Courseiva

AWS Certified Security Specialty SCS-C02 (SCS-C02) — Questions 751–825

1205 questions total · 17pages · All types, answers revealed

Page 10

Page 11 of 17

Page 12
751
MCQmedium

A company has a requirement to retain CloudTrail logs for 7 years for compliance. The logs are stored in an S3 bucket. The security team needs to ensure that logs are not deleted before the retention period ends, even by users with full S3 permissions. Which action should be taken?

A.Enable MFA Delete on the bucket and require MFA for all delete operations.
B.Enable S3 Object Lock in Compliance mode on the bucket with a retention period of 7 years.
C.Enable S3 Versioning and set a lifecycle policy to expire noncurrent versions after 7 years.
D.Create a bucket policy that denies s3:DeleteObject for all users.
AnswerB

Compliance mode prevents any user, including the root account, from overwriting or deleting locked object versions until the retention period expires. This directly satisfies the requirement that logs survive seven years despite users holding full S3 permissions.

Why this answer

S3 Object Lock in Compliance mode prevents any user, including the root user, from overwriting or deleting objects until the retention period expires. This meets the requirement to retain CloudTrail logs for 7 years, even against users with full S3 permissions, because Compliance mode cannot be bypassed or removed by any user.

Exam trap

The trap here is that candidates often choose MFA Delete (Option A) because it adds security, but they overlook that MFA Delete does not prevent deletion by authorized users who have MFA devices, whereas Object Lock in Compliance mode provides true immutability against all users.

How to eliminate wrong answers

Option A is wrong because MFA Delete only adds an extra authentication factor for delete operations but does not prevent deletion by users who have MFA credentials, so it cannot guarantee retention against all users. Option C is wrong because versioning with a lifecycle policy only expires noncurrent versions after 7 years, but current versions can still be deleted immediately by users with s3:DeleteObject permission, and lifecycle policies do not prevent direct deletion. Option D is wrong because a bucket policy that denies s3:DeleteObject for all users can be overridden by an explicit allow in an IAM policy or by the root user, and it does not protect against accidental or malicious deletion by users with full permissions who can modify the policy itself.

752
MCQeasy

A company wants to centralize security logs from multiple AWS accounts into a single S3 bucket. The logging accounts (e.g., security, production) each have their own CloudTrail trails. Which configuration is required to allow cross-account log delivery?

A.Create an IAM role in the destination account with write permissions and allow CloudTrail in source accounts to assume that role.
B.Use a customer-managed KMS key in the destination account and share it with the source accounts.
C.Create an S3 bucket policy in the destination account that allows the CloudTrail service principal to write objects.
D.Configure S3 bucket ACLs to grant write access to the source account IDs.
AnswerC

A bucket policy in the destination account is the only mechanism CloudTrail uses to authorize cross-account log delivery, so the policy must allow the CloudTrail service principal (cloudtrail.amazonaws.com) to perform s3:PutObject and s3:GetBucketAcl on the bucket. For additional security, restrict the policy with aws:SourceAccount or aws:SourceArn to a specific source account, and when SSE-KMS is enabled, also include kms:GenerateDataKey and kms:Decrypt in the policy.

Why this answer

CloudTrail cross-account log delivery requires the destination S3 bucket to have a bucket policy that explicitly grants the CloudTrail service principal (`cloudtrail.amazonaws.com`) permission to write objects (e.g., `s3:PutObject`). This allows CloudTrail in any source account to deliver logs directly to the bucket without needing IAM roles or shared credentials, as the service principal authenticates on behalf of the source account.

Exam trap

The trap here is that candidates often assume cross-account access requires an IAM role (Option A) or shared encryption keys (Option B), but AWS services like CloudTrail use service principals and bucket policies for cross-account log delivery, not IAM roles or ACLs.

How to eliminate wrong answers

Option A is wrong because CloudTrail does not assume an IAM role in the destination account; it uses the source account's CloudTrail service principal to write logs, and the bucket policy must grant access to that principal, not an IAM role. Option B is wrong because while a customer-managed KMS key can be used for encryption, it is not required for cross-account log delivery; the core requirement is the bucket policy, and sharing a KMS key alone does not enable CloudTrail to write logs. Option D is wrong because S3 bucket ACLs are not supported for granting cross-account write access to the CloudTrail service principal; bucket ACLs are legacy and cannot grant permissions to AWS service principals, only to AWS accounts or canonical user IDs.

753
Multi-Selecteasy

Which TWO of the following are best practices for managing IAM user credentials? (Choose TWO.)

Select 2 answers
A.Create a single IAM user for multiple developers.
B.Store access keys in source code repositories for convenience.
C.Enable MFA for all IAM users.
D.Rotate access keys regularly.
E.Use long-term access keys for all users.
AnswersC, D

Enabling MFA for all IAM users is a core AWS security best practice because it requires something the user has, such as a TOTP device or U2F key, in addition to a password or access key. This materially reduces the risk that a stolen password or access key alone can be used to access the account, and AWS recommends MFA for every user including root. MFA protects against credential theft and is an explicit requirement for privileged accounts in many compliance frameworks.

Why this answer

Option C is correct because enabling multi-factor authentication (MFA) for all IAM users adds a second authentication factor beyond the password, significantly reducing the risk of credential compromise if a password is leaked or guessed. Option D is correct because regularly rotating access keys limits the window of exposure if a key is compromised and aligns with AWS security best practices for credential lifecycle management. Option A is incorrect because sharing a single IAM user across multiple developers eliminates individual accountability and makes it impossible to audit or revoke access per person; each developer should have a unique IAM user or federated identity.

Option B is incorrect because storing access keys in source code repositories exposes them to anyone with repository access and is a common cause of credential leakage; secrets should be stored in AWS Secrets Manager or similar. Option E is incorrect because relying on long-term access keys for all users increases risk; temporary credentials via IAM roles or AWS STS are preferred where possible.

Exam trap

SCS-C02 often tests the misconception that convenience (shared users, hardcoded keys) is acceptable, when the exam expects you to recognize that identity isolation, MFA, and short-lived credentials are non-negotiable security controls.

754
MCQmedium

A company is using AWS CloudTrail to monitor API activity in their account. They have enabled CloudTrail in all regions and are logging to an S3 bucket. The security team wants to ensure that log files are not tampered with after delivery. They enable CloudTrail log file integrity validation. Which additional step must be taken to verify the integrity of the log files?

A.Enable S3 versioning on the log bucket.
B.Configure the S3 bucket to use server-side encryption with AWS KMS.
C.Enable S3 Object Lock on the log bucket.
D.Use the AWS CLI to run the validate-logs command against the log files.
AnswerD

Run the AWS CLI command `aws cloudtrail validate-logs --trail-arn ... --start-time ... --end-time ...` to validate CloudTrail log file integrity. The command downloads the signed digest files, verifies their digital signatures using CloudTrail's public key, and then compares the SHA-256 hash of each log file against the hash recorded in the digest, detecting any modification, deletion, or insertion. This is the only option that cryptographically verifies log integrity and is purpose-built for exactly this scenario.

Why this answer

CloudTrail log file integrity validation uses digital signatures (SHA-256 hashing and signing with a private key). To verify integrity, you must use the AWS CLI command 'aws cloudtrail validate-logs' or download the public key and verify manually. Option A (enable S3 versioning) helps protect against accidental deletion or overwriting but does not verify integrity.

Option B (use KMS to encrypt logs) protects confidentiality only. Option C (use S3 Object Lock) prevents deletion or modification but does not provide tamper detection or integrity verification.

755
MCQmedium

An organization uses AWS Organizations and wants to centrally manage Amazon GuardDuty across multiple accounts. What is the correct architecture?

A.Enable GuardDuty only in the master account; it will automatically monitor all member accounts.
B.Use AWS CloudFormation StackSets to deploy GuardDuty in all accounts and regions.
C.Designate a delegated administrator account in Organizations and enable GuardDuty in that account.
D.Enable GuardDuty in each region separately and use cross-region aggregation.
AnswerC

The correct approach is to designate a delegated administrator account in AWS Organizations for GuardDuty. This delegated admin can enable GuardDuty for all member accounts, manage their detectors, and view aggregated findings centrally without needing per-account invitations. It is the only method that provides a single admin control plane over multi-account GuardDuty coverage and findings.

Why this answer

AWS Organizations allows you to designate a delegated administrator account for Amazon GuardDuty, which can then centrally manage GuardDuty across all member accounts in the organization. This architecture simplifies enabling GuardDuty and managing findings without needing to configure each account individually, as the delegated administrator can enable GuardDuty for all accounts in the organization from a single point.

Exam trap

The trap here is that candidates often assume enabling GuardDuty in the master account automatically covers all member accounts (Option A), but in reality, GuardDuty requires explicit member account management or a delegated administrator setup, and the delegated administrator model is the recommended architecture for centralized management in Organizations.

How to eliminate wrong answers

Option A is wrong because enabling GuardDuty only in the master account does not automatically monitor member accounts; GuardDuty must be explicitly enabled in each account, or a delegated administrator must be used to manage member accounts centrally. Option B is wrong because while AWS CloudFormation StackSets can deploy resources across accounts and regions, GuardDuty is a regional service that requires a centralized management approach via Organizations, and StackSets do not provide the native integration for cross-account threat detection management that a delegated administrator does. Option D is wrong because GuardDuty findings are regional by default, and cross-region aggregation is not a built-in feature; instead, you would need to use a delegated administrator to centrally view findings from multiple regions, but the correct architecture for multi-account management is through Organizations delegation, not separate per-region enablement.

756
MCQmedium

A company is using Amazon EC2 instances in a VPC with a security group that allows inbound SSH from 0.0.0.0/0. A security engineer needs to restrict SSH access to only the company's public IP range (203.0.113.0/24) while maintaining all other existing rules. What is the MOST efficient way to accomplish this?

A.Disable SSH and use AWS Systems Manager Session Manager to connect to instances.
B.Create a network ACL with an inbound rule allowing SSH from 203.0.113.0/24 and deny all other traffic.
C.Modify the existing security group rule to change the source from 0.0.0.0/0 to 203.0.113.0/24.
D.Create a new security group rule allowing SSH from 203.0.113.0/24 and keep the existing rule.
AnswerC

Modifying the existing rule is the correct action because security group inbound rules are evaluated as an allow list, and changing the source to 203.0.113.0/24 removes the wildcard entry while authorizing only the specified IP range. The update is an in-place edit, so no duplicate rule remains and the stateful security group automatically permits the return traffic for established SSH sessions. The existing rule should be changed rather than appended because any remaining 0.0.0.0/0 rule would continue to allow all source IPs.

Why this answer

Modifying the existing security group rule's source from 0.0.0.0/0 to 203.0.113.0/24 directly restricts inbound SSH to the company's public IP range without affecting any other rules. Security groups are stateful and rule changes apply immediately, making this the most efficient approach as it requires only a single edit to the existing rule.

Exam trap

The trap here is that candidates may think adding a more specific allow rule overrides a broader allow rule, but security groups use an allow-list model where all rules are additive, so the original 0.0.0.0/0 rule must be removed or modified to actually restrict access.

How to eliminate wrong answers

Option A is wrong because disabling SSH and using AWS Systems Manager Session Manager is an alternative solution, not the most efficient way to restrict SSH access while maintaining existing rules; it changes the access method entirely and may not meet the requirement to restrict SSH specifically. Option B is wrong because network ACLs are stateless and operate at the subnet level, not the instance level; modifying a network ACL would affect all instances in the subnet and require separate inbound and outbound rules for return traffic, making it less efficient and not a direct replacement for a security group rule. Option D is wrong because adding a new security group rule allowing SSH from 203.0.113.0/24 while keeping the existing rule with 0.0.0.0/0 would still allow SSH from all IPs, as security group rules are evaluated as a logical OR; the existing permissive rule would remain in effect, failing to restrict access.

757
MCQmedium

A security engineer is designing a web application that will run on EC2 instances behind an Application Load Balancer (ALB). The application must be protected from common web exploits like SQL injection and cross-site scripting. Which AWS service should be used to provide this protection?

A.AWS WAF
B.Network ACLs
C.Security Groups
D.AWS Shield Advanced
AnswerA

AWS WAF integrates directly with the Application Load Balancer, inspecting HTTP requests against rule groups that block SQL injection and cross-site scripting patterns before traffic reaches the EC2 instances. This satisfies the stem's requirement for protection from common web exploits at the ALB layer, filtering malicious payloads inline.

Why this answer

AWS WAF is a Layer 7 web application firewall that inspects HTTP/HTTPS requests and can block common exploits like SQL injection and cross-site scripting using managed rule groups (e.g., AWSManagedRulesCommonRuleSet, SQLiRuleSet, XSSRuleSet). It integrates natively with ALB, CloudFront, and API Gateway, making it the correct choice for protecting an ALB-fronted web app.

Exam trap

The trap is confusing DDoS protection (Shield) or network-layer filtering (NACLs, Security Groups) with application-layer exploit protection (WAF); only WAF inspects HTTP payloads.

How to eliminate wrong answers

Option B is wrong because Network ACLs are stateless Layer 3/4 filters that only allow or deny based on IP, port, and protocol — they cannot inspect HTTP payloads for SQLi or XSS patterns. Option C is wrong because Security Groups are stateful Layer 3/4 firewalls attached to ENIs; they control which ports and IPs can reach the instance but have no application-layer inspection capability. Option D is wrong because AWS Shield Advanced provides DDoS protection (Layer 3/4 and some Layer 7 volumetric mitigation) but does not perform signature-based inspection for SQLi or XSS.

758
MCQhard

A company uses AWS Organizations with multiple accounts. The security team wants to centrally collect and analyze VPC Flow Logs from all accounts. The team has set up a central logging account with an S3 bucket that has a bucket policy allowing cross-account writes. However, VPC Flow Logs from member accounts are not appearing. What is the most likely cause?

A.AWS CloudTrail is not enabled in the member accounts.
B.The VPC Flow Logs must be delivered to CloudWatch Logs first, then exported to S3.
C.VPC Flow Logs cannot be published directly to an S3 bucket in a different account. The logs must be published to a bucket in the same account as the VPC, and then replicated to the central account.
D.The S3 bucket policy does not allow the s3:PutObject action for the member accounts.
AnswerC

When you create a VPC Flow Log, the destination S3 bucket must be in the same AWS account as the VPC; Amazon VPC does not support publishing flow logs directly to an S3 bucket in a different account. To aggregate logs from member accounts into a central account, you must first deliver them to an S3 bucket in each member account, then configure S3 replication or another copy mechanism to move the logs to the central bucket. Because the company attempted direct cross-account delivery, the flow logs fail to appear in the central destination.

Why this answer

VPC Flow Logs cannot be published directly to an S3 bucket in a different AWS account. The destination S3 bucket must reside in the same account as the VPC from which the logs are generated. To centralize logs, you must first publish them to a bucket in the same account as the VPC, then use S3 cross-region replication or a similar mechanism to copy them to the central logging account.

This is a fundamental limitation of the VPC Flow Logs service.

Exam trap

The trap here is that candidates assume a properly configured bucket policy with cross-account permissions is sufficient, but AWS explicitly restricts VPC Flow Logs to same-account S3 destinations, making the policy irrelevant for direct cross-account delivery.

How to eliminate wrong answers

Option A is wrong because CloudTrail is not required for VPC Flow Logs; they are independent services and CloudTrail's absence does not prevent Flow Log delivery. Option B is wrong because VPC Flow Logs can be published directly to an S3 bucket without first sending them to CloudWatch Logs; the delivery destination can be either CloudWatch Logs or S3. Option D is wrong because the question states the bucket policy already allows cross-account writes, so the s3:PutObject permission is not the issue; the core problem is the architectural limitation of cross-account direct delivery.

759
MCQhard

A company uses Amazon S3 to store sensitive data. The security team needs to be alerted when an S3 bucket policy is changed to allow public access. Which combination of services should be used to meet this requirement?

A.AWS CloudTrail and Amazon Simple Notification Service (SNS)
B.S3 server access logs and Amazon Athena
C.AWS Trusted Advisor and Amazon Simple Notification Service (SNS)
D.AWS Config with AWS Lambda and Amazon Simple Notification Service (SNS)
AnswerD

AWS Config can continuously record configuration changes to an S3 bucket policy and evaluate those changes against a managed or custom rule. When a PutBucketPolicy event occurs, AWS Config marks the configuration item as changed and invokes a custom Lambda function, which can in turn publish a message to an SNS topic to notify security teams. This design provides real-time detection and alerting because the Lambda function is triggered by the configuration change, not by a periodic scan.

Why this answer

AWS Config can monitor S3 bucket policies for changes that grant public access using a managed rule like 's3-bucket-public-read-prohibited' or a custom Lambda function. When a noncompliant change is detected, AWS Config can invoke an AWS Lambda function to evaluate the policy and publish a notification to Amazon SNS, alerting the security team. This combination provides real-time, policy-driven monitoring and alerting for public access changes.

