Courseiva

AWS Certified Security Specialty SCS-C02 (SCS-C02) — Questions 1051–1125

1205 questions total · 17pages · All types, answers revealed

Page 14

Page 15 of 17

Page 16
1051
Multi-Selecthard

A security engineer is investigating a GuardDuty finding of type 'Backdoor:EC2/C&CActivity.B!DNS'. Which TWO actions should the engineer take as part of the initial response? (Choose two.)

Select 2 answers
A.Enable Amazon GuardDuty in the account if not already enabled.
B.Isolate the EC2 instance by modifying its security group to deny all traffic.
C.Immediately terminate the EC2 instance to stop the activity.
D.Take a snapshot of the instance's EBS volume for forensic analysis.
E.Disable termination protection on the instance to allow future termination.
AnswersB, D

Replacing the instance's security group with one that has no inbound or outbound rules immediately severs network paths used for command-and-control, data exfiltration, and lateral movement while the operating system keeps running. Security groups act as a stateful virtual firewall, so removing all allow rules drops existing connections and blocks new ones without terminating the instance. This containment preserves volatile memory and disk state for subsequent forensic collection, making it the correct first response.

Why this answer

Isolating the EC2 instance by modifying its security group to deny all traffic is a critical containment step in incident response. This immediately stops the C2 (command and control) communication detected by GuardDuty's 'Backdoor:EC2/C&CActivity.B!DNS' finding, preventing further data exfiltration or lateral movement while preserving the instance for forensic analysis.

Exam trap

The trap here is that candidates may confuse incident response containment with eradication, choosing immediate termination (Option C) instead of isolation and forensic preservation (Option B and D).

1052
MCQeasy

A security engineer runs the command shown in the exhibit. What is the outcome?

A.The command fails because AES256 is not a valid algorithm.
B.Default encryption is enabled on the bucket using SSE-S3.
C.Default encryption is enabled on the bucket using SSE-KMS.
D.The command removes default encryption from the bucket.
AnswerB

Seeing `SSEAlgorithm: AES256` in the bucket encryption response means default encryption is enabled with SSE-S3, where Amazon S3 manages the encryption keys. This configuration causes new objects written to the bucket to be automatically encrypted at rest with 256-bit AES using S3-managed keys, and the setting is stored as a bucket-level default rather than applied individually per object.

Why this answer

The command `aws s3api put-bucket-encryption --bucket my-bucket --server-side-encryption-configuration '{"Rules":[{"ApplyServerSideEncryptionByDefault":{"SSEAlgorithm":"AES256"}}]}'` enables default encryption on the bucket using SSE-S3, because `AES256` is the algorithm identifier for SSE-S3 (Amazon S3-managed keys). The command succeeds and sets the default encryption configuration to use server-side encryption with S3-managed keys, which is the standard SSE-S3 behavior.

Exam trap

The trap here is that candidates confuse `AES256` with an invalid algorithm or assume it refers to SSE-KMS, but AWS specifically uses `AES256` as the identifier for SSE-S3, while `aws:kms` is used for SSE-KMS.

How to eliminate wrong answers

Option A is wrong because AES256 is a valid algorithm identifier for SSE-S3; it is not invalid, and the command does not fail due to algorithm validation. Option C is wrong because the algorithm identifier for SSE-KMS is `aws:kms`, not `AES256`; using `AES256` explicitly sets SSE-S3, not SSE-KMS. Option D is wrong because the command adds or updates default encryption, it does not remove it; removing default encryption requires a different API call (e.g., `delete-bucket-encryption`).

1053
MCQhard

A company uses AWS Shield Advanced to protect its web application against DDoS attacks. The application is behind an Application Load Balancer (ALB) with a web application firewall (AWS WAF) in front. The security team notices that some requests are being blocked by AWS WAF, but the source IP addresses are legitimate customers. What step should the team take to minimize false positives?

A.Implement rate-based rules with a count action and use the count data to create custom rules.
B.Switch to using AWS Managed Rules for IP reputation lists.
C.Increase the WAF rate-based rule threshold to allow more requests.
D.Reconfigure the ALB idle timeout to a higher value.
AnswerA

Use a rate-based rule in COUNT mode so WAF evaluates the request rate and increments the relevant counters without blocking traffic. This exposes the per-IP distribution in CloudWatch metrics and sampled requests, letting you determine a burst threshold that separates human usage from automated floods. The count data then informs a custom rule (e.g., with an aggregate key or scope-down statement) that blocks only when the observed rate genuinely exceeds your normal baseline, minimizing false positives.

Why this answer

Rate-based rules with a count action allow the team to monitor request patterns without blocking legitimate traffic. The count action logs matching requests, enabling analysis to create custom rules that accurately distinguish between malicious and legitimate traffic. This approach minimizes false positives by basing rule logic on observed data rather than static thresholds.

Exam trap

SCS-C02 often tests the misconception that increasing thresholds or using managed rules directly solves false positives, but the key is to first monitor with count mode to gather data before making blocking decisions.

How to eliminate wrong answers

Option B is wrong because AWS Managed Rules for IP reputation lists block based on known malicious IPs, but legitimate customers may be falsely flagged if their IPs are misclassified or shared, and this doesn't address the root cause of false positives from rate-based rules. Option C is wrong because simply increasing the rate-based rule threshold may allow more malicious traffic through and doesn't solve the false positive issue for legitimate customers who might still exceed the new threshold. Option D is wrong because ALB idle timeout is unrelated to WAF false positives; it controls connection persistence and has no impact on request blocking decisions.

1054
Multi-Selectmedium

A security engineer is designing a VPC with public and private subnets. The private subnets must be able to download software updates from the internet. Which TWO components can provide this functionality without exposing the private instances to inbound internet traffic?

Select 2 answers
A.NAT gateway
B.Internet gateway
C.VPC endpoint
D.Egress-only internet gateway
E.NAT instance
AnswersA, E

A NAT gateway is a fully managed AWS service that performs source network address translation, replacing private IPv4 addresses with its own Elastic IP for outbound internet traffic. Because it is stateful, it automatically drops any unsolicited inbound connections initiated from the internet, so it satisfies the security requirement of blocking inbound while enabling outbound. It also scales automatically and requires no patching or maintenance, making it the recommended choice.

Why this answer

A NAT gateway is a managed AWS service that enables instances in a private subnet to initiate outbound traffic to the internet (e.g., for downloading software updates) while preventing the internet from initiating inbound connections to those instances. It translates the private IP addresses of the instances to the NAT gateway's Elastic IP address, allowing return traffic to be routed back correctly. This meets the requirement of outbound-only internet access without exposing private instances to inbound traffic.

Exam trap

The trap here is that candidates often confuse NAT gateway with internet gateway, assuming both provide outbound-only access, but the internet gateway is bidirectional and would expose private instances to inbound traffic if used directly.

1055
MCQhard

A company uses AWS Organizations with all features enabled. The security team needs to ensure that no member account can disable AWS CloudTrail logging or delete CloudTrail logs stored in S3. Which combination of preventive controls should be implemented?

A.Set up CloudWatch alarms to notify when CloudTrail is modified or logs are deleted.
B.Apply a service control policy (SCP) at the root OU to deny CloudTrail and S3 delete actions, and enable CloudTrail organizational trail.
C.Use IAM policies in each member account to deny CloudTrail and S3 delete actions.
D.Apply an S3 bucket policy denying delete actions, and enable CloudTrail organizational trail.
AnswerB

An SCP placed on the root organizational unit applies as a permission boundary to every account and principal in the organization, including each account's root user, so a deny of cloudtrail:StopLogging, cloudtrail:DeleteTrail, s3:DeleteBucket, and s3:DeleteObject makes tampering impossible even for administrators. The organizational trail, enabled from the management account, automatically collects events from all member accounts and cannot be stopped or disabled by any individual account. Together these controls enforce both protection of the audit trail and preservation of the log files, satisfying the requirement for a preventive solution.

Why this answer

The most effective preventive controls are applying a Service Control Policy (SCP) at the root OU to deny CloudTrail stop/delete and S3 delete actions, combined with enabling an organizational trail in CloudTrail. SCPs enforce guardrails across all member accounts, preventing even account administrators from disabling logging or deleting logs, while the organizational trail ensures centralized logging to a protected S3 bucket.

Exam trap

SCS-C02 often tests whether candidates confuse detective controls (CloudWatch alarms) or per-account IAM policies with organization-wide preventive controls (SCPs), leading them to choose weaker or reactive options.

How to eliminate wrong answers

Option A is wrong because CloudWatch alarms are detective, not preventive; they notify after the fact but do not stop the actions. Option C is wrong because IAM policies in each member account can be modified or bypassed by account administrators and do not provide centralized enforcement like SCPs. Option D is wrong because an S3 bucket policy alone does not prevent disabling CloudTrail logging in member accounts; it only protects the bucket, and it lacks the organization-wide preventive control of an SCP.

1056
MCQhard

A security engineer is troubleshooting an issue where an IAM policy allows access to S3 but the user is denied access to a specific bucket. The policy has the following statement: { "Effect": "Allow", "Action": "s3:*", "Resource": "*" } What is the most likely cause of the denial?

A.The policy statement is too broad and AWS automatically denies access to specific buckets.
B.An explicit deny statement in a different policy (e.g., SCP, permissions boundary) is overriding the allow.
C.The S3 bucket has a bucket policy that denies access to the user.
D.The policy is attached to the user but the user is assuming a role that does not have S3 permissions.
AnswerB

An explicit deny in any applicable policy, such as a service control policy (SCP) attached to an organizational unit or a permissions boundary on the IAM principal, overrides any allow in the user's own IAM policy. During policy evaluation, AWS determines the final decision by first considering all applicable policies and applying the rule that an explicit deny takes precedence over any allow. Even if the user's policy grants s3:GetObject, the explicit deny in the SCP or boundary will cause the request to fail with an access denied error. To resolve this, the security engineer must identify and modify the deny statement or remove the restricting boundary.

Why this answer

AWS evaluates all applicable policies using a union-of-allows model, but any explicit Deny anywhere in the evaluation chain (identity policy, resource policy, SCP, permissions boundary, session policy) wins over every Allow. A broad Allow like s3:* on * does not get 'narrowed' by AWS — it is simply overridden when an explicit Deny matches the same action/resource. The most likely cause is therefore an explicit Deny in an SCP, permissions boundary, or similar policy that targets the specific bucket.

Exam trap

SCS-C02 often tests the misconception that a broad Allow policy 'wins' or that AWS auto-narrows permissions — candidates forget that explicit Deny always overrides Allow in the IAM evaluation chain.

How to eliminate wrong answers

Option A is wrong because AWS never automatically denies access to specific buckets just because a policy is broad — Allow statements are additive and only explicit Deny overrides them. Option C is wrong because while a bucket policy can deny access, the question asks for the most likely cause given the scenario of a policy that 'allows access to S3 but the user is denied' — an explicit Deny in the identity/SCP/boundary chain is the canonical answer, and a bucket policy deny would be a resource-based explicit deny, which is a subset of the same principle but not the best fit for the described symptom. Option D is wrong because if the user assumed a role, the role's permissions would be evaluated instead of the user's policy — but the question states the policy is attached to the user and the user is denied, so the role-assumption scenario contradicts the premise.

1057
MCQeasy

A security engineer is configuring a security group for a web server that should only accept HTTPS traffic from the internet. Which inbound rule should be set?

A.TCP port 3389 from 0.0.0.0/0
B.TCP port 22 from 0.0.0.0/0
C.TCP port 80 from 0.0.0.0/0
D.TCP port 443 from 0.0.0.0/0
AnswerD

Port 443 is HTTPS, the default port for encrypted web traffic using TLS. Because the instance is intended to serve a public website, allowing inbound TCP 443 from 0.0.0.0/0 lets internet clients reach the service securely while security groups remain stateful, automatically permitting return traffic. This rule aligns with the stated requirement and is the correct enablement for a web server receiving secure browser connections.

Why this answer

HTTPS uses TCP port 443, so an inbound security group rule allowing TCP 443 from 0.0.0.0/0 permits HTTPS traffic from any internet source. This is the standard configuration for a public web server that must accept secure web traffic. Security groups are stateful, so return traffic is automatically allowed without an outbound rule.

Exam trap

SCS-C02 often tests port-number recall under time pressure — candidates confuse 443 (HTTPS) with 80 (HTTP) or pick 22/3389 thinking 'secure' means SSH/RDP, when the question specifically asks for HTTPS.

How to eliminate wrong answers

Option A is wrong because TCP 3389 is RDP (Remote Desktop Protocol) for Windows — exposing it to 0.0.0.0/0 is a critical security risk and unrelated to HTTPS. Option B is wrong because TCP 22 is SSH for Linux administration — again a dangerous public exposure and not HTTPS. Option C is wrong because TCP 80 is unencrypted HTTP, not HTTPS; allowing it would permit plaintext web traffic, violating the requirement for HTTPS only.

1058
Multi-Selecthard

A company's security team is implementing controls to meet PCI DSS compliance. The environment includes Amazon EC2, RDS, and S3. Which THREE controls should be implemented to address logging and monitoring requirements?

Select 3 answers
A.Enable AWS Config to track resource configuration changes.
B.Enable VPC Flow Logs for all VPCs.
C.Enable AWS CloudTrail across all AWS regions.
D.Deploy Amazon CloudWatch Application Insights.
E.Enable detailed billing reports.
AnswersA, B, C

AWS Config records resource configuration changes as configuration items, generating a complete history that can be compared against baseline rules. For PCI DSS, it demonstrates compliance with configuration standards (e.g., Requirement 2) by detecting drift from approved settings, such as security group changes or unencrypted storage. This detective control is essential for proving that system configurations are maintained and reviewed.

Why this answer

AWS Config is correct because it tracks resource configuration changes and records them as configuration items, which is essential for PCI DSS Requirement 10.5.2 that mandates logging of all actions taken by any individual with root or administrative privileges. By monitoring changes to EC2, RDS, and S3 configurations, AWS Config provides an audit trail of who made changes, what changed, and when, directly supporting logging and monitoring compliance.

Exam trap

The trap here is that candidates may confuse operational monitoring tools (like CloudWatch Application Insights) or billing tools with the specific logging and monitoring controls required by PCI DSS, which focus on audit trails of configuration changes, network traffic, and API activity.

1059
MCQmedium

A security engineer is investigating a potential data breach. AWS CloudTrail logs show that an IAM user 'svc-backup' created an S3 bucket in the us-east-1 region and then uploaded a large number of objects. The engineer suspects that the user's credentials were compromised. What is the MOST efficient way to quickly identify the source IP address and user agent of the API calls made by this user?

A.Query AWS CloudTrail logs in Amazon Athena for the user's API calls.
B.Analyze VPC Flow Logs for traffic to the S3 bucket.
C.Enable Amazon GuardDuty and review the generated findings.
D.Use AWS Config to review the configuration history of the S3 bucket.
AnswerA

AWS CloudTrail records every S3 management and data event, including the IAM user or role, sourceIPAddress, userAgent, event name, and request parameters, and it delivers these logs as gzipped JSON to an S3 bucket. Amazon Athena can run SQL queries directly against that CloudTrail log set, allowing you to quickly filter for a specific user's API calls over a time range and correlate source IPs, user agents, and event names to determine the scope of the breach. This is the standard, authoritative method for investigating API-level activity after an incident.

Why this answer

CloudTrail logs capture detailed records of all API calls, including the source IP address and user agent for each request. By querying these logs with Amazon Athena, the security engineer can efficiently filter for the specific IAM user 'svc-backup' and extract the source IP and user agent from the relevant event records, enabling rapid identification of the compromised credentials' origin.

Exam trap

The trap here is that candidates may confuse VPC Flow Logs (which show network-level traffic) with CloudTrail logs (which show API-level activity), failing to recognize that only CloudTrail captures the IAM user identity and user agent required for this investigation.

How to eliminate wrong answers

Option B is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) but do not include user agent strings or IAM user identity; they cannot link traffic to a specific IAM user's API calls. Option C is wrong because Amazon GuardDuty generates security findings based on threat detection, but it does not provide a direct, queryable history of source IPs and user agents for past API calls; it would require additional investigation and does not offer the most efficient way to retrieve this specific historical data. Option D is wrong because AWS Config records configuration changes to resources (e.g., bucket creation, policy updates) but does not capture API call metadata such as source IP address or user agent; it is designed for compliance and configuration tracking, not for investigating API call origins.

1060
MCQeasy

A security engineer is configuring an AWS environment to detect and respond to potential security threats. Which AWS service can be used to automate the remediation of unwanted access to Amazon S3 buckets by invoking AWS Lambda functions?

A.AWS Config
B.Amazon GuardDuty
C.Amazon Inspector
D.AWS WAF
AnswerB

Amazon GuardDuty is a threat detection service that continuously analyzes AWS CloudTrail management and data events, VPC Flow Logs, and DNS logs using machine learning and integrated threat intelligence. It specifically detects suspicious S3 access patterns, such as unusual geographical locations, high-volume downloads, or bucket enumeration, and raises findings that can be sent to Amazon EventBridge. This enables automated remediation, for example a Lambda function that revokes IAM policies or applies a bucket policy, making it the correct choice for detecting and automating response to access threats.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior across AWS accounts and workloads. It can integrate with AWS Lambda functions via CloudWatch Events to automate remediation actions, such as blocking unwanted access to S3 buckets by updating bucket policies or removing public access. This makes GuardDuty the correct choice for detecting and automatically responding to security threats against S3 resources.

