Courseiva

AWS Certified Security Specialty SCS-C02 (SCS-C02) — Questions 901–975

1205 questions total · 17pages · All types, answers revealed

Page 12

Page 13 of 17

Page 14
901
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to centrally aggregate and analyze VPC Flow Logs from all accounts. Which solution is MOST efficient and scalable?

A.Configure VPC Flow Logs to send to an S3 bucket in each account and use S3 Cross-Region Replication to a central bucket.
B.Launch Amazon EC2 instances in each account to run tcpdump and send logs to a central S3 bucket.
C.Configure VPC Flow Logs to send to CloudWatch Logs in each account and use cross-account CloudWatch dashboards.
D.Configure VPC Flow Logs to send to Amazon Kinesis Data Firehose in each account, which delivers to a central Amazon OpenSearch Service domain.
AnswerD

VPC Flow Logs can be streamed directly to Amazon Kinesis Data Firehose in each account, and Firehose can then deliver nearly real-time data to a centrally owned Amazon OpenSearch Service domain cross-account. This is a fully managed, serverless pipeline that scales automatically with flow-log volume and avoids installing agents or operating log forwarders. A central OpenSearch cluster provides unified querying and visualization across all accounts' VPC traffic, making it the correct architecture for centralized real-time network analysis.

Why this answer

Amazon Kinesis Data Firehose can directly receive VPC Flow Logs from each account and deliver them to a centralized Amazon OpenSearch Service domain, enabling near-real-time aggregation and analysis without intermediate storage or replication overhead. This architecture is serverless, scales automatically, and avoids the complexity of managing cross-account S3 replication or EC2 instances, making it the most efficient and scalable solution for centralized log analysis.

Exam trap

The trap here is that candidates often default to S3-based solutions (Option A) because they are familiar with S3 for log storage, but they overlook that Kinesis Data Firehose provides a more direct, serverless pipeline for real-time analysis without the latency and complexity of S3 replication.

How to eliminate wrong answers

Option A is wrong because S3 Cross-Region Replication adds latency, requires managing replication rules and IAM permissions across accounts, and does not provide native querying or analysis capabilities—logs would need additional services like Athena or OpenSearch for analysis. Option B is wrong because launching EC2 instances to run tcpdump is inefficient, introduces management overhead, scales poorly across many accounts, and tcpdump captures raw packets rather than VPC Flow Logs, which are already a structured log format. Option C is wrong because cross-account CloudWatch dashboards only visualize logs stored in each account's CloudWatch Logs; they do not centrally aggregate the logs into a single store, and querying across accounts requires complex cross-account log group subscriptions or additional infrastructure.

902
MCQeasy

A security engineer applies the above bucket policy to an S3 bucket. What is the effect of this policy?

A.All requests to the bucket are denied regardless of protocol.
B.All requests to the bucket must be made over HTTPS.
C.The policy has no effect because it uses a condition.
D.All requests to the bucket must be made over HTTP.
AnswerB

This policy uses an explicit Deny with a Bool condition that matches when aws:SecureTransport is false, meaning "if the request did not arrive over TLS/HTTPS, deny it." Since S3 evaluates this explicit Deny before any Allow, even a statement allowing s3:GetObject cannot override it for HTTP requests. The net effect is that every successful request to the bucket must be made over HTTPS.

Why this answer

The bucket policy includes a statement that denies all actions (s3:*) when the request does not use HTTPS (aws:SecureTransport is false). This effectively requires all requests to the bucket to be made over HTTPS. Therefore, option B is correct.

Option A is incorrect because the policy does not deny all requests; it only denies non-HTTPS requests. Option C is incorrect because the condition does have an effect. Option D is incorrect because HTTP requests are denied.

903
Multi-Selecteasy

Which TWO AWS services provide key management for encryption at rest? (Choose 2.)

Select 2 answers
A.AWS Systems Manager Parameter Store
B.AWS CloudHSM
C.AWS Certificate Manager (ACM)
D.AWS Key Management Service (KMS)
E.AWS Secrets Manager
AnswersB, D

CloudHSM is a dedicated hardware security module that provides FIPS 140-2 Level 3 validated, tamper-resistant devices for generating, storing, and using cryptographic keys. Unlike KMS, CloudHSM gives you exclusive, root-level control over your own HSMs and the entire key lifecycle, independent of AWS-operated key infrastructure.

Why this answer

AWS Key Management Service (KMS) is a managed service that makes it easy to create and control customer master keys (CMKs) used for encrypting data at rest across AWS services like S3, EBS, and RDS. AWS CloudHSM provides dedicated hardware security modules (HSMs) that allow you to manage your own encryption keys in a tamper-resistant hardware appliance, meeting FIPS 140-2 Level 3 compliance for key storage and cryptographic operations. Both services directly provide key management for encryption at rest, with KMS offering integrated key rotation and auditing via AWS CloudTrail, while CloudHSM gives you full control over the HSM appliance and keys.

Exam trap

The trap here is that candidates often confuse AWS Secrets Manager or Systems Manager Parameter Store as key management services because they store encrypted secrets, but they are secret storage services that rely on KMS for encryption and do not provide independent key management for encryption at rest.

904
MCQhard

A security engineer needs to analyze VPC Flow Logs to identify traffic to a known malicious IP address. The logs are stored in Amazon S3. Which approach is the most cost-effective for querying the logs?

A.Use Amazon Athena to query the logs in S3
B.Load the logs into an Amazon Redshift cluster
C.Use Amazon EMR to run Spark jobs
D.Use Amazon QuickSight to connect to S3
AnswerA

Amazon Athena is the correct choice because it is a serverless, interactive query service that uses standard SQL to query data directly from S3, paying only for the data scanned. VPC Flow Logs stored in S3 can be queried immediately by creating a table in the AWS Glue Data Catalog, with no infrastructure to provision or manage. Athena is optimized for ad-hoc, cost-effective analysis, and its per-query pricing makes it ideal for the intermittent, investigative queries a security engineer typically runs. Partitioning the S3 flow log data by date and using columnar formats further reduces cost and query time.

Why this answer

Amazon Athena is the most cost-effective option because it is a serverless query service that allows you to run SQL queries directly on data stored in S3, including VPC Flow Logs, without needing to load or transform the data. You pay only for the data scanned per query, and with partitioning (e.g., by date or region), you can minimize costs by scanning only relevant log files. This avoids the overhead of provisioning clusters or managing infrastructure, making it ideal for ad-hoc analysis of malicious IP traffic.

Exam trap

The trap here is that candidates may assume loading data into a dedicated database (Redshift) or using a big data framework (EMR) is necessary for analysis, overlooking Athena’s serverless, pay-per-query model that is purpose-built for querying data directly in S3 without data movement.

How to eliminate wrong answers

Option B is wrong because Amazon Redshift is a fully managed data warehouse designed for complex analytical workloads on structured data; loading VPC Flow Logs into Redshift incurs significant storage and compute costs, and requires ETL processes, making it far less cost-effective for simple querying of logs in S3. Option C is wrong because Amazon EMR with Spark jobs introduces overhead for cluster provisioning, management, and per-hour compute costs, which is overkill for querying logs for a single IP address; it is better suited for large-scale data processing and transformation, not ad-hoc SQL queries. Option D is wrong because Amazon QuickSight is a business intelligence visualization tool, not a query engine; while it can connect to S3 via Athena or other sources, it cannot directly query S3 data and would require additional services, increasing complexity and cost.

905
MCQeasy

A startup uses a single AWS account for development. The security engineer wants to detect if any EC2 instances have been compromised and are performing reconnaissance by probing open ports on other internal instances. The engineer has enabled VPC Flow Logs for all subnets. What is the most cost-effective way to detect this behavior?

A.Enable Amazon GuardDuty and review the findings.
B.Install a third-party intrusion detection system on each EC2 instance.
C.Use Amazon CloudWatch Logs Insights to query VPC Flow Logs for rejected traffic patterns.
D.Use AWS Config rules to check for security group changes.
AnswerA

Amazon GuardDuty is a managed threat detection service that continuously analyzes AWS account activity from VPC Flow Logs, DNS logs, CloudTrail management events, and S3 data events. It uses threat intelligence feeds and machine learning to automatically identify reconnaissance behavior such as port scans, SSH brute-force attempts, or unusual API calls from a suspicious IP range. Enabling GuardDuty and reviewing its severity-ranked findings gives a startup immediate, operational visibility into the attack without deploying agents or writing detection queries, and the findings can be integrated with AWS Security Hub or EventBridge for automated response.

Why this answer

Amazon GuardDuty is a managed threat detection service that uses machine learning and integrated threat intelligence to analyze VPC Flow Logs, DNS logs, and other data sources. It can automatically detect reconnaissance behavior such as port probing or port scanning from compromised EC2 instances without requiring any additional infrastructure or manual query setup. This makes it the most cost-effective solution because it operates on a pay-per-volume basis and eliminates the need for custom log analysis or per-instance agents.

Exam trap

The trap here is that candidates often assume querying VPC Flow Logs directly with CloudWatch Logs Insights is the most cost-effective approach, but they overlook the operational cost and lack of automation, while GuardDuty provides automated, managed detection with no manual query overhead.

How to eliminate wrong answers

Option B is wrong because installing a third-party intrusion detection system on each EC2 instance incurs significant overhead in terms of licensing, management, and compute resources, and it is not cost-effective compared to a managed service like GuardDuty. Option C is wrong because while CloudWatch Logs Insights can query VPC Flow Logs, it requires manual creation and tuning of queries to detect port scanning patterns, and it does not provide automated, continuous detection or threat intelligence integration, leading to higher operational cost and potential missed detections. Option D is wrong because AWS Config rules monitor changes to security group configurations, not network traffic patterns; they cannot detect active reconnaissance behavior such as port probing or scanning.

906
Multi-Selecteasy

A company wants to grant an IAM user the ability to manage (create and update) their own access keys. Which TWO IAM actions must be allowed in the policy?

Select 2 answers
A.iam:UpdateAccessKey
B.iam:CreateAccessKey
C.iam:GetAccessKeyLastUsed
D.iam:DeleteAccessKey
E.iam:ListAccessKeys
AnswersA, B

Allowing `iam:UpdateAccessKey` lets the user activate or deactivate their own existing access keys, satisfying the "update" half of the manage requirement. It does not create keys, so it must be paired with `iam:CreateAccessKey`; together these two actions cover the full create-and-update scope the stem demands.

Why this answer

The scenario requires the IAM user to manage their own access keys, specifically to create and update them. Option B, iam:CreateAccessKey, is correct because it is the exact IAM action that permits a user to create a new access key for themselves. Option A, iam:UpdateAccessKey, is correct because it allows the user to change the status of an existing access key, such as activating or deactivating it, which falls under managing access keys.

Option C, iam:GetAccessKeyLastUsed, is not required because it only retrieves metadata about when an access key was last used, not manage it. Option D, iam:DeleteAccessKey, is not required because the scenario specifies create and update, not delete. Option E, iam:ListAccessKeys, is not required because it only lists access keys and does not grant management capabilities.

Exam trap

SCS-C02 often tests the distinction between read-only and write actions for IAM access keys, and candidates may mistakenly include DeleteAccessKey or ListAccessKeys when the question specifies 'create and update' only.

907
MCQmedium

A security engineer reviews the above CloudTrail event. Which action should the engineer take FIRST to mitigate a potential security issue?

A.Revert the bucket policy to remove the public access.
B.Delete the bucket to prevent data exposure.
C.Contact the root user to confirm the action.
D.Disable the root user's access keys.
AnswerA

Reverting the bucket policy is the correct immediate action because the CloudTrail event shows a PutBucketPolicy call that assigned public read access (e.g., Principal * and s3:GetObject). The bucket is now publicly readable, so you must restore the previous policy version or edit the policy to remove the public grant. While you should also check S3 Block Public Access settings and audit IAM permissions, undoing the policy change is the direct way to stop the exposure.

Why this answer

The CloudTrail event shows that the root user executed `s3:PutBucketPolicy` to apply a bucket policy that grants public access (e.g., `Principal: "*"` or `Effect: "Allow"` with `Action: "s3:GetObject"`). Reverting the bucket policy to remove public access is the immediate corrective action to stop unauthorized data exposure. This directly addresses the security issue by revoking the public read permissions that were just granted.

Exam trap

The trap here is that candidates may focus on disabling the root user's access keys (Option D) because they associate root user actions with compromised credentials, but the real issue is the bucket policy itself—the root user intentionally or unintentionally made the bucket public, and the immediate fix is to revert that policy.

How to eliminate wrong answers

Option B is wrong because deleting the bucket is an overly destructive action that would cause data loss and disrupt any legitimate workloads; the correct first step is to fix the policy, not destroy the resource. Option C is wrong because the root user is the one who performed the action, so contacting them to 'confirm' wastes time and does not mitigate the ongoing public exposure; the engineer should act immediately to revoke access. Option D is wrong because the root user's access keys are not relevant here—the root user performed the action via the AWS Management Console or the root user's own credentials, and disabling access keys does not revoke the bucket policy that is already in effect.

908
Multi-Selectmedium

A company wants to implement a least-privilege access model for their AWS resources. Which TWO of the following are best practices for achieving this?

Select 2 answers
A.Use a single IAM role for all users in the account.
B.Grant permissions only for the specific actions required.
C.Attach IAM policies to groups rather than individual users.
D.Use conditions in IAM policies to restrict access based on attributes like source IP or time.
E.Always use AWS managed policies instead of customer managed policies.
AnswersB, D

Least privilege means constructing IAM policies that explicitly allow only the exact API actions and resources a principal needs for its job function, denying everything else by default. Each Allow statement should enumerate concrete actions such as s3:GetObject on specific resource ARNs rather than using wildcards like s3:* or Action: "*". This minimizes the blast radius if credentials are compromised and ensures that even legitimate users can only perform the minimum operations required to do their work.

Why this answer

Granting only the necessary permissions is the core of least-privilege. Option D is correct because using conditions to restrict access based on attributes like source IP or time further enforces least-privilege. Option A is wrong because using a single IAM role for all users violates the least-privilege principle by granting excessive permissions.

Option C is wrong because attaching policies to groups is a best practice for manageability, but it does not directly address least-privilege. Option E is wrong because using only AWS managed policies may grant more permissions than needed; customer managed policies can be tailored to specific requirements.

909
MCQhard

A company's security team is investigating a potential security incident. They have enabled CloudTrail and CloudWatch Logs. They want to receive real-time alerts when an IAM user creates a new access key. Which combination of services should be used to achieve this?

A.AWS Config rules with an SNS topic
B.Amazon GuardDuty with an SNS topic
C.CloudTrail with CloudWatch Logs, metric filter, alarm, and SNS topic
D.CloudTrail with Lambda function invocation
AnswerC

This is the correct end-to-end solution: AWS CloudTrail records every management API call and delivers those logs to a CloudWatch Logs log group. A CloudWatch Logs metric filter is then created with a pattern that matches the specific event, for example the eventName or a user identity, and the filter publishes a metric value each time a matching event occurs. A CloudWatch alarm can then monitor that metric with a defined threshold, and when triggered, it sends a notification to an SNS topic, enabling real-time alerting for the exact API call of interest.

Why this answer

CloudTrail logs API calls like CreateAccessKey to CloudWatch Logs. A metric filter on the event name 'CreateAccessKey' triggers a CloudWatch alarm that publishes to an SNS topic, enabling real-time notifications. This is the standard AWS architecture for real-time alerting on specific IAM actions.

Exam trap

The trap here is that candidates confuse AWS Config (which monitors configuration changes) with CloudTrail (which records API calls), or assume GuardDuty covers all security events, but GuardDuty does not provide granular, custom alerts on specific IAM actions like access key creation.

How to eliminate wrong answers

Option A is wrong because AWS Config rules evaluate resource configuration compliance, not real-time API call events; they detect drift over time, not instant actions like access key creation. Option B is wrong because Amazon GuardDuty focuses on threat detection (e.g., anomalous API behavior, compromised credentials) and does not natively trigger on specific IAM user actions like CreateAccessKey; it requires additional integration. Option D is wrong because while CloudTrail can invoke a Lambda function via EventBridge, the combination of CloudTrail with Lambda alone lacks the metric filter and alarm mechanism for real-time alerting; it requires additional setup to trigger notifications.

910
MCQeasy

A company has an incident response (IR) process that includes isolating compromised EC2 instances. During a security incident, the IR team needs to block all traffic to and from a compromised instance while preserving the instance for forensic analysis. Which approach should the team take?

