Courseiva

AWS Certified Security Specialty SCS-C02 (SCS-C02) — Questions 976–1050

1205 questions total · 17pages · All types, answers revealed

Page 13

Page 14 of 17

Page 15
976
MCQhard

A security engineer needs to grant a third-party vendor temporary access to an S3 bucket in the company's AWS account. The vendor has its own AWS account and will use its own IAM users. The engineer wants to avoid creating IAM users in the company's account and wants to audit all access. Which solution meets these requirements?

A.Create an IAM role in the company account with a trust policy that allows the vendor's AWS account to assume it, and attach a policy granting access to the S3 bucket.
B.Use AWS Resource Access Manager (RAM) to share the S3 bucket with the vendor's account.
C.Enable S3 public access and provide the vendor with the bucket URL and an access key.
D.Create an IAM user in the company account for each vendor employee and share the credentials securely.
AnswerA

This is the standard cross-account access pattern. The role's trust policy specifies the vendor's account as the principal, allowing its IAM users to assume the role via STS. The permissions policy grants S3 access. No IAM users are created in the company account, and all access is audited through CloudTrail, which logs AssumeRole and S3 API calls. This meets all requirements.

Why this answer

Cross-account access is best achieved by creating an IAM role in the trusting account that the trusted account can assume. The trust policy names the vendor's account, and the permissions policy grants S3 access. This avoids creating IAM users in the company account and ensures all actions are logged in CloudTrail.

Other options either violate security best practices or use unsupported features.

Exam trap

The trap here is assuming that AWS RAM can share S3 buckets, when it cannot, or that creating IAM users is acceptable despite the explicit requirement to avoid them.

977
MCQhard

A company uses AWS Organizations with multiple accounts. The security team needs a centralized solution to automatically initiate incident response runbooks across all accounts when a threat is detected. Which approach meets these requirements?

A.Use AWS Security Hub with cross-account aggregation and Amazon EventBridge to trigger AWS Systems Manager Automation runbooks.
B.Enable Amazon GuardDuty in all accounts and use its built-in remediation actions.
C.Configure AWS CloudFormation StackSets to deploy incident response stacks in all accounts.
D.Deploy an AWS Lambda function in each member account to respond to findings.
AnswerA

Security Hub's cross-account aggregation consolidates findings from all member accounts into a single delegated administrator account, enabling a central view of threats. You can then create EventBridge rules that match specific finding types and trigger Systems Manager Automation runbooks, which can execute remediation actions directly in the affected member account. This provides centralized, event-driven response without manually managing each account individually.

Why this answer

AWS Security Hub with cross-account aggregation collects findings from all accounts into a single administrator account. Amazon EventBridge can then be configured to match specific Security Hub findings (e.g., a GuardDuty threat detection) and trigger AWS Systems Manager Automation runbooks. This provides a centralized, automated incident response mechanism across all accounts without requiring per-account Lambda functions or manual remediation.

Exam trap

The trap here is that candidates often assume GuardDuty's built-in remediation actions are sufficient for centralized multi-account response, but those actions are per-account and lack the orchestration and customization of Security Hub + EventBridge + Systems Manager Automation.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty's built-in remediation actions are limited to predefined, account-specific responses (e.g., blocking IPs via network ACLs) and cannot be centrally orchestrated across all accounts or customized as runbooks. Option C is wrong because AWS CloudFormation StackSets deploy static infrastructure stacks, not dynamic incident response workflows triggered by real-time threats; they lack event-driven automation. Option D is wrong because deploying a Lambda function in each member account creates a decentralized, harder-to-manage solution that requires per-account IAM roles and lacks a single point of orchestration, contrary to the requirement for a centralized solution.

978
MCQeasy

A company wants to receive real-time notifications when an IAM user in their AWS account performs a console login. Which AWS service should be used to monitor and alert on this activity?

A.AWS IAM
B.AWS Config
C.AWS Trusted Advisor
D.AWS CloudTrail and Amazon EventBridge
AnswerD

AWS CloudTrail captures all API activity as events, including who made the call, which service, and the result. These events are delivered to Amazon EventBridge in near real time, where a rule can filter for a specific action (for example, `iam:CreateUser` or `sts:AssumeRole`) and route the matched event to an SNS topic or Lambda function to send a notification. Together they provide an event-driven pipeline for real-time alerting on API calls.

Why this answer

AWS CloudTrail logs console login events, and Amazon EventBridge can be used to create rules that trigger notifications (e.g., via SNS) in real-time when such events occur. Option A is incorrect because IAM does not provide monitoring capabilities. Option B is incorrect because AWS Config is designed for tracking resource configuration changes, not API call activity.

Option C is incorrect because Trusted Advisor offers best-practice recommendations and does not provide real-time monitoring of login events.

979
MCQmedium

A security engineer is reviewing the SQS queue policy shown in the exhibit. The queue is subscribed to an SNS topic in the same account. The security team has a requirement that only the SNS topic should be allowed to send messages to the queue. What is the issue with this policy?

A.The second statement allows any principal in the 10.0.0.0/8 range to receive messages from the queue.
B.The policy does not specify a principal, so it will not work.
C.The aws:SourceArn condition uses ArnLike which is deprecated.
D.The aws:SourceIp condition cannot be used with SQS queue policies.
AnswerA

The second statement grants ReceiveMessage to Principal '*' but limits the request to the 10.0.0.0/8 network via aws:SourceIp. That condition only restricts the caller's IP address; it does not restrict which IAM principal or account can call, so any authenticated principal originating from that CIDR may receive messages. Production should scope the principal to a specific account or IAM role, or add aws:SourceArn if the intent is to allow only a single source service.

Why this answer

The second statement in the SQS queue policy allows any principal in the 10.0.0.0/8 IP range to receive messages from the queue, which violates the security requirement that only the SNS topic should be allowed to send messages. The policy should restrict the `sqs:SendMessage` action to the SNS topic using a condition like `aws:SourceArn` and should not include a broad `Effect: Allow` for `sqs:ReceiveMessage` without restricting the principal or source.

Exam trap

The trap here is that candidates may focus on the `aws:SourceArn` condition or the lack of a principal, overlooking the fact that the second statement grants broad receive access to any IP in the 10.0.0.0/8 range, which violates the requirement to restrict message sending to only the SNS topic.

How to eliminate wrong answers

Option B is wrong because SQS queue policies can work without specifying a principal if the policy is attached to the queue itself, and the `Principal` element can be omitted or set to `*` to allow all principals, but the issue here is not the absence of a principal. Option C is wrong because `ArnLike` is not deprecated; it is a valid condition operator used for pattern matching on ARNs, and the `aws:SourceArn` condition is commonly used with `ArnLike` to restrict access to specific resources. Option D is wrong because `aws:SourceIp` can be used with SQS queue policies to restrict access based on IP addresses, but it is not the issue here; the problem is the overly permissive second statement.

980
MCQhard

A company is deploying a multi-tier web application across multiple Availability Zones. The application includes a web tier, application tier, and database tier. The security team requires that the web tier can communicate with the application tier only on port 8080, and the application tier can communicate with the database tier only on port 3306. Which security group configuration should be used?

A.In the application tier security group, allow inbound from the web tier security group on port 8080. In the database tier security group, allow inbound from the application tier security group on port 3306.
B.In the database tier security group, allow inbound from the application tier's CIDR block on port 3306.
C.In the application tier security group, allow inbound from the web tier's CIDR block on port 8080.
D.In the web tier security group, allow outbound to 0.0.0.0/0 on port 8080.
AnswerA

This is correct because security group references create a logical firewall between tiers that is independent of IP addresses. The application tier security group only accepts HTTP traffic originating from resources that are members of the web tier security group, and the database tier security group only accepts MySQL traffic from members of the application tier security group. AWS resolves the referenced security group to the private IPs of its associated instances at the time the traffic is evaluated, so scaling events and IP changes do not require rule updates.

Why this answer

Referencing security groups as sources (security group referencing) is the AWS-recommended, least-privilege approach for tiered applications. The application tier SG allows inbound on 8080 only from the web tier SG, and the database tier SG allows inbound on 3306 only from the application tier SG. This ensures traffic is permitted based on the identity of the source instances, not on IP ranges, and it scales automatically as instances are added or removed.

Exam trap

SCS-C02 often tests whether candidates know security groups can reference other security groups, so they default to CIDR-based rules and lose least-privilege points.

How to eliminate wrong answers

Option B is wrong because using the application tier's CIDR block is less secure and brittle — it permits any resource in that subnet, not just the application instances, and breaks if IPs change. Option C is wrong because using the web tier's CIDR block similarly allows any host in that subnet, violating least privilege, and it does not restrict to the web tier's actual instances. Option D is wrong because allowing outbound to 0.0.0.0/0 on port 8080 from the web tier does not control inbound access to the application tier and is overly permissive; security groups are stateful, so outbound rules are not the mechanism for restricting tier-to-tier inbound traffic.

981
MCQeasy

A company is using AWS CloudTrail to log API calls. The security team wants to ensure that log files are not modified after they are created. Which feature should they enable?

A.Server-side encryption with AWS KMS
B.Log file integrity validation
C.S3 Object Lock
D.CloudWatch Logs integration
AnswerB

Log file integrity validation is a CloudTrail feature that uses SHA-256 hashing and digital signatures to build a hash chain across log and digest files. CloudTrail periodically delivers a signed digest file that includes the hash of every log file delivered during that period and the hash of the previous digest. If anyone modifies or deletes a log after delivery, the hash stored in the next digest will not match, and the validation command will flag the discrepancy. This is the only option here that provides direct, detection-based integrity assurance for CloudTrail logs.

Why this answer

CloudTrail log file integrity validation uses SHA-256 hashing and RSA digital signatures to create digest files that let you verify log files have not been altered or deleted after delivery. It is the native CloudTrail feature designed specifically for tamper detection.

Exam trap

SCS-C02 often tests the confusion between encryption (confidentiality) and integrity validation (tamper detection) — candidates must not assume KMS encryption prevents log modification.

How to eliminate wrong answers

Option A is wrong because KMS server-side encryption protects confidentiality at rest but does not detect or prevent post-creation modification — an attacker with KMS access could still alter logs. Option C is wrong because S3 Object Lock provides WORM protection but is an S3 feature, not a CloudTrail integrity mechanism, and requires enabling on the bucket separately; it prevents deletion/overwrite but does not provide cryptographic verification of log integrity. Option D is wrong because CloudWatch Logs integration streams events for monitoring but does not validate the integrity of delivered CloudTrail log files.

982
MCQeasy

A security engineer needs to monitor AWS account activity for suspicious API calls, such as disabling AWS CloudTrail or deleting an AWS Config recorder. The engineer wants to receive near-real-time alerts when such events occur. Which AWS service should the engineer use to meet these requirements?

A.Amazon CloudWatch Events (now Amazon EventBridge)
B.AWS CloudTrail Insights
C.Amazon GuardDuty
D.AWS Security Hub
AnswerA

Amazon EventBridge can match events from AWS CloudTrail and trigger alerts via Amazon SNS or other targets. You can create a rule that matches specific API calls like StopLogging or DeleteConfigurationRecorder and sends a notification. This provides near-real-time alerts for the specified events.

Why this answer

Amazon EventBridge (formerly CloudWatch Events) can monitor AWS CloudTrail logs for specific API calls and trigger alerts in near real-time. By creating an event rule that matches events like StopLogging or DeleteConfigurationRecorder, the engineer can receive immediate notifications. This directly meets the requirement.

Exam trap

The trap here is confusing threat detection services like GuardDuty with event-driven monitoring services like EventBridge.

983
MCQhard

An IAM policy has the following statement: {"Effect":"Allow","Action":"s3:*","Resource":"arn:aws:s3:::my-bucket/*"}. A user with this policy tries to perform s3:ListBucket on 'my-bucket'. Will the request succeed?

A.No, because there is an explicit deny elsewhere.
B.Yes, because s3:* allows all actions.
C.No, because the resource ARN does not include the bucket itself.
D.Yes, because the user has permission to access objects.
AnswerC

s3:ListBucket is a bucket-level action, so IAM evaluates the Resource against the bucket's ARN (arn:aws:s3:::bucket), not the ARN of objects inside it. A resource pattern that includes only the wildcard for object keys (e.g., arn:aws:s3:::bucket/*) does not match the bucket ARN, because the bucket itself is a distinct resource. Consequently, the allow statement does not cover this request, and the user cannot list the bucket.

Why this answer

The statement grants s3:* on arn:aws:s3:::my-bucket/*, which matches only objects inside the bucket, not the bucket itself. s3:ListBucket is a bucket-level operation that requires the resource arn:aws:s3:::my-bucket (without the /*). Since the policy does not grant access to that resource, the request is denied by default. This is a classic IAM resource-ARN mismatch.

Exam trap

SCS-C02 often tests the misconception that s3:* on a bucket/* ARN grants all S3 actions on the bucket, but bucket-level actions require the bucket ARN without the wildcard.

How to eliminate wrong answers

Option A is wrong because there is no explicit deny in the policy; the request fails due to lack of an Allow, not an explicit Deny. Option B is wrong because s3:* allows all S3 actions only on the resources specified; the resource ARN here is limited to objects, so bucket-level actions are not permitted. Option D is wrong because permission to access objects does not imply permission to list the bucket; ListBucket is a separate bucket-level action requiring its own resource ARN.

984
MCQmedium

A security engineer needs to provide a detailed report of all IAM users, their access keys, and the last time each key was used, to identify unused credentials. Which AWS service or feature should the engineer use to generate this report?

A.Amazon GuardDuty
B.IAM credential report
C.AWS CloudTrail logs
D.AWS Trusted Advisor
AnswerB

The IAM credential report provides a CSV file listing all IAM users and the status of their credentials, including passwords, access keys, MFA devices, and the last used date for each. It is the most direct way to obtain the required information for identifying unused credentials.

Why this answer

The IAM credential report is specifically designed to provide a comprehensive list of IAM users and their credential details, including last used information for access keys. It is generated on demand and can be downloaded as a CSV. Other services like CloudTrail, Trusted Advisor, and GuardDuty do not offer this consolidated view, making the credential report the correct choice.

Exam trap

The trap here is thinking that CloudTrail logs can easily provide last used dates for access keys, but CloudTrail logs record API calls, not a summary of credential usage, and would require significant effort to aggregate.

985
Multi-Selecthard

Which THREE services can be used to detect and alert on suspicious API activity across an AWS organization? (Choose three.)

Select 3 answers
A.Amazon Inspector
B.Amazon GuardDuty
C.AWS Config
D.AWS Security Hub
E.AWS CloudTrail
AnswersB, D, E

Amazon GuardDuty is a continuous threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to analyze AWS CloudTrail management events, VPC Flow Logs, and DNS query logs. It identifies suspicious API calls, potential credential compromise, and malicious network traffic, and generates detailed findings that can be sent to CloudWatch Events to trigger automated notifications or responses. This directly enables detection and alerting on suspicious activity in near real-time.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious or unauthorized behavior, including suspicious API activity. It uses machine learning, anomaly detection, and integrated threat intelligence to analyze AWS CloudTrail management events, VPC Flow Logs, and DNS logs across an AWS organization, and can trigger alerts via Amazon EventBridge or Security Hub.

Exam trap

The trap here is that candidates often confuse AWS Config's compliance monitoring (e.g., checking if CloudTrail is enabled) with actual threat detection, but Config does not analyze API calls for suspicious patterns—it only checks configuration state against rules.

986
MCQmedium

A security engineer is reviewing AWS CloudTrail logs and notices a large number of DeleteBucket API calls from an unfamiliar IAM role. The engineer wants to automatically notify the security team when similar suspicious API activity occurs in the future. The notification must be sent within minutes and should include details such as the IAM role and the bucket name. Which solution should the engineer implement?