Exam trap

The trap here is that candidates often choose AWS CloudTrail (Option A) because it logs API calls like PutBucketPolicy, but they overlook that CloudTrail alone cannot evaluate the policy content for public access or trigger alerts without additional services like EventBridge and Lambda, whereas AWS Config is purpose-built for continuous compliance monitoring and alerting.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail logs API calls but does not evaluate bucket policies for public access or trigger alerts directly; it would require additional services like Amazon EventBridge and Lambda to filter and act on specific events, making it less direct than AWS Config. Option B is wrong because S3 server access logs record object-level requests (e.g., GET, PUT) and are not designed to monitor or alert on bucket policy changes; Athena is used for querying logs, not for real-time alerting. Option C is wrong because AWS Trusted Advisor checks for publicly accessible S3 buckets but only provides periodic checks (not real-time) and does not trigger alerts via SNS automatically for policy changes; it requires manual review or custom automation.

760
MCQmedium

A company wants to use client-side encryption for data uploaded to Amazon S3. The encryption keys must be managed by the company and never sent to AWS. Which S3 encryption option supports this requirement?

A.Server-side encryption with AWS KMS (SSE-KMS).
B.Client-side encryption using the Amazon S3 encryption client.
C.Server-side encryption with S3 managed keys (SSE-S3).
D.Server-side encryption with customer-provided keys (SSE-C).
AnswerB

The Amazon S3 encryption client performs all cryptographic operations locally, encrypting the object's plaintext with a data key before anything is transmitted; the resulting ciphertext and an encrypted copy of the data key are then uploaded. The plaintext data key is never sent to AWS, and you can choose to wrap the data key with a KMS key or an internal master key that remains entirely under your control. This design is exactly what is needed when only the customer should ever possess the unencrypted form of the data.

Why this answer

Client-side encryption using the Amazon S3 encryption client is correct because the encryption process occurs entirely on the client side before data is uploaded to S3. The company manages the encryption keys locally and never transmits them to AWS, satisfying the requirement that keys are never sent to AWS.

Exam trap

The trap here is that candidates often confuse SSE-C with client-side encryption, not realizing that SSE-C still transmits the encryption key to AWS over the network, albeit encrypted in transit, which violates the 'never sent to AWS' requirement.

How to eliminate wrong answers

Option A is wrong because SSE-KMS uses AWS KMS to manage encryption keys, and the keys are stored and managed by AWS, not the company. Option C is wrong because SSE-S3 uses S3-managed keys that are fully controlled by AWS, not the customer. Option D is wrong because SSE-C requires the customer to provide an encryption key with each request, but the key is sent to AWS over HTTPS for the encryption operation, violating the requirement that keys never be sent to AWS.

761
MCQhard

A company uses Amazon S3 to store sensitive data. The security team wants to detect when objects are made publicly accessible. Which combination of services provides the MOST comprehensive detection with minimal false positives?

A.Enable S3 Block Public Access at the account level and use AWS Config rules to detect public ACLs and bucket policies.
B.Use Amazon Macie to scan S3 buckets for publicly accessible objects.
C.Enable CloudTrail data events for S3 and create a CloudWatch Events rule for PutBucketAcl calls.
D.Enable Amazon GuardDuty and review the S3 findings for public access.
AnswerA

S3 Block Public Access at the account level is a preventive control that overrides any bucket policy or ACL that would grant public access, while AWS Config managed rules such as s3-bucket-public-read-prohibited and s3-bucket-policy-not-more-permissive provide continuous detective monitoring. Together they address both the existence of public ACLs and public bucket policies, which are the two primary vectors for accidental public exposure. This combination satisfies the security requirement without relying on noisy event monitoring or unrelated threat-detection tools.

Why this answer

S3 Block Public Access at the account level provides a preventive control that denies all public access, while AWS Config rules (e.g., s3-bucket-public-read-prohibited, s3-bucket-policy-not-more-permissive) continuously evaluate and detect any public ACLs or bucket policies that would allow public access. This combination ensures comprehensive detection with minimal false positives because Config rules are deterministic and based on explicit policy evaluation, not on heuristic or behavioral analysis.

Exam trap

The trap here is that candidates often choose CloudTrail-based detection (Option C) thinking it captures all public access changes, but they overlook that bucket policies can grant public access without triggering a PutBucketAcl call, and that CloudTrail data events may not be enabled or may miss existing misconfigurations.

How to eliminate wrong answers

Option B is wrong because Amazon Macie is designed to discover sensitive data (e.g., PII, credentials) using machine learning and pattern matching, not to detect public access configurations; it may generate false positives for public objects that do not contain sensitive data. Option C is wrong because CloudTrail data events for S3 and a CloudWatch Events rule for PutBucketAcl calls only capture API calls that change ACLs, but they miss public access granted via bucket policies (PutBucketPolicy) and do not detect existing public objects or changes made outside of CloudTrail logging. Option D is wrong because Amazon GuardDuty uses threat intelligence and anomaly detection to identify suspicious activity (e.g., unusual data access patterns), not to directly detect public access configurations; its S3 findings are behavioral and may produce false positives or miss misconfigurations that are not actively exploited.

762
MCQeasy

A company has a VPC with public and private subnets. The private subnets need to access the internet for software updates. Which component should be added to the VPC to enable this?

A.Internet gateway
B.VPN connection
C.VPC peering connection
D.NAT gateway
AnswerD

A NAT gateway sits in the public subnet with an Elastic IP and performs source NAT, letting private-subnet instances initiate outbound internet traffic for updates while blocking unsolicited inbound connections. This satisfies the requirement to give private subnets internet access without exposing them.

Why this answer

A NAT gateway allows instances in private subnets to initiate outbound internet traffic while preventing inbound traffic from the internet. It is placed in a public subnet and uses an Elastic IP, and private subnet route tables point to it for 0.0.0.0/0.

Exam trap

The trap is confusing NAT gateway with internet gateway; candidates may think private subnets can use an internet gateway directly, but that would require them to be public and have public IPs.

How to eliminate wrong answers

Option A is wrong because an internet gateway enables bidirectional internet access for public subnets; private subnets cannot use it directly without becoming public. Option B is wrong because a VPN connection connects to on-premises networks, not the internet. Option C is wrong because VPC peering connects two VPCs, not to the internet.

763
MCQhard

A company uses AWS CloudHSM to generate and store encryption keys for a custom application. The security team is concerned about key durability and wants to ensure that keys are not lost if the HSM fails. Which action should be taken?

A.Create a multi-region CloudHSM cluster
B.Store the keys in a file on an encrypted EBS volume
C.Use AWS KMS to import the keys from CloudHSM
D.Regularly back up the HSM to an Amazon S3 bucket and restore to a new cluster if needed
AnswerD

CloudHSM automatically stores encrypted backups of each HSM partition in Amazon S3, and you can schedule backups on a regular basis to protect against hardware failure or cluster loss. These backups capture the HSM's key material and data in an encrypted, point-in-time snapshot that can be restored to a new cluster in the same region. By regularly backing up, you ensure that if the cluster becomes unavailable, you can launch a new cluster and restore the backup, preserving access to the keys. This is the supported disaster-recovery mechanism for CloudHSM.

Why this answer

AWS CloudHSM supports taking backups of the HSM content to an Amazon S3 bucket. These backups can be used to restore to a new HSM cluster in case of failure, ensuring key durability. Option A is incorrect because CloudHSM clusters are single-region; multi-region clusters are not supported.

Option B is incorrect because storing keys on an encrypted EBS volume bypasses the security of the HSM and is not a recommended practice for key durability. Option C is incorrect because AWS KMS cannot directly import keys from CloudHSM; KMS and CloudHSM are separate services with different key management capabilities.

Exam trap

Candidates may mistakenly believe that exporting keys to an EBS volume or using KMS provides adequate durability, but CloudHSM's native backup and restore mechanism is the correct method to protect against HSM failure.

764
MCQhard

A company uses Amazon RDS for MySQL with encryption at rest enabled using AWS KMS. They need to ensure that automated backups and snapshots are also encrypted. Which configuration is required?

A.No additional configuration is needed; backups are encrypted automatically.
B.Manually encrypt each snapshot with a separate KMS key.
C.Create a new KMS key and assign it to the backup configuration.
D.Enable encryption on the RDS instance after creation.
AnswerA

Because the RDS MySQL instance already has encryption at rest enabled with a KMS key, all automated backups and manual DB snapshots are encrypted automatically using that same KMS key. AWS handles this at the storage layer with no further input from you, so backup encryption is inherently included.

Why this answer

Amazon RDS automatically encrypts automated backups and snapshots when the source database is encrypted at rest. This encryption is inherited from the primary database, so no additional steps are required. Options B, C, and D are incorrect: manually encrypting each snapshot is unnecessary; assigning a new KMS key to backups is not required; and enabling encryption after creation is not possible for an existing unencrypted instance.

765
MCQmedium

Your company has a single AWS account with a production VPC that contains several EC2 instances running a web application. The security team has enabled Amazon GuardDuty and AWS CloudTrail. Recently, GuardDuty reported a finding 'UnauthorizedAccess:EC2/TorClient' for one of the instances. The finding indicates that the instance is making connections to Tor exit nodes. You need to investigate and contain the incident. The instance is critical to the application and cannot be terminated. You have a forensic analysis instance in a separate security group. What should you do FIRST?

A.Isolate the instance by modifying its security group to remove all inbound and outbound rules except for the forensic analysis instance.
B.Terminate the instance immediately and launch a replacement.
C.Take an EBS snapshot of the instance's root volume for analysis.
D.Use AWS Systems Manager Run Command to install a forensic agent on the instance.
AnswerA

This is the correct immediate response because modifying the security group to remove all inbound and outbound rules—except for a single forensic analysis instance—instantly severs the attacker's network channel while preserving the running instance for investigation. It halts data exfiltration in real time and prevents the attacker from issuing further commands over the network, unlike a snapshot that captures disk state but does not stop ongoing activity. The isolated instance retains volatile evidence like process memory and active network connections, which a forensic analyst can later harvest using controlled, trusted access.

Why this answer

The first step in incident response for a compromised instance that cannot be terminated is to contain the threat by isolating it from the network. Modifying the security group to remove all inbound and outbound rules except for a specific forensic analysis instance prevents the compromised EC2 instance from communicating with Tor exit nodes or other external hosts, while still allowing controlled forensic access. This containment is immediate and reversible, aligning with the AWS incident response best practice of 'isolate first, investigate later'.

Exam trap

The trap here is that candidates may rush to collect forensic evidence (snapshot or agent) before containing the threat, failing to recognize that the first priority in incident response is to stop the active malicious behavior (outbound Tor connections) to prevent data exfiltration or further compromise.

How to eliminate wrong answers

Option B is wrong because the instance is critical to the application and cannot be terminated, and immediate termination would destroy volatile data (e.g., running processes, memory contents) needed for forensic analysis. Option C is wrong because taking an EBS snapshot is a valid forensic step, but it should be performed after containment to prevent the compromised instance from continuing malicious outbound connections during the snapshot process. Option D is wrong because installing a forensic agent via Systems Manager Run Command requires network connectivity and could be blocked or tampered with by the malware, and it does not address the immediate need to stop the outbound Tor connections.

766
MCQeasy

A security engineer needs to grant cross-account read access to an S3 bucket in Account A to a user in Account B. What is the correct combination of actions?

A.Attach an IAM policy to the user in Account B allowing the action; no bucket policy needed
B.Apply a bucket policy in Account A granting access to the user in Account B; no user policy needed
C.Use S3 bucket ACLs to grant READ access to the Account B user
D.Apply a bucket policy in Account A granting access to the principal in Account B, and attach an IAM policy to the user in Account B allowing the action
AnswerD

This is the correct and complete solution. For cross-account S3 access, AWS requires that both the resource-based policy (bucket policy) in Account A and the identity-based policy (IAM policy) attached to the user in Account B explicitly allow the s3:GetObject action. The bucket policy grants the Account B principal access to the bucket, while the IAM policy provisions that principal with the necessary action permissions in its own account. Without either side, the request is denied. This dual-policy requirement ensures both the resource owner and the caller's account are aligned.

Why this answer

Cross-account S3 access requires both a bucket policy in the resource account (Account A) that explicitly grants the cross-account principal (the user in Account B) the s3:GetObject action, and an IAM policy attached to the user in Account B that allows the same action. This two-way authorization is necessary because the bucket policy controls access to the S3 resource, while the IAM policy controls the user's permissions to initiate the request. Without both, the request will be denied by either the resource-based policy or the identity-based policy.

Exam trap

The trap here is that candidates often assume either a bucket policy alone or an IAM policy alone is sufficient for cross-account access, failing to recognize that AWS requires both the resource-based policy to grant access to the external principal and the identity-based policy to authorize the user to make the request.

How to eliminate wrong answers

Option A is wrong because an IAM policy alone in Account B cannot grant access to a resource in Account A; the resource owner must also allow access via a bucket policy or ACL. Option B is wrong because a bucket policy alone in Account A is insufficient; the user in Account B must also have an IAM policy that permits the s3:GetObject action, otherwise the request is denied by the user's own account. Option C is wrong because S3 bucket ACLs are legacy and do not support granting access to individual IAM users in another account; they only support AWS accounts or predefined groups, and are generally superseded by bucket policies for cross-account access.

767
MCQeasy

A security engineer is configuring Amazon GuardDuty in a multi-account environment using AWS Organizations. The engineer wants to designate a delegated administrator account to manage GuardDuty for all member accounts. Which AWS service must be used to enable GuardDuty for all accounts?

A.AWS CloudFormation StackSets
B.AWS Control Tower
C.AWS Config
D.AWS Organizations
AnswerD

AWS Organizations is the foundation for GuardDuty's multi-account management: when you designate a delegated administrator and enable GuardDuty for the organization, GuardDuty automatically provisions detectors in all current and future member accounts and centrally aggregates their findings. This native integration lets you onboard new accounts without manual invites and gives you unified visibility through the administrator account, making Organizations the correct answer.

Why this answer

AWS Organizations is the foundational service required to designate a delegated administrator for Amazon GuardDuty in a multi-account environment. GuardDuty integrates directly with Organizations to allow a management account to enable GuardDuty for all member accounts and delegate administration to a specified account, which then manages threat detection across the organization without needing additional services.

Exam trap

The trap here is that candidates may confuse AWS Organizations as merely an organizational tool and think they need a separate service like CloudFormation StackSets or Control Tower to enable GuardDuty across accounts, but GuardDuty natively integrates with Organizations for delegated administration and automatic enablement.

How to eliminate wrong answers

Option A is wrong because AWS CloudFormation StackSets is used to deploy infrastructure as code across multiple accounts and regions, but it is not required or used to enable GuardDuty or designate a delegated administrator; GuardDuty's multi-account setup is managed through the GuardDuty console or API using Organizations. Option B is wrong because AWS Control Tower provides a governance framework for landing zones and uses Account Factory and preventive/ detective guardrails, but it does not directly enable GuardDuty or designate a delegated administrator; GuardDuty integration is handled via Organizations, not Control Tower. Option C is wrong because AWS Config is a service for resource inventory, configuration history, and compliance rules, not for enabling GuardDuty or managing delegated administration; GuardDuty's multi-account enablement relies on Organizations APIs, not Config.

768
MCQeasy

A company needs to securely store database credentials that are used by an application running on Amazon EC2. The credentials must be automatically rotated every 90 days. Which AWS service should be used?

A.AWS KMS
B.AWS Secrets Manager
C.AWS IAM roles for EC2
D.AWS Systems Manager Parameter Store
AnswerB

AWS Secrets Manager is a purpose-built service for storing and managing database credentials, API keys, and other sensitive values. It natively supports automatic rotation of secrets using a customizable AWS Lambda function, with one-click integration for Amazon RDS, Redshift, and DocumentDB to rotate the password on the datastore as well. Because it combines secure storage, fine-grained IAM access control, secret versioning, and scheduled rotation, it directly meets the stated requirement for securely storing database credentials with automatic rotation.

Why this answer

AWS Secrets Manager is purpose-built for storing, retrieving, and automatically rotating database credentials. It natively supports rotation for Amazon RDS, Aurora, and other databases via Lambda rotation functions, and can rotate credentials every 90 days as required. This directly meets the requirement for secure storage and automatic rotation.

Exam trap

SCS-C02 often tests the difference between Secrets Manager and Parameter Store, leading candidates to choose Parameter Store for automatic rotation when it lacks native rotation capabilities.

How to eliminate wrong answers

Option A is wrong because AWS KMS is a key management service for encryption keys, not for storing and rotating database credentials. Option C is wrong because IAM roles for EC2 provide temporary credentials for AWS API access, not database credentials, and they do not rotate database passwords. Option D is wrong because Systems Manager Parameter Store can store secrets but does not natively support automatic rotation of database credentials; it requires custom automation.

769
MCQmedium

A company uses AWS Direct Connect to connect its on-premises data center to AWS. The company has a VPC with public and private subnets. The security team wants to ensure that all traffic between on-premises and the VPC goes through a set of security appliances (firewalls) deployed in the VPC. The appliances are in separate subnets. Currently, traffic is routed directly via the virtual private gateway. What is the MOST secure and scalable way to force traffic through the security appliances?

