Courseiva

AWS Certified Security Specialty SCS-C02 (SCS-C02) — Questions 826–900

1205 questions total · 17pages · All types, answers revealed

Page 11

Page 12 of 17

Page 13
826
MCQeasy

A security team needs to detect unauthorized API calls made from a compromised IAM user. Which AWS service should be used to monitor and alert on specific API activities?

A.AWS CloudTrail
B.AWS Config
C.Amazon GuardDuty
D.VPC Flow Logs
AnswerA

AWS CloudTrail is the correct choice because it is the native AWS service that records API activity in your account, capturing who made the call, from which source IP, what action was invoked, and when it occurred. For unauthorized API call detection, you can enable CloudTrail across all regions, turn on data events for sensitive services like S3 or Lambda, and use CloudTrail Lake or integration with Amazon EventBridge to trigger real-time alerts on specific unauthorized actions. Unlike configuration state or network flow data, CloudTrail delivers a complete audit trail of every management and data-plane API call.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to the AWS environment, including those from IAM users, and delivers event history for auditing. By enabling CloudTrail trails with management event logging and configuring Amazon CloudWatch alarms or EventBridge rules on specific API actions (e.g., `iam:CreateUser`, `ec2:AuthorizeSecurityGroupIngress`), the security team can detect and alert on unauthorized API activities from a compromised IAM user.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks resource configuration changes) with CloudTrail (which logs API calls), or they assume GuardDuty's threat detection covers all API-level monitoring, but GuardDuty does not provide per-API-call logging or allow custom alerting on specific actions like `iam:CreateAccessKey`.

How to eliminate wrong answers

Option B (AWS Config) is wrong because it evaluates resource configurations against desired policies and tracks configuration changes, not API call activities; it cannot log or alert on specific API actions like `iam:CreateAccessKey`. Option C (Amazon GuardDuty) is wrong because it uses threat intelligence and anomaly detection to identify malicious behavior (e.g., unusual network traffic, compromised credentials) but does not provide granular, per-API-call logging or allow alerting on specific API actions; it focuses on broader threat detection rather than auditing individual API calls. Option D (VPC Flow Logs) is wrong because it captures metadata about IP traffic within VPCs (e.g., source/destination IP, ports, protocol) and has no visibility into AWS API calls made by IAM users; it operates at the network layer, not the control plane.

827
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to ensure that all IAM users in the production account must use multi-factor authentication (MFA) to access the AWS Management Console. Which combination of actions should the security team take to enforce this requirement?

A.Use an SCP to deny access to the AWS Management Console unless MFA is present. Attach the SCP to the production OU.
B.Disable password-based access for all IAM users and require federation with an identity provider that enforces MFA.
C.Enable MFA on the root user and apply a password policy that requires MFA.
D.Create an IAM policy that denies all console actions unless MFA is present. Attach the policy to the IAM group that contains all production users.
AnswerD

After an IAM user signs in to the console with only a password, the resulting temporary credentials have aws:MultiFactorAuthPresent set to false. An explicit deny policy using that condition key will block every console action, forcing the user to either re-authenticate with MFA or call STS GetSessionToken with MFA to obtain valid credentials. This effectively enforces MFA for all console access and directly satisfies the stated requirement for production users.

Why this answer

An IAM policy with a condition that denies all console actions unless MFA is present can be attached to an IAM group containing all production users. This enforces MFA at the user level within the account, directly meeting the requirement to ensure all IAM users in the production account must use MFA to access the AWS Management Console.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies, thinking SCPs can enforce MFA for console access within an account, but SCPs apply at the organizational level and cannot target specific IAM users or groups within an account.

How to eliminate wrong answers

Option A is wrong because SCPs cannot deny access to the AWS Management Console specifically; they deny actions on AWS resources, and the condition for MFA in an SCP would apply to all accounts in the OU, not just the production account's IAM users. Option B is wrong because disabling password-based access and requiring federation with an identity provider that enforces MFA is a valid approach but not listed as a combination of actions that the security team can take directly within the production account; it requires external setup and does not enforce MFA for existing IAM users. Option C is wrong because enabling MFA on the root user and applying a password policy that requires MFA does not enforce MFA for all IAM users; the root user MFA is separate, and password policies cannot enforce MFA for console access.

828
MCQhard

A company uses AWS Lambda functions to process sensitive data. The security team wants to ensure that if a Lambda function is compromised, the attacker cannot use the function's IAM role to access other AWS resources. The team has implemented the principle of least privilege by restricting the IAM role's permissions. However, they are concerned about a scenario where an attacker could use the Lambda function to execute AWS API calls that are not intended by the application. What additional measure should the team implement to reduce the risk of such lateral movement?

A.Use AWS IAM Access Analyzer to generate and refine the IAM policy based on actual usage.
B.Enable AWS CloudTrail data events for the Lambda function.
C.Attach a service control policy (SCP) that denies all actions except those explicitly allowed.
D.Place the Lambda function inside a VPC with no internet access.
AnswerA

IAM Access Analyzer's policy generation feature reviews CloudTrail logs to identify the specific API actions the Lambda function actually invoked, then proposes a least-privilege IAM policy. You refine and attach that policy to the function's execution role, which prevents the role from calling unrelated AWS services that it never legitimately needs. This is a preventive control because it reduces the attack surface and blast radius if credentials are compromised, as opposed to merely logging or auditing activity.

Why this answer

AWS IAM Access Analyzer can generate IAM policies based on the actual API calls made by the Lambda function over a specified period. By reviewing and refining the policy to include only those actions, the team can further tighten least privilege beyond manual estimation, reducing the risk that an attacker could abuse unintended API calls. This directly addresses the concern of lateral movement by ensuring the function's role cannot perform actions not observed in normal operation.

Exam trap

The trap here is that candidates may confuse service control policies (SCPs) with IAM permissions boundaries or think they can be applied to individual resources, when in fact SCPs only affect accounts in an organization and cannot be attached to a Lambda function.

How to eliminate wrong answers

Option B is wrong because enabling CloudTrail data events for the Lambda function only provides logging of invocations and does not restrict the function's IAM role permissions or prevent an attacker from making unintended API calls. Option C is wrong because service control policies (SCPs) apply at the AWS Organizations level to accounts or organizational units, not to individual Lambda functions or their IAM roles; they cannot be attached directly to a function to limit its permissions. Option D is wrong because placing the Lambda function inside a VPC with no internet access restricts network connectivity but does not prevent the function from using its IAM role to call AWS APIs via the AWS private network or VPC endpoints; the attacker could still make API calls to other AWS services.

829
MCQmedium

A security engineer is reviewing an AWS account and notices that multiple IAM users have full administrative access. The company policy requires that users have only the permissions necessary to perform their job. What is the MOST secure and efficient way to enforce this policy?

A.Create an IAM policy that denies all actions except those specifically allowed, and attach it to each user.
B.Use an IAM group for each job function, attach appropriate managed policies to the group, and add users to the group.
C.Use an SCP in AWS Organizations to deny all actions by default.
D.Assign an inline policy to each user that specifies allowed actions.
AnswerB

IAM groups are the recommended way to organize permissions by job function: you attach a managed policy (AWS-managed or customer-managed) to the group, and any user added to the group automatically receives those permissions. This separates identity management from permission management, so updating a group policy affects all members consistently, and you can onboard/offboard users simply by adding or removing them from the group. Groups also help you adhere to least privilege without duplicating policy content across individual users.

Why this answer

Using IAM groups mapped to job functions and attaching managed policies to those groups is the most secure and efficient approach. It enforces least privilege by granting only the permissions each role needs, and it centralizes administration so permissions are managed in one place rather than per user. This aligns with AWS best practices for identity management.

Exam trap

SCS-C02 often tests the misconception that SCPs grant permissions or that per-user inline policies are equivalent to group-based managed policies — candidates must recognize that SCPs are guardrails and that groups are the efficient least-privilege mechanism.

How to eliminate wrong answers

Option A is wrong because creating a deny-all-except-allow policy and attaching it to each user is operationally inefficient and error-prone; AWS evaluates explicit denies first, and maintaining per-user policies scales poorly. Option C is wrong because SCPs apply at the AWS Organizations level and set permission guardrails, but they do not grant permissions — an SCP alone cannot enforce least privilege for individual users. Option D is wrong because inline policies attached directly to each user are harder to audit and manage than group-based managed policies, increasing the risk of permission drift.

830
Multi-Selecteasy

A company wants to protect data stored in Amazon S3 Glacier. The data must be encrypted at rest and the encryption keys must be rotated annually. Which TWO options meet these requirements?

Select 2 answers
A.Use SSE-KMS with a customer-managed key that has automatic key rotation enabled.
B.Use AWS CloudHSM to generate a key and encrypt data before uploading to Glacier.
C.Use client-side encryption with the Amazon S3 encryption client.
D.Use SSE-C with keys stored in AWS Secrets Manager and rotate keys annually.
E.Use the default encryption provided by S3 Glacier (SSE-S3).
AnswersA, E

SSE-KMS with a customer-managed AWS KMS key that has automatic rotation enabled satisfies the requirement because S3 Glacier applies server-side encryption using KMS, and KMS automatically rotates the underlying key material on an annual basis without any manual action. The CMK remains the same logical key, so object references and permissions are unchanged while the encryption material is refreshed, meeting compliance policies that demand automatic key rotation. This is the most flexible option when you need separate permissions and audit trails.

Why this answer

SSE-KMS with a customer-managed key that has automatic key rotation enabled allows annual rotation and meets the encryption requirement. Option E is correct because S3 Glacier's default encryption, SSE-S3, encrypts data at rest and AWS manages key rotation automatically on an annual basis. Option B is incorrect because AWS CloudHSM requires manual key rotation.

Option C is incorrect because client-side encryption with the Amazon S3 encryption client does not use server-side encryption and requires manual key management. Option D is incorrect because SSE-C requires you to manage and rotate the keys manually.

831
MCQmedium

A company uses an AWS Network Firewall to inspect traffic between subnets in a VPC. The security team wants to ensure that all traffic from the web tier to the database tier passes through the firewall. The web servers are in subnet A, and the database servers are in subnet B. What routing configuration is required?

A.Add a route in the route table associated with subnet A that sends all traffic to the firewall endpoint.
B.Add a route in the route table for subnet A with destination subnet B CIDR and target the firewall endpoint. Add a similar route in subnet B's route table with destination subnet A CIDR and target the firewall endpoint.
C.Add a route in the route table associated with subnet B that sends all traffic to the firewall endpoint.
D.Associate both subnets with the same route table and add a route to the firewall endpoint for all traffic.
AnswerB

This is the correct approach because it creates symmetric, purpose-built route entries. The route in subnet A's table with destination subnet B CIDR targets the firewall endpoint so outbound cross-tier traffic is inspected, and the mirrored route in subnet B's table with destination subnet A CIDR ensures replies also traverse the firewall for stateful inspection. All other traffic keeps its normal path, minimizing blast radius and cost. This pair of specific CIDR-based routes guarantees that both directions of the subnet-A-to-subnet-B conversation pass through the firewall endpoint, satisfying the requirement.

Why this answer

AWS Network Firewall is a stateful, managed firewall that inspects traffic only when that traffic is explicitly routed to its firewall endpoint. To inspect east-west traffic between subnet A (web tier) and subnet B (database tier), both directions must be routed through the firewall endpoint. This means adding a route in subnet A's route table for the destination subnet B CIDR pointing to the firewall endpoint, and a reciprocal route in subnet B's route table for the destination subnet A CIDR pointing to the firewall endpoint.

This ensures that traffic from A to B and B to A is symmetrically inspected, which is required for stateful inspection to work correctly.

Exam trap

SCS-C02 often tests the misconception that routing traffic in only one direction is sufficient for stateful inspection, or that a single route table can serve multiple subnets with different routing needs.

How to eliminate wrong answers

Option A is wrong because it only routes traffic from subnet A to the firewall endpoint, leaving return traffic from subnet B to subnet A uninspected and potentially breaking stateful flow symmetry. Option C is wrong because it only routes traffic from subnet B to the firewall endpoint, missing the outbound direction from the web tier. Option D is wrong because associating both subnets with the same route table does not automatically route traffic between them through the firewall; a single route table cannot have overlapping CIDR routes that distinguish traffic based on source subnet, and AWS route tables are per-subnet, not per-source, so this would not achieve bidirectional inspection.

832
Multi-Selectmedium

A security engineer is designing a data protection strategy for an S3 bucket that contains sensitive documents. The bucket is accessed by multiple IAM users and roles. Which TWO actions will help protect the data at rest and in transit?

Select 2 answers
A.Enable S3 Access Logs and send them to a separate account
B.Add a bucket policy that denies requests without aws:SecureTransport
C.Enable MFA Delete on the S3 bucket
D.Enable default encryption on the S3 bucket using SSE-S3 or SSE-KMS
E.Use pre-signed URLs for all access
AnswersB, D

Denying requests lacking `aws:SecureTransport` enforces TLS on every S3 API call, satisfying the in-transit encryption requirement. The condition evaluates the transport protocol of each request, so any IAM user or role attempting plain HTTP access is rejected regardless of identity permissions. This protects sensitive documents during transmission without altering stored object encryption.

Why this answer

Enforcing HTTPS (aws:SecureTransport) protects data in transit by requiring all requests to use TLS. Option D is correct because enabling default encryption (SSE-S3 or SSE-KMS) ensures data at rest is automatically encrypted when written to S3. Option A is incorrect: S3 Access Logs are for auditing access, not for protecting data.

Option C is incorrect: MFA Delete protects against accidental deletion, not data protection at rest or in transit. Option E is incorrect: pre-signed URLs provide time-limited access but do not inherently protect data at rest or enforce encryption in transit.

Exam trap

Candidates often confuse auditing (Access Logs) or deletion protection (MFA Delete) with data protection mechanisms. The question specifically asks for protecting data at rest and in transit, which are encryption and transport enforcement.

833
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to automatically receive alerts when an IAM user attempts to access resources they do not have permissions for, across all accounts. Which combination of services should be used?

A.Amazon Inspector and AWS Lambda
B.AWS Config and Amazon SNS
C.AWS CloudTrail and Amazon CloudWatch Logs
D.Amazon GuardDuty and AWS Security Hub
AnswerD

Amazon GuardDuty is a managed threat detection service that consumes CloudTrail management events, VPC Flow Logs, and DNS query logs to identify compromised credentials, unusual API patterns, and malicious behavior. AWS Security Hub collects GuardDuty findings from all member accounts in the organization, applies security standards, and can forward high-severity results to Amazon SNS through Amazon EventBridge for immediate alerting. Together they give continuous detection plus centralized, actionable visibility across the multi-account environment.

Why this answer

Amazon GuardDuty continuously monitors for suspicious activity, including unauthorized API calls or failed access attempts, across all accounts in an AWS Organization. Security Hub aggregates these findings from GuardDuty and other services, enabling automated alerts via integrations like Amazon SNS or AWS Chatbot. Together, they provide a centralized, cross-account threat detection and alerting solution that meets the requirement of notifying the security team when IAM users attempt unauthorized resource access.

Exam trap

The trap here is that candidates often choose CloudTrail and CloudWatch Logs (Option C) because they know CloudTrail logs API calls, but they overlook that GuardDuty and Security Hub provide automated, cross-account threat detection and aggregation without requiring custom metric filters and manual setup for every account.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and network exposure, not for monitoring IAM user access attempts or authorization failures. Option B is wrong because AWS Config evaluates resource configurations against rules and tracks configuration changes, but it does not monitor or detect unauthorized API calls or access attempts by IAM users. Option C is wrong because AWS CloudTrail logs API calls and CloudWatch Logs can store and alert on those logs, but this combination requires custom metric filters and alarms to detect unauthorized access attempts; it lacks the built-in, automated threat detection and cross-account aggregation that GuardDuty and Security Hub provide, making it less efficient and more error-prone for this specific use case.

834
MCQhard

A company uses AWS KMS to encrypt secrets stored in AWS Secrets Manager. The security team wants to audit all KMS key usage, including attempts to use the key without proper authorization. Which AWS service should the team use to meet this requirement?