A.Enable CloudTrail Insights and configure an Amazon CloudWatch alarm on the Insights metric to send notifications via Amazon SNS.
B.Use Amazon GuardDuty to monitor for S3 bucket deletion activity and configure GuardDuty findings to send notifications via Amazon SNS.
C.Configure AWS Config to record configuration changes for S3 buckets and use an AWS Config rule to trigger an Amazon SNS notification when a bucket is deleted.
D.Create an Amazon EventBridge rule that matches AWS API calls via CloudTrail, filter for the DeleteBucket event, and route the event to an Amazon SNS topic that notifies the security team.
AnswerD

EventBridge can match CloudTrail management events in near real time. By creating a rule that filters for DeleteBucket events, you can route the full event JSON to an SNS topic, which sends email or SMS to the security team. This provides rapid notification and includes details like the IAM role and bucket name in the event payload.

Why this answer

EventBridge can match CloudTrail management events and filter for specific API calls like DeleteBucket. Routing the event to SNS provides near real-time notification with the full event details, including the IAM role and bucket name. This is the most direct and low-latency solution for the requirement.

Exam trap

The trap here is thinking that GuardDuty or CloudTrail Insights will alert on specific API calls, when they are designed for anomaly detection rather than exact event matching.

987
MCQhard

A company has a multi-account AWS environment using AWS Organizations. The security team needs to enforce that all new S3 buckets created in any account in the organization are encrypted with a specific KMS key. Which approach should be used?

A.Set up AWS Config rules to detect non-compliant buckets
B.Apply a Service Control Policy (SCP) that denies s3:CreateBucket unless encryption is configured
C.Create an IAM role that requires encryption and attach it to all users
D.Use an S3 bucket policy with a condition for encryption
AnswerB

SCPs can deny actions based on conditions, enforcing encryption at creation time.

Why this answer

Service Control Policies (SCPs) in AWS Organizations can centrally deny the creation of S3 buckets unless specific encryption conditions are met. By using an SCP with a condition that requires `s3:x-amz-server-side-encryption-aws-kms-key-id` to match the specific KMS key ARN, the security team can enforce encryption at the organizational level, preventing any account from creating non-compliant buckets regardless of IAM permissions.

Exam trap

The trap here is that candidates often confuse detective controls (AWS Config) with preventive controls (SCPs), or mistakenly think S3 bucket policies can govern bucket creation, when in fact bucket policies only apply to operations on existing buckets.

How to eliminate wrong answers

Option A is wrong because AWS Config rules are detective, not preventive; they can detect non-compliant buckets after creation but cannot block the creation itself, leaving a window of non-compliance. Option C is wrong because IAM roles attached to users do not enforce encryption on S3 bucket creation across all accounts in the organization; users can still create buckets without encryption if they have direct S3 permissions or use other roles, and IAM roles cannot override permissions granted by other policies. Option D is wrong because S3 bucket policies are resource-based and apply only to existing buckets, not to the creation of new buckets; they cannot prevent a bucket from being created without encryption.

988
Multi-Selectmedium

Which TWO actions should a security engineer take to ensure that an S3 bucket is not publicly accessible? (Choose two.)

Select 2 answers
A.Enable S3 Block Public Access at the account level
B.Enable AWS CloudTrail for the bucket
C.Remove all bucket ACLs
D.Set a bucket policy that denies all public access
E.Enable S3 Block Public Access at the bucket level
AnswersA, E

Enabling S3 Block Public Access at the account level is the definitive control because it applies a centralized, organization-wide guardrail that overrides any per-bucket settings. It blocks public access through all four mechanisms—ACLs, bucket policies, access point policies, and multi-object access point policies—and, once set, cannot be overridden by a bucket policy unless the account-level setting itself is changed. This creates a hard boundary that ensures no bucket in the account can be made publicly accessible, even if a future misconfiguration or a bucket policy explicitly permits public access. The question asks for actions to 'ensure' protection, making this the strongest and most reliable answer as it covers all existing and future buckets.

Why this answer

Block Public Access settings at bucket and account level prevent all public access. The other options are not correct because: ACLs can allow public access; CloudTrail does not block; Bucket policies are overridden by Block Public Access.

989
MCQeasy

A security team wants to detect and alert on API calls that create or modify IAM roles in their AWS account. Which AWS service can be used to create a metric filter and alarm for these specific CloudTrail events?

A.Amazon GuardDuty
B.AWS CloudTrail
C.Amazon CloudWatch Logs
D.AWS Config
AnswerC

Amazon CloudWatch Logs can ingest CloudTrail events when a trail is configured to send events to CloudWatch Logs, and then you can create a metric filter that uses pattern matching to identify specific API calls such as 'StopInstances' or 'DeleteBucket'. The metric filter counts occurrences of matching events in near-real time, and a CloudWatch alarm on that metric can trigger an SNS notification or other action. This is a native, fully managed solution for custom API call detection and alerting, directly satisfying the security team's requirement.

Why this answer

Amazon CloudWatch Logs can create metric filters on CloudTrail log data to detect specific API calls, such as CreateRole or UpdateAssumeRolePolicy. These metric filters can then trigger CloudWatch alarms for real-time notification. CloudTrail delivers logs to CloudWatch Logs, but the metric filter and alarm capabilities reside in CloudWatch Logs, not in CloudTrail itself.

Exam trap

The trap here is that candidates often confuse CloudTrail's logging capability with CloudWatch Logs' metric and alarm features, assuming CloudTrail itself can create alarms, when in reality CloudTrail only delivers logs and CloudWatch Logs provides the filtering and alerting mechanism.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes CloudTrail events, VPC flow logs, and DNS logs for malicious activity, but it does not allow you to create custom metric filters or alarms for specific API calls. Option B is wrong because AWS CloudTrail records API calls and delivers log files to an S3 bucket or CloudWatch Logs, but it does not have native metric filter or alarm creation capabilities. Option D is wrong because AWS Config evaluates resource configurations against rules and tracks configuration changes, but it does not create metric filters or alarms on CloudTrail event patterns.

990
MCQmedium

A security engineer is troubleshooting an issue where an IAM user is unable to list objects in an S3 bucket even though the user has an IAM policy that allows s3:ListBucket. What is the MOST likely cause?

A.The user's IAM policy is not attached to the user.
B.The bucket is in a different AWS region.
C.The user needs to use MFA.
D.The bucket policy explicitly denies the action for that user.
AnswerD

In S3, an explicit deny in a bucket policy takes precedence over any allow from an identity-based IAM policy. When a bucket policy includes a Deny statement that matches the principal, action, and resource, the request is rejected regardless of the user's IAM permissions. This is the most direct and common cause of an Access Denied error when the user's IAM policy already grants the s3:ListBucket action.

Why this answer

In AWS, an explicit deny in a bucket policy overrides any allow in an IAM policy. Even if the IAM user has s3:ListBucket allowed, if the bucket policy explicitly denies that action for that user, the user will be unable to list objects. This is the most likely cause given the scenario.

Exam trap

The trap is assuming that an IAM allow is sufficient; candidates might overlook the possibility of an explicit deny in a bucket policy, which takes precedence.

How to eliminate wrong answers

Option A is wrong because if the IAM policy were not attached, the user would have no permissions at all, but the question states the user has an IAM policy that allows s3:ListBucket. Option B is wrong because S3 bucket names are globally unique and region is specified in the endpoint; a different region would cause a redirect but not an authorization failure. Option C is wrong because MFA is not required for s3:ListBucket by default; it could be enforced by policy, but that would be an explicit deny or condition, not the most likely cause without evidence.

991
MCQhard

A company uses AWS Organizations with multiple accounts. The security team wants to detect suspicious API activity across all accounts in real time. They have enabled AWS CloudTrail in all accounts and are sending logs to a centralized S3 bucket. However, they are receiving alerts only after a significant delay. What should the security team do to reduce the latency of threat detection?

A.Set up Amazon EventBridge rules in each account to send specific CloudTrail events to a centralized event bus for immediate processing.
B.Enable Amazon GuardDuty in each account and configure it to send findings to a centralized S3 bucket.
C.Configure CloudTrail to deliver logs to a single S3 bucket and use S3 Event Notifications to trigger a Lambda function.
D.Use Amazon CloudWatch Logs Insights to query CloudTrail logs across accounts in real time.
AnswerA

This is the correct approach because Amazon EventBridge can ingest CloudTrail API calls in near real time via the default event bus in each account. You can then attach a rule that matches specific CloudTrail event names (e.g., ConsoleLogin, CreateAccessKey) and routes them to a centralized event bus in a monitoring account using an EventBridge cross-account target. This enables immediate, event-driven processing through AWS Lambda, Step Functions, or SNS, and avoids the multi-minute batching delays inherent in CloudTrail S3 delivery.

Why this answer

Amazon EventBridge can be configured with rules in each account to forward specific CloudTrail events to a centralized event bus in near real time, bypassing the latency introduced by CloudTrail log delivery to S3 (which can be up to 15 minutes). This allows the security team to process and alert on suspicious API activity immediately as events occur, rather than waiting for log files to be delivered and processed.

Exam trap

The trap here is that candidates often assume CloudTrail logs in S3 are the only source for threat detection, overlooking that EventBridge can ingest CloudTrail events in real time without waiting for S3 log delivery.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty generates findings based on its own threat detection models, not on real-time CloudTrail events, and sending findings to an S3 bucket introduces similar delivery latency (up to 5 minutes for GuardDuty findings). Option C is wrong because S3 Event Notifications are typically invoked after CloudTrail delivers log files to the bucket, which can have a delay of several minutes, and they are not designed for sub-second real-time event processing. Option D is wrong because Amazon CloudWatch Logs Insights is a query tool for historical log analysis, not a real-time streaming or alerting mechanism; it cannot reduce the latency of threat detection because it queries already-delivered logs.

992
MCQmedium

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The security team wants to analyze web request logs to identify potential SQL injection attacks. Which AWS service should be used to collect and analyze the ALB access logs?

A.VPC Flow Logs
B.AWS WAF
C.Amazon CloudWatch Logs Insights
D.Amazon Athena
AnswerD

Amazon Athena is the correct choice because it allows you to query ALB access logs directly in S3 using standard SQL without needing to load or transform the data. You can create an external table over the gzipped log files, then run SQL queries that look for SQL injection indicators such as 'OR 1=1', suspicious quotes, or UNION SELECT statements in the request and URL fields. This serverless, on-demand query engine is ideal for post-incident forensic analysis of historical access logs stored in S3.

Why this answer

Amazon Athena is the correct service because it allows you to query ALB access logs stored in Amazon S3 directly using standard SQL, without needing to load or transform the data. This makes it ideal for ad-hoc analysis of web request logs to identify patterns like SQL injection attempts, as you can run complex queries against the raw log data.

Exam trap

The trap here is that candidates often confuse AWS WAF's real-time blocking capability with the need for post-incident log analysis, leading them to choose WAF instead of recognizing that Athena is the appropriate service for querying stored ALB access logs.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) but do not include application-layer details like HTTP request URIs or payloads needed to detect SQL injection. Option B is wrong because AWS WAF is a web application firewall that can block SQL injection attacks in real time, but it does not provide a mechanism to analyze historical ALB access logs; it operates on incoming traffic, not stored logs. Option C is wrong because Amazon CloudWatch Logs Insights is designed to query CloudWatch Logs, but ALB access logs are not automatically sent to CloudWatch Logs; they are delivered to S3, and CloudWatch Logs Insights cannot directly query S3 data without additional configuration like a subscription filter or Lambda.

993
MCQeasy

A company needs to encrypt data in transit between an on-premises data center and Amazon S3. Which solution should they use?

A.Use AWS KMS to encrypt the data before transmission.
B.Use an S3 VPC endpoint.
C.Use HTTPS endpoints for S3 API calls.
D.Use S3 Transfer Acceleration.
AnswerC

HTTPS endpoints for S3 API calls use Transport Layer Security (TLS) to encrypt the entire HTTP request and response payload between the on-premises client and the S3 service. This protects the confidentiality and integrity of data in transit, preventing eavesdropping and tampering. Using HTTPS is the standard, built-in mechanism for securing S3 API traffic, and it applies regardless of whether the client is in your VPC or on-premises.

Why this answer

HTTPS (HTTP over TLS) encrypts data in transit between the on-premises data center and Amazon S3 by using TLS 1.2/1.3 to secure the API calls. This ensures that all data transmitted over the network is encrypted end-to-end, protecting it from eavesdropping and man-in-the-middle attacks. AWS S3 enforces HTTPS for all API requests when using the default endpoint, and customers can also configure bucket policies to deny HTTP requests.

Exam trap

The trap here is that candidates often confuse encryption at rest (KMS) with encryption in transit, or assume that network-level features like VPC endpoints or Transfer Acceleration inherently provide encryption, when in fact they do not add transport-layer security beyond what HTTPS already provides.

How to eliminate wrong answers

Option A is wrong because AWS KMS is a key management service for encrypting data at rest, not for encrypting data in transit; it does not provide transport-layer encryption during transmission. Option B is wrong because an S3 VPC endpoint (Gateway or Interface type) provides private connectivity to S3 over the AWS network but does not inherently encrypt data in transit; encryption must still be applied at the application layer (e.g., HTTPS). Option D is wrong because S3 Transfer Acceleration optimizes transfer speed by using AWS edge locations and the AWS global network, but it does not add encryption; it relies on the same HTTPS/TLS encryption used by standard S3 endpoints.

994
MCQhard

Refer to the exhibit. This IAM policy is attached to a user. The user attempts to assume the AdminRole without using MFA. What is the result?

A.The user can assume the role because the Allow statement grants it
B.The user cannot assume the role because the Deny statement blocks all actions when MFA is not present
C.The user can assume the role because the Deny statement does not apply to sts:AssumeRole
D.The user cannot assume the role because the Allow statement requires MFA
AnswerB

The Deny statement applies to all actions, including sts:AssumeRole, because its Action element is the wildcard '*'. Its condition, typically 'aws:MultiFactorAuthPresent' being false, is true for a user who has not authenticated with MFA, so the explicit deny is in effect. Under IAM's evaluation logic, an explicit deny always blocks the request, regardless of any other matching Allow statements, so the role assumption fails.

Why this answer

The Deny statement explicitly denies all actions when MFA is not present, overriding the Allow statement. Since the user is not using MFA, sts:AssumeRole is denied. Option A is incorrect because the Deny overrides the Allow.

Option C is incorrect because the Deny applies to all actions, including sts:AssumeRole. Option D is incorrect because the Deny, not the Allow, imposes the MFA requirement.

995
Multi-Selectmedium

Which THREE steps should a security engineer take to ensure that an incident response plan for an AWS environment is effective? (Choose three.)

Select 3 answers
A.Regularly test the incident response plan through tabletop exercises and simulations.
B.Document and maintain an up-to-date list of incident response team members and their contact information.
C.Use the AWS account root user for incident response actions to ensure full permissions.
D.Store all evidence in an S3 bucket with public read access for easy sharing.
E.Automate containment actions using AWS Lambda and AWS Systems Manager.
AnswersA, B, E

Tabletop exercises and game days on AWS simulate realistic compromise scenarios (e.g., a compromised EC2 instance or leaked access key) so responders can validate runbooks, verify IAM escalation/containment steps, and identify gaps before a real event. AWS Well-Architected and Security Incident Response guides recommend periodic testing to improve procedural accuracy, tool effectiveness, and decision-making under stress. This is a core preparedness activity.

Why this answer

Regularly testing the incident response plan through tabletop exercises and simulations validates the plan's effectiveness, identifies gaps, and ensures team readiness. AWS recommends using Game Days and fault injection simulators to practice real-world scenarios without impacting production environments.

Exam trap

The trap here is that candidates may mistakenly believe the root user is necessary for incident response due to its full permissions, but AWS best practices and the SCS-C02 exam emphasize using IAM roles with just-in-time access and MFA for all response actions.

996
MCQeasy

A company wants to automate the response to a specific GuardDuty finding. When GuardDuty detects a finding of type `UnauthorizedAccess:EC2/SSHBruteForce`, they want to automatically block the offending IP address using a network ACL. Which AWS service can they use to orchestrate this response?