Exam trap

The trap here is that candidates often confuse AWS Config's ability to auto-remediate noncompliant resources (using AWS Config rules and Lambda) with GuardDuty's threat-specific detection and response, but AWS Config does not detect security threats like unauthorized access—it only enforces configuration rules.

How to eliminate wrong answers

Option A is wrong because AWS Config is a configuration auditing and compliance service that evaluates resource configurations against rules, but it does not natively detect security threats or invoke Lambda functions for threat remediation; it can trigger Lambda for configuration drift, not for threat response. Option C is wrong because Amazon Inspector is a vulnerability assessment service that scans EC2 instances and container images for software vulnerabilities and network exposure, not for detecting or remediating unwanted access to S3 buckets. Option D is wrong because AWS WAF is a web application firewall that protects web applications from common exploits like SQL injection and cross-site scripting, and it does not monitor or remediate S3 bucket access patterns.

1061
MCQhard

A company uses AWS Organizations with multiple accounts. The security team wants to centrally monitor and analyze all CloudTrail logs from all accounts. The logs must be stored in a centralized S3 bucket with encryption and access logging enabled. Additionally, the team needs to detect anomalous API activity across accounts using machine learning. Which combination of services meets these requirements?

A.AWS CloudTrail to deliver logs to a centralized S3 bucket with default encryption; AWS Config to monitor API activity; S3 server access logs enabled.
B.AWS CloudTrail to deliver logs to a centralized S3 bucket with default encryption; Amazon Macie to detect anomalous API activity; S3 server access logs enabled.
C.AWS CloudTrail to deliver logs to a centralized S3 bucket with default encryption; Amazon Detective to analyze API activity; S3 server access logs enabled.
D.AWS CloudTrail to deliver logs to a centralized S3 bucket with default encryption and S3 server access logs; Amazon GuardDuty enabled in all accounts.
AnswerD

CloudTrail captures every API call across all accounts and delivers a tamper-evident log to the centralized S3 bucket, with default encryption protecting it at rest. Amazon GuardDuty, enabled in all accounts, continuously analyzes CloudTrail events along with VPC Flow Logs and DNS logs using machine learning and threat intelligence to detect anomalies such as compromised credentials or unusual API sequences. S3 server access logs provide object-level request logging for the centralized bucket itself. Together these components deliver both comprehensive API activity logging and proactive ML-based anomaly detection across the organization.

Why this answer

It combines AWS CloudTrail for centralized log delivery to an S3 bucket with default encryption and server access logs, and Amazon GuardDuty, which uses machine learning to detect anomalous API activity across accounts. GuardDuty analyzes CloudTrail management events, VPC flow logs, and DNS logs to identify suspicious behavior, meeting the requirement for ML-based anomaly detection.

Exam trap

The trap here is confusing Amazon Detective as a proactive detection service when it is actually a reactive investigation tool that relies on findings from GuardDuty, not a standalone ML-based anomaly detector for API activity.

How to eliminate wrong answers

Option A is wrong because AWS Config is a configuration compliance service that monitors resource changes, not API activity anomalies, and it does not use machine learning for detection. Option B is wrong because Amazon Macie is designed for data security and privacy, focusing on sensitive data discovery in S3, not for detecting anomalous API activity across accounts. Option C is wrong because Amazon Detective is a post-incident investigation tool that analyzes existing findings from GuardDuty, not a real-time ML-based anomaly detection service for API activity.

1062
MCQeasy

A company uses S3 Server Access Logs to audit access to their S3 buckets. The security team wants to ensure that the log files themselves are encrypted at rest using SSE-KMS. Which configuration step is necessary?

A.Use an S3 bucket policy to deny unencrypted uploads to the source bucket
B.Enable default encryption on the source bucket
C.Add a bucket policy on the destination bucket that grants the S3 log delivery service permission to use the KMS key
D.Configure the destination bucket with a lifecycle policy
AnswerC

When the destination bucket for S3 server access logs uses SSE-KMS, the S3 log delivery service (logging.s3.amazonaws.com) must be explicitly allowed to use that KMS key to encrypt the log objects it writes. This is done by adding a bucket policy on the destination bucket that grants kms:GenerateDataKey and kms:Encrypt (as well as s3:PutObject) to the log delivery service. Additionally, the KMS key policy must also allow this service principal to use the key; otherwise, log delivery will fail with an access denied error. This is a required step, so this is the correct answer.

Why this answer

To encrypt S3 Server Access Logs at rest with SSE-KMS, you must add a bucket policy on the destination (log) bucket that grants the S3 log delivery service principal permission to use the KMS key. S3 log delivery writes logs as a service principal, so it needs explicit kms:GenerateDataKey and kms:Decrypt permissions on the key, plus s3:PutObject on the bucket. Without this, log delivery fails when the destination bucket uses SSE-KMS.

Exam trap

SCS-C02 often tests the misconception that enabling default encryption on the source bucket or denying unencrypted uploads secures log files, when the actual requirement is granting the log delivery service permission to use the KMS key on the destination bucket.

How to eliminate wrong answers

Option A is wrong because denying unencrypted uploads to the source bucket does not affect how log files are encrypted in the destination bucket; it addresses source bucket uploads, not log delivery encryption. Option B is wrong because enabling default encryption on the source bucket encrypts objects in the source bucket, not the server access log files delivered to the destination bucket. Option D is wrong because a lifecycle policy manages object transitions and expiration, not encryption or permissions for log delivery; it has no bearing on SSE-KMS for logs.

1063
MCQmedium

A company uses Amazon S3 to store sensitive data. The security team wants to detect and alert on public read access to S3 buckets. Which combination of AWS services is MOST appropriate?

A.AWS CloudTrail and Amazon CloudWatch Logs with metric filters for `PutBucketPolicy` events.
B.Amazon Macie with automated discovery jobs and Amazon CloudWatch Events to send alerts.
C.Amazon GuardDuty and AWS Lambda.
D.AWS Config with managed rules like `s3-bucket-public-read-prohibited` and Amazon SNS.
AnswerB

Macie automatically discovers sensitive data using managed data identifiers and also evaluates S3 bucket policies and ACLs for public access. It runs automated discovery jobs on a schedule, and you can use CloudWatch Events to trigger alerts for both sensitive data findings and policy findings. This combines content discovery with access control verification, addressing both dimensions of the requirement.

Why this answer

Amazon Macie is purpose-built for discovering and protecting sensitive data in S3, and its automated discovery jobs can detect public read access to buckets. By integrating with Amazon CloudWatch Events, Macie can trigger alerts in real-time when such access is identified, making it the most appropriate choice for this detection and alerting requirement.

Exam trap

The trap here is that candidates often confuse AWS Config's compliance evaluation (which is periodic and reactive) with real-time detection and alerting, or they mistakenly believe CloudTrail captures all public access events, when in fact it only logs API calls that change permissions, not the resulting access state.

How to eliminate wrong answers

Option A is wrong because CloudTrail logs `PutBucketPolicy` events, but this only captures policy changes, not the actual public read access state; a bucket could be publicly readable via ACLs or a pre-existing policy without triggering a new `PutBucketPolicy` event, leading to missed detections. Option C is wrong because GuardDuty focuses on threat detection (e.g., unusual API calls, credential compromise) and does not natively scan S3 bucket permissions for public read access; while Lambda could be used to write custom logic, it is not a direct or managed solution for this specific requirement. Option D is wrong because AWS Config managed rule `s3-bucket-public-read-prohibited` is a detective control that evaluates compliance but does not natively generate real-time alerts; while SNS can be configured, the rule only runs on periodic evaluations or configuration changes, not continuously, and it does not detect public read access via ACLs or bucket policies that are already in place.

1064
Multi-Selecteasy

A developer wants to allow an IAM role to be assumed by an EC2 instance that is part of an Auto Scaling group. Which TWO AWS services or features are required? (Choose TWO.)

Select 2 answers
A.AWS Config
B.Instance profile
C.IAM role
D.AWS CloudFormation
E.AWS Single Sign-On (SSO)
AnswersB, C

An instance profile is the container that delivers an IAM role's temporary credentials to EC2 via the instance metadata service. Auto Scaling groups reference the profile in their launch template, so each launched instance automatically assumes the role.

Why this answer

Option B (Instance profile) is correct because an instance profile is the container that passes an IAM role's temporary credentials to an EC2 instance; without attaching an instance profile to the instance, the EC2 instance cannot assume the role. Option C (IAM role) is correct because the role defines the permissions and trust policy that the EC2 instance assumes to obtain temporary credentials via the instance metadata service (IMDS). AWS Config (A) is a compliance and configuration tracking service and is not required to assume a role.

AWS CloudFormation (D) is an infrastructure-as-code service that could optionally launch resources but is not required for role assumption. AWS Single Sign-On (E) is for human user federated access, not for EC2 instance role assumption.

Exam trap

The trap here is that candidates often confuse IAM roles with instance profiles, thinking a role can be directly attached to an EC2 instance, but the instance profile is the required intermediary container that enables the role to be assumed by the instance.

1065
MCQhard

Refer to the exhibit. An IAM policy attached to a user allows s3:GetObject only from a specific IP range and denies all S3 actions if not using HTTPS. What happens when the user makes a GET request from IP 10.0.0.5 using HTTP?

A.Allowed because the IP is in the range
B.Allowed because the condition does not match
C.Denied because the Deny statement matches
D.Denied because the IP is not in the range
AnswerC

IAM decisions are made by evaluating all statements: if any applicable Deny statement matches the request, the result is Deny regardless of any matching Allow. Here, the Deny statement's condition is satisfied by the request, and because explicit Deny statements cannot be overridden by Allows, the effective decision is denied. This is not due to a default deny or missing allow, but an active, matching Deny.

Why this answer

IAM policies evaluate all matching statements, and an explicit Deny always wins over any Allow. The policy denies all S3 actions when the request is not using HTTPS (aws:SecureTransport is false). Since the user made the request over HTTP, the Deny statement matches, so the request is denied regardless of the IP-based Allow.

Exam trap

SCS-C02 often tests the misconception that an Allow for a matching IP will permit the request — candidates forget that an explicit Deny with a matching condition always wins.

How to eliminate wrong answers

Option A is wrong because the IP being in the allowed range is irrelevant when an explicit Deny matches — explicit Deny overrides Allow. Option B is wrong because the condition does match: HTTP means aws:SecureTransport is false, triggering the Deny. Option D is wrong because the IP 10.0.0.5 is within the allowed range, so the IP is not the reason for denial — the HTTP protocol is.

1066
MCQhard

A company is using AWS DMS to migrate data from an on-premises Oracle database to Amazon RDS for PostgreSQL. The data must be encrypted in transit. What should the company do?

A.Use AWS Direct Connect to establish a private connection.
B.Enable SSL on the source and target endpoints in the DMS task.
C.Use AWS KMS to encrypt the data before sending.
D.Set up a VPN connection between the on-premises network and AWS VPC.
AnswerB

AWS DMS has native support for SSL/TLS encryption between the replication instance and both the source and target endpoints. For each endpoint, you can specify an SSL mode (e.g., require for Oracle, SQL Server, and PostgreSQL, or verify-ca for Aurora MySQL) so that all data transferred between the database and DMS is encrypted in transit. With SSL enabled, DMS negotiates an encrypted connection directly with the database engines, ensuring data is protected without relying on additional VPN or network manipulation. This is the most direct and appropriate way to encrypt migration traffic in AWS DMS.

Why this answer

AWS DMS supports SSL/TLS to encrypt data in transit between source and target endpoints. Enabling SSL on both endpoints ensures that the data migration is encrypted over the network. Option A is incorrect because AWS Direct Connect provides a private network connection but does not automatically encrypt traffic; additional encryption like SSL is still required for data in transit.

Option C is incorrect because AWS KMS is used for encryption at rest, not for encrypting data in transit. Option D is incorrect because a VPN connection provides a secure tunnel but is not necessary; DMS can use SSL directly on the endpoints, which is a simpler solution.

1067
MCQeasy

A company is using Amazon S3 to store sensitive data. The security team wants to ensure that all data is encrypted in transit between the company's on-premises data center and AWS. Which solution should be used?

A.Use an AWS Site-to-Site VPN with IPsec to encrypt traffic
B.Use AWS CloudHSM to encrypt the data in transit
C.Enable SSE-S3 on the S3 bucket
D.Use AWS KMS to encrypt the data before transmission
AnswerA

An AWS Site-to-Site VPN uses IPsec to encrypt traffic between the on-premises data centre and AWS, satisfying the in-transit encryption requirement for data moving to Amazon S3. IPsec provides cryptographic protection at the network layer, covering all traffic over the connection without application changes.

Why this answer

An AWS Site-to-Site VPN with IPsec is the correct solution because it creates an encrypted tunnel between the on-premises data center and AWS, ensuring all data in transit is protected. IPsec operates at the network layer (Layer 3) and encrypts the entire IP packet, providing confidentiality and integrity for data moving over the public internet. This directly addresses the requirement to encrypt data in transit between the two environments.

Exam trap

The trap here is that candidates often confuse encryption at rest (SSE-S3, KMS) with encryption in transit, and assume that encrypting data before sending it (e.g., with KMS) automatically secures the transmission channel, when in fact a transport-layer encryption mechanism like IPsec or TLS is required to protect data during transit.

How to eliminate wrong answers

Option B is wrong because AWS CloudHSM is a hardware security module used for key storage and cryptographic operations, not for encrypting data in transit; it does not provide network-level encryption between on-premises and AWS. Option C is wrong because SSE-S3 (Server-Side Encryption with S3-Managed Keys) encrypts data at rest in S3, not data in transit; it has no effect on traffic between the on-premises data center and AWS. Option D is wrong because AWS KMS is a key management service that can be used to encrypt data before transmission, but it does not provide a secure tunnel or protocol-level encryption for the data in transit; the data would still be sent over the internet in an unencrypted form unless a transport encryption mechanism like TLS or IPsec is also applied.

1068
MCQhard

Refer to the exhibit. A security engineer is reviewing a CloudTrail event. What security concern does this event raise?

A.The user is revoking a security group rule.
B.The event is not being logged by CloudTrail.
C.The user is using the AWS root account.
D.The user is opening SSH access to the world.
AnswerD

The AuthorizeSecurityGroupIngress call is adding a rule allowing TCP port 22 (SSH) from CIDR 0.0.0.0/0. A CIDR of 0.0.0.0/0 represents all possible IPv4 addresses, meaning any host on the internet can attempt to connect to port 22 on the associated instances. This effectively exposes SSH to the world, which is a critical security risk because it invites brute-force attacks and unauthorized access attempts.

Why this answer

The CloudTrail event shows an AuthorizeSecurityGroupIngress API call with a CidrIp of 0.0.0.0/0 for port 22 (SSH). This opens SSH access to the entire internet, which is a severe security risk because it exposes the instance to brute-force attacks, unauthorized access, and potential compromise. The correct answer is D because this action directly violates the principle of least privilege and is a common misconfiguration.

Exam trap

The trap here is that candidates may focus on the fact that the event is logged (Option B) or the user identity (Option C), but the core security concern is the overly permissive inbound rule that grants unrestricted SSH access.

How to eliminate wrong answers

Option A is wrong because the event is an AuthorizeSecurityGroupIngress call, which adds a rule, not a RevokeSecurityGroupIngress call, which would remove a rule. Option B is wrong because the event is already being logged by CloudTrail, as evidenced by the JSON record provided; CloudTrail logs all API calls by default unless explicitly excluded. Option C is wrong because the user identity in the event shows an ARN with 'user/Admin', indicating an IAM user, not the root account (which would have 'root' in the ARN).

1069
Multi-Selectmedium

Which TWO AWS services can be used to centrally manage and audit permissions across multiple AWS accounts? (Choose two.)

Select 2 answers
A.AWS Config
B.AWS CloudTrail
C.AWS Organizations
D.AWS Single Sign-On
E.IAM Access Analyzer
AnswersC, E

AWS Organizations is the correct service for centrally managing multiple accounts and applying service control policies (SCPs) that place guardrails on the maximum permissions available to IAM principals within member accounts. SCPs act as a policy filter, allowing you to forbid or allow specific AWS services and actions at the organizational, organizational unit, or account level without modifying the IAM policies themselves. This makes Organizations a central control plane for permission boundaries across an entire AWS environment.

Why this answer

AWS Organizations provides a central view of all accounts and can apply SCPs. IAM Access Analyzer analyzes resource policies across accounts to identify public or cross-account access. AWS Config evaluates resource configurations but does not centrally manage permissions.

AWS CloudTrail logs API calls but does not manage permissions. AWS SSO manages user access but not resource permissions.

1070
MCQhard

A company has a policy that requires all IAM users to use multi-factor authentication (MFA) to access the AWS Management Console. A user reports that they are unable to sign in even after configuring MFA. What is the most likely cause?

A.The IAM policy explicitly denies console access.
B.The user is using the root account instead of an IAM user.
C.The MFA token has expired.
D.The MFA device is not properly synchronized with AWS.
AnswerD

The most common cause of consistently rejected MFA codes is clock drift between the authenticator device and AWS’s TOTP server, so the 30-second time window computed by the device does not match AWS’s window. AWS compares the presented code with codes for the current time step and an allowed clock skew; if the device’s time is off by more than the skew, even a freshly generated code will fail. To fix this, synchronize the device clock (or re-register the MFA device), which is why 'MFA device is not properly synchronized with AWS' correctly describes the failure.

