not directly detect the API calls themselves. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail management events for malicious activity, but it is not designed for custom operational monitoring of specific API calls like database start/stop events; it focuses on security threats, not operational compliance. Option D is wrong because AWS Config is a configuration tracking and compliance service that evaluates resource configurations against rules, but it does not monitor real-time API calls; it can detect configuration changes (e.g., a DB instance being stopped) only after they occur via configuration changes, not the API call event itself.

728
MCQeasy

A company wants to detect and alert on suspicious IAM user behavior, such as accessing services that are not typically used. Which AWS service provides prebuilt anomaly detection for IAM users?

A.AWS Trusted Advisor
B.AWS CloudTrail
C.Amazon GuardDuty
D.Amazon Inspector
AnswerC

Amazon GuardDuty is the correct answer because it is a managed threat detection service that combines machine learning, anomaly detection, and threat intelligence to monitor suspicious activity across your AWS environment. Specifically, it consumes CloudTrail management events to profile each IAM user's normal behavior—typical IP addresses, geographic locations, login times, and API call frequency—and then flags deviations as findings like 'Unusual IAM User Login' or 'Impossible Travel' activity. When a finding is generated, GuardDuty automatically emits an event to Amazon EventBridge, which you can pipe to SNS, Lambda, or Security Hub to trigger near-real-time alerts and automated responses. This provides exactly the detect-and-alert capability the company needs without requiring them to build custom analytics.

Why this answer

Amazon GuardDuty is the correct answer because it is a threat detection service that uses machine learning and anomaly detection to identify suspicious IAM user behavior, such as accessing services not typically used. It analyzes AWS CloudTrail management and data events, VPC Flow Logs, and DNS logs to establish baselines and generate findings for unusual API calls or access patterns. This prebuilt capability directly addresses the requirement for detecting atypical IAM activity without manual configuration.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail's logging capability with active threat detection, assuming that because CloudTrail records API calls, it can also detect anomalies, but it lacks the machine learning engine required for prebuilt anomaly detection.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor is a service that provides best-practice recommendations for cost optimization, performance, security, and fault tolerance, but it does not perform real-time anomaly detection or monitor IAM user behavior. Option B is wrong because AWS CloudTrail is a logging service that records API activity for auditing and compliance, but it lacks built-in anomaly detection; it requires integration with other services like GuardDuty or third-party tools to identify suspicious behavior. Option D is wrong because Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, not IAM user behavior or API call anomalies.

729
Multi-Selecthard

A company has a requirement to automatically rotate encryption keys for S3 objects every 90 days. They are using SSE-KMS with a customer managed key. Which action will meet the requirement without breaking access to existing objects?

Select 1 answer
A.Configure an S3 lifecycle policy to re-encrypt objects
B.Use S3 Batch Operations to re-encrypt existing objects with the new key
C.Manually rotate the key every 90 days and re-encrypt all objects
D.Delete the existing key and create a new one each 90 days
E.Enable automatic key rotation in AWS KMS for the customer managed key
AnswersB

Correct. S3 Batch Operations can re-encrypt existing objects with a new key, and the old key remains active for decryption.

Why this answer

(S3 Batch Operations) allows re-encrypting existing objects with a new key without breaking access because the previous key remains available for decryption. Option E (Enable automatic key rotation in AWS KMS) rotates the key annually, not every 90 days, so it does not meet the requirement. No other combination of options fully satisfies the 90-day rotation requirement; thus only B is correct.

730
Multi-Selecteasy

Which TWO of the following are valid options for encrypting data at rest in Amazon S3? (Choose 2.)

Select 2 answers
A.SSL/TLS encryption
B.IAM policy encryption
C.SSE-S3
D.CloudHSM client-side encryption
E.SSE-KMS
AnswersC, E

SSE-S3 (Server-Side Encryption with Amazon S3-Managed Keys) is a built-in S3 feature that uses AES-256 to encrypt each object at rest with a unique data key, and the data key itself is encrypted with a regularly rotated master key managed by S3. You enable it by setting the x-amz-server-side-encryption header to AES256 or by applying a bucket default encryption policy, and S3 fully handles the key lifecycle—requiring no customer key management or extra cost.

Why this answer

SSE-S3 is correct because it provides server-side encryption where Amazon S3 manages the encryption keys entirely. When you upload an object, S3 encrypts it using AES-256 before writing to disk and decrypts it when you access it, with no additional configuration needed beyond enabling the header `x-amz-server-side-encryption: AES256`.

Exam trap

The trap here is confusing encryption at rest with encryption in transit, leading candidates to select SSL/TLS, or misinterpreting IAM policies as an encryption mechanism, or assuming CloudHSM is a native S3 server-side encryption option rather than a client-side tool.

731
MCQhard

A company has a multi-account AWS Organization with 50 accounts. The security team wants to monitor for unauthorized IAM role assumption across all accounts. They have enabled AWS CloudTrail in all accounts and are delivering logs to a central S3 bucket in the security account. They also have Amazon GuardDuty enabled in all accounts. The security team wants a centralized dashboard to visualize cross-account role assumption events. They have limited budget and want to use existing services. What should they do?