A.Amazon GuardDuty
B.AWS Config
C.AWS CloudTrail
D.Amazon CloudWatch Logs
AnswerC

AWS CloudTrail is the only service here that natively captures every KMS API operation as an audit event, including both management-plane calls like CreateKey and PutKeyPolicy and data-plane cryptographic calls such as Encrypt, Decrypt, and GenerateDataKey when data events are enabled. Each log entry contains the requesting IAM principal, source IP, request parameters, and response elements, and even records access-denied events from failed authorization attempts, giving security teams a complete, tamper-evident trail for compliance investigations. Because CloudTrail delivers events to an S3 bucket and optionally to CloudWatch Logs, it provides the durable, centralized audit history required by regulators, whereas the other options do not capture KMS API calls directly.

Why this answer

AWS CloudTrail records every API call made to KMS, including successful and failed attempts to use, encrypt, decrypt, or manage keys. Failed attempts due to insufficient permissions are logged as AccessDenied errors, giving the security team the audit trail they need. CloudTrail is the authoritative service for API-level auditing across AWS.

Exam trap

SCS-C02 often tests the distinction between GuardDuty (threat detection) and CloudTrail (audit logging) — candidates pick GuardDuty thinking it audits all API calls, but it only surfaces findings, not raw audit records.

How to eliminate wrong answers

Option A is wrong because GuardDuty is a threat detection service that analyzes logs for malicious activity — it does not provide a complete audit trail of all KMS key usage attempts. Option B is wrong because AWS Config tracks resource configuration changes and compliance, not individual API calls or authorization failures. Option D is wrong because CloudWatch Logs is a log aggregation and monitoring service; while CloudTrail can deliver events to CloudWatch Logs, CloudWatch Logs alone does not capture KMS API activity unless CloudTrail is already feeding it.

835
Multi-Selecteasy

A security engineer needs to ensure that all changes to IAM policies in an AWS account are logged and that the logs are immutable and cannot be deleted by any user, including the root user. Which actions should the engineer take? (Choose two.)

Select 2 answers
A.Enable default encryption with AWS KMS on the bucket.
B.Enable AWS CloudTrail to log IAM events.
C.Enable S3 Versioning on the bucket.
D.Enable multi-factor authentication (MFA) delete on the S3 bucket.
E.Enable S3 Object Lock in compliance mode on the bucket.
AnswersB, E

CloudTrail records every IAM API call, including policy changes, capturing the who, what, when and source IP. This satisfies the logging half of the requirement; immutability is delivered separately by S3 Object Lock in compliance mode.

Why this answer

AWS CloudTrail is the service specifically designed to log all API activity, including IAM policy changes. By enabling CloudTrail with management event logging, all IAM CreatePolicy, PutPolicy, DeletePolicy, and similar actions are recorded in a log file delivered to an S3 bucket. This provides an authoritative audit trail of who made the change, when, and from which source IP.

Option E is correct because S3 Object Lock in compliance mode prevents any user, including the root user, from overwriting or deleting objects for the specified retention period. This ensures the log files are immutable and cannot be tampered with or deleted, fulfilling the requirement that logs cannot be deleted by any user.

Exam trap

The trap here is that candidates often confuse S3 Versioning (which provides object recovery but not immutability) with S3 Object Lock (which provides true WORM immutability), and they may also overlook that MFA Delete still allows deletion by an authorized user with MFA, not preventing root from ultimately deleting logs.

836
MCQmedium

A company is using AWS CloudFormation to deploy infrastructure. Which method ensures that sensitive data, such as database passwords, is not exposed in the template or outputs?

A.Use the 'NoEcho' property on the password parameter.
B.Store the password in the template outputs.
C.Hardcode the password in the template and use the 'NoEcho' property.
D.Use a dynamic reference to a Systems Manager Parameter Store parameter.
AnswerD

A dynamic reference to Systems Manager Parameter Store, such as {{resolve:ssm:parameter-name}}, lets CloudFormation retrieve the password securely at deployment time without ever embedding it in the template. The parameter can be stored as a SecureString using AWS KMS encryption, and access can be governed by IAM policies, ensuring only authorized stacks and roles can retrieve the value. This approach separates secrets from infrastructure code, follows least-privilege principles, and provides auditability through Parameter Store and CloudTrail.

Why this answer

Using a dynamic reference to an AWS Systems Manager Parameter Store parameter allows CloudFormation to retrieve the password at stack creation time without embedding it in the template or exposing it in outputs. The password is stored securely in Parameter Store, and CloudFormation resolves the reference dynamically, ensuring the sensitive value never appears in plaintext in the template, stack events, or outputs.

Exam trap

The trap here is that candidates often confuse the 'NoEcho' property with a security control that protects the value from being exposed anywhere, when in reality it only hides the input during parameter entry and does not prevent exposure in the template file, outputs, or logs.

How to eliminate wrong answers

Option A is wrong because the 'NoEcho' property only masks the parameter value in the console or CLI when the user enters it; it does not prevent the value from being stored in the template or from being exposed in stack outputs if the parameter is referenced there. Option B is wrong because storing the password in template outputs explicitly exposes the sensitive data in the Outputs tab of the CloudFormation console and in the DescribeStacks API response, which is the opposite of secure handling. Option C is wrong because hardcoding the password in the template, even with 'NoEcho', still embeds the plaintext value in the template file itself, which can be exposed through version control, logs, or template retrieval; 'NoEcho' only hides it during parameter input, not from the template content.

837
MCQhard

A company uses AWS Organizations and wants to centralize security logs from all member accounts into a single S3 bucket in the management account. The bucket policy allows only the management account's root user to write objects. However, logs are not being delivered from member accounts. What is the MOST likely cause?

A.S3 Transfer Acceleration is not enabled.
B.VPC endpoints are not configured for the logging service.
C.The S3 bucket uses an AWS KMS key, and the key policy does not grant decrypt permissions to the logging service.
D.The bucket policy denies write access to all principals except the management account's root user, preventing cross-account writes.
AnswerD

To centralize security logs in a management account bucket, the bucket policy must explicitly allow the logging service principal, such as cloudtrail.amazonaws.com, to write objects on behalf of member accounts. If the bucket policy denies s3:PutObject to all principals except the management account root user, every delivery attempt from a member account is a cross-account write and is denied. Service principals are not the root user and never inherit the account root's permissions, so this restrictive bucket policy exactly prevents central log delivery.

Why this answer

The bucket policy explicitly restricts write access to only the management account's root user. For cross-account log delivery from member accounts, the policy must grant write permissions to the logging service (e.g., AWS CloudTrail or AWS Config) in each member account. Without such permissions, the service cannot write objects to the bucket, causing log delivery to fail.

Exam trap

The trap here is that candidates often overlook that the bucket policy's explicit denial to all principals except the management account root user also blocks the logging service's cross-account write attempts, even though the service is not a user but an AWS service principal.

How to eliminate wrong answers

Option A is wrong because S3 Transfer Acceleration is a feature for speeding up uploads over long distances and has no bearing on cross-account write permissions for logging services. Option B is wrong because VPC endpoints are used for private connectivity within a VPC and are not required for logging services to deliver logs to an S3 bucket; the issue is a permissions problem, not a network connectivity one. Option C is wrong because while KMS key policies can affect decryption, the logging service needs encrypt permissions (kms:GenerateDataKey and kms:Encrypt) to write objects, not decrypt; furthermore, the question states logs are not being delivered, which points to a write permission failure, not a decryption issue.

838
MCQmedium

A security engineer is designing a solution to encrypt data at rest in an Amazon DynamoDB table. The data must be encrypted with a customer managed key in AWS KMS that the security team can rotate annually. The DynamoDB table is used by an AWS Lambda function. Which approach should the engineer take to meet these requirements?

A.Create a customer managed KMS key, enable automatic key rotation with a one-year rotation period, and specify this key when creating the DynamoDB table.
B.Enable DynamoDB encryption at rest with the default AWS owned key and configure annual rotation of that key.
C.Enable DynamoDB encryption at rest with an AWS managed key and manually rotate the key every year using the AWS CLI.
D.Use AWS CloudHSM to generate a custom encryption key and configure DynamoDB to use that key for encryption at rest.
AnswerA

A customer managed KMS key allows the security team to control rotation. Enabling automatic rotation with a one-year period meets the annual rotation requirement. When creating the DynamoDB table, specifying this key ensures all data is encrypted with it. The Lambda function's IAM role must have permissions to use the key for encrypt and decrypt operations.

Why this answer

Using a customer managed KMS key with automatic rotation set to one year gives the security team control over the key lifecycle. DynamoDB supports specifying a customer managed key at table creation. The Lambda function must have IAM permissions to use the key.

This solution meets both the encryption and rotation requirements.

Exam trap

The trap here is assuming that AWS managed keys or AWS owned keys can be rotated on a custom schedule, when in fact only customer managed keys support configurable automatic rotation.

839
MCQeasy

Refer to the exhibit. A security engineer runs the command shown and gets the output. What does this output indicate about the bucket's encryption configuration?

A.The bucket does not allow unencrypted objects.
B.The bucket has default encryption enabled using SSE-KMS.
C.The bucket requires all objects to be encrypted with SSE-KMS.
D.The bucket has default encryption enabled using SSE-S3.
AnswerD

The API response shows "ApplyServerSideEncryptionByDefault" with "SSEAlgorithm": "AES256", which directly maps to S3-managed keys, i.e., SSE-S3. With SSE-S3 default encryption enabled, any object uploaded without an encryption header is automatically encrypted at rest using S3's AES-256 encryption. This is exactly what the get-bucket-encryption output demonstrates, making this the correct interpretation.

Why this answer

The output shows that default encryption is set to AES256, which corresponds to SSE-S3. This means new objects uploaded to the bucket will be encrypted with SSE-S3 unless a different encryption header is provided. Therefore, option D is correct.

Option A is incorrect because the default encryption setting does not prevent unencrypted objects from being uploaded if the client does not provide encryption headers—it only applies encryption by default. Option B is incorrect because SSE-KMS uses a different key management service, not AES256. Option C is incorrect because default encryption does not require all objects to be encrypted with SSE-KMS; it sets a server-side default, but clients can override with their own encryption settings.

840
MCQeasy

A company is using AWS WAF to protect a web application. The security team wants to receive alerts when a specific rule block is triggered. Which AWS service should they use to achieve this?

A.Amazon EventBridge
B.CloudWatch Alarms with SNS
C.Amazon S3
D.Amazon SNS
AnswerB

AWS WAF publishes real-time CloudWatch metrics such as BlockedCount and CountedCount for each web ACL and rule. A CloudWatch Alarm can monitor these metrics and transition to the ALARM state when a threshold (e.g., blocked requests exceed 100 per minute) is breached, then automatically publish to an SNS topic to send email or SMS notifications. This is the native, direct alerting mechanism for WAF rule events because it uses the service's own metric stream.

Why this answer

AWS WAF integrates with Amazon CloudWatch to provide metrics for each rule, including the 'BlockedRequests' count. By creating a CloudWatch Alarm on this metric, you can trigger an SNS notification when the threshold is exceeded, alerting the security team. This is the standard pattern for receiving alerts on WAF rule actions, as CloudWatch Alarms with SNS provide the necessary monitoring and notification pipeline.

Exam trap

The trap here is that candidates often confuse the notification mechanism (SNS) with the evaluation mechanism (CloudWatch Alarms), selecting SNS alone without recognizing that CloudWatch Alarms are required to evaluate the WAF metric and trigger the notification.

How to eliminate wrong answers

Option A is wrong because Amazon EventBridge is used for event-driven architectures to route events from various sources to targets, but it does not natively evaluate metric thresholds or generate alerts based on WAF rule triggers without additional custom logic. Option C is wrong because Amazon S3 is an object storage service and cannot evaluate metrics or send alerts; it can only store logs or data. Option D is wrong because Amazon SNS alone is a notification service that requires a publisher to send messages; without a CloudWatch Alarm to evaluate the WAF metric and publish to the SNS topic, no alert will be generated.

841
MCQeasy

A security engineer needs to ensure that all S3 buckets in an AWS account have server access logging enabled. Which AWS service should be used to continuously monitor for compliance?

A.AWS Config
B.Amazon GuardDuty
C.AWS IAM Access Analyzer
D.AWS CloudTrail
AnswerA

AWS Config is the correct choice because it is a configuration assessment service that continuously records S3 bucket configurations and evaluates them against managed rules such as s3-bucket-logging-enabled. When server access logging is disabled, the rule marks the bucket as noncompliant, and you can automate remediation with SSM documents or custom Lambda functions. AWS Config provides a compliance history, so you can see exactly when a bucket fell out of compliance, which is essential for audit evidence.

Why this answer

AWS Config is the correct service because it provides continuous monitoring and evaluation of your AWS resource configurations against desired policies. You can create an AWS Config rule, such as the managed rule 's3-bucket-server-access-logging-enabled', which will automatically check all S3 buckets in your account and report any that do not have server access logging enabled, flagging them as noncompliant. This allows for ongoing, automated compliance auditing without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Config with AWS CloudTrail, mistakenly thinking that CloudTrail's logging of API calls can be used to continuously monitor compliance, but CloudTrail only records events and does not evaluate the current state of resources against a desired configuration.

How to eliminate wrong answers

Option B (Amazon GuardDuty) is wrong because GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events to identify malicious activity; it does not evaluate resource configurations for compliance with logging requirements. Option C (AWS IAM Access Analyzer) is wrong because it focuses on identifying resources shared with external entities by analyzing resource-based policies (e.g., S3 bucket policies), not on verifying whether server access logging is enabled. Option D (AWS CloudTrail) is wrong because CloudTrail records API calls made in your account for auditing and governance, but it does not continuously monitor the configuration state of S3 buckets to enforce compliance with logging settings.

842
Multi-Selecteasy

A company needs to ensure that its S3 buckets are not publicly accessible. Which TWO AWS services can be used to detect and report on public S3 buckets? (Choose two.)

Select 2 answers
A.Amazon GuardDuty
B.AWS Trusted Advisor
C.AWS Config
D.AWS CloudTrail
E.Amazon Inspector
AnswersB, C

AWS Trusted Advisor includes the 'S3 Bucket Permissions' check, which specifically reviews S3 bucket policies and ACLs for configurations that allow public read or write access, and flags those buckets in the Security category of the dashboard. This is a prescriptive, AWS-managed check that immediately identifies public buckets across your account. The check also differentiates between public access granted by ACLs versus bucket policies, providing focused remediation guidance and making it a first-line tool for this requirement.

Why this answer

AWS Trusted Advisor (option B) checks S3 bucket permissions and reports any bucket that has open access policies, including public read or write access. AWS Config (option C) can evaluate S3 bucket policies against custom or managed rules (e.g., s3-bucket-public-read-prohibited, s3-bucket-public-write-prohibited) to detect noncompliant buckets and trigger remediation. Both services provide detection and reporting capabilities for public S3 buckets.

Exam trap

The trap here is that candidates often confuse Amazon GuardDuty's threat detection capabilities with S3 bucket policy auditing, but GuardDuty does not evaluate bucket permissions for public access; it only detects suspicious API activity after the fact.

843
MCQhard

Refer to the exhibit. A security engineer runs the IAM Policy Simulator with the provided policy input. The result shows 'explicitDeny' for ec2:RunInstances even though the policy only contains an Allow. What is the most likely reason?

A.The user has an attached policy or SCP that explicitly denies ec2:RunInstances.
B.The policy input has a syntax error.
C.The simulate-custom-policy command does not support ec2:RunInstances.
D.The resource ARN is incorrect for ec2:RunInstances.
AnswerA

An explicit Deny in any attached identity policy, permissions boundary or AWS Organizations SCP always overrides Allow, producing explicitDeny in the simulator. The Allow in the supplied policy cannot take effect while that deny remains in force.