A.Detach the instance from the Auto Scaling group and stop it.
B.Modify the security group associated with the instance to remove all inbound and outbound rules.
C.Update the network ACL for the subnet to deny all traffic.
D.Terminate the instance immediately.
AnswerB

Modifying the instance's security group to remove all inbound and outbound rules is the correct containment step because security groups are instance-level stateful firewalls, and deleting every rule immediately terminates existing and new connections while leaving the instance powered on. This preserves volatile memory and running processes for live forensics, and because the change applies only to that security group, other instances and the overall subnet remain unaffected. It is preferable to a NACL change, which would block traffic to the entire subnet.

Why this answer

Modifying the security group to remove all inbound and outbound rules effectively blocks all traffic to and from the EC2 instance because security groups act as a stateful virtual firewall at the instance level. This approach preserves the instance in its current running state, allowing the IR team to perform forensic analysis without the risk of the instance being tampered with or communicating with external systems.

Exam trap

The trap here is that candidates often confuse security groups (stateful, instance-level) with network ACLs (stateless, subnet-level) and incorrectly assume that updating the NACL is the correct way to isolate a single instance without affecting other instances in the subnet.

How to eliminate wrong answers

Option A is wrong because detaching the instance from the Auto Scaling group and stopping it will halt the operating system and may trigger lifecycle hooks or termination policies, but it does not immediately block all network traffic during the stop process; additionally, stopping an instance can cause loss of volatile memory data critical for forensic analysis. Option C is wrong because updating the network ACL for the subnet denies traffic at the subnet level, but network ACLs are stateless and require explicit rules for both inbound and outbound traffic; moreover, the compromised instance could still communicate with other instances within the same subnet if the subnet's default rules allow it, and NACL changes affect all instances in the subnet, potentially disrupting other workloads. Option D is wrong because terminating the instance immediately destroys the instance and its attached EBS volumes (unless termination protection is enabled and volume deletion is disabled), making forensic analysis impossible and violating the requirement to preserve the instance for investigation.

911
MCQmedium

A security engineer is investigating a potential data exfiltration incident. They see that an EC2 instance with an IAM role is making API calls to S3 to download objects. The IAM role has an S3 bucket policy that allows access from that role. However, CloudTrail logs show that the calls are being made from an IP address outside the company's network. What is the most likely explanation?

A.The IAM role credentials were stolen and are being used from an external machine.
B.The EC2 instance has a public IP and the calls are originating from the instance itself.
C.CloudTrail is logging the IP address of the AWS service endpoint, not the client.
D.The S3 bucket policy allows public access.
AnswerA

The CloudTrail event shows the calls were made using the IAM role's temporary credentials but with a sourceIP address that does not match the EC2 instance's IP. Because the role's credentials are obtainable from the instance metadata service (IMDS), if an attacker gains access (e.g., via SSRF) they can extract the credentials and replay them from an external machine, making CloudTrail log that external source IP. This is a classic credential exfiltration scenario, and it explains why the identity is the role while the network origin is elsewhere.

Why this answer

The CloudTrail logs show the API calls originating from an IP address outside the company's network, which indicates that the IAM role credentials (temporary security credentials from the instance metadata) have been compromised and are being used from an external machine. The S3 bucket policy allows access from the IAM role, but the source IP in the logs is external, confirming the credentials are being used outside the EC2 instance.

Exam trap

The trap here is that candidates may assume the external IP is due to a NAT gateway or AWS service endpoint, but CloudTrail always logs the actual client IP, not the service endpoint IP.

How to eliminate wrong answers

Option B is wrong because if the EC2 instance has a public IP and the calls originate from the instance itself, the source IP in CloudTrail would be the instance's public IP or the NAT gateway IP, not an IP outside the company's network. Option C is wrong because CloudTrail logs the source IP address of the client making the API call, not the AWS service endpoint IP; this is a fundamental behavior of CloudTrail logging. Option D is wrong because the S3 bucket policy allows access from the IAM role, not public access; a public access policy would allow anonymous requests, but the logs show the calls are made with the IAM role's credentials, not anonymously.

912
MCQmedium

The above condition is added to an S3 bucket policy to restrict access to a specific VPC endpoint. An EC2 instance in the same VPC is unable to access the bucket. What is the most likely reason?

A.The condition should use aws:SourceVpc instead of aws:SourceVpce
B.The EC2 instance does not have a public IP address
C.The VPC endpoint policy does not allow the s3:GetObject action
D.The resource ARN in the policy is for EC2, not for S3
AnswerD

S3 bucket policies are resource-based policies attached to a bucket, so the Resource field must use the S3 ARN format arn:aws:s3:::bucket-name (or an object key pattern). Using an EC2 resource ARN, such as arn:aws:ec2:region:account-id:instance/instance-id, makes the policy invalid for S3 and therefore it does not grant or restrict access. This is the fundamental reason the bucket policy fails, regardless of any condition keys or endpoint configuration.

Why this answer

The resource ARN in the policy must reference the S3 bucket (e.g., arn:aws:s3:::bucket-name/*), not an EC2 resource. If the ARN is for EC2, the policy will not apply to S3 operations, causing the EC2 instance to be denied access regardless of the VPC endpoint condition. S3 bucket policies only take effect when the Resource element specifies the S3 bucket ARN.

Exam trap

The trap here is that candidates focus on the VPC endpoint condition (aws:SourceVpce vs aws:SourceVpc) and overlook the fundamental requirement that the Resource ARN must match the S3 bucket, not the EC2 instance.

How to eliminate wrong answers

Option A is wrong because aws:SourceVpce is the correct condition key to restrict access to a specific VPC endpoint; aws:SourceVpc is used to restrict to an entire VPC, not a specific endpoint, so using aws:SourceVpce is valid and not the cause of the failure. Option B is wrong because an EC2 instance accessing S3 via a VPC endpoint does not require a public IP address; traffic stays within the AWS network and uses private IPs. Option C is wrong because the VPC endpoint policy, if not explicitly denying s3:GetObject, would default to allowing it; the issue is with the bucket policy, not the endpoint policy.

913
Multi-Selectmedium

A security engineer is configuring Amazon GuardDuty to generate alerts for specific threat types. The engineer wants to ensure that alerts are sent to the security team's email distribution list and also trigger an automated Lambda function for immediate response. Which two actions should the engineer take? (Select TWO.)

Select 2 answers
A.Create an Amazon EventBridge rule that matches GuardDuty findings and triggers a Lambda function.
B.Configure Amazon CloudWatch Logs to send log events to an email distribution list.
C.Create an Amazon CloudWatch Events rule to route findings to a Lambda function.
D.Create an Amazon Simple Notification Service (SNS) topic and subscribe the email distribution list.
E.Create an Amazon Simple Queue Service (SQS) queue and have the Lambda function poll the queue.
AnswersA, D

Amazon GuardDuty publishes a `GuardDuty Finding` event to the default EventBridge event bus whenever a finding is generated. An EventBridge rule with an event pattern that matches finding types, account IDs, or severity can directly invoke a Lambda function as a target, giving you a serverless, near-real-time response path. This is the most idiomatic native integration for GuardDuty because it requires no polling, no extra queue, and gives you full filtering and transformation logic inside Lambda.

Why this answer

Amazon EventBridge (formerly CloudWatch Events) can be configured with a rule that matches GuardDuty finding events. When a finding matches the rule pattern, EventBridge can directly invoke a Lambda function for automated incident response, such as isolating a compromised instance or updating security groups.

Exam trap

The trap here is that candidates may confuse CloudWatch Events (now EventBridge) with CloudWatch Logs or think that SQS alone can handle email notifications, overlooking the need for SNS to deliver messages to email distribution lists.

914
MCQhard

A company uses AWS Organizations with multiple accounts. The security team wants to ensure that all CloudTrail trails are enabled in all accounts and log to a central S3 bucket. What is the MOST efficient way to enforce this?

A.Use AWS Lambda to check each account and enable CloudTrail if missing.
B.Use AWS Config aggregator to verify compliance and send alerts.
C.Create a service control policy (SCP) that requires CloudTrail.
D.Use AWS CloudFormation StackSets to deploy a CloudTrail template to all accounts.
AnswerD

CloudFormation StackSets, especially when backed by service-managed permissions, let you deploy the same CloudTrail stack to every account or OU in AWS Organizations from a single template. StackSets create, update, and delete resources in parallel across specified accounts and regions, and they can automatically add new accounts when they join the organization. This gives you a consistent, auditable, and repeatable way to ensure each account has a configured CloudTrail trail, unlike the other options that either merely report or cannot provision resources.

Why this answer

AWS CloudFormation StackSets allows you to deploy a CloudTrail template across multiple accounts and Regions from a single management account, ensuring all accounts have a trail configured to log to the central S3 bucket. This approach is the most efficient as it automates deployment, enforces consistent configuration, and scales across the entire organization without requiring per-account manual intervention or custom scripting.

Exam trap

The trap here is that candidates often confuse SCPs with proactive enforcement tools, but SCPs only deny or allow actions and cannot create or enable resources, making them unsuitable for requiring a specific service configuration like CloudTrail.

How to eliminate wrong answers

Option A is wrong because using AWS Lambda to check each account and enable CloudTrail is reactive, inefficient, and does not enforce compliance proactively; it requires custom code, permissions, and ongoing maintenance, and it cannot prevent accounts from disabling the trail. Option B is wrong because AWS Config aggregator can verify compliance and send alerts, but it does not enforce or remediate the missing CloudTrail configuration; it only provides visibility and notifications, leaving the actual enforcement to other services. Option C is wrong because a service control policy (SCP) cannot require or enable CloudTrail; SCPs only restrict permissions (deny actions) and cannot create resources or enforce positive configurations like enabling a trail.

915
MCQhard

A company has a multi-account AWS environment with hundreds of accounts. The security team needs to ensure that all security findings from GuardDuty, Security Hub, and Detective are centrally collected and correlated. Which architecture is the MOST scalable and cost-effective?

A.Deploy a central Lambda function that polls each account's GuardDuty, Security Hub, and Detective APIs and stores findings in DynamoDB.
B.Enable AWS Security Hub as the central aggregator, with GuardDuty and Detective integrated. Use Security Hub cross-account aggregation.
C.Configure each account to send findings to a central CloudWatch Logs log group and use CloudWatch Logs Insights to correlate.
D.Stream all findings from all services to a central Amazon S3 bucket and use Amazon Athena to query them.
AnswerB

Security Hub natively acts as the central aggregator by ingesting GuardDuty findings and Detective investigation data as standard findings in the AWS Security Finding Format. Once you designate an administrator account and enable cross-account aggregation via AWS Organizations, all member accounts' findings flow into one dashboard with automatic deduplication, enrichment, and integration with EventBridge for remediation. This purpose-built architecture scales to hundreds of accounts without custom polling or log shipping.

Why this answer

AWS Security Hub natively supports cross-account aggregation via a delegated administrator, allowing findings from GuardDuty, Security Hub, and Detective to be centrally collected without custom code. This architecture is both scalable (handles hundreds of accounts without polling or custom infrastructure) and cost-effective (no additional Lambda, DynamoDB, or S3 query costs), leveraging built-in integrations and consolidated findings views.

Exam trap

The trap here is that candidates may over-engineer a solution with Lambda, DynamoDB, or S3/Athena, overlooking that Security Hub's built-in cross-account aggregation is the simplest, most scalable, and most cost-effective approach for centralizing security findings.

How to eliminate wrong answers

Option A is wrong because polling each account's APIs with a central Lambda function introduces latency, single points of failure, and significant cost at scale (Lambda invocations, DynamoDB read/write capacity), and does not leverage native cross-account aggregation features. Option C is wrong because CloudWatch Logs is not designed to receive structured findings from GuardDuty, Security Hub, or Detective natively; it would require custom log shipping and parsing, and CloudWatch Logs Insights is not optimized for correlating security findings across hundreds of accounts. Option D is wrong because streaming all findings to a central S3 bucket and querying with Athena incurs high storage and query costs, adds latency for real-time correlation, and misses native deduplication and enrichment provided by Security Hub's consolidated findings view.

916
MCQmedium

A company stores sensitive data in an S3 bucket with default encryption (SSE-S3) enabled. A security audit reveals that objects are being accessed by users from unexpected IP addresses. The company wants to enforce that only objects encrypted with a specific KMS key (managed by the security team) can be accessed. Which combination of actions should be taken?

A.Use SSE-C and distribute the customer key to authorized users only.
B.Modify the bucket policy to deny PutObject and GetObject unless the request includes the specific KMS key ID in the 'x-amz-server-side-encryption-aws-kms-key-id' header.
C.Enable S3 Block Public Access and use AWS WAF to filter IP addresses.
D.Apply an S3 Lifecycle policy to transition objects to Glacier after 30 days.
AnswerB

This enforces use of the specific KMS key for all operations.

Why this answer

It uses a bucket policy with the 's3:x-amz-server-side-encryption-aws-kms-key-id' condition key to deny requests that do not include the specific KMS key ID in the 'x-amz-server-side-encryption-aws-kms-key-id' header. This enforces that only objects encrypted with the specified KMS key can be accessed. Option A is incorrect because SSE-C uses customer-provided keys and does not integrate with KMS key IDs; distributing a customer key does not enforce the specific KMS key.

Option C is incorrect because S3 Block Public Access and AWS WAF do not control access based on encryption key. Option D is incorrect because lifecycle policies do not restrict access based on encryption key.

917
MCQeasy

A security engineer needs to automate the response to an AWS CloudTrail log event that indicates a potential security threat. Which AWS service would be most appropriate to orchestrate the automated response?

A.AWS Lambda
B.Amazon Simple Queue Service (SQS)
C.AWS Step Functions
D.Amazon EventBridge
AnswerC

AWS Step Functions is a serverless workflow orchestration service that models security response runbooks as state machines with explicit states for Lambda invocations, AWS API calls, and human approvals. Its built-in retry, timeout, branching, and parallel-execution semantics let the engineer encode conditional decision points and error handling without custom code. This makes it the appropriate service for automating a coordinated, auditable response to CloudTrail events.

Why this answer

AWS Step Functions is a serverless orchestration service that models workflows as state machines, making it ideal for coordinating multi-step, multi-service incident response (e.g., isolate instance → snapshot → notify → create ticket) with retries, branching, and human-approval steps. While Lambda executes individual functions, Step Functions provides the durable orchestration, state tracking, and error handling needed for a reliable automated response. It integrates natively with EventBridge, Lambda, SNS, and security services.

Exam trap

SCS-C02 often tests the distinction between 'trigger' and 'orchestrate'—candidates pick EventBridge or Lambda because they initiate the response, but the question asks for the service that coordinates the multi-step workflow, which is Step Functions.

How to eliminate wrong answers

Option A is wrong because AWS Lambda is a compute service for running individual functions; it can perform a single action but lacks built-in state management, sequencing, and long-running workflow orchestration. Option B is wrong because SQS is a message queue for decoupling producers and consumers, not an orchestration engine—it buffers messages but does not coordinate multi-step response logic. Option D is wrong because EventBridge is an event bus that routes events to targets; it can trigger a workflow but does not itself orchestrate the sequence of remediation actions.

918
MCQhard

A company uses AWS Organizations with multiple accounts. They want to centralize logging of all API calls across all accounts and store them in a single S3 bucket. Which configuration should be used?

A.Use AWS Config to record API calls across all accounts
B.Create a separate CloudTrail trail in each account and aggregate logs using Amazon Athena
C.Create an organization trail in the management account
D.Enable VPC Flow Logs in each account and send to a central S3 bucket
AnswerC

An organization trail created in the management account automatically logs API activity across every account in AWS Organizations into one S3 bucket, satisfying the centralisation requirement. Account-level trails would need separate configuration per account and would not aggregate automatically.

Why this answer

AWS Organizations allows you to create an organization trail in the management account that automatically logs API calls for all member accounts. This centralizes CloudTrail logs into a single S3 bucket without needing to configure individual trails per account, ensuring complete coverage and simplified management.

Exam trap

The trap here is that candidates often confuse AWS Config (which records configuration changes) with CloudTrail (which records API calls), or they think VPC Flow Logs can substitute for API logging, leading them to select options that do not meet the requirement for centralized API call logging.

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configuration changes, not API calls; it does not capture the detailed API activity that CloudTrail provides. Option B is wrong because while separate trails per account can send logs to a central bucket, this approach is redundant and harder to manage compared to an organization trail, and Athena is a query service, not a logging aggregation service. Option D is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols), not API calls; they are used for network analysis, not API activity logging.

919
MCQeasy

A company uses Amazon S3 to store sensitive data. The security team wants to ensure that all objects are encrypted at rest. Which feature should they enable on the S3 bucket?

A.Versioning
B.Server access logging
C.Cross-Region Replication
D.Default encryption
AnswerD

Default encryption automatically applies server-side encryption (SSE-S3, SSE-KMS, or SSE-C) to every new object written to the bucket. This is the correct remediation because it guarantees that all future uploads are encrypted at rest, establishing a consistent security baseline. It is a direct control that addresses the requirement to protect sensitive data, and it can be further enforced with a bucket policy denying unencrypted uploads. Note that default encryption does not encrypt existing objects, so those must be handled separately.