A.Use Amazon Athena to query CloudTrail logs in S3 and visualize with Amazon QuickSight.
B.Use AWS Config aggregator to view cross-account IAM role creation.
C.Use Amazon CloudWatch Logs Insights to query logs from the central S3 bucket.
D.Use Amazon Elasticsearch Service to index CloudTrail logs from S3 and visualize with Kibana.
AnswerA

Amazon Athena can query CloudTrail logs directly in Amazon S3 using standard SQL, without requiring any ingestion or ETL step. When all accounts in the organization deliver CloudTrail logs to a centralized S3 bucket, Athena can run cross-account queries over the entire set of log files. Amazon QuickSight connects to Athena to build interactive dashboards from those results, and the serverless pay-per-query pricing makes this a cost-effective analysis solution.

Why this answer

Amazon Athena can query CloudTrail logs stored in S3 using standard SQL, and Amazon QuickSight can create visualizations from Athena query results. This leverages existing services without additional cost for Amazon QuickSight (pay-per-session pricing) and minimal cost for Athena (based on data scanned). Option B is incorrect because AWS Config aggregator provides a view of resource configuration across accounts, not API call analysis.

Option C is incorrect because CloudWatch Logs Insights cannot directly query logs stored in S3; it requires logs to be in CloudWatch Logs. Option D is incorrect because Amazon Elasticsearch Service incurs additional costs and complexity, which the company wants to avoid.

732
MCQmedium

A company uses AWS CloudTrail and wants to ensure that any modification to the trail itself is detected immediately. What should be done?

A.Configure Amazon GuardDuty to monitor for trail modifications
B.Enable CloudTrail Insights to detect unusual activity
C.Create a CloudWatch Events rule that matches the StopLogging or UpdateTrail API calls and sends an alert
D.Enable S3 event notifications on the trail's S3 bucket
AnswerC

The correct solution is a CloudWatch Events rule (now Amazon EventBridge) that matches the management events CloudTrail emits for the StopLogging, UpdateTrail, or DeleteTrail API calls, using an event pattern with source 'aws.cloudtrail' and eventName in the list. When such a call occurs, the rule triggers an SNS topic or Lambda function to notify security teams in near real-time. This works because CloudTrail delivers every management event to CloudWatch Events as a default integration, including the very call that disables logging.

Why this answer

CloudWatch Events (now part of Amazon EventBridge) can be configured with a rule that matches specific API calls like StopLogging or UpdateTrail via CloudTrail. When such an API call is made, the rule triggers an action such as sending an SNS notification or invoking a Lambda function, enabling immediate detection of trail modifications. This approach directly monitors the control plane operations that alter the trail's configuration.

Exam trap

The trap here is that candidates often confuse monitoring the trail's log files (S3 events) with monitoring the trail's configuration (CloudTrail API calls), leading them to choose Option D instead of the correct CloudWatch Events approach.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail management events for malicious activity, but it does not provide real-time alerting on specific API calls like UpdateTrail; it focuses on threat intelligence rather than configuration change monitoring. Option B is wrong because CloudTrail Insights identifies unusual API activity and write management events, but it is designed for anomaly detection over time, not immediate alerting on specific trail modifications. Option D is wrong because S3 event notifications on the trail's S3 bucket would only detect changes to the log files stored in the bucket, not modifications to the trail configuration itself (e.g., disabling logging or changing the trail's settings).

733
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to centralize VPC Flow Logs from all accounts into a single S3 bucket in the security account. The flow logs are created in the member accounts and sent to the centralized bucket. However, the security team notices that flow logs from some member accounts are not being delivered. What is the most likely cause?

A.The member accounts need an IAM role with permissions to write to the centralized bucket.
B.CloudTrail must be enabled in each member account before VPC Flow Logs can be sent to a centralized bucket.
C.The S3 bucket policy does not grant write permissions to the member accounts.
D.VPC Flow Logs cannot be aggregated across multiple AWS accounts.
AnswerC

The most direct reason the flow logs fail is that the S3 bucket policy is missing an explicit Allow that lets the delivering VPC Flow Logs service write objects into the bucket. For cross-account delivery, the policy needs a statement with Principal as vpc-flow-logs.amazonaws.com (or the aggregated log delivery principal) and Action s3:PutObject on the destination prefix such as arn:aws:s3:::central-bucket/AWSLogs/<member-account-id>/*. Without this resource-based grant, S3 denies the write even if the member account has full IAM permissions.

Why this answer

VPC Flow Logs are delivered to an S3 bucket using the flow log publisher's IAM role, but the destination bucket must also have a bucket policy that explicitly grants the necessary permissions (e.g., s3:PutObject) to the member accounts' log delivery service. Without this policy, the S3 bucket will reject write requests from member accounts, causing flow logs to fail silently.

Exam trap

The trap here is that candidates often assume an IAM role in the member account is required (Option A), but AWS actually uses resource-based policies (S3 bucket policy) for cross-account VPC Flow Log delivery, not IAM roles.