A.Place the security appliances in a public subnet and route traffic through a NAT gateway.
B.Create a transit gateway and attach the Direct Connect virtual interface to it. Then route traffic through the appliance subnets.
C.Deploy a Gateway Load Balancer and create Gateway Load Balancer endpoints in each subnet. Update the route tables to point to the endpoints.
D.Set up a VPN connection from on-premises to the VPC and route traffic through the appliance subnets.
AnswerC

A Gateway Load Balancer (GWLB) transparently intercepts traffic using Gateway Load Balancer endpoints, which are VPC endpoints that can be designated as route-table targets. After you deploy the GWLB in one VPC and the security appliances in target groups, you create endpoints in each subnet and update those subnets' route tables to point the Direct Connect prefix or default route to the endpoints. The GWLB then encapsulates traffic using the GENEVE protocol and distributes flows across the appliance fleet, enabling scaling, health checks, and automatic failover while keeping the appliances transparent to the source and destination. This is the standard pattern for inserting a horizontal fleet of third-party security appliances inline for inspection of Direct Connect traffic.

Why this answer

Using a Gateway Load Balancer with Gateway Load Balancer endpoints in each subnet allows transparent traffic inspection and scaling. Option A is wrong because a NAT gateway only handles outbound traffic, not bidirectional inspection. Option B is wrong because a transit gateway does not force traffic through appliances; additional routing and appliance VPCs are needed.

Option D is wrong because a VPN connection does not inherently route through VPC appliances; it would require custom routing.

770
MCQhard

A security engineer notices that an EC2 instance in a private subnet can reach the internet, even though there is no NAT gateway or instance in the route table. What is the most likely cause?

A.An internet gateway is attached to the VPC and a default route points to it.
B.A VPC endpoint for S3 is configured.
C.A NAT gateway is configured in a different availability zone.
D.An egress-only internet gateway is used for IPv6 traffic.
AnswerD

An egress-only internet gateway (EIGW) is a special gateway that enables outbound IPv6 connectivity from a VPC to the internet while blocking any inbound IPv6 traffic. It is the IPv6 counterpart to a NAT gateway, designed for private subnets that need to initiate internet requests without being connetionally reachable. The presence of a route for ::/0 pointing to the EIGW in the private subnet's route table exactly produces the observed outbound-only behavior.

Why this answer

An egress-only internet gateway (EIGW) allows outbound-only IPv6 traffic from instances in a private subnet to the internet, but it does not permit inbound connections initiated from the internet. Since the question states there is no NAT gateway or instance, and the instance can reach the internet, the most likely cause is that the VPC uses IPv6 and an EIGW is configured with a default route (::/0) pointing to it. This enables outbound internet access without a NAT device, matching the described scenario.

Exam trap

The trap here is that candidates often assume internet access from a private subnet always requires a NAT gateway or instance, overlooking the fact that egress-only internet gateways provide outbound-only IPv6 internet access without any NAT device.

How to eliminate wrong answers

Option A is wrong because an internet gateway (IGW) attached to a VPC with a default route (0.0.0.0/0) pointing to it would provide internet access only to instances in public subnets (those with a route to the IGW and a public IP), not to instances in a private subnet. Option B is wrong because a VPC endpoint for S3 provides private connectivity to S3 only, not general internet access. Option C is wrong because a NAT gateway configured in a different availability zone would still appear in the route table of the private subnet’s route table (as a default route pointing to the NAT gateway ID) to provide internet access; the question explicitly states there is no NAT gateway or instance in the route table, so this cannot be the cause.

771
MCQmedium

A company has enabled Amazon GuardDuty in all accounts within AWS Organizations. The security team wants to view aggregated findings from all accounts in a single dashboard. Which service should the team use?

A.Amazon CloudWatch
B.Amazon Inspector
C.Amazon Macie
D.AWS Security Hub
AnswerD

AWS Security Hub is a cloud security posture management service that aggregates security findings from GuardDuty, Inspector, Macie, and other AWS services into a consistent format. It supports cross-account aggregation through AWS Organizations, enabling a consolidated view of threat findings across all accounts. Security Hub also runs continuous security standard checks and enables automated remediation, making it the correct service to centralize GuardDuty findings.

Why this answer

AWS Security Hub is the correct service because it provides a single dashboard that aggregates and prioritizes security findings from multiple AWS services, including Amazon GuardDuty, across all accounts in an AWS Organization. It normalizes findings from GuardDuty, Inspector, Macie, and other sources into the AWS Security Finding Format (ASFF), enabling centralized viewing and automated response workflows.

Exam trap

The trap here is that candidates may confuse GuardDuty's own multi-account dashboard with Security Hub's cross-service aggregation, or mistakenly think CloudWatch can serve as a centralized security dashboard, but CloudWatch lacks the finding normalization and multi-account aggregation capabilities that Security Hub provides.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch is a monitoring and observability service for metrics, logs, and alarms, not designed to aggregate security findings from GuardDuty across multiple accounts into a single dashboard. Option B is wrong because Amazon Inspector is a vulnerability assessment service that scans EC2 instances and container images for software vulnerabilities and network exposure; it does not aggregate GuardDuty findings. Option C is wrong because Amazon Macie is a data security service that discovers and protects sensitive data in S3 using machine learning; it does not aggregate GuardDuty findings from other accounts.

772
MCQeasy

A company wants to allow users from an external AWS account to assume a role in the company's account. What must be configured in the company's account?

A.An IAM user in the company's account with cross-account access.
B.A permissions policy that allows the external account to list roles.
C.An IAM identity provider for the external account.
D.A trust policy that allows the external account to assume the role.
AnswerD

The trust policy, also called the assume-role policy, is attached to the IAM role and grants the external AWS account permission to call sts:AssumeRole, with the account ID listed as the Principal. When the external account's IAM users or roles have permission to use that trust relationship, AWS then issues temporary credentials scoped by the role's permissions policy. This is exactly the cross-account role assumption pattern required to give the external account access.

Why this answer

Cross-account IAM role access requires the role in the company's account to have a trust policy that explicitly grants the external AWS account's root user or specific IAM entities permission to assume the role. The trust policy uses the `sts:AssumeRole` action and specifies the external account ID as the `Principal`, which establishes the trust relationship necessary for the external account to request temporary security credentials via AWS STS.

Exam trap

The trap here is that candidates confuse a trust policy (which grants permission to assume a role) with a permissions policy (which defines what actions the role can perform after being assumed), leading them to incorrectly select Option B or C.

How to eliminate wrong answers

Option A is wrong because creating an IAM user in the company's account with cross-account access would require sharing long-term access keys, which violates the principle of least privilege and does not leverage the secure, temporary credential model of role assumption. Option B is wrong because a permissions policy that allows the external account to list roles does not grant the ability to assume a role; listing roles is a read-only operation that provides no mechanism for obtaining temporary credentials or performing actions in the company's account. Option C is wrong because an IAM identity provider is used for federating external identities (e.g., SAML 2.0 or OpenID Connect) from a third-party identity provider, not for granting access to another AWS account's IAM entities; cross-account role access between AWS accounts does not require an identity provider.

773
MCQhard

A company stores sensitive data in Amazon S3 and wants to detect and alert on any public read access to objects. Which combination of services provides the most comprehensive solution?

A.Enable VPC Flow Logs and analyze for S3 traffic
B.Use AWS Config rules to check for public bucket policies and alert via SNS
C.Enable S3 server access logging and use Amazon Athena to query logs, with CloudWatch Events to alert on specific patterns
D.Enable S3 event notifications for all object-level events and send to Amazon SNS
AnswerC

S3 server access logging produces detailed log records containing the requester, bucket name, object key, action string (e.g., REST.GET.OBJECT), and response status for each API call. Querying these logs with Amazon Athena lets you filter for the 'Anonymous' requester and identify specific objects being read publicly. A scheduled Athena query orchestrated via CloudWatch Events (now Amazon EventBridge) can publish findings to SNS or Lambda, enabling alerting on suspicious read patterns.

Why this answer

S3 server access logs capture detailed records of all requests made to a bucket, including the requester, bucket name, request time, action, and response status. By using Amazon Athena to query these logs and CloudWatch Events to trigger alerts on patterns indicating public read access (e.g., a specific HTTP method like GET from an anonymous principal), you can detect and alert on unauthorized public reads comprehensively. This combination provides granular, queryable logging with event-driven alerting, covering both current and historical access patterns.

Exam trap

The trap here is that candidates often confuse S3 event notifications (which only cover write/delete events) with server access logs (which cover all operations including reads), leading them to choose Option D, which cannot detect read access at all.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol) but do not log S3 object-level operations like GetObject; they cannot identify public read access to S3 objects. Option B is wrong because AWS Config rules can check for public bucket policies (e.g., a policy allowing Principal: '*') but cannot detect actual public read access events—they only evaluate static configuration, not runtime access patterns. Option D is wrong because S3 event notifications for object-level events (e.g., s3:ObjectCreated) do not include read events like GetObject; they only trigger on write or delete operations, so they cannot detect public read access.

774
MCQhard

A company uses AWS KMS to encrypt data in Amazon S3. They need to audit all KMS key usage for an S3 bucket. Which AWS service should be used to capture KMS Decrypt API calls?

A.Amazon S3 server access logs
B.Amazon VPC Flow Logs
C.AWS CloudTrail
D.AWS CloudWatch Logs
AnswerC

AWS CloudTrail is the only service listed that natively records the KMS API calls, including the Decrypt operation used when S3 fetches an SSE-KMS-encrypted object. Each KMS event in CloudTrail includes the key ARN, the IAM identity of the caller, the source IP address, and the encryption context, which together provide the complete audit trail required for security investigations. By default, KMS data-plane events like Decrypt are captured in the CloudTrail event history, and you can optionally set up a trail to deliver them to an S3 bucket or CloudWatch Logs for long-term retention.

Why this answer

AWS CloudTrail captures API calls to AWS services, including KMS Decrypt. CloudTrail logs can be delivered to S3 for analysis. Option C is correct.

CloudWatch Logs can receive logs but does not directly capture KMS API calls; S3 server access logs do not include KMS decryption events; VPC Flow Logs capture network traffic, not API calls.

775
MCQhard

A security team wants to grant a Lambda function access to read from a DynamoDB table in the same account. What is the most secure way to do this?

A.Create a VPC endpoint for DynamoDB and associate it with the Lambda function.
B.Attach the AWS managed policy AmazonDynamoDBFullAccess to the Lambda execution role.
C.Store the database access keys in the Lambda environment variables.
D.Create an IAM role with a policy that allows only the required DynamoDB actions (e.g., GetItem, Query) on the specific table and assign it to the Lambda function.
AnswerD

The correct approach is to create a custom IAM role with a policy that grants only the required DynamoDB actions (e.g., GetItem, Query) on the specific table ARN, and then assign that role to the Lambda function as its execution role. At runtime, Lambda uses this role to obtain temporary credentials through AWS STS, which are automatically rotated and scoped to the policy. This follows the principle of least privilege because the function can only perform the exact actions on the exact table it needs, minimizing the blast radius of a compromise. It is the AWS-recommended best practice for granting Lambda functions access to AWS services.

Why this answer

The most secure method is D because it follows the principle of least privilege by creating a custom IAM role that grants only the necessary DynamoDB actions (like GetItem, Query) on the specific table. This limits the Lambda function's permissions to only what is required. Option A is incorrect because a VPC endpoint allows network access to DynamoDB but does not grant IAM permissions; the Lambda function still needs an IAM role with appropriate permissions.

Option B is incorrect because attaching the managed policy AmazonDynamoDBFullAccess grants full access to all DynamoDB resources, violating least privilege and increasing security risk. Option C is incorrect because storing database access keys in Lambda environment variables exposes credentials and is insecure; the recommended approach is to use an IAM execution role.

776
MCQmedium

A company is designing a data protection strategy for its Amazon RDS for PostgreSQL database. The database contains sensitive customer data. Compliance requirements mandate that all backups be encrypted at rest and that the encryption keys be rotated annually. Which solution meets these requirements?

A.Create an encrypted read replica of the RDS instance and use the replica for backups.
B.Use S3 server-side encryption with a customer managed key for automated backups. Configure lifecycle policies to rotate the key.
C.Enable encryption at rest on the RDS instance using an AWS managed KMS key. The key will be rotated automatically every year.
D.Enable encryption at rest on the RDS instance using a customer managed KMS key. Enable automatic key rotation in KMS.
AnswerD

Customer managed KMS keys with automatic rotation satisfy both mandates: RDS backups inherit the instance's encryption at rest, and KMS rotates the key annually. AWS managed keys do not offer customer-controlled rotation, so they fail the compliance requirement.

Why this answer

Enabling encryption at rest on the RDS instance with a customer managed KMS key gives the company control over the key, and enabling automatic key rotation in KMS satisfies the annual rotation requirement. Customer managed keys support automatic rotation (default 365 days), unlike AWS managed keys, which cannot be rotated on a customer-defined schedule.

Exam trap

SCS-C02 often tests the difference between AWS managed and customer managed KMS keys, tempting candidates to pick AWS managed keys when the requirement specifies customer-controlled annual rotation.

How to eliminate wrong answers

Option A is wrong because an encrypted read replica does not encrypt the primary instance's automated backups, and using the replica for backups does not address key rotation. Option B is wrong because RDS automated backups are not stored in S3 under customer control — they are managed by RDS and encrypted with the instance's KMS key; S3 SSE with lifecycle policies does not apply. Option C is wrong because AWS managed KMS keys are rotated automatically every three years (not annually) and cannot be configured for annual rotation by the customer.

777
MCQhard

A security engineer is configuring an IAM role for a Lambda function that must access an Amazon RDS database. The engineer wants the Lambda function to retrieve database credentials from AWS Secrets Manager without hardcoding them. Which combination of IAM permissions and trust policy is required?

A.The role's trust policy must allow lambda.amazonaws.com to assume it, and the role's permissions policy must allow secretsmanager:GetSecretValue on the specific secret ARN.
B.The role's trust policy must allow the Lambda function's IAM user to assume it, and the permissions policy must allow secretsmanager:GetSecretValue.
C.The role's trust policy must allow lambda.amazonaws.com, and the permissions policy must allow secretsmanager:* on all resources.
D.The role's trust policy must allow secretsmanager.amazonaws.com to assume it, and the permissions policy must allow rds:DescribeDBInstances.
AnswerA

Lambda functions assume an execution role via the service principal lambda.amazonaws.com. The trust policy must allow that principal to call sts:AssumeRole. The permissions policy then grants secretsmanager:GetSecretValue on the secret ARN, enabling the function to retrieve credentials securely without embedding them in code. This is the standard, least-privilege approach for Lambda accessing Secrets Manager.

Why this answer

A Lambda execution role requires a trust policy that allows the Lambda service principal to assume it, and a permissions policy that grants the specific Secrets Manager action on the secret ARN. This enables secure, dynamic credential retrieval without hardcoding. Trusting the wrong principal or granting excessive permissions fails the security and functional requirements.

Exam trap

The trap here is confusing the trust policy principal with the permissions policy action, and assuming the service that stores the secret is the one that assumes the role.

778
MCQhard

A company wants to enforce that all S3 buckets are encrypted with SSE-KMS. Which AWS service can be used to automatically remediate non-compliant buckets?

A.AWS CloudTrail with CloudWatch Events
B.AWS Service Catalog
C.AWS Config with auto-remediation
D.AWS Organizations
AnswerC

AWS Config with auto-remediation is the correct choice because it continuously evaluates bucket configuration against a managed rule such as s3-bucket-server-side-encryption-enabled. When a bucket is non-compliant, Config automatically triggers a Systems Manager Automation document, often AWS-EnableS3BucketEncryption, to enable SSE-S3 or SSE-KMS on that bucket. This provides a closed-loop detective-and-remediative workflow that handles both newly created and already-existing unencrypted buckets.

Why this answer

AWS Config with auto-remediation can enforce that all S3 buckets are encrypted with SSE-KMS. You create an AWS Config rule (e.g., s3-bucket-server-side-encryption-enabled) that evaluates bucket encryption settings, and attach an AWS Systems Manager Automation document (e.g., AWS-EnableS3BucketEncryption) as a remediation action. When a non-compliant bucket is detected, AWS Config automatically triggers the remediation action to enable SSE-KMS encryption on that bucket.

Exam trap

The trap here is that candidates may confuse AWS Config's evaluation and remediation capabilities with AWS CloudTrail's logging and event-driven actions, assuming CloudTrail with CloudWatch Events can automatically fix non-compliance without custom code, but AWS Config is the only service that provides native, automated remediation via managed rules and automation documents.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail with CloudWatch Events can detect API calls (like creating an unencrypted bucket) and trigger a notification or a Lambda function, but it does not provide native auto-remediation; you would need custom code to enforce encryption, making it less direct and not an automatic remediation service. Option B is wrong because AWS Service Catalog is used to create and manage a catalog of approved IT services (e.g., pre-configured S3 buckets with SSE-KMS), but it does not monitor or remediate existing non-compliant buckets; it only governs new resources provisioned through the catalog. Option D is wrong because AWS Organizations provides centralized policy management (e.g., Service Control Policies) to restrict actions like creating unencrypted buckets, but it cannot automatically remediate already non-compliant buckets; it only prevents future violations.

779
MCQeasy

A security engineer is configuring a new VPC with public and private subnets. The application servers in the private subnet need to download patches from the internet. Which component is required?