Why this answer

The most likely cause is that the MFA device is not properly synchronized with AWS. When an IAM user configures MFA, the device must be synchronized with AWS to generate valid tokens. If synchronization fails, the token entered during sign-in will be rejected, preventing console access.

Option A is unlikely because if the policy explicitly denied console access, the user would not be able to sign in at all regardless of MFA, but the user specifically reported having configured MFA and still fails. Option B is incorrect because the root account does not require MFA for console access by default, and the user stated they are an IAM user. Option C is incorrect because MFA tokens do not expire; they are time-based and change every 30 seconds, but the token itself does not become permanently invalid after a period.

The issue is synchronization.

1071
MCQhard

A security engineer is designing a solution to monitor and remediate non-compliant resources across multiple AWS accounts. The company uses AWS Organizations and wants to enforce that any S3 bucket with public read access is automatically remediated. The solution must be centralized and scalable. Which approach should the engineer take?

A.Deploy an AWS Config conformance pack with a rule and an auto-remediation action using AWS Systems Manager Automation.
B.Create an AWS Config rule in each account and configure an Amazon CloudWatch Events rule to trigger an AWS Lambda function for remediation.
C.Use AWS Trusted Advisor to identify public buckets and manually remediate them.
D.Deploy an AWS Config conformance pack with a rule that checks for public buckets and reports non-compliance.
AnswerA

AWS Config conformance packs aggregate a pack of rules plus associated remediation actions, deployable across an entire AWS Organization from a single managed template. For a public S3 bucket, the included rule (e.g., s3-bucket-public-read-prohibited) detects noncompliance and automatically invokes an SSM Automation document, such as AWS-DisablePublicReadAccessForS3Bucket, to remove public access. This provides centralized, scalable, and fully automated governance rather than per-account, manual, or report-only controls.

Why this answer

AWS Config conformance packs allow you to deploy a collection of AWS Config rules and remediation actions across multiple accounts and Regions in AWS Organizations. By including an auto-remediation action using AWS Systems Manager Automation, the solution can automatically remediate S3 buckets with public read access in a centralized and scalable manner, without manual intervention or per-account configuration.

Exam trap

The trap here is that candidates may confuse conformance packs with simple AWS Config rules, forgetting that conformance packs can include automated remediation actions via Systems Manager Automation, while standalone rules only detect and report non-compliance.

How to eliminate wrong answers

Option B is wrong because creating an AWS Config rule in each account is not centralized; it requires manual setup per account and does not scale efficiently across many accounts. Option C is wrong because AWS Trusted Advisor only identifies public buckets and provides recommendations, but it does not support automated remediation; manual remediation is not scalable or centralized. Option D is wrong because while an AWS Config conformance pack with a rule can detect non-compliant public buckets, it only reports non-compliance and does not include an auto-remediation action, failing to meet the requirement for automatic remediation.

1072
MCQeasy

A security engineer is configuring a multi-account CloudTrail setup. The above bucket policy is attached to the central logging bucket. Despite the policy, CloudTrail in the member account (123456789012) cannot deliver logs. What is the MOST likely issue?

A.The Principal should be the CloudTrail service principal of the member account.
B.The condition s3:x-amz-acl is not required; CloudTrail does not set that ACL.
C.The Action should be s3:PutObjectAcl instead of s3:PutObject.
D.The resource ARN must include the source account ID in the path.
AnswerB

CloudTrail delivers log files via the S3 `PutObject` API, but it does not set the `x-amz-acl` request header or the `bucket-owner-full-control` canned ACL unless the trail is explicitly configured for that behavior. If the bucket policy uses a `StringEquals` condition on `s3:x-amz-acl`, every PutObject request from CloudTrail will not match the condition and is denied before the write can occur. Removing that condition allows the PutObject action to succeed; use a condition on `aws:SourceArn` or `aws:SourceAccount` instead to scope the trust.

Why this answer

CloudTrail does not set the s3:x-amz-acl condition key when delivering log files to S3. The bucket policy incorrectly includes this condition, which causes the S3 authorization to fail because the condition key is not present in the CloudTrail PutObject request. Removing the condition or adjusting the policy to not require it resolves the delivery failure.

Exam trap

The trap here is that candidates assume the condition s3:x-amz-acl is always required for CloudTrail delivery, but CloudTrail does not set this condition key by default; the policy must match the actual request attributes, and misconfiguring conditions is a common cause of silent delivery failures.

How to eliminate wrong answers

Option A is wrong because the Principal in a bucket policy for cross-account CloudTrail delivery must be the CloudTrail service principal (cloudtrail.amazonaws.com) of the member account, not the member account itself; however, the issue here is the condition key, not the principal. Option C is wrong because CloudTrail uses s3:PutObject to deliver logs, not s3:PutObjectAcl; the ACL is set via the x-amz-acl header in the PutObject request, not a separate API call. Option D is wrong because the resource ARN in a CloudTrail bucket policy does not require the source account ID in the path; the ARN format is arn:aws:s3:::bucket-name/optional-prefix/*, and the source account is identified via the Principal or condition keys like s3:SourceAccount.

1073
MCQeasy

A company wants to allow an EC2 instance to access an S3 bucket without exposing the instance to the internet. Which AWS service should be used to achieve this?

A.NAT Gateway
B.AWS Site-to-Site VPN
C.Internet Gateway
D.VPC Endpoint (Gateway type) for S3
AnswerD

A gateway VPC endpoint for S3 is the correct solution because it provides private connectivity from the VPC to S3 without requiring an Internet Gateway, NAT Gateway, or public IP address. It is implemented as a route-table entry using a prefix list for S3, directing traffic to the S3 service over the AWS private network. This endpoint does not incur per-hour or data-processing charges, and it keeps traffic entirely within AWS, satisfying both security and cost-efficiency requirements.

Why this answer

A VPC Endpoint (Gateway type) for S3 allows EC2 instances within a VPC to access S3 buckets privately using AWS's internal network, without traversing the internet. This is achieved by adding an endpoint route in the VPC route table that directs S3 traffic to the endpoint, which uses AWS's private infrastructure. It eliminates the need for an internet gateway, NAT gateway, or VPN connection, ensuring the instance remains isolated from the public internet.

Exam trap

The trap here is that candidates often confuse Gateway Endpoints with Interface Endpoints (powered by AWS PrivateLink) and incorrectly assume a NAT Gateway is required for private subnet access, but Gateway Endpoints are specifically designed for S3 and DynamoDB and do not require any additional infrastructure.

How to eliminate wrong answers

Option A is wrong because a NAT Gateway enables outbound internet access for private instances but still routes traffic through the internet, exposing the instance to potential risks and incurring data transfer costs. Option B is wrong because AWS Site-to-Site VPN connects on-premises networks to a VPC over the internet, but it does not provide private access to S3 from within the VPC without internet egress. Option C is wrong because an Internet Gateway allows bidirectional internet traffic, which would expose the EC2 instance to the internet, violating the requirement to keep it isolated.

1074
MCQhard

A company is using AWS KMS to encrypt data in Amazon S3. The security team discovers that an S3 bucket has a bucket policy that allows s3:PutObject without requiring encryption. What is the risk?

A.The KMS key can be used by unauthorized users
B.Data can be downloaded without authentication
C.Data in transit is not encrypted
D.Data can be uploaded without encryption at rest
AnswerD

If the policy permits PutObject without requiring the s3:x-amz-server-side-encryption header or a condition that forces encryption, clients can upload objects in plaintext to S3. Although the company uses KMS for encryption, that KMS key is only used when the upload explicitly requests SSE-KMS or the bucket has default encryption and the client doesn't override it. Without an explicit Deny for unencrypted uploads, some objects may remain unencrypted at rest, defeating the company's stated security intent.

Why this answer

When the bucket policy allows s3:PutObject without requiring encryption (e.g., x-amz-server-side-encryption header), data can be uploaded as plaintext and stored without encryption at rest, violating data protection requirements. Option A is incorrect because the KMS key usage is controlled by KMS policies, not the bucket policy. Option B is incorrect because authentication is required for PutObject, but encryption is not enforced.

Option C is incorrect because encryption in transit (TLS) is separate from encryption at rest.

1075
MCQmedium

A company is using AWS KMS to encrypt data at rest in Amazon S3. The security team wants to ensure that only a specific IAM role can decrypt objects in a particular S3 bucket. Which policy should be attached to the KMS key to enforce this restriction?

A.KMS grant that gives the IAM role decrypt permissions for the key
B.IAM policy attached to the role that allows kms:Decrypt for the key
C.S3 bucket policy that denies decrypt unless the requester is the specific IAM role
D.KMS key policy with a condition that the principal must be the specific IAM role
AnswerD

A KMS key policy that explicitly lists the IAM role as Principal, optionally with a condition like aws:PrincipalArn, correctly restricts kms:Decrypt to that role. Key policies are the authoritative control for a KMS key, and when they grant access to a specific principal, IAM policies are not required for that identity to decrypt. This is the recommended approach when the desired access is limited to a particular role and you want the key policy to be self-contained and auditable. Since the key policy is evaluated first and any IAM allow is subordinate to it, this configuration unambiguously enforces the intended restriction.

Why this answer

KMS key policies are the main mechanism to control access to KMS keys. By specifying the IAM role as the principal in a key policy statement for the kms:Decrypt action, only that role can decrypt using the key. Option A is incorrect because KMS grants are intended for temporary or cross-account access and are not the best practice for permanent control.

Option B is incorrect because IAM policies alone are not sufficient if the key policy does not allow the role; both policies must align. Option C is incorrect because S3 bucket policies control access to S3 operations, not KMS decryption permissions directly.

1076
MCQmedium

A company's security engineer is configuring a web application firewall (WAF) to protect a public-facing Application Load Balancer (ALB). The application is vulnerable to SQL injection attacks. Which AWS WAF rule should be used to mitigate this threat?

A.Add a rule to block cross-site scripting (XSS) attacks.
B.Add a rule from the AWS Managed Rules for SQL injection.
C.Add a rate-based rule to limit requests per IP.
D.Add a geographic match rule to block traffic from specific countries.
AnswerB

AWS WAF's AWSManagedRulesSQLiRuleSet is a managed rule group specifically designed to detect and block SQL injection attempts by inspecting request components such as query strings, body, and headers. It uses curated signatures and pattern-matching to catch syntactic SQLi payloads, and you can associate it with your web ACL on the Application Load Balancer, CloudFront, or API Gateway. Enabling this rule directly addresses the reported vulnerability.

Why this answer

AWS WAF includes managed rule groups specifically designed to detect and block SQL injection attacks by inspecting request parameters, URIs, and headers for malicious SQL patterns. This directly addresses the vulnerability described in the scenario, as SQL injection targets the application's database layer through crafted input.

Exam trap

The trap here is that candidates may confuse SQL injection with XSS because both involve input validation, but AWS WAF treats them as distinct managed rule groups with separate inspection logic and signatures.

How to eliminate wrong answers

Option A is wrong because cross-site scripting (XSS) rules target script injection into web pages, not SQL injection into database queries, and the two attack vectors use different payload patterns and inspection points. Option C is wrong because rate-based rules limit request volume per IP to mitigate DDoS or brute-force attacks, but they do not inspect request content for SQL injection signatures. Option D is wrong because geographic match rules block traffic based on country of origin, which is irrelevant to SQL injection payloads that can originate from any location.

1077
MCQeasy

A company wants to restrict access to an S3 bucket so that only requests from a specific VPC are allowed. Which policy should be used?

A.Security group assigned to the S3 bucket
B.IAM policy with aws:SourceIp condition
C.S3 bucket policy with aws:SourceVpc condition
D.Network ACL attached to the S3 bucket
AnswerC

An S3 bucket policy with an aws:SourceVpc condition is the correct way to restrict access to requests originating from a specific VPC. This condition evaluates the VPC ID of the requester, which is available when the request comes through a VPC gateway endpoint (service: s3). It is a resource-based policy, meaning it applies directly to the S3 bucket regardless of which IAM principal makes the request, and is a standard pattern for keeping buckets private to a particular VPC.

Why this answer

S3 bucket policies support the `aws:SourceVpc` condition key, which allows you to restrict access to requests originating from a specific VPC. This works by evaluating the VPC ID from which the request was made, using the source VPC information that AWS automatically includes in requests from VPC endpoints. No other mechanism (security groups, IAM source IP conditions, or network ACLs) can directly enforce VPC-level access control on S3.

Exam trap

The trap here is that candidates often confuse network-level controls (security groups, NACLs) with service-level controls (bucket policies) and assume that S3 can be protected like an EC2 instance, when in fact S3 only supports bucket policies and IAM policies for access control.

How to eliminate wrong answers

Option A is wrong because security groups are network-level firewalls for EC2 instances and cannot be assigned to S3 buckets; S3 is a managed service that does not support security group attachments. Option B is wrong because `aws:SourceIp` condition in IAM policies checks the originating IP address, not the VPC, so it cannot restrict access based on VPC membership and would not work for traffic from a VPC endpoint where the source IP is internal. Option D is wrong because network ACLs are stateless firewalls attached to subnets, not to S3 buckets, and they cannot control access to S3 at the bucket level.

1078
Multi-Selecteasy

Which TWO AWS services can be used to detect unauthorized access to an S3 bucket? (Select TWO.)

Select 2 answers
A.AWS WAF
B.AWS CloudTrail
C.Amazon GuardDuty
D.Amazon Macie
E.AWS Config
AnswersC, D

Amazon GuardDuty is a threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to continuously monitor for malicious activity. It ingests and analyzes AWS CloudTrail event logs, VPC flow logs, and DNS logs to identify suspicious patterns, including unusual S3 access, credential compromise, or unauthorized API usage. GuardDuty generates findings that indicate potential security threats, making it a direct and effective tool for detecting unauthorized access.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior across AWS accounts and workloads. It uses machine learning, anomaly detection, and integrated threat intelligence to analyze S3 data events (e.g., GetObject, PutObject) logged via CloudTrail management and data events, identifying suspicious patterns such as unusual access from a known malicious IP address or an anonymous user gaining access to an S3 bucket.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (a logging service) with a detection service, forgetting that CloudTrail only records events and does not analyze or alert on unauthorized access without additional services like GuardDuty or Amazon Detective.

1079
MCQhard

A company uses AWS CloudTrail to log all API calls. The security team notices that some expected log entries are missing for actions performed by an IAM role assumed by an EC2 instance. The instance has the required permissions. What is the MOST likely cause of the missing log entries?

A.The EC2 instance is in a VPC that has a VPC endpoint for CloudTrail, but the endpoint policy denies logging.
B.CloudTrail is not logging read-only API calls by default; the trail must be configured to log read events.
C.CloudTrail trail is not configured to log data events for EC2.
D.The IAM role used by the EC2 instance has a permissions boundary that excludes cloudtrail:PutLogEvents.
AnswerB

CloudTrail's management event selector controls whether read-only API calls are captured; if the trail is configured as 'Write-only', then actions like `ec2:DescribeInstances` are omitted. Even though the console default for a new trail is to log both read and write events, an existing trail may have been changed to write-only, and that setting is a common cause of missing read activity. To record these calls, the trail must be explicitly set to log 'Read' or 'All' management events.

Why this answer

CloudTrail logs management events by default, but the trail can be configured to log only write events or only read events. If the trail is set to log only write events, read-only API calls (such as Describe* or Get* actions) made by the IAM role will not be recorded. Since the missing log entries are likely read operations, the lack of read event logging would result in missing entries.

Option B correctly identifies this scenario.

Exam trap

The trap is to assume that missing logs are due to IAM permissions boundaries, when in fact CloudTrail logs all API calls regardless of the caller's permissions. Instead, the issue is often a misconfiguration of the trail's logging scope (e.g., read events not logged).

How to eliminate wrong answers

Option A is wrong because a VPC endpoint for CloudTrail is used to send log data from CloudTrail to S3, not to log API calls; the endpoint policy would affect delivery, not the logging of actions performed by the EC2 instance. Option B is wrong because CloudTrail logs all API calls (both read and write) by default when management events are enabled; read-only events are not excluded unless the trail is explicitly configured to log only write events. Option C is wrong because the missing log entries are for management API calls (e.g., EC2 actions), not data events (e.g., S3 object-level operations); data events are an additional configuration and are not required for logging standard EC2 API actions.

1080
MCQhard

A security engineer needs to monitor AWS API calls for potential unauthorized access. The engineer wants to be alerted when a specific IAM user performs a high-risk action like deleting a CloudTrail trail. What is the MOST efficient way to achieve this?

A.Configure CloudTrail to send logs to CloudWatch Logs and create a metric filter with an alarm.
B.Enable VPC Flow Logs and analyze with Elasticsearch.
C.Use Amazon Athena to query CloudTrail logs daily for the action.
D.Enable Amazon GuardDuty with a custom threat list.
E.Create a CloudWatch Events rule that matches the API call and sends an SNS notification.
AnswerE

A CloudWatch Events rule (now Amazon EventBridge) can define an event pattern that matches the exact API call, because CloudTrail delivers all AWS API events as CloudWatch Events in near real-time. When the event matches, the rule triggers an SNS topic to send a notification. This provides immediate, event-driven alerting without the delay of log aggregation, querying, or metric filters.