How to eliminate wrong answers

Option A is wrong because member accounts do not need an IAM role with write permissions to the centralized bucket; instead, the flow log delivery uses the VPC Flow Logs service principal (delivery.logs.amazonaws.com) and relies on the S3 bucket policy to grant cross-account access. Option B is wrong because CloudTrail is not a prerequisite for VPC Flow Logs; flow logs operate independently and can be sent to S3 without CloudTrail being enabled. Option D is wrong because VPC Flow Logs can indeed be aggregated across multiple AWS accounts by using a centralized S3 bucket with appropriate bucket policies and resource-based policies.

734
MCQeasy

A company is designing a multi-tier web application. The web servers must be accessible from the internet, but the application servers must only be accessible from the web servers. Which AWS feature should be used to meet these requirements?

A.Use security groups with rules that allow inbound traffic to the web servers from the internet, and allow inbound traffic to the application servers only from the web server security group.
B.Use a VPC peering connection between the web tier and application tier subnets.
C.Use network ACLs to allow inbound traffic to the web tier from the internet and to the application tier only from the web tier.
D.Use a VPN connection to isolate the application tier from the web tier.
AnswerA

Security groups are stateful, instance-level firewalls that allow you to reference another security group as a source. By creating a web server security group that allows inbound TCP/443 and TCP/80 from 0.0.0.0/0, and an application server security group with an inbound rule whose source is the web server security group ID, traffic is permitted only from the specific EC2 instances associated with that web security group. This precisely satisfies the requirement without exposing the application tier directly to the internet, and it automatically accounts for new web instances that join the group.

Why this answer

Security groups are stateful, instance-level virtual firewalls in AWS. By allowing inbound internet traffic to the web server security group and then allowing inbound traffic to the application server security group only from the web server security group (referencing the SG as the source), you enforce that only web servers can reach application servers. This is the standard AWS pattern for tiered isolation.

Exam trap

SCS-C02 often tests the confusion between security groups (stateful, instance-level, SG references) and network ACLs (stateless, subnet-level, CIDR-only) — the requirement 'only from the web servers' points to SG referencing.

How to eliminate wrong answers

Option B is wrong because VPC peering connects VPCs, not tiers within a VPC — it does not provide the required access control between web and application subnets. Option C is wrong because network ACLs are stateless and subnet-level; while they can filter traffic, they cannot reference security groups as sources, making it harder to express 'only from the web tier' cleanly and requiring separate rules for return traffic. Option D is wrong because a VPN connection is for secure connectivity between on-premises networks and AWS, not for isolating tiers within a VPC.

735
Drag & Dropmedium

Drag and drop the steps to configure a VPC with private subnets and NAT gateway for outbound internet access in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

VPC creation, subnets, internet gateway, NAT gateway, and route table update are required for private subnet internet access.

736
MCQmedium

A security team needs to be alerted when an IAM user generates a console login failure. Which combination of AWS services should be used to meet this requirement?

A.CloudTrail and Amazon S3
B.CloudTrail, Amazon CloudWatch Logs, and CloudWatch Alarms
C.AWS Config and Amazon SNS
D.Amazon GuardDuty and AWS Lambda
AnswerB

The correct architecture is CloudTrail for recording console login events, CloudWatch Logs as the destination for those CloudTrail events, and a CloudWatch Logs metric filter that looks for IAM console sign-in failures (e.g., MFA denied or incorrect password). The metric filter increments a CloudWatch metric, and a CloudWatch Alarm on that metric triggers an Amazon SNS notification, delivering a near-real-time alert when a defined threshold (like 1 failure) is breached.

Why this answer

CloudTrail captures IAM console login failures as CloudTrail events, which can be streamed to CloudWatch Logs. A CloudWatch Alarm can then be configured to trigger on a metric filter that matches the specific 'ConsoleLogin' event with a 'Failure' status, enabling real-time alerting via Amazon SNS.

Exam trap

The trap here is that candidates may think CloudTrail alone is sufficient for alerting, but CloudTrail only logs events; it requires integration with CloudWatch Logs and Alarms to generate notifications, and options like GuardDuty or Config are often mistakenly chosen because they sound security-related but do not directly address the specific login failure alerting requirement.

How to eliminate wrong answers

Option A is wrong because Amazon S3 alone cannot generate alerts; it is a storage service and lacks native alerting capabilities. Option C is wrong because AWS Config is designed for resource compliance and configuration tracking, not for monitoring real-time API events like login failures. Option D is wrong because Amazon GuardDuty focuses on threat detection using DNS, VPC flow logs, and CloudTrail management events, but it does not provide direct alerting for IAM console login failures without additional custom Lambda logic, and it is not the standard recommended combination for this specific requirement.

737
Multi-Selecthard

Which THREE components are required to set up a client VPN for remote access to a VPC? (Choose 3.)