Why this answer

S3 Default Encryption (now called Default Bucket Encryption) automatically encrypts every object uploaded to the bucket using either SSE-S3 or SSE-KMS, without requiring the uploader to specify encryption headers. Enabling it on the bucket ensures all objects are encrypted at rest by default, satisfying the security team's requirement. It is the only option that directly enforces encryption at rest for all objects.

Exam trap

SCS-C02 often tests the difference between features that sound security-related (logging, versioning, replication) and the one that actually enforces encryption at rest — candidates frequently pick Server Access Logging or Versioning as a security control when the question asks specifically about encryption.

How to eliminate wrong answers

Option A is wrong because Versioning only preserves multiple versions of objects — it has no encryption capability and does not enforce encryption at rest. Option B is wrong because Server Access Logging records requests made to the bucket for auditing purposes; it does not encrypt data. Option C is wrong because Cross-Region Replication copies objects to another bucket in a different region for durability or latency, but it does not enforce encryption at rest on the source bucket.

920
Multi-Selectmedium

A security engineer is designing a logging solution for an application that runs on Amazon EC2 instances behind an Application Load Balancer (ALB). The engineer needs to capture and store the following logs for analysis: (1) HTTP request logs from the ALB, (2) operating system logs from the EC2 instances, and (3) network traffic logs for the VPC. Which combination of AWS services should the engineer use? (Choose three.)

Select 3 answers
A.Enable access logging on the ALB and store logs in an S3 bucket.
B.Enable VPC Flow Logs to capture network traffic metadata.
C.Enable S3 server access logging for the application's S3 buckets.
D.Enable AWS CloudTrail to capture API calls.
E.Install the CloudWatch Logs agent on EC2 instances to send OS logs to CloudWatch Logs.
AnswersA, B, E

ALB access logging is the correct choice because it records detailed HTTP request data—method, URI, requester IP, user agent, latency, and the ALB's response code—for every request the load balancer processes. Since an ALB sits in front of the application's EC2 or container targets, enabling this access log and delivering it to an S3 bucket directly captures the application-level request telemetry needed to analyze client traffic patterns, troubleshoot HTTP errors, and support security investigations.

Why this answer

ALB access logging captures detailed HTTP request data (method, URI, status code, user agent, etc.) and can be directly configured to store logs in an S3 bucket without additional agents or infrastructure. This satisfies the requirement for HTTP request logs from the ALB.

Exam trap

The trap here is that candidates often confuse CloudTrail with VPC Flow Logs or ALB access logs, not realizing CloudTrail only captures management plane API calls, not data plane logs like HTTP requests or network traffic.

921
MCQeasy

A company is migrating sensitive customer data to Amazon RDS for MySQL. The security team requires that data be encrypted at rest and in transit. The database will be accessed by a web application running on Amazon EC2 instances in the same VPC. The RDS instance is launched with encryption enabled using an AWS managed KMS key. The security team also enables SSL/TLS for connections. Which additional step is necessary to ensure that the web application uses encrypted connections?

A.Enable encryption at rest on the EC2 instance's EBS volumes.
B.Create an SCP to enforce SSL connections to RDS.
C.Configure the web application's database connection string to use SSL/TLS.
D.Grant the EC2 instance's IAM role permission to use the KMS key for decrypting RDS connections.
AnswerC

The web application must explicitly request TLS because RDS defaults to allowing both encrypted and unencrypted connections depending on the client. Adding an SSL/TLS option to the connection string—such as 'sslMode=require' or 'sslmode=verify-full'—forces the client to negotiate an encrypted channel. This is the only option that directly controls the confidentiality of data as it travels from the application to the RDS database.

Why this answer

Enabling SSL/TLS on the RDS instance allows encrypted connections, but the web application must be configured to actually use SSL/TLS when connecting. This is done by modifying the database connection string to require SSL/TLS. Without this step, the application may connect without encryption.

Exam trap

The trap is thinking that enabling SSL/TLS on RDS is sufficient; candidates may overlook that the client application must be configured to use SSL/TLS, and they may confuse encryption at rest (KMS) with encryption in transit (SSL/TLS).

How to eliminate wrong answers

Option A is wrong because EBS encryption on EC2 instances protects data at rest on the EC2 volumes, not data in transit to RDS. Option B is wrong because an SCP can enforce that SSL connections are used, but it does not configure the application to use SSL; it is a preventive control, not a configuration step. Option D is wrong because IAM permissions for KMS are for encrypting/decrypting data at rest, not for establishing SSL/TLS connections; SSL/TLS uses certificates, not KMS keys.

922
MCQhard

A security engineer is configuring automated incident response for an Amazon EC2 instance that has been compromised. The engineer needs to isolate the instance while preserving forensic data. Which solution meets these requirements?

A.Detach the EBS volumes and attach them to a new instance in a different VPC.
B.Terminate the instance immediately to prevent further damage.
C.Create an AMI of the instance, then remove the instance from the security group to isolate it.
D.Stop the instance and change the security group to deny all traffic.
AnswerC

Creating an AMI of the running instance captures point-in-time snapshots of its EBS volumes, preserving the full disk state without requiring a stop; this enables offline forensic analysis of the root volume and any additional data volumes. Removing the instance from its security group—or applying an empty security group—immediately blocks all inbound and outbound traffic to the instance, containing the compromise while the instance remains powered on with its memory, processes, and network flows intact. This approach gives responders the ability to perform live forensics (such as memory capture) while ensuring the attacker cannot use the instance to move laterally, and it is fully reversible if the instance is later cleared.

Why this answer

Creating an AMI preserves the EBS volumes and their forensic data, while removing the instance from the security group effectively isolates it by denying all network traffic. This approach allows the engineer to later launch a forensic instance from the AMI in a controlled environment for analysis, without losing the compromised instance's state.

Exam trap

The trap here is that candidates may think stopping the instance (Option D) is sufficient for isolation, but they overlook that stopping does not prevent an attacker from restarting the instance, and it can destroy volatile forensic data.

How to eliminate wrong answers

Option A is wrong because detaching EBS volumes and attaching them to a new instance in a different VPC does not isolate the original instance; the instance remains running and could still be accessed or cause further damage. Option B is wrong because terminating the instance immediately destroys the forensic data on the instance store and EBS volumes (unless snapshots were taken beforehand), violating the requirement to preserve forensic data. Option D is wrong because stopping the instance and changing the security group to deny all traffic does not prevent the instance from being started again by an attacker with access, and stopping an instance can cause loss of in-memory forensic data (e.g., running processes, network connections).

923
MCQhard

A company is using AWS Organizations to manage multiple accounts. The security team wants to ensure that all accounts have AWS CloudTrail enabled in all regions. Which approach should be used?

A.Create an SCP that requires CloudTrail to be enabled.
B.Enable CloudTrail in each account using a cross-account IAM role.
C.Use AWS Config rules to detect non-compliant accounts and automatically enable CloudTrail.
D.Enable AWS CloudTrail from the master account as an organization trail.
AnswerD

An organization trail, created from the management (master) account of AWS Organizations, automatically applies to every account within the organization and is centrally managed as a single trail. CloudTrail delivers log files for the management account and all member accounts to the same S3 bucket, and member accounts cannot stop or modify the trail, preserving a reliable audit baseline. This is the intended, native way to enable CloudTrail across an organization, and it fulfills the requirement with no per-account setup.

Why this answer

AWS Organizations allows you to create an organization trail from the management account that automatically applies to all member accounts and all regions. This ensures CloudTrail is enabled across the entire organization without requiring per-account configuration, and it centralizes log delivery to a single Amazon S3 bucket for auditing.

Exam trap

The SCS-C02 exam often tests the misconception that SCPs can enforce positive actions (like enabling a service), when in reality SCPs only provide preventive controls (denying actions) and cannot proactively configure resources.

How to eliminate wrong answers

Option A is wrong because SCPs can only deny or allow actions (e.g., prevent disabling CloudTrail), but they cannot enforce enabling a service; they are not proactive configuration tools. Option B is wrong because using a cross-account IAM role to enable CloudTrail in each account is manual, error-prone, and does not scale; it also fails to enforce compliance automatically across all regions. Option C is wrong because AWS Config rules can detect non-compliance but cannot automatically enable CloudTrail; remediation actions require additional automation (e.g., AWS Systems Manager Automation), and Config itself is not a provisioning tool.

924
Multi-Selecthard

Which THREE AWS services can be used to centrally manage and audit permissions across multiple accounts in AWS Organizations?

Select 3 answers
A.Amazon Inspector
B.AWS Shield
C.AWS IAM Access Analyzer
D.AWS CloudTrail
E.AWS Config
AnswersC, D, E

AWS IAM Access Analyzer provides centralized visibility into resource-based policies across your account or entire AWS organization by continuously generating findings when a resource is shared with external principals. It examines policies attached to S3 buckets, IAM roles, KMS keys, and Secrets Manager secrets, flagging access from outside your organization's trusted boundary. This makes it a core service for monitoring and managing external permission exposure at scale.

Why this answer

AWS IAM Access Analyzer (C) is correct because it continuously analyzes resource policies across accounts in AWS Organizations to identify resources shared with external entities, helping centrally manage and audit permissions. AWS CloudTrail (D) is correct because it records API activity across all accounts in an organization into a centralized trail, enabling auditing of who did what and when for permission-related changes. AWS Config (E) is correct because it continuously assesses and records resource configurations and policy compliance across accounts, allowing centralized auditing of permission-related configuration drift.

Amazon Inspector (A) is not correct because it is a vulnerability management service for EC2, Lambda, and container images, not a permissions auditing tool. AWS Shield (B) is not correct because it is a managed DDoS protection service, unrelated to centrally managing or auditing permissions.

Exam trap

The trap is selecting security services by name association — candidates see 'Inspector' or 'Shield' and assume they relate to permissions, when only Access Analyzer, CloudTrail, and Config actually provide centralized permission auditing.

925
MCQhard

A security engineer creates an Amazon CloudWatch Events rule with this event pattern to trigger an AWS Lambda function for automated response to GuardDuty findings. However, the Lambda function is not triggered for new findings. What is the MOST likely cause?

A.The finding type is not specified in the pattern.
B.CloudTrail is not enabled in the account.
C.The event pattern does not match the actual structure of GuardDuty findings.
D.The Lambda function does not have permission to be invoked by CloudWatch Events.
AnswerC

In a GuardDuty finding event, `detail.resources` is an array of resource objects, each containing properties like `arn`, `type`, `id`, and `partition`, rather than a flat JSON object. If the event pattern is written with `resources` as an object, such as `detail.resources.arn`, it will not match because CloudWatch Events compares the pattern against the actual array structure. An array field must be matched using an array pattern, for example `"resources": [{"arn": []}]`, so the Lambda is never invoked when the pattern has the wrong shape.

Why this answer

The event pattern provided in the CloudWatch Events rule must exactly match the JSON structure of a GuardDuty finding as it is published to the default event bus. GuardDuty findings are delivered with a specific schema that includes a `detail` object containing `type`, `severity`, and other fields. If the event pattern uses incorrect field names, nesting, or missing required elements (e.g., `source` must be `aws.guardduty`), CloudWatch Events will not match the incoming events, and the Lambda function will not be triggered.

Exam trap

The trap here is that candidates often assume the issue is a missing permission (Option D) or a missing finding type (Option A), but AWS specifically designs this question to test whether you understand that CloudWatch Events pattern matching is strict and case-sensitive, and that GuardDuty findings have a predefined event structure that must be replicated exactly.

How to eliminate wrong answers

Option A is wrong because the finding type does not need to be specified in the pattern; you can use an empty pattern or a pattern that matches all GuardDuty findings, and the function will still trigger. Option B is wrong because CloudTrail is not required for GuardDuty to publish findings to CloudWatch Events; GuardDuty sends findings directly to the default event bus via its own integration. Option D is wrong because if the Lambda function lacked permission to be invoked by CloudWatch Events, you would see an explicit error in the CloudWatch Events rule's monitoring or the Lambda function's CloudWatch Logs, and the rule would show a failed invocation count; the question states the function is not triggered at all, which points to a pattern mismatch, not a permissions issue.

926
MCQeasy

A startup is building a web application on AWS. They have an Application Load Balancer (ALB) in front of EC2 instances in an Auto Scaling group. They want to protect the application from common web exploits like SQL injection and cross-site scripting. They also need to allow only traffic from certain geographic regions. Which AWS service should they use to achieve these requirements?

A.AWS WAF
B.AWS Shield Advanced
C.Security groups on the ALB
D.Network ACLs on the ALB subnets
AnswerA

AWS WAF is the correct service because it operates at Layer 7 and can inspect every HTTP(S) request forwarded to the ALB, allowing you to block SQL injection, cross-site scripting, and other application-layer attacks via managed or custom rules. It also supports geo-match and rate-based rules, which are essential for a web-facing application. By associating a WAF web ACL directly with the ALB, traffic is filtered before reaching the application, giving you granular control over the actual request content.

Why this answer

AWS WAF is a web application firewall that protects against common web exploits like SQL injection and cross-site scripting. It also allows you to create geo-match conditions to allow or block traffic based on geographic regions, meeting both requirements.

Exam trap

SCS-C02 often tests the distinction between WAF and Shield, and candidates might think Shield Advanced provides WAF capabilities, but it's primarily for DDoS; also, they might confuse security groups with WAF for application-layer protection.

How to eliminate wrong answers

Option B is wrong because AWS Shield Advanced provides DDoS protection, not web exploit protection like SQL injection or XSS, and does not offer geographic traffic filtering. Option C is wrong because security groups on the ALB control IP/port-based access, not web exploits or geographic filtering. Option D is wrong because network ACLs on subnets are stateless and control IP/port traffic, not application-layer attacks or geo-blocking.

927
Multi-Selecthard

A security engineer is investigating a potential incident where an EC2 instance was compromised. The engineer has access to the following logs: CloudTrail, VPC Flow Logs, and OS-level logs from the instance. Which TWO log sources would be MOST useful to determine the initial attack vector? (Choose TWO.)

Select 2 answers
A.Amazon CloudWatch Metrics for the instance
B.OS-level authentication and system logs
C.AWS CloudTrail logs
D.AWS Config configuration history
E.VPC Flow Logs
AnswersB, C

OS-level authentication and system logs (e.g., /var/log/auth.log on Linux or the Security Event Log on Windows) record each successful and failed login attempt, source IP, user account, timestamp, and sudo/su command usage. These logs can directly expose the initial access vector, such as an SSH brute-force attack or a compromised credential, and also trace post-exploitation actions like privilege escalation. Because they reside on the instance itself, they contain ground-truth details about what actually occurred inside the compromised system, which no AWS service-level log can provide.

Why this answer

OS-level authentication and system logs (option B) are critical because they record local login attempts, sudo commands, and process executions that can reveal how an attacker gained initial access—such as via SSH brute force, a compromised user account, or a vulnerable service. CloudTrail logs (option C) are equally important because they capture API calls made to AWS services, including RunInstances, CreateKeyPair, and ModifySecurityGroup, which can show if the attacker launched the instance from a compromised AWS account or modified security groups to allow inbound traffic. Together, these two sources provide the evidence needed to trace the initial compromise vector, whether it originated from within the OS or through AWS API manipulation.

Exam trap

The trap here is that candidates often pick VPC Flow Logs (option E) thinking network traffic will show the attack vector, but flow logs only show metadata like IP addresses and ports, not the authentication success or API calls that actually prove how the attacker got in.

928
MCQhard

A company is running a critical web application on EC2 instances behind an Application Load Balancer (ALB) in a VPC. The application serves traffic on port 443. The security team has implemented a security group for the ALB that allows inbound HTTPS from 0.0.0.0/0. The EC2 instances are in a private subnet with a security group that allows inbound traffic from the ALB security group on port 8080. The application works correctly. However, the security team wants to add an additional layer of defense by implementing a web application firewall (WAF) to block common web exploits. The team also wants to ensure that only traffic from the company's corporate IP range (203.0.113.0/24) can access the application for administrative purposes on a separate path. The team has enabled AWS WAF on the ALB and associated a web ACL. They have also created a rule to allow traffic from the corporate IP range and block all other traffic. After deploying these changes, external users (not from corporate IP) cannot access the application at all. The company wants external users to be able to access the main application, but only corporate IPs should access the admin path. What should the security engineer do to fix the issue?