Why this answer

The IAM Policy Simulator evaluates the effective permissions by combining all applicable policies — identity-based policies, resource-based policies, permissions boundaries, SCPs, and session policies. An 'explicitDeny' result means some policy in the evaluation chain contains an explicit Deny statement for ec2:RunInstances, which always overrides any Allow. Since the input policy only has an Allow, the deny must originate from an attached policy or an SCP in the account hierarchy.

Exam trap

SCS-C02 often tests the misconception that the simulator only evaluates the policy you paste in — candidates forget that explicit Deny from SCPs, permissions boundaries, or other attached policies takes precedence and produces the explicitDeny result.

How to eliminate wrong answers

Option B is wrong because a syntax error in the policy would produce a malformed-policy or validation error, not a clean 'explicitDeny' evaluation result — the simulator would reject the policy before evaluating it. Option C is wrong because the IAM Policy Simulator supports all IAM actions including ec2:RunInstances; there is no per-action restriction on the simulation engine. Option D is wrong because an incorrect resource ARN would cause the Allow statement to not match, resulting in an implicit deny (not an explicitDeny), and the simulator would report 'implicitDeny' or 'allowed: false' rather than the explicitDeny classification.

844
Multi-Selectmedium

A security engineer is configuring AWS CloudTrail to monitor data events for S3 objects. Which TWO of the following must be enabled to log object-level operations? (Select TWO.)

Select 2 answers
A.Enable data events in the CloudTrail trail.
B.Enable S3 server access logs on the bucket.
C.Enable management events in the CloudTrail trail.
D.Enable S3 Object Lambda.
E.Specify the S3 bucket ARN or prefix in the trail configuration.
AnswersA, E

CloudTrail data events record S3 object-level operations such as GetObject, PutObject, and DeleteObject. Enabling data events is essential because management events only cover control-plane actions (e.g., bucket creation or policy changes), not the actual access to objects. Data events must be explicitly enabled in the trail, as they are not on by default due to their high volume, but they are exactly what you need to monitor object-level activity.

Why this answer

CloudTrail data events capture S3 object-level operations such as GetObject, PutObject, and DeleteObject. To enable this, you must explicitly select 'Data events' in the CloudTrail trail configuration, as management events only cover bucket-level operations like CreateBucket.

Exam trap

The trap here is that candidates often confuse management events (which log bucket-level actions) with data events (which log object-level actions), leading them to select Option C instead of recognizing that both data events and a specific bucket ARN or prefix are required.

845
MCQhard

A security team wants to centrally collect and analyze VPC Flow Logs from multiple AWS accounts for security monitoring. Which solution is MOST scalable and cost-effective?

A.Aggregate logs in an EC2 instance running an ELK stack.
B.Use Amazon Kinesis Data Firehose to stream logs to an S3 bucket and process with AWS Lambda.
C.Configure VPC Flow Logs to send to a centralized CloudWatch Logs account using cross-account subscriptions.
D.Use AWS Organizations to centralize logging by delivering VPC Flow Logs to a centralized S3 bucket and query with Amazon Athena.
AnswerD

AWS Organizations centralises log delivery across accounts into one S3 bucket, avoiding per-account pipelines. Athena queries that bucket serverlessly, paying only per query, which satisfies the scalability and cost-effectiveness constraints for multi-account VPC Flow Log analysis.

Why this answer

Using AWS Organizations to centrally deliver VPC Flow Logs to a centralized S3 bucket, then querying with Amazon Athena, is both scalable and cost-effective. S3 provides durable, low-cost storage for large volumes of log data, and Athena allows serverless, pay-per-query analysis without provisioning infrastructure. This approach avoids the operational overhead of managing EC2 instances or streaming pipelines, and scales seamlessly as log volume grows.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing a streaming or real-time processing service (like Kinesis or CloudWatch Logs) when the requirement is for cost-effective batch analysis, not real-time alerting.

How to eliminate wrong answers

Option A is wrong because running an ELK stack on an EC2 instance introduces significant operational overhead, requires manual scaling, and incurs costs for compute and storage even when idle, making it less scalable and cost-effective than serverless alternatives. Option B is wrong because Amazon Kinesis Data Firehose to S3 with Lambda processing adds unnecessary complexity and cost for a use case that can be served by direct S3 delivery and Athena queries, and Firehose is optimized for streaming ingestion, not batch log analysis. Option C is wrong because cross-account CloudWatch Logs subscriptions require managing subscription filters and IAM roles across accounts, and CloudWatch Logs costs are higher per GB ingested and stored compared to S3, making it less cost-effective for high-volume VPC Flow Logs.

846
MCQmedium

A company is implementing a multi-account strategy using AWS Organizations. The security team wants to enforce that all newly created member accounts automatically have an IAM role that allows read-only access to the management account. Which configuration should be used?

A.Create an AWS Lambda function that listens for AWS CloudTrail CreateAccount events and creates the role in the new account.
B.Use AWS CloudFormation StackSets to deploy the role to all existing and future accounts.
C.Use an AWS Config managed rule to evaluate new accounts and trigger a remediation action to create the role.
D.Configure an SCP with the 'iam_role' setting to specify a role name and path to be automatically created in new accounts.
AnswerB

AWS CloudFormation StackSets with service-managed permissions allows you to deploy a stack template that defines the IAM role to every account in your AWS Organization. When you enable automatic deployment and specify the organization-wide or OU-wide target, StackSets automatically deploys the stack to new accounts as they are created. This ensures the role exists in all existing and future accounts without requiring custom orchestration or event-driven logic.

Why this answer

AWS CloudFormation StackSets is the correct service for deploying a common IAM role across multiple accounts, including automatically to new accounts as they are added to the organization. When you create a StackSet with service-managed permissions, you can enable automatic deployments so that the stack instance is created in every new account that joins the target organizational unit (OU). This directly satisfies the requirement to enforce the role's presence in all newly created member accounts without custom automation.

Exam trap

SCS-C02 often tests the misconception that SCPs can create or manage resources, when they are only permission boundaries; candidates may also overlook StackSets' automatic deployment feature for new accounts.

How to eliminate wrong answers

Option A is wrong because building a custom Lambda function to react to CloudTrail CreateAccount events is unnecessarily complex, introduces latency, and requires maintaining event patterns and cross-account permissions; it is not the native, recommended mechanism. Option C is wrong because AWS Config rules evaluate resource compliance and can trigger remediation, but they do not proactively create resources in new accounts; they are reactive and would require a custom remediation action, plus Config must be enabled in each account. Option D is wrong because SCPs are permission guardrails that restrict what principals can do; they do not have an 'iam_role' setting and cannot create IAM roles or any resources.

847
MCQmedium

A security team is using AWS CloudTrail and Amazon CloudWatch Logs to monitor for unauthorized API calls. They want to receive an alert when an API call is made with an access key that has been reported as compromised. They have configured CloudTrail to send logs to CloudWatch Logs. What should they do next to achieve this?

A.Create an AWS Lambda function that periodically queries CloudTrail event history for the access key ID and sends an alert via Amazon SES.
B.Create a CloudWatch Logs metric filter that matches the access key ID in the CloudTrail logs, and create a CloudWatch alarm that publishes to an SNS topic.
C.Use Amazon GuardDuty to monitor for the compromised access key and configure it to send findings to an SNS topic.
D.Enable AWS CloudTrail Insights to automatically detect the compromised access key and send an alert.
AnswerB

CloudWatch Logs metric filters can search for specific terms, such as the compromised access key ID, in the log data. When the filter matches, it increments a metric. A CloudWatch alarm on that metric can trigger an SNS notification, providing the desired alert. This is the standard method for alerting on specific log patterns.

Why this answer

The most efficient and real-time method is to create a CloudWatch Logs metric filter that matches the compromised access key ID in the CloudTrail logs. When the filter matches, it increments a custom metric. A CloudWatch alarm on that metric can then publish to an SNS topic, alerting the team.

This leverages the existing log delivery and requires no custom code.

Exam trap

The trap here is assuming GuardDuty or CloudTrail Insights can monitor for a specific user-defined access key ID, when they do not support such custom matching.

848
MCQeasy

A developer needs to access AWS resources from a mobile app. Which AWS service allows the app to obtain temporary credentials for authenticated users?

A.Amazon Cognito user pools
B.AWS IAM Identity Center (AWS SSO)
C.Amazon Cognito identity pools (federated identities)
D.AWS Key Management Service (AWS KMS)
AnswerC

Amazon Cognito identity pools (federated identities) are the correct choice because they are specifically built to trade identity tokens—from Cognito user pools, social IdPs, or custom OIDC providers—for temporary AWS credentials. Internally, this uses AWS Security Token Service (STS) actions like AssumeRoleWithWebIdentity, and the resulting credentials are automatically refreshed by the AWS mobile SDKs. They also support unauthenticated guest access when guest users need limited access. This maps the authenticated/unauth user to an IAM role with fine-grained permissions to AWS resources.

Why this answer

Amazon Cognito identity pools (federated identities) are specifically designed to provide temporary, scoped AWS credentials to authenticated and unauthenticated users. The identity pool exchanges a token from an identity provider (such as a Cognito user pool, social provider, or SAML) for temporary AWS credentials via AWS Security Token Service (STS). This allows mobile apps to directly access AWS services like S3 or DynamoDB without embedding long-term credentials.

Exam trap

SCS-C02 often tests the distinction between Cognito user pools (authentication) and identity pools (authorization for AWS credentials), causing candidates to confuse the two and select user pools when temporary AWS credentials are required.

How to eliminate wrong answers

Option A is wrong because Amazon Cognito user pools are directories for user sign-up and sign-in, and they issue JSON Web Tokens (JWTs) for authentication, but they do not directly provide temporary AWS credentials for accessing AWS services. Option B is wrong because AWS IAM Identity Center (AWS SSO) is designed for workforce identity and access management across multiple AWS accounts and business applications, not for providing temporary credentials to end-users of a mobile app. Option D is wrong because AWS Key Management Service (KMS) is a service for creating and managing encryption keys, not for issuing temporary credentials to users or applications.

849
MCQeasy

A security engineer needs to ensure that an Amazon RDS for MySQL database is encrypted at rest. Which action should be taken?

A.Use a client-side encryption tool to encrypt data before writing to the database.
B.Use AWS KMS to encrypt individual databases within the instance.
C.Enable encryption on an existing unencrypted DB instance.
D.Create a new DB instance with encryption enabled.
AnswerD

Creating a new DB instance with encryption enabled is the correct approach because RDS encryption at rest is enabled at launch using an AWS KMS customer managed key. Once enabled, Amazon RDS transparently encrypts the underlying storage, automated backups, read replicas, and snapshots without requiring any application changes. After the new encrypted instance is created, migrate data from the existing source—either by restoring from an encrypted snapshot or using native database export/import tools—to complete the transition.

Why this answer

Amazon RDS does not support enabling encryption on an existing unencrypted DB instance. Encryption at rest must be configured at instance creation time by selecting the KMS key. Therefore, the only valid path is to create a new DB instance with encryption enabled and migrate data to it.

Exam trap

The trap here is assuming RDS supports in-place encryption toggling like some other AWS services; candidates often pick 'enable encryption on existing instance' because it sounds operationally convenient, but RDS requires instance recreation.

How to eliminate wrong answers

Option A is wrong because client-side encryption protects data before it reaches RDS but does not satisfy the requirement for RDS encryption at rest, which is a storage-layer feature managed by AWS. Option B is wrong because AWS KMS encrypts the underlying storage volume of the DB instance, not individual databases inside the instance; RDS does not expose per-database encryption controls. Option C is wrong because RDS does not allow enabling encryption on an existing unencrypted DB instance — the instance must be recreated from a snapshot with encryption enabled.

850
MCQeasy

A company is using AWS Organizations to manage multiple accounts. The security team wants to prevent any IAM user from creating access keys. Which type of policy should be used to enforce this control across all accounts?

A.Service Control Policy (SCP)
B.AWS CloudTrail trail
C.AWS Config managed rule
D.IAM permissions boundary
AnswerA

SCPs are the AWS Organizations feature that centrally controls the maximum allowed permissions for all IAM principals in member accounts. You attach an SCP to the organization root, OUs, or individual accounts, and it applies to every user and role in that account, including the account root user, without requiring per-resource configuration. Because SCPs act as a boundary that IAM policies cannot exceed, they are the effective preventive control to block actions across all accounts in the organization.

Why this answer

Service Control Policies (SCPs) are the only AWS Organizations policy type that can centrally restrict what IAM principals in member accounts are allowed to do, including denying iam:CreateAccessKey across every account in the OU. Because SCPs set the maximum permissions boundary for all identities in the account, an explicit Deny in an SCP overrides any IAM policy that would otherwise grant the action. This makes SCPs the correct mechanism for enforcing a blanket, organization-wide control.

Exam trap

SCS-C02 often tests the misconception that IAM permissions boundaries or AWS Config rules can enforce organization-wide preventive controls, when only SCPs provide centralized, preventive permission filtering across all accounts in an OU.

How to eliminate wrong answers

Option B is wrong because CloudTrail is a logging and auditing service that records API activity; it can detect that an access key was created but cannot prevent the action. Option C is wrong because AWS Config managed rules evaluate resource configuration compliance after the fact and can trigger remediation, but they do not block the iam:CreateAccessKey API call in real time. Option D is wrong because an IAM permissions boundary only limits the maximum permissions of a single IAM user or role to which it is attached; it must be applied per-identity and cannot be enforced organization-wide from a central point.

851
MCQeasy

A security engineer needs to capture all API calls made to AWS services for forensic analysis. Which AWS service should be used to store these logs durably and cost-effectively for long-term retention?

A.VPC Flow Logs
B.Amazon GuardDuty
C.AWS Config
D.AWS CloudTrail
AnswerD

AWS CloudTrail records every API call across AWS services as management and data events, satisfying the requirement to capture all API activity. Delivering these trails to Amazon S3 provides durable, low-cost long-term retention for forensic analysis, unlike CloudWatch Logs, which is pricier for bulk storage.

Why this answer

AWS CloudTrail is the correct service because it captures all API calls made to AWS services, including the identity of the caller, time of the call, source IP address, and request parameters. It stores these logs durably in Amazon S3, which provides cost-effective long-term retention for forensic analysis. CloudTrail is specifically designed for auditing and monitoring API activity across an AWS environment.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks resource configuration changes) with CloudTrail (which tracks API calls), leading them to select Config when the question explicitly asks for capturing API calls.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) at the VPC level, not API calls to AWS services. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes logs (including CloudTrail, VPC Flow Logs, and DNS logs) for malicious activity, but it does not natively store or capture raw API call logs for long-term retention. Option C is wrong because AWS Config records resource configuration changes and evaluates compliance rules, but it does not capture API calls; it focuses on resource state history, not the API actions that caused changes.

852
Multi-Selectmedium

Which TWO actions should a security engineer take to ensure that CloudTrail logs are protected from unauthorized deletion? (Choose two.)

Select 2 answers
A.Attach an S3 bucket policy that denies s3:DeleteObject to all principals except the CloudTrail service principal.
B.Enable S3 versioning on the log bucket.
C.Enable S3 default encryption with SSE-S3.
D.Configure CloudTrail to send logs to CloudWatch Logs.
E.Enable S3 MFA Delete on the log bucket.
AnswersA, E

This bucket policy uses an explicit Deny for s3:DeleteObject scoped to all principals except the CloudTrail service principal (with conditions like aws:SourceArn to prevent misuse), which prevents any IAM user, role, or AWS account from deleting log objects. Because an explicit Deny overrides all Allows, this enforces immutability of the logs while still allowing CloudTrail to write new objects. This is a direct and robust control for preserving audit log integrity.

Why this answer

Attaching an S3 bucket policy that denies s3:DeleteObject to all principals except the CloudTrail service principal prevents any user or role (including root) from deleting log files, while still allowing CloudTrail to write logs. This ensures that even if an attacker gains administrative access, they cannot delete the logs, preserving their integrity for forensic analysis.

Exam trap

The trap here is that candidates often confuse data protection mechanisms (encryption, versioning) with deletion prevention, leading them to select options like B or C instead of recognizing that only explicit deny policies and MFA Delete directly block deletion actions.