Select 3 answers
A.Client VPN endpoint
B.Virtual Private Gateway
C.Customer Gateway
D.Authorization rule
E.Target network association
AnswersA, D, E

The Client VPN endpoint is the central AWS server component that clients connect to; it is configured with a server certificate, authentication methods (such as mutual TLS, SAML, or Active Directory), and connection parameters like client CIDR ranges and DNS settings. It serves as the termination point for TLS-based VPN sessions and is a required component because without it, there is nothing for remote clients to establish a tunnel with. All other components (like target network associations and authorization rules) are configured on this endpoint.

Why this answer

A Client VPN endpoint is required as the entry point for remote clients to connect to the VPC. It manages authentication, encryption (using TLS 1.2), and routing for client connections. Without this component, there is no VPN server to accept and authenticate client traffic.

Exam trap

The trap here is confusing the components required for a site-to-site VPN (Virtual Private Gateway and Customer Gateway) with those needed for a client-based VPN, leading candidates to incorrectly select B or C instead of the correct client VPN-specific components.

738
MCQmedium

A security team needs to monitor for failed login attempts to an EC2 instance running Linux. The team wants to send a real-time alert when more than 10 failed SSH attempts occur within 5 minutes. Which solution is the most efficient?

A.Install the CloudWatch Logs agent on the EC2 instance to stream /var/log/secure to CloudWatch Logs. Create a metric filter for 'Failed password' and set a CloudWatch alarm.
B.Enable VPC Flow Logs and filter for SSH traffic to detect failed attempts.
C.Configure the EC2 instance to write failed attempts to a file in S3 and use S3 events to trigger a Lambda function for alerting.
D.Enable Amazon GuardDuty and create a custom threat list for failed SSH attempts.
AnswerA

Streaming /var/log/secure to CloudWatch Logs via the CloudWatch Logs agent enables real-time ingestion of OS-level authentication events. A metric filter with pattern 'Failed password' converts each matching log line into a metric value, and a CloudWatch alarm evaluates the metric over a chosen period to alert on anomalous login failures. This is the standard pattern for Linux SSH login monitoring because the agent is natively supported and the filter operates on the actual log content.

Why this answer

The CloudWatch Logs agent can stream /var/log/secure (which logs SSH authentication events) to CloudWatch Logs. A metric filter on the 'Failed password' pattern counts failed SSH attempts, and a CloudWatch alarm with a threshold of 10 within a 5-minute period triggers a real-time alert. This is the most efficient solution as it directly monitors the specific log source for SSH failures without additional overhead.

Exam trap

The trap here is that candidates may confuse VPC Flow Logs (network-level) with application-level logs (e.g., /var/log/secure), assuming flow logs can detect failed SSH attempts when they only show connection attempts, not authentication success or failure.

How to eliminate wrong answers

Option B is wrong because VPC Flow Logs capture network metadata (e.g., source/destination IP, port, protocol) but do not log application-level authentication outcomes like 'Failed password'; they cannot distinguish between successful and failed SSH logins. Option C is wrong because writing failed attempts to a file in S3 introduces latency and complexity (e.g., S3 events are not real-time, and Lambda invocation adds delay), making it less efficient than direct CloudWatch monitoring. Option D is wrong because Amazon GuardDuty uses machine learning and threat intelligence to detect suspicious behavior, but it does not natively support custom threat lists for failed SSH attempts; custom threat lists are for known malicious IPs, not for counting failed logins.

739
Multi-Selecteasy

Which TWO AWS services can be used to detect and alert on suspicious API activity in real-time? (Choose two.)

Select 2 answers
A.AWS CloudTrail with CloudWatch Events
B.VPC Flow Logs
C.Amazon S3
D.AWS Config
E.Amazon GuardDuty
AnswersA, E

AWS CloudTrail records all API activity across your account, including the identity making the call, source IP, timestamp, and the exact action performed. By creating a CloudWatch Events rule that filters for specific CloudTrail events—such as unauthorized PutBucketPolicy attempts, failed console logins, or IAM privilege escalation patterns—you can trigger near-real-time alerts through Amazon SNS, Lambda, or AWS Chatbot. This combination provides a native, low-latency pipeline to both detect and alert on suspicious management-plane activity.

Why this answer

AWS CloudTrail with CloudWatch Events (A) is correct because CloudTrail records every API call as a management or data event, and CloudWatch Events (now EventBridge) can match those events in near real-time using rules and trigger alerts via SNS, Lambda, or other targets, enabling detection of suspicious API activity as it happens. Amazon GuardDuty (E) is correct because it continuously analyzes CloudTrail management events, VPC Flow Logs, and DNS logs with threat intelligence and machine learning to detect anomalous or malicious API activity and generate findings in real time. VPC Flow Logs (B) only capture IP traffic metadata at the network interface level, not API-level activity, so they cannot directly detect suspicious API calls.

Amazon S3 (C) is an object storage service and provides no native detection or alerting for API activity. AWS Config (D) evaluates resource configuration compliance and records configuration changes, but it is not designed for real-time detection and alerting on suspicious API behavior.

Exam trap

SCS-C02 often tests the distinction between network-level monitoring (VPC Flow Logs) and API-level monitoring (CloudTrail/GuardDuty), causing candidates to select VPC Flow Logs for API activity detection.