Why this answer

CloudWatch Events (now part of Amazon EventBridge) can directly capture AWS API calls from CloudTrail in near real-time. By creating a rule that matches the specific API call (e.g., `DeleteTrail`) from a specific IAM user, you can trigger an SNS notification instantly without the latency or cost of log shipping, metric filters, or periodic queries. This is the most efficient method for real-time alerting on specific API actions.

Exam trap

The trap here is that candidates often default to CloudTrail + CloudWatch Logs + metric filters (Option A) because it's a common pattern, but they overlook that CloudWatch Events provides a simpler, lower-latency, and more cost-effective solution for real-time alerting on specific API calls without the overhead of log ingestion and metric evaluation.

How to eliminate wrong answers

Option A is wrong because while CloudTrail logs to CloudWatch Logs with a metric filter and alarm can work, it introduces unnecessary latency and complexity (log delivery, metric evaluation) compared to a direct CloudWatch Events rule, making it less efficient for real-time alerting. Option B is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols), not AWS API calls like `DeleteTrail`, so they are completely irrelevant for monitoring IAM user actions. Option C is wrong because using Athena to query CloudTrail logs daily is a batch, retrospective approach that cannot provide real-time alerts; it is inefficient for immediate detection of unauthorized access.

Option D is wrong because Amazon GuardDuty with a custom threat list is designed to detect malicious activity based on threat intelligence and network anomalies, not to trigger alerts on specific API calls from a known IAM user; it does not natively support event-driven alerting for individual API actions.

1081
MCQhard

A Security Engineer is designing a network architecture for a multi-tier application. The web tier must be accessible from the internet, while the application tier should only be accessible from the web tier, and the database tier only from the application tier. All tiers are in the same VPC. Which configuration meets these requirements with minimal administrative overhead?

A.Use network ACLs with inbound rules that reference the prefix list of the previous tier's subnets.
B.Use network ACLs with inbound rules that allow traffic from the previous tier's subnet CIDR.
C.Use security groups with inbound rules that allow traffic from the previous tier's public IP addresses.
D.Use security groups with inbound rules that reference the security group of the previous tier.
AnswerD

Referencing the previous tier's security group as the source in an inbound rule is the correct approach because security groups are stateful and allow logical references to other security groups, not just IP addresses. When you assign an instance to the source security group, it automatically becomes allowed to reach the target tier, even if its IP address changes or new instances are added. This eliminates the need to manage CIDR blocks or public IPs and keeps security policies tightly aligned with architectural tiers. It is the AWS-recommended pattern for multi-tier security group design.

Why this answer

Security groups are stateful and can reference other security groups as a source in inbound rules, allowing traffic from any instance associated with the referenced security group regardless of IP address changes. This creates a logical dependency chain (web SG → app SG → db SG) that enforces the required tier-to-tier access with zero maintenance when instances scale or subnets change. Option D meets the requirement with minimal administrative overhead because security group references automatically adapt to dynamic environments.

Exam trap

The trap here is that candidates confuse network ACLs with security groups, assuming stateless ACLs can use logical references like security group IDs, or they overlook the administrative overhead of managing CIDR-based rules in dynamic architectures.

How to eliminate wrong answers

Option A is wrong because network ACLs are stateless and cannot reference prefix lists of subnets as a source in inbound rules; they only support CIDR blocks, IP ranges, or protocol/port numbers. Option B is wrong because network ACLs require explicit allow and return traffic rules (stateless), and using subnet CIDRs creates administrative overhead when subnets change or scale, plus they cannot dynamically follow instances that move between subnets. Option C is wrong because referencing public IP addresses is fragile (IPs can change with scaling or NAT), violates the principle of using private addressing within a VPC, and adds administrative burden to track and update IPs.

1082
MCQhard

A company uses AWS KMS to encrypt EBS volumes. They want to ensure that the key used for EBS encryption is not shared across different AWS accounts. Which feature should they use?

A.Use a CloudHSM custom key store.
B.Use the key's alias to restrict access.
C.Enable automatic key rotation.
D.Configure the key policy to deny access to any principal from another AWS account.
AnswerD

Configure the key policy with a Deny statement that uses the aws:PrincipalAccount condition to block any principal whose account ID does not match the expected account. Since the key policy is the authoritative resource-based policy for the KMS key, an explicit deny overrides any IAM permissions in another account and prevents cross-account EBS volume or snapshot sharing. This directly enforces the desired account boundary.

Why this answer

AWS KMS key policies can explicitly deny access to principals from other AWS accounts by using the `aws:SourceAccount` or `aws:SourceArn` condition keys, or by specifying a `Deny` statement with a condition that checks the account ID. This ensures that the KMS key used for EBS encryption cannot be used by any IAM principal or role from a different AWS account, preventing cross-account key sharing.

Exam trap

The trap here is that candidates often confuse key rotation (Option C) or aliases (Option B) with access control, or assume that CloudHSM (Option A) inherently isolates keys across accounts, when in fact only the key policy can enforce account-level restrictions.

How to eliminate wrong answers

Option A is wrong because CloudHSM custom key stores provide a hardware security module (HSM) for key storage but do not inherently restrict cross-account access; the key policy must still be configured to deny other accounts. Option B is wrong because a key's alias is simply a friendly name for the key and does not enforce any access control; aliases are not evaluated in authorization decisions. Option C is wrong because automatic key rotation only changes the cryptographic material of the key over time (typically annually) and has no effect on cross-account access permissions.

1083
Multi-Selectmedium

A company needs to enforce encryption in transit for all traffic between an Amazon EC2 instance and an Amazon RDS database. Which TWO steps should be taken?

Select 2 answers
A.Enable TLS on the RDS database and configure the database to require encrypted connections.
B.Configure security groups to allow traffic only on port 3306 (MySQL) or 5432 (PostgreSQL).
C.Set up a VPN connection between the EC2 instance and the RDS database.
D.Enable encryption at rest on the RDS instance.
E.Configure the application to connect using TLS/SSL.
AnswersA, E

Setting `require_secure_transport=1` on MySQL or `rds.force_ssl=1` on PostgreSQL in the RDS parameter group makes the server reject any non-TLS connection, explicitly enforcing encryption at the database layer. This server-side configuration is authoritative: only TLS-enabled clients with the appropriate CA certificate can connect, so plaintext traffic is refused regardless of client-side settings.

Why this answer

Option A is correct because enforcing encryption in transit for RDS requires enabling TLS on the DB instance and setting the parameter group so the database requires SSL/TLS connections (for example, MySQL's require_secure_transport or PostgreSQL's rds.force_ssl), which rejects unencrypted client sessions. Option E is correct because the client side must actually negotiate TLS: the application on the EC2 instance has to connect using SSL/TLS, typically by supplying the RDS CA certificate (rds-ca-rsa2048-g1 or similar) and using the appropriate driver parameters such as sslmode=require for PostgreSQL or ssl-mode=REQUIRED for MySQL. Option B is not correct because security groups only control network reachability on ports 3306/5432 and do not provide or enforce encryption.

Option C is not correct because a VPN encrypts traffic at the network layer between networks but is not the mechanism used to enforce TLS between an EC2 instance and an RDS endpoint, and RDS TLS is the supported approach. Option D is not correct because encryption at rest protects stored data via KMS and does not address data in transit between the EC2 instance and the database.

Exam trap

SCS-C02 often tests the distinction between encryption at rest (KMS, option D) and encryption in transit (TLS, options A/E); candidates who see 'encrypt' and grab the KMS/at-rest answer miss that the question specifies traffic between EC2 and RDS.

1084
MCQhard

A company uses AWS CloudFormation to deploy infrastructure. The security team wants to ensure that all CloudFormation stacks include a specific tag "Environment" with a value of "Production" or "Development". Which approach should be used?

A.Use AWS CloudFormation Guard to validate that the template includes the required tag with allowed values.
B.Apply an IAM policy that requires the tag on all CloudFormation actions.
C.Use AWS Config to detect and automatically remediate non-compliant stacks.
D.Create an SCP to deny CloudFormation stacks that do not have the required tag.
AnswerA

AWS CloudFormation Guard is a policy-as-code engine that parses and evaluates a template's structure before deployment, allowing you to assert that every resource includes a specific tag key with an allowed value. This validation is proactive, occurring in the CI/CD pipeline prior to stack creation, so non-compliant templates are rejected before any infrastructure exists. Guard rules are written in a simple DSL and can be enforced alongside other template checks, making it the only option that directly inspects the template content rather than relying on API request conditions.

Why this answer

AWS CloudFormation Guard (cfn-guard) is a policy-as-code tool that allows you to define rules to validate CloudFormation templates before they are used to create or update stacks. By writing a Guard rule that checks for the 'Environment' tag with allowed values of 'Production' or 'Development', you can enforce this requirement at the template level, preventing non-compliant stacks from being deployed. This approach is proactive, catching violations during the authoring or CI/CD pipeline stage rather than after deployment.

Exam trap

The trap here is that candidates confuse AWS CloudFormation Guard (a pre-deployment validation tool) with AWS Config (a post-deployment compliance service), or mistakenly believe that IAM policies or SCPs can enforce resource-level tags on CloudFormation stacks, when in fact they only control API request parameters.

How to eliminate wrong answers

Option B is wrong because IAM policies control who can perform actions (e.g., CreateStack) but cannot enforce specific tag keys or values on resources created by CloudFormation; IAM conditions like 'aws:RequestTag' only apply to tagging actions on the API call itself, not to tags on the resulting stack resources. Option C is wrong because AWS Config can detect non-compliant stacks after they are created and trigger remediation (e.g., via Systems Manager Automation), but it is reactive and does not prevent the initial deployment of non-compliant stacks. Option D is wrong because Service Control Policies (SCPs) are applied at the AWS Organizations level to restrict permissions for accounts, but they cannot enforce tags on CloudFormation stacks; SCPs can only deny API actions based on request parameters, not validate tags on resources after creation.

1085
Multi-Selecteasy

A company needs to protect data at rest in Amazon S3. Which THREE server-side encryption mechanisms can be used to encrypt objects stored in S3?

Select 3 answers
A.Server-Side Encryption with S3-Managed Keys (SSE-S3)
B.Server-Side Encryption with AWS KMS-Managed Keys (SSE-KMS)
C.Client-Side Encryption
D.Server-Side Encryption with IAM-Managed Keys (SSE-IAM)
E.Server-Side Encryption with Customer-Provided Keys (SSE-C)
AnswersA, B, E

SSE-S3 encrypts each object with a unique key, itself encrypted by a regularly rotated root key managed entirely by AWS, using AES-256. It satisfies data-at-rest protection with no key management overhead, applied by default to every uploaded object.

Why this answer

The question asks for server-side encryption mechanisms for S3 objects, and three options qualify. Option A, SSE-S3, is correct because Amazon S3 manages the encryption keys and applies AES-256 encryption to objects at rest, requiring only the x-amz-server-side-encryption: AES256 header. Option B, SSE-KMS, is correct because it uses AWS KMS customer master keys (CMKs) to generate and manage data keys, providing auditability via CloudTrail and granular key policies.

Option E, SSE-C, is correct because the customer supplies their own encryption key with each request, and S3 performs the encryption/decryption server-side without storing the key. Option C, Client-Side Encryption, is not a server-side mechanism since data is encrypted before it reaches S3. Option D, SSE-IAM, does not exist as an S3 encryption option; IAM manages permissions, not encryption keys.

Exam trap

SCS-C02 often tests whether candidates confuse client-side encryption with server-side options or invent non-existent mechanisms like SSE-IAM — the trap is picking 'client-side' as a server-side method or selecting a fabricated acronym.

1086
MCQmedium

A company uses AWS Organizations and has enabled GuardDuty in the management account. The security team wants to view GuardDuty findings for all member accounts from a single delegated administrator account. Which configuration step is required?

A.Enable GuardDuty in each member account and configure cross-account IAM roles to aggregate findings in the management account.
B.Enable GuardDuty only in the management account and share findings via CloudWatch Logs cross-account subscription.
C.Designate a delegated administrator account in Organizations, then enable GuardDuty in that account. GuardDuty will automatically aggregate findings from member accounts.
D.Enable GuardDuty in the management account and use CloudWatch cross-account dashboard to view findings from member accounts.
AnswerC

This is the recommended multi-account design. By designating a delegated administrator through AWS Organizations, the admin account can enable GuardDuty across every member account with a single action and receives a consolidated view of all findings in the GuardDuty console and via the API. The delegated administrator also gains centralized control to manage member accounts, apply trusted IP lists, configure threat list filters, and create suppression rules for the entire organization. This integration is natively built into GuardDuty, so no custom IAM roles or log-forwarding pipelines are required to aggregate findings.

Why this answer

AWS Organizations allows you to designate a delegated administrator account for GuardDuty, which can then manage and view findings from all member accounts without needing to enable GuardDuty individually in each account. Once the delegated administrator is set up, GuardDuty automatically aggregates findings from all member accounts in the organization, providing a single-pane-of-glass view for the security team.

Exam trap

The trap here is that candidates often assume GuardDuty must be enabled manually in each account or that CloudWatch cross-account features can aggregate GuardDuty findings, but the exam tests knowledge of the delegated administrator feature which is the native, automated solution for multi-account aggregation.

How to eliminate wrong answers

Option A is wrong because it describes a manual, cross-account IAM role approach that is unnecessary and less efficient; GuardDuty's delegated administrator feature eliminates the need for per-account enablement and custom aggregation. Option B is wrong because enabling GuardDuty only in the management account does not allow it to monitor member account activity; GuardDuty must be enabled in each account (or via the delegated administrator) to generate findings from those accounts, and CloudWatch Logs cross-account subscription is not the intended mechanism for aggregating GuardDuty findings. Option D is wrong because CloudWatch cross-account dashboards can visualize metrics but do not automatically aggregate GuardDuty findings from member accounts; GuardDuty findings are not natively pushed to CloudWatch as metrics without additional configuration, and the delegated administrator approach is the correct method.

1087
MCQmedium

Refer to the exhibit. A security engineer runs the above command and sees the security group configuration. Based on the output, which statement is correct?

A.The security group has no outbound rules.
B.The security group allows SSH access from any IP address.
C.The security group allows HTTP traffic from the internet.
D.The security group is associated with multiple EC2 instances.
AnswerC

The rule permits TCP port 80 from 0.0.0.0/0, so any host on the internet can reach the group's instances over unencrypted HTTP. That source range is the axis distinguishing public exposure from a restricted CIDR.

Why this answer

The security group output shows an inbound rule permitting HTTP (TCP port 80) from 0.0.0.0/0, which means any internet source can reach the instance on port 80. That is the definition of allowing HTTP traffic from the internet. The other statements either misread the output or describe attributes (outbound rules, instance associations) that are not determinable from the rule listing alone.

Exam trap

The trap is reading a security group rule listing and inferring properties that are not actually shown — such as outbound rules or instance associations — or confusing the port in the rule (80) with a different service (SSH/22).

How to eliminate wrong answers

Option A is wrong because security groups in AWS are stateful and include a default allow-all outbound rule unless it has been explicitly removed; the exhibit does not show the outbound rules, so claiming there are none is unsupported. Option B is wrong because the rule shown is for port 80 (HTTP), not port 22 (SSH); SSH access from any IP would require a separate inbound rule for TCP/22 from 0.0.0.0/0, which is not present in the output. Option D is wrong because a security group's rule listing does not reveal how many EC2 instances are associated with it; that information comes from the instance's network interface configuration, not the group's rule set.

1088
MCQmedium

A security engineer needs to detect and alert on suspicious API calls made from a compromised EC2 instance. The instance is associated with an IAM role that has permissions to call various AWS APIs. Which AWS service should the engineer use to monitor API calls and trigger alerts?

A.Amazon GuardDuty
B.AWS CloudTrail combined with Amazon CloudWatch Events
C.AWS Config
D.VPC Flow Logs
AnswerB

AWS CloudTrail records every API call made to AWS services, capturing details such as the identity, time, source IP, and request parameters. By sending these event logs to Amazon CloudWatch Events (or Amazon EventBridge), you can create custom rules to match specific API activity, such as unusual calls or attempts from unexpected regions, and trigger alerts via SNS or AWS Lambda. This combination gives you direct, real-time, and customizable detection and alerting on the API calls themselves, making it the correct choice.

Why this answer

AWS CloudTrail records all API calls made by or on behalf of the EC2 instance's IAM role. By sending these logs to Amazon CloudWatch Events (now Amazon EventBridge), you can create rules that match specific API actions (e.g., 'ec2:TerminateInstances') and trigger alerts via SNS, Lambda, or other targets. This combination provides real-time monitoring and alerting for suspicious API activity from a compromised instance.

Exam trap

The trap here is that candidates confuse GuardDuty's threat detection capabilities with the need for custom alerting on specific API calls, overlooking that CloudTrail combined with CloudWatch Events (EventBridge) is the correct service pair for granular, user-defined monitoring and alerting.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events to identify malicious behavior, but it does not natively trigger custom alerts for specific API calls; it generates its own findings. Option C is wrong because AWS Config is a resource inventory and compliance service that evaluates configuration changes against rules, not a real-time API monitoring and alerting service. Option D is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) but do not log API calls or IAM role activity, so they cannot detect suspicious API calls.

1089
MCQeasy

A company wants to encrypt data in transit between an Application Load Balancer (ALB) and its targets. Which configuration should be used?