A.Configure the security group of the ALB to allow only corporate IPs.
B.Create two separate ALBs, one for admin traffic and one for main traffic.
C.Remove the WAF rule that blocks all non-corporate traffic and rely on security groups.
D.Modify the WAF rule to allow traffic from the corporate IP range on the admin path and allow all traffic on the main application path.
AnswerD

Modify the WAF web ACL rule so it permits requests from the corporate IP range when the URI path is /admin*, while allowing all other traffic to the main application path without restriction. This can be implemented as a rule with a condition combining the IP set source match and a string pattern match for the admin path, with an appropriate action to block non-matching admin requests. This preserves the public availability of the main application and maintains a tight security boundary on administrative endpoints.

Why this answer

The correct action is to modify the WAF rule to allow traffic from corporate IPs on the admin path and allow all other traffic on the main application path. Currently, the WAF rule blocks all non-corporate traffic, which prevents external users from accessing the main application. By creating separate conditions for the admin path (corporate IPs only) and the main path (allow all), the security team can achieve the desired access control.

Option A is incorrect because it would block external users at the security group level. Option B is unnecessary and adds complexity. Option C removes the WAF protection entirely.

Therefore, option D is the correct solution.

929
MCQeasy

A company is designing a security group for a web application that must receive HTTPS traffic from the internet and send traffic to a backend database. The backend database is an Amazon RDS MySQL instance. What is the best practice for configuring the security groups?

A.Web server SG: inbound HTTPS from 0.0.0.0/0. Database SG: inbound MySQL from web server SG.
B.Web server SG: inbound HTTPS from 0.0.0.0/0, outbound to database SG on port 3306. Database SG: inbound MySQL from web server CIDR block.
C.Web server SG: inbound HTTPS from 0.0.0.0/0, outbound all traffic. Database SG: inbound MySQL from 0.0.0.0/0.
D.Web server SG: inbound HTTPS from 0.0.0.0/0, inbound MySQL from database SG. Database SG: outbound MySQL to web server SG.
AnswerA

This configuration is correct because it applies the principle of least privilege: the web server security group only opens HTTPS to the internet, while the database security group restricts MySQL access to only the web server security group via a security group reference. Security group references are dynamic, so any instance attached to the web server SG is automatically allowed, even as the fleet scales, without needing to update CIDR ranges. This also prevents any other source—including other VPCs or subnets—from reaching the database directly.

Why this answer

The best practice is to allow inbound HTTPS from the internet to the web server security group, and then allow inbound MySQL on the database security group referencing the web server security group as the source. This creates a tight, identity-based trust relationship between tiers without hardcoding CIDR ranges.

Exam trap

SCS-C02 often tests security group referencing versus CIDR blocks, and candidates frequently choose CIDR-based rules or open database ports to 0.0.0.0/0, missing that security group references provide tighter, identity-based control.

How to eliminate wrong answers

Option B is wrong because it uses a CIDR block for the database inbound rule instead of referencing the web server security group, which is less precise and can break if IPs change. Option C is wrong because allowing MySQL from 0.0.0.0/0 exposes the database to the entire internet, a severe security risk. Option D is wrong because it reverses the direction — the web server should not accept inbound MySQL from the database, and the database should not initiate outbound MySQL to the web server.

930
MCQhard

A security engineer is designing a multi-tier web application on AWS. The web tier must be accessible from the internet, but the application tier should be accessible only from the web tier. The database tier should be accessible only from the application tier. Which combination of security groups provides the MOST secure configuration?

A.Web SG: allow HTTP/HTTPS from 0.0.0.0/0. App SG: allow HTTP from Web SG CIDR. DB SG: allow MySQL from App SG CIDR.
B.Web SG: allow HTTP/HTTPS from 0.0.0.0/0. App SG: allow all traffic from Web SG. DB SG: allow MySQL from App SG.
C.Web SG: allow HTTP/HTTPS from 0.0.0.0/0. App SG: allow HTTP from Web SG security group ID. DB SG: allow MySQL from 10.0.0.0/24.
D.Web SG: allow HTTP/HTTPS from 0.0.0.0/0. App SG: allow HTTP from Web SG security group ID. DB SG: allow MySQL from App SG security group ID.
AnswerD

Referencing security group IDs as sources enforces tier-to-tier traffic only, so the app tier accepts HTTP solely from the web tier and the database accepts MySQL solely from the app tier. This satisfies the least-privilege constraint without CIDR-based exposure.

Why this answer

It uses security group IDs as the source for inbound rules, which allows traffic only from instances associated with the specified security group, regardless of their IP addresses. This provides a dynamic and secure way to control traffic between tiers, as security group IDs are resolved at the instance level and automatically adapt to changes in instance membership. By contrast, using CIDR blocks (as in options A and C) is less secure because it relies on static IP ranges that may not accurately reflect the actual instances in the web or app tiers, and option B is overly permissive by allowing all traffic from the web SG.

Exam trap

The trap here is that candidates often choose CIDR-based rules (options A or C) because they seem simpler, but they fail to recognize that security group IDs provide a more secure and dynamic way to enforce tier-to-tier access, especially in environments with elastic IPs or auto-scaling.

How to eliminate wrong answers

Option A is wrong because it uses CIDR blocks (Web SG CIDR) instead of security group IDs, which is less secure as CIDR blocks can be broader than necessary and do not automatically update when instances change IPs. Option B is wrong because it allows all traffic from the Web SG to the App SG, which is overly permissive and violates the principle of least privilege by permitting unnecessary protocols beyond HTTP. Option C is wrong because it uses a static CIDR block (10.0.0.0/24) for the database tier, which does not restrict access solely to the app tier instances and may allow other resources in that subnet to reach the database.

931
MCQmedium

A security engineer needs to ensure that all API calls made to AWS services are logged for auditing. Which AWS service should be used?

A.AWS Config
B.Amazon VPC Flow Logs
C.AWS CloudTrail
D.Amazon CloudWatch Logs
AnswerC

AWS CloudTrail is the appropriate service for capturing API activity across AWS. It records management events by default, including actions performed through the AWS Management Console, SDKs, CLI, and other services, and can be configured to log data events for services like Amazon S3 and Lambda. Each CloudTrail event provides the identity, timestamp, source IP, request parameters, and response elements, making it the definitive source for API call auditing.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to AWS services, capturing details such as the identity of the caller, the time of the call, the source IP address, request parameters, and response elements. This provides a complete audit trail of user activity and API usage, which is essential for security auditing and compliance.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks configuration changes) with CloudTrail (which logs API calls), or they mistakenly think VPC Flow Logs or CloudWatch Logs are the primary services for API auditing, when in fact CloudTrail is the dedicated service for recording all AWS API activity.

How to eliminate wrong answers

Option A is wrong because AWS Config is designed for resource inventory, configuration history, and compliance rules, not for logging API calls; it tracks changes to resource configurations, not the API actions themselves. Option B is wrong because Amazon VPC Flow Logs capture information about IP traffic going to and from network interfaces in a VPC, such as source/destination IPs and ports, but they do not log AWS API calls. Option D is wrong because Amazon CloudWatch Logs is a service for storing, monitoring, and accessing log files from various sources, but it does not natively capture API calls; it can be used to store CloudTrail logs, but the service that actually generates the API call logs is CloudTrail.

932
MCQeasy

A developer needs to grant an IAM user read-only access to an S3 bucket named 'my-bucket'. Which policy should be attached to the IAM user?

A.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:ListBucket","Resource":"arn:aws:s3:::my-bucket"}]}
B.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:*","Resource":"*"}]}
C.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:PutObject","Resource":"arn:aws:s3:::my-bucket/*"}]}
D.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:GetObject","Resource":"arn:aws:s3:::my-bucket/*"}]}
AnswerD

This policy exactly implements read-only object access by allowing the s3:GetObject action on the objects within the bucket. The resource ARN arn:aws:s3:::my-bucket/* correctly scopes the action to object keys under my-bucket, rather than the bucket itself or all buckets. This grants the user the ability to retrieve object data and metadata while denying writes, deletions, or bucket-level administrative changes.

Why this answer

Option D grants s3:GetObject, which allows the IAM user to read (download) objects from the bucket. Although full read-only access typically includes s3:ListBucket to list objects, the question asks for read access, and s3:GetObject is the essential read action. Option A only allows listing, not reading object data.

Option B grants full access, and option C grants write access. Thus, D is the best choice for read-only access.

Exam trap

The trap here is that candidates often confuse s3:ListBucket with read access, thinking listing objects is sufficient for reading, when in fact s3:GetObject is required to retrieve the actual object data.

How to eliminate wrong answers

Option A is wrong because it only grants s3:ListBucket on the bucket itself, which allows listing objects but not reading their contents; this is insufficient for read-only access. Option B is wrong because it grants s3:* on all resources, which is an administrative full-access policy that violates the principle of least privilege. Option C is wrong because it grants s3:PutObject, which is a write action that allows uploading objects, not read-only access.

933
MCQmedium

A security team wants to centrally manage and automatically remediate findings across 40 AWS accounts in an organization. They need a solution that aggregates security findings from GuardDuty, Inspector, and Macie into one place and can trigger automated remediation runbooks. Which combination of services BEST meets these requirements?

A.Enable Amazon Detective in all accounts and forward findings to a central S3 bucket, then use AWS Lambda functions triggered by S3 event notifications for remediation.
B.Enable AWS CloudTrail Lake in all accounts and create queries that detect GuardDuty, Inspector, and Macie findings, then use EventBridge Scheduler to run remediation scripts.
C.Enable AWS Security Hub in all accounts with the organization integration, then use Amazon EventBridge rules and AWS Systems Manager Automation runbooks for remediation.
D.Enable AWS Trusted Advisor in all accounts and use AWS Config rules with automatic remediation for findings from GuardDuty, Inspector, and Macie.
AnswerC

Security Hub aggregates findings from GuardDuty, Inspector, and Macie across organization accounts when centralized configuration is enabled. EventBridge can match Security Hub findings and invoke Systems Manager Automation runbooks to remediate automatically. This combination provides both centralized aggregation and automated response, directly satisfying the stated requirements for 40 accounts.

Why this answer

Security Hub with organization integration ingests and normalizes findings from GuardDuty, Inspector, and Macie across all accounts, providing a single aggregation point. EventBridge rules can match Security Hub findings and invoke Systems Manager Automation runbooks for automated remediation. Trusted Advisor, Detective, and CloudTrail Lake do not aggregate these detection findings, and scheduled or S3-triggered remediation lacks native integration.

Exam trap

The trap here is assuming AWS Config automatic remediation can act on GuardDuty, Inspector, or Macie findings, when Config remediation is scoped to Config rules.

934
MCQmedium

A company has an S3 bucket that stores sensitive data. The bucket policy allows access only from a specific VPC endpoint. The security team notices that an object was accessed from an IP address outside the allowed VPC. CloudTrail logs show that the access was made using temporary credentials from an assumed role. The role was assumed by an EC2 instance in the allowed VPC. What is the MOST likely reason the access was allowed despite the bucket policy restriction?

A.The bucket policy does not require encryption in transit.
B.The bucket policy allows access from the VPC endpoint, and the request was made through that endpoint.
C.The bucket policy has a syntax error that makes it ineffective.
D.The IAM role used by the EC2 instance has permissions that override the bucket policy.
AnswerB

When a request is sent to S3 through a VPC gateway endpoint, the bucket policy can explicitly allow it using the aws:sourceVpce condition key, which matches the endpoint ID rather than the client's IP address. Because the policy authorizes that specific endpoint, every request routed through it satisfies the policy, regardless of the source IP. This means an IP-based restriction intended for other sources is effectively bypassed, so this option correctly identifies the root cause.

Why this answer

The bucket policy uses the aws:SourceVpce condition to restrict access to a specific VPC endpoint. When the EC2 instance in the allowed VPC makes a request, it goes through the VPC endpoint, satisfying the condition. Even though the source IP address appears to be outside the VPC (the VPC endpoint's public IP), the policy evaluates based on the VPC endpoint, not the source IP.

Therefore, the request was allowed. Option A is incorrect because encryption in transit is not related to the access restriction. Option C is incorrect because there is no evidence of a syntax error.

Option D is incorrect because IAM permissions cannot override a bucket policy that explicitly denies access; the bucket policy allowed the access because the condition was met.

935
MCQhard

A financial services company uses a multi-account AWS organization with a centralized security account. The security team has enabled Amazon GuardDuty in all accounts and configured it to send findings to the security account via AWS Organizations. The team also uses AWS Security Hub in the security account to aggregate findings. They have set up automated response using AWS Systems Manager Automation documents to isolate compromised EC2 instances by applying a security group that denies all traffic. However, during a recent incident, the automation failed because the Systems Automation document did not have permission to modify the security group in the member account. The security team needs to design a solution that allows the security account to automatically isolate instances in any member account. What should they do?

A.Create a Lambda function in each member account that is triggered by GuardDuty findings and modifies the security group.
B.Create a single IAM role in the security account that has permissions to modify security groups in all member accounts.
C.Use AWS CloudFormation StackSets to deploy an IAM role in each member account with permissions to modify security groups. Then, in the security account, configure the Systems Manager Automation document to assume that role when running the isolation step.
D.Modify the IAM role used by Systems Manager Automation in the security account to include permissions to modify security groups in all member accounts.
AnswerC

AWS CloudFormation StackSets deploys the same IAM role template to every member account, and the role is configured with a trust policy that allows the Systems Manager Automation execution role in the security account to assume it. The automation document uses the 'assumeRole' parameter in a step such as aws:executeScript to switch to that member account role, then runs the EC2 ModifySecurityGroup API against local resources. Because StackSets is integrated with AWS Organizations, the role is automatically provisioned when new accounts are added, centralizing governance while keeping permissions scoped per account.

Why this answer

It uses AWS CloudFormation StackSets to deploy an IAM role in each member account with the necessary permissions to modify security groups. The Systems Manager Automation document in the security account can then assume this role via a cross-account IAM role assumption, allowing it to isolate EC2 instances in any member account without requiring a single monolithic role or per-account Lambda functions.

Exam trap

The trap here is that candidates often assume a single IAM role in the security account can be granted permissions across all member accounts via resource-based policies, but in reality, cross-account access requires a role in the target account that trusts the source account, not just permissions on the source role.

How to eliminate wrong answers

Option A is wrong because creating a Lambda function in each member account triggered by GuardDuty findings would bypass the existing Systems Manager Automation workflow and introduce unnecessary complexity and duplication, rather than enabling the existing automation to work cross-account. Option B is wrong because a single IAM role in the security account cannot directly modify resources in member accounts; cross-account access requires the member account to trust the security account role via an IAM role in the member account with a trust policy. Option D is wrong because modifying the IAM role used by Systems Manager Automation in the security account to include permissions to modify security groups in all member accounts violates the principle of least privilege and is not technically feasible—AWS IAM roles are scoped to a single account and cannot grant permissions to resources in other accounts without a trust relationship and role assumption.

936
MCQmedium

A security engineer needs to monitor for unauthorized changes to IAM roles and policies in an AWS account. The engineer wants to receive an email notification whenever an IAM policy is attached to a role. Which AWS services should be combined to achieve this?

A.Amazon GuardDuty and Amazon Simple Email Service (SES)
B.AWS CloudTrail and Amazon CloudWatch Events (Amazon EventBridge)
C.AWS Config and Amazon Simple Notification Service (SNS)
D.Amazon Inspector and Amazon CloudWatch Logs
AnswerB

AWS CloudTrail is the correct source because it records management events such as an IAM policy modification, capturing the requesting principal, event time, and source IP. Amazon CloudWatch Events (now Amazon EventBridge) can define an event pattern that matches the specific CloudTrail event name and source, then targets an SNS topic to notify the security team. Together they provide near-real-time, API-level monitoring and alerting for unauthorized changes.

Why this answer

AWS CloudTrail logs all API calls, including AttachRolePolicy, and CloudWatch Events (EventBridge) can filter for that specific event and trigger an action such as sending an email via SNS. This combination allows real-time monitoring and notification for unauthorized IAM policy attachments to roles.

Exam trap

The trap here is that candidates often confuse AWS Config's compliance evaluation and SNS notifications with real-time event-driven monitoring, but Config evaluates resources on a periodic or change-triggered basis rather than capturing every API call instantly like CloudTrail and EventBridge do.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes DNS, VPC flow logs, and CloudTrail events for malicious activity, but it does not directly trigger email notifications for specific IAM API calls; it would require additional services like EventBridge and SNS. Option C is wrong because AWS Config is a configuration compliance service that evaluates resource configurations against rules, but it does not provide real-time event-driven notifications for API calls like AttachRolePolicy; it can trigger SNS notifications only after a configuration change is detected, which is not immediate. Option D is wrong because Amazon Inspector is a vulnerability assessment service for EC2 instances and container workloads, not for monitoring IAM policy changes; CloudWatch Logs can store logs but cannot trigger email notifications without additional services like EventBridge and SNS.