740
MCQhard

A security engineer has attached the above IAM policy to a role used by an application to write logs to an S3 bucket. However, the application is unable to write logs. What is the MOST likely reason?

A.The Effect is set to Allow, which is too permissive.
B.The application does not set the x-amz-acl header to bucket-owner-full-control on PutObject requests.
C.The policy does not allow server-side encryption.
D.The resource ARN is incorrect; it should be arn:aws:s3:::my-log-bucket/*.
AnswerB

The application is failing because the IAM policy includes a Condition key s3:x-amz-acl with StringEquals bucket-owner-full-control. For S3 to allow a PutObject call, the request must carry an x-amz-acl header matching that exact value; if the header is absent or different, S3 treats the condition as unmet and denies the request. IAM permissions alone don't bypass S3's request-level parameter checks. The application must explicitly set the header in each PutObject request.

Why this answer

When an IAM policy grants PutObject access to an S3 bucket, the application must also include the `x-amz-acl: bucket-owner-full-control` header in its PutObject requests to ensure the bucket owner retains full control over the uploaded objects. Without this header, the object is owned by the writer (the role), and the bucket owner cannot manage it, causing the write to fail due to access control mismatches, especially in cross-account scenarios or when the bucket policy enforces specific ACLs.

Exam trap

The trap here is that candidates often focus on IAM policy syntax errors (like ARN format or missing actions) and overlook the requirement for specific request headers (like ACLs) that are enforced by the bucket policy or S3 default settings, not by the IAM policy itself.

How to eliminate wrong answers

Option A is wrong because setting the Effect to Allow is standard for granting permissions; the issue is not about permissiveness but about missing required headers. Option C is wrong because the policy does not need to explicitly allow server-side encryption; S3 supports default encryption at the bucket level, and the policy shown does not deny encryption-related actions. Option D is wrong because the resource ARN `arn:aws:s3:::my-log-bucket/*` is correct for granting access to objects within the bucket; the error is not due to the ARN format but due to missing ACL headers.

741
Multi-Selecthard

A company wants to centrally manage and enforce security policies across multiple AWS accounts using AWS Organizations. Which THREE actions should be taken? (Choose three.)

Select 3 answers
A.Use the root user of each member account for administrative tasks.
B.Enable all features in AWS Organizations and create service control policies (SCPs) to restrict actions.
C.Use AWS CloudTrail to log API calls in all accounts and deliver logs to a centralized S3 bucket.
D.Create IAM roles in member accounts that grant cross-account access from the management account.
E.Disable CloudTrail in member accounts to reduce costs.
AnswersB, C, D

Enabling all features in AWS Organizations and creating service control policies (SCPs) is the foundational step for central governance because SCPs apply boundary limits across every principal in member accounts, including the root user, without needing to log in to each account. SCPs can deny high-risk actions such as disabling CloudTrail, deleting IAM roles, or leaving the organization, and they work alongside IAM policies to enforce a global guardrail.

Why this answer

Option B is correct because enabling all features in AWS Organizations unlocks advanced governance capabilities, including service control policies (SCPs), which are the mechanism for centrally restricting the maximum available permissions across member accounts. Option C is correct because AWS CloudTrail provides centralized audit logging of API activity; creating a trail that applies to all accounts and delivers logs to a single S3 bucket in a central account gives the company visibility and evidence of policy enforcement across the organization. Option D is correct because IAM roles in member accounts with trust policies allowing the management account to assume them enable secure cross-account administration without sharing long-term credentials, which is the recommended pattern for centralized management.

Option A is not appropriate because the root user of each member account should not be used for routine administrative tasks; it has unrestricted permissions, cannot be constrained by SCPs, and should be protected with MFA and reserved for break-glass scenarios. Option E is incorrect because disabling CloudTrail in member accounts would eliminate the audit trail needed to verify and enforce security policies, undermining the centralized governance goal.

Exam trap

SCS-C02 often tests the misconception that root users are needed for cross-account administration — candidates forget that IAM roles with trust policies are the secure, auditable alternative.

742
MCQmedium

A company is designing a data encryption solution for its Amazon RDS for PostgreSQL database. The database must be encrypted at rest. What is the simplest way to achieve this?

A.Enable encryption when creating the RDS instance using a KMS key.
B.Enable AWS KMS encryption on the RDS instance after creation.
C.Use application-level encryption before inserting data into the database.
D.Use AWS CloudHSM to encrypt the EBS volumes attached to the RDS instance.
AnswerA

Native RDS encryption at rest is a one-way, create-time configuration: you specify a customer-managed AWS KMS key (or the default aws/rds key) when launching the DB instance, and RDS uses envelope encryption to encrypt the instance's storage, automated backups, snapshots, and read replicas. Because the encryption decision is baked into the underlying storage during provisioning, it cannot be retroactively applied to an already-running instance. This is the simplest and most operationally transparent way to meet an at-rest encryption requirement for Amazon RDS.

Why this answer

RDS supports encryption at rest for new databases using AWS KMS. Option B is incorrect because there is no separate encryption layer; RDS uses KMS. Option C is incorrect because application-level encryption is not the simplest.