A.Configure the ALB with a TCP listener and use Network Load Balancer.
B.Configure the ALB with an HTTPS listener and use HTTPS as the protocol for the target group.
C.Configure the ALB security group to allow only encrypted traffic.
D.Configure the ALB with an HTTP listener and use a security group to enforce encryption.
AnswerB

Configuring an HTTPS listener and an HTTPS target group encrypts traffic at both hops, including the ALB-to-target leg. This satisfies the requirement for in-transit encryption between load balancer and targets, since the default HTTP target protocol leaves that segment unencrypted.

Why this answer

To encrypt data in transit between an ALB and its targets, you must configure the ALB listener to use HTTPS and set the target group protocol to HTTPS. This ensures that traffic from the ALB to the targets is encrypted using TLS. The ALB terminates the client-side TLS and establishes a new TLS connection to the targets.

Exam trap

SCS-C02 often tests the difference between encryption in transit and network security controls, and candidates may incorrectly assume that security groups can enforce encryption or confuse ALB with NLB capabilities.

How to eliminate wrong answers

Option A is wrong because ALBs do not support TCP listeners; TCP listeners are for Network Load Balancers (NLB). Also, using an NLB would not meet the requirement of an ALB. Option C is wrong because security groups control network access, not encryption; they cannot enforce encryption.

Option D is wrong because an HTTP listener does not encrypt traffic, and security groups cannot enforce encryption; they only filter traffic based on IP, port, and protocol.

1090
MCQhard

A company is designing a data protection strategy for sensitive data stored in Amazon S3. Compliance requirements mandate that all data be encrypted at rest using customer-provided keys (SSE-C). Which solution meets the requirements with minimal operational overhead?

A.Use server-side encryption with Amazon S3 managed keys (SSE-S3) and enable bucket versioning.
B.Use client-side encryption with the AWS Encryption SDK and store keys in the application configuration.
C.Use server-side encryption with customer-provided keys (SSE-C) and store the keys in AWS Secrets Manager.
D.Use server-side encryption with AWS KMS managed keys (SSE-KMS) and enable automatic key rotation.
AnswerC

SSE-C allows you to provide your own encryption keys in S3 API request headers, and S3 uses them for AES-256 encryption/decryption but never stores the key material, giving you full control over the key lifecycle. Storing those keys in AWS Secrets Manager adds secure storage, centralizes access control, and enables programmatic retrieval for uploads/downloads while keeping the key material customer-owned. This directly satisfies a bring-your-own-key requirement without the overhead of client-side encryption, though you must use HTTPS and supply the key on every request.

Why this answer

Server-side encryption with customer-provided keys (SSE-C) allows the customer to supply their own encryption keys while AWS manages the encryption/decryption process, meeting compliance requirements with minimal operational overhead. Storing the keys in AWS Secrets Manager adds convenience and security. Option A is incorrect because SSE-S3 uses AWS-managed keys, not customer-provided keys.

Option B is incorrect because client-side encryption with the AWS Encryption SDK requires the application to handle encryption, increasing overhead and complexity, and it does not use SSE-C. Option D is incorrect because SSE-KMS uses AWS KMS managed keys, not customer-provided keys, even if key rotation is enabled.

1091
MCQhard

A company has a CloudTrail trail that logs management events for all regions. The security team notices that some S3 data events are not being logged. How should the team enable logging for all S3 data events?

A.Update the existing CloudTrail trail to include data events for S3
B.Create a new CloudTrail trail that logs only data events
C.Use Amazon GuardDuty to monitor S3 access
D.Enable S3 server access logging on each bucket
AnswerA

CloudTrail trails can be updated at any time to include data events for specific S3 buckets or all buckets, capturing object-level operations such as GetObject, PutObject, and DeleteObject in addition to the existing management events. This consolidates all API activity into a single audit stream, avoids the operational overhead of managing multiple trails, and is the direct, recommended way to meet the requirement for S3 access logging within CloudTrail.

Why this answer

CloudTrail trails can be configured to log data events for S3 in addition to management events. By updating the existing trail to include S3 data events (e.g., GetObject, PutObject), the security team can capture all object-level API activity without creating a separate trail. This ensures comprehensive logging while maintaining the existing management event logging for all regions.

Exam trap

The trap here is that candidates may think S3 server access logging (Option D) is equivalent to CloudTrail data events, but server access logs are separate, bucket-specific logs that lack the centralized management, API-level detail, and integration with CloudTrail Insights or other monitoring services.

How to eliminate wrong answers

Option B is wrong because creating a new CloudTrail trail that logs only data events would duplicate logging infrastructure and incur additional costs, but the existing trail already logs management events; the correct approach is to modify the existing trail to include data events. Option C is wrong because Amazon GuardDuty is a threat detection service that monitors for malicious activity using CloudTrail logs, VPC Flow Logs, and DNS logs, but it does not enable or configure CloudTrail data event logging itself. Option D is wrong because S3 server access logs are bucket-level logs that record requests made to the bucket, but they are not integrated with CloudTrail and do not provide the centralized, API-level data event logging that CloudTrail offers; they also require enabling on each bucket individually and do not support the same filtering or integration with other AWS services.

1092
MCQmedium

A company uses AWS Organizations with multiple accounts and wants to ensure that all newly created S3 buckets have encryption enabled. The Security team needs a solution that automatically remediates non-compliant buckets without manual intervention. What should they do?

A.Apply a service control policy (SCP) that denies the s3:PutBucketPublicAccessBlock and s3:PutBucketEncryption actions unless the bucket has encryption enabled.
B.Use an S3 bucket policy that denies PutObject unless the request includes the x-amz-server-side-encryption header.
C.Enable AWS Config with the s3-bucket-server-side-encryption-enabled rule and set up automatic remediation using Systems Manager Automation.
D.Create an IAM role with permissions to enforce encryption and attach it to all accounts in the organization.
AnswerC

AWS Config's managed rule s3-bucket-server-side-encryption-enabled continuously evaluates each bucket and flags any bucket whose default encryption setting is disabled. When non-compliance is detected, the rule can trigger an SSM Automation remediation—typically the AWS-EnableS3BucketEncryption document—which automatically applies the appropriate SSE-S3 or SSE-KMS default encryption to the bucket. This pairing of continuous detection and automated remediation provides an enforceable, organization-wide corrective control that directly satisfies the encryption requirement.

Why this answer

AWS Config can continuously evaluate S3 buckets against the s3-bucket-server-side-encryption-enabled rule and automatically remediate non-compliant buckets using Systems Manager Automation, requiring no manual intervention. Option A is incorrect because a service control policy (SCP) cannot enforce encryption on bucket creation; the described SCP is circular and unenforceable since it denies s3:PutBucketEncryption unless encryption is already enabled, which is impossible to satisfy at creation time.

Exam trap

Candidates often think SCPs can enforce encryption on resource creation, but SCPs only control API permissions, not resource configuration. The correct approach is reactive remediation via AWS Config and automation, not proactive denial through SCPs.

How to eliminate wrong answers

Option B is wrong because an S3 bucket policy that denies PutObject unless the x-amz-server-side-encryption header is present only enforces encryption on objects uploaded to existing buckets, not on the bucket creation itself, and does not prevent creation of unencrypted buckets. Option C is wrong because AWS Config with the s3-bucket-server-side-encryption-enabled rule can detect non-compliant buckets, but automatic remediation using Systems Manager Automation requires manual setup and may not prevent creation in real time; it is reactive rather than proactive. Option D is wrong because creating an IAM role with permissions to enforce encryption and attaching it to all accounts does not automatically enforce encryption on new buckets; it only provides the capability, and users could still create buckets without encryption if they have other permissions.

1093
MCQhard

A company uses Amazon GuardDuty to monitor for threats. The security team receives a high-severity finding: 'UnauthorizedAccess:EC2/SSHBruteForce'. The finding indicates a single EC2 instance with a public IP is receiving SSH connection attempts from multiple external IPs. The instance is part of an Auto Scaling group and is fronted by an Application Load Balancer (ALB). The security team wants to block the attacking IPs without disrupting legitimate traffic. What is the MOST effective approach?

A.Stop the EC2 instance and launch a new one in a different subnet.
B.Modify the security group of the EC2 instance to deny inbound SSH from the attacking IPs.
C.Create a network ACL rule on the subnet to deny inbound traffic from the attacking IPs.
D.Configure AWS WAF on the ALB to block the attacking IPs using an IP set rule.
AnswerB

Modifying the security group to deny inbound SSH from the attacking IPs directly blocks the SSH brute force attempts at the instance level. Since the instance uses a security group that can be applied to all instances in the Auto Scaling group, this approach is effective and persistent.

Why this answer

Modifying the security group of the EC2 instance to deny inbound SSH from the attacking IPs directly blocks the SSH brute force attempts at the instance level. Since the instance is part of an Auto Scaling group, security group modifications will apply to all instances launched with that security group, and updates are immediate. Option D (AWS WAF on ALB) is ineffective because WAF only inspects HTTP/HTTPS traffic at Layer 7, while SSH traffic operates at Layer 4 and does not pass through the ALB; the ALB only handles HTTP/HTTPS, not SSH.

The attackers are targeting the instance's public IP directly over SSH, not through the ALB. Therefore, WAF cannot block SSH traffic. Option A (stop instance) is disruptive and unnecessary.

Option C (network ACL) would block traffic at the subnet level but would affect all instances in the subnet and is less granular than a security group.

Exam trap

The trap is that candidates assume AWS WAF can block any type of traffic when attached to an ALB, but WAF only inspects HTTP/HTTPS requests at Layer 7, not SSH traffic at Layer 4. The correct approach is to use a security group to block SSH at the instance level.

How to eliminate wrong answers

Option A is wrong because stopping the EC2 instance and launching a new one in a different subnet does not block the attacking IPs; it only changes the instance's IP address, and the attackers can still target the new instance. Option B is wrong because modifying the security group to deny inbound SSH from the attacking IPs would block SSH from those IPs but would also disrupt legitimate SSH traffic from those IPs if any existed, and it does not address the fact that the instance is behind an ALB where SSH traffic typically bypasses the ALB; moreover, security group rules are stateful and cannot block traffic at the application layer. Option C is wrong because creating a network ACL rule to deny inbound traffic from the attacking IPs would block all traffic from those IPs at the subnet level, including legitimate traffic (e.g., HTTP/HTTPS via the ALB), and network ACLs are stateless, requiring separate inbound and outbound rules, which complicates management and can disrupt legitimate traffic.

1094
MCQeasy

A company runs a web application on EC2 instances in an Auto Scaling group across two Availability Zones. The instances are behind an Application Load Balancer. The security team wants to ensure that only the ALB can send traffic to the instances. The instances are in a security group named 'app-sg'. Currently, 'app-sg' has an inbound rule allowing HTTP traffic from 0.0.0.0/0. The team wants to restrict access to only the ALB's security group. The ALB is in a security group named 'alb-sg'. Which course of action should the security engineer take to meet the requirement with minimal disruption?

A.Modify the inbound rule of 'app-sg' to allow HTTP traffic from the private IP addresses of the ALB nodes.
B.Modify the inbound rule of 'app-sg' to allow HTTPS traffic from 0.0.0.0/0 and remove the HTTP rule.
C.Modify the inbound rule of 'app-sg' to allow HTTP traffic from the ALB's elastic network interface (ENI).
D.Modify the inbound rule of 'app-sg' to allow HTTP traffic from security group 'alb-sg'.
AnswerD

Setting the source of the app-sg inbound rule to the alb-sg security group creates an identity-based dependency: only traffic originating from network interfaces associated with alb-sg is permitted. This automatically accommodates ALB node IP changes and scale events because AWS resolves the security group relationship in the VPC. It is a best practice for internal load-balanced architectures and is preferred over CIDR/ENI references since it remains valid across AZs and lifecycle changes.

Why this answer

Security groups can reference each other by ID, allowing traffic from any instance associated with the source security group (alb-sg) without needing to know the ALB's IP addresses. This ensures that only the ALB can send HTTP traffic to the EC2 instances, as the rule dynamically applies to all ALB nodes across Availability Zones. It also minimizes disruption because no IP changes are required, and the rule automatically scales with the ALB.

Exam trap

The trap here is that candidates may think they need to use the ALB's private IP addresses or ENI details, but AWS security groups support referencing other security groups by ID, which is the correct and scalable method for this use case.

How to eliminate wrong answers

Option A is wrong because ALB nodes use elastic network interfaces (ENIs) with private IPs that can change during scaling or replacement, making this approach brittle and requiring constant updates; it also violates the principle of using security group references for dynamic environments. Option B is wrong because allowing HTTPS from 0.0.0.0/0 still permits traffic from any source, failing to restrict access to only the ALB, and removing the HTTP rule does not address the requirement. Option C is wrong because referencing an ALB's ENI is not a valid security group rule source; security groups can only reference other security groups or CIDR blocks, not specific ENIs.

1095
MCQeasy

A company's security policy requires that all IAM users must use strong passwords. Which IAM feature should be used to enforce this requirement?

A.AWS Organizations
B.AWS Key Management Service (AWS KMS)
C.AWS CloudTrail
D.IAM password policy
AnswerD

The IAM password policy is the account-level setting designed to enforce password requirements for all IAM users. It lets you require minimum length, uppercase/lowercase letters, numbers, non-alphanumeric characters, password expiration, and prevent password reuse, and users see the requirements during sign-in. Because this policy is applied natively by the IAM service during authentication and password changes, it exactly matches the security policy described.

Why this answer

The IAM password policy is the feature that enforces password requirements such as minimum length, complexity (uppercase, lowercase, numbers, symbols), reuse prevention, and expiration for IAM users. It is applied at the account level and directly addresses the requirement for strong passwords. Other services like AWS Organizations, KMS, and CloudTrail do not manage IAM user password rules.

Exam trap

SCS-C02 often tests the misconception that AWS Organizations or KMS can enforce IAM password rules — candidates must remember the IAM password policy is the specific feature for this requirement.

How to eliminate wrong answers

Option A is wrong because AWS Organizations manages multiple accounts, SCPs, and consolidated billing — it does not enforce IAM user password policies. Option B is wrong because KMS is a key management service for encryption, not password policy enforcement. Option C is wrong because CloudTrail logs API activity for auditing, not password enforcement.

1096
MCQhard

An organization has a requirement to retain all security logs for at least 7 years for compliance. The logs are stored in Amazon S3 and are rarely accessed. Which storage class is the MOST cost-effective for this retention period?

A.S3 Glacier Deep Archive
B.S3 Standard
C.S3 One Zone-IA
D.S3 Intelligent-Tiering
AnswerA

S3 Glacier Deep Archive is the correct choice for 7-year security log retention because it provides the lowest storage cost of any S3 storage class, designed specifically for long-term, rarely accessed archival data. It offers 99.999999999% durability across multiple Availability Zones and a standard retrieval time of 12 hours, which is acceptable for compliance-oriented logs that are seldom retrieved. The one-time retrieval fee and minimum 180-day storage period are outweighed by the dramatic per-GB savings over the full 7-year cycle.

Why this answer

S3 Glacier Deep Archive is the most cost-effective storage class for data that is rarely accessed and must be retained for 7 years. It offers the lowest storage cost among S3 classes, designed specifically for long-term retention of archival data where retrieval times of 12 hours are acceptable. The compliance requirement for 7-year retention aligns perfectly with Glacier Deep Archive's intended use case, minimizing costs while meeting the retention mandate.

Exam trap

The trap here is that candidates often choose S3 Intelligent-Tiering thinking it automatically optimizes costs for long-term storage, but they overlook the per-object monitoring fee and the fact that for data that is never accessed after initial storage, Glacier Deep Archive is cheaper because it has no automation overhead.

How to eliminate wrong answers

Option B (S3 Standard) is wrong because it is designed for frequently accessed data with millisecond retrieval, incurring high storage costs over 7 years for rarely accessed logs, making it cost-ineffective. Option C (S3 One Zone-IA) is wrong because it stores data in a single Availability Zone, which does not meet the durability and availability requirements for compliance logs that must be retained for 7 years; it also has higher storage costs than Glacier Deep Archive for long-term archival. Option D (S3 Intelligent-Tiering) is wrong because it is optimized for data with unknown or changing access patterns, automatically moving objects between tiers, but it incurs monitoring and automation fees that are unnecessary for logs that are rarely accessed and have a fixed retention period, making it less cost-effective than Glacier Deep Archive.

1097
MCQmedium

A company is using Amazon GuardDuty to monitor for malicious activity. The security team wants to automatically isolate an EC2 instance that is flagged for outbound communication with a known malicious IP address. Which approach is the most efficient and scalable?

A.Use a CloudWatch Alarm to directly invoke a Lambda function to isolate the instance.
B.Use AWS Config to automatically terminate the instance when a GuardDuty finding is reported.
C.Use Amazon EventBridge to invoke an AWS Lambda function that modifies the instance's security group.
D.Create a CloudWatch alarm on GuardDuty findings and modify the subnet's network ACL to block the traffic.
AnswerC

GuardDuty publishes every finding as an event to Amazon EventBridge, where a rule with an event pattern matching specific finding types and severities can route to a Lambda function. That function can call ec2:RevokeSecurityGroupIngress or ec2:ModifyNetworkInterfaceAttribute to swap the instance onto a dedicated quarantine security group, removing internet-facing ingress rules. This approach is targeted to the exact resource in the finding, reversible, and scales across many findings without affecting the rest of the subnet.