853
MCQeasy

A company wants to protect data at rest for an Amazon RDS for PostgreSQL database. Which AWS service should be used to manage the encryption keys?

A.AWS CloudHSM
B.AWS Key Management Service (KMS)
C.AWS Certificate Manager (ACM)
D.AWS Secrets Manager
AnswerB

AWS Key Management Service (KMS) is the correct service for encrypting Amazon RDS data at rest. When you enable RDS encryption, you select a KMS customer master key (CMK) — either the AWS-managed key (aws/rds) or a customer-managed CMK — which encrypts the underlying storage, automated backups, snapshots, and read replicas. KMS also provides fine-grained access control and AWS CloudTrail auditing for every key use, making it the native integration point for RDS storage encryption.

Why this answer

Amazon RDS for PostgreSQL integrates with AWS Key Management Service (KMS) to enable encryption at rest. When you enable encryption for an RDS DB instance, KMS manages the customer master keys (CMKs) that encrypt the data keys used by the storage layer. This is the standard, fully managed key management service for RDS encryption, supporting automatic key rotation and fine-grained access control.

Exam trap

The trap here is that candidates confuse AWS Secrets Manager (which manages secrets like passwords) with KMS (which manages encryption keys), leading them to select Secrets Manager for key management instead of the correct service for RDS encryption at rest.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides hardware security modules for key generation and storage but does not integrate directly with RDS for encryption at rest; RDS relies on KMS for key management, not CloudHSM. Option C is wrong because AWS Certificate Manager (ACM) handles SSL/TLS certificates for securing data in transit, not encryption keys for data at rest. Option D is wrong because AWS Secrets Manager is designed to rotate and manage database credentials and other secrets, not to manage the encryption keys used for RDS storage encryption.

854
MCQeasy

A security auditor needs to view a list of all IAM users, including their last activity timestamps, for a compliance review. Which AWS service provides this information natively?

A.AWS CloudTrail
B.IAM Access Analyzer
C.AWS IAM credential report
D.AWS Config
AnswerC

The IAM credential report is a CSV exported through the console or via GenerateCredentialReport/GetCredentialReport APIs that lists every IAM user in the account. It includes password last used and rotation status, access key IDs and their last-used/rotation dates, MFA device presence, and whether the user has a password. This report directly answers the auditor's need for a complete, current list of IAM users plus their credential hygiene.

Why this answer

The AWS IAM credential report is a native feature that generates a CSV containing all IAM users, their access keys, password status, MFA status, and key rotation dates including last activity timestamps. It is specifically designed for auditing user credentials and activity, making it the correct choice for a compliance review of last activity.

Exam trap

The trap is confusing activity logging (CloudTrail) with credential inventory (credential report) — candidates pick CloudTrail because it 'shows activity', but it does not natively produce a per-user last-activity list.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity events, not a consolidated list of IAM users with last-activity timestamps — you would have to parse logs manually. Option B is wrong because IAM Access Analyzer identifies resources shared with external entities and validates policies; it does not report user last-activity. Option D is wrong because AWS Config tracks resource configuration changes and compliance, not per-user credential activity timestamps.

855
MCQhard

A company has enabled AWS CloudTrail in all accounts and regions, with log file validation enabled. The security team needs to verify that a specific log file has not been modified since it was delivered. Which action should be taken?

A.Query the log files using Amazon CloudWatch Logs Insights.
B.Enable S3 server-side encryption with AWS KMS (SSE-KMS) on the CloudTrail bucket.
C.Enable S3 Object Lock on the bucket to prevent modifications.
D.Use the AWS CLI `validate-logs` command with the digest file from the S3 bucket.
AnswerD

The `aws cloudtrail validate-logs` command implements CloudTrail's integrity validation by reading the digest files delivered to the S3 bucket. Each digest file contains the SHA-256 hash of the log files and a digital signature generated with AWS's private key; the CLI retrieves the corresponding public key from AWS, verifies the signature, and then recomputes the hash of each log file to compare against the digest. This process cryptographically confirms that log files were not altered or removed during delivery, providing a tamper-evident chain from the moment CloudTrail wrote the file.

Why this answer

CloudTrail log file validation creates a hash of each log file and stores it in a digest file. To verify that a specific log file has not been altered since delivery, you must use the AWS CLI `validate-logs` command, which compares the hash in the digest file against the current hash of the log file. This command also validates the digital signature of the digest file itself, ensuring end-to-end integrity.

Exam trap

The trap here is that candidates confuse data integrity verification (hash comparison) with data protection mechanisms like encryption or object lock, which prevent or obscure modification but do not prove that a file has remained unchanged since its creation.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs Insights is used for querying and analyzing log data, not for cryptographic integrity verification of individual log files. Option B is wrong because SSE-KMS encrypts data at rest but does not provide any mechanism to detect or prevent modification of log files after delivery. Option C is wrong because S3 Object Lock prevents deletion or overwrite of objects during a retention period, but it does not verify the integrity of already-delivered log files or detect modifications made before the lock was applied.

856
MCQhard

A company uses AWS Systems Manager Patch Manager to apply patches to EC2 instances. The security team wants to ensure that instances are patched within 7 days of a patch release. Which service should be used to monitor and report compliance?

A.AWS Config
B.AWS Security Hub
C.Amazon Inspector
D.AWS Trusted Advisor
AnswerA

AWS Config integrates with Systems Manager Patch Manager to record patch compliance state as a configuration item. You can use managed rules like ec2-managedinstance-patch-compliance-status-check or custom Lambda rules to evaluate whether instances are patched within the required timeframe, and trigger remediation actions such as Systems Manager Automation. It provides an ongoing compliance history and can enforce patch validation across the fleet.

Why this answer

AWS Config is the correct service because it provides continuous monitoring and evaluation of your AWS resource configurations, including patch compliance status via Systems Manager Patch Manager. You can create an AWS Config rule (e.g., 'ec2-managedinstance-patch-compliance-status') that checks whether instances have the required patches installed within a specified time frame (e.g., 7 days). AWS Config then reports noncompliant resources, enabling the security team to track and remediate patching gaps.

Exam trap

The trap here is that candidates often confuse Amazon Inspector's vulnerability scanning with patch compliance monitoring, but Inspector does not track whether patches have been applied within a specific time window after release—it only identifies missing patches or vulnerabilities at a point in time.

How to eliminate wrong answers

Option B (AWS Security Hub) is wrong because it aggregates security findings from multiple AWS services (like AWS Config, GuardDuty, Inspector) but does not itself perform patch compliance monitoring; it relies on AWS Config rules to provide that data. Option C (Amazon Inspector) is wrong because it focuses on vulnerability assessments and network reachability analysis, not on tracking whether patches have been applied within a specific time window after release. Option D (AWS Trusted Advisor) is wrong because it provides best-practice checks for cost, performance, security, and fault tolerance, but it does not monitor patch compliance status or report on patch age relative to release dates.

857
MCQmedium

A company has deployed a multi-tier web application on AWS. The web servers are in a public subnet, and the application servers are in a private subnet. The security team wants to ensure that the application servers cannot initiate outbound connections to the internet. What should the team do?

A.Add a deny rule for all outbound traffic in the network ACL of the private subnet.
B.Modify the security group of the application servers to deny all outbound traffic.
C.Remove the default route (0.0.0.0/0) pointing to an internet gateway or NAT gateway from the private subnet's route table.
D.Attach an egress-only internet gateway to the private subnet.
AnswerC

Removing the default route (0.0.0.0/0) to an internet gateway or NAT gateway from the private subnet's route table eliminates the only path for outbound traffic to reach the internet. Route tables govern where traffic is sent from the subnet; without a default route, any packet destined outside the VPC has no route and is dropped. This does not affect inbound traffic, which is controlled by security groups and network ACLs, making it a precise and effective solution.

Why this answer

Removing the default route (0.0.0.0/0) from the private subnet's route table ensures that any traffic destined for the internet has no valid path, effectively preventing application servers from initiating outbound internet connections. Network ACLs and security groups are stateful or stateless filters but do not control routing; without a route, packets cannot leave the subnet regardless of allow rules. This aligns with the principle of using route tables to enforce network segmentation in a multi-tier architecture.

Exam trap

The trap here is that candidates often confuse security group rules or network ACLs with routing decisions, mistakenly believing that blocking outbound traffic at the firewall level is sufficient, when in fact AWS routes traffic before applying security group or ACL rules, so without a route, no traffic can leave the subnet regardless of allow rules.

How to eliminate wrong answers

Option A is wrong because network ACLs are stateless and apply to both inbound and outbound traffic at the subnet level, but adding a deny rule for all outbound traffic would still allow return traffic for established connections if inbound rules permit it; more importantly, it does not prevent the application servers from initiating connections if a route exists, as the ACL only filters packets that are already routed. Option B is wrong because security groups are stateful and cannot deny outbound traffic; they only support allow rules, and by default all outbound traffic is allowed unless explicitly removed, but removing all outbound rules still permits return traffic for inbound-initiated connections due to statefulness, and the security group does not control routing. Option D is wrong because an egress-only internet gateway is designed for IPv6 traffic to allow outbound-only connections from a private subnet, which would actually enable outbound internet access for IPv6, contrary to the requirement to prevent all outbound internet connections.

858
MCQmedium

During an incident response, a security team needs to capture a memory dump of an Amazon EC2 instance running Linux. What is the recommended approach?

A.Use AWS Systems Manager Run Command to run a script that extracts memory using LiME.
B.Use Amazon Inspector to collect memory dumps.
C.Stop the instance and create an EBS snapshot for memory analysis.
D.Use the EC2 console to take a screenshot and capture memory from the hypervisor.
AnswerA

AWS Systems Manager Run Command is the correct approach because it can execute a script on the running EC2 instance through the SSM agent, installing the LiME kernel module and dumping the full contents of volatile memory to a file. The acquired memory image can then be uploaded to S3 for forensic analysis. Unlike other methods, Run Command works while the instance remains powered on, which is essential because memory is lost the moment the instance is stopped or rebooted. It also provides fine-grained IAM permissions and a complete audit trail of the command invocation.

Why this answer

AWS Systems Manager Run Command allows you to execute a script on a running EC2 instance without needing SSH access, and LiME (Linux Memory Extractor) is a trusted tool for capturing volatile memory. This approach preserves the memory state for forensic analysis while maintaining the instance's running state, which is critical for incident response.

Exam trap

The trap here is that candidates confuse memory capture with disk capture, assuming an EBS snapshot or Inspector can retrieve volatile data, when in fact only a tool like LiME executed on the running instance can capture RAM.

How to eliminate wrong answers

Option B is wrong because Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and network exposures, not a tool for capturing memory dumps. Option C is wrong because stopping the instance and creating an EBS snapshot captures only disk data, not volatile memory (RAM), which is lost when the instance stops. Option D is wrong because the EC2 console screenshot captures only the display output, not the full memory contents, and the hypervisor does not expose a mechanism to capture a guest instance's RAM directly.

859
MCQeasy

A company wants to restrict access to an S3 bucket so that only requests from a specific VPC endpoint are allowed. Which S3 bucket policy condition key should be used?

A.aws:VpcSourceIp
B.aws:SourceVpc
C.aws:SourceVpce
D.aws:SourceIp
AnswerC

The aws:SourceVpce condition key is explicitly designed for VPC endpoints and lets you match the ID of the VPC endpoint through which the request was made, such as vpce-12345678. By placing a StringEquals condition in the bucket policy, you can allow access only when the request arrives via that exact endpoint. This satisfies the requirement to restrict access to a specific VPC endpoint, while all other traffic is implicitly denied.

Why this answer

To restrict access to an S3 bucket so that only requests originating from a specific VPC endpoint are allowed, you must use the `aws:SourceVpce` condition key in the S3 bucket policy. This key evaluates the VPC endpoint ID (e.g., `vpce-1a2b3c4d`) of the request, ensuring that only traffic routed through that specific endpoint is granted access. The `aws:SourceVpc` key is used to restrict access based on the VPC ID, not the endpoint ID, and `aws:SourceIp` and `aws:VpcSourceIp` are not valid condition keys for VPC endpoint-based restrictions.

Exam trap

The trap here is that candidates often confuse `aws:SourceVpc` (which restricts by VPC ID) with `aws:SourceVpce` (which restricts by VPC endpoint ID), leading them to select the wrong condition key when the requirement is specifically to allow only traffic from a particular VPC endpoint.

How to eliminate wrong answers

Option A is wrong because `aws:VpcSourceIp` is not a valid AWS condition key; the correct key for source IP is `aws:SourceIp`, and it does not restrict based on VPC endpoint. Option B is wrong because `aws:SourceVpc` restricts access based on the VPC ID (e.g., `vpc-12345678`), not the specific VPC endpoint ID, so it would allow any traffic from within that VPC, not just through the endpoint. Option D is wrong because `aws:SourceIp` restricts based on the client's IP address, which is not suitable for VPC endpoint-based access control since the endpoint uses private IPs and the condition key cannot enforce endpoint-specific restrictions.

860
MCQmedium

A company is using AWS KMS to encrypt data in Amazon S3. The security team wants to ensure that only a specific IAM role can decrypt the data. What is the MOST secure way to enforce this?

A.Attach an IAM policy to the role granting kms:Decrypt
B.Configure the KMS key policy with a condition that allows only the role to decrypt
C.Disable the KMS key and re-enable it only when the role needs to decrypt
D.Configure an S3 bucket policy that denies all principals except the role
AnswerB

A KMS key policy is the resource-based policy that ultimately defines which principals are allowed to use the key. By adding a condition such as aws:PrincipalArn to the kms:Decrypt action, you can limit the permission to a specific IAM role ARN, ensuring that no other principal can invoke decrypt even if they have IAM permissions. The key policy, not IAM, is the controlling restriction here. Always include a statement allowing the account root user to administer the key so you don't lock yourself out.

Why this answer

AWS KMS key policies are the primary resource-based access control for a KMS key. To ensure only a specific IAM role can decrypt, the key policy must explicitly allow that role (and no other principals) for kms:Decrypt, optionally with conditions. IAM policies alone cannot grant access to a KMS key unless the key policy also permits it, making the key policy the authoritative enforcement point.

Exam trap

SCS-C02 often tests the misconception that an IAM policy alone can grant KMS decrypt access, when in fact the KMS key policy must also allow the principal — key policy is the gatekeeper.

How to eliminate wrong answers

Option A is wrong because an IAM policy granting kms:Decrypt is necessary but not sufficient — the KMS key policy must also allow the principal, otherwise access is denied. Option C is wrong because disabling and re-enabling a KMS key is operationally disruptive, does not provide fine-grained per-role control, and can break dependent services; it is not an access-control mechanism. Option D is wrong because an S3 bucket policy controls access to S3 objects/API actions, not to KMS cryptographic operations; it cannot directly restrict who can call kms:Decrypt.

861
MCQeasy

A security engineer is investigating a potential compromise of an EC2 instance. The engineer wants to capture memory and disk forensics without shutting down the instance. Which service should the engineer use?

A.AWS Config
B.AWS Systems Manager
C.EC2 Instance Connect
D.Amazon CloudWatch Logs
AnswerB

AWS Systems Manager, especially via Run Command and Session Manager, gives you a controlled, auditable channel to execute arbitrary scripts on EC2 instances without opening SSH or RDP. You can run built-in SSM documents or custom scripts to capture memory dumps, collect disk evidence, and pull system logs for an investigation. Its agent is already installed on many instances, making it the standard tool for on-host forensic collection.

Why this answer

AWS Systems Manager (SSM) is the correct service because it provides the capability to perform forensic data collection on a running EC2 instance without shutting it down. Specifically, SSM Automation documents like AWS-RunShellScript or AWS-GatherEC2InstanceInfo can execute commands to capture memory (e.g., using LiME or fmem) and disk forensics (e.g., dd or volume snapshots) via the SSM Agent, which runs as a system service and does not require instance termination.

Exam trap

The trap here is that candidates may confuse AWS Systems Manager with EC2 Instance Connect, thinking that SSH access alone is sufficient for forensic collection, but Systems Manager provides the necessary automation and agent-based execution to capture memory and disk data without requiring the instance to be stopped or terminated.