Option D is incorrect because RDS does not support CloudHSM for encryption at rest.

743
MCQmedium

A developer needs to grant an EC2 instance access to an S3 bucket. Which is the most secure way to provide credentials to the EC2 instance?

A.Store AWS access keys in the application code
B.Store the keys in an S3 bucket and download them at startup
C.Create an IAM role and attach it to the EC2 instance profile
D.Use environment variables to store the keys
AnswerC

Creating an IAM role and attaching it to the EC2 instance profile is the AWS-recommended pattern. The instance profile securely delivers temporary credentials to the instance through the instance metadata service (IMDSv2), and the AWS SDKs automatically retrieve and refresh these credentials. Permissions are scoped to the role's policy, no secrets are stored on disk or in source code, and credentials rotate automatically, minimizing the blast radius of any single credential leak.

Why this answer

It uses an IAM role attached to an EC2 instance profile, which allows the instance to obtain temporary, automatically rotated credentials from the AWS STS service via the instance metadata service (IMDS). This eliminates the need to hardcode, store, or manage long-term access keys, significantly reducing the risk of credential exposure.

Exam trap

The trap here is that candidates may think storing keys in S3 or environment variables is acceptable, but the exam emphasizes that any form of long-term static credential storage on an EC2 instance is insecure compared to using IAM roles with instance profiles and temporary credentials from STS.

How to eliminate wrong answers

Option A is wrong because storing AWS access keys in application code exposes them to version control, code reviews, and potential leaks, violating the principle of least privilege and long-term credential security. Option B is wrong because storing keys in an S3 bucket and downloading them at startup still requires the instance to have long-term credentials to access the bucket, creating a circular dependency and exposing keys during transit and at rest. Option D is wrong because environment variables can be read by any process or user on the instance, are often logged or captured in debugging output, and still rely on long-term access keys that must be manually rotated.

744
MCQeasy

A company has a security group rule that allows inbound traffic from 0.0.0.0/0 on port 22. The security engineer wants to restrict SSH access to only the company's public IP range (203.0.113.0/24). What is the correct way to update the security group rule?

A.Remove the existing inbound rule and do not add any new rule; SSH access will be denied by default.
B.Modify the existing inbound rule to change the source from 0.0.0.0/0 to 203.0.113.0/24.
C.Add a new inbound rule with source 203.0.113.0/24 and the security group will automatically deny all other traffic.
D.Change the outbound rules to restrict traffic.
AnswerB

Modifying the existing rule's source CIDR from 0.0.0.0/0 to 203.0.113.0/24 is the minimal, precise change: the rule continues to allow TCP/22 only from the company's IP range. Security group rules are stateful and evaluated as a union, so editing the existing rule ensures no separate overly permissive rule remains. This directly satisfies the requirement to allow SSH only from the company IP while preserving connectivity for authorized administrators.

Why this answer

Option B is correct because modifying the existing inbound rule to change the source from 0.0.0.0/0 to 203.0.113.0/24 directly restricts SSH access to the company's public IP range. Security groups are stateful and allow you to edit rules in place, so this is the simplest and most accurate method.

Exam trap

The trap here is assuming that adding a new rule with a narrower CIDR will override the existing broader rule, but security groups are allow-only and all rules are evaluated together, so the broader rule must be removed or modified.

How to eliminate wrong answers

Option A is wrong because removing the rule without adding a new one would block all SSH access, not just restrict it to the company's range. Option C is wrong because adding a new rule does not automatically deny other traffic; security groups are allow-only, so the existing 0.0.0.0/0 rule would still permit all SSH access. Option D is wrong because outbound rules control outbound traffic, not inbound SSH access; changing outbound rules would not restrict inbound SSH.

745
MCQeasy

A security engineer needs to detect and respond to potential credential theft where an IAM user's access key is being used from an unusual geographic location. Which AWS service should be used to generate alerts based on this anomaly?

A.AWS IAM Access Analyzer
B.AWS CloudTrail
C.Amazon GuardDuty
D.AWS Config
AnswerC

Amazon GuardDuty is a continuous threat detection service that consumes CloudTrail management and data events, VPC flow logs, and DNS logs, then applies anomaly detection and threat intelligence to identify suspicious API activity and credential compromise. It uses machine learning to baseline normal behavior and can trigger findings for events like unusual login patterns, account compromises, or API calls made from known malicious IPs. This directly satisfies the requirement to detect and respond to potential behavioral threats, making it the correct choice.

Why this answer

Amazon GuardDuty is the correct choice because it is a threat detection service that uses machine learning and integrated threat intelligence to identify anomalous behavior, such as an IAM access key being used from an unusual geographic location. It specifically analyzes CloudTrail management and data events, VPC flow logs, and DNS logs to detect credential theft patterns like a new geolocation or an impossible travel scenario, and can trigger alerts via Amazon EventBridge or SNS for automated response.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail's logging capability with active threat detection, assuming that CloudTrail alone can generate alerts for geographic anomalies, when in reality it only provides raw logs that require additional analysis services like GuardDuty or custom solutions to detect and alert on such patterns.