A.AWS Lambda
B.AWS Systems Manager Automation
C.AWS Config
D.AWS CloudFormation
AnswerB

Systems Manager Automation is the correct service because it runs SSM runbooks in response to events via Amazon EventBridge. A GuardDuty finding event can invoke a public or custom runbook, which then performs steps such as updating a VPC Network ACL with a deny rule for the offending IP address. This service provides built-in approval gates, rollback controls, and parameterized execution, making it the native orchestration layer for GuardDuty-driven incident response rather than a mere compute or provisioning tool.

Why this answer

AWS Systems Manager Automation is the correct service because it provides a runbook-based automation framework that can be triggered by Amazon EventBridge events from GuardDuty. When GuardDuty generates a finding of type `UnauthorizedAccess:EC2/SSHBruteForce`, an EventBridge rule can invoke an SSM Automation document that modifies the network ACL to block the offending IP address. This orchestration is natively supported by SSM Automation without requiring custom code, making it the ideal choice for automated incident response workflows.

Exam trap

The trap here is that candidates often assume AWS Lambda is the only option for custom automation, but the exam specifically tests knowledge of SSM Automation as a managed orchestration service that can perform remediation actions without writing code, especially when the question uses the word 'orchestrate'.

How to eliminate wrong answers

Option A is wrong because AWS Lambda is a compute service for running custom code, not an orchestration service; while Lambda can be used to modify network ACLs via SDK calls, the question asks for a service to 'orchestrate' the response, and SSM Automation is purpose-built for runbook-based orchestration with built-in error handling and approval steps. Option C is wrong because AWS Config is a configuration auditing and compliance service that evaluates resource configurations against rules; it cannot directly modify network ACLs or execute remediation actions without invoking another service like SSM Automation or Lambda. Option D is wrong because AWS CloudFormation is an infrastructure-as-code service for provisioning and managing AWS resources; it is not designed for real-time event-driven incident response and cannot dynamically modify a network ACL in response to a GuardDuty finding without additional services.

997
MCQhard

Refer to the exhibit. A security engineer applies this S3 bucket policy to an S3 bucket. The bucket contains sensitive data. What is the effect of this policy?

A.It allows anonymous users to upload objects.
B.It denies PutObject requests that are not using HTTPS.
C.It denies all PutObject requests to the bucket.
D.It enforces that all objects must be encrypted at rest.
AnswerB

With the condition key aws:SecureTransport set to false, the Deny effect triggers only when the request travels over plain HTTP. Since the Action is limited to s3:PutObject, only object uploads are blocked; other operations remain unaffected. The result is that any PUT request without TLS is rejected, effectively mandating HTTPS for uploads to the bucket while still allowing secure uploads to proceed.

Why this answer

The bucket policy uses a Deny effect with a condition on 'aws:SecureTransport' set to false, which blocks any PutObject request made over plain HTTP. Requests over HTTPS satisfy the condition (SecureTransport = true), so they are not denied by this statement. This is the standard pattern for enforcing encryption in transit for S3 uploads.

Exam trap

SCS-C02 often tests the confusion between encryption in transit (SecureTransport/HTTPS) and encryption at rest (SSE headers), so candidates pick the at-rest encryption option when the policy actually enforces TLS.

How to eliminate wrong answers

Option A is wrong because the policy explicitly denies requests, not allows anonymous uploads; there is no Allow statement granting public access. Option C is wrong because the Deny only applies when SecureTransport is false — HTTPS PutObject requests are permitted, so it does not deny all uploads. Option D is wrong because the policy conditions on transport security (HTTPS), not on encryption at rest; enforcing at-rest encryption requires conditions on 's3:x-amz-server-side-encryption'.

998
MCQeasy

A company is required to retain CloudTrail logs for 7 years for compliance. Which solution meets this requirement with the LEAST operational overhead?

A.Store logs in CloudWatch Logs with a retention period of 7 years.
B.Configure CloudTrail to automatically delete logs older than 7 years.
C.Use an AWS Lambda function to delete logs older than 7 years.
D.Configure an S3 Lifecycle policy to transition logs to S3 Glacier Deep Archive after 90 days and expire after 7 years.
E.Export logs to AWS Snowball for offline archival.
AnswerD

S3 Glacier Deep Archive satisfies the seven-year retention mandate at the lowest storage cost, while the lifecycle policy automates both the transition and the expiry date. This removes manual intervention entirely, delivering the least operational overhead compared with custom archival pipelines or third-party tooling.

Why this answer

It uses an S3 Lifecycle policy to automatically transition CloudTrail logs to S3 Glacier Deep Archive after 90 days (reducing storage costs) and then expire (delete) the objects after 7 years, meeting the retention requirement with zero ongoing operational effort. This is the least operational overhead solution as it is fully automated within S3, requiring no custom code, manual intervention, or additional services.

Exam trap

The trap here is that candidates may think CloudTrail itself manages log retention (Option B) or that CloudWatch Logs is the simplest option (Option A), but AWS explicitly requires you to manage retention at the destination, and S3 Lifecycle policies are the native, automated, and lowest-overhead solution for long-term archival and deletion.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs has a maximum retention period of 10 years, but storing 7 years of CloudTrail logs in CloudWatch Logs incurs high ingestion and storage costs compared to S3, and requires manual or automated export for long-term archival, increasing operational overhead. Option B is wrong because CloudTrail does not have a built-in feature to automatically delete logs older than a specified period; log retention and deletion must be managed at the destination (e.g., S3 Lifecycle policies). Option C is wrong because using a Lambda function to delete logs older than 7 years introduces custom code, potential execution failures, and ongoing maintenance, which is higher operational overhead than a native S3 Lifecycle policy.

Option E is wrong because exporting logs to AWS Snowball for offline archival is designed for large-scale data transfer and physical shipping, not for routine 7-year retention, and it adds significant operational overhead and latency.

999
MCQmedium

A security engineer is investigating a potential compromise of an IAM user. The engineer sees that the user's access keys were used from an IP address outside the company's allowed geography. Which AWS service can provide the most immediate notification of such anomalous API calls?

A.AWS Trusted Advisor
B.Amazon GuardDuty
C.AWS CloudTrail
D.Amazon CloudWatch
AnswerB

GuardDuty is a continuous, intelligent threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to identify unexpected and potentially malicious activity within your AWS environment. It analyzes CloudTrail management and data events, VPC Flow Logs, and DNS query logs to detect suspicious API calls, unusual network traffic, and compromised credentials. Findings are generated with severity levels and can automatically trigger remediation workflows via EventBridge, making it the ideal service for investigating a potential compromise.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious or unauthorized behavior, including anomalous API calls from unusual geographies. It uses machine learning and integrated threat intelligence to analyze CloudTrail events, VPC flow logs, and DNS logs in near real-time, enabling immediate notification of suspicious activity such as access key usage from an unexpected IP address.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail's logging capability with active threat detection, forgetting that CloudTrail only records events and requires an additional service like GuardDuty or a custom CloudWatch alarm to provide immediate notification of anomalous activity.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor provides best-practice recommendations for cost, performance, security, and fault tolerance, but it does not monitor or alert on anomalous API calls in real-time; it is a reactive advisory tool, not a threat detection service. Option C is wrong because AWS CloudTrail is a logging service that records API activity, but it does not analyze or alert on anomalous behavior; it requires an additional service like GuardDuty or a custom CloudWatch rule to generate notifications. Option D is wrong because Amazon CloudWatch can monitor metrics and logs and trigger alarms, but it lacks built-in threat detection intelligence; to detect anomalous geolocation-based API calls, you would need to manually create custom metrics and alarms from CloudTrail logs, which is not immediate or automated compared to GuardDuty's out-of-the-box anomaly detection.

1000
MCQhard

Refer to the exhibit. A security engineer configures the above KMS key policy. The DataAccess role is used by an application that runs on EC2 instances in the us-east-1 region. The application needs to read encrypted objects from an S3 bucket in the same region. Which of the following is true about this configuration?

A.The role can use the key for any S3 operation in any region.
B.The role cannot use the key for any operation because the condition is invalid.
C.The role can only encrypt data, not decrypt it.
D.The role can decrypt objects in S3, but cannot use the key outside of S3.
AnswerD

The role can decrypt objects in S3 because the policy grants kms:Decrypt and includes a condition that limits the key's use to the S3 service in us-east-1 (for example, kms:ViaService with s3.us-east-1.amazonaws.com). This allows S3 to use the key to decrypt SSE-KMS-encrypted objects. However, the same condition prevents any other service (such as EC2, Lambda, or EBS) from using the key, even within us-east-1. The role also cannot use the key with S3 in other regions, so the overall scope is exactly S3 in us-east-1 for the allowed actions.

Why this answer

The key policy includes a condition 'kms:ViaService' that restricts use of the key to requests that originate from S3 in us-east-1. The DataAccess role has permissions to call kms:Decrypt and kms:GenerateDataKey. With kms:Decrypt, the role can decrypt objects in S3 (e.g., via S3 GetObject with SSE-KMS).

The role can also encrypt objects via S3 PutObject using kms:GenerateDataKey. However, the 'kms:ViaService' condition prevents the role from using the key for any operation outside of S3 (e.g., direct KMS API calls). Option A is incorrect because the condition restricts usage to S3 in us-east-1 only, not any region or any operation.

Option B is incorrect because the condition 'kms:ViaService' is syntactically valid and functions as intended. Option C is incorrect because the role has kms:GenerateDataKey, which allows encryption via S3 PutObject, and kms:Decrypt for decryption, so it can both encrypt and decrypt.

1001
MCQhard

This SCP is attached to an organizational unit (OU). A developer in an account within the OU tries to launch a t2.small instance. What is the outcome?

A.The launch fails because the SCP denies all RunInstances actions.
B.The launch succeeds because the SCP allows t2.micro only.
C.The launch fails because the SCP denies non-t2.micro instances.
D.The launch succeeds because SCPs do not apply to developers.
AnswerC

The SCP's Deny effect triggers when the ec2:InstanceType condition does not equal t2.micro, typically using StringNotEquals. A t2.small instance does not match t2.micro, so the condition evaluates to true and the Deny takes effect, blocking the RunInstances call. Since SCPs are implicit deny guardrails applied at the OU level, not even the developer's IAM permissions can override this denial, so the launch fails with an unauthorized operation error.

Why this answer

The SCP denies ec2:RunInstances if the instance type is not t2.micro. Since t2.small is not t2.micro, the condition matches, and the action is denied. Option A is wrong because the SCP does not deny all RunInstances actions; it only denies those that do not match the condition.

Option B is wrong because the launch fails, not succeeds. Option D is wrong because SCPs apply to all principals in the account, including developers.

1002
MCQhard

An IAM user reports that they are unable to launch an EC2 instance in a specific VPC. The user has an IAM policy that allows ec2:RunInstances but does not grant permission for the subnet resource. The VPC has a network ACL that allows all inbound and outbound traffic. What is the most likely cause of the failure?

A.The IAM policy does not grant permission to use the VPC.
B.The security group associated with the instance is blocking the launch.
C.The IAM policy does not grant permission to use the subnet.
D.The network ACL is blocking the launch request.
AnswerC

Launching an instance with a resource-scoped IAM policy requires the ec2:RunInstances action to be granted on each dependent resource, including the subnet ARN (e.g., arn:aws:ec2:region:account-id:subnet/subnet-...). If the policy's Resource element omits the subnet but references the instance or AMI, the request fails with an explicit access denied because RunInstances is a 'create' action that conditionally requires subnet permission. This is the exact reason a user can have broad EC2 permissions yet still be blocked for a specific subnet.

Why this answer

ec2:RunInstances requires permissions on multiple resource types — the instance, the AMI, the subnet, the security group, the key pair, and the volume. If the IAM policy grants ec2:RunInstances on * for the instance resource but omits the subnet ARN (or uses a Resource that does not include the subnet), the request fails with an unauthorized error even though the VPC and NACL are permissive. The fix is to include the subnet ARN in the Resource element or use a wildcard that covers it.

Exam trap

SCS-C02 often tests the misconception that RunInstances only needs permission on the instance resource — candidates forget that the subnet, AMI, security group, and volume are also required resources in the IAM evaluation.

How to eliminate wrong answers

Option A is wrong because IAM does not have a separate 'use the VPC' permission for RunInstances — the relevant resource is the subnet, not the VPC itself. Option B is wrong because security groups are evaluated at the network layer after the instance is launched; they do not block the RunInstances API call itself. Option D is wrong because network ACLs operate at the subnet boundary for data-plane traffic and have no role in authorizing the control-plane RunInstances API call.

1003
Multi-Selectmedium

A company wants to ensure that all Amazon S3 buckets are encrypted at rest. Which THREE services can be used together to automatically remediate unencrypted S3 buckets?

Select 3 answers
A.Amazon S3 default encryption
B.AWS CloudTrail
C.Amazon EventBridge
D.AWS Config
E.AWS Lambda
AnswersC, D, E

Amazon EventBridge is the event-routing backbone of the remediation workflow: it receives compliance state-change events published by AWS Config, such as a bucket transitioning to NON_COMPLIANT for the s3-bucket-server-side-encryption-enabled rule. Using an EventBridge rule, you filter for these S3 compliance events and target an AWS Lambda function for automatic response. Without EventBridge, AWS Config would only generate history or console notifications and would not have a native, low-latency path to invoke custom remediation code.

Why this answer

AWS Config (D) is correct because it continuously evaluates S3 bucket configuration against a managed rule such as s3-bucket-server-side-encryption-enabled and flags buckets that are not encrypted at rest. Amazon EventBridge (C) is correct because it can receive the AWS Config compliance-change event (or a Config rule evaluation result) and route it to a target for automated remediation. AWS Lambda (E) is correct because it serves as the remediation target, running code that calls PutBucketEncryption to enable default encryption on the noncompliant bucket.

Amazon S3 default encryption (A) is not a remediation mechanism by itself; it only defines encryption applied to objects when the bucket setting is enabled, so it cannot detect or fix an unencrypted bucket. AWS CloudTrail (B) records API activity for auditing but does not evaluate resource compliance or trigger automatic remediation.

Exam trap

SCS-C02 often tests the misconception that CloudTrail or S3 default encryption alone can remediate — the trap is forgetting that Config detects, EventBridge routes, and Lambda acts, forming a three-service chain.

1004
MCQhard

A security engineer notices that an IAM user has permissions to create new IAM users and attach policies. What is the most effective way to detect if this user created a backdoor user?

A.Review S3 access logs for any PutObject calls from the IAM user.
B.Use IAM Access Analyzer to review all IAM policies for potential backdoor access.
C.Configure an AWS Config rule to check for IAM users with administrative policies.
D.Enable AWS CloudTrail and monitor IAM events using Amazon CloudWatch Logs and create a metric filter for CreateUser and AttachUserPolicy events.
AnswerD

AWS CloudTrail records every IAM control-plane API call, including CreateUser and AttachUserPolicy, as management events with the user identity, source IP, and timestamps. By delivering the trail to Amazon CloudWatch Logs and creating a metric filter that matches on the eventName field for these API calls, you can trigger an Amazon CloudWatch alarm to alert a security engineer in near real-time. This gives you both a complete audit trail and an automated detection mechanism, making it the appropriate detective control for this scenario.

Why this answer

The most effective way to detect if a user created a backdoor IAM user is to enable AWS CloudTrail and monitor IAM events such as CreateUser and AttachUserPolicy using CloudWatch Logs metric filters and alarms. CloudTrail records all API activity, including IAM changes, and CloudWatch can alert on specific event names in near real-time. This provides direct detection of the exact actions that would indicate backdoor user creation.

Exam trap

SCS-C02 often tests the difference between detection tools — candidates confuse Access Analyzer (policy analysis) with CloudTrail (activity logging) and pick the wrong service for detecting user creation events.

How to eliminate wrong answers

Option A is wrong because S3 access logs only record S3 data-plane operations like PutObject and have no visibility into IAM user creation or policy attachment. Option B is wrong because IAM Access Analyzer analyzes resource policies and permissions for external access, but it does not detect the creation of new IAM users or the act of attaching policies — it is a static analysis tool, not an activity monitor. Option C is wrong because an AWS Config rule checking for IAM users with administrative policies detects a configuration state, not the real-time event of a user being created, and it would not identify who created it or when.