How to eliminate wrong answers

Option A is wrong because AWS Config is a service for resource inventory, compliance auditing, and configuration change tracking, not for capturing memory or disk forensics on a running instance. Option C is wrong because EC2 Instance Connect only provides SSH access to the instance for interactive shell sessions; it does not have built-in capabilities to capture memory dumps or perform disk forensics without additional tools and manual intervention. Option D is wrong because Amazon CloudWatch Logs is a service for collecting, monitoring, and storing log files from EC2 instances and other sources; it cannot capture memory or disk forensics data directly.

862
Multi-Selecthard

Which THREE are best practices for managing security in a multi-account AWS environment? (Choose three.)

Select 3 answers
A.Use SCPs to restrict permissions across accounts.
B.Disable AWS CloudTrail in production accounts to reduce costs.
C.Use a dedicated security account for security tools and audits.
D.Centralize logging in a dedicated security account.
E.Use the root user of each account for administrative tasks.
AnswersA, C, D

SCPs provide central control over every account's permissions by acting as a permission filter on all IAM principals in AWS Organizations' organizational units. They can deny services or actions even if the account's own IAM policies allow them, but they do not grant access themselves; instead, SCPs set a boundary that effects only the accounts they are attached to, ensuring that even root users of member accounts cannot perform unauthorized operations.

Why this answer

Option A is correct because AWS Organizations Service Control Policies (SCPs) are applied at the OU or account level and set the maximum available permissions for all IAM principals in member accounts, providing a centralized guardrail to restrict permissions across accounts. Option C is correct because a dedicated security account isolates security tooling (such as GuardDuty, Security Hub, and IAM Access Analyzer) and audit activities from production workloads, following AWS's recommended multi-account security structure. Option D is correct because centralizing logs in a dedicated security account (often via AWS Organizations CloudTrail organization trails and cross-account log destinations) protects audit data from tampering by account owners and enables unified monitoring and retention.

Option B is incorrect because disabling CloudTrail removes the audit trail needed for incident response, compliance, and forensics; CloudTrail is a foundational detective control, not an optional cost to cut. Option E is incorrect because the root user has unrestricted access that cannot be limited by SCPs or IAM policies, so it should be locked away with MFA and never used for routine administrative tasks; least-privilege IAM roles or federated identities should be used instead.

Exam trap

SCS-C02 often tests the misconception that cost optimization justifies disabling CloudTrail or that root user access is acceptable for admin tasks — both are anti-patterns that violate core security best practices.

863
MCQeasy

A company wants to centrally manage access keys for all IAM users across multiple accounts. Which AWS service should be used to rotate access keys automatically?

A.AWS STS
B.AWS IAM
C.AWS Secrets Manager
D.AWS CloudHSM
AnswerB

AWS IAM is the only service that owns the lifecycle of IAM user access keys through CreateAccessKey, UpdateAccessKey, and DeleteAccessKey APIs. Because IAM does not provide built-in scheduling for rotation, central management must be implemented as custom automation (for example, a Lambda function invoked by Amazon EventBridge) that rotates keys across accounts using IAM APIs. IAM also tracks access key status and last-used metadata, which supports a central auditing and rotation process.

Why this answer

AWS IAM is the service that manages IAM users and access keys. While there is no built-in automatic rotation feature in IAM, you can automate access key rotation using IAM APIs or the AWS CLI. Among the given options, AWS IAM is the correct choice because it directly handles access keys.

AWS STS provides temporary credentials, not access key management. AWS Secrets Manager can store secrets but cannot automatically rotate IAM access keys. AWS CloudHSM is for hardware-based cryptographic key storage.

864
Multi-Selectmedium

Which TWO of the following are valid ways to control inbound traffic to an EC2 instance? (Select TWO.)

Select 2 answers
A.Network ACLs
B.IAM policies
C.Amazon CloudWatch alarms
D.AWS Key Management Service (KMS)
E.Security groups
AnswersA, E

Network ACLs are stateless virtual firewalls applied at the subnet boundary. They evaluate inbound and outbound traffic against an ordered set of allow and deny rules based on source/destination IP, port, and protocol, with the first matching rule winning. Because NACLs are stateless, an inbound connection's return packets must be explicitly allowed by a matching outbound rule. This makes them an effective subnet-level control for blocking unwanted inbound traffic before it reaches any instance.

Why this answer

Network ACLs (NACLs) are a valid method to control inbound traffic to an EC2 instance because they act as a stateless firewall at the subnet level. Each NACL rule evaluates inbound traffic based on source IP, protocol, and port, and rules are processed in order from lowest to highest number. Since NACLs are stateless, you must explicitly allow both inbound and outbound traffic for a response to return.

Exam trap

The trap here is that candidates often confuse IAM policies with network-level controls, mistakenly thinking IAM can filter traffic, or they assume CloudWatch alarms can block traffic when they only trigger notifications or auto-scaling actions.

865
MCQmedium

A security engineer receives an Amazon GuardDuty finding for 'UnauthorizedAccess:EC2/SSHBruteForce'. The engineer needs to automatically isolate the compromised EC2 instance and then perform forensic analysis. Which solution meets these requirements with the LEAST operational overhead?

A.Manually SSH into the instance, stop it, and create an AMI for analysis.
B.Create an Amazon EventBridge rule that triggers an AWS Lambda function to isolate the instance by modifying its security group and then take a forensic snapshot.
C.Use AWS Config rules to automatically stop the instance.
D.Configure an Auto Scaling lifecycle hook to terminate the instance and launch a new one.
AnswerB

This is the correct response because Amazon EventBridge can be configured to receive GuardDuty findings as events, triggering a Lambda function for immediate, automated response. The Lambda function can modify the instance's security group to deny all ingress and egress traffic, effectively isolating it while preserving the running state and memory for analysis. A subsequent snapshot of the EBS volumes provides a forensically sound copy for offline investigation, all without manual intervention or risk of contaminating the evidence.

Why this answer

It automates the isolation and forensic capture of the compromised EC2 instance with minimal operational overhead. An Amazon EventBridge rule listens for the specific GuardDuty finding and triggers an AWS Lambda function that modifies the instance's security group to deny all inbound/outbound traffic (isolation) and then creates an EBS snapshot for forensic analysis. This serverless, event-driven approach eliminates manual intervention and ensures consistent, rapid response.

Exam trap

The trap here is that candidates may assume manual SSH or AWS Config rules are sufficient for incident response, but they fail to recognize that GuardDuty findings require automated, event-driven isolation without human intervention, and that Config rules lack the ability to trigger real-time security group modifications or snapshots.

How to eliminate wrong answers

Option A is wrong because manually SSHing into a compromised instance is dangerous (the attacker may still have access), and manually stopping and creating an AMI introduces high operational overhead and delays, violating the 'least operational overhead' requirement. Option C is wrong because AWS Config rules are designed for compliance and resource configuration auditing, not for real-time incident response actions like stopping instances; they cannot directly trigger instance isolation based on GuardDuty findings. Option D is wrong because an Auto Scaling lifecycle hook terminates the instance and launches a new one, which destroys forensic evidence and does not allow for isolation or forensic analysis of the original compromised instance.

866
MCQmedium

A security engineer needs to detect when an EC2 instance is terminated in an AWS account. The solution must provide near-real-time notification. Which combination of services should be used?

A.VPC Flow Logs and Amazon CloudWatch Logs
B.AWS CloudTrail and Amazon EventBridge
C.AWS Config and Amazon SNS
D.Amazon CloudWatch Alarms and Amazon SNS
AnswerB

AWS CloudTrail is the correct service here because it records management events as API calls, including the TerminateInstances action, with details such as the IAM principal, source IP, and request parameters. Amazon EventBridge can consume CloudTrail API events through a rule that matches source=aws.ec2 and eventName=TerminateInstances, then trigger an SNS topic or Lambda function within seconds. This gives a near-real-time, audit-ready detection path that is directly tied to the API request that caused the termination.

Why this answer

AWS CloudTrail captures API calls, including TerminateInstances, as management events. Amazon EventBridge can filter these events in near real-time and trigger a notification action (e.g., via SNS or Lambda). This combination provides immediate detection of EC2 termination without polling or delays.

Exam trap

The trap here is that candidates often confuse CloudWatch Alarms (which monitor metrics) with event-driven services like EventBridge, failing to recognize that EC2 termination is an API event, not a metric change, and thus requires CloudTrail as the event source.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) and are not designed to detect EC2 instance lifecycle events like termination; they lack the API-level visibility needed. Option C is wrong because AWS Config evaluates resource configuration changes against rules and typically delivers results with a delay (minutes to hours), not near-real-time, and it is not optimized for event-driven notification of a single termination action. Option D is wrong because CloudWatch Alarms monitor metric thresholds (e.g., CPU utilization) and cannot directly detect the termination of an EC2 instance; they would require a custom metric or a proxy signal, which adds latency and complexity.

867
MCQhard

An organization wants to detect and alert on the use of root user credentials in their AWS accounts. They have multiple accounts managed via AWS Organizations. What is the most efficient way to centralize this monitoring?

A.Create an AWS CloudTrail trail in each account and aggregate logs to a central S3 bucket.
B.Use IAM Access Analyzer to find resources shared with external entities.
C.Use AWS Config rules to detect root user usage in each account.
D.Enable Amazon GuardDuty in the management account and use the delegated administrator feature.
AnswerD

Enabling GuardDuty in the management account and designating a delegated administrator lets one account manage GuardDuty for all member accounts in the organization, aggregating findings centrally. GuardDuty uses integrated threat intelligence and anomaly detection to analyze CloudTrail management events, VPC flow logs, and DNS logs, generating a specific finding type when root user credentials are used anomalously, such as 'UnauthorizedAccess:IAMUser/RootCredentialUsage'. This provides cross-account visibility and built-in detection without needing to build custom log-analysis pipelines in each account.

Why this answer

Amazon GuardDuty, when enabled in the management account with a delegated administrator, can centrally monitor and detect suspicious activity—including root user credential usage—across all member accounts in AWS Organizations. This approach eliminates the need to configure per-account monitoring and provides a single pane of glass for security alerts, making it the most efficient centralized solution.

Exam trap

The trap here is that candidates often assume CloudTrail or AWS Config are sufficient for monitoring root user usage, but they overlook GuardDuty's purpose-built, centralized detection capability for security events like root credential usage across multi-account environments.

How to eliminate wrong answers

Option A is wrong because while aggregating CloudTrail logs to a central S3 bucket enables log storage, it does not provide built-in alerting or detection for root user usage; you would need additional services (e.g., Amazon Athena, Lambda) to parse and alert on root activity, which is less efficient than GuardDuty's native detection. Option B is wrong because IAM Access Analyzer is designed to identify resources shared with external entities (e.g., S3 buckets, KMS keys) and does not monitor or alert on root user credential usage. Option C is wrong because AWS Config rules can evaluate resource configurations but cannot directly detect root user login events; root usage is an API call event, not a configuration state, and Config lacks native real-time alerting for such activity.

868
Multi-Selecthard

A company wants to implement least privilege access for a data analytics team that uses Amazon Athena to query data in S3. Which THREE steps should be taken?

Select 3 answers
A.Grant full S3 access to all buckets
B.Grant write access to an S3 bucket for query results
C.Grant access to Amazon Redshift
D.Grant permissions to use Athena workgroups and queries
E.Grant read access to the specific S3 buckets containing the data
AnswersB, D, E

When Athena executes a query, it writes the query results, metadata, and any converted data to a designated S3 location, typically the workgroup's result bucket. Granting write access (for example s3:PutObject and s3:GetObject) to that bucket is a required part of the permission set. Without this, Athena fails with an access denied error after the query runs even if the data was read successfully.

Why this answer

Athena requires a dedicated S3 bucket to store query results, and granting write access to that specific bucket ensures the service can write output without exposing other data. This aligns with least privilege by limiting write permissions to only the necessary location.

Exam trap

The trap here is that candidates often assume Athena requires broad S3 permissions or confuse it with Redshift Spectrum, leading them to select full S3 access or irrelevant Redshift permissions instead of focusing on the specific read and write buckets needed for least privilege.

869
Multi-Selecthard

A company wants to monitor for unauthorized API calls in real-time. The solution must meet the following requirements: - Detect calls that fail authentication (AccessDenied). - Detect calls that use a revoked IAM role. - Provide a centralized view across multiple accounts. Which THREE services should be used together to implement this solution? (Choose three.)

Select 3 answers
A.AWS Organizations
B.AWS CloudTrail
C.AWS IAM Access Analyzer
D.Amazon CloudWatch Logs
E.AWS Config
AnswersA, B, D

AWS Organizations is the correct answer because it lets you create a single organization trail in CloudTrail that captures API activity for every member account, including new accounts as they join. By aggregating all trails centrally, you gain a complete audit baseline and can enforce a trail that member accounts cannot disable or modify, preventing gaps in monitoring. This makes Organizations essential for managing and protecting your organization-wide API monitoring infrastructure.

Why this answer

AWS Organizations is correct because it enables centralized management of multiple AWS accounts, allowing the solution to aggregate CloudTrail logs from all accounts into a single CloudWatch Logs group. This centralization is essential for real-time monitoring of unauthorized API calls across the entire organization, as CloudTrail logs record all API activity including AccessDenied errors and actions taken by revoked IAM roles.

Exam trap

The trap here is that candidates often confuse AWS IAM Access Analyzer with CloudTrail for monitoring API calls, but Access Analyzer only analyzes resource policies for external access, not real-time API activity or authentication failures.

870
MCQhard

A company uses Amazon EBS volumes for EC2 instances. Security policy requires that all EBS volumes be encrypted at rest. The company already has a default KMS key for EBS encryption. However, some new volumes are created without encryption. What is the most efficient way to enforce encryption for all new EBS volumes?

A.Use AWS CloudTrail to monitor volume creation and send alerts
B.Create an AWS Config rule to detect unencrypted volumes and trigger a Lambda function to encrypt them
C.Use a custom AMI that enforces encryption
D.Enable EBS encryption by default in the EC2 console or via the API
AnswerD

Enable EBS encryption by default at the account or region level, either through the EC2 console or the API (EnableEbsEncryptionByDefault). This setting automatically encrypts all newly created volumes, snapshots, and volumes created from those snapshots, using either the default AWS-managed key or a custom KMS key you specify. Because it is enforced at creation time, it is a preventive control that eliminates the risk of accidentally leaving new volumes unencrypted, which is exactly what the security requirement demands.

Why this answer

Enabling EBS encryption by default in the EC2 console or via the API (EnableEbsEncryptionByDefault) ensures that every new EBS volume created in the region is automatically encrypted with the specified KMS key, without requiring any per-volume action or custom tooling. This is the most efficient, native enforcement mechanism because it operates at the account/region level and applies to all volume creation paths, including those from AMIs, snapshots, and instance launches.

Exam trap

SCS-C02 often tests whether candidates choose detective/corrective controls (Config + Lambda, CloudTrail alerts) over the native preventive control (EBS encryption by default), which is simpler and more efficient.

How to eliminate wrong answers

Option A is wrong because CloudTrail only records API activity for auditing — it can detect that an unencrypted volume was created but cannot prevent or remediate it, and alerting is reactive rather than preventive. Option B is wrong because an AWS Config rule with a Lambda remediation function is a detective-and-corrective control that adds latency and complexity; it also requires custom code and does not prevent the unencrypted volume from existing temporarily. Option C is wrong because a custom AMI only enforces encryption for volumes created from that specific AMI — it does not cover volumes created by other means (e.g., from snapshots, other AMIs, or direct volume creation), leaving gaps in enforcement.

871
MCQhard

A company is designing a VPC with public and private subnets. The application servers in the private subnets need to download patches from the internet. Which architecture provides the highest security while allowing internet access?