Why this answer

Amazon EventBridge can directly capture GuardDuty findings as events and trigger an AWS Lambda function to modify the instance's security group, revoking outbound access to the malicious IP. This approach is event-driven, serverless, and scales automatically without polling or manual intervention, making it the most efficient and scalable solution.

Exam trap

The trap here is that candidates may confuse CloudWatch Alarms with EventBridge rules, not realizing that EventBridge provides native, real-time event filtering and direct Lambda invocation without the polling or metric-based delays inherent in CloudWatch Alarms.

How to eliminate wrong answers

Option A is wrong because CloudWatch Alarms cannot directly invoke Lambda functions; they can only trigger actions like SNS, Auto Scaling, or EC2 actions, and would require an additional intermediary (e.g., SNS to Lambda) adding latency and complexity. Option B is wrong because AWS Config is a configuration auditing and compliance service, not a real-time event-driven response system; it cannot automatically terminate instances based on GuardDuty findings, and termination is an overly destructive action that may not be appropriate for isolation. Option D is wrong because modifying a subnet's network ACL (NACL) is stateless and affects all instances in the subnet, not just the flagged instance, and CloudWatch alarms on GuardDuty findings would require custom metric filters and lack direct integration with NACL modifications.

1098
Multi-Selectmedium

A security engineer needs to implement a solution to detect and alert on suspicious API calls in an AWS account. Which TWO AWS services should be integrated to achieve this? (Choose two.)

Select 2 answers
A.AWS Config
B.Amazon Inspector
C.AWS CloudTrail
D.AWS Trusted Advisor
E.Amazon GuardDuty
AnswersC, E

AWS CloudTrail is an audit service that continuously records all API activity in an AWS account, capturing the calling identity, source IP address, timestamp, request parameters, and response elements. CloudTrail itself is not a threat-detection engine—it simply produces the raw audit logs—but it is a required and correct component because it provides the management-event data that GuardDuty consumes to detect suspicious API calls. Enabling CloudTrail is the necessary first step, and when paired with GuardDuty's analysis engine, it becomes part of a complete detection solution.

Why this answer

AWS CloudTrail (C) is correct because it records API activity in the account as management and data events, providing the raw log source needed to detect suspicious API calls. Amazon GuardDuty (E) is correct because it continuously analyzes CloudTrail management events (along with VPC Flow Logs and DNS logs) using threat intelligence and machine learning to detect and alert on suspicious API activity. Together, CloudTrail supplies the API call records and GuardDuty generates the findings and alerts.

AWS Config (A) evaluates resource configuration compliance rather than detecting suspicious API behavior, Amazon Inspector (B) scans workloads for software vulnerabilities and network exposure, and AWS Trusted Advisor (D) provides best-practice recommendations, so none of these fulfill the detection-and-alert requirement.

Exam trap

SCS-C02 often tests the pairing of CloudTrail (the data source) with GuardDuty (the analyzer), tempting candidates to pick AWS Config or Inspector, which address compliance and vulnerability scanning rather than threat detection.

1099
MCQmedium

A security engineer needs to analyze large volumes of VPC Flow Logs stored in Amazon S3 to identify anomalous traffic patterns. Which approach is MOST cost-effective and scalable?

A.Use AWS Glue to catalog and query the logs.
B.Download the logs to an EC2 instance and use grep commands.
C.Use Amazon Athena with partitioned data in S3.
D.Use Amazon QuickSight to directly query the logs.
AnswerC

Amazon Athena is serverless and lets you run standard SQL directly against VPC Flow Logs stored in S3, requiring no ETL or infrastructure to manage. By partitioning the logs in S3—for example by year/month/day or by hour—you drastically reduce the amount of data scanned per query, and Athena charges per byte scanned, so partitioning cuts costs substantially. Athena is built on Presto, supports filtering, grouping, and joins, and is well suited for ad-hoc security investigations over large volumes of network traffic.

Why this answer

Amazon Athena is the most cost-effective and scalable solution for querying large volumes of VPC Flow Logs stored in S3 because it uses a serverless, pay-per-query model with no infrastructure to manage. By partitioning the data (e.g., by date or region), Athena minimizes the amount of data scanned per query, directly reducing costs while enabling complex SQL-based analysis for anomaly detection.

Exam trap

The trap here is that candidates may confuse AWS Glue's cataloging role with a query engine, or assume QuickSight can directly query S3 without an intermediate service, leading them to overlook Athena's serverless, pay-per-query model as the optimal choice for scalable log analysis.

How to eliminate wrong answers

Option A is wrong because AWS Glue is primarily a metadata catalog and ETL service, not optimized for direct ad-hoc querying of large datasets; using Glue for this purpose would incur unnecessary costs for crawlers and ETL jobs without providing the scalable, on-demand querying that Athena offers. Option B is wrong because downloading logs to an EC2 instance and using grep is not scalable for large volumes, introduces egress costs from S3, requires managing EC2 resources, and cannot efficiently handle complex analytical queries across terabytes of data. Option D is wrong because Amazon QuickSight is a business intelligence visualization tool that relies on a query engine like Athena or a database; directly querying S3 with QuickSight is not supported—it would need Athena as an intermediary, making the suggestion technically incorrect and inefficient.

1100
MCQeasy

A company has an S3 bucket that contains sensitive data. The security team wants to ensure that all access to the bucket is encrypted in transit. Which policy should be attached to the bucket to enforce this?

A.Configure a bucket policy that denies requests that do not include the x-amz-server-side-encryption header.
B.Attach a bucket policy that denies requests when aws:SecureTransport is false.
C.Enable default encryption on the bucket using SSE-S3.
D.Use Amazon CloudFront to serve the content and require HTTPS.
AnswerB

The aws:SecureTransport condition key is a boolean that is true only when the request is made over SSL/TLS. By attaching a bucket policy with a Deny effect when aws:SecureTransport is false, the bucket rejects every HTTP request and only allows HTTPS requests. This enforces encryption in transit for all S3 operations, including direct API calls from any client or SDK, making it the correct solution.

Why this answer

The `aws:SecureTransport` condition key in an S3 bucket policy evaluates whether the request was sent over HTTPS (TLS). By attaching a bucket policy that denies access when `aws:SecureTransport` is false, the security team enforces that all access to the bucket must be encrypted in transit, blocking any HTTP requests.

Exam trap

The trap here is confusing encryption in transit (HTTPS/TLS) with encryption at rest (SSE headers or default encryption), leading candidates to pick options that enforce server-side encryption instead of transport-layer security.

How to eliminate wrong answers

Option A is wrong because the `x-amz-server-side-encryption` header is used to enforce encryption at rest (server-side encryption), not encryption in transit; it does not control whether the connection uses HTTPS. Option C is wrong because enabling default encryption on the bucket (e.g., SSE-S3) only encrypts objects at rest in S3, not the data in transit between the client and S3. Option D is wrong because while CloudFront with HTTPS can enforce encryption in transit for content delivery, it does not apply to direct S3 bucket access via the S3 API or other endpoints; the bucket policy itself must enforce the condition.

1101
Multi-Selectmedium

A company uses AWS Organizations with multiple accounts. The security team wants to ensure that all API calls in the organization are logged and retained for at least one year. Which AWS services or features should be used to meet these requirements? (Choose TWO.)

Select 2 answers
A.Amazon GuardDuty with threat detection enabled.
B.AWS Config with recording enabled for all resources.
C.Amazon S3 lifecycle policy to transition logs to S3 Glacier after one year.
D.VPC Flow Logs for all VPCs.
E.AWS CloudTrail with organization trail.
AnswersC, E

An S3 lifecycle policy can transition delivered log objects from frequently accessed storage classes to S3 Glacier after one year, preserving the logs for long-term audit needs while reducing cost. This is a correct component for the retention half of the requirement, provided that a delivery mechanism such as an organization CloudTrail trail first places the logs into the S3 bucket. It does not record any API activity by itself, so it is complementary to CloudTrail rather than a replacement.

Why this answer

An Amazon S3 lifecycle policy can automatically transition CloudTrail log objects from S3 Standard to S3 Glacier after one year, meeting the retention requirement cost-effectively. Option E is correct because AWS CloudTrail with an organization trail logs all API calls across all accounts in the AWS Organization, ensuring comprehensive logging.

Exam trap

The trap here is that candidates often confuse AWS Config (which records resource configuration changes) with CloudTrail (which records API calls), leading them to select Config as a logging solution for API activity.

1102
MCQhard

Refer to the exhibit. A security engineer reviews IAM permissions for the 'admin' user. The user is a member of the 'Administrators' group, which has the 'AdministratorAccess' managed policy attached. Additionally, the user has an inline policy named 'AllowSSH'. The engineer wants to ensure that the user can only start SSM sessions on instances with the tag 'SSH: enabled'. However, the user can still start sessions on any instance. What is the most likely reason?

A.The inline policy does not include 'ec2:DescribeInstances' for the SSM session, so it cannot start sessions.
B.The condition 'aws:ResourceTag/SSH' should be 'aws:RequestTag/SSH' to check the request tag.
C.The inline policy uses 'Allow' instead of 'Deny' for instances without the tag, so it does not restrict access.
D.The inline policy 'AllowSSH' is not effective because it is overridden by the group policy 'AdministratorAccess'.
AnswerC

The inline policy allows SSM StartSession only on tagged instances, but since the group policy allows all actions, the effective permission is still 'Allow' on all instances. To restrict, a 'Deny' statement is needed for instances without the tag.

Why this answer

In AWS IAM, an explicit Allow in any attached policy grants access — there is no 'most restrictive wins' rule for Allow statements. Because the user already has AdministratorAccess (which allows ssm:StartSession on *), the inline AllowSSH policy's Allow statement cannot restrict anything; it only adds permissions. To restrict the user to tagged instances, the inline policy must contain an explicit Deny for ssm:StartSession when the resource tag condition is not met (or the AdministratorAccess policy must be removed/scoped).

Exam trap

SCS-C02 often tests the misconception that a more specific Allow policy can restrict a broader Allow — in IAM, only an explicit Deny can override an Allow, so candidates who pick 'policy precedence' answers fall for this trap.

How to eliminate wrong answers

Option A is wrong because ec2:DescribeInstances is not required to call ssm:StartSession — SSM session authorization is evaluated against the managed instance resource ARN, not EC2 describe permissions. Option B is wrong because aws:ResourceTag/SSH is the correct condition key for evaluating the tag on the target managed instance; aws:RequestTag is used when tagging resources during creation, not when starting a session. Option D is wrong because inline policies are not 'overridden' by managed policies — IAM evaluates the union of all policies, and any Allow grants access; the issue is the absence of a Deny, not policy precedence.

1103
Multi-Selecteasy

Which TWO AWS services can be used to monitor network traffic for malicious activity? (Select TWO.)

Select 2 answers
A.AWS Network Firewall
B.Amazon GuardDuty
C.AWS Shield
D.AWS WAF
E.Amazon Inspector
AnswersA, B

AWS Network Firewall inspects inbound, outbound and east-west traffic using Suricata-compatible stateful rules, enabling signature-based detection of malicious activity across VPC subnets. It satisfies the monitoring requirement by logging alerts and flow data to CloudWatch, S3 or Kinesis Firehose, giving the visibility needed to identify threats rather than merely filtering them.

Why this answer

AWS Network Firewall (A) is correct because it is a managed, stateful network firewall and intrusion prevention service that inspects VPC traffic (including VPC-to-VPC, egress, and ingress) and can alert on or block malicious activity using Suricata-compatible rules and managed threat signatures. Amazon GuardDuty (B) is correct because it continuously monitors network traffic and account activity—analyzing VPC Flow Logs, DNS logs, and CloudTrail events—to detect malicious or unauthorized behavior such as crypto-mining, port scanning, and communication with known malicious IPs. AWS Shield (C) is not the right answer because it is a managed DDoS protection service that mitigates volumetric and layer 3/4 attacks but does not provide general network traffic monitoring for malicious activity.

AWS WAF (D) is not the right answer because it filters HTTP(S) requests at layer 7 against web exploits like SQL injection and XSS, not network traffic monitoring. Amazon Inspector (E) is not the right answer because it is a vulnerability management service that scans EC2 instances, container images, and Lambda functions for software vulnerabilities and unintended network exposure, rather than monitoring live network traffic.

Exam trap

The trap here is that candidates confuse AWS Shield (DDoS protection) or AWS WAF (web application firewall) with network traffic monitoring, but neither performs deep packet inspection or threat detection for general malicious network activity beyond their specific scopes.

1104
MCQeasy

A company has a requirement that all S3 buckets must block public access. The security engineer needs to continuously monitor for compliance and automatically remediate any noncompliant buckets. Which combination of AWS services should the engineer use?

A.Amazon GuardDuty and AWS Security Hub
B.AWS Config and AWS Lambda (or SSM Automation)
C.AWS Organizations SCPs and AWS CloudTrail
D.AWS Trusted Advisor and Amazon SNS
AnswerB

AWS Config rules continuously evaluate bucket public access settings and flag noncompliant resources, triggering remediation. Lambda or SSM Automation then applies the block public access configuration automatically, satisfying both continuous monitoring and automatic remediation requirements.

Why this answer

AWS Config continuously evaluates S3 bucket configurations against a managed rule such as 's3-bucket-public-read-prohibited' or 's3-bucket-level-public-access-prohibited', detecting any bucket that becomes noncompliant. Config can then trigger an EventBridge event that invokes a Lambda function or SSM Automation document to re-apply the Block Public Access settings, delivering both continuous monitoring and automatic remediation. This is the canonical AWS pattern for compliance enforcement.

Exam trap

SCS-C02 often tests the distinction between detection-only services (GuardDuty, Security Hub, Trusted Advisor) and the Config + Lambda/SSM Automation pattern that provides both continuous compliance evaluation and automated remediation.

How to eliminate wrong answers

Option A is wrong because GuardDuty is a threat-detection service that analyzes logs for malicious activity and Security Hub aggregates findings — neither continuously evaluates resource configuration state nor performs remediation. Option C is wrong because SCPs are preventive guardrails applied at the Organizations level and CloudTrail only records API activity; SCPs cannot retroactively detect or remediate an already-misconfigured bucket, and CloudTrail does not evaluate compliance. Option D is wrong because Trusted Advisor provides periodic best-practice checks (not continuous configuration evaluation) and SNS only delivers notifications — it cannot remediate.

1105
MCQhard

A company uses AWS Organizations with multiple accounts. The security team needs to ensure that all accounts have CloudTrail enabled and that logs are delivered to a centralized S3 bucket in the management account. Which solution meets these requirements?

A.Write a script that runs in each account using AWS Lambda to enable CloudTrail and point to the central bucket.
B.Use AWS Config rules in each account to check CloudTrail status and remediate via Lambda.
C.Use AWS CloudTrail with Organizations to create an organization trail that logs all accounts to the central bucket.
D.Create an IAM role that each account assumes to enable CloudTrail and log to the central bucket.
AnswerC

Creating an organization trail in the management account (with isOrganizationTrail set to true) automatically provisions CloudTrail for every current and future member account in AWS Organizations, delivering logs to a single central S3 bucket. Member account users—even those with administrative rights—cannot disable or alter the trail because ownership rests with the management account, eliminating the need for per-account configuration or remediation. This native, centralized governance model is exactly why recommended architectures consistently select this option over per-account scripts, roles, or Config checks.

Why this answer

AWS CloudTrail supports integration with AWS Organizations, allowing you to create an organization trail that automatically logs events for all accounts in the organization. This trail delivers log files to a single centralized S3 bucket in the management account without requiring per-account configuration, ensuring compliance with the security team's requirement.

Exam trap

The trap here is that candidates often assume they must enable CloudTrail individually in each account or use complex cross-account IAM roles, overlooking the native AWS Organizations integration that automatically applies a single trail to all accounts.

How to eliminate wrong answers

Option A is wrong because it relies on a script running in each account via Lambda, which is operationally complex, not scalable, and does not leverage the native multi-account capabilities of CloudTrail; it also risks missing accounts or failing to maintain consistent configuration. Option B is wrong because AWS Config rules can only detect and remediate non-compliance after the fact, not proactively enable CloudTrail across all accounts, and the remediation Lambda would need to be deployed in each account, adding overhead and potential latency. Option D is wrong because creating an IAM role for each account to assume does not automatically enable CloudTrail; it only provides permissions, and the actual enabling would still require manual or scripted actions in each account, failing to meet the requirement for a centralized, automated solution.

1106
MCQmedium

A company uses IAM roles for EC2 instances. An application running on an EC2 instance needs to read from an S3 bucket in another AWS account. What is the most secure way to grant access?

A.Create an IAM role in the target account with read access to the bucket, and allow the EC2 instance's role to assume it.
B.Store the other account's IAM user access keys in the EC2 instance.
C.Make the bucket public.
D.Create a bucket policy that allows access from the EC2 instance's public IP.
AnswerA

By creating an IAM role in the target account with read-only permissions to the S3 bucket, the application can use the EC2 instance's existing instance profile role to assume that role via STS AssumeRole. The target account role's trust policy must explicitly allow the EC2 instance role as a principal, and the instance role needs sts:AssumeRole permission. This yields temporary security credentials, avoids storing long-term keys, and adheres to least-privilege cross-account access.