1005
MCQhard

A company uses AWS CloudTrail to log all API calls. The security team notices that some PutObject API calls are not appearing in the CloudTrail logs. The S3 bucket in question has server access logging enabled. What is the MOST likely reason for the missing CloudTrail events?

A.CloudTrail was not configured to log data events for S3.
B.Server access logs are interfering with CloudTrail.
C.The PutObject calls were made via the AWS Management Console.
D.The S3 bucket policy denies CloudTrail from logging.
AnswerA

CloudTrail trails capture management events by default, but S3 data events such as PutObject require explicit enablement through trail configuration. Without adding S3 object-level data events for the bucket (or a prefix), PutObject requests will not appear in the CloudTrail history.

Why this answer

CloudTrail logs are categorized into management events and data events. By default, CloudTrail only logs management events (e.g., CreateBucket, DeleteBucket). Data events, such as S3 object-level operations like PutObject, must be explicitly enabled in the CloudTrail trail configuration.

Since the security team sees missing PutObject calls, the most likely cause is that CloudTrail was not configured to log S3 data events.

Exam trap

The trap here is that candidates often confuse CloudTrail management events (which are logged by default) with data events (which require explicit configuration), leading them to overlook the need to enable S3 data event logging.

How to eliminate wrong answers

Option B is wrong because server access logs are separate from CloudTrail logs; they are stored in a different S3 bucket and do not interfere with CloudTrail's ability to capture API calls. Option C is wrong because PutObject calls made via the AWS Management Console still generate S3 API calls that CloudTrail can capture if data events are enabled; the console does not bypass CloudTrail logging. Option D is wrong because an S3 bucket policy that denies CloudTrail from logging would affect CloudTrail's ability to deliver log files to the bucket, not prevent CloudTrail from capturing the PutObject events themselves.

1006
MCQmedium

A security analyst needs to review all failed SSH login attempts to an EC2 instance. Which combination will provide this information?

A.Use AWS Config to record EC2 instance configuration and check for security group changes.
B.Install the CloudWatch agent on the EC2 instance to collect /var/log/secure and stream to CloudWatch Logs.
C.Enable AWS CloudTrail and search for EC2-related events.
D.Enable VPC Flow Logs for the subnet and query the logs in CloudWatch Logs Insights for rejected traffic on port 22.
AnswerB

The CloudWatch agent (or unified agent) runs inside the EC2 instance and can tail local log files such as /var/log/secure on Amazon Linux/RHEL (or /var/log/auth.log on Ubuntu), streaming them to CloudWatch Logs. The sshd daemon writes entries like 'Failed password for ...' to this file for every failed authentication attempt. Reviewing the collected log group in CloudWatch Logs Insights, for example with a query filtering on 'Failed password', directly reveals the failed SSH login attempts and their source IPs.

Why this answer

The CloudWatch agent installed on the EC2 instance can collect OS-level logs such as /var/log/secure (on Linux), which contains detailed records of SSH authentication attempts, including failed logins. By streaming these logs to CloudWatch Logs, the analyst can query and review all failed SSH login attempts at the application layer. Options A, C, and D capture network-level metadata but do not provide information about authentication failures after a successful TCP connection.

Exam trap

The key pitfall is interpreting 'failed SSH login attempts' as network-level rejections rather than OS-level authentication failures. VPC Flow Logs show only accepted or rejected network traffic, not login outcomes. The correct approach is to collect system authentication logs via the CloudWatch agent.

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configuration changes, not network traffic or login attempts; it cannot capture failed SSH login events. Option B is wrong because /var/log/secure logs successful and failed authentication attempts at the OS level, but the question asks for 'failed SSH login attempts' as seen from the network perspective, and the CloudWatch agent collects OS logs, not network-level rejected packets. Option C is wrong because AWS CloudTrail records API calls made to the AWS management plane, not network traffic or SSH login attempts to the EC2 instance itself.

1007
MCQhard

A security engineer reviews the above IAM policy attached to an IAM user. The user reports that they cannot download objects from the S3 bucket 'example-bucket' when connected from the office network (IP range 10.0.0.0/16). What is the most likely cause?

A.The bucket policy overrides the IAM policy
B.The policy does not allow the s3:GetObject action
C.The source IP condition does not match the user's actual IP address
D.The user is not assuming the correct IAM role
AnswerC

The policy condition uses the aws:SourceIp global condition key and requires the request to originate from 10.0.0.0/16, a private RFC 1918 CIDR range. IAM compares this against the actual source IP recorded in the request, so if the IAM user is connecting from outside that range—for example, from a public internet address—the condition fails. When a condition fails, the Allow statement is skipped and the request is implicitly denied.

Why this answer

The IAM policy includes a `Condition` block using `aws:SourceIp` that restricts allowed IP addresses to the range 10.0.0.0/16. If the user's actual office network IP address falls outside this range (e.g., due to NAT or a different subnet), the condition fails, and the `s3:GetObject` action is denied, even though the user has the necessary permissions in the `Action` field.

Exam trap

The trap here is that candidates may overlook the `Condition` block and assume the policy allows the action because `s3:GetObject` is listed, failing to realize that the source IP condition can override the allow even when the action is explicitly permitted.

How to eliminate wrong answers

Option A is wrong because bucket policies and IAM policies are evaluated together; an explicit deny in either will override an allow, but there is no bucket policy mentioned in the scenario, and the IAM policy itself is the likely cause of denial. Option B is wrong because the policy explicitly includes `s3:GetObject` in the `Action` list, so the action is allowed by the policy statement. Option D is wrong because the policy is directly attached to the IAM user, not requiring role assumption; the user is already operating under the attached policy.

1008
MCQmedium

A security engineer is tasked with ensuring that all data stored in an RDS DB instance is encrypted at rest. The database is already running and contains data. What should the engineer do?

A.Change the KMS key associated with the DB instance
B.Modify the DB instance to use an encrypted storage type
C.Create a snapshot of the DB instance, copy it with encryption, and restore the encrypted snapshot
D.Enable encryption at rest in the RDS console for the existing DB instance
AnswerC

To enable encryption-at-rest on an existing unencrypted Amazon RDS DB instance, you must create a manual snapshot, make an encrypted copy of that snapshot (either with the default AWS-managed key or a customer-managed KMS key), and then restore a new DB instance from the encrypted snapshot. During the snapshot copy you can also specify a KMS key; the restored instance will be encrypted, and you can then update your applications' connection strings to point to the new endpoint. This is the documented and only supported approach, since encryption cannot be added in place.

Why this answer

RDS encryption at rest can only be enabled at DB instance creation time; it cannot be turned on for an existing unencrypted instance. The supported migration path is to take a snapshot of the unencrypted instance, copy that snapshot with the encryption option enabled (specifying a KMS key), and then restore a new DB instance from the encrypted snapshot. This produces an encrypted instance containing the same data.

Exam trap

SCS-C02 often tests the immutability of RDS encryption — candidates who assume encryption can be toggled on an existing instance pick the wrong 'modify' option.

How to eliminate wrong answers

Option A is wrong because you cannot change the KMS key on an unencrypted DB instance — there is no key associated with it, and the modify action does not add encryption. Option B is wrong because RDS does not expose an 'encrypted storage type' toggle in the modify-instance API; storage encryption is immutable after creation. Option D is wrong because the RDS console does not offer an 'enable encryption' checkbox for an existing unencrypted instance — that option only appears during creation.

1009
MCQmedium

A company needs to centralize security logs from multiple AWS accounts and on-premises servers. The logs must be encrypted at rest and stored in a cost-effective manner. Which solution meets these requirements?

A.Use Amazon S3 Glacier with Vault Lock
B.Use Amazon S3 with server-side encryption (SSE-S3)
C.Use Amazon Kinesis Data Firehose to deliver logs to Amazon Redshift
D.Use Amazon CloudWatch Logs with KMS encryption
AnswerB

Amazon S3 with SSE-S3 is the correct choice because S3 provides a cost-effective, highly durable object store optimized for high-volume log ingestion and retention, and SSE-S3 automatically encrypts each object with strong AES-256 encryption managed by AWS. S3 integrates natively with CloudTrail, VPC Flow Logs, and AWS Config to centralize logs from multiple accounts, and it supports lifecycle policies that can later transition older logs to S3 Glacier for further cost reduction. The encrypted-at-rest capability satisfies compliance requirements without the operational overhead of managing customer keys.

Why this answer

Amazon S3 with server-side encryption (SSE-S3) meets the requirements because it provides encryption at rest using AES-256, is cost-effective for log storage, and can centralize logs from multiple AWS accounts and on-premises servers via S3 Cross-Account Access and the S3 API. SSE-S3 is fully managed by AWS, requiring no additional key management overhead, and S3's lifecycle policies can transition older logs to lower-cost tiers like S3 Glacier for further cost savings.

Exam trap

The trap here is that candidates often choose Amazon CloudWatch Logs with KMS encryption (Option D) because it seems like a natural fit for log management, but they overlook the cost implications and the requirement for cost-effective storage, which S3 with SSE-S3 addresses more efficiently.

How to eliminate wrong answers

Option A is wrong because Amazon S3 Glacier with Vault Lock is designed for long-term archival and compliance, not for active log ingestion and retrieval, and it lacks the flexibility for centralized log aggregation from multiple sources. Option C is wrong because Amazon Kinesis Data Firehose delivering to Amazon Redshift is optimized for real-time analytics and data warehousing, not for cost-effective long-term log storage, and Redshift is significantly more expensive per GB than S3 for storing raw logs. Option D is wrong because Amazon CloudWatch Logs with KMS encryption is a viable option for log storage but is generally more expensive than S3 for large volumes of logs, and it does not natively support direct ingestion from on-premises servers without additional agents or configurations.

1010
MCQeasy

A security engineer wants to capture all DNS queries made by EC2 instances to detect potential data exfiltration. Which AWS service should be used to log the DNS requests?

A.Use Route 53 Resolver DNS Firewall with query logging
B.Use Amazon GuardDuty
C.Enable VPC Flow Logs
D.Enable AWS CloudTrail
AnswerA

Route 53 Resolver DNS Firewall query logging captures every DNS query that instances resolve through the Amazon-provided VPC resolver, publishing records to CloudWatch Logs, S3, or Kinesis Data Firehose. This satisfies the requirement to log all EC2 DNS requests for exfiltration detection, since instances use that resolver by default.

Why this answer

Route 53 Resolver DNS Firewall with query logging is the correct choice because it is specifically designed to log all DNS queries made by EC2 instances that use the Route 53 Resolver. This service captures the domain names being queried, the source IP, and the response, enabling detection of DNS-based data exfiltration (e.g., DNS tunneling). It integrates directly with the VPC's DNS resolver, ensuring all outbound DNS traffic from EC2 instances is logged without additional agents.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (which show IP-level metadata) with DNS query logs, not realizing that DNS exfiltration requires the actual domain names being queried, which only DNS-specific logging provides.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes DNS logs from Route 53 Resolver DNS Firewall or other sources, but it does not itself capture or log raw DNS queries; it relies on existing logs. Option C is wrong because VPC Flow Logs capture metadata about IP traffic (source/destination IP, ports, protocol) but do not log the actual DNS query names or payloads, making them insufficient for detecting DNS exfiltration. Option D is wrong because AWS CloudTrail logs API calls to AWS services (e.g., Route 53 API calls) but does not capture the DNS queries made by EC2 instances to external domains.

1011
MCQmedium

A company wants to enforce that all IAM users in an AWS account must have multi-factor authentication (MFA) enabled. Which AWS service can be used to automatically detect and remediate non-compliant users?

A.AWS Trusted Advisor
B.AWS IAM Access Analyzer
C.AWS CloudTrail
D.AWS Config
AnswerD

AWS Config continuously evaluates resources such as AWS::IAM::User against managed rules, and the iam-user-mfa-enabled rule specifically designates IAM users without a registered MFA device as noncompliant. Config can then invoke an AWS Systems Manager Automation document or a custom remediation action to remediate noncompliant IAM users, making it the only listed service that can both detect and act on missing MFA across all IAM users.

Why this answer

AWS Config continuously records resource configurations and evaluates them against rules. A managed rule such as 'iam-user-mfa-enabled' detects IAM users without MFA, and Config remediation actions (via SSM Automation documents) can automatically enforce MFA or disable non-compliant users. This gives both detection and automated remediation in a single service, matching the requirement.

Exam trap

SCS-C02 often tests the difference between services that only detect (Trusted Advisor, Access Analyzer, CloudTrail) and services that both detect and remediate (AWS Config with remediation actions) — candidates pick Trusted Advisor because it sounds like a security advisor.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor only provides advisory checks (including a security category for MFA on the root account) and cannot detect per-user MFA status or perform remediation. Option B is wrong because IAM Access Analyzer identifies resources shared with external entities (S3 buckets, roles, KMS keys) — it does not evaluate MFA compliance. Option C is wrong because CloudTrail only logs API activity; it records events but has no rule-evaluation or remediation capability.

1012
MCQmedium

A company needs to encrypt data at rest in Amazon Redshift. They want to use an AWS KMS customer managed key. What is the correct procedure to enable encryption for an existing Redshift cluster?

A.Enable encryption using the Redshift console by selecting the KMS key.
B.Use the AWS CLI command 'aws redshift modify-cluster' with --encrypted flag.
C.Modify the cluster and enable encryption with the KMS key.
D.Take a snapshot of the cluster, restore it to a new cluster with encryption enabled, and point applications to the new cluster.
AnswerD

To add encryption to an existing Redshift cluster, take a snapshot of the source cluster and restore it as a new cluster while specifying a KMS key in the restore settings. The restore operation initializes a fresh cluster with encryption enabled at the storage layer, then you can update your application's JDBC/ODBC connection strings and DNS to point to the new endpoint. Once verified, you can retire the old cluster. This is the only AWS-supported path for retrofitting encryption.

Why this answer

Amazon Redshift does not support enabling encryption on an existing cluster directly. The only way to transition an unencrypted cluster to an encrypted one is to take a snapshot of the cluster, restore it to a new cluster with encryption enabled using a KMS customer managed key, and then redirect applications to the new cluster. This is because encryption settings are immutable after cluster creation.

Exam trap

The trap here is that candidates assume encryption can be toggled on an existing cluster via console or CLI commands, similar to services like RDS or EBS, but Redshift enforces encryption as a cluster-level immutable property.

How to eliminate wrong answers

Option A is wrong because the Redshift console does not allow enabling encryption on an existing cluster; encryption can only be specified at cluster creation or during a restore from snapshot. Option B is wrong because the 'aws redshift modify-cluster' command does not support the --encrypted flag; encryption cannot be modified on a running cluster. Option C is wrong because modifying the cluster to enable encryption with a KMS key is not a supported operation; encryption settings are immutable after creation.

1013
MCQmedium

A security engineer is investigating a potential compromise. An EC2 instance running Amazon Linux 2 is sending outbound traffic to a known malicious IP address. The engineer needs to capture the network traffic for analysis without alerting the attacker. Which solution meets these requirements?

A.Enable VPC Flow Logs on the ENI and stream to Amazon S3 for analysis.
B.Attach a security group to the instance that logs all traffic to CloudWatch Logs.
C.Use VPC Traffic Mirroring to mirror the EC2 instance's ENI traffic to a monitoring appliance in a separate VPC.
D.Enable AWS Network Firewall on the VPC and configure a rule to log all traffic to the malicious IP.
AnswerC

VPC Traffic Mirroring copies the actual packet payloads from the EC2 instance's Elastic Network Interface and forwards them through a mirror session to a monitoring appliance—which can be hosted in a separate VPC via a Gateway Load Balancer or a Network Load Balancer. Because mirroring is out-of-band and does not insert in the data path, the original traffic is unaffected and the attacker is not alerted by any inline inspection or blocking. This provides full packet capture, enabling deep forensic analysis of the attacker's actions, commands, and any exfiltrated data with no impact on the live environment.