937
MCQmedium

A company wants to store audit logs for a minimum of 7 years to meet compliance requirements. The logs are stored in Amazon S3. Which action should be taken to ensure logs are not deleted before 7 years?

A.Enable MFA Delete on the bucket.
B.Configure an S3 Lifecycle policy to transition objects to Glacier after 7 years.
C.Enable S3 Versioning to preserve all versions of objects.
D.Enable S3 Object Lock in Compliance mode with a 7-year retention period on the bucket.
AnswerD

S3 Object Lock in Compliance mode gives each object a write-once-read-many (WORM) retention period, and once a 7-year retention is applied, no user, including the AWS account root user, can delete or overwrite that object version until the period expires. Because Compliance mode is irrevocable for the locked object, even an admin with full permissions cannot shorten the retention or remove the lock. This directly enforces the seven-year audit-log requirement at the S3 API level.

Why this answer

S3 Object Lock in Compliance mode prevents any user, including the root account, from deleting or overwriting an object version until the retention period expires. Setting a 7-year retention period on the bucket enforces the compliance requirement at the object level and cannot be bypassed, which is exactly what is needed to guarantee logs are not deleted before 7 years.

Exam trap

SCS-C02 often tests whether candidates confuse versioning or MFA Delete with true immutability, leading them to pick options that preserve data but do not legally prevent deletion before the retention period.

How to eliminate wrong answers

Option A is wrong because MFA Delete only requires additional authentication for delete operations; it does not prevent an authorized user with MFA from deleting objects before 7 years. Option B is wrong because a lifecycle transition to Glacier after 7 years does not prevent deletion; lifecycle policies manage storage class, not immutability. Option C is wrong because S3 Versioning preserves versions but does not prevent deletion of the current version or the entire object; a user can still delete all versions.

938
MCQhard

A financial company uses AWS KMS to encrypt sensitive data. The security team notices that a KMS key has been deleted, but the encrypted data is still needed for a short period. What is the fastest way to make the data decryptable again?

A.Contact AWS Support to recover the key material
B.Cancel the key deletion within the waiting period
C.Restore the key from a CloudHSM backup
D.Re-encrypt the data with a new KMS key
AnswerB

When a customer-managed KMS key is scheduled for deletion, KMS enforces a mandatory waiting period (7 to 30 days, configurable) during which the key can be restored using the CancelKeyDeletion operation, which returns the key to its previous enabled state. As long as the original key is restored before the deletion completes, any ciphertext encrypted under that key—including data keys wrapped by the key—remains decryptable, so your data is not lost. The waiting period is designed exactly for this recovery scenario; after it expires, deletion is irreversible and no recovery path exists.

Why this answer

When a KMS key is scheduled for deletion, there is a waiting period (7-30 days) during which the deletion can be cancelled, restoring the key and making the data decryptable. Option A is incorrect because AWS Support cannot recover a deleted KMS key. Option C is incorrect because CloudHSM backups are unrelated to KMS key material.

Option D is incorrect because re-encrypting with a new key would require the original key to decrypt first.

939
MCQmedium

A security engineer is analyzing VPC Flow Logs and sees the entry above. The source IP 203.0.113.5 is flagged as suspicious. What additional information would help determine if this is malicious?

A.The source port used by 203.0.113.5.
B.CloudTrail logs for any `ConsoleLogin` or `AssumeRole` events from 203.0.113.5.
C.Network ACL changes associated with the destination subnet.
D.Amazon GuardDuty findings for the destination 10.0.1.5.
AnswerB

CloudTrail records identity-plane events such as `ConsoleLogin` (sign-in events) and `sts:AssumeRole` with the source IP address of the caller. If the same IP 203.0.113.5 appears in these events, it directly links the network traffic to authentication or authorization activity, suggesting the IP is an active user or an attacker leveraging compromised credentials. This correlation is the strongest indicator of malicious intent because VPC Flow Logs alone cannot attribute network flows to an IAM principal, whereas CloudTrail can.

Why this answer

VPC Flow Logs capture network traffic metadata (IPs, ports, protocols) but not the identity or authentication context of the source. CloudTrail logs record API calls, including ConsoleLogin and AssumeRole events, which can reveal whether 203.0.113.5 is associated with an authenticated user or role. If no such events exist, the traffic is likely from an unauthenticated external source, strengthening the case for malicious activity.

Exam trap

The trap here is that candidates focus on network-layer indicators (ports, ACLs, GuardDuty) instead of recognizing that VPC Flow Logs lack identity context, so CloudTrail is the only service that can tie an IP to an authenticated action.

How to eliminate wrong answers

Option A is wrong because the source port is ephemeral and dynamically assigned by the OS; it provides no meaningful security context for determining malicious intent. Option C is wrong because network ACL changes affect traffic filtering rules, not the identity or behavior of the source IP; they are irrelevant to assessing whether 203.0.113.5 is malicious. Option D is wrong because GuardDuty findings for the destination 10.0.1.5 would indicate threats targeting that host, but they do not directly confirm whether the source IP 203.0.113.5 is malicious—the source could be benign even if the destination is compromised.

940
Multi-Selectmedium

A security engineer is investigating a potential compromise of an EC2 instance. The engineer wants to capture volatile memory data and create a forensic image of the instance's EBS volumes. Which TWO actions should the engineer take? (Choose 2.)

Select 2 answers
A.Enable AWS CloudTrail for the instance.
B.Use AWS Systems Manager Run Command to execute a memory capture script.
C.Use AWS Backup to create a backup of the instance.
D.Create an Amazon EBS snapshot of the instance's root volume.
E.Use Amazon Inspector to scan the instance for vulnerabilities.
AnswersB, D

Run Command uses the AWS Systems Manager (SSM) agent already installed on the instance to execute a locally supplied script, so you can run a memory acquisition tool like LiME (Linux) or WinPmem (Windows), save the memory image to a file, and upload it to Amazon S3 for analysis. Because Run Command executes without terminating or rebooting the instance, the volatile state is preserved, which is crucial for retrieving running processes, loaded kernel modules, and open network connections. The SSM agent must be running, and the instance profile needs SSM permissions and access to the destination S3 bucket.

Why this answer

AWS Systems Manager Run Command allows you to remotely execute scripts on EC2 instances without needing SSH access, which is critical during incident response to capture volatile memory data before the instance is compromised further. Option D is correct because creating an EBS snapshot provides a point-in-time forensic image of the root volume that can be analyzed offline without altering the original evidence.

Exam trap

The trap here is that candidates confuse AWS Backup (a managed backup service) with EBS snapshots, not realizing that AWS Backup does not provide the immediate, point-in-time forensic snapshot needed for incident response and may introduce additional latency or metadata changes.

941
MCQmedium

A company runs a multi-tier web application on AWS. The application consists of an Application Load Balancer (ALB), a fleet of EC2 instances in an Auto Scaling group, and an RDS MySQL database. The security team wants to monitor for SQL injection attempts. They have enabled AWS WAF on the ALB and are logging all requests. The security engineer needs to analyze the WAF logs to identify if any SQL injection attacks have been attempted. The logs are stored in an S3 bucket. The engineer needs to query the logs for patterns like 'SELECT * FROM' or 'DROP TABLE' in the URI. Which service should the engineer use to perform this analysis?

A.Amazon Kinesis Data Analytics
B.Amazon QuickSight
C.CloudWatch Logs Insights
D.Amazon Athena
AnswerD

Amazon Athena is a serverless, interactive query service that runs standard SQL directly against structured, semistructured, or unstructured data stored in Amazon S3. For AWS WAF logs, which are JSON objects, you can define a table in the AWS Glue Data Catalog and query them with Athena using partitions by date, with no servers or clusters to provision. It is the natural fit for analyzing WAF log files in S3.

Why this answer

Amazon Athena is a serverless interactive query service that can query data directly from S3 using standard SQL, making it ideal for analyzing WAF logs stored in S3. The engineer can run SQL queries with LIKE clauses to search for patterns like 'SELECT * FROM' or 'DROP TABLE' in the URI field. Athena integrates natively with S3 and requires no infrastructure management.

Exam trap

SCS-C02 often tests the distinction between services that query S3 data (Athena) versus services that process streams (Kinesis) or visualize data (QuickSight), so candidates must match the tool to the data location and query need.

How to eliminate wrong answers

Option A is wrong because Kinesis Data Analytics is for real-time stream processing, not ad-hoc querying of historical logs in S3. Option B is wrong because QuickSight is a business intelligence visualization tool, not a log query engine. Option C is wrong because CloudWatch Logs Insights queries CloudWatch Logs, not S3-stored WAF logs.

942
Multi-Selectmedium

Which TWO of the following are valid methods to protect data in transit between an on-premises data center and AWS? (Choose two.)

Select 2 answers
A.Amazon CloudFront with HTTPS-only viewer protocol policy
B.AWS Site-to-Site VPN
C.VPC Peering
D.S3 Transfer Acceleration
E.AWS Direct Connect with encryption (MACsec)
AnswersB, E

AWS Site-to-Site VPN establishes a secure IPsec tunnel between your on-premises gateway and a virtual private gateway or transit gateway in AWS. Using IKEv2 and AES encryption, it encrypts all IP traffic traversing the public internet, ensuring confidentiality and integrity for data in transit. This is a core service for hybrid cloud connectivity and a valid method for protecting data.

Why this answer

Options B and E are correct. AWS Site-to-Site VPN creates an encrypted tunnel over the internet, protecting data in transit. AWS Direct Connect with MACsec provides encryption over a private physical connection.

Option A is incorrect because CloudFront with HTTPS only encrypts between viewer and edge locations, not necessarily between the origin and edge, and it is not a method to connect on-premises directly to AWS. Option C is incorrect because VPC Peering does not encrypt traffic; it only routes between VPCs. Option D is incorrect because S3 Transfer Acceleration only speeds up transfers using edge locations but does not provide encryption.

943
MCQmedium

A security analyst needs to detect and respond to suspicious API activity in a multi-account AWS environment. The analyst wants near real-time detection of anomalous IAM behavior and the ability to automatically invoke a remediation Lambda function when a specific finding occurs. Which combination of AWS services provides this with the least operational overhead?

A.Amazon GuardDuty with an AWS Organizations delegated administrator, an Amazon EventBridge rule matching the finding, and the remediation Lambda function as the rule target.
B.Amazon Detective with an organization-wide graph, Amazon EventBridge rules for each account, and AWS Systems Manager Automation documents to run remediation.
C.AWS Security Hub with custom insights, Amazon CloudWatch Logs metric filters on CloudTrail, and a CloudWatch alarm that invokes the remediation Lambda function.
D.AWS CloudTrail with an organization trail, Amazon Athena queries scheduled by AWS Glue, and an Amazon SNS topic that invokes the remediation Lambda function.
AnswerA

GuardDuty continuously analyzes CloudTrail management events, VPC Flow Logs, and DNS logs with threat intelligence to produce findings in near real-time. With a delegated administrator it centrally manages all accounts in the organization. EventBridge delivers findings as events, and a rule can invoke the Lambda function directly for automated remediation with minimal overhead.

Why this answer

GuardDuty provides managed, near real-time threat detection using CloudTrail, VPC Flow Logs, DNS logs, and threat intelligence, and it integrates with Organizations through a delegated administrator so all accounts are covered centrally. EventBridge receives GuardDuty findings as events, and a rule can target a Lambda function directly, enabling automated remediation without building custom detection logic or per-account rules.

Exam trap

The trap here is assuming Security Hub or Detective generates detections, when they aggregate or investigate findings that GuardDuty and other services produce.

944
MCQhard

A company has multiple AWS accounts in AWS Organizations. The security team wants to centralize threat detection and automate incident response. Which combination of services should they use?

A.GuardDuty + Security Hub + Step Functions
B.GuardDuty + Amazon EventBridge + AWS Lambda
C.Amazon Macie + AWS Config + SNS
D.CloudTrail + CloudWatch Logs + Lambda
AnswerB

GuardDuty continuously detects threats and generates findings that are automatically emitted as events to Amazon EventBridge. An EventBridge rule filters for the relevant GuardDuty finding types and delivers them to an AWS Lambda function, which runs the remediation logic, such as quarantining an EC2 instance or revoking IAM credentials. This serverless, event-driven design provides immediate, automated response without managing underlying infrastructure.

Why this answer

GuardDuty generates threat detection findings, which are sent to Amazon EventBridge as events. EventBridge then triggers an AWS Lambda function to automate incident response actions, such as isolating an EC2 instance or revoking IAM credentials. This combination provides a fully serverless, event-driven pipeline for centralized threat detection and automated remediation across multiple AWS accounts in Organizations.

Exam trap

The trap here is that candidates often confuse Security Hub with EventBridge, thinking Security Hub is required to aggregate findings before automation, but EventBridge can directly consume GuardDuty findings without Security Hub, and Security Hub is a separate service for multi-framework compliance and aggregation, not a prerequisite for automated incident response.

How to eliminate wrong answers

Option A is wrong because Step Functions is a workflow orchestration service, not a direct event trigger for GuardDuty findings; while it can be used for complex workflows, the standard pattern for automated incident response uses EventBridge to directly invoke Lambda, making Step Functions an unnecessary and less efficient intermediate layer for simple automation. Option C is wrong because Amazon Macie focuses on sensitive data discovery in S3, not threat detection, and AWS Config tracks resource configuration changes, not security threats; SNS alone cannot automate incident response actions. Option D is wrong because CloudTrail and CloudWatch Logs are logging and monitoring services, not dedicated threat detection services; while Lambda can be triggered from CloudWatch Logs, this setup lacks GuardDuty's intelligent threat detection and requires custom log analysis to identify threats, missing the centralized threat detection requirement.

945
MCQeasy

A company uses Amazon S3 to store confidential documents. The security team wants to ensure that all objects are encrypted at rest using server-side encryption with AES-256. Which S3 encryption option should be used?

A.SSE-C
B.SSE-KMS
C.SSE-S3
D.Client-side encryption
AnswerC

SSE-S3 (server-side encryption with Amazon S3 managed keys) is the correct option because it uses strong AES-256 encryption with keys that are managed entirely by Amazon S3. Each object is encrypted with a unique data key, and the data key is wrapped by a regular rotating S3-managed key. This gives S3 the responsibility for encrypting confidential documents with no additional cost, no key rotation overhead, and no need for the customer to supply or manage keys.

Why this answer

SSE-S3 applies server-side encryption with AES-256 using keys fully managed by Amazon S3, meeting the requirement for AES-256 encryption at rest without customer key management overhead. It is the default and simplest S3-managed encryption option, automatically encrypting every object with strong AES-256 and requiring no additional configuration or key infrastructure. This directly satisfies the stated requirement.

Exam trap

SCS-C02 often tests the confusion between 'AES-256' as an algorithm and the key-management model, tempting candidates to select SSE-KMS for stronger-sounding control when the requirement only specifies AES-256 at rest.

How to eliminate wrong answers

Option A (SSE-C) is wrong because it requires the customer to supply and manage their own encryption keys with every request, which is unnecessary complexity when the requirement is simply AES-256 at rest. Option B (SSE-KMS) is wrong because although it uses AES-256, it introduces AWS KMS key management, permissions, and potential API throttling, which exceeds the stated requirement. Option D (client-side encryption) is wrong because it encrypts data before upload, placing key management and cryptographic operations on the customer, and is not server-side encryption at all.

946
Multi-Selecthard

A company runs a two-tier application in a VPC. The web tier runs on EC2 instances in a public subnet behind an Application Load Balancer. The database tier runs on Amazon RDS for MySQL in two private subnets. A security engineer must harden the database tier so that only the web tier can reach the database on port 3306, and so that the database instances are not reachable from the internet under any circumstances. (Choose two.)

Select 2 answers
A.Attach an Elastic IP address to each RDS instance and restrict the security group to the web tier's public addresses.
B.Enable public accessibility on the RDS instances and rely on the security group to block unauthorized sources.
C.Configure the RDS subnet group to use only private subnets that have no route to an internet gateway.
D.Attach a security group to the RDS instances that allows inbound TCP 3306 only from the web tier's security group.
E.Create a network ACL on the private subnets that allows inbound TCP 3306 from 0.0.0.0/0 and denies all other inbound traffic.
AnswersC, D

Placing the database in private subnets with no route to an internet gateway removes any path to or from the internet, which directly satisfies the requirement that the database never be internet-reachable. Route table design, not just security groups, is what guarantees the absence of that path.

Why this answer

Restricting port 3306 by referencing the web tier's security group enforces identity-based access, while keeping the database in private subnets without an internet gateway route removes any possible internet path. Together they satisfy both the least-privilege and the no-internet-exposure requirements without relying on address-based rules.