A.Place a NAT Gateway in the public subnet and configure the private subnet route table to send 0.0.0.0/0 traffic to the NAT Gateway
B.Create a VPC endpoint for Amazon S3 and route traffic through it
C.Attach an internet gateway to the private subnet and configure the route table to send 0.0.0.0/0 traffic to the internet gateway
D.Place a bastion host in the public subnet and configure the private instances to route internet traffic through it
AnswerA

The NAT Gateway is deployed in a public subnet with an Elastic IP and performs source network address translation for instances in private subnets. Outbound packets are sent to the NAT Gateway via the 0.0.0.0/0 route, and return traffic is delivered back through the same stateful translation. Because private instances lack public IPs and the route table points to the NAT Gateway rather than an internet gateway, unsolicited inbound connections cannot reach them, making this the standard design for outbound-only internet access.

Why this answer

A NAT Gateway in a public subnet allows instances in private subnets to initiate outbound traffic to the internet (e.g., for patch downloads) while preventing any unsolicited inbound traffic from the internet. The private subnet route table sends 0.0.0.0/0 traffic to the NAT Gateway, which then forwards it through the Internet Gateway (IGW) attached to the VPC. This provides the highest security because the private instances remain unreachable from the internet, unlike using an IGW directly or a bastion host for routing.

Exam trap

The trap here is that candidates often confuse a bastion host (for administrative access) with a NAT device (for outbound internet routing), or incorrectly assume that a VPC endpoint can provide general internet access instead of just private connectivity to specific AWS services.

How to eliminate wrong answers

Option B is wrong because a VPC endpoint for Amazon S3 only provides private connectivity to S3, not general internet access for downloading patches from arbitrary internet sources. Option C is wrong because attaching an Internet Gateway directly to a private subnet and routing 0.0.0.0/0 traffic to it would make the subnet effectively public, exposing instances to unsolicited inbound traffic and defeating the purpose of a private subnet. Option D is wrong because a bastion host is designed for secure administrative access (SSH/RDP) to private instances, not for routing general internet traffic; using it as a NAT would create a single point of failure, performance bottleneck, and security risk due to its management plane exposure.

872
MCQhard

A company wants to monitor AWS API calls for suspicious activity and automatically remediate by revoking IAM roles in real time. Which combination of services should be used?

A.AWS CloudTrail and Amazon Inspector
B.AWS CloudTrail and AWS Config
C.Amazon GuardDuty and AWS Config
D.Amazon CloudWatch Events and AWS Lambda
AnswerD

By creating a CloudWatch Events rule with an event pattern matching specific AWS API calls recorded by CloudTrail, organizations can invoke a Lambda function in real time to conduct security actions such as revoking IAM roles, deleting access keys, or restricting permissions. This event-driven model delivers immediate, automated remediation of suspicious API activity, satisfying the requirement.

Why this answer

The combination of Amazon CloudWatch Events and AWS Lambda enables real-time monitoring and automated remediation of AWS API calls. CloudWatch Events can capture API calls from AWS CloudTrail (or other sources) and trigger a Lambda function to revoke IAM roles based on suspicious activity patterns, providing the required real-time response.

Exam trap

The trap here is that candidates may confuse AWS Config's compliance evaluation with real-time event-driven remediation, or assume GuardDuty alone provides automated remediation, when in fact both require CloudWatch Events and Lambda for the actual automated response.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability assessment service that scans for software vulnerabilities and network exposures, not a real-time API monitoring or remediation service. Option B is wrong because AWS Config is a configuration auditing and compliance service that evaluates resource configurations against rules, not designed for real-time API call monitoring or automated IAM role revocation. Option C is wrong because while Amazon GuardDuty can detect suspicious API activity, AWS Config is not the appropriate service for real-time remediation; GuardDuty findings typically trigger CloudWatch Events or Lambda for automated response, not AWS Config.

873
MCQhard

A company uses an AWS Transit Gateway to connect multiple VPCs and on-premises networks. A security engineer needs to ensure that traffic between VPCs is inspected by a third-party firewall appliance. Which architecture should be used?

A.Configure security groups on the transit gateway to inspect traffic.
B.Create VPC endpoints for each VPC to route traffic through the firewall.
C.Attach the firewall appliance to a dedicated inspection VPC and route traffic from other VPCs through the inspection VPC using transit gateway route tables.
D.Use network ACLs on the transit gateway to filter traffic.
AnswerC

This is the standard centralized inspection architecture: deploy the firewall appliance in a dedicated inspection VPC and attach that VPC to the transit gateway, then use separate transit gateway route tables to force all traffic from spoke VPCs to route to the inspection VPC before it proceeds to other attachments. The inspection VPC must also have route tables that forward traffic back to the transit gateway toward the final destination, enabling asymmetric return-path handling and stateful inspection. This design works because the transit gateway routes based on its route tables, so the firewall becomes an inline bump-in-the-wire for all inter-VPC traffic while maintaining a single control point.

Why this answer

It uses a dedicated inspection VPC as a central point for traffic inspection. By attaching the third-party firewall appliance to this inspection VPC and manipulating transit gateway route tables, you can force all inter-VPC traffic to be routed through the firewall for inspection. This architecture leverages the transit gateway's ability to route traffic between attachments based on route table entries, enabling centralized security enforcement without modifying individual VPC routing.

Exam trap

The trap here is that candidates often confuse transit gateway capabilities with VPC-level constructs like security groups or network ACLs, assuming they can be applied directly to the transit gateway, when in fact transit gateway traffic inspection requires a separate inspection VPC architecture.

How to eliminate wrong answers

Option A is wrong because security groups are stateful firewalls applied at the instance or elastic network interface level, not on transit gateways; transit gateways do not support security groups. Option B is wrong because VPC endpoints (Gateway Endpoints or Interface Endpoints) are used for private connectivity to AWS services (e.g., S3, DynamoDB) and cannot route general inter-VPC traffic through a third-party firewall. Option D is wrong because network ACLs are stateless firewalls applied at the subnet level, not on transit gateways; transit gateways do not support network ACLs.

874
MCQmedium

An IAM user has the policy shown in the exhibit. The user tries to launch an m5.large instance in us-east-1, but gets an 'AccessDenied' error. Why does this happen?

A.The policy restricts RunInstances to instance type t2.micro, but the user requested m5.large.
B.The condition uses StringEquals, which is case-sensitive and the instance type is in the wrong case.
C.The policy does not allow the RunInstances action at all.
D.The resource ARN in the policy is incorrect for launching instances.
AnswerA

The policy grants RunInstances only when the ec2:InstanceType condition key exactly equals t2.micro, so a request for m5.large does not satisfy the condition and is implicitly denied. IAM evaluation requires an explicit Allow to match all parts of the request—action, resource, and condition—and because the condition fails here, the request falls through to the default deny, producing AccessDenied. This is the correct explanation because the user did have permission to launch instances, but only for the specific instance type t2.micro, not m5.large.

Why this answer

The IAM policy's RunInstances statement includes a condition that restricts the allowed instance type (likely ec2:InstanceType StringEquals t2.micro). Because the user requested m5.large, the condition evaluates false and the Allow does not apply, resulting in an implicit deny and AccessDenied.

Exam trap

SCS-C02 often tests the misconception that AccessDenied always means the action is missing — candidates overlook that a condition inside an Allow statement can silently block the request, producing the same error as an explicit deny.

How to eliminate wrong answers

Option B is wrong because StringEquals is indeed case-sensitive, but the instance type 'm5.large' is already in the correct lowercase format — case is not the issue here. Option C is wrong because the policy does allow RunInstances; the deny is caused by the condition, not by the absence of the action. Option D is wrong because the resource ARN for RunInstances (typically '*' or an instance ARN) is not the cause — the failure is driven by the instance-type condition, not the resource element.

875
MCQeasy

A company has a VPC with public and private subnets. The private subnets need to access the internet for software updates. Which AWS service provides a managed, highly available, and scalable solution for this requirement?

A.NAT instance in a public subnet
B.Internet Gateway attached to the VPC
C.NAT Gateway in a public subnet
D.AWS Site-to-Site VPN connection
AnswerC

A NAT Gateway is a fully managed service placed in a public subnet with an Elastic IP, and it automatically scales throughput and is highly available when deployed in multiple Availability Zones. It allows instances in private subnets to initiate outbound internet sessions by translating their private source addresses to the gateway's public address, while preventing inbound connections from the internet. This directly satisfies the need for managed, scalable internet egress for the private workload.

Why this answer

A NAT Gateway is a managed AWS service that provides outbound-only internet access for instances in private subnets. It is highly available within an Availability Zone (AZ) and scales automatically up to 45 Gbps, making it the ideal solution for private subnet internet access without the management overhead of a NAT instance.

Exam trap

The trap here is that candidates often confuse a NAT Gateway with a NAT instance, thinking the instance is more flexible or cheaper, but they overlook the managed, highly available, and scalable nature of the NAT Gateway that directly addresses the requirement without operational overhead.

How to eliminate wrong answers

Option A is wrong because a NAT instance is a single EC2 instance that you must manage, patch, and configure for high availability (e.g., using an Auto Scaling group with a script), and it does not provide the same managed scalability or automatic failover as a NAT Gateway. Option B is wrong because an Internet Gateway (IGW) allows bidirectional traffic; attaching it to a VPC and routing private subnets to it would expose those instances to inbound internet traffic, violating the requirement for private subnets that should only initiate outbound connections. Option D is wrong because an AWS Site-to-Site VPN connects your VPC to an on-premises network over the internet, not to the public internet for software updates; it is designed for hybrid connectivity, not outbound internet access for private subnets.

876
MCQhard

A security engineer notices that an IAM role has a trust policy that allows 'sts:AssumeRole' from any AWS account. What is the security risk?

A.The role can be assumed by any AWS service.
B.The role's permissions are exposed to all AWS accounts.
C.Any IAM user in any AWS account can assume the role and gain its permissions.
D.The role can be used to access resources in other accounts.
AnswerC

Because the trust policy allows 'sts:AssumeRole' from any principal (often expressed as 'Principal': '*'), any IAM user in any AWS account can call the STS API to assume this role. Upon successful assumption, AWS returns temporary credentials bound to the role's permission policy, so the user gains whatever access that policy grants. This is precisely the overly permissive condition that makes the role dangerous.

Why this answer

A trust policy with a Principal of "*" (or an account root without conditions) allows sts:AssumeRole from any AWS account, meaning any IAM principal in any account that knows the role ARN can call AssumeRole and obtain temporary credentials scoped to that role's permissions. This is a classic cross-account confused-deputy vulnerability: the role's identity-based policies determine what the assumer can do, so the blast radius is exactly the role's permissions. The risk is not that permissions are 'exposed' in a read sense, but that they can be actively exercised by untrusted external principals.

Exam trap

SCS-C02 often tests the misconception that a wildcard Principal in a trust policy grants service access or exposes permissions, when the actual risk is that any external IAM principal can assume the role and exercise its permissions.

How to eliminate wrong answers

Option A is wrong because a trust policy controls which principals may call sts:AssumeRole, not which AWS services can use the role — service principals must be explicitly listed (e.g., ec2.amazonaws.com) and a wildcard principal does not grant service-linked usage. Option B is wrong because permissions are not 'exposed' passively; IAM policies are not readable by other accounts, and the actual risk is unauthorized assumption and use of the role's permissions, not visibility of the policy. Option D is wrong because the role's ability to access resources in other accounts depends on the role's identity-based policies and those accounts' resource policies — the trust policy alone does not grant cross-account resource access, and the question asks about the risk of the trust policy itself.

877
Multi-Selecteasy

Which TWO are valid methods to centrally manage multiple AWS accounts? (Choose two.)

Select 2 answers
A.AWS IAM
B.AWS Service Catalog
C.Amazon Cognito
D.AWS Control Tower
E.AWS Organizations
AnswersD, E

AWS Control Tower is the correct answer because it provides a centralized governance solution specifically for multi-account environments. It automatically sets up a landing zone, provisions accounts through an account factory, and applies preventive and detective guardrails using AWS Organizations and IAM under the hood. Control Tower gives you a single pane of glass for managing account structure and compliance.

Why this answer

AWS Control Tower (D) is correct because it provides a centralized landing zone that automates the setup of a multi-account AWS environment using AWS Organizations, IAM Identity Center, and guardrails (preventive and detective controls) to govern accounts at scale. AWS Organizations (E) is correct because it is the foundational service for centrally managing multiple AWS accounts, allowing consolidated billing, organizational units (OUs), service control policies (SCPs), and centralized policy-based governance across accounts. AWS IAM (A) is not correct because it manages users, groups, roles, and permissions within a single AWS account (or via roles across accounts), not centralized multi-account governance.

AWS Service Catalog (B) is not correct because it lets administrators create and manage approved IT service portfolios for end users, but it does not itself centrally manage multiple AWS accounts. Amazon Cognito (C) is not correct because it provides identity, authentication, and authorization for web and mobile applications, not multi-account AWS management.

Exam trap

SCS-C02 often tests the confusion between IAM (single-account identity) and Organizations/Control Tower (multi-account governance), tempting candidates to pick IAM for central management.

878
MCQhard

A company is using Amazon Macie to discover sensitive data in S3. The security team wants to be notified when Macie finds a high-severity alert. Which integration should be used?

A.Configure Macie to store findings in an S3 bucket and enable S3 event notifications.
B.Integrate Macie with AWS Security Hub and create a custom action to send to SNS.
C.Create an Amazon EventBridge rule that matches Macie findings and targets an SNS topic.
D.Configure Macie to send findings to CloudWatch Logs and create a metric filter.
AnswerC

Macie automatically publishes every finding to Amazon EventBridge as a 'Macie Finding' event on the default event bus. An EventBridge rule with an event pattern matching source 'aws.macie' and detail-type 'Macie Finding' can route to an SNS topic in near real time. This is the native integration path, requiring no additional services, custom code, or intermediate storage.

Why this answer

Amazon EventBridge can directly capture Macie findings (which are emitted as events) and route them to an SNS topic for notification. This is the native, event-driven integration that requires no intermediate storage or custom actions, making it the simplest and most reliable approach for real-time alerting on high-severity findings.

Exam trap

The trap here is that candidates often assume Macie findings must go through Security Hub or CloudWatch first, but EventBridge is the native event bus for all AWS services including Macie, and it directly supports SNS as a target without custom actions.

How to eliminate wrong answers

Option A is wrong because Macie does not natively store findings in an S3 bucket; findings are stored in Macie itself or can be exported via a separate process, and S3 event notifications would not trigger on Macie findings directly. Option B is wrong because while Macie integrates with Security Hub, creating a custom action in Security Hub to send to SNS adds unnecessary complexity and latency; EventBridge is the direct integration point for Macie events. Option D is wrong because Macie does not send findings to CloudWatch Logs natively; you would need a custom solution to forward them, and metric filters are for log pattern matching, not for triggering notifications on structured findings.

879
MCQmedium

A company wants to securely share an Amazon S3 object with an external partner. The partner needs to download the object using an HTTP GET request. The object must be accessible for only 24 hours. What is the most secure way to grant access?

A.Create a new IAM user with read access to the object and share the access key and secret key.
B.Make the object publicly readable and share the object URL.
C.Generate a presigned URL for the object with an expiration of 24 hours.
D.Create a new IAM user with read access to the object, then generate a presigned URL for the object.
AnswerC

A presigned URL is generated by using AWS Signature Version 4 to sign a request for a specific S3 object action, such as GetObject, using the caller's credentials. With a 24-hour expiration, the embedded X-Amz-Expires parameter causes S3 to reject the URL after one day, so the recipient never needs the IAM user's actual secret key. The underlying object stays private because access still passes through S3's authorization layer; the URL only carries the cryptographic signature that proves the request was authorized.

Why this answer

A presigned URL grants time-limited, secure access to a specific S3 object without exposing AWS credentials. The partner can download the object via HTTP GET within the 24-hour expiration window. Option A is incorrect because sharing IAM user credentials is insecure and provides broader access than needed.

Option B is incorrect because making the object public exposes it to anyone, violating security. Option D is incorrect because creating an IAM user is unnecessary; the presigned URL alone provides the required access, and adding a user credential undermines security.

880
MCQmedium

A company uses AWS CloudHSM to store encryption keys. The security team wants to ensure that keys stored in CloudHSM are backed up and can be restored in another AWS Region. What is the BEST approach?