Why this answer

VPC Traffic Mirroring captures all network traffic at the packet level from the EC2 instance's Elastic Network Interface (ENI) and forwards it to a monitoring appliance without any inline processing or modification of the traffic. This allows the security engineer to perform deep packet analysis while remaining completely transparent to the attacker, as the mirrored traffic is a copy and does not affect the original flow. Unlike other options, Traffic Mirroring provides full packet capture (including headers and payloads) for forensic analysis, which is essential for investigating a compromise.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (which only provide metadata) with full packet capture, or assume that security groups or Network Firewall can log traffic passively, when in fact they are active security controls that could interfere with the attacker's activities.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture only metadata (source/destination IP, ports, protocol, packet/byte counts) and not the actual packet payloads, so they cannot provide the deep packet analysis needed for investigating a compromise. Option B is wrong because security groups are stateful firewalls that filter traffic at the instance level and do not have a logging capability to CloudWatch Logs; they only allow or deny traffic based on rules, and any logging would require additional agent-based solutions. Option D is wrong because AWS Network Firewall is a managed firewall service that inspects and potentially modifies traffic inline, which could alert the attacker by dropping or altering packets, and it does not provide passive packet capture for analysis.

1014
MCQmedium

Refer to the exhibit. An administrator applies this bucket policy to an S3 bucket. Which of the following statements describes the effect of this policy?

A.The policy denies all PutObject requests that do not specify SSE-KMS.
B.The policy allows uploads without encryption but denies uploads with SSE-KMS.
C.The policy allows unencrypted uploads but denies uploads with SSE-KMS.
D.The policy allows uploads with SSE-S3 but denies uploads with SSE-KMS.
AnswerA

The policy's Deny effect on s3:PutObject with a condition checking that the encryption header is absent or not SSE-KMS means any upload lacking SSE-KMS encryption is rejected. Requests specifying SSE-KMS satisfy the condition and are permitted.

Why this answer

The bucket policy contains two Deny statements: the first denies PutObject when the `x-amz-server-side-encryption` header is not `aws:kms`, and the second denies PutObject when the header is absent (null). Together, they ensure that any upload without SSE-KMS is denied, effectively requiring SSE-KMS for all PutObject requests. Options B, C, and D are incorrect because the policy does not allow any unencrypted uploads or uploads with SSE-S3; it only allows uploads with SSE-KMS.

Exam trap

The trap is that candidates might misread the policy and think the first statement alone denies all non-KMS encryption, but the second statement is needed to also deny requests with no encryption header at all.

1015
MCQhard

A company's security team needs to enforce encryption at rest for all RDS instances in the production account. They have enabled mandatory encryption using a service control policy. What else must be done to ensure existing unencrypted RDS instances are encrypted?

A.Attach a new KMS key policy to the RDS instance.
B.Create a snapshot of the unencrypted instance, copy the snapshot with encryption enabled, and restore the encrypted snapshot to a new DB instance.
C.Enable encryption on the DB subnet group and reboot the instance.
D.Modify the RDS instance to enable encryption using the AWS Console.
AnswerB

This is the standard, supported migration path. First, create a manual snapshot of the unencrypted RDS instance. Then copy that snapshot and select 'Enable encryption' (or specify a KMS key ID), because the copy operation re-encrypts the data at rest. Finally, restore the encrypted snapshot to a new DB instance, redirect application traffic to the new instance, and retire the old unencrypted instance once validation is complete.

Why this answer

RDS does not support directly enabling encryption on an existing unencrypted instance. The only way to encrypt an existing unencrypted RDS instance is to take a snapshot of it, copy the snapshot with encryption enabled, and restore the encrypted snapshot to a new DB instance. Options A, C, and D are incorrect: A: Attaching a new KMS key policy to the RDS instance does not encrypt the instance; encryption is applied at snapshot creation.

C: Enabling encryption on the DB subnet group does not affect existing instances; it only applies to new instances. D: Modifying the RDS instance via the console does not allow enabling encryption on an existing instance; encryption can only be enabled at creation or via snapshot copy.

1016
MCQhard

A healthcare company runs a HIPAA-compliant application on AWS. The application uses Amazon S3 to store Protected Health Information (PHI). The company has implemented the following controls: (1) All S3 buckets are configured with default encryption using SSE-S3. (2) Bucket policies restrict access to only authorized IAM roles. (3) S3 access logs are enabled and sent to a centralized logging account. (4) MFA Delete is enabled on all buckets. (5) Object lock is not enabled. Recently, an internal auditor discovered that when an authorized user deletes an object, the object is permanently deleted and cannot be recovered. The company's data retention policy requires that deleted PHI be recoverable for at least 30 days after deletion. A review of the IAM policies shows that users have s3:DeleteObject permission. The auditor also notes that the bucket versioning is not enabled. The security team needs to implement a solution that allows authorized users to delete objects but ensures that deleted objects can be recovered within 30 days. Which of the following is the MOST effective course of action?

A.Enable S3 Object Lock in Governance mode with a retention period of 30 days.
B.Enable S3 Versioning on the buckets and ensure that the IAM policies include s3:DeleteObjectVersion where appropriate.
C.Remove the s3:DeleteObject permission from all IAM policies and use S3 Lifecycle policies to expire objects after 30 days.
D.Change the default encryption from SSE-S3 to SSE-C and use a separate key for each object.
AnswerB

S3 Versioning is the correct data-protection mechanism because a regular DELETE on a versioned object only inserts a null-version delete marker while preserving all prior versions, allowing recovery by deleting that marker. Granting the s3:DeleteObjectVersion permission (only where appropriate) enables administrators to permanently purge specific object versions when retention or compliance demands actual deletion, while ordinary deletions remain reversible. This creates a two-tier deletion model where accidental deletes can be untangled and legitimate permanent deletes are still possible, exactly matching the requirement.

Why this answer

Enabling S3 Versioning is the most effective solution because it preserves all object versions, including deleted objects (which become delete markers). With versioning enabled, authorized users can still use s3:DeleteObject to delete the current version, but the previous versions remain recoverable. Since the requirement is to recover deleted PHI within 30 days, versioning combined with a lifecycle policy to permanently delete old versions after 30 days would meet the retention policy without blocking immediate deletion.

Exam trap

The trap here is that candidates may think S3 Object Lock (Option A) is the only way to prevent deletion, but they overlook that versioning allows deletion with recoverability, which directly satisfies the requirement for authorized users to delete objects while retaining the ability to recover them within 30 days.

How to eliminate wrong answers

Option A is wrong because S3 Object Lock in Governance mode prevents any deletion (including overwrites) until the retention period expires, which conflicts with the requirement that authorized users can delete objects immediately. Option C is wrong because removing s3:DeleteObject permission and relying solely on lifecycle policies would prevent users from deleting objects on demand, violating the requirement that authorized users can delete objects. Option D is wrong because changing encryption to SSE-C has no effect on object deletion or recovery; encryption protects data at rest but does not provide versioning or retention capabilities.

1017
Multi-Selectmedium

A security engineer is auditing IAM policies. The engineer wants to identify if any policy grants 'Effect: Allow' with 'Action: *' and 'Resource: *'. Which TWO AWS services can be used to detect such overly permissive policies?

Select 2 answers
A.AWS CloudTrail
B.AWS Trusted Advisor
C.AWS Config
D.IAM Access Analyzer
E.Amazon GuardDuty
AnswersC, D

AWS Config continuously records resource configurations and evaluates them against managed or custom rules, so a rule can flag IAM policies whose statements contain Action: * with Resource: *. This satisfies the requirement to detect overly permissive policies across accounts.

Why this answer

AWS Config [CORRECT] is right because it continuously evaluates IAM policies against managed or custom rules (e.g., iam-policy-no-statements-with-admin-access) and can flag policies containing Effect: Allow with Action: * and Resource: *, which is exactly the overly permissive pattern being audited. IAM Access Analyzer [CORRECT] is also correct because its policy validation and findings (including checks for overly permissive policies such as those granting full administrative access) can identify policies with Action: * and Resource: * on Allow statements. AWS CloudTrail is not correct because it records API activity and events, not policy permission analysis.

AWS Trusted Advisor is not correct because its security checks focus on broad best-practice items like open ports or MFA, not parsing IAM policy statements for wildcard Action/Resource. Amazon GuardDuty is not correct because it detects suspicious activity and threats from logs, not static IAM policy permissiveness.

Exam trap

The trap is selecting CloudTrail or GuardDuty because they are 'security' services — candidates must distinguish between activity logging/threat detection and policy content analysis, which is the domain of Config and IAM Access Analyzer.

1018
Multi-Selectmedium

A security team suspects that an attacker has compromised an EC2 instance and is using it to launch outbound DDoS attacks. The team needs to quickly isolate the instance while preserving forensic data. Which combination of actions should the team take? (Choose TWO.)

Select 2 answers
A.Apply a restrictive security group that blocks all outbound traffic.
B.Modify the network ACL for the subnet to deny all outbound traffic.
C.Create a snapshot of the EBS volumes attached to the EC2 instance.
D.Detach the instance from the Auto Scaling group.
E.Terminate the EC2 instance immediately.
AnswersA, C

Applying a restrictive security group that blocks all outbound traffic is the right containment step because security groups act as a stateful instance-level firewall. This prevents the compromised EC2 instance from establishing new outbound connections to a command-and-control server or performing data exfiltration, while leaving the instance running so forensic artifacts like memory and processes can be collected. Inbound rules can still permit limited SSH access from approved forensic workstations, allowing incident responders to investigate without fully disconnecting the instance.

Why this answer

Applying a restrictive security group that blocks all outbound traffic immediately stops the EC2 instance from sending any network packets, including DDoS traffic, without terminating the instance. This preserves the running state and allows forensic data collection from the instance's memory and disk. Security groups act as a stateful virtual firewall at the instance level, so blocking outbound traffic effectively isolates the instance from the network.

Exam trap

The trap here is that candidates often confuse network ACLs with security groups, thinking a subnet-level NACL change is equivalent to instance-level isolation, but NACLs affect all instances in the subnet and are stateless, making them unsuitable for targeted incident response.

1019
Multi-Selecteasy

A company wants to allow only specific IP addresses to access an S3 bucket. Which two methods can achieve this? (Choose TWO.)

Select 2 answers
A.Use an IAM policy with a condition that limits access to specific IP addresses.
B.Configure a network ACL on the subnet that blocks traffic from all but specific IPs.
C.Enable VPC Flow Logs to filter traffic from specific IPs.
D.Attach a security group to the S3 bucket that allows traffic only from specific IPs.
E.Use an S3 bucket policy with a condition that limits access to specific IP addresses.
AnswersA, E

An IAM policy with a condition key such as aws:SourceIp is valid for restricting S3 actions to specific source IP addresses when the request originates from an authenticated principal. This identity-based policy attaches to IAM users, groups, or roles, and the condition is evaluated against the public IP address of the caller's client. It works for requests made over the internet, but note that when traffic comes through a VPC endpoint, aws:SourceIp is not available and aws:VpcSourceIp would be needed instead.

Why this answer

Option A is correct because an IAM policy can include a Condition element using the aws:SourceIp (or aws:SourceIp with NotIpAddress) key to allow or deny requests based on the requester's IP address, effectively restricting access to specific IPs for the identities the policy is attached to. Option E is correct because an S3 bucket policy is a resource-based policy that can also use the aws:SourceIp condition key to allow only specified IP addresses to access the bucket, which is the most direct way to enforce IP restrictions on the bucket itself. Option B is not correct because a network ACL operates at the subnet level and filters traffic by IP/port for resources in a VPC, but it cannot govern access to an S3 bucket endpoint (especially public S3 endpoints) and does not apply to bucket-level authorization.

Option C is not correct because VPC Flow Logs only capture and record IP traffic metadata for monitoring; they do not filter or block traffic. Option D is not correct because security groups are attached to network interfaces (such as EC2 instances) and cannot be attached to an S3 bucket, and S3 does not use security groups for access control.

Exam trap

The trap here is that candidates often confuse network ACLs or security groups with S3 access control, not realizing that S3 is a global service that does not reside within a VPC subnet and cannot have security groups attached.

1020
MCQeasy

A security engineer is analyzing the VPC Flow Logs entry in the exhibit. The log shows traffic from an internal IP to an external IP. Which potential security concern should the engineer investigate?

A.The instance is participating in a DDoS attack against the external IP.
B.An EC2 instance is attempting to connect to an external host on port 3389 (RDP).
C.An external host is scanning the internal network on port 443.
D.The security group allows inbound RDP from 0.0.0.0/0.
AnswerB

Outbound RDP from an internal EC2 instance to an external host on port 3389 is inherently suspicious because RDP is a remote administration protocol and is not a normal outbound service. This direction of traffic can indicate a compromised instance serving as a pivot, data exfiltration, or an attacker maintaining persistent control. The flow log shows source 10.0.1.5 (private) to destination 203.0.113.50 on port 3389, so the correct interpretation is that the instance is attempting an outbound RDP connection.

Why this answer

The VPC Flow Logs entry shows outbound traffic from an internal IP to an external IP on destination port 3389, which is the default port for Remote Desktop Protocol (RDP). RDP outbound from an EC2 instance to an external host is a security concern because it could indicate an attacker using the instance as a pivot point to connect to an external command-and-control server or to exfiltrate data via an RDP tunnel. The log direction (src internal, dst external) and port 3389 specifically point to an outbound RDP attempt, not inbound scanning or DDoS.

Exam trap

The trap here is that candidates focus on the port number (3389) and assume it is about inbound RDP from the internet, but the flow direction (src internal, dst external) indicates outbound traffic, which is a different security concern related to egress filtering and potential command-and-control activity.

How to eliminate wrong answers

Option A is wrong because a single outbound RDP connection to an external IP does not indicate participation in a DDoS attack; DDoS attacks typically involve high-volume traffic (e.g., SYN floods, UDP floods) to many targets, not a single TCP connection on port 3389. Option C is wrong because the log shows traffic from an internal IP to an external IP (src internal, dst external), not an external host scanning the internal network; scanning would have the external IP as the source. Option D is wrong because the VPC Flow Logs entry does not contain any information about security group rules; it only shows the traffic flow, and the concern is the outbound RDP attempt, not inbound rules.

1021
MCQhard

A company uses AWS Config to evaluate resource compliance. The security team notices that the AWS::IAM::Group resource type is not supported by AWS Config managed rules. What is the best way to detect IAM groups that have an inline policy allowing 'iam:CreateUser'?

A.Create a custom AWS Config rule using a Lambda function that evaluates IAM groups
B.Use IAM Access Analyzer to identify policies that grant broad access
C.Use AWS CloudTrail Insights to detect CreateUser events
D.Enable AWS Config advanced query and run a query on IAM groups
AnswerA

AWS Config does not natively record IAM groups, so a Lambda-backed custom rule is required. The Lambda function can call the IAM API to retrieve a group's policies and evaluate them against your compliance logic, then report compliance via PutEvaluations. This approach gives you full flexibility to assess inline and attached managed policies for groups, which no managed Config rule can do.

Why this answer

AWS Config managed rules do not support the AWS::IAM::Group resource type, so you cannot use a managed rule to evaluate inline policies on IAM groups. The best approach is to create a custom AWS Config rule backed by a Lambda function that can evaluate the IAM group's inline policies and trigger a compliance check when the group configuration changes. This allows you to detect any inline policy that contains the 'iam:CreateUser' action.

Exam trap

The trap here is that candidates assume AWS Config advanced queries can evaluate any resource type, but AWS Config only supports querying resource types that it records, and IAM groups are not recorded, making Option D ineffective.

How to eliminate wrong answers

Option B is wrong because IAM Access Analyzer is designed to identify resources shared with external entities, not to evaluate inline policies on IAM groups for specific actions like 'iam:CreateUser'. Option C is wrong because AWS CloudTrail Insights detects unusual API activity patterns, not the static configuration of IAM group policies; it would only alert after a CreateUser event occurs, not proactively detect the policy. Option D is wrong because AWS Config advanced queries can query resource configuration data, but they cannot evaluate inline policies on IAM groups since AWS Config does not support the AWS::IAM::Group resource type for configuration recording or querying.

1022
MCQeasy

A company is designing a new AWS account structure using AWS Organizations. The security team wants to restrict the use of specific AWS services across all member accounts. Which feature should they use?