Exam trap

The trap here is treating a security group rule as sufficient protection while leaving the database in a subnet that still has a route to an internet gateway or public accessibility enabled.

947
Multi-Selectmedium

Which TWO are characteristics of an IAM role? (Choose 2.)

Select 2 answers
A.It can be used to grant permissions to an AWS service without requiring a user.
B.It does not have long-term access keys.
C.It cannot have an attached permissions policy.
D.It provides temporary security credentials.
E.It is associated with a specific IAM user.
AnswersB, D

An IAM role has no embedded long-term credentials such as static IAM user access keys. Instead, it contains a trust policy and permission policies, and when an entity assumes the role, AWS STS issues temporary credentials — an access key ID, a secret access key, and a session token — that expire after a configurable duration between 15 minutes and 12 hours.

Why this answer

IAM roles do not have long-term access keys; they provide temporary security credentials when assumed. Option D is correct because roles provide temporary security credentials through AWS STS. Option A is incorrect because while a role can be used by an AWS service, it still requires an entity (user, service, or application) to assume it—a role is not 'without a user.' Option C is incorrect because roles can have attached permissions policies that define what actions are allowed.

Option E is incorrect because a role is not tied to a specific IAM user; it can be assumed by multiple users, services, or federated identities.

948
MCQeasy

A company wants to allow an IAM user to list objects in an S3 bucket named 'my-bucket'. Which IAM policy statement grants the minimum required permissions?

A.{"Effect":"Allow","Action":"s3:PutObject","Resource":"arn:aws:s3:::my-bucket/*"}
B.{"Effect":"Allow","Action":"s3:GetObject","Resource":"arn:aws:s3:::my-bucket/*"}
C.{"Effect":"Allow","Action":"s3:ListBucket","Resource":"arn:aws:s3:::my-bucket"}
D.{"Effect":"Allow","Action":"s3:*","Resource":"arn:aws:s3:::my-bucket"}
AnswerC

This is the correct minimal policy because s3:ListBucket is the exact permission required for the S3 ListObjects/ListObjectsV2 API calls used to list objects and prefixes. The resource is correctly set to the bucket ARN, which is where S3 checks the ListBucket authorization; object-level ARNs like arn:aws:s3:::my-bucket/* are not valid for this action. It is least-privilege because it grants only the ability to list, with no object-level read, write, or delete permissions and no bucket administrative rights.

Why this answer

The s3:ListBucket action is the specific permission required to list objects in an S3 bucket, and the resource ARN must be the bucket itself (arn:aws:s3:::my-bucket) without a trailing /*. This grants the minimum necessary permission to perform the ListObjects (or ListObjectsV2) API call, which returns the object keys in the bucket.

Exam trap

The trap here is that candidates often confuse s3:ListBucket with s3:GetObject or incorrectly use an object-level ARN (with /*) for listing permissions, failing to recognize that listing requires the bucket-level ARN and the specific ListBucket action.

How to eliminate wrong answers

Option A is wrong because s3:PutObject grants permission to upload objects, not to list them, and it uses a resource ARN with /* which applies to objects, not the bucket. Option B is wrong because s3:GetObject grants permission to read object content, not to list objects, and again uses an object-level ARN. Option D is wrong because s3:* grants all S3 actions (including delete, write, etc.), which violates the principle of least privilege by providing far more permissions than needed to list objects.

949
Multi-Selectmedium

A security team is designing a logging solution for a multi-account AWS environment using AWS Organizations. They need to collect CloudTrail logs, VPC Flow Logs, and DNS logs from all accounts. Which TWO services can be used to centralize this logging?

Select 2 answers
A.Amazon CloudWatch Logs
B.AWS CloudTrail (Organization Trail)
C.AWS Config
D.Amazon GuardDuty
E.Amazon S3
AnswersA, E

Amazon CloudWatch Logs is incorrect because it primarily serves as a destination for log streams within individual AWS accounts, providing real-time monitoring and analysis capabilities. While CloudTrail, VPC Flow Logs, and DNS logs can be directed to CloudWatch Logs, it lacks a native, managed mechanism to centrally *collect and aggregate* these log types *from multiple accounts* within an AWS Organizations structure into a single logging account. It is tempting because CloudWatch Logs is a core log management service, ideal for operational visibility, metric extraction, and alerting on logs *per account*, or for smaller-scale log storage.

Why this answer

Amazon CloudWatch Logs (A) is correct because it can serve as a centralized log repository where log groups from multiple accounts stream CloudTrail, VPC Flow Logs, and Route 53 DNS query logs via subscription filters and cross-account log sharing, enabling a single security account to aggregate and query all log data. Amazon S3 (E) is correct because it is the standard centralized destination for CloudTrail log file delivery (including organization trails), VPC Flow Logs (delivered to S3 buckets), and Route 53 DNS query logs, with cross-account bucket policies and AWS Organizations allowing all member accounts to write into a central logging bucket. AWS CloudTrail (Organization Trail) (B) is not correct here because it only captures CloudTrail API activity across accounts, not VPC Flow Logs or DNS logs, so it cannot centralize all three log types.

AWS Config (C) is not correct because it records resource configuration changes and compliance state, not CloudTrail, VPC Flow Log, or DNS log data. Amazon GuardDuty (D) is not correct because it is a threat-detection service that consumes logs to generate findings, not a service for centralizing and storing the raw logs themselves.

Exam trap

Candidates may mistakenly choose CloudTrail (Organization Trail) because it centralizes CloudTrail logs, but it does not apply to the other log types. The correct central aggregation services are CloudWatch Logs and S3.

950
Multi-Selecthard

A security engineer is reviewing the security of an Amazon EKS cluster. The cluster is used to run containerized applications. Which three actions should the engineer take to improve the security of the cluster?

Select 3 answers
A.Restrict access to the cluster using AWS IAM authentication for kubectl.
B.Use the default VPC for the cluster.
C.Configure the cluster API server endpoint to be private.
D.Grant the cluster-admin role to all developers.
E.Enable audit logging for the cluster.
AnswersA, C, E

Restricting kubectl access through AWS IAM authentication is correct because it integrates IAM identities with Kubernetes RBAC, allowing precise mapping of IAM users and roles to cluster permissions. This avoids shared static credentials and ensures that only authenticated AWS principals with an explicit RBAC role can execute kubectl commands against the EKS cluster.

Why this answer

Restricting access to the cluster using AWS IAM authentication for kubectl is correct because it integrates with AWS IAM to manage user and role permissions, ensuring that only authorized principals can interact with the EKS cluster. This replaces the default, less secure static token or certificate-based authentication with a robust, auditable identity federation. By mapping IAM roles to Kubernetes RBAC, you enforce least-privilege access and prevent unauthorized API calls.

Exam trap

The trap here is that candidates often confuse using the default VPC as a 'safe' choice because it is pre-configured, but it lacks the isolation and security group controls needed for production workloads, making Option B a common distractor.

951
MCQhard

An organization uses AWS Organizations with hundreds of accounts. The security team wants to automatically respond to a specific GuardDuty finding by isolating the affected EC2 instance. What is the recommended architecture?

A.Use EventBridge to trigger a Lambda function in the delegated administrator account, which assumes an IAM role in the affected account to isolate the instance.
B.Configure GuardDuty to invoke a Lambda function in the affected account directly.
C.Use EventBridge to send the finding to a Step Functions workflow that isolates the instance.
D.Use AWS Systems Manager Automation to isolate the instance across accounts.
AnswerA

This is the AWS-recommended architecture for automated, cross-account GuardDuty response. GuardDuty publishes findings as EventBridge events, and because you are using a delegated administrator, you can centralize an EventBridge rule in that administrator account to capture findings from all member accounts. The triggered Lambda then assumes an IAM role in the specific affected member account (via the role's trust policy) to make the EC2 'isolate' API calls (e.g., stopping the instance or applying a security group) without requiring credentials stored in the Lambda. This pattern keep the response logic centralized, avoids per-account Lambda copies, and follows the secure cross-account role assumption model.

Why this answer

It follows the recommended architecture for cross-account automated response to GuardDuty findings. EventBridge in the delegated administrator account captures the finding and triggers a Lambda function, which then assumes an IAM role (using STS AssumeRole) in the affected member account to perform the isolation. This pattern centralizes management while respecting the security boundary between accounts.

Exam trap

The trap here is that candidates may assume GuardDuty can directly trigger a Lambda in any account, but in reality, GuardDuty findings are centralized in the delegated administrator account and cross-account actions require explicit role assumption via EventBridge and Lambda.

How to eliminate wrong answers

Option B is wrong because GuardDuty cannot directly invoke Lambda functions in member accounts; it can only send findings to EventBridge or to the delegated administrator account. Option C is wrong because while Step Functions can orchestrate workflows, the recommended architecture uses a Lambda function to assume a role in the affected account, not a direct Step Functions cross-account invocation (which would require additional complexity and is not the standard pattern). Option D is wrong because AWS Systems Manager Automation does not natively support cross-account isolation of EC2 instances without first assuming a role via Lambda or similar; the recommended approach uses EventBridge and Lambda, not Systems Manager Automation directly.

952
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team needs to centrally monitor all API calls made in the member accounts. The team wants to ensure that all CloudTrail logs are delivered to a centralized S3 bucket in the management account. Which configuration should the security team implement?

A.Configure CloudWatch cross-account subscription to send logs from member accounts to the management account.
B.Enable CloudTrail in each member account and configure each trail to deliver logs to the same S3 bucket.
C.Create an organization trail in the management account with the S3 bucket in the management account.
D.Use Amazon S3 replication to copy logs from member account buckets to the management account bucket.
AnswerC

An organization trail is created only in the management account (or delegated administrator) and automatically applies to all accounts in the AWS organization, with no per-account setup required. It records management events across all accounts, including AWS Organizations control-plane operations like CreateAccount and AttachPolicy, and delivers the aggregated logs to a single S3 bucket in the management account. This is the correct way to centrally collect CloudTrail logs for governance and compliance.

Why this answer

AWS Organizations supports creating an organization trail in the management account that automatically applies to all member accounts. This ensures that all API calls from every account in the organization are logged and delivered to a centralized S3 bucket in the management account without needing to configure individual trails or manage cross-account permissions manually.

Exam trap

The trap here is that candidates often think they need to configure CloudTrail in each member account individually (Option B) or use S3 replication (Option D), missing the fact that AWS Organizations provides a native, centralized organization trail feature that automatically applies to all accounts.

How to eliminate wrong answers

Option A is wrong because CloudWatch cross-account subscription is designed for streaming log data to a central account for real-time monitoring, not for delivering CloudTrail logs to an S3 bucket; CloudTrail logs are stored in S3, not CloudWatch Logs by default. Option B is wrong because while it would technically deliver logs to the same S3 bucket, it requires manual configuration in each member account, does not leverage the centralized management capabilities of AWS Organizations, and can lead to permission issues or inconsistent configurations. Option D is wrong because S3 replication copies objects between buckets after they are written, but it introduces complexity, additional costs, and potential delays; it does not provide a native, centralized way to ensure all CloudTrail logs are delivered directly to the management account bucket without first storing them in member account buckets.

953
MCQhard

During a security incident, a security engineer needs to collect EBS snapshots of multiple EC2 instances across different accounts in AWS Organizations. The snapshots must be copied to a central forensics account. Which combination of steps is MOST efficient?

A.Use Amazon Data Lifecycle Manager (DLM) to create snapshots and copy them to the forensics account using S3 cross-region replication.
B.Use AWS CloudFormation StackSets to deploy a stack that creates snapshots and copies them manually.
C.Use AWS Systems Manager Automation to run scripts in each account that create snapshots and copy them to the forensics account via Lambda.
D.Use AWS Backup to create backup plans in each account and enable cross-account backup copy to the forensics account.
AnswerD

AWS Backup is the correct choice because it natively supports scheduled backup plans, retention management, and cross-account backup copy in a single service. By enabling the AWS Backup organization feature, you can centrally define backup plans and automatically apply them to resources across all accounts, with copies delivered to the forensics account. The service also handles encryption with KMS keys, monitoring with CloudWatch, and audit trails via CloudTrail, which is essential for a defensible forensic process.

Why this answer

AWS Backup is the most efficient solution because it natively supports cross-account backup copy, allowing you to create backup plans in each account and automatically copy EBS snapshots to a central forensics account without custom scripting or manual intervention. This integrates directly with AWS Organizations, enabling centralized management of backup policies across multiple accounts, which is ideal for incident response scenarios requiring rapid, consistent snapshot collection.

Exam trap

The trap here is that candidates may choose DLM (Option A) because it is commonly used for snapshot automation, but they overlook that DLM cannot copy snapshots across accounts, which is a critical requirement for cross-account forensics.

How to eliminate wrong answers

Option A is wrong because Amazon Data Lifecycle Manager (DLM) does not support cross-account snapshot copying; it can only copy snapshots within the same account or across regions, not to a different AWS account. Option B is wrong because CloudFormation StackSets can deploy stacks across accounts, but they cannot create snapshots or copy them automatically; manual copying is required, which is inefficient during an incident. Option C is wrong because Systems Manager Automation with Lambda introduces unnecessary complexity and latency; it requires custom scripts and cross-account IAM roles, whereas AWS Backup provides a managed, policy-driven solution that is more reliable and efficient.

954
Multi-Selecthard

An organization wants to enforce that all IAM users must use MFA to access the AWS API. Which TWO steps should be taken?

Select 2 answers
A.Rotate all IAM user access keys.
B.Attach the policy to all IAM users or to a group that all users belong to.
C.Create an IAM policy with a condition that denies all actions unless aws:MultiFactorAuthPresent is true.
D.Configure the account password policy to require MFA.
E.Create a service control policy (SCP) that requires MFA for all API calls.
AnswersB, C

Attaching the MFA enforcement policy to every IAM user, or to a group that all users belong to, is the required deployment step: IAM policies have no effect until they are attached to an identity. Using a group is the most maintainable approach because new users added to the group automatically receive the policy, and it prevents individual users from being missed. This distribution is what makes the deny-unless-MFA condition universally enforced across the account.

Why this answer

Option B is correct because an IAM policy that enforces MFA must actually be attached to the principals it should affect — either directly to each IAM user or, more manageably, to a group that all users belong to, so the deny-unless-MFA condition is evaluated for their API calls. Option C is correct because the standard way to enforce MFA on API access is an IAM policy with a Deny effect on all actions ("*") guarded by a condition such as "aws:MultiFactorAuthPresent": "true" (typically combined with a BoolIfExists or Null check to handle cases where the key is absent), which blocks any request not made with MFA-authenticated credentials. Option A is not required: rotating access keys improves key hygiene but does not enforce MFA on API calls.

Option D is wrong because the account password policy controls password complexity, length, and rotation for console sign-in, not MFA requirements for API access. Option E is wrong because SCPs only apply to accounts within AWS Organizations and cannot require MFA for individual IAM users' API calls; MFA enforcement for users is done with IAM policies.

Exam trap

SCS-C02 often tests the misconception that SCPs or password policies can enforce MFA for IAM users, when in fact only IAM policies with the aws:MultiFactorAuthPresent condition key (attached to users/groups) achieve API-level MFA enforcement.

955
MCQeasy

A security engineer needs to centrally manage and enforce security policies across multiple AWS accounts in an organization. Which AWS service should they use?

A.AWS CloudFormation StackSets
B.AWS IAM
C.AWS Firewall Manager
D.AWS Organizations with SCPs
AnswerD

AWS Organizations with Service Control Policies (SCPs) is the correct choice because SCPs are centralized policy documents that attach to the organization root, organizational units, or individual accounts and define the maximum allowed permissions for all IAM principals in those accounts. SCPs act as guardrails that restrict what services and actions can be performed, and they are enforced by a central governance layer independent of the account's local IAM administrators. Because SCPs are managed from the management account of the organization, they provide a single point to centrally administer and enforce security policies across every member account.

Why this answer

AWS Organizations with Service Control Policies (SCPs) allows central policy management across accounts. Firewall Manager focuses on VPC security, not general policies.

956
MCQmedium

A security engineer notices that an IAM role allows 'iam:PassRole' to an EC2 instance. What security risk does this present?

A.The instance can launch new resources with a more privileged role.
B.The instance can modify IAM policies.
C.The instance can stop CloudTrail logging.
D.The instance can decrypt data encrypted with KMS keys.
AnswerA

The ability to pass a role (iam:PassRole) combined with permission to launch EC2 instances (ec2:RunInstances) lets the instance specify a different, more privileged IAM instance profile at launch. Because the PassRole permission is often granted broadly without restricting which roles can be passed, the current instance can create a new instance carrying permissions beyond its own, thereby escalating privileges within the account.