How to eliminate wrong answers

Option A is wrong because AWS IAM Access Analyzer is designed to identify resources shared with external entities by analyzing resource-based policies, not to detect anomalous usage patterns like geographic anomalies in access key usage. Option B is wrong because AWS CloudTrail is a logging service that records API activity but does not perform real-time anomaly detection or generate alerts based on unusual geographic locations; it would require additional custom logic (e.g., Athena queries or Lambda functions) to analyze the logs for such patterns. Option D is wrong because AWS Config is a configuration management and compliance service that tracks resource configuration changes and evaluates rules, not a threat detection service capable of identifying credential theft or geographic anomalies in IAM user activity.

746
MCQmedium

An IAM policy grants access to a DynamoDB table with a condition that the request must originate from a specific VPC endpoint. However, requests from an EC2 instance in that VPC are being denied. What is the most likely cause?

A.The EC2 instance does not have a public IP address.
B.The security group on the EC2 instance does not allow outbound traffic to the DynamoDB endpoint.
C.The EC2 instance is not using the VPC endpoint to access DynamoDB; it is using an internet gateway.
D.The VPC endpoint policy does not allow the specific DynamoDB action.
AnswerC

The IAM policy includes a condition that requires requests to originate from the VPC endpoint (e.g., aws:SourceVpce). If the EC2 instance routes traffic over an internet gateway to DynamoDB's public endpoint, the source is the internet gateway, not the VPC endpoint, so the condition fails. This mismatch directly explains the access denied error. To resolve it, the instance should route DynamoDB-bound traffic through the VPC endpoint, or the condition must be changed to align with the actual traffic path.

Why this answer

The IAM policy condition uses aws:SourceVpce to restrict access to requests routed through a specific VPC endpoint. If the EC2 instance reaches DynamoDB via an internet gateway (using the public DynamoDB endpoint), the request's source is not the VPC endpoint, so the condition evaluates to false and access is denied. The instance must be configured to resolve the DynamoDB service name to the VPC endpoint's private DNS name (via the endpoint's private DNS or a Route 53 private hosted zone) so traffic actually flows through the endpoint.

Exam trap

SCS-C02 often tests the misconception that creating a VPC endpoint automatically routes all DynamoDB traffic through it, when in fact DNS resolution and route selection determine whether aws:SourceVpce is populated.

How to eliminate wrong answers

Option A is wrong because a public IP is irrelevant to VPC endpoint access — interface endpoints use private IPs and the instance doesn't need a public IP to reach them. Option B is wrong because the security group on the EC2 instance governs outbound traffic to the endpoint's ENI, but the symptom described (denial due to a condition on the request source) points to the request not traversing the endpoint at all, not a blocked outbound rule; a blocked SG would typically cause a timeout, not an IAM condition failure. Option D is wrong because a restrictive endpoint policy would produce an explicit AccessDenied from the endpoint policy, and the question already states the IAM policy grants access with a source condition — the endpoint policy is a separate layer not indicated as the cause.

747
MCQmedium

A security engineer is auditing an S3 bucket policy that allows cross-account access. The engineer wants to ensure that only encrypted connections are permitted. Which condition should be added to the policy?

A.aws:SourceIp
B.aws:Referer
C.aws:SecureTransport
D.s3:x-amz-server-side-encryption
AnswerC

The aws:SecureTransport condition key evaluates whether the request arrived over TLS, returning false for plain HTTP. Adding it with a Boolean false value denies unencrypted access, satisfying the stem's requirement that only encrypted connections reach the cross-account bucket.

Why this answer

The aws:SecureTransport condition key evaluates to true when the request is made over HTTPS/TLS and false over HTTP. Adding a Deny statement with 'aws:SecureTransport: false' ensures that any non-TLS request to the bucket is rejected, enforcing encrypted connections.

Exam trap

The trap is confusing in-transit encryption (aws:SecureTransport) with at-rest encryption (s3:x-amz-server-side-encryption); candidates who pick the latter misunderstand which layer the condition controls.

How to eliminate wrong answers

Option A is wrong because aws:SourceIp restricts access by source IP address, not by transport encryption; it does not prevent HTTP requests from an allowed IP. Option B is wrong because aws:Referer checks the HTTP Referer header, which is trivially spoofable and unrelated to encryption enforcement. Option D is wrong because s3:x-amz-server-side-encryption checks the encryption algorithm requested for the object at rest, not whether the connection itself is encrypted in transit.

748
MCQeasy

A security engineer needs to ensure that any changes to an S3 bucket's public access settings are immediately detected and an alert is sent. Which combination of AWS services should be used?

A.Amazon GuardDuty and AWS Lambda
B.Amazon CloudWatch Logs and Amazon SNS
C.AWS CloudTrail and Amazon CloudWatch Logs
D.AWS Config and AWS Lambda
AnswerD

AWS Config natively tracks configuration items for S3 buckets and applies managed rules such as s3-bucket-public-read-prohibited and s3-bucket-public-write-prohibited to flag noncompliant public access settings. When a change makes a bucket noncompliant, Config can invoke an AWS Lambda function through an SNS topic or a custom rule, allowing the Lambda to send an alert or automatically remediate the issue. This pairing provides the state-based monitoring and action-taking pipeline the requirement asks for.