A.AWS Single Sign-On (SSO)
B.AWS CloudTrail
C.AWS Identity and Access Management (IAM) cross-account roles
D.Service control policies (SCPs)
AnswerD

Service control policies (SCPs) are an AWS Organizations feature that specify the maximum permission boundary for all IAM entities in the accounts, OUs, or root to which they are attached. By adding an SCP that denies or allows specific services, you can prevent member-account users and roots from using services outside the approved set, even if they have IAM policies that allow those actions. SCPs inherit down the organizational hierarchy and are evaluated as a top-level guardrail, making them the appropriate tool to restrict how teams use AWS services in a new account structure.

Why this answer

Service control policies (SCPs) are the correct feature because they allow you to centrally restrict which AWS services and actions are permitted across all member accounts in an AWS Organization. SCPs act as a permission guardrail that applies to all IAM users, roles, and root users within the affected accounts, enabling the security team to enforce service restrictions without modifying individual account configurations.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies, thinking IAM cross-account roles can enforce service restrictions, but SCPs are the only mechanism that applies globally across all users and roles in an AWS Organization.

How to eliminate wrong answers

Option A is wrong because AWS Single Sign-On (SSO) is a service for managing user access and authentication across multiple AWS accounts and applications, not for restricting service usage. Option B is wrong because AWS CloudTrail is a logging and monitoring service that records API activity, but it does not enforce or restrict which services can be used. Option C is wrong because IAM cross-account roles allow users in one account to assume roles in another account for access, but they do not provide a centralized mechanism to deny specific services across all accounts.

1023
MCQeasy

A company stores sensitive documents in an S3 bucket. The security team wants to ensure that any object uploaded to the bucket is automatically encrypted using server-side encryption with AWS KMS. Which S3 bucket feature should be configured?

A.Default encryption
B.Versioning
C.Bucket policy
D.Lifecycle policy
AnswerA

Setting default encryption on the bucket is the correct way to ensure that all objects are encrypted at rest automatically. When enabled, Amazon S3 applies server-side encryption (SSE-S3 by default, or SSE-KMS if configured) to every object uploaded to the bucket, even if the upload request does not include an encryption header. This provides a security baseline for sensitive documents and guarantees that no object is stored in an unencrypted state. Unlike policies or lifecycle rules, default encryption directly acts on the data itself at write time.

Why this answer

S3 default encryption (now called default encryption with SSE-KMS or SSE-S3) automatically encrypts every object at rest when it is uploaded, without requiring the uploader to specify encryption headers. Configuring default encryption with SSE-KMS using a customer-managed KMS key satisfies the requirement for automatic server-side encryption with AWS KMS. This is a bucket-level setting applied at PUT time.

Exam trap

SCS-C02 often tests the confusion between access control (bucket policy) and encryption enforcement (default encryption), and candidates may pick bucket policy thinking it encrypts objects.

How to eliminate wrong answers

Option B is wrong because versioning preserves multiple versions of objects but does not encrypt them. Option C is wrong because a bucket policy controls access permissions, not encryption at rest — it can enforce encryption via a condition like s3:PutObject requiring x-amz-server-side-encryption, but it does not itself perform encryption. Option D is wrong because a lifecycle policy manages object transitions and expiration, not encryption.

1024
MCQeasy

A company wants to host a static website in an Amazon S3 bucket. The bucket must be private and accessible only through an Amazon CloudFront distribution. Which configuration ensures that CloudFront can access the S3 bucket while blocking direct access via S3 URL?

A.Use CloudFront signed URLs and configure the bucket policy to allow access from CloudFront IP ranges
B.Enable S3 Block Public Access and configure CloudFront to use the bucket as an origin
C.Configure the bucket policy to allow s3:GetObject from the CloudFront service principal
D.Create an Origin Access Control (OAC) and update the bucket policy to allow access only to the CloudFront distribution
AnswerD

Origin Access Control (OAC) is the recommended way to keep an S3 bucket private while allowing only CloudFront to retrieve objects. You create an OAC, associate it with the distribution's origin, and update the bucket policy to permit s3:GetObject for the cloudfront.amazonaws.com principal under a condition like aws:SourceArn that matches your specific distribution. This prevents direct S3 access via the bucket URL, supports SSE-KMS encryption, and works seamlessly with S3 Block Public Access for a least-privilege, secure static website architecture.

Why this answer

Origin Access Control (OAC) is the recommended way to secure an S3 origin for CloudFront. OAC allows CloudFront to sign requests to S3, and the bucket policy can be configured to allow access only from the specific CloudFront distribution using the OAC. This blocks direct access via S3 URL because the bucket policy does not grant public access.

Exam trap

The trap is confusing OAC with OAI or thinking that a bucket policy allowing the CloudFront service principal is enough; the key is that the policy must be tied to the specific distribution via OAC and condition keys.

How to eliminate wrong answers

Option A is wrong because using CloudFront signed URLs is for restricting access to content at the user level, not for securing the origin; also, allowing access from CloudFront IP ranges is not secure because those IPs can change and are shared. Option B is wrong because simply enabling S3 Block Public Access and using the bucket as an origin does not grant CloudFront access; the bucket would remain private and CloudFront would be denied unless you also configure OAC or OAI. Option C is wrong because allowing 's3:GetObject' from the CloudFront service principal alone is not sufficient; you need to specify the specific distribution and use OAC or OAI to authenticate the request.

1025
MCQmedium

A company uses AWS Organizations and wants to enforce that all S3 buckets created in any account within the organization have default encryption enabled. Which policy should be used?

A.Use a bucket policy on each bucket to enforce encryption
B.Use a service control policy (SCP) to deny creation of buckets without default encryption
C.Use an IAM policy to require encryption on all bucket creation actions
D.Use AWS Config rules to automatically enable encryption on new buckets
AnswerB

Service control policies set permission guardrails across every account in AWS Organizations, so an SCP denying s3:CreateBucket without default encryption blocks non-compliant buckets organisation-wide. This satisfies the requirement to enforce encryption centrally in all accounts, which bucket policies cannot do.

Why this answer

(SCP) is correct because a service control policy can be applied to all accounts in an AWS Organization to deny the creation of S3 buckets without default encryption, providing a preventive control. Option A is incorrect because bucket policies are applied per bucket and are not preventive during creation. Option C is incorrect because IAM policies are account-specific and do not cover all accounts in the organization.

Option D is incorrect because AWS Config rules are detective, not preventive; they can trigger remediation but do not prevent creation.

1026
MCQmedium

A company is using AWS KMS to encrypt data at rest in Amazon S3. The security team requires that all encryption keys be automatically rotated every year. However, the current KMS key policy does not allow rotation. Which action should the security team take to meet the requirement?

A.Manually rotate the key by creating a new key and updating the S3 bucket policy.
B.Use an AWS managed key instead of a customer managed key.
C.Create a new customer managed key with imported key material and enable automatic rotation.
D.Enable automatic rotation on the existing customer managed key.
AnswerB

Using an AWS managed key such as the aws/s3 key automatically satisfies the rotation requirement because AWS KMS rotates AWS managed keys automatically every year (approximately 365 days) without any customer action. These keys are provisioned and managed by AWS, so the restrictive customer key policy on the existing customer managed key does not apply, and you cannot disable or alter their automatic rotation. For S3 server-side encryption with KMS, simply selecting the aws/s3 managed key encrypts objects with a key that is automatically rotated.

Why this answer

AWS managed keys are automatically rotated annually by AWS. This meets the requirement without needing to modify the existing key policy. Option A is wrong because manually rotating the key by creating a new key and updating the S3 bucket policy does not provide automatic rotation and is not the simplest solution.

Option C is wrong because customer managed keys with imported key material do not support automatic rotation. Option D is wrong because the existing key policy does not allow rotation, so enabling automatic rotation on that key would fail; the correct approach is to use an AWS managed key.

1027
Multi-Selectmedium

A security engineer is configuring a VPC for a three-tier application. The web tier must be accessible from the internet, the application tier must be accessible only from the web tier, and the database tier must be accessible only from the application tier. Which TWO security group configurations should be used? (Choose TWO.)

Select 2 answers
A.Allow inbound SSH from 0.0.0.0/0 on the web tier security group.
B.Allow inbound HTTP/HTTPS from 0.0.0.0/0 on the web tier security group.
C.Allow inbound HTTP/HTTPS from the web tier security group on the database tier security group.
D.Allow inbound HTTP/HTTPS from the web tier security group on the application tier security group.
E.Allow inbound HTTP/HTTPS from the internet on the database tier security group.
AnswersB, D

The web tier is the only component that needs to accept unsolicited traffic from the internet. By allowing HTTP/HTTPS from 0.0.0.0/0, you enable clients to reach the application via the public IP of the load balancer or the web servers. This is a standard and secure configuration because the web tier acts as the entry point that forwards requests to the application tier, and the other tiers remain hidden from direct internet access.

Why this answer

Option B is correct because the web tier is the only tier that must be reachable from the internet, so its security group should permit inbound HTTP (TCP 80) and HTTPS (TCP 443) from 0.0.0.0/0. Option D is correct because the application tier must be accessible only from the web tier, and referencing the web tier's security group as the source in the application tier's inbound rule enforces that tier-to-tier restriction. Option A is wrong because allowing SSH from 0.0.0.0/0 exposes the web tier to unrestricted remote administration and is not required by the scenario.

Option C is wrong because the database tier should accept traffic only from the application tier, not directly from the web tier. Option E is wrong because exposing the database tier to inbound HTTP/HTTPS from the internet violates the requirement that it be accessible only from the application tier.

Exam trap

The trap here is that candidates often confuse the direction of traffic flow and incorrectly apply security group rules to the wrong tier, such as allowing HTTP/HTTPS from the web tier directly to the database tier (Option C) instead of to the application tier, or they mistakenly open unnecessary ports like SSH (Option A) thinking it is needed for management, which violates the principle of least privilege.

1028
MCQhard

A company's Security team is using AWS Organizations with a consolidated billing account. The security team wants to ensure that all member accounts have AWS CloudTrail enabled and that logs are delivered to a central S3 bucket in the management account. Which combination of actions should the security team take? (Choose the best answer.)

A.Use AWS Config rules to detect when CloudTrail is disabled.
B.Create a new IAM policy that requires each account owner to enable CloudTrail.
C.Enable CloudTrail in the management account only and use cross-account logging.
D.Use an SCP to deny disabling CloudTrail and use CloudFormation StackSets to deploy CloudTrail in all accounts.
AnswerD

An SCP such as 'DenyCloudTrailDisable' can be attached to the root or OU to explicitly deny cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail (along with PutEventSelectors actions that could stop recording), preventing any principal—including the root user—from disabling the trail. CloudFormation StackSets then deploys a consistent multi-region trail template to every account in the organization, automatically creating the required trail, S3 bucket, and bucket policy. Because SCPs are evaluated in addition to IAM policies and cannot be overridden by account admins, this combination provides both automated enablement and a hard preventive boundary.

Why this answer

Using an SCP to deny disabling CloudTrail and a CloudFormation StackSet to deploy CloudTrail in each account ensures enforcement and deployment across all member accounts. Option A is wrong because AWS Config rules can detect but not prevent disabling of CloudTrail. Option B is wrong because an IAM policy requiring account owners to enable CloudTrail is not enforceable and relies on individual action.

Option C is wrong because enabling CloudTrail only in the management account does not enable it in member accounts; cross-account logging requires member accounts to have CloudTrail configured.

1029
Multi-Selectmedium

A security engineer is designing a VPC with public and private subnets. The application servers in the private subnets need to access the internet for software updates, but must not be directly reachable from the internet. Which TWO actions satisfy these requirements?

Select 2 answers
A.Configure the private subnet's security group to allow inbound traffic from 0.0.0.0/0.
B.Add a route in the private subnet's route table pointing to the NAT gateway.
C.Attach an internet gateway to the private subnet's route table.
D.Create a VPC gateway endpoint for Amazon S3.
E.Deploy a NAT gateway in a public subnet.
AnswersB, E

A NAT gateway performs source network address translation for outbound traffic, letting private subnet instances initiate internet connections for updates while remaining unreachable inbound. The private route table's 0.0.0.0/0 route to the NAT gateway satisfies both requirements.

Why this answer

Option B is correct because the private subnet's route table must contain a route (typically 0.0.0.0/0) targeting the NAT gateway so that outbound internet-bound traffic from private instances is forwarded through the NAT. Option E is correct because the NAT gateway itself must reside in a public subnet with a route to an internet gateway, allowing it to translate private instances' traffic to the internet while preventing inbound connections to those instances. Together, B and E provide outbound-only internet access for the private application servers.

Option A is wrong because allowing inbound 0.0.0.0/0 on the private subnet's security group would make the servers reachable from the internet, violating the requirement. Option C is wrong because attaching an internet gateway to a private subnet's route table would make the subnet public and expose the instances directly. Option D is wrong because a VPC gateway endpoint for Amazon S3 only provides private access to S3, not general internet access for software updates.

Exam trap

The trap here is that candidates often confuse a NAT gateway with an internet gateway, mistakenly thinking that adding an internet gateway to a private subnet's route table provides outbound-only access, when in fact it enables bidirectional internet connectivity and requires public IPs on the instances.

1030
MCQhard

During a security incident, a security engineer needs to capture network traffic from an EC2 instance for forensic analysis. The instance is part of an Auto Scaling group and may be terminated. What is the MOST efficient way to capture the traffic without affecting the instance's performance?

A.Use VPC Traffic Mirroring to mirror the instance's network traffic.
B.Enable VPC Flow Logs for the subnet.
C.SSH into the instance and run tcpdump to capture packets.
D.Attach a Network Load Balancer in front of the instance.
AnswerA

VPC Traffic Mirroring copies the full packet payload from the instance's elastic network interface to a target such as a Network Load Balancer or another ENI, operating at the hypervisor level without installing agents or consuming the instance's CPU and memory. Because the capture is passive and out-of-band, it preserves the forensic integrity of the evidence and enables thorough inspection of both inbound and outbound traffic.

Why this answer

VPC Traffic Mirroring captures all network traffic at the hypervisor level without installing agents or consuming instance CPU/memory, making it ideal for forensic analysis of an EC2 instance that may be terminated. It works by copying packets from the source ENI to a target (e.g., a Network Load Balancer or another ENI) for inspection, ensuring zero performance impact on the production instance. This approach preserves traffic even if the instance is later terminated, as the mirror session is tied to the ENI, not the instance lifecycle.

Exam trap

The trap here is that candidates confuse VPC Flow Logs (metadata only) with full packet capture, or assume that running tcpdump on the instance is acceptable despite the performance impact and risk of data loss upon termination.

How to eliminate wrong answers

Option B is wrong because VPC Flow Logs capture only metadata (IP addresses, ports, protocols, packet counts) and not the actual packet payloads, making them insufficient for deep forensic analysis. Option C is wrong because running tcpdump on the instance consumes CPU and memory resources, degrading performance during a security incident, and the captured data would be lost if the instance is terminated. Option D is wrong because attaching a Network Load Balancer in front of the instance does not capture traffic; it only distributes incoming traffic and does not provide a copy of the packets for analysis.

1031
MCQeasy

A company wants to audit all changes to security group rules in their AWS account. Which AWS service should be used to record these changes?

A.Amazon CloudWatch Logs.
B.AWS CloudTrail.
C.VPC Flow Logs.
D.AWS Config.
AnswerB

AWS CloudTrail is the service designed to record AWS API activity, and it captures every security group change as an API event such as AuthorizeSecurityGroupIngress, RevokeSecurityGroupIngress, AuthorizeSecurityGroupEgress, RevokeSecurityGroupEgress, CreateSecurityGroup, or DeleteSecurityGroup. Each event includes the identity of the caller, the source IP address, the request parameters, and the response elements, giving a complete audit trail of who changed what and when. This makes CloudTrail the appropriate service for auditing all changes to security group rules.