Why this answer

The 'iam:PassRole' permission allows an entity to pass an IAM role to an AWS service, such as EC2. If an EC2 instance has this permission, it can launch new resources (like another EC2 instance or a Lambda function) and associate a more privileged role with that resource. This is a privilege escalation risk because the instance could effectively gain the permissions of the passed role.

Exam trap

The trap is thinking that 'iam:PassRole' directly allows modifying IAM policies or other actions, when it specifically enables passing roles to services, leading to potential privilege escalation if not properly restricted.

How to eliminate wrong answers

Option B is wrong because 'iam:PassRole' does not grant permission to modify IAM policies; that would require actions like 'iam:CreatePolicy' or 'iam:PutRolePolicy'. Option C is wrong because stopping CloudTrail logging requires permissions like 'cloudtrail:StopLogging', which are not granted by 'iam:PassRole'. Option D is wrong because decrypting data with KMS keys requires 'kms:Decrypt' permissions, not 'iam:PassRole'.

957
MCQmedium

Refer to the exhibit. The bucket policy allows access from a specific IP range and denies access over HTTP. A user from IP 198.51.100.5 makes a GET request over HTTPS. What will happen?

A.Denied because of the explicit Deny statement.
B.Allowed because the request is over HTTPS.
C.Allowed because the Deny condition is not satisfied.
D.Denied because no explicit allow matches the request.
AnswerD

The explicit Deny statement is skipped because the request uses HTTPS and thereby satisfies the secure-transport condition, but that only removes a blocking rule. The sole Allow statement, however, is conditioned on the request's source IP being in the specified allowed range, and this request's source IP does not fall within that range. Since the request does not match the condition of any Allow statement, no explicit allow applies, and AWS IAM falls back to the default implicit deny. The request is denied for exactly that reason: no explicit allow matches it.

Why this answer

In AWS S3 bucket policies, an explicit Deny always overrides any Allow, but the request must first match a Deny condition. Here, the Deny condition applies to HTTP requests, but the request is HTTPS, so the Deny does not apply. However, the bucket policy only allows access from a specific IP range, and the user's IP (198.51.100.5) is not within that allowed range.

Since no explicit Allow matches the request, the default implicit Deny applies, resulting in access being denied.

Exam trap

The trap here is that candidates often assume that because the Deny condition is not triggered (due to HTTPS), the request must be allowed, overlooking the fact that the request still fails the IP-based Allow condition, leading to an implicit Deny.

How to eliminate wrong answers

Option A is wrong because the explicit Deny statement only denies access over HTTP, and this request is over HTTPS, so the Deny condition is not satisfied. Option B is wrong because while the request is over HTTPS, it does not satisfy the IP range condition in the Allow statement, so it is not allowed. Option C is wrong because the Deny condition is not satisfied, but the request still fails due to the lack of an explicit Allow matching the IP address, leading to an implicit Deny.

958
MCQmedium

A company is designing a VPC with public and private subnets. The web servers in the public subnets must be accessible from the internet on port 443, but the database servers in the private subnets should only be accessible from the web servers on port 3306. Which combination of security group rules and network ACL rules should be used to meet these requirements with the least administrative overhead?

A.Use security groups for all tiers; add an inbound rule to the database security group allowing traffic from the web security group on port 3306.
B.Use security groups for all tiers; add an inbound rule to the web security group allowing internet traffic on port 443, and add an outbound rule to the web security group allowing traffic to the database security group on port 3306.
C.Use security groups for the web tier and network ACLs for the database tier; add an inbound rule to the database network ACL allowing traffic from the web subnet CIDR on port 3306.
D.Use security groups for the web tier and network ACLs for the database tier; add an inbound rule to the database network ACL allowing all traffic from the web security group.
AnswerA

Security groups are stateful and support referencing other security groups as a source, allowing an inbound rule on the database security group to permit traffic only from instances associated with the web security group on port 3306. This removes the need to track instance IP addresses or rely on broad CIDR ranges, and it automatically scales with the web tier's launch or termination. Because security groups are stateful, return traffic from the database to the web tier is implicitly allowed, reducing operational overhead while maintaining least-privilege access.

Why this answer

Security groups are stateful and support referencing other security groups as a source, which allows you to permit traffic from the web security group to the database security group on port 3306 without needing to specify IP addresses. This approach minimizes administrative overhead as security group rules are automatically applied to all instances associated with the group, and changes propagate without updating network ACLs or CIDR ranges. The web security group can have an inbound rule allowing HTTPS (port 443) from the internet (0.0.0.0/0), while the database security group only allows inbound MySQL/Aurora (port 3306) from the web security group, meeting the access requirements precisely.

Exam trap

The trap here is that candidates often confuse the stateful nature of security groups with the stateless nature of network ACLs, leading them to incorrectly add outbound rules (Option B) or choose network ACLs (Options C and D) when security group references provide a simpler, more scalable solution.

How to eliminate wrong answers

Option B is wrong because it adds an outbound rule to the web security group for traffic to the database security group on port 3306, but security groups are stateful—if the inbound rule on the database security group allows traffic from the web security group, the return traffic is automatically permitted, making the outbound rule redundant and not the primary mechanism to restrict database access. Option C is wrong because it uses a network ACL for the database tier, which is stateless and requires separate inbound and outbound rules, increasing administrative overhead; additionally, referencing a subnet CIDR instead of a security group is less flexible and does not automatically adapt to changes in the web tier. Option D is wrong because network ACLs do not support referencing security groups as a source or destination—they only support CIDR blocks, IP addresses, or service prefixes, so the rule 'allowing all traffic from the web security group' is invalid and would not work.

959
Multi-Selecteasy

A security engineer needs to collect and analyze operating system logs from EC2 instances. Which TWO services are required?

Select 2 answers
A.Amazon VPC Flow Logs
B.AWS Config
C.Amazon CloudWatch Logs
D.Amazon CloudWatch Agent
E.AWS CloudTrail
AnswersC, D

Amazon CloudWatch Logs is the correct central service for storing, monitoring, and analyzing OS logs collected from EC2 instances. It receives log data forwarded by the CloudWatch agent and organizes it into log groups and log streams, enabling real-time searching, metric filters, alarms, and querying with Logs Insights. Once OS logs are ingested, the engineer can use CloudWatch Logs to correlate events across instances, build dashboards, and set automated alerts, making it the core analysis platform for the collected logs.

Why this answer

Amazon CloudWatch Logs is the service that stores, monitors, and accesses operating system logs from EC2 instances. However, to collect and send those logs to CloudWatch Logs, you must install and configure the Amazon CloudWatch Agent on the EC2 instances. The CloudWatch Agent can collect logs from the OS (e.g., /var/log/syslog, /var/log/messages, Windows Event Log) and forward them to CloudWatch Logs for analysis.

Exam trap

The trap here is that candidates often confuse Amazon CloudWatch Logs (the destination service) with the CloudWatch Agent (the collection mechanism), thinking that CloudWatch Logs alone can pull logs from EC2 instances without needing an agent installed on the OS.

960
MCQmedium

A company is using AWS WAF to protect a web application behind an Application Load Balancer. The Security Engineer wants to block requests that contain SQL injection attacks. Which action should the Engineer take?

A.Enable AWS Shield Advanced to automatically block SQL injection attacks.
B.Create a WAF rule with a SQL injection match condition and set the action to block.
C.Use Amazon GuardDuty to detect and block SQL injection attempts.
D.Configure the security group of the EC2 instances to block traffic containing SQL injection patterns.
AnswerB

AWS WAF's SQL injection match condition inspects HTTP request components—such as the URI, query string, body, cookies, and headers—for known malicious SQL patterns using transformations like URL decode and lowercasing to evade bypass attempts. Setting the rule action to Block causes the AWS WAF web ACL to terminate matching requests before they reach the protected resource, which is exactly the correct mechanism for preventing SQL injection attacks at the application layer.

Why this answer

AWS WAF is the native service for filtering web traffic to Application Load Balancers, and it includes a managed rule set specifically for SQL injection (SQLi) detection. By creating a custom WAF rule with a SQL injection match condition and setting the action to 'Block', the Engineer directly instructs WAF to inspect incoming requests for SQLi patterns and drop matching traffic before it reaches the ALB. This is the correct, service-native approach for blocking SQL injection attacks at the application layer.

Exam trap

The trap here is that candidates confuse AWS Shield Advanced (a DDoS service) with WAF (a web application firewall), or assume that network-layer controls like security groups can inspect application-layer payloads, when in fact only WAF can perform content inspection for SQL injection.

How to eliminate wrong answers

Option A is wrong because AWS Shield Advanced provides DDoS protection and does not have native SQL injection detection capabilities; it can work with WAF but cannot independently block SQLi. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events for malicious activity, but it does not inspect HTTP request payloads for SQL injection patterns and cannot block traffic in real-time at the ALB. Option D is wrong because security groups operate at the network layer (Layer 3/4) and cannot inspect application-layer payloads for SQL injection patterns; they only filter based on IP addresses, ports, and protocols.

961
MCQeasy

A company is using AWS Key Management Service (KMS) to encrypt data at rest in Amazon S3. The security team wants to ensure that only a specific IAM role can decrypt the data. Which KMS policy element should be used?

A.Principal
B.Resource
C.Action
D.Effect
AnswerA

The Principal element in a KMS key policy identifies the IAM role, user, service, or account that is explicitly granted permission to use the key. For example, the ARN of an IAM role is placed here so that role can call kms:Encrypt or kms:Decrypt. Since the question asks who can use the key, Principal is the correct answer.

Why this answer

(Principal) is correct because in a KMS key policy, the Principal element specifies which IAM users, roles, or AWS services are allowed to perform actions on the key. By setting the Principal to the specific IAM role's ARN, only that role can decrypt the data, enforcing the security team's requirement.

Exam trap

The trap here is that candidates often confuse the Principal element with the Resource element, thinking Resource controls who can use the key, when in fact Resource identifies the key itself and Principal identifies the entity allowed to act on it.

How to eliminate wrong answers

Option B (Resource) is wrong because the Resource element in a KMS key policy identifies the key itself (e.g., the key ARN), not the entity allowed to use it; it does not restrict which IAM role can decrypt. Option C (Action) is wrong because the Action element defines the cryptographic operations (like kms:Decrypt) that are allowed, but it does not specify who can perform them. Option D (Effect) is wrong because the Effect element only sets whether the policy statement allows or denies access (e.g., 'Allow' or 'Deny'), but it does not identify the specific IAM role permitted to decrypt.

962
MCQhard

A security engineer notices that an IAM user has been performing suspicious actions in an AWS account. The engineer needs to generate a credential report to identify the age of the user's access keys. Which AWS CLI command should the engineer run?

A.aws iam get-account-authorization-details
B.aws iam generate-credential-report && aws iam get-credential-report
C.aws iam generate-service-last-accessed-details
D.aws iam list-access-keys --user-name suspectUser
AnswerB

The generate-credential-report command starts an asynchronous job in IAM, and then get-credential-report downloads the completed CSV file. The report contains columns such as access_key_1_last_rotated, access_key_2_last_rotated, and password_last_rotated, which directly provide the age of every key and password in the account. This is the standard, account-wide method for determining stale access keys and exactly satisfies the need to identify the age of a user's access key.

Why this answer

The AWS CLI command to generate and retrieve an IAM credential report is a two-step process: first run 'aws iam generate-credential-report' to trigger report generation, then run 'aws iam get-credential-report' to retrieve it. The report includes access key age, password age, MFA status, and other credential metadata for all IAM users, which is exactly what the engineer needs.

Exam trap

SCS-C02 often tests the confusion between 'list-access-keys' (which shows key IDs and status but not age) and the credential report (which includes creation/rotation dates), causing candidates to pick the simpler but insufficient command.

How to eliminate wrong answers

Option A is wrong because 'aws iam get-account-authorization-details' returns IAM policies, roles, groups, and users but does not include credential age or access key rotation information. Option C is wrong because 'aws iam generate-service-last-accessed-details' generates a report on which services and actions were last accessed by an IAM entity, not credential age. Option D is wrong because 'aws iam list-access-keys' lists access key IDs and status (Active/Inactive) for a user but does not provide the creation date or age of the keys — the credential report is required for age data.

963
MCQeasy

A company needs to ensure that all API calls in their AWS account are logged and monitored for suspicious activity. Which service should be enabled first?

A.Amazon GuardDuty
B.Amazon Inspector
C.AWS Config
D.AWS CloudTrail
AnswerD

AWS CloudTrail is the native audit service that records API activity in your account. Every supported management event and, if enabled, data event is captured with details like the IAM user/role, source IP address, time, request parameters, and response elements. CloudTrail delivers encrypted log files to an S3 bucket and optionally CloudWatch Logs for long-term retention and analysis, making it the correct service for ensuring all API calls are logged.

Why this answer

AWS CloudTrail is the correct first service to enable because it records all API calls made in the AWS account, including the identity, source IP, and timestamp of each call. This audit log is foundational for detecting suspicious activity, as it provides the raw data needed for analysis by other services like Amazon GuardDuty or third-party tools. Without CloudTrail, there is no record of API activity to monitor.

Exam trap

The trap here is that candidates often choose Amazon GuardDuty (Option A) because it is a dedicated threat detection service, but they overlook that GuardDuty relies on CloudTrail as a data source and cannot log API calls itself.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes CloudTrail logs, VPC Flow Logs, and DNS logs for anomalies; it cannot function without CloudTrail being enabled first. Option B is wrong because Amazon Inspector is a vulnerability assessment service that scans EC2 instances and container images for software vulnerabilities and network exposure, not API call logging. Option C is wrong because AWS Config is a resource inventory and compliance service that tracks configuration changes to AWS resources, not API call activity.

964
MCQhard

Refer to the exhibit. A security engineer reviews this CloudFormation template. The bucket is intended to be private. What is the security issue in the configuration?

A.The PublicAccessBlock configuration is missing the BlockPublicPolicy setting.
B.The bucket does not have versioning enabled.
C.The bucket policy grants public read access to the bucket, which overrides the PublicAccessBlock configuration.
D.The bucket policy uses an incorrect resource ARN.
AnswerA

The PublicAccessBlock configuration is missing the BlockPublicPolicy setting, so S3 does not reject the bucket policy that explicitly grants public read access. When BlockPublicPolicy is not enabled, a bucket policy allowing public access is evaluated as valid and takes effect, making the bucket publicly readable. Enabling BlockPublicPolicy would cause S3 to deny the policy request and preserve the bucket's private access, thereby eliminating the public exposure.

Why this answer

The PublicAccessBlock configuration in the template is missing the BlockPublicPolicy setting. Without BlockPublicPolicy enabled, a bucket policy that grants public read access (Effect: Allow, Principal: *, Action: s3:GetObject) can be applied to the bucket, overriding the intended private configuration. The other PublicAccessBlock settings (BlockPublicAcls, IgnorePublicAcls, RestrictPublicBuckets) do not block bucket policies; only BlockPublicPolicy does.

The security issue is that the bucket policy, though present, would be blocked if BlockPublicPolicy were enabled, but since it is missing, the bucket becomes publicly accessible.

Exam trap

The trap is that candidates assume any PublicAccessBlock setting prevents public access, but BlockPublicPolicy specifically blocks bucket policies. Without it, a bucket policy granting public access can be applied, making the bucket public despite other PublicAccessBlock settings.

How to eliminate wrong answers

Option A is wrong because the PublicAccessBlock configuration includes BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, and RestrictPublicBuckets; the template shows BlockPublicPolicy set to true, so it is not missing. Option B is wrong because versioning is a data protection and recovery feature, not a security control for preventing public access; its absence does not cause the bucket to be publicly readable. Option D is wrong because the resource ARN arn:aws:s3:::my-bucket/* correctly specifies all objects in the bucket, and the bucket name matches the logical ID; the ARN is valid for the policy statement.

965
MCQhard

Refer to the exhibit. A security engineer is analyzing a VPC Flow Logs entry for an EC2 instance with private IP 192.0.2.10. The log shows an accepted outbound connection from the instance to 203.0.113.50 on port 443. The instance is not expected to initiate outbound HTTPS connections. What should the engineer do next to investigate?

A.Log into the instance and check for unauthorized processes or malware.
B.Block the IP 203.0.113.50 in the security group immediately.
C.Check the security group rules to see if outbound HTTPS is allowed.
D.Check Amazon Route 53 DNS logs to see what domain was resolved.
AnswerA

The observed egress traffic to a suspicious external IP is an indicator, but the only way to determine whether the instance is actually compromised is to inspect the operating system itself. Using a secure channel such as AWS Systems Manager Session Manager, you can examine running processes, active network sockets, scheduled tasks, and persistence mechanisms for malware, crypto miners, or reverse shells. This host-level triage is the correct immediate next step because it directly establishes the root cause and preserves forensic evidence before taking any broader network or DNS-based action.