A.VPC endpoint
B.Direct Connect
C.Internet gateway
D.NAT gateway
AnswerD

A NAT gateway is a managed AWS service that enables instances in a private subnet to initiate outbound connections to the internet (e.g., for software updates or API calls) while preventing unsolicited inbound connections. It is deployed in a public subnet with an Elastic IP address, and the private subnet's route table sends non-local traffic to the NAT gateway's network interface. This exactly matches the requirement to provide outbound internet access for private subnet instances without exposing them to inbound traffic.

Why this answer

A NAT gateway is required to allow instances in a private subnet to initiate outbound traffic to the internet (e.g., to download patches) while preventing the internet from initiating inbound connections to those instances. The NAT gateway resides in a public subnet with an attached Internet Gateway, and it translates the private IP addresses of the application servers to the NAT gateway's Elastic IP address for outbound traffic.

Exam trap

The trap here is that candidates often confuse a NAT gateway with an Internet Gateway, mistakenly thinking an Internet Gateway can be attached directly to a private subnet, but an Internet Gateway only works with resources that have public IP addresses, whereas a NAT gateway enables outbound internet access for private instances without public IPs.

How to eliminate wrong answers

Option A is wrong because a VPC endpoint (e.g., Gateway or Interface endpoint) provides private connectivity to AWS services (like S3 or DynamoDB) without traversing the internet, but it does not provide general internet access for downloading patches from arbitrary internet hosts. Option B is wrong because Direct Connect establishes a dedicated private network connection from on-premises to AWS, but it does not inherently provide internet access; it would require additional routing and an internet gateway to reach the public internet. Option C is wrong because an Internet Gateway alone enables bidirectional communication between the VPC and the internet, but it cannot be directly attached to a private subnet; instances in a private subnet without a public IP cannot use an Internet Gateway for outbound-only traffic.

780
MCQhard

A company uses AWS Secrets Manager to rotate secrets for its RDS database. The rotation fails periodically, and the security team needs to troubleshoot. Which CloudWatch metric should be monitored to detect rotation failures?

A.AWS/KMS: KeyUsage
B.AWS/SecretsManager: SecretRotationSucceeded
C.AWS/Lambda: Invocations
D.AWS/RDS: DatabaseConnections
AnswerB

The AWS/SecretsManager namespace provides SecretRotationSucceeded, which is published after each automatic rotation attempt for a secret and increments when the rotation callback completes successfully. The complementary SecretRotationFailed metric reports failures; by using an alarm on SecretRotationSucceeded with a period and statistic appropriate for the rotation schedule, you can detect missed or unsuccessful rotations. Because this metric is emitted by the Secrets Manager service directly from the rotation process, it is the most precise signal for verifying that rotation is working as configured. For example, you can alarm when SecretRotationSucceeded equals zero for the expected rotation interval.

Why this answer

The correct metric to monitor for Secrets Manager rotation failures is `AWS/SecretsManager:SecretRotationSucceeded`. When rotation fails, the `SecretRotationSucceeded` metric reports a value of 0, allowing the security team to set alarms. Option A is incorrect because KMS key usage metrics are not specific to rotation.

Option C is incorrect because Lambda invocations may not capture all rotation failures and are not a direct indicator. Option D is incorrect because RDS metrics do not include Secrets Manager rotation status.

781
MCQeasy

A company has a single AWS account with multiple IAM users. The administrator created an IAM policy that allows all users to launch EC2 instances, but only if they use a specific AMI ID (ami-12345678) and a specific instance type (t3.micro). The policy uses a condition that checks the EC2 instance type and AMI ID. However, a user is able to launch an EC2 instance with a different AMI ID and a larger instance type. The administrator reviews the policy and confirms that the condition is correctly written. What is the most likely reason that the policy is not working as expected?

A.The condition keys used (ec2:InstanceType and ec2:ImageId) are not supported for the RunInstances action in IAM policies.
B.The policy is attached to the user but must also be attached to the IAM group.
C.The policy does not include an explicit deny statement for non-compliant launches.
D.The condition is written incorrectly; it should use StringLike instead of StringEquals.
AnswerC

In IAM, the default behavior is to deny access, but that default is overridden by any applicable allow statement from another policy. This policy only allows RunInstances when the specified condition keys match; it does not explicitly deny RunInstances when the conditions are not met. Consequently, if the user has any other identity-based or resource-based policy that allows RunInstances without conditions, the user can still launch non-compliant instances. An explicit Deny statement using a condition like StringNotEquals (or a NotCondition) would be required to block those non-compliant launches, making the missing deny the root cause.

Why this answer

The most likely reason is that the user has another IAM policy attached (e.g., a managed policy or group policy) that allows ec2:RunInstances without the condition. IAM evaluates all policies; if any allow statement grants the action, the action is permitted unless explicitly denied. The conditional allow only restricts when that specific statement is used, but a separate unconditional allow overrides the condition.

Adding an explicit deny for non-compliant launches would block them regardless of other policies.

Exam trap

Candidates often assume that adding a condition to an allow statement is sufficient to restrict actions, but if another allow statement without the condition exists, the condition is ineffective. An explicit deny is required to override other allows.

How to eliminate wrong answers

Option B is wrong because attaching a policy to an IAM group is not required for it to take effect; policies attached directly to a user are fully evaluated and do not need group attachment to work. Option C is wrong because an explicit deny statement is not needed; IAM policies are deny-by-default, so an allow with a condition that fails results in an implicit deny, but the condition keys are unsupported, so the condition is ignored and the allow applies broadly. Option D is wrong because the condition key issue is not about the operator (StringEquals vs StringLike); even if StringLike were used, the unsupported condition keys would still be ignored, so the policy would still not restrict the launch.

782
MCQhard

A security engineer is designing a solution to protect sensitive data in an Amazon RDS for MySQL database. The data must be encrypted at rest using a key stored in AWS KMS. Additionally, the database must support automated backups and cross-region disaster recovery. Which architecture meets these requirements?

A.Launch an unencrypted RDS instance, then use AWS DMS to replicate data to an encrypted instance in another region.
B.Launch an unencrypted RDS instance, then enable encryption using the AWS Console after creation.
C.Launch an encrypted RDS instance using the default KMS key, then export the database to S3 and copy to another region.
D.Launch an encrypted RDS instance using a customer-managed KMS key. Enable automated backups and create a cross-region read replica.
AnswerD

Launching an encrypted RDS instance with a customer-managed KMS key ensures data at rest is protected by an encryption key you create and control. Enabling automated backups provides point-in-time recovery, while a cross-region read replica serves as a disaster recovery target that can be promoted to a primary database in a regional outage. This combination fully meets the requirements for encryption, availability, and automated recovery.

Why this answer

Launching an encrypted RDS instance with a customer-managed KMS key satisfies the encryption-at-rest requirement with control over key rotation and access. Enabling automated backups ensures point-in-time recovery, and creating a cross-region read replica provides cross-region disaster recovery — all requirements are met in a single architecture.

Exam trap

SCS-C02 often tests the misconception that encryption can be enabled on an existing RDS instance — candidates forget that encryption must be set at creation and can only be applied to a new instance via snapshot restore.

How to eliminate wrong answers

Option A is wrong because it starts with an unencrypted instance, which violates the encryption-at-rest requirement from the outset, and DMS replication adds complexity without addressing encryption of the source. Option B is wrong because RDS does not allow enabling encryption on an existing unencrypted instance after creation — you must restore from a snapshot into a new encrypted instance. Option C is wrong because exporting to S3 and copying to another region is not a supported cross-region DR mechanism for RDS and does not provide automated failover or replication.

783
MCQhard

A company runs a multi-tier web application on AWS. The web tier uses an Application Load Balancer (ALB) in a public subnet, and the application tier runs on EC2 instances in private subnets. The security team recently ran a vulnerability scan and found that the application instances are accessible from the internet on port 8080. The EC2 instances have a security group that allows inbound traffic on port 8080 from the ALB's security group only. However, the ALB's security group allows inbound traffic on port 8080 from 0.0.0.0/0. The architecture also includes a NAT Gateway for outbound internet access from private subnets. The security engineer needs to ensure that only the ALB can communicate with the application instances on port 8080, and that the application instances cannot be directly accessed from the internet. What should the security engineer do?

A.Change the EC2 instance security group to allow inbound traffic on port 8080 from 0.0.0.0/0, and rely on the subnet network ACL to block traffic.
B.Add a rule to the EC2 security group that denies inbound traffic from 0.0.0.0/0 on port 8080.
C.Modify the ALB security group to remove the inbound rule for port 8080 from 0.0.0.0/0, and configure the ALB listener to forward traffic from port 80/443 to port 8080 on the target group.
D.Place the EC2 instances in a public subnet and use a network ACL to block inbound traffic on port 8080 from the internet.
AnswerC

This is the correct solution because it eliminates the unintended public exposure of port 8080 while still enabling the ALB to forward client traffic to the instances on that port. The ALB security group should only permit inbound HTTP/HTTPS on ports 80 and 443, and the ALB listener should be configured with a forward action to the target group on port 8080. Instance security groups should then independently restrict port 8080 to only accept traffic from the ALB security group, preserving a defense-in-depth architecture where instances are not directly internet-reachable.

Why this answer

The ALB security group should only allow inbound traffic on the listener ports (80/443) from the internet, not port 8080. The ALB listener then forwards to the target group on port 8080, and the EC2 security group already restricts 8080 to the ALB's security group. Removing the 0.0.0.0/0 rule on 8080 from the ALB SG closes the exposure while preserving the ALB-to-instance path.

Exam trap

SCS-C02 often tests the misconception that security groups support deny rules or that NACLs can substitute for SG least privilege — candidates must remember SGs are allow-only and that the fix is removing the overly permissive inbound rule, not adding a deny.

How to eliminate wrong answers

Option A is wrong because opening 8080 to 0.0.0.0/0 on the instances and relying on NACLs inverts the security model and exposes instances directly. Option B is wrong because security groups are allow-only — you cannot create explicit deny rules, so a 'deny 0.0.0.0/0' rule is not possible. Option D is wrong because moving instances to a public subnet increases exposure and NACLs are stateless and coarse, not a substitute for SG-based least privilege.

784
MCQmedium

A company needs to audit all changes to IAM policies in its AWS account. Which AWS service should be used to record the change history of IAM policies?

A.Amazon CloudWatch Logs
B.Amazon GuardDuty
C.AWS CloudTrail
D.AWS Config
AnswerC

AWS CloudTrail is the correct choice because it records every management event API call made in your AWS account, including all IAM policy changes such as PutRolePolicy, AttachUserPolicy, DeletePolicy, and CreatePolicy. Each event includes the identity of the caller (user, role, or service), the timestamp, source IP address, request parameters, and response elements, giving you a complete and verifiable audit trail. CloudTrail trails can deliver event logs to an Amazon S3 bucket for long-term retention and optionally to CloudWatch Logs for monitoring. This makes CloudTrail the authoritative service for auditing who changed an IAM policy, when, and what exactly was changed.

Why this answer

AWS CloudTrail is the service that records API activity in an AWS account, including all changes to IAM policies. When an IAM policy is created, modified, or deleted, CloudTrail logs the event with details such as the identity of the caller, the time of the API call, the source IP address, and the request parameters. This makes CloudTrail the authoritative source for auditing IAM policy changes.

Exam trap

SCS-C02 often tests the distinction between AWS Config and CloudTrail: candidates may choose AWS Config because it tracks resource changes, but CloudTrail is specifically for API activity auditing, which includes the 'who, what, when, and where' of IAM policy modifications.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs is a log storage and analysis service; it does not natively record AWS API calls unless CloudTrail or other services deliver logs to it. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes logs (like CloudTrail events) for malicious activity, but it does not provide a raw audit trail of IAM policy changes. Option D is wrong because AWS Config records resource configurations and changes, but it is designed for compliance and configuration history, not for capturing the full API-level audit trail of who made the change and how; CloudTrail is the primary service for API auditing.

785
MCQmedium

A security engineer reviews the trust policy of an IAM role. Which accounts can assume this role?

A.Only the root user of account 123456789012
B.Account 123456789012
C.Any AWS account
D.Account 111111111111
AnswerD

By setting the Principal to "arn:aws:iam::111111111111:root", the trust policy authorizes all IAM users and roles within account 111111111111 to assume the role. This root principal syntax is idiomatic for granting an entire account access, including both current and future IAM principals in that account. The policy does not restrict to a specific user or role, so the correct interpretation is that the whole account is permitted.

Why this answer

The trust policy of the IAM role specifies a principal of "111111111111" as the trusted entity. This means only accounts explicitly listed in the Principal element can assume the role. Since the policy does not include account 123456789012 or allow any AWS account, only account 111111111111 is authorized to assume the role.

Exam trap

The trap here is that candidates often assume the role is in the account that owns the trust policy (e.g., 123456789012) and mistakenly think that account can always assume it, but the trust policy explicitly lists a different account as the trusted entity, so only that account's principals can assume the role.

How to eliminate wrong answers

Option A is wrong because the trust policy does not restrict the principal to the root user of account 123456789012; it specifies account 111111111111, not 123456789012. Option B is wrong because account 123456789012 is not listed in the Principal element of the trust policy, so no IAM users or roles from that account can assume the role. Option C is wrong because the trust policy does not use a wildcard principal like "*" or "AWS": "*", which would allow any AWS account; it explicitly specifies a single account ID.

786
MCQmedium

A company has an AWS Lambda function that needs to access an Amazon RDS database. The database is in a private subnet. Which configuration will allow the Lambda function to securely access the database without traversing the internet?

A.Create a VPC peering connection between the Lambda VPC and the RDS VPC.
B.Place the Lambda function in a public subnet and use a NAT gateway to access the RDS database.
C.Configure the Lambda function to run in the same VPC as the RDS database, in the same private subnet.
D.Use a VPC endpoint for Lambda to connect to the RDS database.
AnswerC

Attaching the Lambda function to the VPC and placing it in the same private subnet as the RDS instance allows the function's elastic network interface to communicate directly with the database over private IP addresses. This satisfies the security group rules—Lambda can use its own security group to allow inbound traffic to RDS on the database port. There is no need for internet access or NAT, and the connection remains within the private network. This is the recommended AWS pattern for Lambda plus RDS in the same VPC.

Why this answer

Placing the Lambda function in the same VPC and the same private subnet as the RDS database allows the Lambda function to communicate with the database directly over the AWS network using private IP addresses. This configuration ensures traffic does not traverse the internet, and it leverages VPC routing and security groups for access control. Lambda functions must be configured with VPC settings to access resources in private subnets, and when both are in the same subnet, no additional gateways or peering are required.

Exam trap

The trap here is that candidates often assume Lambda functions always run inside a VPC by default, but in reality, Lambda runs in an AWS-managed VPC unless explicitly configured with VPC settings, and they mistakenly think VPC endpoints can be used for any AWS service, including RDS, when in fact RDS does not support VPC interface endpoints for database connections.

How to eliminate wrong answers

Option A is wrong because VPC peering connects two separate VPCs, but Lambda functions run within a VPC only when explicitly configured; the default Lambda execution environment is outside any VPC, so peering does not apply unless the Lambda is already in a VPC. Option B is wrong because placing the Lambda function in a public subnet and using a NAT gateway would still route traffic through the internet (via the NAT gateway) to reach the RDS database in a private subnet, which is unnecessary and less secure; direct VPC placement avoids internet traversal. Option D is wrong because VPC endpoints are used for connecting to AWS services like S3 or DynamoDB via PrivateLink, not for connecting to an RDS database; RDS does not support VPC interface endpoints for database connections.

787
MCQeasy

A company uses AWS Systems Manager Session Manager to manage EC2 instances without opening inbound ports. Which IAM policy is required for an EC2 instance to allow Session Manager to connect?

A.AmazonSSMFullAccess
B.AmazonEC2FullAccess
C.AdministratorAccess
D.AmazonSSMManagedInstanceCore
AnswerD

AmazonSSMManagedInstanceCore is the AWS-managed policy specifically designed for EC2 instances that need to be managed through Systems Manager and Session Manager. It includes the required actions such as ssm:UpdateInstanceInformation, ssmmessages:CreateControlChannel, ssmmessages:CreateDataChannel, and s3:GetObject for patch retrieval, while excluding unrelated administrative permissions. Applying this policy to an instance role is the recommended least-privilege approach, ensuring the SSM agent can communicate with the control plane without opening the instance to broader AWS management capabilities.

Why this answer

The AmazonSSMManagedInstanceCore policy grants the minimum permissions required for an EC2 instance to communicate with the Systems Manager service via the SSM Agent, including sending heartbeats, receiving commands, and establishing Session Manager connections. Session Manager does not require inbound ports; it relies on the instance initiating outbound HTTPS connections (port 443) to the SSM endpoints, so the instance needs only the permissions in this managed policy to function as a managed node.

Exam trap

The trap here is that candidates often pick AmazonSSMFullAccess (Option A) because it sounds like it covers all SSM needs, but they fail to distinguish between the permissions needed for the instance role (which only needs to act as a managed node) versus the permissions needed for an administrator user who manages SSM features.