Why this answer

AWS CloudTrail is the correct service because it records API calls made to the AWS environment, including changes to security group rules via the EC2 AuthorizeSecurityGroupIngress, RevokeSecurityGroupIngress, AuthorizeSecurityGroupEgress, and RevokeSecurityGroupEgress API actions. These events are captured as management events in CloudTrail, providing a complete audit trail of who made the change, when, from which IP address, and the exact parameters of the rule modification.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks resource configuration state) with CloudTrail (which tracks API activity), leading them to select AWS Config because they think 'audit changes' means monitoring the current state of rules, but the question specifically asks for recording the changes themselves, which requires API-level logging.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs is a service for storing, monitoring, and accessing log files from AWS resources, but it does not natively capture API-level changes to security group rules; it would require custom integration or agent-based logging. Option C is wrong because VPC Flow Logs capture metadata about network traffic (IP addresses, ports, protocols) flowing through ENIs, not the configuration changes to security group rules themselves. Option D is wrong because AWS Config evaluates and records resource configuration changes over time, but it is not the primary service for auditing API calls; CloudTrail is the service that records the API actions that trigger those configuration changes, while AWS Config focuses on the resulting state.

1032
MCQmedium

A company has a requirement to log all network traffic flowing through a VPC, including traffic between EC2 instances within the same subnet. Which AWS service should be used?

A.VPC Flow Logs
B.Amazon GuardDuty
C.AWS Config
D.AWS CloudTrail
AnswerA

VPC Flow Logs is the only option that captures network traffic itself. It records flow metadata for every accepted and rejected connection at the VPC, subnet, or elastic network interface (ENI) level, including intra-subnet traffic between instances. The logs contain source/destination addresses, source/destination ports, protocol, packets, bytes, and the connection action, and can be published to CloudWatch Logs or Amazon S3 for analysis. While it captures flow metadata rather than packet payloads, it fully meets a requirement to log all network traffic for audit and troubleshooting.

Why this answer

VPC Flow Logs capture IP traffic information for network interfaces in a VPC, including traffic between EC2 instances within the same subnet, and can be published to CloudWatch Logs or S3. It is the only AWS service listed that provides packet-level metadata for all traffic flowing through VPC network interfaces.

Exam trap

SCS-C02 often tests the confusion between VPC Flow Logs (network traffic metadata), CloudTrail (API activity), and GuardDuty (threat detection), tricking candidates into selecting CloudTrail for network-level logging.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes logs (including VPC Flow Logs) for malicious activity — it does not itself log network traffic. Option C is wrong because AWS Config records resource configuration changes and evaluates compliance against rules; it does not capture network traffic. Option D is wrong because AWS CloudTrail logs API activity (who called which AWS API), not network traffic flowing through a VPC.

1033
MCQeasy

A security engineer needs to ensure that all data in transit between an Application Load Balancer and EC2 instances is encrypted using TLS. Which configuration is required?

A.Configure the ALB with an HTTPS listener and the target group with HTTPS protocol.
B.Configure the ALB with an HTTPS listener and the target group with HTTP protocol.
C.Configure the ALB with a TLS listener and the target group with TCP protocol.
D.Configure the ALB with a TCP listener and the target group with HTTP protocol.
AnswerA

To encrypt traffic for the entire path, the ALB must terminate the client-facing TLS connection on an HTTPS listener and then originate a new TLS session to each registered target using an HTTPS target group. This ensures the request is decrypted only inside the ALB and re-encrypted before traversing any network segments to the EC2 instances. Both the listener and the target group certificate must be trusted, and health checks also run over HTTPS, maintaining encryption from edge to backend.

Why this answer

To encrypt data in transit between the Application Load Balancer and EC2 instances, the ALB must have an HTTPS listener and the target group must use HTTPS protocol. This ensures end-to-end TLS encryption from client to ALB and from ALB to EC2 instances. Option A correctly specifies this configuration.

1034
MCQeasy

A company has an Amazon RDS for MySQL database in a private subnet. The security team wants to ensure that only an application server in the same VPC can connect to the database. Which security group configuration should be used?

A.Inbound rule on the RDS security group: allow MySQL on port 3306 from the VPC's CIDR.
B.Inbound rule on the RDS security group: allow MySQL on port 3306 from the subnet CIDR of the application server.
C.Inbound rule on the RDS security group: allow MySQL on port 3306 from the security group ID of the application server.
D.Inbound rule on the application server's security group: allow outbound MySQL to the RDS security group.
AnswerC

Setting the source of the RDS security group's inbound rule to the application server's security group ID restricts MySQL access to only those instances whose network interfaces are associated with that security group, regardless of their IP addresses. This is the recommended least-privilege pattern because it ties the rule to a logical group of resources rather than a static IP range, so the rule remains valid if the application server's private IP changes. It also prevents any unrelated VPC or subnet resource from reaching the database, as only resources carrying that specific security group are allowed.

Why this answer

Referencing the application server's security group ID as the source in the inbound rule for MySQL (port 3306) on the RDS security group allows traffic only from instances that are members of that security group, regardless of their IP addresses. This is the most secure and precise method, as it automatically adapts to changes in the application server's IP (e.g., after scaling or replacement) and avoids opening the database to the entire subnet or VPC CIDR.

Exam trap

The trap here is that candidates often confuse inbound vs. outbound rules or mistakenly think that allowing a subnet CIDR is equivalent to allowing a specific instance, when in fact security group ID-based rules provide instance-level granularity and are the recommended approach for this use case.

How to eliminate wrong answers

Option A is wrong because allowing the VPC's CIDR on port 3306 would permit any resource in the VPC (including unauthorized instances, Lambda functions in the same VPC, or even compromised hosts) to connect to the database, violating the principle of least privilege. Option B is wrong because allowing the subnet CIDR of the application server still opens the database to all instances in that subnet, not just the specific application server, and does not protect against lateral movement within the subnet. Option D is wrong because it configures an outbound rule on the application server's security group, which controls traffic leaving the application server, not inbound access to the RDS instance; the RDS security group's inbound rules are what enforce which sources can connect to the database.

1035
MCQeasy

A company has an AWS account with multiple S3 buckets that contain sensitive data. The security team wants to ensure that no public access is granted to any bucket. The team has enabled AWS Config and set up a rule to detect public buckets. The rule reports that all buckets are compliant. However, during a security review, a team member finds that one bucket has a bucket policy that grants 's3:GetObject' to 'Principal': '*'. Why did the AWS Config rule not detect this?

A.AWS CloudTrail must be enabled for Config to evaluate policies.
B.The AWS Config rule only checks ACLs, not bucket policies.
C.The bucket is in a different AWS account.
D.IAM Access Analyzer must be enabled first.
AnswerB

The managed rule s3-bucket-public-read-prohibited inspects the bucket's access control list (ACL) for grants to AllUsers or AuthenticatedUsers and reports NON_COMPLIANT only if those ACL grants are present. It does not parse or evaluate bucket policies, even though bucket policy statements with Principal '*' can also enable public read access. Therefore a bucket with a private ACL and a public bucket policy will show COMPLIANT even though it is actually publicly readable.

Why this answer

The AWS Config managed rule 's3-bucket-public-read-prohibited' only checks for public read access via ACLs, not bucket policies. Therefore, a bucket policy granting 's3:GetObject' to 'Principal': '*' would not be flagged as non-compliant by this rule. To detect public access via bucket policies, a custom AWS Config rule or other mechanisms like IAM Access Analyzer are needed.

Option A is incorrect because CloudTrail logs API calls but does not evaluate compliance. Option C is incorrect because the bucket is in the same account as per the scenario. Option D is incorrect because IAM Access Analyzer can analyze policies but does not enforce compliance rules.

1036
MCQeasy

A company wants to ensure that all data in transit between its EC2 instances and an RDS database is encrypted. The instances and the database are in the same VPC. Which configuration step is necessary to achieve this?

A.Enable encryption at rest for the RDS instance using AWS KMS.
B.Set up a VPN connection between the EC2 instances and the RDS database.
C.Configure the security group for the RDS instance to enforce encryption.
D.Enable SSL/TLS on the RDS instance and configure the EC2 instances to connect using SSL.
AnswerD

Enabling SSL/TLS on the RDS instance makes the database server accept and require encrypted connections, and configuring the EC2 clients to connect with SSL (for example, using sslmode=require or verify-full in PostgreSQL, or useSSL=true in MySQL) encrypts all data in flight between the application and the database. RDS provides server certificates for each region that clients can validate to prevent man-in-the-middle attacks. This directly satisfies the requirement that all data in transit be encrypted.

Why this answer

To encrypt data in transit between EC2 instances and an RDS database within the same VPC, you must enable SSL/TLS on the RDS instance and configure the EC2 instances to connect using SSL. This ensures that the network traffic is encrypted at the transport layer, protecting against eavesdropping or man-in-the-middle attacks. AWS RDS supports SSL/TLS for most database engines, and the client must explicitly request an encrypted connection.

Exam trap

The trap here is that candidates often confuse encryption at rest (Option A) with encryption in transit, or assume that security groups (Option C) can enforce encryption, when in fact they only filter traffic at the network layer.

How to eliminate wrong answers

Option A is wrong because encryption at rest protects data stored on disk, not data in transit over the network. Option B is wrong because a VPN connection is unnecessary and irrelevant when both resources are in the same VPC; VPNs are used for hybrid connectivity, not for intra-VPC traffic encryption. Option C is wrong because security groups are stateful firewalls that control traffic based on IP addresses and ports, not encryption protocols; they cannot enforce or negotiate SSL/TLS encryption.

1037
Multi-Selecthard

Which THREE AWS services can be used to centrally manage security across multiple accounts? (Select THREE.)

Select 3 answers
A.AWS Config
B.AWS Shield
C.AWS CloudTrail
D.Amazon GuardDuty
E.AWS Organizations
AnswersA, C, E

Config can aggregate rules and compliance across accounts.

Why this answer

AWS Config is correct because it provides a centralized view of resource configurations and compliance across multiple accounts when integrated with AWS Organizations. By enabling Config in the management account and using aggregation authorizations, you can aggregate configuration and compliance data from all member accounts into a single administrator account, enabling centralized security governance.

Exam trap

The trap here is that candidates confuse services that aggregate findings (like GuardDuty with Organizations) with services that centrally manage security policies and configurations, leading them to select GuardDuty instead of recognizing that only AWS Config, AWS CloudTrail (for centralized logging), and AWS Organizations (for policy-based governance) provide true centralized management.

1038
Multi-Selectmedium

Which TWO actions should a security engineer take to protect root user credentials? (Select TWO.)

Select 2 answers
A.Use the root user only for billing
B.Share the root user credentials with the security team
C.Do not create access keys for the root user
D.Enable MFA on the root user account
E.Delete the root user account
AnswersC, D

Access keys for the root user are long-term static credentials that bypass the password and MFA protections on the AWS console, enabling direct API calls with full account authority. AWS explicitly warns that root access keys cannot be rotated like IAM user keys and can only be deleted, making any leak a catastrophic risk. Avoiding root access keys entirely -- and using temporary credentials from IAM roles or federation -- is the recommended safeguard.

Why this answer

AWS strongly recommends that you do not create access keys for the root user. Access keys provide programmatic access to the AWS API, and if compromised, an attacker would have unrestricted access to all AWS resources and billing information. By not creating access keys, you eliminate this high-risk attack vector.

Exam trap

The trap here is that candidates often think the root user can be deleted or that using it only for billing is acceptable, but AWS explicitly prohibits deleting the root user and recommends using IAM users with billing permissions instead.

1039
MCQhard

During an incident investigation, a security analyst finds that an IAM user 'JohnDoe' has been using an access key that was last rotated over 2 years ago. The analyst needs to determine if this key has been compromised. Which approach provides the MOST definitive evidence?

A.Check the S3 access logs to see if the key was used to download sensitive data
B.Use AWS CloudTrail LookupEvents to find API calls made by the key, focusing on unusual IP addresses or times
C.Review the IAM password policy to see if the key was created before the current policy
D.Use AWS Config to see if the key's permissions have changed
AnswerB

CloudTrail LookupEvents is the correct tool because it queries the CloudTrail event history for actual API calls made by an access key, including action name, source IP address, user agent, and timestamp. You can specify the AccessKeyId in the lookup filter to see every call attributed to that key, then correlate those calls with unusual IP addresses or times to spot anomalous behavior. This gives the security analyst direct evidence of what the compromised key did across AWS services, which is exactly the goal of the investigation.

Why this answer

AWS CloudTrail LookupEvents allows you to filter API calls by user identity (such as the access key ID) and examine attributes like source IP address, user agent, and timestamp. Unusual IP addresses or times of day are strong indicators of compromise, as they suggest the key is being used from locations or at hours inconsistent with the legitimate user's behavior. This provides the most definitive evidence because it directly correlates the key's usage with anomalous patterns, rather than relying on indirect indicators like data downloads or permission changes.

Exam trap

The trap here is that candidates assume S3 access logs (Option A) are the definitive source for detecting compromise, but they miss that CloudTrail provides a complete audit trail of all API calls, including those that don't involve S3 data access, making it the superior choice for identifying anomalous behavior.

How to eliminate wrong answers

Option A is wrong because S3 access logs only show object-level operations (e.g., GetObject, PutObject) and do not capture all API calls made by the key; a compromised key might be used for reconnaissance or other actions that don't involve downloading sensitive data, so absence of such logs does not rule out compromise. Option C is wrong because the IAM password policy governs user passwords, not access keys; access key rotation is managed independently via the IAM console or API, and the password policy has no bearing on whether a key is compromised. Option D is wrong because AWS Config tracks resource configuration changes over time, but a compromised key can be used without any permission changes—attackers often use existing permissions to exfiltrate data or perform actions, so unchanged permissions do not indicate the key is safe.

1040
MCQeasy

A security engineer needs to ensure that data at rest in an Amazon RDS for PostgreSQL DB instance is encrypted. Which action should the engineer take?

A.Grant the rds:ModifyDBInstance permission to allow encryption toggling.
B.Modify the existing unencrypted DB instance to enable encryption.
C.Enable encryption automatically by enabling automated backups.
D.Create a new DB instance with encryption enabled using the AWS CLI or Console.
AnswerD

To encrypt an existing unencrypted database, you must provision a new DB instance with the StorageEncrypted flag set to true, using either the AWS Management Console, the AWS CLI (--storage-encrypted), or an SDK. You can choose the default aws/rds KMS key or a custom customer-managed key. After the encrypted instance is available, migrate the data from the original instance, for example by restoring an encrypted snapshot or using a logical export/import.

Why this answer

Amazon RDS does not support enabling encryption on an existing unencrypted DB instance; encryption must be specified at creation time. To encrypt data at rest, the engineer must create a new DB instance with encryption enabled (via Console, CLI, or API), then migrate data from the old instance. This is the only supported path for RDS encryption at rest.

Exam trap

SCS-C02 often tests the misconception that RDS encryption can be toggled on an existing instance like an EBS volume — candidates pick 'modify the instance' and miss that StorageEncrypted is immutable at creation.

How to eliminate wrong answers

Option A is wrong because granting rds:ModifyDBInstance does not enable encryption — the ModifyDBInstance API cannot toggle the StorageEncrypted attribute on an existing instance. Option B is wrong because RDS explicitly does not allow modifying an existing unencrypted DB instance to enable encryption; the StorageEncrypted setting is immutable after creation. Option C is wrong because enabling automated backups has no relationship to encryption at rest; backups inherit encryption from the source instance and do not turn on encryption for the primary storage.

1041
MCQeasy

A company wants to protect its Amazon EC2 instances from distributed denial-of-service (DDoS) attacks at the network layer. Which AWS service should be used?

A.Amazon CloudFront
B.Amazon GuardDuty
C.AWS Shield Advanced
D.AWS WAF
AnswerC

AWS Shield Advanced is purpose-built for DDoS protection, providing enhanced always-on detection and automatic inline mitigation for network-layer (L3/L4) attacks such as SYN floods and UDP reflection. It works by absorbing attack traffic and rerouting it to AWS's global scrubbing infrastructure while maintaining availability of protected resources like EC2 instances. Advanced also adds cost protection (DDoS-induced spikes are charged back as credits), access to the AWS DDoS Response Team (DRT), and integration with AWS WAF for additional Layer 7 defense. This is the service designed to directly protect EC2 from DDoS attacks.