Why this answer

The VPC Flow Logs show an accepted outbound connection from the EC2 instance to an external IP on port 443, which is unexpected behavior. The immediate next step is to log into the instance and investigate for unauthorized processes, malware, or compromised credentials that could be initiating this outbound HTTPS traffic. This aligns with incident response best practices: verify the host before making network-level changes.

Exam trap

The trap here is that candidates assume the first step is to modify network controls (security groups or DNS logs) rather than performing host-level investigation, which is the correct incident response priority when the instance itself is the source of unexpected traffic.

How to eliminate wrong answers

Option B is wrong because blocking the IP immediately without first confirming the instance is compromised could disrupt legitimate traffic or alert an attacker prematurely; security groups should be modified only after a thorough investigation. Option C is wrong because checking security group rules is unnecessary—the flow log already shows the connection was accepted, meaning outbound HTTPS is permitted; the question is why the instance is making the connection, not whether it can. Option D is wrong because Amazon Route 53 DNS logs would only show DNS queries made to Route 53, and the instance may be using an external DNS resolver or a hardcoded IP, so this step is not the immediate priority for investigating unexpected outbound traffic.

966
Drag & Dropmedium

Drag and drop the steps to configure AWS WAF with rate-based rules in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Rate-based rules require creating a web ACL first, then adding the rule, associating with a resource, testing, and monitoring.

967
MCQeasy

An AWS Lambda function needs to read from a DynamoDB table. What is the best practice for granting the Lambda function the necessary permissions?

A.Use a resource-based policy on the DynamoDB table to allow the Lambda function.
B.Create an IAM user with the necessary permissions and assign it to the Lambda function.
C.Create an IAM role with the necessary permissions and attach it as the Lambda function's execution role.
D.Embed the IAM user's access key and secret key in the Lambda function code.
AnswerC

Attaching an IAM role as the Lambda function's execution role is the recommended pattern. In the role's trust policy you allow the Lambda service principal, lambda.amazonaws.com, to assume the role; the role's permissions policy then grants the minimal DynamoDB actions needed, such as GetItem or Query. Lambda automatically calls sts:AssumeRole and obtains short-term credentials, so no long-lived keys are ever stored in the function.

Why this answer

The best practice for granting a Lambda function permissions to DynamoDB is to create an IAM role with the necessary permissions and attach it as the function's execution role. Lambda assumes this role at runtime, and the AWS SDK automatically uses temporary credentials from the role, eliminating the need to manage long-term keys. This follows the principle of least privilege and avoids embedding secrets.

Exam trap

SCS-C02 often tests the misconception that Lambda can use IAM user credentials or resource-based policies for same-account access, when the correct and secure practice is an IAM execution role.

How to eliminate wrong answers

Option A is wrong because DynamoDB resource-based policies are used for cross-account access or specific resource permissions, but they are not the standard mechanism for granting a Lambda function in the same account access; the execution role is the correct approach. Option B is wrong because Lambda functions cannot be assigned an IAM user; they assume an IAM role, and creating an IAM user with long-term credentials is an anti-pattern. Option D is wrong because embedding access keys in code is a severe security risk, violates best practices, and keys can be leaked or rotated improperly.

968
MCQmedium

A security engineer needs to grant an IAM user in Account A (111111111111) access to an S3 bucket in Account B (222222222222). The bucket policy in Account B allows cross-account access from Account A. Which additional step is required?

A.Attach an IAM policy to the IAM user in Account A granting s3:GetObject on the bucket.
B.Create a cross-account role in Account B and have the user assume it.
C.Attach the bucket policy to the IAM user in Account A.
D.Create an S3 access point in Account B and grant the IAM user access.
AnswerA

For cross-account access, S3 requires an explicit allow from both the resource-based policy (the bucket policy in Account B, which is already in place) and an identity-based policy on the IAM user in Account A. The IAM user's permissions are evaluated separately, and even though the bucket policy grants the Account A root access, the user does not inherit that permission without an explicit identity-based allow. Attaching a policy that grants s3:GetObject on the specific bucket is the necessary, minimal step to complete the authorization chain.

Why this answer

For cross-account access to an S3 bucket, both the bucket policy in Account B and an IAM policy in Account A are required. The bucket policy grants access to the Account A user, but the user also needs an IAM policy in their own account allowing the s3:GetObject action on that bucket. This is because IAM policies in the user's account must permit the action, and the bucket policy must also allow it.

Exam trap

SCS-C02 often tests cross-account access, and candidates may forget that both the bucket policy and the IAM policy are required, thinking that the bucket policy alone is sufficient.

How to eliminate wrong answers

Option B is wrong because creating a cross-account role is an alternative approach, but the question states the bucket policy already allows access, so the additional step is an IAM policy, not a role. Option C is wrong because bucket policies are attached to buckets, not IAM users. Option D is wrong because S3 access points are a different feature and not required for basic cross-account access.

969
MCQeasy

A company stores sensitive customer data in an S3 bucket. The security team wants to ensure that all data is encrypted at rest using server-side encryption with AWS KMS (SSE-KMS). Which bucket policy statement should be added to deny uploads that do not use SSE-KMS?

A.{"Effect":"Deny","Principal":"*","Action":"s3:PutObject","Resource":"arn:aws:s3:::bucket-name/*"}
B.{"Effect":"Deny","Principal":"*","Action":"s3:PutObject","Resource":"arn:aws:s3:::bucket-name/*","Condition":{"StringNotEquals":{"s3:x-amz-server-side-encryption":"aws:kms"}}}
C.{"Effect":"Deny","Principal":"*","Action":"s3:PutObject","Resource":"arn:aws:s3:::bucket-name/*","Condition":{"StringNotEquals":{"s3:x-amz-server-side-encryption":"AES256"}}}
D.{"Effect":"Deny","Principal":"*","Action":"s3:PutObject","Resource":"arn:aws:s3:::bucket-name/*","Condition":{"StringNotEquals":{"s3:x-amz-server-side-encryption":"aws:kms"},"Null":{"s3:x-amz-server-side-encryption-aws-kms-key-id":"true"}}}
AnswerB

This is the correct policy because it uses `StringNotEquals` on the `s3:x-amz-server-side-encryption` header to deny any upload that does not specify `aws:kms`. Requests that omit the encryption header or use `AES256` (SSE-S3) will have a condition that evaluates to true, triggering the Deny, while requests that explicitly send `aws:kms` are permitted. This narrowly enforces SSE-KMS for all new objects without blocking compliant uploads.

Why this answer

The correct bucket policy statement uses a Deny effect on s3:PutObject with a condition that checks if the s3:x-amz-server-side-encryption header is not equal to 'aws:kms'. This ensures that any upload request that does not specify SSE-KMS with AWS KMS is denied. The condition StringNotEquals on that key enforces the requirement.

Exam trap

The trap is confusing the encryption header values: 'aws:kms' for SSE-KMS and 'AES256' for SSE-S3. Candidates might choose the condition that checks for AES256, thinking it enforces KMS, but that would actually enforce SSE-S3. Also, adding extra conditions like Null on key ID can overcomplicate and may not be required.

How to eliminate wrong answers

Option A is wrong because it denies all s3:PutObject requests unconditionally, which would block all uploads, not just those without SSE-KMS. Option C is wrong because it denies uploads that do not use AES256 (SSE-S3), which is the opposite of what is needed; it would allow SSE-KMS but block SSE-S3, but the requirement is to deny non-SSE-KMS, so this condition would actually deny SSE-S3 and allow SSE-KMS, but it's not the correct condition because it checks for AES256, not aws:kms. Option D is wrong because it adds an additional Null condition on the KMS key ID, which would deny uploads that do not specify a KMS key ID, but the requirement is only to enforce SSE-KMS, not necessarily a specific key ID.

This condition would also deny uploads that use SSE-KMS with the default key, which may be too restrictive.

970
MCQeasy

A company's security team wants to receive alerts when an IAM user creates a new access key. Which AWS service can be used to monitor and notify on this specific API call?

A.AWS Trusted Advisor
B.Amazon GuardDuty
C.AWS CloudTrail with Amazon CloudWatch Events
D.AWS Config
AnswerC

AWS CloudTrail records every API call made by an IAM user or role, and delivering those trail events to Amazon CloudWatch Events (now EventBridge) enables custom rules that match exact API actions and principals. A rule can filter on eventName, userIdentity, and request parameters, then invoke an SNS topic to notify the security team in near real time. This is the only option that directly reacts to specific API activities rather than aggregate state or threats.

Why this answer

CloudTrail logs IAM CreateAccessKey events, and CloudWatch Events can trigger a notification. Option A is wrong because Trusted Advisor is for best practices. Option B is wrong because GuardDuty is for threat detection.

Option D is wrong because AWS Config is for resource compliance.

971
MCQeasy

A security engineer is configuring an automated response to a GuardDuty finding that indicates a compromised EC2 instance. The engineer wants to isolate the instance by changing its security group to a 'quarantine' group. Which AWS service is BEST suited to automate this response?

A.AWS Step Functions
B.AWS Config
C.Amazon EventBridge
D.AWS Systems Manager Automation
AnswerC

Amazon EventBridge is the correct trigger because GuardDuty natively publishes all findings to the EventBridge default bus as events. A security engineer can create a rule with an event pattern matching GuardDuty finding types, then set a Lambda function as the target to automatically remediate or alert. EventBridge provides real-time, serverless event delivery without custom polling, making it the designed integration point for GuardDuty findings.

Why this answer

Amazon EventBridge is the best choice because it can directly receive GuardDuty findings as events and trigger an automated response, such as invoking a Lambda function or Systems Manager Automation runbook to change the EC2 instance's security group to a quarantine group. EventBridge provides native integration with GuardDuty via its default event bus, enabling real-time, event-driven automation without additional orchestration overhead.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Automation as the primary automation service, forgetting that it requires an event source like EventBridge to trigger it, making EventBridge the correct answer for the 'best suited' service to automate the response directly from GuardDuty.

How to eliminate wrong answers

Option A is wrong because AWS Step Functions is a workflow orchestration service that requires an event source (like EventBridge) to trigger it; it is not the direct trigger for GuardDuty findings and adds unnecessary complexity for a simple one-step response. Option B is wrong because AWS Config is a configuration auditing and compliance service that can evaluate resource configurations and trigger remediation via Systems Manager Automation, but it cannot directly receive GuardDuty findings as events and is not designed for real-time threat response. Option D is wrong because AWS Systems Manager Automation is a runbook execution service that can perform remediation actions, but it requires an event trigger (such as EventBridge) to start; it is not the service that listens for GuardDuty findings directly.

972
MCQmedium

A security engineer is designing a solution to enforce that all S3 buckets in an AWS account have server-side encryption enabled. The engineer needs to automatically remediate any non-compliant buckets. Which AWS service should be used to implement this requirement?

A.AWS Lambda with S3 events
B.AWS Config with managed rules and auto-remediation
C.AWS IAM policy to deny PutBucketEncryption without encryption
D.AWS CloudTrail
AnswerB

The correct solution is AWS Config with a managed rule such as s3-bucket-server-side-encryption-enabled, which continuously evaluates whether each bucket has default encryption enabled. When a bucket is noncompliant, AWS Config can invoke auto-remediation using an SSM Automation document like AWS-EnableS3BucketEncryption to apply SSE-S3 or SSE-KMS. This provides both detection and automated correction, unlike event-driven or logging-only approaches.

Why this answer

AWS Config continuously evaluates resource configurations against rules, and managed rules such as s3-bucket-server-side-encryption-enabled detect non-compliant buckets; Config remediation actions can then invoke SSM Automation documents or Lambda to automatically re-enable encryption. This provides both detection and automatic remediation in a single managed service, which is exactly what the requirement asks for.

Exam trap

SCS-C02 often tests the misconception that CloudTrail or IAM policies can enforce encryption compliance — candidates must distinguish detective/remediative services (Config) from logging (CloudTrail) and preventive but limited controls (IAM).

How to eliminate wrong answers

Option A is wrong because Lambda with S3 events reacts to object-level events, not to configuration state changes like encryption being disabled; it would require custom logic and does not provide continuous compliance evaluation. Option C is wrong because an IAM policy denying PutBucketEncryption without encryption is not a valid condition — IAM cannot inspect the encryption parameters of the request in that way, and it does not remediate existing non-compliant buckets. Option D is wrong because CloudTrail only records API activity; it does not evaluate compliance or remediate resources.

973
MCQeasy

A developer needs to grant an IAM user read-only access to an S3 bucket containing sensitive data. The bucket is encrypted with an AWS KMS customer managed key. Which set of permissions must be included in the IAM policy?

A.s3:GetObject, kms:Encrypt
B.s3:GetObject, kms:Decrypt
C.kms:Decrypt
D.s3:ListBucket, kms:Decrypt
AnswerB

This pair is correct because reading a KMS-encrypted S3 object is a two-step operation: S3 GetObject retrieves the ciphertext from the bucket, and KMS Decrypt decrypts the envelope-encrypted data key so the object's contents are revealed. The s3:GetObject permission allows the actual read of the object, while kms:Decrypt grants the ability to unwrap the key that protects that object. Together they provide exactly the read-only access required.

Why this answer

To read objects from an encrypted S3 bucket, the user needs both s3:GetObject to retrieve the object and kms:Decrypt to decrypt the object using the KMS key. Option A is wrong because it includes kms:Encrypt instead of kms:Decrypt; decryption is required, not encryption. Option C is wrong because it lacks s3:GetObject permission, which is necessary to retrieve the object.

Option D is wrong because it includes s3:ListBucket, which is not required for reading a specific object, and it lacks s3:GetObject.

974
Multi-Selectmedium

Which THREE actions can be performed using AWS CloudTrail to enhance security monitoring?

Select 3 answers
A.Monitor SSH login attempts to EC2 instances.
B.Detect unauthorized API calls by analyzing CloudTrail logs.
C.Monitor changes to S3 bucket policies.
D.Capture all network traffic to and from EC2 instances.
E.Track changes to IAM user permissions.
AnswersB, C, E

CloudTrail delivers a record of every AWS API call, capturing the requesting principal, source IP, user agent, and request parameters, regardless of whether the call succeeded or was denied. Security teams can analyze these logs to detect unauthorized attempts, such as AccessDenied errors, calls from unexpected identities or regions, or anomalous API patterns. This detective capability is often combined with Amazon GuardDuty or Athena queries to surface suspicious activity that would otherwise go unnoticed.

Why this answer

AWS CloudTrail records API activity in your AWS account, including calls to IAM, S3, and other services. By analyzing CloudTrail logs, you can detect unauthorized API calls (Option B) because every API call is logged with details such as the identity, source IP, and timestamp, enabling security monitoring and alerting on suspicious actions.

Exam trap

The trap here is that candidates often confuse CloudTrail's scope with OS-level or network-level monitoring, mistakenly thinking it can capture SSH logins or network traffic, when in fact it only records AWS API calls.

975
Multi-Selectmedium

Which TWO of the following are best practices for protecting data in transit? (Choose TWO.)

Select 2 answers
A.Use a VPN for all traffic
B.Use HTTP for internal traffic
C.Enforce HTTPS for web traffic
D.Use SSL/TLS for all data transfers
E.Use encryption at rest
AnswersC, D

Enforcing HTTPS for web traffic is a critical best practice because HTTPS runs HTTP over TLS, providing confidentiality, integrity, and server authentication for every request and response. Redirecting all HTTP requests to HTTPS and applying HTTP Strict Transport Security (HSTS) ensures clients never send or accept plaintext web communication, mitigating man-in-the-middle and session-hijacking attacks. This should be the baseline for every public-facing web workload and ideally applied to internal web consoles and APIs as well.

Why this answer

Option C is correct because enforcing HTTPS for web traffic ensures that HTTP is wrapped in TLS, providing confidentiality and integrity for browser-to-server communications and preventing eavesdropping or man-in-the-middle tampering on the wire. Option D is correct because using SSL/TLS for all data transfers applies strong, standardized transport encryption (e.g., TLS 1.2/1.3) to any protocol carrying sensitive data, which is the core best practice for protecting data in transit. Option A is not the best answer because a VPN encrypts traffic over an untrusted network but does not by itself secure application-layer transfers end-to-end, and 'all traffic' is overly broad rather than a targeted transit-protection control.

Option B is wrong because plain HTTP transmits data unencrypted and is unsuitable even for internal traffic. Option E is wrong because encryption at rest protects stored data, not data moving across a network.

Exam trap

SCS-C02 often tests the confusion between 'in transit' and 'at rest' controls — candidates pick encryption-at-rest options (KMS, BitLocker) for transit questions, or assume a VPN alone satisfies all transit encryption requirements.

Page 12

Page 13 of 17

Page 14