A.Enable automatic cross-region replication on the CloudHSM cluster
B.Copy the HSM user credentials and use them in the new region
C.Use AWS Backup to back up the CloudHSM cluster and restore in another region
D.Export the security domain from the source cluster and import it into a new cluster in the target region
AnswerD

The security domain is the encrypted root-of-trust material generated when a CloudHSM cluster is initialized, and it is required to decrypt cluster backups and recover the keys stored in the HSM. By exporting the security domain from the source cluster and importing or supplying it during the initialization of a new cluster in the target region, you give the new cluster the ability to unlock the restored backup and retrieve the original key material. This is the correct disaster-recovery action, and it must be paired with copying and restoring a CloudHSM backup to that region.

Why this answer

AWS CloudHSM allows you to export the security domain from a source cluster, which contains the cryptographic material needed to back up and restore keys. You can then create a new CloudHSM cluster in the target region and import the security domain to restore the keys. Option A is incorrect because CloudHSM does not support automatic cross-region replication.

Option B is incorrect because HSM user credentials alone do not contain the key material; they are used for authentication, not backup. Option C is incorrect because AWS Backup does not integrate with CloudHSM to back up the cluster's keys.

881
MCQhard

A security engineer is configuring an automated incident response workflow. When a GuardDuty finding of type 'UnauthorizedAccess:EC2/SSHBruteForce' is generated, the workflow should isolate the EC2 instance and snapshot its EBS volume. Which AWS service can coordinate these actions?

A.AWS Lambda functions invoked sequentially
B.AWS Step Functions
C.AWS CloudFormation
D.AWS Config rules with auto-remediation
AnswerB

AWS Step Functions is the correct choice because it models incident response as a state machine, allowing you to coordinate Lambda, ECS, SNS, DynamoDB, and other services with explicit transitions, choice states, and parallel branches. Its durable execution records the state of each step, and built-in retry/timeout policies handle transient failures, while Standard Workflows support long-running processes such as waiting for a security analyst to approve a containment action. This gives you auditable, repeatable automation that remains maintainable as the response plan evolves.

Why this answer

AWS Step Functions is the correct service because it is designed to orchestrate multi-step workflows by coordinating AWS services like Lambda, EC2, and EBS snapshots in a defined state machine. For the given GuardDuty finding, Step Functions can receive the event, invoke a Lambda function to isolate the EC2 instance (e.g., modify security groups or attach a deny-all NACL), and then trigger another Lambda or direct API call to snapshot the EBS volume, all with built-in error handling, retries, and sequencing.

Exam trap

The trap here is that candidates confuse Lambda's ability to run code with the need for orchestration, overlooking that Step Functions provides the necessary state management, sequencing, and error handling for multi-step incident response workflows.

How to eliminate wrong answers

Option A is wrong because AWS Lambda functions invoked sequentially lack native orchestration features like branching, parallel execution, or built-in error handling; you would need to write custom code to chain them, which is less maintainable and not the recommended approach for complex workflows. Option C is wrong because AWS CloudFormation is an Infrastructure as Code (IaC) service for provisioning and managing resources, not for orchestrating real-time incident response actions triggered by GuardDuty findings. Option D is wrong because AWS Config rules with auto-remediation are designed for continuous compliance checks and corrective actions on resource configuration drift, not for responding to security findings like SSH brute force attempts; they cannot directly trigger an EC2 isolation and EBS snapshot workflow based on a GuardDuty finding.

882
Drag & Dropmedium

Drag and drop the steps to set up AWS Shield Advanced with automatic application layer DDoS mitigation in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Shield Advanced requires subscription first, then resource protection, WAF integration, mitigation rule, and health-based detection.

883
MCQmedium

A company uses an IAM role to allow an EC2 instance to access an S3 bucket. The instance is launched in a VPC with a VPC endpoint for S3. The IAM role has a policy that grants s3:GetObject on the bucket. However, the application on the instance receives 'Access Denied' errors when trying to read objects. What is the MOST likely cause?

A.The VPC endpoint policy for S3 does not allow the required action.
B.The EC2 instance does not have an encryption key to decrypt the objects.
C.The S3 bucket policy does not explicitly allow the IAM role.
D.The IAM role is not attached to the EC2 instance profile.
AnswerA

A VPC endpoint policy is an additional authorization boundary for S3 traffic routed through the gateway endpoint. Even when the IAM role explicitly allows s3:GetObject and the bucket policy permits the request, the endpoint policy must also allow the action; if it only allows s3:ListBucket or omits the operation, the request is denied. S3 evaluates the endpoint policy alongside the IAM role's permissions, and any missing allow from this policy results in AccessDenied.

Why this answer

When an EC2 instance accesses S3 through a VPC endpoint (gateway endpoint), both the IAM role policy and the VPC endpoint policy must allow the action. The default endpoint policy allows all, but if a custom policy restricts actions or resources, s3:GetObject can be denied even though the IAM role grants it. This is the most likely cause of the Access Denied error.

Exam trap

The trap is assuming IAM role permissions are sufficient — candidates forget that VPC endpoint policies act as an additional permission boundary, and a restrictive endpoint policy can silently block access even when IAM grants it.

How to eliminate wrong answers

Option B is wrong because encryption key access is governed by KMS permissions, and the error would typically mention KMS or be a different error code; also the scenario does not mention SSE-KMS. Option C is wrong because an S3 bucket policy does not need to explicitly allow the IAM role if the bucket is owned by the same account and the IAM policy grants access — IAM policies alone suffice unless the bucket policy explicitly denies. Option D is wrong because if the role were not attached to the instance profile, the instance would have no credentials at all, producing a different error (Unable to locate credentials), not Access Denied.

884
Drag & Dropmedium

Drag and drop the steps to implement AWS KMS key rotation in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Key rotation starts with creating a CMK, enabling auto-rotation, manual rotation if needed, updating apps, and verifying decryption.

885
MCQmedium

A company uses an Application Load Balancer (ALB) to distribute traffic to a fleet of EC2 instances in private subnets. The security team wants to ensure that only the ALB can communicate with the EC2 instances. Which security group configuration should be applied to the EC2 instances?

A.Allow inbound HTTP traffic from the EC2 instances' own security group
B.Allow inbound HTTP traffic from 0.0.0.0/0
C.Allow inbound HTTP traffic from the VPC CIDR block
D.Allow inbound HTTP traffic from the ALB's security group
AnswerD

Referencing the ALB's security group as the source means the EC2 instances accept traffic only from ENIs belonging to that group, regardless of IP addresses. This satisfies the stem's constraint that only the ALB may communicate with the instances.

Why this answer

Security groups can reference other security groups as a source, allowing traffic only from resources associated with that security group. By specifying the ALB's security group as the source for inbound HTTP traffic, the EC2 instances will only accept traffic originating from the ALB, effectively restricting all other inbound traffic. This is a best practice for securing backend instances behind a load balancer.

Exam trap

The trap here is that candidates often confuse security group referencing with CIDR-based rules, mistakenly thinking that allowing the VPC CIDR (Option C) is sufficient, but this would allow any resource in the VPC, not just the ALB, to reach the EC2 instances.

How to eliminate wrong answers

Option A is wrong because allowing inbound HTTP traffic from the EC2 instances' own security group would permit traffic between the EC2 instances themselves, not from the ALB, and does not restrict access to the ALB only. Option B is wrong because allowing inbound HTTP traffic from 0.0.0.0/0 would permit traffic from any IP address on the internet, completely bypassing the ALB and exposing the EC2 instances directly. Option C is wrong because allowing inbound HTTP traffic from the VPC CIDR block would permit traffic from any resource within the VPC (including other EC2 instances, NAT gateways, or VPN connections), not exclusively from the ALB.

886
MCQhard

A company's security team uses AWS Security Hub in a central security account. They want to ensure that when a critical finding is generated in any member account, the affected resource is automatically tagged with an incident identifier and the finding is routed to a third-party ticketing system. Which approach best meets these requirements?

A.Use AWS Config conformance packs to evaluate resources, and configure an Amazon SNS topic that invokes the tagging and ticketing Lambda function for noncompliant resources.
B.Configure Security Hub to send findings to EventBridge in each member account, create an EventBridge rule matching the critical severity, and target a Lambda function that tags the resource and calls the ticketing API.
C.Create a custom action in Security Hub that the analyst manually triggers for each critical finding, and configure the custom action to invoke a Lambda function that tags the resource and creates a ticket.
D.Enable cross-region aggregation in Security Hub and configure a single EventBridge rule in the aggregation Region to invoke the tagging and ticketing Lambda function for all findings.
AnswerB

Security Hub automatically sends all findings to EventBridge in the account where the finding is generated. An EventBridge rule matching ImportFindings or the severity field can invoke a Lambda function that applies the incident tag and integrates with the ticketing system, providing automatic response in every member account.

Why this answer

Security Hub publishes findings to EventBridge in the account where they are generated, so a rule in each member account can match critical severity and invoke a Lambda function that tags the resource and creates a ticket. This provides automatic, near real-time response in every account without manual intervention, and it scales across an organization when deployed consistently.

Exam trap

The trap here is expecting cross-region aggregation in Security Hub to also forward EventBridge events, when aggregation only consolidates findings for viewing.

887
MCQeasy

A security engineer is tasked with ensuring that all S3 buckets in an AWS account have versioning enabled. The engineer needs to identify buckets that do not have versioning enabled. Which AWS service is BEST suited for this task?

A.AWS Trusted Advisor
B.AWS CloudTrail
C.IAM Access Analyzer
D.AWS Config
AnswerD

AWS Config provides the managed rule 's3-bucket-versioning-enabled' and continuously records S3 bucket configuration items. When a bucket is created or changed, AWS Config evaluates it against the rule and marks it compliant or noncompliant, allowing you to track versioning status over time. This is the correct service because it performs continuous, account-wide configuration compliance evaluation rather than a one-time or policy-focused check.

Why this answer

AWS Config is the best-suited service because it continuously evaluates resource configurations against desired rules. You can use the managed rule 's3-bucket-versioning-enabled' to identify buckets that do not have versioning enabled, and AWS Config will flag them as non-compliant. This provides an automated, scalable way to audit all buckets in an account.

Exam trap

SCS-C02 often tests the distinction between services that record activity (CloudTrail) and services that evaluate configuration state (AWS Config) — candidates may pick CloudTrail because it logs S3 API calls, but it cannot report on current versioning status.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor provides best-practice checks, including an S3 bucket versioning check, but it is not as granular or customizable as AWS Config for enforcing and remediating specific configurations across all buckets. Option B is wrong because AWS CloudTrail records API activity and management events, not the current configuration state of S3 buckets — it cannot directly tell you which buckets lack versioning. Option C is wrong because IAM Access Analyzer identifies resources shared with external entities, not S3 bucket versioning status.

888
MCQhard

A company has a VPC with a public subnet and a private subnet. They launch an EC2 instance in the private subnet with a default security group that allows all outbound traffic. The instance needs to download files from an S3 bucket in the same region. Which configuration allows this without internet access?

A.Set up an AWS Direct Connect connection to the S3 bucket.
B.Create a VPC gateway endpoint for S3 and add a route to the private subnet's route table.
C.Attach an internet gateway to the VPC and add a route to the private subnet.
D.Create a NAT gateway in the public subnet and add a route to the private subnet's route table.
AnswerB

A VPC gateway endpoint for S3 is a horizontally scaled, highly available service that allows instances in a private subnet to communicate with S3 without traversing the internet or requiring public IP addresses. Adding a route in the private subnet's route table that points the S3 prefix list (e.g., com.amazonaws.region.s3) to the endpoint ID (pl-xxxx) keeps all traffic within the AWS network, ensuring low latency and enhanced security. This is the recommended, cost-effective approach because the gateway endpoint itself is free and there are no data transfer charges for S3 traffic.

Why this answer

A VPC gateway endpoint for S3 allows instances in a private subnet to access S3 without traversing the internet. By adding a route to the private subnet's route table that points to the endpoint, traffic destined for S3 stays within the AWS network. The default security group's outbound rule permits all traffic, so no additional security group changes are needed.

Exam trap

The trap here is that candidates often confuse VPC gateway endpoints with interface endpoints or assume a NAT gateway is required for any outbound traffic, missing that S3 and DynamoDB support gateway endpoints which work directly from private subnets without internet access.

How to eliminate wrong answers

Option A is wrong because AWS Direct Connect is a dedicated network connection from on-premises to AWS, not a solution for VPC-to-S3 access without internet; it adds unnecessary complexity and cost. Option C is wrong because attaching an internet gateway and adding a route to the private subnet would require the instance to have a public IP or a NAT device to reach the internet, and the question explicitly states 'without internet access'. Option D is wrong because a NAT gateway provides outbound internet access for private instances, which contradicts the requirement of no internet access; it also introduces a dependency on a public subnet and an internet gateway.

889
MCQeasy

A company is deploying a web application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The instances are in a private subnet. How should the security group for the EC2 instances be configured?

A.Allow inbound HTTP/HTTPS from the internet gateway.
B.Allow inbound HTTP/HTTPS from the security group of the ALB.
C.Allow inbound HTTP/HTTPS from 0.0.0.0/0.
D.Allow inbound HTTP/HTTPS from the VPC CIDR.
AnswerB

Referencing the ALB's security group as the source in the EC2 instance's security group inbound rule is the recommended, least-privilege approach for a private-subnet web tier. This creates a security-group-to-security-group dependency: the rule dynamically allows traffic from any network interface that is associated with the ALB's security group, regardless of the ALB's IP addresses or how they change over time. Because the ALB terminates the client connection and opens a new connection to the instance, the source IP of those connections is the ALB's private IP (or its ENI), which is covered by the ALB's security group association. This rule also ensures that no other resource in the VPC or on-premises can reach the instances directly, preserving the private subnet's isolation and forcing all traffic through the ALB.

Why this answer

The EC2 instances are in a private subnet and should only accept traffic from the ALB, not directly from the internet. By referencing the ALB's security group as the source, you ensure that only traffic that has passed through the ALB can reach the instances, maintaining a secure architecture. This follows the principle of least privilege and prevents bypassing the load balancer.

Exam trap

The trap here is that candidates often confuse the source for security group rules, thinking they should use the internet gateway or VPC CIDR, when the correct approach is to reference the ALB's security group to enforce traffic flow through the load balancer.

How to eliminate wrong answers

Option A is wrong because the internet gateway is a network routing component, not a security group source; security groups cannot reference an internet gateway. Option C is wrong because allowing 0.0.0.0/0 would permit direct inbound traffic from the internet, which defeats the purpose of placing instances in a private subnet and bypasses the ALB. Option D is wrong because allowing the VPC CIDR would permit traffic from any resource within the VPC, including potentially compromised instances, rather than restricting traffic to only the ALB.

890
MCQmedium

A company hosts a web application on EC2 instances behind an Application Load Balancer. The application accesses an S3 bucket to store user uploads. The security team needs to ensure that the EC2 instances can access the S3 bucket without storing AWS credentials on the instances. What should the security team do?

A.Create an IAM user with programmatic access and use those credentials in the application.
B.Configure a security group that allows outbound traffic to the S3 bucket.
C.Create an IAM role with an S3 access policy and attach it to the EC2 instance profile.
D.Store AWS access keys in a configuration file on the EC2 instances.
AnswerC

Attaching an IAM role with the appropriate S3 access policy to the EC2 instance profile enables the instance to obtain temporary credentials from AWS STS via the instance metadata service (IMDSv2). The AWS SDK automatically retrieves and rotates these credentials, meaning the application never stores or manages long-lived keys. This follows the principle of least privilege and is the AWS-recommended pattern for granting EC2 instances access to S3, because it ties permissions to the instance itself rather than to a user or stored key.

Why this answer

An IAM instance profile with an IAM role grants temporary credentials to EC2 instances. Option A is wrong because storing credentials on instances is insecure. Option B is wrong because it's not a best practice.

Option D is wrong because security groups do not grant access to S3.