Why this answer

The most secure cross-account access pattern is to create an IAM role in the target (bucket-owning) account with read access to the S3 bucket, and allow the EC2 instance's role in the source account to assume it via STS AssumeRole. This uses temporary credentials, avoids long-term keys, and follows least privilege without exposing the bucket publicly.

Exam trap

SCS-C02 often tests whether candidates choose temporary role-based credentials over long-term access keys or public access, tempting them with seemingly simple solutions (public bucket, IP allowlist) that violate least privilege and security best practices.

How to eliminate wrong answers

Option B is wrong because storing another account's IAM user access keys on an EC2 instance creates long-term credentials that can be exfiltrated, violates AWS best practices, and bypasses role-based temporary credential rotation. Option C is wrong because making the bucket public exposes data to the entire internet, violating confidentiality and least privilege, and is a common cause of data breaches. Option D is wrong because allowing access based on the EC2 instance's public IP is fragile (IPs change), insecure (IP spoofing, shared NAT), and does not authenticate the instance's identity — IAM roles are the correct identity mechanism.

1107
MCQeasy

A company wants to ensure that all traffic to and from an Amazon RDS instance is encrypted in transit. Which solution should the security engineer implement?

A.Enable encryption at rest using AWS KMS.
B.Configure the database to require SSL/TLS connections and modify clients to connect using SSL.
C.Use an S3 bucket policy to enforce encryption in transit for all S3 traffic.
D.Use an AWS Transit Gateway to route traffic through a central VPC.
AnswerB

RDS natively supports SSL/TLS for encrypting the connection between a client and your database. You must set the database parameter group to require a secure connection (for example, 'require_secure_transport=ON' for MySQL, or use the rds-force-ssl-parameter for PostgreSQL) and then modify your application's connection string to use SSL mode, pointing to the RDS CA certificate. This ensures that all SQL queries, result sets, and authentication data are encrypted in transit, directly satisfying the requirement.

Why this answer

Encrypting data in transit for Amazon RDS requires enabling SSL/TLS on the database instance and configuring client connections to use SSL/TLS. This ensures that all traffic between the client and the RDS instance is encrypted using TLS protocols, protecting against eavesdropping and man-in-the-middle attacks. Amazon RDS supports SSL/TLS for all database engines, and you can enforce SSL connections by setting the 'require_secure_transport' parameter (MySQL) or similar parameters for other engines.

Exam trap

The trap here is that candidates confuse encryption at rest (KMS) with encryption in transit (SSL/TLS), leading them to select Option A, which does not address network traffic encryption.

How to eliminate wrong answers

Option A is wrong because encryption at rest using AWS KMS protects data stored on disk, not data in transit; it does not encrypt network traffic between clients and the RDS instance. Option C is wrong because an S3 bucket policy enforces encryption in transit for S3 traffic only, not for RDS traffic; it is irrelevant to RDS connectivity. Option D is wrong because an AWS Transit Gateway is used to route traffic between VPCs and on-premises networks, not to enforce encryption; it does not provide any encryption of data in transit between clients and RDS.

1108
Multi-Selectmedium

A security administrator is designing a cross-account access strategy. The administrator needs to allow users in Account A to assume an IAM role in Account B to access an S3 bucket. Which TWO of the following statements are true regarding this configuration?

Select 2 answers
A.The IAM users in Account A must have an IAM policy that allows the sts:AssumeRole action for the role ARN in Account B.
B.The trust policy for the role must be defined in Account A.
C.The S3 bucket policy must grant access to the IAM users in Account A.
D.The role in Account B must have a trust policy that allows the IAM users in Account A to assume the role.
E.The IAM users in Account A must have cross-account permissions on the S3 bucket in Account B.
AnswersA, D

The IAM users in Account A must have an identity-based policy that explicitly grants the sts:AssumeRole action against the role ARN in Account B. Without this allow, the AssumeRole API call is denied even if the trust policy in Account B permits the user, because IAM policies are evaluated by default-deny. The policy should specify the exact role ARN in the Resource element, for example arn:aws:iam::AccountB:role/CrossAccountRole.

Why this answer

For an IAM user in Account A to assume a role in Account B, the user must be explicitly granted permission to call the sts:AssumeRole API action against the role's Amazon Resource Name (ARN). This is done by attaching an IAM policy to the user (or a group/role the user belongs to) that includes the sts:AssumeRole action and specifies the target role ARN as the resource. Without this permission, the user cannot initiate the cross-account role assumption, even if the role's trust policy allows it.

Exam trap

The trap here is confusing where the trust policy is defined (it must be on the role in the target account, not in the source account) and assuming that direct IAM user permissions on the S3 bucket are required instead of using the assumed role's permissions.

1109
MCQmedium

A company is using AWS CloudTrail to log API calls and wants to ensure that log files are not tampered with after delivery to S3. Which feature should be enabled to validate the integrity of CloudTrail log files?

A.Enable CloudTrail log file validation
B.Enable MFA Delete on the S3 bucket
C.Enable S3 Versioning on the bucket
D.Enable S3 bucket default encryption
AnswerA

CloudTrail log file validation creates a SHA-256 hash of each log file and stores it in a digest file in the same S3 bucket. When enabled, you can use the AWS CLI or API to validate that log files were not modified or deleted after delivery. It uses a private key to sign the digest files, providing cryptographic assurance that the logs themselves are authentic and intact. This directly detects any tampering with log integrity, unlike the other options.

Why this answer

Enabling CloudTrail log file validation creates a digest file for each log file delivery, which includes a SHA-256 hash of the log file. This digest is signed using the private key of a dedicated CloudTrail key pair, allowing you to verify the integrity and authenticity of the log files by comparing the hash against the digest, ensuring no tampering occurred after delivery to S3.

Exam trap

The trap here is that candidates confuse data integrity validation with data protection features like encryption or versioning, mistakenly thinking that preventing deletion or encrypting data also ensures the data hasn't been tampered with.

How to eliminate wrong answers

Option B is wrong because MFA Delete on the S3 bucket protects against accidental or unauthorized deletion of objects by requiring multi-factor authentication for delete operations, but it does not validate the integrity or detect tampering of already-delivered log files. Option C is wrong because S3 Versioning preserves multiple versions of objects, which can help recover from accidental overwrites or deletions, but it does not provide cryptographic verification that the log file content has not been altered. Option D is wrong because S3 bucket default encryption ensures data is encrypted at rest, protecting confidentiality, but it does not provide any mechanism to verify that the log file has not been tampered with after delivery.

1110
Multi-Selectmedium

Which TWO actions are valid ways to enforce the principle of least privilege in an AWS environment?

Select 2 answers
A.Use the root user for daily administration
B.Use S3 bucket policies to allow all IAM users
C.Grant only the necessary actions in IAM policies
D.Use SCPs to deny actions that are not required
E.Assign the AdministratorAccess managed policy to all users
AnswersC, D

IAM policies define which actions an identity may perform on which resources; listing only the required actions means any unlisted API call is implicitly denied. This directly enforces least privilege at the identity-policy layer, satisfying the stem's requirement to grant no more than the task needs.

Why this answer

Option C is correct because least privilege means granting identities only the specific IAM actions and resources they actually need, so scoping IAM policy statements to the minimum required actions directly enforces that principle. Option D is correct because AWS Organizations Service Control Policies (SCPs) set a permissions boundary that can explicitly deny actions not required across accounts or OUs, preventing even otherwise-allowed IAM permissions from being used. Option A is wrong because using the root user for daily administration violates least privilege, as root has unrestricted access and should be reserved for a few account-level tasks.

Option B is wrong because an S3 bucket policy allowing all IAM users grants broad access rather than the minimum necessary. Option E is wrong because attaching AdministratorAccess to all users gives full administrative permissions, the opposite of least privilege.

Exam trap

SCS-C02 often tests the difference between IAM policies and SCPs. Candidates may think SCPs alone are sufficient, but they must be combined with IAM policies that grant only necessary actions. Also, candidates may confuse least privilege with other concepts like defense in depth.

1111
MCQeasy

A company wants to centralize the management of IAM users and groups for multiple AWS accounts. Which AWS service should be used to allow users to access multiple accounts with a single set of credentials?

A.AWS Organizations
B.IAM users and groups in each account
C.Amazon Cognito
D.AWS IAM Identity Center (AWS SSO)
AnswerD

AWS IAM Identity Center (successor to AWS SSO) is designed precisely for centralized management of workforce user access to multiple AWS accounts. It connects to external identity providers like Okta, Azure AD, or its own built-in identity store, and assigns users and groups to accounts using permission sets that define granular IAM permissions. With IAM Identity Center, an organization can manage one user directory and control sign-in across all accounts, complete with MFA and auditing, eliminating the need to create IAM users in each account.

Why this answer

AWS IAM Identity Center (successor to AWS SSO) is purpose-built to centralize workforce access across multiple AWS accounts using a single set of credentials. It integrates with AWS Organizations to enumerate accounts and permission sets, and can federate with an external IdP (e.g., Okta, Azure AD) or use its own identity store. Users sign in once and pick from assigned accounts/roles, eliminating per-account IAM users.

Exam trap

SCS-C02 often tests the distinction between AWS Organizations (account governance) and IAM Identity Center (workforce SSO) — candidates pick Organizations because it 'centralizes accounts' and miss that it has no identity store.

How to eliminate wrong answers

Option A is wrong because AWS Organizations is a governance/billing construct for grouping accounts and applying SCPs — it does not provide a user identity store or single-sign-on credentials. Option B is wrong because creating IAM users and groups in each account is exactly the siloed, multi-credential model the company wants to eliminate; it does not centralize identity. Option C is wrong because Amazon Cognito is a customer-facing CIAM service for application sign-up/sign-in (user pools, identity pools), not for workforce SSO into AWS accounts/console.

1112
Multi-Selecthard

Which THREE are AWS best practices for securing an Amazon EC2 instance? (Choose three.)

Select 3 answers
A.Store database credentials in instance metadata for easy retrieval.
B.Launch instances in the default VPC for easier network configuration.
C.Use security groups to control inbound and outbound traffic.
D.Disable password-based authentication and use SSH key pairs instead.
E.Regularly apply security patches using AWS Systems Manager Patch Manager.
AnswersC, D, E

Security groups provide stateful, instance-level filtering of inbound and outbound traffic, allowing least-privilege rules per workload. This satisfies the EC2 hardening requirement by restricting which ports and sources can reach each instance, unlike subnet-level NACLs alone.

Why this answer

Option C is correct because security groups act as stateful virtual firewalls at the instance/ENI level, and AWS best practice is to allow only the specific inbound ports (e.g., 22/443) and restrict outbound traffic needed by the workload rather than permitting all traffic. Option D is correct because disabling password-based SSH authentication and using SSH key pairs (or EC2 Instance Connect/SSM Session Manager) removes the risk of brute-force credential attacks and aligns with AWS guidance for Linux instance access. Option E is correct because AWS Systems Manager Patch Manager automates scanning and installation of OS and application security patches via patch baselines and maintenance windows, which is the recommended way to keep EC2 instances patched at scale.

Option A is wrong because instance metadata is readable from the instance (and potentially via SSRF) and is not a secure secret store; credentials should go in AWS Secrets Manager or Systems Manager Parameter Store. Option B is wrong because launching in the default VPC is not a security best practice; AWS recommends custom VPCs with segmented subnets, least-privilege routing, and controlled internet exposure.

Exam trap

The trap here is that candidates may think instance metadata is a secure place to store credentials because it is convenient, but AWS explicitly warns against this due to the risk of exposure through SSRF or other instance-level vulnerabilities.

1113
MCQeasy

A company wants to restrict access to an Amazon S3 bucket so that only objects uploaded with server-side encryption using AWS KMS (SSE-KMS) are allowed. Which bucket policy condition key should be used?

A.s3:x-amz-server-side-encryption-customer-key
B.s3:x-amz-server-side-encryption-aws-kms-key-id
C.kms:EncryptionContext
D.s3:x-amz-server-side-encryption
AnswerD

The s3:x-amz-server-side-encryption condition key only verifies that server-side encryption was requested or applied, typically checking the value such as AES256 or aws:kms, but it does not identify which AWS KMS key was used. This condition can ensure that objects are encrypted, but it cannot distinguish between different KMS keys, so it is insufficient for restricting access to objects encrypted with a specific KMS key. The requirement specifically calls for enforcing a particular KMS key, which requires a more granular condition key like s3:x-amz-server-side-encryption-aws-kms-key-id.

Why this answer

To enforce that all objects uploaded to an S3 bucket use SSE-KMS, you should use the bucket policy condition key `s3:x-amz-server-side-encryption` and set its value to `aws:kms`. This ensures the encryption header is `aws:kms` without requiring a specific KMS key. The key `s3:x-amz-server-side-encryption-aws-kms-key-id` is used only when you need to require a particular KMS key ARN.

Exam trap

Candidates often confuse the generic encryption condition key with the specific KMS key ID condition key. For restricting to any SSE-KMS, use `s3:x-amz-server-side-encryption` with value `aws:kms`. To restrict to a specific KMS key, use `s3:x-amz-server-side-encryption-aws-kms-key-id`.

How to eliminate wrong answers

Option A is wrong because `s3:x-amz-server-side-encryption-customer-key` is used to enforce server-side encryption with customer-provided encryption keys (SSE-C), not SSE-KMS. Option C is wrong because `kms:EncryptionContext` is a condition key for KMS API actions (like Encrypt or Decrypt) and is not used in S3 bucket policies to enforce encryption type on uploads. Option D is wrong because `s3:x-amz-server-side-encryption` only checks whether the `x-amz-server-side-encryption` header is present (e.g., 'AES256' for SSE-S3 or 'aws:kms' for SSE-KMS), but it cannot enforce that a specific KMS key ID is used, which is required to restrict to SSE-KMS only.

1114
MCQmedium

A company uses AWS KMS to encrypt data in Amazon RDS. The security team needs to ensure that the KMS key cannot be deleted accidentally. Which action should be taken?

A.Create an alias for the key.
B.Enable automatic key rotation.
C.Add a statement to the key policy that denies the kms:ScheduleKeyDeletion action.
D.Use a multi-Region key.
AnswerC

A key policy is the resource-based policy that governs access to a KMS key. Adding an explicit Deny statement for the kms:ScheduleKeyDeletion action prevents any principal—including IAM users, roles, or the account root—from scheduling the key for deletion, because an explicit Deny overrides any Allow. This makes the key effectively non-deletable through the normal API, assuming the key policy itself cannot be altered by unauthorized principals.

Why this answer

A key policy statement that explicitly denies kms:ScheduleKeyDeletion prevents any principal from scheduling the key for deletion, which is the strongest guard against accidental deletion. Explicit deny in a key policy overrides any allow, so even administrators cannot schedule deletion.

Exam trap

SCS-C02 often tests the misconception that key rotation or aliases protect against deletion, when the only reliable protection is an explicit Deny on kms:ScheduleKeyDeletion in the key policy.

How to eliminate wrong answers

Option A is wrong because an alias is just a friendly name for a key; it does not prevent deletion and can be reassigned. Option B is wrong because automatic key rotation rotates the backing key material but does not prevent the key from being scheduled for deletion. Option D is wrong because a multi-Region key is a replication feature for cross-Region use; it does not protect against deletion and in fact deleting a multi-Region primary key affects replicas.

1115
MCQeasy

A company wants to centralize CloudTrail logs from multiple AWS accounts into a single S3 bucket for security analysis. The logs must be encrypted at rest and access must be logged. What is the MOST secure way to grant cross-account access to the central S3 bucket?

A.Create an S3 bucket policy that grants s3:PutObject to everyone, and rely on CloudTrail to restrict access.
B.Create an IAM role in the central account that each member account can assume to write logs.
C.Create an S3 bucket policy that grants CloudTrail service principal permission to write objects, with a condition checking the source account ID.
D.Use an S3 bucket with default encryption enabled and share the KMS key with the other accounts.
AnswerC

This is the documented pattern for aggregating CloudTrail logs: the bucket policy grants s3:PutObject (and s3:GetBucketAcl if not using bucket owner enforcement) to the CloudTrail service principal, and the aws:SourceAccount condition restricts the service request to CloudTrail accounts explicitly allowed. The service principal cloudtrail.amazonaws.com prevents individuals or other AWS services from writing, while the condition blocks confused-deputy attacks from accounts not in the allow list. The central account then receives trail logs from all member accounts.

Why this answer

It uses an S3 bucket policy that grants the CloudTrail service principal (cloudtrail.amazonaws.com) permission to write objects, with a condition that checks the source account ID. This ensures that only CloudTrail from authorized accounts can deliver logs, and the service principal approach avoids the need for IAM roles or sharing credentials. The bucket policy also allows encryption at rest via S3 default encryption or a KMS key, and access logging can be enabled separately on the bucket.

Exam trap

The trap here is that candidates often confuse IAM roles with service principals, thinking that cross-account access always requires an IAM role, but CloudTrail uses service principals and bucket policies for cross-account log delivery, making option B a common distractor.

How to eliminate wrong answers

Option A is wrong because granting s3:PutObject to everyone allows any AWS principal or unauthenticated user to write objects, which is insecure and violates the principle of least privilege; CloudTrail cannot restrict access after the policy allows it. Option B is wrong because creating an IAM role in the central account for each member account to assume is not the most secure or efficient method for CloudTrail log delivery—CloudTrail uses service principals, not IAM roles, to write logs cross-account, and this approach adds complexity and potential for misconfiguration. Option D is wrong because sharing the KMS key with other accounts does not grant the necessary S3 write permissions; the bucket policy must explicitly allow CloudTrail to write, and simply enabling default encryption does not control access—also, sharing KMS keys with multiple accounts increases the attack surface and is not the primary mechanism for cross-account access.