Why this answer

AWS Config continuously monitors and records changes to AWS resource configurations, including S3 bucket public access settings. By creating a Config rule that triggers on changes to the `PublicAccessBlockConfiguration` or bucket ACLs, you can invoke an AWS Lambda function via an Amazon SNS topic to send an alert. This combination provides real-time detection and automated response to unauthorized public access changes.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which logs API calls) with AWS Config (which evaluates configuration compliance), leading them to choose Option C, but CloudTrail alone cannot trigger alerts without additional services like CloudWatch Logs and Lambda, and it lacks the continuous compliance evaluation that AWS Config provides.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that monitors for malicious activity (e.g., unusual API calls or compromised credentials), not for configuration changes to S3 bucket public access settings. Option B is wrong because Amazon CloudWatch Logs can store log data but does not natively detect or alert on S3 configuration changes; it would require additional services like CloudTrail to capture the events, and the combination lacks the rule-based evaluation needed for immediate detection. Option C is wrong because AWS CloudTrail logs API calls (including changes to S3 bucket policies), but CloudTrail alone does not provide real-time alerting; while you can create a metric filter on CloudWatch Logs, this setup requires manual configuration and does not natively evaluate configuration compliance like AWS Config does, and it lacks the automated remediation capability of AWS Lambda.

749
MCQhard

A company has a multi-account AWS environment using AWS Organizations. The security team uses AWS Security Hub to consolidate findings. They notice that a critical finding in the production account is not being aggregated in Security Hub. The finding is generated by Amazon GuardDuty. What is the MOST likely cause?

A.Amazon GuardDuty is not enabled in the production account.
B.The IAM role for Security Hub does not have permissions to read GuardDuty findings.
C.AWS Config is not enabled in the production account.
D.VPC Flow Logs are not enabled in the production account.
AnswerA

GuardDuty is the source service that produces the security findings in question. Security Hub is purely an aggregator: it ingests findings from GuardDuty only when GuardDuty is actually enabled and actively detecting threats in the account. If GuardDuty is not enabled in the production account, it generates no findings, so Security Hub has nothing to aggregate, regardless of how correctly Security Hub and cross-account roles are configured. Enabling Security Hub does not automatically enable GuardDuty, so this is the root cause.

Why this answer

Amazon Security Hub aggregates findings from enabled security services across accounts. For GuardDuty findings to appear in Security Hub, GuardDuty must be enabled in the account where the finding is generated. If GuardDuty is not enabled in the production account, it cannot produce findings for Security Hub to consume, which is the most likely cause of the missing critical finding.

Exam trap

The trap here is that candidates may assume Security Hub automatically enables or integrates with all security services across accounts, but in reality, each service (like GuardDuty) must be individually enabled in each account for its findings to be aggregated.

How to eliminate wrong answers

Option B is wrong because Security Hub uses a service-linked role (AWSServiceRoleForSecurityHub) that automatically includes permissions to read findings from GuardDuty via the BatchImportFindings API; an explicit IAM role for reading GuardDuty findings is not required. Option C is wrong because AWS Config is not a prerequisite for Security Hub to aggregate GuardDuty findings; Security Hub can ingest GuardDuty findings independently of Config. Option D is wrong because VPC Flow Logs are not a source of findings for Security Hub; they are used by GuardDuty for anomaly detection but are not required for Security Hub to receive GuardDuty findings.

750
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to enforce that no IAM user can have an access key older than 90 days. What is the MOST efficient way to achieve this?

A.Use an SCP in the root organizational unit that denies IAM actions if the access key age exceeds 90 days.
B.Use AWS Config rules to detect old access keys and send alerts.
C.Use an IAM policy in each account that denies access if the key age exceeds 90 days.
D.Use an SCP to disable IAM user creation.
AnswerA

A service control policy (SCP) applied at the root organizational unit centrally enforces the 90-day access key age limit across all accounts. SCPs can use a condition like 'aws:AccessKeyAge' to deny actions (e.g., 'iam:CreateAccessKey') when the age exceeds 90 days. This is the most efficient because it's a single policy that applies to all accounts without per-account configuration or manual auditing.

Why this answer

A service control policy (SCP) applied at the root organizational unit centrally enforces the 90-day access key age limit across all accounts. SCPs can use a condition like 'aws:AccessKeyAge' to deny actions (e.g., 'iam:CreateAccessKey') when the age exceeds 90 days. This is the most efficient because it's a single policy that applies to all accounts without per-account configuration or manual auditing.

Option B (AWS Config) is reactive—it only sends alerts and does not prevent excessive key age.

Option C (IAM policy in each account) requires deploying a policy to every account individually, which is less efficient and prone to gaps.

Option D disables IAM user creation entirely, which is too restrictive and does not address existing old access keys.

Page 9

Page 10 of 17

Page 11