How to eliminate wrong answers

Option A is wrong because AmazonSSMFullAccess is an AWS-managed policy intended for IAM users or roles that need full administrative access to Systems Manager actions (e.g., creating documents, running automations), not for the EC2 instance role; it grants overly broad permissions that are unnecessary and violate least privilege for the instance. Option B is wrong because AmazonEC2FullAccess provides full access to EC2 resources (e.g., launching instances, modifying security groups) but does not include the specific SSM actions (ssm:UpdateInstanceInformation, ssm:SendCommand, etc.) required for the SSM Agent to register and communicate with Session Manager. Option C is wrong because AdministratorAccess grants full access to all AWS services and resources, which is far beyond the principle of least privilege and is never recommended for an EC2 instance role; it would work technically but is a security anti-pattern that the exam expects you to reject in favor of the minimal policy.

788
MCQhard

A company is designing a hybrid cloud architecture with an AWS Direct Connect connection. The company wants to ensure that traffic to and from the VPC goes through the Direct Connect connection and not over the internet. Which configuration should be used?

A.Create a VPC Endpoint for each AWS service.
B.Set up a VPN connection over the internet as a backup.
C.Attach a Virtual Private Gateway to the VPC and update the route tables to point to the Direct Connect virtual interface.
D.Configure the Direct Connect connection and assign public IPs to instances.
AnswerC

Forcing traffic through Direct Connect requires a Virtual Private Gateway (VGW) attached to the VPC and a private virtual interface (VIF) connecting the Direct Connect connection to that VGW. Once the VGW is attached, you update each subnet's route table with a static route pointing to the on-premises CIDR via the VGW, and you must also enable route propagation from the VGW so that routes are advertised. This ensures that any packet bound for the on-premises network is sent to the VGW and then over the Direct Connect private VIF, bypassing the internet entirely.

Why this answer

A Virtual Private Gateway (VGW) is the AWS-side anchor for an AWS Direct Connect private virtual interface (VIF). By attaching the VGW to the VPC and updating the VPC route tables to point the destination CIDR (e.g., the on-premises network) to the Direct Connect VIF, all traffic between the VPC and the on-premises network is forced through the Direct Connect link, bypassing the internet entirely.

Exam trap

The trap here is that candidates often confuse VPC Endpoints (which provide private access to AWS services) with the mechanism needed to route general VPC-to-on-premises traffic through Direct Connect, leading them to select Option A instead of understanding that a VGW and proper route table entries are required.

How to eliminate wrong answers

Option A is wrong because VPC Endpoints allow private access to specific AWS services (e.g., S3, DynamoDB) without traversing the internet, but they do not route general VPC traffic (e.g., to on-premises networks) through Direct Connect; they are service-specific, not a replacement for a VGW. Option B is wrong because a VPN backup over the internet would still allow traffic to potentially egress via the internet if the Direct Connect link fails, and the question explicitly requires traffic to go through Direct Connect, not over the internet; a VPN is a backup path, not a mechanism to enforce Direct Connect usage. Option D is wrong because assigning public IPs to instances would actually encourage traffic to route over the internet (via the IGW), defeating the requirement to keep traffic off the internet; Direct Connect does not require public IPs for private VIF traffic.

789
Multi-Selectmedium

A security engineer is configuring AWS KMS key policies for a customer managed key used to encrypt data in multiple AWS services. The engineer needs to allow the key to be used by principals in the same account and by a specific IAM role in another account for cross-account access. Which two statements should be included in the key policy to meet these requirements? (Choose two.)

Select 2 answers
A.A statement that allows AWS services to use the key on behalf of the account, with a condition that the request comes from the same account.
B.A statement that allows the account root user to have full KMS permissions, enabling IAM policies in the account to delegate access to the key.
C.A statement that allows all principals in the other account to use the key, with a condition that they have the appropriate IAM permissions.
D.A statement that denies all access to the key except for the account root user, to enforce strict control.
E.A statement that allows the specific IAM role in the other account to use the key for cryptographic operations.
AnswersB, E

Including a statement that allows the account root user full KMS permissions is the standard way to enable IAM policies in that account to control access to the key. Without this, IAM policies alone cannot grant access. This statement effectively delegates control to IAM for principals in the same account, which is necessary for same-account access.

Why this answer

For same-account access, the key policy must allow the account root user full KMS permissions so that IAM policies can delegate access. For cross-account access, the key policy must explicitly allow the external IAM role to use the key. The external role also needs an IAM policy allowing the KMS actions.

These two statements together satisfy the requirements.

Exam trap

The trap here is forgetting that cross-account KMS access requires the key policy to explicitly allow the external principal; an IAM policy in the other account alone is insufficient.

790
MCQmedium

A company is using AWS Lambda functions to process sensitive data. The security team wants to detect when a Lambda function is invoked with an unexpected payload that may indicate an injection attack. Which AWS service should the team use to inspect the function's input for malicious patterns?

A.AWS WAF
B.None of the above; the team should implement custom validation within the Lambda function.
C.Amazon Inspector
D.AWS Shield
E.Amazon GuardDuty
AnswerB

Lambda does not include a built-in AWS service that intercepts and validates event payloads for injection attacks such as SQL, OS command, or NoSQL injection. The correct approach is to implement custom input validation and sanitization inside the function code—for example using allowlists, parameterized queries, and parsing libraries—because only the function itself understands the expected schema and context of its event data.

Why this answer

AWS Lambda functions process event payloads directly within the function code, and no AWS managed service can inspect the actual input data passed to a Lambda function at invocation time. AWS WAF operates at the HTTP/HTTPS layer for API Gateway or CloudFront, not for Lambda function payloads. Amazon Inspector scans for software vulnerabilities in EC2 instances and container images, not runtime payloads.

AWS Shield provides DDoS protection at the network and transport layers. Amazon GuardDuty analyzes VPC flow logs, DNS logs, and CloudTrail events for threats, but it does not inspect Lambda function invocation payloads. Therefore, the only way to detect malicious patterns in the function's input is to implement custom validation logic within the Lambda function code itself.

Exam trap

The trap here is that candidates often assume AWS WAF or GuardDuty can inspect all types of data flowing through AWS, but in reality, these services have specific scope limitations and cannot inspect Lambda invocation payloads directly.

How to eliminate wrong answers

Option A is wrong because AWS WAF is a web application firewall that inspects HTTP/HTTPS traffic at the application layer for resources like API Gateway, CloudFront, or ALB, but it cannot inspect the payload passed directly to a Lambda function via SDK, CLI, or other AWS services. Option C is wrong because Amazon Inspector is a vulnerability management service that assesses EC2 instances, container images, and Lambda functions for software vulnerabilities and unintended network exposure, not for inspecting runtime invocation payloads for injection attacks. Option D is wrong because AWS Shield is a managed DDoS protection service that operates at the network and transport layers (Layer 3/4) and does not inspect application-level payloads for malicious patterns.

Option E is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, CloudTrail management events, DNS logs, and EKS audit logs, but it does not have visibility into the actual data payloads passed to Lambda functions during invocation.

791
MCQmedium

A company uses AWS CloudFormation to deploy infrastructure. A security engineer needs to ensure that all CloudFormation stacks use a specific AWS KMS key for encrypting resources that support encryption. Which approach should be used?

A.Use a CloudFormation template that includes the KMS key ID as a hardcoded value.
B.Use a CloudFormation parameter to accept the KMS key ID and validate it with a rule.
C.Use AWS CloudFormation StackSets with a service-managed permission model to deploy stacks from a centrally managed template that includes the KMS key.
D.Use an AWS Organizations service control policy (SCP) to deny all CloudFormation actions unless a specific KMS key is used.
AnswerC

AWS CloudFormation StackSets with a service-managed permission model centralizes template management in the management account, and the StackSets service automatically creates and manages IAM roles in every target account within the AWS Organization, so end users cannot alter the template or the KMS key reference during deployment. Stack instances are deployed with identical configuration, and updates are controlled by the administrator, ensuring the approved KMS key is consistently used across all accounts. This is an enforceable control because the template content is immutable to users in target accounts, and StackSets provides auditable, repeatable deployments through the Organizations integration.

Why this answer

AWS CloudFormation StackSets with a service-managed permission model allow you to deploy a centrally managed template across multiple accounts and regions from a single administrator account. By hardcoding the KMS key ID directly in the template (or referencing a stack-set parameter that is locked down), you enforce that all stack instances use the specified KMS key for encryption-enabled resources, ensuring consistent compliance without relying on individual user input.

Exam trap

The trap here is that candidates often confuse SCPs with resource-level enforcement, not realizing that SCPs cannot evaluate the specific values of CloudFormation template parameters or resource properties, only the API actions themselves.

How to eliminate wrong answers

Option A is wrong because hardcoding the KMS key ID in a CloudFormation template reduces flexibility and security—anyone with access to the template can see the key ID, and it prevents reuse across environments without manual edits. Option B is wrong because a CloudFormation parameter with a validation rule only checks the format or allowed values of the input; it does not enforce that the key is actually used by resources in the stack, and users can still supply a different key ID that passes validation. Option D is wrong because an SCP cannot inspect the specific KMS key ID used within a CloudFormation resource property; SCPs operate at the API action level (e.g., denying `cloudformation:CreateStack`) and cannot conditionally allow actions based on the value of a template parameter or resource property.

792
MCQhard

A security analyst notices an IAM role 'AdminRole' is being assumed from an IP address outside the company's allowed network. The analyst wants to receive real-time alerts when this role is assumed from unauthorized locations. Which combination of services should be used?

A.AWS CloudTrail, Amazon S3, and Amazon Athena
B.AWS Config, Amazon SNS, and AWS Lambda
C.Amazon GuardDuty and AWS Lambda
D.AWS CloudTrail, Amazon CloudWatch Events, and Amazon SNS
AnswerD

This is the correct answer because each service plays a specific role in a real-time alert pipeline: CloudTrail captures the API activity from adminrole, CloudWatch Events (now Amazon EventBridge) applies a custom pattern to match events containing that role's ARN or name and forwards them to SNS, and SNS delivers the notification to subscribers. The integration is event-driven and near-real-time, with no need for polling or querying, which makes it the ideal setup for immediate alerts.

Why this answer

AWS CloudTrail logs IAM role assumption events (sts:AssumeRole) as CloudTrail events, which can be sent to Amazon CloudWatch Events (now Amazon EventBridge) as a real-time event stream. CloudWatch Events rules can then match specific patterns (e.g., source IP outside allowed ranges) and trigger an Amazon SNS notification to alert the security analyst immediately. This combination provides the real-time alerting required without additional polling or storage.

Exam trap

The trap here is that candidates often confuse AWS Config (which evaluates configuration compliance) with CloudTrail (which records API activity), or they assume GuardDuty can be customized for specific role assumption alerts, when in fact GuardDuty does not support custom event pattern matching for individual IAM roles.

How to eliminate wrong answers

Option A is wrong because while CloudTrail logs to S3 and Athena can query those logs, this setup is for historical analysis and batch queries, not real-time alerting. Option B is wrong because AWS Config evaluates resource configuration changes (e.g., IAM policy changes) but does not monitor API call events like sts:AssumeRole from specific IP addresses; it is not designed for real-time event-driven alerting on API activity. Option C is wrong because Amazon GuardDuty detects threats based on DNS, VPC flow logs, and CloudTrail management events, but it does not provide custom real-time alerts for a specific IAM role being assumed from unauthorized IPs; it focuses on broader anomaly detection and requires additional services to trigger custom SNS alerts.

793
MCQmedium

A security engineer is configuring automated response to a GuardDuty finding of type 'UnauthorizedAccess:EC2/SSHBruteForce'. The engineer needs to isolate the compromised instance by modifying the security group to deny all inbound traffic. Which AWS service should be used to orchestrate this response?

A.AWS Lambda
B.AWS CloudFormation
C.AWS Config
D.AWS Systems Manager Automation
AnswerD

Systems Manager Automation is the correct service because it uses automation documents (runbooks) designed specifically to perform operational remediation in a controlled, repeatable way. A runbook can include steps that modify security group rules, stop or isolate EC2 instances, collect diagnostics, or invoke Lambda functions, and it supports IAM roles, approval gates, and rate controls for safe execution. EventBridge rules can trigger these runbooks automatically from security findings, making it the orchestration layer for automated incident response.

Why this answer

AWS Systems Manager Automation is the correct service because it provides a pre-built runbook, AWS-IsolateInstanceEC2, specifically designed to isolate an EC2 instance by modifying its security group to deny all inbound traffic. This runbook can be triggered directly by a CloudWatch Events rule that matches the GuardDuty finding, enabling fully automated incident response without custom code. Systems Manager Automation also supports cross-account and cross-region execution, making it suitable for enterprise-scale response orchestration.

Exam trap

The trap here is that candidates often choose AWS Lambda because they think they need custom code to modify security groups, but AWS Systems Manager Automation provides a pre-built, auditable, and fully managed runbook that eliminates the need for custom code and is the recommended service for orchestrating automated incident response actions.

How to eliminate wrong answers

Option A is wrong because AWS Lambda is a compute service for running custom code, not an orchestration service; while you could write a Lambda function to modify security groups, the question asks for the service to *orchestrate* the response, and Systems Manager Automation provides a managed, auditable runbook without requiring custom code. Option B is wrong because AWS CloudFormation is an infrastructure-as-code service for provisioning resources, not for real-time incident response orchestration; it cannot dynamically react to a GuardDuty finding and execute a security group modification. Option C is wrong because AWS Config is a configuration auditing and compliance service that evaluates resource configurations against rules, but it cannot execute remediation actions like modifying security groups; it can only trigger Lambda or Systems Manager for remediation, not perform the action itself.

794
MCQhard

An organization uses AWS Organizations and wants to restrict the use of specific EC2 instance types across all member accounts. Which policy type should be used to enforce this restriction?

A.Resource-based policy
B.IAM policy
C.Service control policy (SCP)
D.AWS CloudFormation policy
AnswerC

A service control policy (SCP) is a feature of AWS Organizations that you attach to the organization root, an organizational unit (OU), or an individual account to centrally set the maximum permissions available to all principals within those accounts. SCPs do not grant permissions; instead, they act as a permission boundary, and their effects are inherited by all child accounts, making them the only option among these that can consistently restrict services across many accounts at once. For example, you can use an SCP to deny the use of a specific AWS service or the ability to leave the organization, which cannot be accomplished with IAM or resource-based policies alone. This makes the SCP the correct choice for organization-wide service restriction.

Why this answer

Service control policies (SCPs) are the only AWS Organizations policy type that can centrally restrict the maximum available permissions for all accounts in an organization or organizational unit. By attaching an SCP that denies the ec2:RunInstances action for specific instance types (using condition keys like ec2:InstanceType), the organization can enforce the restriction across all member accounts, regardless of their local IAM policies. SCPs do not grant permissions; they only filter them, so they are ideal for guardrails.

Exam trap

The trap is assuming that IAM policies can be used organization-wide or that SCPs grant permissions; candidates must remember that SCPs are guardrails that limit permissions and are the only centralized policy type for multi-account restrictions.

How to eliminate wrong answers

Option A is wrong because resource-based policies are attached to individual resources (e.g., S3 buckets, KMS keys) and cannot enforce organization-wide restrictions on EC2 instance types. Option B is wrong because IAM policies are account-specific and cannot be centrally applied to all accounts in an organization; they also grant permissions rather than restrict them at the organizational level. Option D is wrong because AWS CloudFormation policies do not exist as a policy type; CloudFormation is a service for provisioning resources, not for enforcing permission boundaries.

795
Multi-Selecthard

Which THREE AWS services can be used to detect and alert on suspicious network traffic patterns? (Choose three.)

Select 3 answers
A.AWS Network Firewall
B.Amazon VPC Flow Logs
C.AWS Systems Manager
D.AWS CloudTrail
E.Amazon GuardDuty
AnswersA, B, E

AWS Network Firewall is a managed stateful firewall that performs packet-level inspection on all traffic traversing a VPC using a Suricata-compatible engine. It supports both intrusion detection (IDS) and intrusion prevention (IPS) modes, with managed or custom rule groups that match against packet signatures, domain lists, and port/protocol patterns. When a stateful rule fires, the service can emit alert logs to Amazon S3, CloudWatch Logs, or Kinesis Data Firehose, making it an AWS-native service that directly detects and alerts on suspicious network traffic.

Why this answer

AWS Network Firewall is correct because it is a managed firewall service that can inspect network traffic at the VPC level using stateful and stateless rules. It can detect suspicious patterns such as port scans, malicious IP addresses, or protocol anomalies and generate alerts via Amazon CloudWatch metrics and logs, enabling real-time notification of suspicious network traffic.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (API logging) with network traffic monitoring, or assume AWS Systems Manager has security detection capabilities, when in fact neither service inspects network packet flows or traffic patterns.

796
MCQhard

A company is using Amazon GuardDuty to detect threats. They notice that GuardDuty is generating a high volume of 'UnauthorizedAccess:EC2/SSHBruteForce' findings from an internal EC2 instance that is used for vulnerability scanning. The security team wants to reduce false positives without disabling GuardDuty entirely. What should they do?