Why this answer

AWS Shield Advanced provides enhanced protections for Amazon EC2 instances against network-layer (Layer 3/4) DDoS attacks, such as SYN floods, UDP reflection attacks, and other volumetric attacks. It includes always-on traffic monitoring, automated mitigation, and access to the DDoS Response Team (DRT) for custom mitigations, making it the correct choice for network-layer DDoS protection.

Exam trap

The trap here is that candidates often confuse AWS WAF (Layer 7) with network-layer DDoS protection, or assume Amazon CloudFront's edge caching alone is sufficient for all DDoS types, but Shield Advanced is the specific service designed for comprehensive network-layer (Layer 3/4) DDoS mitigation.

How to eliminate wrong answers

Option A is wrong because Amazon CloudFront is a content delivery network (CDN) that primarily protects against application-layer (Layer 7) attacks and provides edge-based DDoS mitigation, but it does not offer dedicated network-layer DDoS protection for EC2 instances directly. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events to identify malicious activity, but it does not actively mitigate or block DDoS attacks at the network layer. Option D is wrong because AWS WAF is a web application firewall that operates at Layer 7 (HTTP/HTTPS) to filter malicious requests like SQL injection or cross-site scripting, and it cannot mitigate network-layer (Layer 3/4) attacks such as SYN floods or UDP amplification.

1042
MCQmedium

A company wants to automatically detect and notify about any S3 buckets that have public read access. Which combination of services should be used?

A.AWS CloudTrail and AWS Lambda
B.AWS Config and Amazon EventBridge
C.AWS IAM Access Analyzer and Amazon CloudWatch
D.AWS Trusted Advisor and Amazon SES
AnswerB

AWS Config rules continuously evaluate bucket policies and ACLs, flagging any bucket granting public read access as noncompliant. EventBridge then routes those compliance-change events to a notification target, delivering the automatic detection and alerting the stem requires without polling.

Why this answer

AWS Config continuously records S3 bucket configurations and can evaluate them against managed rules such as 's3-bucket-public-read-prohibited', flagging any bucket with public read access as non-compliant. Amazon EventBridge can then route Config's compliance change events to targets like SNS or Lambda for notification. This combination provides both detection and automated notification without custom code.

Exam trap

SCS-C02 often tests the distinction between services that log activity (CloudTrail) versus services that evaluate configuration state (Config) — candidates frequently pick CloudTrail for detection questions when Config is the correct answer.

How to eliminate wrong answers

Option A is wrong because CloudTrail only logs API activity (who did what and when) — it does not evaluate resource configuration state, so it cannot detect that a bucket currently has public read access. Option C is wrong because IAM Access Analyzer identifies resources shared with external entities (including public S3 buckets) but does not natively emit EventBridge events for notification workflows in the same compliance-driven way, and CloudWatch alone does not evaluate S3 bucket policies. Option D is wrong because Trusted Advisor offers a limited set of checks (including S3 bucket permissions) but is not designed for continuous, event-driven detection and notification, and SES is an email service, not a notification router for compliance events.

1043
Multi-Selecteasy

A company wants to monitor unauthorized API calls in their AWS account. Which TWO AWS services can provide real-time alerting on such events?

Select 2 answers
A.AWS Config
B.AWS CloudTrail
C.Amazon GuardDuty
D.AWS Trusted Advisor
E.Amazon Inspector
AnswersB, C

CloudTrail records every API call as a management event, capturing the identity, source IP and error code. Filtering for AccessDenied errors lets you detect unauthorised calls, and delivering trails to CloudWatch Logs enables real-time metric filters and alarms.

Why this answer

AWS CloudTrail (B) is correct because it records every API call made in the account as management and data events, and when combined with CloudWatch Logs metric filters and alarms it delivers real-time alerting on unauthorized or suspicious API activity. Amazon GuardDuty (C) is correct because it continuously analyzes CloudTrail management events, VPC Flow Logs, and DNS logs with threat intelligence and machine learning to detect anomalous or unauthorized API calls and generate findings in near real time. AWS Config (A) is not designed for real-time alerting on API calls; it evaluates resource configuration compliance and records configuration changes, not API invocation events.

AWS Trusted Advisor (D) provides periodic best-practice checks and recommendations, not real-time monitoring of API activity. Amazon Inspector (E) is a vulnerability management service that scans EC2 instances, container images, and Lambda functions for software vulnerabilities and network exposure, not API call monitoring.

Exam trap

Candidates often assume that only CloudTrail can monitor unauthorized API calls because it logs all API events, overlooking GuardDuty's ability to detect suspicious API activity through anomaly detection and threat intelligence. Both services can provide real-time alerting on unauthorized API calls, but via different mechanisms: CloudTrail via CloudWatch alarms on specific API error codes, and GuardDuty via findings based on unusual API patterns.

1044
MCQhard

A company's security team wants to detect and block malicious SQL injection attempts against an Application Load Balancer. Which AWS service should be used?

A.AWS WAF
B.Amazon GuardDuty
C.Amazon Inspector
D.AWS Shield Advanced
AnswerA

AWS WAF is a Layer 7 web application firewall that you can associate with an Application Load Balancer to inspect incoming HTTP(S) requests. It uses managed rule groups, such as the AWS Managed Rules for SQL injection (SQLi_RULE), to match request patterns like malicious query strings, bodies, or headers. When a rule matches, WAF can immediately block the request, return a custom response, or count it, providing inline detection and blocking at the ALB. This is exactly what the security team needs for identifying and stopping SQL injection attempts before they reach the application.

Why this answer

AWS WAF is a web application firewall that can be associated with an Application Load Balancer to inspect HTTP/HTTPS requests for malicious patterns, such as SQL injection attempts. It uses managed rule sets (e.g., AWS Managed Rules for SQL injection) to detect and block these attacks in real time, making it the correct choice for this use case.

Exam trap

The trap here is that candidates often confuse GuardDuty's threat detection (which covers network and account-level anomalies) with application-layer attack detection, or assume Shield Advanced's DDoS protection includes web application firewall capabilities.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events for anomalous behavior, but it does not inspect or block application-layer requests like SQL injection at the ALB level. Option C is wrong because Amazon Inspector is a vulnerability assessment service that scans EC2 instances and container images for software vulnerabilities and network exposure, not for detecting or blocking live web application attacks. Option D is wrong because AWS Shield Advanced provides DDoS protection against volumetric and state-exhaustion attacks, but it does not include application-layer inspection for SQL injection payloads.

1045
Multi-Selectmedium

Which TWO of the following are valid methods to protect sensitive data in transit between an on-premises data center and AWS? (Select TWO.)

Select 2 answers
A.AWS Transit Gateway
B.AWS Site-to-Site VPN
C.Internet Gateway
D.VPC Peering
E.AWS Direct Connect with IPSec VPN
AnswersB, E

AWS Site-to-Site VPN creates an encrypted IPsec tunnel between your on-premises VPN device and the AWS VPN endpoint, using protocols like IKE and ESP to authenticate and encrypt all traffic traversing the public internet. The VPN tunnels support AES-128 or AES-256 encryption, along with perfect forward secrecy, ensuring confidentiality and data integrity. This native AWS service directly provides secure encryption of data in transit between your network and the VPC, making it a valid method to protect sensitive data.

Why this answer

AWS Site-to-Site VPN (Option B) creates an encrypted tunnel between an on-premises VPN device and a Virtual Private Gateway in AWS, using IPSec to protect data in transit. This ensures confidentiality and integrity of data crossing the public internet, making it a valid method for securing sensitive data between an on-premises data center and AWS.

Exam trap

The trap here is that candidates often assume AWS Transit Gateway or VPC Peering inherently encrypt traffic, but they do not; encryption must be explicitly added via VPN or Direct Connect with IPSec, and the exam tests this distinction between connectivity and encryption.

1046
Multi-Selectmedium

A security team needs to monitor for unauthorized API calls in their AWS account. Which TWO services can provide real-time alerts for such events?

Select 2 answers
A.Amazon CloudWatch Logs Insights
B.AWS CloudTrail with Amazon CloudWatch Events
C.Amazon VPC Flow Logs
D.AWS Config
E.Amazon GuardDuty
AnswersB, E

AWS CloudTrail captures the complete audit trail of API calls made to your account, including the identity, time, source IP, and request parameters. By integrating CloudTrail with Amazon CloudWatch Events, you can create rules that match specific API events—such as unauthorized or denied actions—and trigger immediate alerts via SNS, Lambda, or other targets in real time. CloudTrail delivers each API event as a JSON object, and CloudWatch Events helps filter those objects by fields like `errorCode` or `userIdentity` to detect suspicious activity. This combination is the recommended native mechanism for monitoring and reacting to unauthorized API calls.

Why this answer

B is correct because AWS CloudTrail logs all API calls, and by integrating CloudTrail with Amazon CloudWatch Events (now Amazon EventBridge), you can create event rules that trigger real-time alerts (e.g., via SNS or Lambda) for unauthorized API calls. This combination provides the necessary logging and immediate notification capability for security monitoring.

Exam trap

The trap here is that candidates often confuse CloudWatch Logs Insights (a query tool) with real-time alerting, or they mistakenly think VPC Flow Logs can monitor API calls because they capture all traffic, but they only capture network flows, not application-level API events.

1047
Multi-Selecteasy

Which TWO are valid IAM identity-based policies? (Choose 2.)

Select 2 answers
A.Trust policy
B.Inline policy
C.S3 bucket policy
D.Service control policy (SCP)
E.AWS managed policy
AnswersB, E

Inline policies are identity-based policies that are embedded directly into a single IAM user, group, or role. They are maintained as part of the entity itself, rather than as standalone managed policies, which ensures a strict one-to-one relationship between the policy and the identity. This direct attachment qualifies inline policies as a valid type of identity-based policy in IAM. They are particularly useful when you need to guarantee that a specific policy cannot be accidentally attached to another entity.

Why this answer

An inline policy (B) is a valid IAM identity-based policy because it is an embedded JSON policy document attached directly to a single IAM user, group, or role, granting or denying that identity's permissions. An AWS managed policy (E) is also a valid identity-based policy since it is a standalone, AWS-authored policy that can be attached to IAM users, groups, or roles as their permissions policy. By contrast, a trust policy (A) is a resource-based policy on an IAM role that defines which principals may assume it via sts:AssumeRole, not an identity-based permissions policy.

An S3 bucket policy (C) is a resource-based policy attached to the bucket, and a service control policy (D) is an AWS Organizations guardrail that sets maximum permissions for accounts, not an identity-based policy attached to an IAM identity.

Exam trap

SCS-C02 often tests the confusion between identity-based and resource-based policies, so candidates incorrectly select trust policies or S3 bucket policies as identity-based because they all use similar JSON syntax.

1048
MCQhard

A company uses AWS CloudTrail and wants to ensure that log files are encrypted at rest and that access to the logs is logged. Which combination of S3 features should be enabled on the destination bucket?

A.S3 Transfer Acceleration and default encryption
B.MFA Delete and versioning
C.Default encryption and server access logging
D.S3 Object Lock and versioning
AnswerC

Default encryption on the destination S3 bucket automatically applies server-side encryption (SSE-S3, SSE-KMS, or SSE-C) to every CloudTrail log object, satisfying the encryption-at-rest requirement. Server access logging captures detailed records of every request made to the bucket, including the source IP, requester, and operation, which provides the needed audit trail of access to those logs. Together, these features ensure the CloudTrail logs are protected and their access activity is observable.

Why this answer

Enabling default encryption on the S3 bucket ensures that all CloudTrail log files are encrypted at rest using SSE-S3 or SSE-KMS, satisfying the encryption requirement. Enabling server access logging on the same bucket creates detailed records of every request made to the bucket, including who accessed the logs and from where, thus logging access to the logs themselves. This combination directly addresses both requirements: encryption at rest and access logging.

Exam trap

The trap here is that candidates often confuse server access logging with CloudTrail itself, thinking CloudTrail already logs access to the S3 bucket, but CloudTrail logs API calls to the bucket (e.g., PutObject), while server access logging captures every HTTP request at the object level, including reads and anonymous requests.

How to eliminate wrong answers

Option A is wrong because S3 Transfer Acceleration is a feature for speeding up uploads over long distances using edge locations; it does not provide encryption at rest or log access to the bucket. Option B is wrong because MFA Delete adds an extra authentication factor for deleting objects and versioning protects against accidental overwrites, but neither feature encrypts data at rest nor logs access to the logs. Option D is wrong because S3 Object Lock prevents objects from being deleted or overwritten for a fixed time, and versioning maintains multiple versions of objects, but neither provides encryption at rest or access logging.

1049
MCQmedium

A security engineer is troubleshooting why CloudTrail is not delivering logs to an S3 bucket. The bucket policy allows CloudTrail to write objects, and the trail is configured with the correct bucket name. However, no log files appear. What is the most likely cause?

A.The S3 bucket has an S3 Object Lock configuration that prevents writes.
B.The S3 bucket is in a different AWS Region from the trail.
C.CloudTrail is not enabled in the AWS Region where the S3 bucket resides.
D.The S3 bucket uses AWS KMS server-side encryption (SSE-KMS) and the KMS key policy does not grant CloudTrail permission to use the key.
AnswerD

When a destination bucket uses SSE-KMS, CloudTrail must have permission to call kms:GenerateDataKey for encrypting each log file and kms:Decrypt for delivering or reading those files. If the KMS key policy does not explicitly grant CloudTrail these actions, PutObject requests to the bucket will fail even if the bucket policy is correct. CloudTrail’s role also needs the appropriate KMS permissions in the trail’s advanced settings, but the key policy is the critical constraint here.

Why this answer

When CloudTrail is configured to deliver logs to an S3 bucket that uses SSE-KMS, CloudTrail must have explicit permission to use the KMS key for encrypting the log files. Even if the bucket policy allows CloudTrail to write objects, the KMS key policy must grant the `kms:GenerateDataKey` and `kms:Decrypt` actions to the CloudTrail service principal. Without these permissions, CloudTrail cannot encrypt the logs, and delivery fails silently—no log files appear.

Exam trap

The trap here is that candidates often focus only on the S3 bucket policy and overlook the separate KMS key policy requirement, assuming that SSE-KMS encryption is transparent to CloudTrail.

How to eliminate wrong answers

Option A is wrong because S3 Object Lock, when configured, prevents object deletion or overwrite, but it does not prevent initial writes; CloudTrail can still create new log objects. Option B is wrong because CloudTrail can deliver logs to an S3 bucket in a different AWS Region; cross-region delivery is supported and not a cause of failure. Option C is wrong because CloudTrail is enabled in the region where the trail is created, not necessarily where the S3 bucket resides; the trail's region determines logging, not the bucket's region.

1050
MCQeasy

A company wants to provide temporary security credentials to users accessing AWS resources from a mobile app. Which AWS service should they use?

A.AWS Signer
B.AWS Directory Service
C.Amazon Cognito Identity Pools (Federated Identities)
D.AWS IAM roles for cross-account access
AnswerC

Amazon Cognito Identity Pools are built specifically to trade identity tokens from any public or custom identity provider for temporary, least-privilege AWS credentials. The service assigns an IAM role per authenticated or guest user, and returns credentials with a short expiration that map to permissions defined in that role. This makes them the standard choice for mobile and web apps that need direct AWS API access without embedding long-term keys on devices.

Why this answer

Amazon Cognito Identity Pools (Federated Identities) allow you to create unique identities for your users and federate them with identity providers. With an identity pool, you can obtain temporary, limited-privilege AWS credentials to access other AWS services. This is the correct service for providing temporary security credentials to users accessing AWS resources from a mobile app.

Option A (AWS Signer) is for code signing, not temporary credentials. Option B (AWS Directory Service) is for managing Microsoft Active Directory, not for generating temporary credentials. Option D (AWS IAM roles for cross-account access) is for granting access between AWS accounts, not for mobile app users.

Page 13

Page 14 of 17

Page 15