1116
Multi-Selecthard

A company uses AWS CloudTrail to log API calls. They want to ensure that log files are encrypted at rest and that integrity is verified. Which TWO services can be used together to achieve this?

Select 2 answers
A.S3 Inventory
B.AWS CloudHSM
C.CloudTrail log file integrity validation
D.AWS KMS to encrypt the log files
E.S3 MFA Delete
AnswersC, D

CloudTrail log file integrity validation delivers a tamper-evident chain by hashing each log file with SHA-256, digitally signing the digest with a private key, and storing those digest files in the same delivery bucket. During validation, CloudTrail compares file hashes and signatures, so any modification, deletion, or replacement of delivered logs is detected, even if someone has access to the bucket. This directly addresses the requirement to prove that CloudTrail logs have not been altered.

Why this answer

CloudTrail log file integrity validation (option C) provides a built-in mechanism to verify that log files have not been modified, deleted, or tampered with after delivery. It uses SHA-256 hashing and digital signatures (based on RSA) to create a digest file that can be independently validated. AWS KMS (option D) allows you to encrypt CloudTrail log files at rest using server-side encryption (SSE-KMS), ensuring that the logs are stored in an encrypted format.

Together, they meet both the encryption-at-rest and integrity verification requirements.

Exam trap

The trap here is that candidates often confuse AWS CloudHSM with AWS KMS, thinking CloudHSM can directly encrypt CloudTrail logs, but CloudTrail only supports encryption via S3-managed keys (SSE-S3) or KMS keys (SSE-KMS), not CloudHSM, and integrity validation is a separate built-in feature of CloudTrail itself.

1117
MCQhard

A company deploys an AWS Lambda function inside a VPC to read from an Amazon RDS for PostgreSQL database in a private subnet. The function also needs to write logs to CloudWatch Logs and store objects in Amazon S3. The security team wants to eliminate the need for a NAT gateway while still allowing the function to reach both AWS services. Which combination of actions should the engineer take?

A.Create a gateway endpoint for Amazon S3 and a gateway endpoint for CloudWatch Logs, then associate both with the function's route tables.
B.Create interface endpoints for both Amazon S3 and CloudWatch Logs, and enable private DNS so the function resolves the service names to the endpoint addresses.
C.Create gateway endpoints for Amazon S3 and interface endpoints for CloudWatch Logs, associate them with the function's subnets, and attach a security group to the interface endpoints that allows HTTPS from the function's security group.
D.Attach an internet gateway to the VPC and update the function's route table to direct 0.0.0.0/0 to the internet gateway, then rely on the function's security group to restrict egress.
AnswerC

Gateway endpoints for S3 and interface endpoints for CloudWatch Logs keep that traffic on the AWS network, so no NAT gateway is needed. Interface endpoints use elastic network interfaces with security groups, so permitting HTTPS from the Lambda function's security group is required for the logs path to succeed.

Why this answer

Gateway endpoints serve Amazon S3 without hourly charges, while interface endpoints powered by AWS PrivateLink serve CloudWatch Logs. Because interface endpoints are elastic network interfaces, the endpoint's security group must allow inbound HTTPS from the Lambda function's security group, and private DNS resolution lets the SDK reach the service names transparently.

Exam trap

The trap here is assuming that a gateway endpoint can be created for any AWS service, when gateway endpoints exist only for Amazon S3 and DynamoDB.

1118
MCQhard

A company uses cross-account IAM roles to allow a third-party vendor to access resources in the company's AWS account. The security team wants to ensure that the vendor can only access the specific S3 bucket named 'vendor-bucket'. What should the security team do?

A.Create an IAM user for the vendor and attach a policy that allows access to 'vendor-bucket'.
B.In the trust policy of the role, specify the vendor's AWS account and attach a permissions policy that allows s3:* on 'vendor-bucket'. Also create a bucket policy that allows the role.
C.Use an SCP to deny access to all S3 buckets except 'vendor-bucket'.
D.Create a new AWS account for the vendor and use VPC peering.
AnswerB

The trust policy in the role should list the vendor's AWS account as a principal, allowing that account's users or roles to call sts:AssumeRole. The role's permissions policy then grants only s3:* on 'vendor-bucket' (e.g., arn:aws:s3:::vendor-bucket and arn:aws:s3:::vendor-bucket/*), adhering to least privilege. A bucket policy that explicitly allows the role can be added to make the resource-based authorization unambiguous and to satisfy any governance requirement that the bucket owner also approve access.

Why this answer

The correct approach is to create a cross-account IAM role for the vendor. In the role's trust policy, specify the vendor's AWS account as the trusted entity. Attach a permissions policy to the role that grants access only to the specific S3 bucket 'vendor-bucket' (e.g., s3:GetObject, s3:PutObject).

Additionally, create a bucket policy on 'vendor-bucket' that allows the role to access the bucket. This ensures the vendor can only assume the role and access the designated bucket.

1119
Multi-Selectmedium

A security engineer is configuring an automated incident response workflow for Amazon GuardDuty findings. Which TWO actions should the engineer take to ensure that the response is triggered for all current and future GuardDuty findings?

Select 2 answers
A.Enable GuardDuty to export findings to CloudWatch Logs and then create a metric filter.
B.Create an Amazon EventBridge rule with an event pattern that matches GuardDuty finding events.
C.Create an Amazon SNS topic and subscribe the Lambda function to it, then configure GuardDuty to publish to SNS.
D.Configure the rule to invoke an AWS Lambda function that executes the incident response playbook.
E.Set up a CloudWatch Logs subscription filter to forward GuardDuty logs to the Lambda function.
AnswersB, D

GuardDuty publishes every finding as an event to the default EventBridge event bus with a source of 'aws.guardduty' and a detail-type of 'GuardDuty Finding'. A rule with an event pattern that filters on either the source or the detail-type gives you a flexible, event-driven trigger point for incident response. This approach is direct, near-real-time, and requires no extra services or log processing to detect a new security finding.

Why this answer

Amazon EventBridge can capture all GuardDuty findings by using an event pattern that matches the 'GuardDuty Finding' event type. This ensures that both current and future findings automatically trigger the rule without requiring manual updates or additional configuration.

Exam trap

The trap here is that candidates often confuse GuardDuty's integration with CloudWatch Logs (which does not exist) or assume GuardDuty can directly publish to SNS, when in fact EventBridge is the required intermediary for automated workflows.

1120
Multi-Selecthard

Which THREE measures can be taken to secure a VPC's network boundary? (Choose three.)

Select 3 answers
A.Attach an S3 bucket policy to restrict access to the bucket.
B.Use security groups to control inbound and outbound traffic at the instance level.
C.Attach an internet gateway to the VPC.
D.Use network ACLs to add an additional layer of stateless filtering at the subnet level.
E.Enable VPC Flow Logs to capture and analyze traffic metadata.
AnswersB, D, E

Security groups act as a stateful virtual firewall attached to Elastic Network Interfaces, allowing you to define allow rules for inbound and outbound traffic. Stateful means return traffic is automatically permitted for an allowed request, and you can only specify allow rules—there is no explicit deny—so managing per-instance traffic at the protocol, port, and source/destination CIDR is the core instance-level measure. This is a foundational VPC security control that directly filters traffic before it reaches an instance.

Why this answer

Option B is correct because security groups act as stateful virtual firewalls at the instance/ENI level, allowing you to permit only specific inbound and outbound traffic, which directly hardens the VPC boundary. Option D is correct because network ACLs provide stateless subnet-level filtering with allow and deny rules, adding a second layer of defense that complements security groups. Option E is correct because VPC Flow Logs capture IP traffic metadata to CloudWatch Logs or S3, enabling detection and analysis of suspicious or unauthorized traffic crossing the VPC boundary.

Option A is not correct here because an S3 bucket policy secures access to an S3 bucket, not the VPC network boundary. Option C is not correct because attaching an internet gateway enables connectivity to the internet rather than restricting or securing the boundary.

Exam trap

The trap here is confusing network security controls (security groups, network ACLs, VPC Flow Logs) with resource-level policies (S3 bucket policies) or connectivity components (internet gateway), leading candidates to select options that do not directly secure the VPC's network boundary.

1121
MCQmedium

Refer to the exhibit. An IAM policy allows s3:GetObject on an S3 bucket only when the object is encrypted with SSE-KMS. An IAM user with this policy attempts to download an object that is not encrypted. What will happen?

A.The download fails because the condition is not met, even though the action is allowed.
B.The download succeeds because the condition is not required.
C.The download fails because the policy is invalid.
D.The download succeeds because there is no explicit deny.
AnswerA

The request does not satisfy the condition placed on the Allow, so the policy engine cannot produce an effective Allow for this operation. AWS evaluates IAM condition blocks as part of determining whether a statement applies, and a false condition causes the statement to be skipped entirely. Consequently, the s3:GetObject action is denied by default even though the statement text appears to authorize the action.

Why this answer

The policy allows s3:GetObject only when the condition (SSE-KMS encryption) is met. Since the object is not encrypted with SSE-KMS, the condition fails, the allow does not apply, and the request is implicitly denied. Option B is incorrect because the condition is required for the allow to take effect.

Option C is incorrect because the policy is syntactically valid. Option D is incorrect because the absence of an explicit deny does not grant permission; the allow condition must still be satisfied.

1122
MCQmedium

A company uses AWS Organizations with a single management account and multiple member accounts. The security team needs to ensure that all member accounts automatically deploy AWS Config rules to audit security group configurations. Which solution meets this requirement with minimal operational overhead?

A.Configure an AWS Lambda function in each account that periodically checks security group compliance.
B.Enable AWS Security Hub and rely on its built-in security group checks.
C.Use AWS Config conformance packs deployed via AWS CloudFormation StackSets from the management account.
D.Create an AWS Config rule in each member account manually using AWS CloudFormation templates.
AnswerC

AWS Config conformance packs bundle multiple managed or custom Config rules and remediation actions into a single CloudFormation template, and when deployed from the management account using CloudFormation StackSets, they are automatically applied to every target member account and Region. This leverages native AWS Organizations integration, so rules are provisioned consistently without manual per-account steps, and any updates to the conformance pack template can be rolled out centrally. With organization conformance packs, AWS Config manages the deployment across all accounts, making this a fully managed, scalable solution for enforcing security group compliance.

Why this answer

AWS Config conformance packs, deployed via AWS CloudFormation StackSets from the management account, allow you to centrally deploy a collection of AWS Config rules and remediation actions across all member accounts in an AWS Organization. This approach ensures consistent security group auditing with minimal operational overhead, as StackSets automatically handle deployment, updates, and drift detection across accounts and Regions.

Exam trap

The trap here is that candidates often confuse AWS Security Hub’s ability to aggregate and visualize security findings with the ability to automatically deploy and enforce Config rules, leading them to select Option B, but Security Hub does not deploy or manage Config rules itself.

How to eliminate wrong answers

Option A is wrong because using an AWS Lambda function in each account to periodically check security group compliance introduces significant operational overhead (function maintenance, scheduling, cross-account coordination) and does not leverage AWS Config’s native, event-driven compliance evaluation. Option B is wrong because AWS Security Hub provides security posture visibility and aggregates findings, but it does not automatically deploy AWS Config rules; it relies on existing Config rules or other integrations to generate findings. Option D is wrong because manually creating an AWS Config rule in each member account using AWS CloudFormation templates requires per-account deployment and maintenance, which is not scalable and contradicts the requirement for minimal operational overhead.

1123
MCQhard

A security engineer is investigating a potential compromise of an EC2 instance. The instance was launched from a custom AMI. The engineer needs to determine if the AMI itself contains malicious software. Which approach provides the most thorough analysis without risking the production environment?

A.Launch a test instance from the AMI in an isolated VPC and run Amazon Inspector.
B.Use AWS Systems Manager to run a compliance scan on the running instance.
C.Create an EBS snapshot from the AMI and scan the snapshot with Amazon Detective.
D.Launch a test instance from the AMI in an isolated VPC and analyze its behavior.
AnswerA

Launching an isolated test instance from the AMI prevents any risk to production resources while allowing deep inspection. Amazon Inspector automatically assesses the instance for software vulnerabilities and unintended network exposure, producing a prioritized list of findings. This approach gives a clean, controlled environment for forensics without altering the original evidence.

Why this answer

Launching a test instance from the AMI in an isolated VPC allows you to run Amazon Inspector, which performs automated vulnerability assessments and network reachability checks against the instance. This approach provides a thorough analysis of the AMI's software and configuration without exposing the production environment to any potential malicious activity. Amazon Inspector uses a knowledge base of common vulnerabilities and exposures (CVEs) and CIS benchmarks to identify security issues, making it effective for detecting malicious software embedded in the AMI.

Exam trap

The trap here is that candidates may choose Option D (behavioral analysis) because it seems more hands-on and thorough, but they overlook that Amazon Inspector provides a more systematic, automated, and comprehensive scan for known vulnerabilities and misconfigurations, which is the most efficient way to identify malicious software in an AMI without risking the production environment.

How to eliminate wrong answers

Option B is wrong because AWS Systems Manager compliance scans are designed to assess the configuration of a running instance against defined policies (e.g., patch compliance), not to detect malicious software within the AMI itself; the scan runs on the potentially compromised production instance, risking the production environment. Option C is wrong because Amazon Detective analyzes VPC flow logs, CloudTrail logs, and GuardDuty findings to investigate security incidents, but it does not scan EBS snapshots for malware; creating a snapshot from the AMI and scanning it with Detective would not reveal malicious software in the snapshot. Option D is wrong because while launching a test instance in an isolated VPC and analyzing its behavior (e.g., network traffic, process activity) can provide insights, it lacks the automated, comprehensive vulnerability scanning capabilities of Amazon Inspector, making it less thorough for identifying known malicious software or CVEs.

1124
MCQeasy

A company wants to provide temporary, limited-privilege credentials to users so they can access AWS resources from mobile applications. Which AWS service should the company use?

A.AWS Security Token Service (STS)
B.AWS Single Sign-On (SSO)
C.AWS Identity and Access Management (IAM) users
D.Amazon Cognito user pools
AnswerA

AWS Security Token Service (STS) is the correct service because it explicitly issues temporary, limited-privilege credentials—typically an access key ID, a secret access key, and a session token—with configurable durations (15 minutes to 12 hours). For a mobile app that needs scoped permissions without embedding permanent keys, STS operations like AssumeRole or GetFederationToken are the direct mechanism, and the returned credentials are automatically expired, reducing risk of long-term exposure.

Why this answer

AWS Security Token Service (STS) is the correct service because it enables the generation of temporary, limited-privilege credentials (access key, secret key, and session token) that can be used to access AWS resources. These credentials are ideal for mobile applications where long-term keys are a security risk, as they can be scoped with an IAM role and have a configurable expiration (default 1 hour, max 36 hours). STS supports the AWS Signature Version 4 signing process and can be called via the AssumeRole or GetFederationToken APIs to provide federated access.

Exam trap

The trap here is that candidates confuse Amazon Cognito user pools (which handle authentication and user management) with identity pools (which use STS to grant AWS credentials), leading them to select Cognito user pools instead of STS as the direct service for temporary credentials.

How to eliminate wrong answers

Option B (AWS Single Sign-On) is wrong because it is a centralized authentication service for workforce users accessing multiple AWS accounts or business applications, not designed to issue temporary credentials for mobile app users. Option C (IAM users) is wrong because IAM users have long-term static credentials (access key and secret key) that are not temporary and pose a higher security risk if exposed in mobile applications. Option D (Amazon Cognito user pools) is wrong because user pools are a user directory and authentication provider for mobile apps, but they do not directly issue AWS credentials; instead, they integrate with identity pools (which use STS) to grant temporary AWS access.

1125
Multi-Selecthard

A security engineer is configuring a new AWS account and wants to ensure that all API activity is logged and that logs are protected from deletion. The engineer plans to use AWS CloudTrail and Amazon S3. Which TWO actions should the engineer take to meet these requirements? (Choose two.)

Select 2 answers
A.Enable CloudTrail log file validation to ensure logs are not tampered with.
B.Configure the S3 bucket policy to deny deletion of objects by any principal except the security engineer's IAM role.
C.Enable S3 Object Lock in compliance mode on the S3 bucket used for CloudTrail logs.
D.Use AWS Key Management Service (AWS KMS) to encrypt the CloudTrail logs in the S3 bucket.
E.Create a CloudTrail trail that applies to all regions and logs management events.
AnswersC, E

S3 Object Lock in compliance mode prevents objects from being deleted or overwritten for a specified retention period, even by the root user. This protects CloudTrail logs from tampering or deletion, satisfying the immutability requirement. It is a strong control that ensures logs cannot be altered, which is critical for security and compliance.

Why this answer

To log all API activity, a multi-region trail that logs management events is necessary. To protect logs from deletion, S3 Object Lock in compliance mode provides immutability. Other options either do not prevent deletion, provide only detection, or address confidentiality rather than integrity.

Together, these two actions meet the requirements for logging and protection.

Exam trap

The trap here is confusing log file validation or encryption with immutability; they do not prevent deletion, whereas S3 Object Lock does.

Page 14

Page 15 of 17

Page 16