A.Change the security group of the vulnerability scanner to block SSH traffic.
B.Disable GuardDuty for the subnet where the vulnerability scanner is located.
C.Disable the 'UnauthorizedAccess:EC2/SSHBruteForce' finding type in GuardDuty.
D.Create a suppression rule for findings originating from the vulnerability scanner's IP address.
AnswerD

Creating a suppression rule that matches the vulnerability scanner's IP address is the correct action because GuardDuty suppression rules automatically archive findings from trusted sources without changing your security posture. The rule can be scoped to the specific IP and finding type (or even the specific scanner instance), preventing future false positives while preserving detection of real SSH brute-force attempts from any other source.

Why this answer

Amazon GuardDuty's suppression rules allow you to filter out findings based on criteria such as IP address, without disabling the detector or any finding types. By creating a suppression rule that matches the vulnerability scanner's IP address, you automatically archive and suppress future 'UnauthorizedAccess:EC2/SSHBruteForce' findings from that specific source, reducing false positives while maintaining full threat detection coverage for all other instances.

Exam trap

The trap here is that candidates often confuse suppression rules with disabling finding types or disabling GuardDuty entirely, not realizing that suppression rules provide a granular, IP-based mechanism to reduce noise without compromising overall security coverage.

How to eliminate wrong answers

Option A is wrong because changing the security group to block SSH traffic would break the vulnerability scanner's functionality, as it needs SSH access to perform its scanning tasks. Option B is wrong because disabling GuardDuty for the subnet would stop all threat detection for every instance in that subnet, not just the scanner, leaving other workloads unprotected. Option C is wrong because disabling the 'UnauthorizedAccess:EC2/SSHBruteForce' finding type globally would suppress all SSH brute force alerts across the entire AWS account, including legitimate threats, which defeats the purpose of targeted false positive reduction.

797
MCQeasy

A developer needs to grant an IAM user temporary access to an S3 bucket for 15 minutes. Which AWS service should be used to generate temporary credentials?

A.AWS Certificate Manager (ACM)
B.AWS Key Management Service (KMS)
C.AWS Security Token Service (STS)
D.AWS Directory Service
AnswerC

AWS Security Token Service (STS) is the service that issues short-lived credentials composed of an access key ID, secret access key, and session token, exactly what an IAM user needs for temporary access. By calling sts:AssumeRole (or GetFederationToken), the developer can request a role's permissions for a configurable duration and receive credentials that expire automatically. This matches the requirement: STS is the correct service for granting temporary access to AWS resources.

Why this answer

AWS Security Token Service (STS) is the service that issues temporary, limited-privilege credentials via APIs like AssumeRole, GetSessionToken, and GetFederationToken. To grant an IAM user temporary access to an S3 bucket for 15 minutes, you call STS AssumeRole (or GetSessionToken) with a DurationSeconds value of 900, and STS returns an access key, secret key, and session token that expire automatically.

Exam trap

SCS-C02 often tests whether candidates confuse key-management services with credential-issuing services; the trap is selecting KMS because it 'manages keys,' when the question is about temporary IAM credentials, which only STS provides.

How to eliminate wrong answers

Option A is wrong because AWS Certificate Manager (ACM) provisions and manages TLS/SSL certificates for HTTPS — it has no role in issuing credentials. Option B is wrong because AWS KMS manages encryption keys for data at rest and does not issue IAM credentials or session tokens. Option D is wrong because AWS Directory Service provides managed Microsoft AD or Simple AD for directory-based identity, not temporary AWS credentials; it can be a source of identities but does not itself mint STS tokens.

798
MCQmedium

A company has an Amazon S3 bucket that stores sensitive data. The security team needs to ensure that all access to the bucket is encrypted in transit. Which condition should be added to the bucket policy?

A.aws:SecureTransport
B.aws:SourceIp
C.s3:x-amz-server-side-encryption
D.aws:UserAgent
AnswerA

The aws:SecureTransport condition key is a global IAM condition that evaluates to true only when the request to S3 was made over HTTPS/TLS. By including it in a bucket policy with a Deny effect, you can reject any HTTP request, thereby enforcing encryption in transit for all S3 API operations. This condition directly addresses the requirement that sensitive data not be transmitted in plaintext.

Why this answer

The `aws:SecureTransport` condition key in an S3 bucket policy enforces that all requests to the bucket must be made over HTTPS (TLS). When set to `false`, any HTTP request is denied, ensuring data is encrypted in transit. This directly addresses the security team's requirement to encrypt all access to the bucket during transmission.

Exam trap

The trap here is that candidates confuse encryption in transit (HTTPS/TLS) with encryption at rest (server-side encryption), leading them to select `s3:x-amz-server-side-encryption` instead of `aws:SecureTransport`.

How to eliminate wrong answers

Option B is wrong because `aws:SourceIp` restricts access based on the requester's IP address, not the encryption of the connection; it does not enforce HTTPS. Option C is wrong because `s3:x-amz-server-side-encryption` controls server-side encryption at rest (e.g., SSE-S3, SSE-KMS), not encryption in transit over the network. Option D is wrong because `aws:UserAgent` filters requests based on the user agent string of the client application, which has no bearing on whether the transport layer is encrypted.

799
Multi-Selectmedium

A security engineer is implementing centralized logging across multiple AWS accounts. Which TWO actions should the engineer take to ensure logs are securely stored and immutable? (Choose TWO.)

Select 2 answers
A.Enable S3 Transfer Acceleration on the bucket
B.Use AWS KMS with a customer managed key for encryption
C.Enable S3 Object Lock on the destination bucket
D.Enable CloudTrail log file validation
E.Enable MFA Delete on the bucket
AnswersB, C

AWS KMS customer managed keys encrypt logs at rest with granular key policies and audit trails via CloudTrail. This satisfies the secure storage constraint by ensuring only authorised principals can decrypt, and key revocation instantly blocks access.

Why this answer

Using AWS KMS with a customer managed key (CMK) for encryption ensures that the security engineer has full control over the encryption keys, including key rotation, access policies, and the ability to disable or revoke the key. This prevents unauthorized decryption of logs, even by AWS, and is a critical component of securing log data at rest. Option C is correct because enabling S3 Object Lock on the destination bucket enforces a write-once-read-many (WORM) model, preventing logs from being deleted or overwritten for a specified retention period, which ensures immutability and compliance with regulatory requirements.

Exam trap

The trap here is that candidates often confuse CloudTrail log file validation (which only detects tampering) with immutability (which prevents tampering), or they mistakenly think MFA Delete provides the same WORM protection as S3 Object Lock.

800
Multi-Selecthard

Which THREE AWS services can be used to authenticate users for accessing AWS resources?

Select 3 answers
A.AWS Single Sign-On
B.Amazon Cognito
C.AWS Secrets Manager
D.AWS Identity and Access Management (IAM)
E.AWS CloudTrail
AnswersA, B, D

AWS Single Sign-On (now AWS IAM Identity Center) authenticates users by acting as a broker between AWS and a trusted external identity provider, such as Okta, Azure AD, or a built-in identity store. It validates the user's credentials through the IdP and then issues temporary AWS credentials or federation tokens, making it a fully functional authentication service for workforce users.

Why this answer

AWS Single Sign-On (SSO) is a service that centrally manages access to multiple AWS accounts and business applications, authenticating users via an external identity provider (IdP) such as Microsoft Active Directory or Okta. It allows users to sign in once and gain federated access to assigned AWS resources, making it a valid authentication service for AWS resource access.

Exam trap

The trap here is that candidates often confuse AWS Secrets Manager as an authentication service because it stores credentials, but it does not authenticate users—it only provides secure storage for secrets that other services use.

801
Multi-Selecteasy

A company is designing a data protection strategy for Amazon S3. Which TWO of the following are valid methods to protect data at rest in S3?

Select 2 answers
A.S3 Versioning
B.S3 bucket policies
C.MFA Delete
D.Server-side encryption with S3-managed keys (SSE-S3)
E.Server-side encryption with AWS KMS (SSE-KMS)
AnswersD, E

SSE-S3 (Server-Side Encryption with S3-Managed Keys) encrypts objects at rest using S3's native AES-256 encryption, where Amazon S3 fully manages the encryption keys on the customer's behalf. When enabled, S3 automatically encrypts all new objects before persisting them and decrypts them on retrieval, with no additional configuration, key management cost, or KMS API usage. It is the simplest and most lightweight way to meet an encryption-at-rest compliance requirement for S3 data.

Why this answer

Options D and E are correct because both are encryption mechanisms that protect S3 object data at rest: SSE-S3 (D) encrypts objects with AES-256 keys fully managed by Amazon S3, while SSE-KMS (E) encrypts objects using keys managed in AWS KMS, giving you control over key policies, rotation, and audit trails via CloudTrail. These directly satisfy the requirement of protecting data at rest in S3. Option A (S3 Versioning) preserves multiple object versions to aid recovery from overwrites or deletions but does not encrypt data.

Option B (S3 bucket policies) is an access-control mechanism governing who can perform actions on the bucket, not encryption at rest. Option C (MFA Delete) adds an authentication requirement for deleting versions or changing versioning state, which is a deletion-protection control rather than data-at-rest encryption.

Exam trap

The trap here is that candidates often confuse data protection features like versioning or access controls (bucket policies, MFA Delete) with encryption mechanisms, assuming they provide data-at-rest protection when they do not.

802
MCQeasy

A company uses AWS CloudTrail to log all API activity. The security team wants to be alerted when an IAM user creates a new access key. They have created a CloudWatch metric filter on the CloudTrail log group for the event name 'CreateAccessKey' and set up a CloudWatch alarm that sends an email via Amazon SNS. However, the alarm is not triggering even though the team knows that access keys have been created. The metric filter has been tested and shows data points in CloudWatch. What should the security team check next?

A.Ensure that the CloudTrail trail is delivering logs to the correct CloudWatch Logs log group.
B.Verify that the CloudTrail trail is logging data events.
C.Review the CloudWatch alarm configuration, including the period and threshold.
D.Check that the IAM user has permissions to create access keys.
AnswerC

Once the metric filter confirms that the CreateAccessKey events are being published to CloudWatch, the alarm logic itself is the next layer to inspect. A period that is too long, a threshold set above the number of events in the window, or an inappropriate statistic (such as Average instead of Sum) can keep the alarm in OK even though events are occurring. Also, the alarm must be configured with a ComparisonOperator and EvaluationPeriods that reflect the expected bursty nature of access-key creation; one event in a five-minute period will never breach a threshold of 1 if the metric is evaluated every minute.

Why this answer

The metric filter is producing data points, which means logs are being ingested and the filter is matching events. The most likely issue is that the CloudWatch alarm's period or threshold is misconfigured—for example, the evaluation period might be too long or the threshold too high, causing the alarm to not transition to ALARM state despite the metric having values. The security team should verify the alarm's settings, such as the period (e.g., 5 minutes) and the threshold (e.g., >= 1), to ensure they align with the expected frequency of access key creation events.

Exam trap

The trap here is that candidates assume the issue must be with log delivery or event type, but the metric filter already shows data points, so the problem lies in the alarm's evaluation configuration—specifically the period and threshold settings that control when the alarm triggers.

How to eliminate wrong answers

Option A is wrong because the metric filter is showing data points, which confirms that the CloudTrail trail is already delivering logs to the correct CloudWatch Logs log group; if it were not, no data points would appear. Option B is wrong because 'CreateAccessKey' is a management event, not a data event, and CloudTrail logs management events by default; data events are for S3 object-level or Lambda function invocations and are irrelevant here. Option D is wrong because the question states that access keys have been created, which means the IAM user already has the necessary permissions; the issue is with the alarm triggering, not with the creation of keys.

803
MCQmedium

A security engineer is designing a VPC with a public subnet and a private subnet. The private subnet will host a database instance that should only be accessible from the application instances in the public subnet. The application instances use an Auto Scaling group. Which configuration ensures that only the application instances can access the database?

A.Allow inbound database port from the security group attached to the application instances in the public subnet.
B.Allow inbound database port from 0.0.0.0/0 in the database security group.
C.Configure a network ACL on the private subnet to allow the database port from the public subnet CIDR.
D.Allow inbound database port from the public subnet CIDR block in the database security group.
AnswerA

Referencing the application instances' security group as the source makes the rule follow the Auto Scaling group automatically, so only those instances can reach the database port. This satisfies the constraint that access be limited to the application tier despite changing instance IPs.

Why this answer

Referencing the application instances' security group as the source in the database security group's inbound rule allows only instances that carry that security group to connect. Because the Auto Scaling group applies the same security group to all instances, this dynamically permits all current and future application instances without hardcoding CIDRs. This is the only option that restricts access to the application instances specifically.

Exam trap

SCS-C02 often tests the misconception that subnet CIDR-based rules are equivalent to security group references — candidates pick the CIDR option, missing that only SG referencing restricts access to the specific instances.

How to eliminate wrong answers

Option B is wrong because allowing 0.0.0.0/0 opens the database to the entire internet, violating the least-privilege requirement. Option C is wrong because network ACLs are stateless and subnet-level; allowing the public subnet CIDR would permit any host in that subnet, not just the application instances, and NACLs cannot reference security groups. Option D is wrong because allowing the public subnet CIDR permits any resource in that subnet — including future unrelated instances — rather than only the application instances identified by their security group.

804
MCQeasy

A company stores data in Amazon S3 and wants to ensure that objects are encrypted at rest. The security team decides to use server-side encryption with AWS KMS (SSE-KMS). Which additional benefit does SSE-KMS provide over SSE-S3?

A.Faster encryption and decryption
B.Lower cost per object
C.Separate permissions for key usage and audit of key usage
D.Stronger encryption algorithm
AnswerC

SSE-KMS integrates with AWS KMS to provide granular IAM and key policies that separate permissions for who can use a key (e.g., kms:Encrypt, kms:Decrypt) from who can administer it (e.g., kms:PutKeyPolicy, kms:ScheduleKeyDeletion). Additionally, every KMS API call is recorded in AWS CloudTrail, enabling robust audit trails of encryption key usage—something SSE-S3 cannot offer because S3 manages the keys entirely behind the scenes. This separation of duties and auditability is essential for many compliance frameworks, making it the correct benefit.

Why this answer

SSE-KMS provides separate permissions for key usage and allows auditing of key usage via AWS CloudTrail. Option A is incorrect because both SSE-S3 and SSE-KMS use the same AES-256 encryption algorithm for encryption and decryption. Option B is incorrect because SSE-KMS incurs additional costs for KMS API calls, making it more expensive per object than SSE-S3.

Option D is incorrect because both options use the same strong encryption algorithm (AES-256).

805
MCQeasy

A company needs to centrally manage access to AWS resources across multiple accounts. Which AWS service should be used to define and enforce a set of common permissions for all accounts in the organization?

A.AWS Directory Service
B.AWS IAM
C.AWS Single Sign-On (SSO)
D.AWS Organizations with SCPs
AnswerD

AWS Organizations with Service Control Policies (SCPs) is the correct mechanism for centrally managing access because SCPs act as organization-wide authorization filters that cap the maximum permissions for every IAM principal—including the root user—in every member account. You can attach SCPs at the root, organizational unit (OU), or account level, and they apply transitively to all child accounts. SCPs do not grant permissions; instead, they explicitly allow or deny API actions, effectively enforcing common compliance guardrails and permission boundaries consistently across the whole organization.

Why this answer

AWS Organizations with Service Control Policies (SCPs) allows you to centrally manage and enforce permissions across all accounts in an organization. SCPs define the maximum permissions for accounts and can be applied to the root, OUs, or individual accounts. Option A (AWS Directory Service) is for managed directory services, not for permissions management.

Option B (IAM) is per-account and does not centrally manage multiple accounts. Option C (AWS SSO) is for federated access, not for enforcing permissions boundaries.

806
MCQhard

A company uses AWS CloudTrail to log API activity. The security team wants to ensure that log files are encrypted at rest and that any tampering with logs is detectable. Which combination of services should be used?

A.Enable CloudTrail and configure S3 bucket to use default encryption and enable S3 server access logs.
B.Enable CloudTrail log file SSE-KMS encryption and enable CloudTrail log file integrity validation.
C.Use AWS CloudHSM to generate keys and encrypt CloudTrail logs at the application layer.
D.Enable CloudTrail log file encryption using SSE-S3 and store logs in CloudWatch Logs.
AnswerB

SSE-KMS encrypts CloudTrail log files with a customer-managed KMS key, giving you explicit control over decryption permissions and key rotation. CloudTrail log file integrity validation then publishes signed digest files containing SHA-256 hashes of each log file, allowing you to cryptographically verify that files were not altered or deleted after delivery. The two features together satisfy confidentiality and tamper detection.

Why this answer

CloudTrail log file integrity validation produces digest files signed with SHA-256 and RSA that let you prove logs were not altered or deleted after delivery, while SSE-KMS encryption protects the log objects at rest with a customer-managed or AWS-managed KMS key. Together they satisfy both the confidentiality and tamper-detection requirements. This is the AWS-documented combination for secure, verifiable CloudTrail log storage.

Exam trap

SCS-C02 often tests the difference between encryption at rest and tamper detection — candidates pick SSE-S3 or access logs thinking they cover integrity, when only CloudTrail's digest-based validation actually proves logs were not modified.