891
MCQhard

Refer to the exhibit. A security engineer runs the get-trail-status command for a CloudTrail trail. The engineer notices that LatestCloudWatchLogsDeliveryTime is null. What does this indicate?

A.The trail has stopped logging.
B.The trail is not delivering logs to S3.
C.The digest delivery has failed.
D.The trail is not configured to deliver logs to CloudWatch Logs.
AnswerD

The absence of a CloudWatch Logs delivery timestamp (such as LatestCloudWatchLogsDeliveryTime) and the lack of a CloudWatch Logs log group ARN indicate the trail does not have the CloudWatch Logs integration enabled. Trail status returns these fields only when the trail is configured to send events to CloudWatch Logs, which requires an IAM role and explicit log-group setup. Therefore, the trail is not delivering to CloudWatch Logs.

Why this answer

LatestCloudWatchLogsDeliveryTime being null indicates the trail has never delivered logs to a CloudWatch Logs log group — in other words, CloudWatch Logs delivery is not configured for this trail. If delivery were configured and functioning, this field would contain the timestamp of the most recent delivery. A null value specifically means no delivery has occurred, not that delivery failed.

Exam trap

SCS-C02 often tests the distinction between S3 delivery fields and CloudWatch Logs delivery fields in get-trail-status, and candidates assume a null timestamp means logging is broken rather than that the specific integration is unconfigured.

How to eliminate wrong answers

Option A is wrong because a stopped trail would still show a historical LatestCloudWatchLogsDeliveryTime if it had ever delivered; null means it never delivered, and logging status is reflected in other fields like IsLogging. Option B is wrong because S3 delivery status is tracked by separate fields (LatestDeliveryTime, LatestDeliveryAttemptTime), not by the CloudWatch-specific field. Option C is wrong because digest delivery failure would populate error fields like LastDeliveryError rather than leaving the timestamp null.

892
MCQeasy

Which of the following is a best practice for securing an AWS account root user?

A.Create access keys for the root user and use them for API calls.
B.Enable multi-factor authentication (MFA) and avoid using the root user.
C.Use the root user for daily administrative tasks.
D.Share the root user password with the IT team for emergency access.
AnswerB

Enabling MFA on the root account adds a second authentication factor that protects account-level actions such as changing the account email or closing the account, which cannot be performed by IAM users. Avoiding the root user for routine operations means you create IAM administrative users or roles with least privilege, ensuring every action is attributable and auditable. The combination dramatically reduces the risk of root credential misuse.

Why this answer

The AWS root user has unrestricted access to all AWS resources and services, making it a high-value target. Enabling multi-factor authentication (MFA) adds an extra layer of security beyond the password, and AWS best practices dictate that the root user should only be used for a limited set of tasks (e.g., changing account settings) and never for daily operations. This minimizes the attack surface and reduces the risk of compromise.

Exam trap

The trap here is that candidates may think the root user is necessary for daily administration or that sharing credentials is acceptable for emergencies, but AWS explicitly prohibits these practices in favor of IAM roles and MFA-protected root user access only for account-level changes.

How to eliminate wrong answers

Option A is wrong because creating access keys for the root user violates AWS security best practices; root user access keys provide unrestricted, permanent credentials that cannot be rotated or scoped down, and AWS recommends never using them for API calls. Option C is wrong because using the root user for daily administrative tasks exposes the account to unnecessary risk; instead, AWS Identity and Access Management (IAM) users with appropriate permissions should be used for routine operations. Option D is wrong because sharing the root user password with the IT team undermines accountability and security; AWS recommends using IAM roles or a secure password management system for emergency access, not distributing the root password.

893
MCQmedium

A security engineer notices that CloudTrail logs for a production account are not being delivered to the S3 bucket. The bucket policy allows CloudTrail to write objects. What is the MOST likely cause?

A.The S3 bucket does not have versioning enabled.
B.The S3 bucket uses SSE-KMS encryption.
C.The bucket policy does not grant s3:GetBucketAcl to CloudTrail.
D.The S3 bucket contains existing objects before CloudTrail delivery started.
AnswerC

CloudTrail does not merely write objects; it first calls s3:GetBucketAcl to confirm it is allowed to deliver to that bucket and to verify bucket ownership. A bucket policy that omits s3:GetBucketAcl causes CloudTrail's initial validation to fail, and delivery is not set up even though the s3:PutObject action may be allowed. This access check is distinct from an S3 write permission, which is why the correct fix is to add an ACL-read allowance, not just PutObject.

Why this answer

CloudTrail requires the `s3:GetBucketAcl` permission on the destination S3 bucket to verify that the bucket policy grants CloudTrail the necessary write access. Without this permission, CloudTrail cannot confirm its ability to deliver logs, even if the bucket policy explicitly allows `s3:PutObject`. This is a prerequisite check performed by CloudTrail before any log delivery occurs.

Exam trap

The trap here is that candidates assume the only permission needed for CloudTrail to deliver logs is `s3:PutObject`, overlooking the prerequisite `s3:GetBucketAcl` permission that CloudTrail requires to validate the bucket policy before any log delivery can start.

How to eliminate wrong answers

Option A is wrong because S3 versioning is not required for CloudTrail log delivery; it is an optional feature for preserving object versions. Option B is wrong because SSE-KMS encryption is supported by CloudTrail as long as the necessary KMS key permissions (kms:GenerateDataKey and kms:Decrypt) are granted to the CloudTrail service principal; the bucket policy allowing CloudTrail to write objects does not preclude SSE-KMS. Option D is wrong because the presence of existing objects in the S3 bucket does not prevent CloudTrail from delivering new log files; CloudTrail only needs write access and does not require an empty bucket.

894
MCQeasy

A company is using AWS Systems Manager Session Manager to provide secure shell access to EC2 instances without opening inbound ports. Which of the following is a requirement for this setup?

A.The EC2 instance must have an IAM role that allows SSM actions.
B.The EC2 instance must be in a public subnet.
C.The EC2 instance must have a public IP address.
D.The security group must allow inbound SSH from 0.0.0.0/0.
AnswerA

The SSM Agent on the EC2 instance requires an IAM instance role that grants the necessary Systems Manager permissions, such as the managed policy AmazonSSMManagedInstanceCore. This role provides temporary credentials that the agent uses to authenticate to the Systems Manager control plane and to open the bidirectional websocket channel required for Session Manager. Without these IAM permissions, even a technically healthy instance will be unable to register with Systems Manager or start a session.

Why this answer

AWS Systems Manager Session Manager establishes a secure shell connection to EC2 instances without requiring inbound ports. The EC2 instance must have an IAM role attached that includes the AWS managed policy AmazonSSMManagedInstanceCore, which grants permissions for the SSM agent to communicate with the Systems Manager service. This IAM role is essential because the SSM agent uses AWS credentials from the instance metadata to authenticate and establish a bidirectional control channel via HTTPS (port 443) to the Systems Manager endpoint, not through traditional SSH.

Exam trap

The trap here is that candidates assume Session Manager requires inbound network access (like SSH) or public IPs, but the key requirement is the IAM role that grants the SSM agent permission to communicate with the AWS Systems Manager service via outbound-only HTTPS connections.

How to eliminate wrong answers

Option B is wrong because the EC2 instance does not need to be in a public subnet; Session Manager works with instances in private subnets as long as they have outbound internet access (via NAT gateway or VPC endpoints) to reach the Systems Manager endpoints. Option C is wrong because the instance does not require a public IP address; Session Manager uses the SSM agent to initiate an outbound connection to AWS, so the instance can be fully private with no public IP. Option D is wrong because Session Manager explicitly avoids opening inbound SSH ports; the security group does not need to allow inbound SSH from 0.0.0.0/0, and in fact, a best practice is to block all inbound SSH traffic when using Session Manager.

895
MCQmedium

A company needs to securely store database credentials used by a Lambda function. The credentials must be automatically rotated. Which service should be used?

A.AWS Identity and Access Management (IAM)
B.AWS Key Management Service (KMS)
C.AWS Systems Manager Parameter Store
D.AWS Secrets Manager
AnswerD

Secrets Manager is the purpose-built service for storing sensitive data like database credentials, API keys, and passwords. It provides native automatic rotation using a configurable Lambda function and integrates with RDS, Redshift, and DocumentDB for out-of-the-box rotation. Secrets Manager also maintains versions and enforces fine-grained IAM policies, so it is the correct choice when credentials must be rotated automatically and safely.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to securely store, manage, and automatically rotate database credentials and other secrets throughout their lifecycle. It natively supports automatic rotation for Amazon RDS, Redshift, and DocumentDB databases without requiring custom code, and it integrates directly with Lambda via the AWS SDK to retrieve secrets on demand.

Exam trap

The trap here is that candidates often confuse Parameter Store's SecureString parameter (which can store encrypted secrets) with Secrets Manager's automatic rotation feature, overlooking that Parameter Store does not natively rotate secrets.

How to eliminate wrong answers

Option A is wrong because IAM is an access management service for controlling permissions to AWS resources, not a secrets storage service; it cannot store or rotate database credentials. Option B is wrong because KMS is a key management service for creating and controlling encryption keys, not for storing or rotating secrets like database credentials. Option C is wrong because Systems Manager Parameter Store can store secrets as SecureString parameters but lacks built-in automatic rotation capabilities; it requires custom solutions or integration with Secrets Manager to achieve rotation.

896
MCQmedium

A company uses AWS Organizations and wants to restrict the AWS Regions in which resources can be created across all member accounts. Which mechanism should be used?

A.Apply a service control policy (SCP) that denies operations in unauthorized regions.
B.Use VPC endpoints to restrict API calls to specific regions.
C.Configure AWS Config rules to detect and delete resources in unauthorized regions.
D.Attach an IAM policy to each user that denies operations in unauthorized regions.
AnswerA

A service control policy (SCP) attached at the organization root or an organizational unit acts as an upper boundary on all IAM principals in every member account, including the account root user. Because member account administrators cannot modify or remove an SCP, adding a Deny statement with a condition such as aws:RequestedRegion not in an allowed list prevents any operation in unauthorized Regions before the API call executes. This is the recommended preventive, centralized control for enforcing regional boundaries across AWS Organizations.

Why this answer

A service control policy (SCP) in AWS Organizations can be used to restrict the AWS Regions in which resources can be created across all member accounts. SCPs define the maximum permissions for accounts and can deny actions in unauthorized regions.

Exam trap

SCS-C02 often tests the use of SCPs for centralized governance. Candidates might choose IAM policies or Config rules, but SCPs are the only mechanism that can enforce restrictions across all accounts in an organization.

How to eliminate wrong answers

Option B is wrong because VPC endpoints are used to privately connect to AWS services, not to restrict regions. Option C is wrong because AWS Config rules can detect non-compliant resources but do not prevent their creation; they are reactive. Option D is wrong because attaching an IAM policy to each user is not scalable and does not enforce restrictions across all accounts centrally.

897
Multi-Selectmedium

A company uses Amazon GuardDuty to monitor its AWS environment. The security team has received a GuardDuty finding of type 'Recon:EC2/PortProbeUnprotectedPort'. The finding indicates that an EC2 instance has an open SSH port that is being probed from the internet. The team wants to reduce the attack surface and prevent future probes. Which THREE actions should the team take? (Choose THREE.)

Select 3 answers
A.Suppress the GuardDuty finding to reduce noise.
B.Modify the security group to allow SSH only from specific IP addresses.
C.Terminate the EC2 instance and launch a new one.
D.Move the instance to a private subnet and use a NAT gateway for outbound internet access.
E.Use AWS Systems Manager Session Manager to access the instance instead of SSH.
AnswersB, D, E

Restricting the security group source to a specific IP CIDR for port 22 ensures that only authorized administrative workstations can open SSH connections, while all other public access is denied at the network layer. This directly reduces the attack surface because the instance is no longer reachable from the entire internet, and it also preserves the existing instance, its data, and its DNS name. This is a minimal, reversible change that addresses the identified risk without disrupting running workloads.

Why this answer

Modifying the security group to allow SSH only from specific IP addresses directly restricts inbound traffic to trusted sources, eliminating the open exposure that triggers the GuardDuty 'Recon:EC2/PortProbeUnprotectedPort' finding. This is a fundamental network access control that reduces the attack surface by applying the principle of least privilege at the security group level.

Exam trap

The trap here is that candidates may think suppressing the finding (Option A) is a valid remediation step, but AWS explicitly distinguishes between 'suppression' (hiding alerts) and 'remediation' (fixing the root cause), and the question asks for actions to 'prevent future probes,' not just reduce alert noise.

898
Multi-Selectmedium

A security engineer is designing a solution to protect sensitive data in S3. Which THREE mechanisms can be used to enforce encryption at rest?

Select 3 answers
A.Use an SCP to deny s3:PutObject without encryption
B.Enable default encryption on the S3 bucket
C.Enable cross-region replication
D.Apply a bucket policy that denies PutObject without the x-amz-server-side-encryption header
E.Enable MFA Delete on the S3 bucket
AnswersA, B, D

An SCP is an organization-level policy that can restrict IAM actions across all accounts in an OU. By adding a deny condition that requires the s3:x-amz-server-side-encryption key to be present for s3:PutObject, the SCP effectively blocks any unencrypted upload to S3 in the selected accounts, regardless of IAM permissions. This is a preventive control that cannot be overridden by individual bucket policies or IAM users, providing centralized enforcement for sensitive data.

Why this answer

An SCP (Service Control Policy) can be applied at the organizational level to deny any s3:PutObject action that does not include encryption parameters. This enforces encryption at rest across all accounts in the organization, preventing users from uploading unencrypted objects regardless of individual bucket policies or default encryption settings.

Exam trap

The trap here is that candidates confuse cross-region replication (which copies encrypted objects but does not enforce encryption) with an encryption enforcement mechanism, or they think MFA Delete relates to encryption at rest when it only protects against deletion.

899
MCQeasy

A company wants to allow an IAM user to manage only their own password in the AWS Management Console. Which IAM policy action should be used?

A.iam:ChangePassword
B.iam:ListUsers
C.iam:CreateAccessKey
D.iam:DeactivateMFADevice
AnswerA

iam:ChangePassword permits a user to change only their own console password, provided they supply the existing password. It grants no ability to modify other users' credentials, matching the requirement to manage solely their own password.

Why this answer

The correct IAM policy action to allow a user to manage only their own password is iam:ChangePassword. This action enables the user to change their password in the AWS Management Console. Option A is correct.

Option B (iam:ListUsers) is used to list IAM users, not relevant to password management. Option C (iam:CreateAccessKey) creates access keys, which is unrelated. Option D (iam:DeactivateMFADevice) deactivates MFA devices, also not relevant.

Therefore, only iam:ChangePassword is appropriate.

900
Multi-Selecthard

A security engineer is designing a logging strategy for a multi-account environment. The engineer needs to ensure that all API activity across accounts is logged and that logs are immutable and centrally accessible. Which THREE actions should the engineer take?

Select 3 answers
A.Stream logs to CloudWatch Logs for real-time monitoring.
B.Create an AWS CloudTrail organization trail that logs to a central S3 bucket.
C.Enable S3 Object Lock in Compliance mode on the central bucket.
D.Enable VPC Flow Logs in all accounts and send to the central bucket.
E.Grant the central bucket policy to allow only the CloudTrail service to write logs.
AnswersB, C, E

An organization trail in the management account is the only single configuration that captures management events from every account within the AWS Organization, including member accounts, and delivers them to a designated central S3 bucket. This avoids needing to deploy separate trails per account, centralizes the audit source of record, and is the appropriate backbone for the logging strategy described in the scenario.

Why this answer

AWS CloudTrail organization trails automatically aggregate API activity from all member accounts in an AWS Organizations setup, delivering log files to a single, centrally managed S3 bucket. This eliminates the need to configure individual trails per account, ensuring comprehensive and centralized logging of all API calls across the multi-account environment.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (network-level) with CloudTrail (API-level) logging, or they assume CloudWatch Logs alone provides immutability, when in fact only S3 Object Lock in Compliance mode guarantees write-once-read-many (WORM) protection for audit logs.

Page 11

Page 12 of 17

Page 13