How to eliminate wrong answers

Option A is wrong because S3 default encryption (SSE-S3) does not give you control over the key or audit trail of key usage, and S3 server access logs record bucket access, not tampering with log file contents — they do not provide integrity validation. Option C is wrong because CloudHSM is for dedicated HSM key storage and application-layer encryption; CloudTrail does not support encrypting its logs via CloudHSM at the application layer, and this adds complexity without meeting the integrity requirement. Option D is wrong because SSE-S3 lacks KMS key control and CloudWatch Logs is a separate delivery target that does not provide CloudTrail's digest-based integrity validation.

807
MCQeasy

A company needs to encrypt data at rest in Amazon EBS volumes. They want to use an AWS managed key that is automatically rotated. Which encryption option should they choose?

A.Use SSE-S3.
B.Enable EBS encryption by default using the AWS managed key for Amazon EBS.
C.Use a customer-managed KMS key with automatic rotation enabled.
D.Use client-side encryption.
AnswerB

Enable EBS encryption by default establishes that every newly created EBS volume and snapshot is encrypted with the volume's key—the AWS managed key with alias aws/ebs—without requiring per-volume configuration. Because this is an AWS managed key, AWS rotates it automatically and handles the key material, so the company does not need to manage lifecycle or permissions. This satisfies the requirement to encrypt data at rest in the EBS volume directly at the block-storage layer.

Why this answer

Enabling EBS encryption by default using the AWS managed key for Amazon EBS (alias `aws/ebs`) ensures data at rest is encrypted with a key that is automatically rotated on an annual basis, as required. This key is managed by AWS and requires no manual intervention for rotation, meeting the company's need for a managed, automatically rotated key.

Exam trap

The trap here is that candidates often confuse 'AWS managed key' with 'customer-managed KMS key with automatic rotation enabled,' but the key distinction is that a customer-managed key is not an AWS managed key—it is managed by the customer, even if rotation is automated.

How to eliminate wrong answers

Option A is wrong because SSE-S3 is an encryption option for Amazon S3, not for Amazon EBS volumes; it uses S3-managed keys and is irrelevant to EBS encryption. Option C is wrong because while a customer-managed KMS key can have automatic rotation enabled, it is not an AWS managed key—it is customer-managed, meaning the customer retains control and responsibility, which does not satisfy the requirement for an AWS managed key. Option D is wrong because client-side encryption occurs before data reaches AWS and does not use an AWS managed key; it requires the customer to manage encryption keys locally, contradicting the need for an AWS managed, automatically rotated key.

808
Multi-Selectmedium

A security engineer is configuring logging for an application running on Amazon EC2 instances. The engineer needs to capture both operating system-level logs and application logs. Which TWO services can be used together to achieve this? (Choose two.)

Select 2 answers
A.AWS CloudTrail
B.VPC Flow Logs
C.Amazon CloudWatch Logs
D.Amazon CloudWatch agent
E.Amazon Inspector
AnswersC, D

Amazon CloudWatch Logs is the managed destination where log data is stored, monitored, and queried; it centralizes log events from EC2, Lambda, and on-premises sources into log groups and log streams. When the CloudWatch agent publishes log records to this service, you can search them with Logs Insights, alarm on error patterns, and export them to S3 for long-term retention.

Why this answer

Amazon CloudWatch Logs is the correct service because it provides a centralized location to store, monitor, and access log files from your EC2 instances. The Amazon CloudWatch agent is the correct companion service because it is specifically designed to collect both operating system-level logs (e.g., syslog, Windows Event Log) and application logs from EC2 instances and send them to CloudWatch Logs. Together, they fulfill the requirement of capturing both OS and application logs.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which logs AWS API calls) with the CloudWatch agent (which collects OS and application logs), leading them to select CloudTrail instead of the CloudWatch agent for internal instance logging.

809
MCQmedium

A security team needs to analyze historical CloudTrail logs across multiple AWS accounts to detect patterns of suspicious activity. Which solution provides the MOST cost-effective and scalable analysis?

A.Aggregate logs into a central S3 bucket and query with Amazon Athena
B.Stream logs to Amazon Elasticsearch Service and use Kibana
C.Load logs into Amazon Redshift for analysis
D.Use Amazon CloudWatch Logs Insights across all accounts
AnswerA

Centralizing CloudTrail logs in a single S3 bucket is the AWS-recommended architecture for historical analysis. Amazon Athena uses serverless Presto/Trino to run SQL directly over S3 objects, charging only for bytes scanned, which is cost-effective for infrequent deep queries. Partitioning the data by date and converting to columnar formats like Parquet further reduces scan costs and speeds up analysis. This approach avoids provisioning any compute, making it the natural fit for auditing historical events across accounts.

Why this answer

Aggregating CloudTrail logs into a central S3 bucket and querying with Amazon Athena is the most cost-effective and scalable solution because Athena uses a serverless, pay-per-query model with no infrastructure to manage, and it can directly analyze large volumes of structured log data stored in S3 using standard SQL. This approach avoids the cost of provisioning and maintaining dedicated clusters (as with Redshift or Elasticsearch) and avoids the per-GB ingestion and storage fees of CloudWatch Logs Insights, making it ideal for historical analysis across multiple accounts.

Exam trap

The trap here is that candidates often choose CloudWatch Logs Insights (Option D) because it seems convenient for log analysis, but they overlook its high ingestion costs and limited retention for historical data, whereas Athena's serverless, pay-per-query model is far more cost-effective for large-scale, infrequent queries of archived logs.

How to eliminate wrong answers

Option B is wrong because streaming logs to Amazon Elasticsearch Service (now OpenSearch Service) incurs ongoing costs for cluster instances, storage, and data ingestion, and it is not as cost-effective for infrequent historical queries compared to Athena's pay-per-query model. Option C is wrong because loading logs into Amazon Redshift requires provisioning a cluster, paying for compute and storage even when idle, and involves ETL overhead, making it overkill and more expensive for ad-hoc analysis of CloudTrail logs. Option D is wrong because Amazon CloudWatch Logs Insights is designed for real-time log analysis and has a per-GB ingestion cost and a limited query history retention (typically 30 days), making it unsuitable and costly for analyzing long-term historical logs across multiple accounts.

810
MCQhard

A security team notices that an IAM user has permissions to launch EC2 instances but should not have access to certain instance types. Which IAM policy condition key should be used to restrict this?

A.ec2:ResourceTag
B.ec2:Tenancy
C.ec2:InstanceProfile
D.ec2:InstanceType
AnswerD

ec2:InstanceType is the IAM condition key specifically intended for restricting the type of EC2 instance a principal can launch, and it can be used with the ec2:RunInstances action. By applying, for example, a StringLike condition of "t3.*" or "t3.micro", an administrator can deny all other instance families and sizes. This key is evaluated as a request-level condition during the RunInstances call, so it directly matches the requirement to control which instance type a user is allowed to create.

Why this answer

The ec2:InstanceType condition key allows you to restrict IAM users to launching only specific EC2 instance types (e.g., t2.micro, m5.large) by evaluating the instance type value in the RunInstances API call. This is the correct key to enforce a policy that denies access to certain instance types while permitting others.

Exam trap

The trap here is that candidates often confuse ec2:InstanceType with ec2:ResourceTag, thinking they can use tags to restrict instance types, but tags are applied after launch and cannot be used to block the initial API call based on instance type.

How to eliminate wrong answers

Option A is wrong because ec2:ResourceTag is used to control access based on tags attached to EC2 resources, not to restrict instance types. Option B is wrong because ec2:Tenancy controls whether instances can be launched on shared or dedicated hardware (e.g., default vs. dedicated tenancy), not the instance type. Option C is wrong because ec2:InstanceProfile is used to restrict which IAM roles (instance profiles) can be associated with an EC2 instance, not the instance type itself.

811
MCQhard

A security team notices that an S3 bucket containing sensitive data has been repeatedly accessed from an IP address outside the company's network. They need to set up a real-time alert when such access occurs. Which combination of services should they use?

A.VPC Flow Logs and Amazon QuickSight
B.AWS Config and Amazon SNS
C.CloudWatch Logs Insights and Amazon SES
D.Amazon GuardDuty and Amazon EventBridge
AnswerD

Amazon GuardDuty is a threat-detection service that continuously analyzes S3 data-plane events from CloudTrail, using anomaly detection and threat intelligence to identify patterns like unusual object access or credential abuse. When a finding is generated, GuardDuty emits it as an event to the default event bus, where Amazon EventBridge rules can filter on severity or finding type and trigger Lambda, SNS, or other targets for immediate alerting. This pair combines detection and event-driven response, making it the appropriate real-time security monitoring solution for the sensitive S3 bucket.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity, including unusual API calls and unauthorized access patterns from external IPs. When GuardDuty detects such access to an S3 bucket, it can generate findings that are sent to Amazon EventBridge, which then triggers a real-time alert (e.g., via SNS or Lambda). This combination provides immediate, automated notification of the suspicious access without requiring custom log parsing.

Exam trap

The trap here is that candidates often confuse AWS Config (which monitors configuration drift) with GuardDuty (which monitors actual access events), or they assume CloudWatch Logs Insights can provide real-time alerts when it is actually a query-based analysis tool with no native push alerting.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata at the VPC level, not S3 data plane API calls, and Amazon QuickSight is a business intelligence tool for visualization, not real-time alerting. Option B is wrong because AWS Config tracks resource configuration changes and compliance, not real-time data access events; Amazon SNS can send notifications but requires a proper event source, and Config rules are not designed for per-request S3 access monitoring. Option C is wrong because CloudWatch Logs Insights is a query tool for analyzing log data, not a real-time alerting mechanism, and Amazon SES is an email sending service that cannot directly ingest or process S3 access logs for alerting.

812
MCQhard

An IAM policy allows a user to pass a specific role and launch EC2 instances. The user tries to launch an EC2 instance with the role 'ec2-full-access' but receives an error: 'You are not authorized to perform iam:PassRole'. What is the MOST likely cause?

A.The role 'ec2-full-access' does not exist in the account
B.The user is attempting to pass a role with an ARN that does not exactly match the one in the policy
C.The policy is missing a condition key such as ec2:InstanceProfile
D.The user does not have permission to call ec2:RunInstances
AnswerB

The iam:PassRole error occurs because the role ARN in the request does not exactly match the Resource element in the policy. IAM evaluates ARNs literally, so any mismatch in account, path, or role name denies the action despite the Allow.

Why this answer

The error 'You are not authorized to perform iam:PassRole' indicates that the iam:PassRole permission is being denied. In IAM policies, the Resource element for iam:PassRole must specify the exact ARN of the role that can be passed. If the user attempts to pass a role whose ARN does not exactly match the ARN in the policy (e.g., due to a different path, account ID, or role name), the PassRole action is not allowed, resulting in this error.

Therefore, the most likely cause is that the role ARN being passed does not match the ARN specified in the policy.

Exam trap

SCS-C02 often tests the misconception that iam:PassRole permission is granted based on role name alone, but the exam expects you to know that the exact ARN, including path and account ID, must match the policy's Resource element.

How to eliminate wrong answers

Option A is wrong because if the role did not exist, the error would typically be 'The role with name ec2-full-access cannot be found' or similar, not an authorization error for iam:PassRole. Option C is wrong because condition keys like ec2:InstanceProfile are used to restrict which instance profiles can be passed, but the absence of such a condition does not cause an authorization failure; it would only make the policy less restrictive. Option D is wrong because the error explicitly mentions iam:PassRole, not ec2:RunInstances; if the user lacked RunInstances permission, the error would be 'You are not authorized to perform ec2:RunInstances'.

813
MCQhard

Refer to the exhibit. A security engineer is reviewing the CloudWatch Logs configuration for a Lambda function. The log group is encrypted with a customer managed key. The engineer needs to ensure that only the Lambda service can write logs to this log group and that only a specific IAM role can read logs. Which additional configuration is required?

A.Attach a resource-based policy to the log group that allows only the Lambda service to write logs
B.Create an S3 bucket policy to allow only Lambda to write to the log group
C.Assign an IAM role to the log group that has permission to write logs
D.Add a condition to the KMS key policy that uses kms:ViaService to restrict encryption/decryption to logs.amazonaws.com and a condition that the Lambda function is the source
AnswerD

This is correct because the KMS key policy is the authoritative control for who can use the customer-managed key, and CloudWatch Logs calls KMS on behalf of the Lambda function when encrypting/decrypting log data. Adding a statement with Principal as logs.amazonaws.com and a condition using kms:ViaService logs.<region>.amazonaws.com restricts the key's use to calls that come through the CloudWatch Logs service endpoint. To ensure the request is tied to the specific Lambda function, you would also include a condition such as aws:SourceArn matching the Lambda function ARN or an EncryptionContext condition on the log group ARN, so the key cannot be used for unrelated log groups or services.

Why this answer

To ensure only the Lambda service can write logs and only a specific IAM role can read logs, you need to use KMS key policy conditions. The key policy should include a condition that allows CloudWatch Logs to use the key for encryption/decryption only when the request originates from the Lambda service (using kms:ViaService condition). Additionally, you can restrict read access by specifying the IAM role in the key policy.

Option A is incorrect because resource-based policies on log groups cannot restrict write access to Lambda only; they are typically used for cross-account access. Option B is incorrect because S3 bucket policies are not applicable to CloudWatch Logs. Option C is incorrect because you cannot assign an IAM role to a log group; IAM roles are assumed by entities, not assigned to resources.

814
MCQmedium

A security engineer manages a VPC with a fleet of Amazon EC2 instances running behind an Application Load Balancer. The engineer needs to capture, in near real time, metadata about all IP traffic entering and leaving the network interfaces in the VPC, including source and destination IP, ports, and protocol, and then store the records in Amazon S3 for later analysis. Which solution meets these requirements with the LEAST operational overhead?

A.Install the CloudWatch agent on each EC2 instance and configure it to collect network traffic metrics and send them to CloudWatch Logs.
B.Enable VPC Flow Logs at the VPC level with a destination of Amazon S3 and the default format.
C.Deploy a third-party network monitoring appliance on an EC2 instance and mirror all VPC traffic to it using AWS PrivateLink.
D.Enable AWS CloudTrail data events on the network interfaces and deliver the logs to Amazon S3.
AnswerB

VPC Flow Logs capture IP traffic metadata for network interfaces in a VPC, including source/destination IP, ports, and protocol. Publishing directly to Amazon S3 requires no agent installation or additional pipeline, making it the lowest-overhead solution. The default format already includes the required fields, and flow logs can be created at the VPC, subnet, or ENI level.

Why this answer

VPC Flow Logs are the native AWS feature for capturing IP traffic metadata for network interfaces in a VPC. Publishing directly to Amazon S3 avoids the need for agents or custom pipelines and provides the required fields in the default format. The other options either capture the wrong type of data or introduce unnecessary complexity.

Exam trap

The trap here is assuming that CloudTrail or the CloudWatch agent can capture network traffic metadata, when only VPC Flow Logs provide that specific IP-level detail.

815
MCQhard

A company has an AWS account with a single VPC and multiple subnets. The security team wants to ensure that no network ACL (NACL) allows inbound SSH (port 22) from 0.0.0.0/0. Which AWS service can be used to detect and alert on such non-compliant NACLs?

A.Amazon Inspector
B.Amazon GuardDuty
C.AWS Config
D.AWS CloudTrail
AnswerC

AWS Config continuously records the configuration of supported resources, including Network ACLs and their inbound/outbound rules, as configuration items in a timeline. It then evaluates those config items against managed rules—such as the managed rule 'incoming-ssh-disabled'—or custom Lambda rules that can inspect each NACL entry and mark any ingress rule allowing 0.0.0.0/0 on port 22 as non-compliant. When non-compliance is detected, AWS Config can trigger an Amazon SNS notification for immediate alerting, and it retains a compliance history for auditing, which is exactly what the company needs.

Why this answer

AWS Config continuously records resource configurations and evaluates them against rules, making it the correct service to detect non-compliant NACLs. You can use the managed rule 'nacl-no-unrestricted-ssh-rdp' (or a custom rule) to flag any NACL that allows inbound SSH from 0.0.0.0/0 and trigger alerts via Amazon EventBridge or SNS. This directly addresses the requirement to detect and alert on non-compliant NACLs.

Exam trap

SCS-C02 often tests the distinction between detection services (GuardDuty for threats, Inspector for vulnerabilities) and compliance evaluation services (Config for configuration rules), tempting candidates to pick GuardDuty for configuration issues.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances, container images, and Lambda functions for software vulnerabilities and unintended network exposure — it does not evaluate NACL configuration rules. Option B is wrong because GuardDuty is a threat detection service that analyzes logs (CloudTrail, VPC Flow Logs, DNS) for malicious activity; it does not assess NACL compliance. Option D is wrong because CloudTrail records API activity and changes but does not evaluate whether configurations comply with a policy — it provides the audit trail, not the compliance check.

816
MCQmedium

A company uses AWS Systems Manager Session Manager to manage EC2 instances. The security team wants to ensure that all SSH sessions are logged and that commands are recorded. What should be configured?

A.Enable session logging in the Session Manager preferences to send logs to Amazon S3 and CloudWatch Logs
B.Configure the security group to allow inbound SSH from the Session Manager service
C.Enable AWS CloudTrail to log Systems Manager API calls
D.Create an IAM policy that allows ssm:StartSession and attach it to the instance role
AnswerA

Enabling session logging in Session Manager preferences is the correct approach because it captures the actual interactive session stream—every keystroke, command, and output—and delivers it to centralized destinations such as Amazon S3 and CloudWatch Logs. This configuration is applied at the Systems Manager account level and can enforce audit trails for all sessions, including the ability to search and alert on command history. Without this, there is no native way to retroactively review the commands executed inside a session, making it essential for compliance and forensic requirements.

Why this answer

Session Manager preferences allow logging session activity to Amazon S3 and CloudWatch Logs, which records all commands run during SSH sessions. Option B is incorrect because security groups control network access, not logging. Option C is incorrect because CloudTrail logs API calls to Systems Manager, not the commands executed within a session.

Option D is incorrect because an IAM policy only controls permissions to start sessions, not the logging of session activity.

817
Multi-Selecthard

Which THREE factors should be considered when designing IAM policies for cross-account access? (Choose three.)

Select 3 answers
A.The resource-based policy must allow the external account
B.Permission boundaries must be used
C.The AWS account ID must be specified in the policy
D.The IAM policy in the external account must allow the action
E.Service control policies (SCPs) must allow the action
AnswersA, C, D

For cross-account access, the resource owner must explicitly grant the external account or its principal access in the resource-based policy. This policy defines the trust relationship because it specifies who can access the resource and what actions they can perform. Without this allow, the request fails even if the caller has valid IAM permissions in their own account.

Why this answer

For cross-account access using resource-based policies (e.g., S3 bucket policies, KMS key policies), the resource-based policy must explicitly grant access to the external AWS account. This allows the external account's IAM principals to access the resource, provided the external account's IAM policy also permits the action. Without this allowance in the resource-based policy, the external account cannot access the resource, even if its own IAM policies allow it.

Exam trap

The SCS-C02 exam often tests the misconception that only one policy (either resource-based or identity-based) is sufficient for cross-account access, but in reality both the resource-based policy and the external account's IAM policy must allow the action.

818
MCQhard

A company uses AWS Organizations and wants to restrict the use of specific AWS services in member accounts. For example, they want to block the use of Amazon Redshift. Which policy type should be used?

A.Service control policies (SCPs)
B.IAM permissions boundaries
C.IAM identity-based policies
D.S3 bucket policies
AnswerA

Service control policies (SCPs) are the correct mechanism because AWS Organizations lets you attach them to the root, OUs, or individual accounts, where they act as an account-wide permission guardrail. An SCP defines the maximum allowed actions for every IAM principal in the account, including the root user, so it can deny entire AWS services across all enrolled accounts. This central, inherited control does not require touching each IAM role or user individually.

Why this answer

Service control policies (SCPs) are used in AWS Organizations to centrally manage permissions across multiple accounts. They can restrict which AWS services and actions are available to member accounts. To block the use of Amazon Redshift in member accounts, an SCP can be applied to the organizational units or accounts that denies the redshift:* actions.

Exam trap

The trap is confusing SCPs with IAM policies; SCPs are specifically for Organizations and apply across accounts, while IAM policies are within a single account.

How to eliminate wrong answers

Option B is wrong because IAM permissions boundaries are used to set the maximum permissions for an IAM entity, but they do not apply across accounts and are not used for service-level restrictions in Organizations. Option C is wrong because IAM identity-based policies are attached to IAM users, groups, or roles and grant permissions within a single account; they cannot be used to restrict services across multiple accounts in an organization. Option D is wrong because S3 bucket policies are resource-based policies that apply only to S3 buckets and cannot block the use of Amazon Redshift.

819
MCQeasy

A company needs to grant cross-account access to an S3 bucket in Account A to users in Account B. What is the recommended approach?

A.Attach an IAM role to Account B's users.
B.Add a bucket policy in Account A that grants access to the IAM user ARNs from Account B.
C.Make the bucket public.
D.Create an IAM user in Account A and share the credentials with Account B users.
AnswerB

A bucket policy in Account A can specify the Amazon Resource Names (ARNs) of IAM users from Account B in the Principal element, granting them explicit actions such as s3:GetObject on the bucket and its objects. For this to work, those IAM users also need an identity-based policy in Account B that allows the corresponding S3 actions, but the bucket policy is what authorizes the cross-account access at the resource level. This approach is precise, auditable, and follows least privilege because only the named IAM users get access, not any broader principal.

Why this answer

A bucket policy in Account A can explicitly grant cross-account access to IAM user ARNs from Account B. This is the recommended approach for granting access to an S3 bucket across AWS accounts, as it avoids managing additional IAM users or roles and leverages the resource-based policy directly on the bucket. The bucket policy must specify the `Principal` element with the AWS account ID of Account B and the `Action` and `Resource` for the S3 operations, allowing Account B's IAM users to access the bucket after they have appropriate permissions in their own account.

Exam trap

The trap here is that candidates often confuse resource-based policies (bucket policies) with identity-based policies (IAM policies) and incorrectly think that a bucket policy cannot grant access to users in another account, or they mistakenly believe that an IAM role must be created in the target account for cross-account access.

How to eliminate wrong answers

Option A is wrong because attaching an IAM role to Account B's users is not a valid operation; IAM roles are attached to AWS resources or assumed by users, not directly attached to users in another account. The correct approach would be for Account B's users to assume a cross-account role, but that requires a role in Account A with a trust policy, not attaching a role to users. Option C is wrong because making the bucket public grants access to anyone on the internet, which violates the principle of least privilege and is not a secure cross-account access method.

Option D is wrong because creating an IAM user in Account A and sharing credentials with Account B users introduces security risks (e.g., credential leakage, lack of audit trail) and is not a scalable or recommended practice for cross-account access.

820
MCQhard

A security engineer runs the CLI command above to investigate a console login event. The output shows: {"type":"Root","principalId":"123456789012","arn":"arn:aws:iam::123456789012:root"}. What does this indicate?

A.A federated user performed the console login.
B.An AWS service performed the console login.
C.An IAM user in the account performed the console login.
D.The AWS account root user performed the console login.
AnswerD

The root user is the only IAM principal that CloudTrail identifies with userIdentity.type equal to Root, and its ARN is always arn:aws:iam::123456789012:root with no session context or userName. The presence of a login event with this type proves the AWS account root user directly authenticated using the account's email and password (plus any MFA), bypassing any identity provider or IAM role. This is exactly what the CloudTrail event indicates.

Why this answer

The output shows `"type":"Root"` and `"arn":"arn:aws:iam::123456789012:root"`, which are the exact identifiers AWS CloudTrail uses to record an action performed by the AWS account root user. The root user is the account owner with full administrative access, and its principal ARN always ends with `:root`. This confirms that the console login was performed by the root user, not by any other identity.

Exam trap

The trap here is that candidates may confuse the `:root` suffix in the ARN with an IAM user named 'root', but AWS reserves the `:root` ARN exclusively for the account root user, and any IAM user would have a distinct ARN with a username after `:user/`.

How to eliminate wrong answers

Option A is wrong because a federated user would have a `type` of `FederatedUser` or `AssumedRole` in the CloudTrail event, not `Root`. Option B is wrong because an AWS service performs actions using an IAM role or service-linked role, which would appear with a `type` of `AssumedRole` or `AWSAccount`, not `Root`. Option C is wrong because an IAM user would have a `type` of `IAMUser` and an ARN like `arn:aws:iam::123456789012:user/username`, not `arn:aws:iam::123456789012:root`.

821
MCQhard

A security engineer is designing a network segmentation strategy for a VPC that hosts sensitive data. The engineer needs to ensure that EC2 instances in a private subnet can communicate with an RDS database in a different private subnet, but cannot communicate with any other resources in the same VPC. Which configuration should be used?

A.Create a VPC peering connection between the subnets.
B.Configure security groups for the EC2 instances that only allow outbound traffic to the RDS security group, and RDS security group allows inbound from the EC2 security group.
C.Assign the same security group to both the EC2 instances and the RDS database.
D.Use network ACLs with deny rules for all traffic except between the two subnets.
AnswerB

Security groups act as stateful, instance-level firewalls, and AWS allows one security group to reference another as a source or destination in its rules. By configuring the EC2 security group's outbound rule to destination the RDS security group, and the RDS security group's inbound rule to source the EC2 security group, the two sets of instances can communicate only with each other, without hard-coding IP addresses. Because security groups default to deny-all and automatically allow return traffic, this pattern creates a minimal-privilege channel between the application tier and the database tier, and it self-maintains when instances are replaced or auto-scaled since the rule references the group, not individual instance IPs.

Why this answer

Security groups act as a virtual firewall at the instance level, allowing stateful traffic filtering. By configuring the EC2 security group to allow outbound traffic only to the RDS security group (using the security group ID as the destination), and the RDS security group to allow inbound traffic only from the EC2 security group, you create a precise, bidirectional allowlist. This ensures that EC2 instances can communicate exclusively with the RDS database, blocking all other traffic within the VPC without relying on IP addresses or subnet CIDRs.

Exam trap

The trap here is that candidates often confuse security groups with network ACLs or assume that VPC peering or shared security groups are sufficient for fine-grained segmentation, overlooking that security group referencing provides the precise, resource-level isolation required for this scenario.

How to eliminate wrong answers

Option A is wrong because VPC peering connects entire VPCs, not subnets, and would allow all traffic between the peered VPCs, not restrict communication to specific resources. Option C is wrong because assigning the same security group to both EC2 and RDS would allow all traffic between any instances using that group, including unintended communication between multiple EC2 instances or other resources, violating the requirement to restrict communication solely to the EC2-RDS pair. Option D is wrong because network ACLs are stateless and operate at the subnet level, requiring explicit allow rules for both inbound and outbound traffic; using deny rules for all traffic except between the two subnets would be complex, error-prone, and still allow any instance in those subnets to communicate, not just the specific EC2 and RDS instances.

822
Multi-Selecteasy

Which TWO services can be used to manage identity and access across multiple AWS accounts? (Choose TWO.)

Select 2 answers
A.Amazon Cognito
B.AWS Organizations
C.AWS Single Sign-On (SSO)
D.AWS Config
E.AWS CloudTrail
AnswersB, C

AWS Organizations is a governance service that lets you centrally manage multiple AWS accounts by organizing them into organizational units and applying service control policies (SCPs). SCPs define the maximum allowed permissions for every IAM principal in an account, effectively managing identity and access by creating guardrails at the organization level. This makes Organizations a correct service for managing identity and access across accounts.

Why this answer

AWS Organizations (B) is correct because it centrally manages multiple AWS accounts under a single organization, enabling consolidated billing and centralized policy-based governance through Service Control Policies (SCPs) that control access across all member accounts. AWS Single Sign-On (C) is correct because it provides centralized identity and access management across multiple AWS accounts, letting users sign in once with their existing corporate credentials and access assigned accounts and roles via permission sets. Amazon Cognito (A) is incorrect because it is a customer-facing identity service for web and mobile applications (user pools and identity pools), not for managing access across AWS accounts.

AWS Config (D) is incorrect because it is a configuration compliance and auditing service that records resource changes, not an identity and access management service. AWS CloudTrail (E) is incorrect because it logs API activity and account events for auditing, not identity or access management.

Exam trap

SCS-C02 often tests the distinction between services that manage identities and access versus those that monitor or audit, so candidates may incorrectly select AWS Config or CloudTrail for identity management.

823
MCQmedium

A company uses IAM roles for EC2 instances to access S3. A security audit reveals that some instances have roles with overly permissive policies. What is the BEST practice to scope down permissions while maintaining functionality?

A.Use S3 bucket policies instead of IAM policies
B.Attach the AdministratorAccess policy to the role and use S3 conditions
C.Create custom IAM policies that grant only the necessary S3 actions on specific buckets
D.Create a new instance profile with a more restrictive permissions boundary
AnswerC

A custom IAM policy should be scoped to the exact S3 actions the application requires, such as s3:GetObject and s3:PutObject, and limited to the specific bucket ARNs and optional prefixes. When attached to the instance role, this policy ensures the temporary credentials issued to the EC2 instance can perform only the intended S3 operations, aligning with the least-privilege principle. This is the standard and recommended way to control S3 access for EC2 roles.

Why this answer

The best practice to scope down permissions while maintaining functionality is to create custom IAM policies that grant only the necessary S3 actions on specific buckets. This follows the principle of least privilege, ensuring that the EC2 instances have exactly the permissions they need to perform their tasks, and no more. This approach is more granular and secure than using broader policies or alternative methods.

Exam trap

SCS-C02 often tests the misconception that permissions boundaries alone can restrict permissions; they only limit, but you still need to attach appropriate policies. Also, candidates might think bucket policies can replace IAM policies, but they serve different purposes.

How to eliminate wrong answers

Option A is wrong because using S3 bucket policies instead of IAM policies does not scope down the IAM role's permissions; bucket policies are resource-based and can complement IAM policies, but they do not replace the need for least privilege in IAM. Option B is wrong because attaching AdministratorAccess is overly permissive and violates least privilege, even with S3 conditions; it grants full access to all AWS services. Option D is wrong because creating a new instance profile with a permissions boundary does not by itself scope down permissions; a permissions boundary sets the maximum permissions but does not grant permissions, and you still need to attach policies that grant only necessary actions.

It is not the best practice for scoping down.

824
MCQeasy

The above CLI output shows the encryption configuration for an S3 bucket. What type of encryption is enabled by default?

A.SSE-C
B.Client-side encryption
C.SSE-KMS
D.SSE-S3
AnswerD

The CLI output shows SSEAlgorithm set to 'AES256', which is the exact algorithm identifier that Amazon S3 uses to represent SSE-S3 in a bucket default encryption configuration. With SSE-S3, S3 automatically manages all encryption keys, encrypts each object with a unique key, and wraps that key with a regularly rotated master key, requiring no customer action or KMS involvement. This precisely matches the output shown, confirming that the bucket is configured for SSE-S3.

Why this answer

SSE-S3 (AES-256) is the default encryption applied by Amazon S3 when no explicit encryption configuration is set on a bucket. The CLI output showing 'ApplyServerSideEncryptionByDefault' with 'SSEAlgorithm: AES256' indicates SSE-S3, where S3 manages the keys entirely. SSE-KMS would show 'aws:kms' and a KMS key ARN, while SSE-C requires customer-provided keys per request.

Exam trap

SCS-C02 often tests the confusion between SSE-S3 and SSE-KMS by showing CLI output with 'AES256' and expecting candidates to recognize it as the S3-managed default rather than assuming KMS is always used for sensitive data.

How to eliminate wrong answers

Option A is wrong because SSE-C requires the customer to supply the encryption key with every PUT/GET request via headers; it is never a bucket default and would not appear as an AES256 default algorithm. Option B is wrong because client-side encryption happens before data reaches S3, so S3's encryption configuration would not reflect it. Option C is wrong because SSE-KMS would display 'aws:kms' as the SSEAlgorithm and reference a KMS key ARN, not plain AES256.

825
MCQhard

A company uses AWS Organizations with multiple accounts. The security team wants to centralize threat detection and automatically remediate high-severity GuardDuty findings across all accounts. What is the MOST efficient way to achieve this?

A.Enable GuardDuty in the management account and designate a delegated administrator to manage findings across all accounts
B.Create a Lambda function that enables GuardDuty in each account using cross-account IAM roles
C.Configure Amazon EventBridge to forward findings from each account to a central account
D.Use AWS Security Hub and enable GuardDuty in each account separately
AnswerA

Designating a GuardDuty delegated administrator in AWS Organizations is the native, recommended pattern because it uses the service's integration with Organizations to auto-enable GuardDuty for every current and future member account via a single API call. The delegated administrator account receives a centralized view of all findings and can configure threat detection policies, while individual accounts retain read access to their own results. This eliminates per-account manual steps and provides a consistent audit trail of enablement state across the organization.

Why this answer

AWS Organizations allows you to enable GuardDuty in the management account and designate a delegated administrator, which automatically enables GuardDuty across all member accounts and centralizes finding management. This approach eliminates the need for per-account configuration or cross-account IAM roles, as the delegated administrator can view and manage findings from all accounts in a single GuardDuty console. It is the most efficient method because it leverages native AWS Organizations integration for automated, centralized threat detection and remediation.

Exam trap

The trap here is that candidates often assume Security Hub (Option D) is required for centralization, but GuardDuty's delegated administrator feature already provides native centralized finding management without additional services.

How to eliminate wrong answers

Option B is wrong because creating a Lambda function to enable GuardDuty in each account using cross-account IAM roles is inefficient, requires custom scripting, and does not provide centralized finding management without additional EventBridge or S3 forwarding. Option C is wrong because configuring Amazon EventBridge to forward findings from each account to a central account adds complexity and latency, and still requires GuardDuty to be enabled individually in each account. Option D is wrong because using AWS Security Hub and enabling GuardDuty in each account separately does not centralize the GuardDuty console itself; Security Hub aggregates findings but does not replace the need for per-account GuardDuty setup or provide the same native centralized management as a delegated administrator.

Page 10

Page 11 of 17

Page 12