Courseiva

AWS Certified Security Specialty SCS-C02 (SCS-C02) — Questions 1126–1200

1205 questions total · 17pages · All types, answers revealed

Page 15

Page 16 of 17

Page 17
1126
MCQeasy

A company needs to ensure that data in transit between an on-premises data center and Amazon S3 is encrypted. The data will be transferred using HTTPS. What additional step should be taken to ensure the encryption is enforced?

A.Use AWS KMS to require encryption in transit
B.Enable S3 Transfer Acceleration
C.Add a bucket policy that denies requests where aws:SecureTransport is false
D.Use Amazon CloudFront with HTTPS only
AnswerC

Adding a bucket policy with a condition that denies requests when `aws:SecureTransport` is `false` enforces HTTPS by rejecting any HTTP or unencrypted requests at the S3 API level. This satisfies the stem’s requirement to ensure encryption is enforced for data in transit, as the policy explicitly blocks non-HTTPS traffic regardless of the client’s protocol choice.

Why this answer

The correct answer is C because S3 bucket policies can enforce encryption in transit by denying any request where the aws:SecureTransport condition key is false. This ensures that only HTTPS (TLS) requests are allowed, effectively blocking HTTP access. Since the data is already being transferred over HTTPS, adding this policy guarantees that encryption in transit is enforced and cannot be bypassed.

Exam trap

SCS-C02 often tests the difference between encryption at rest and encryption in transit, and candidates may confuse AWS KMS (which is for at-rest encryption) with mechanisms that enforce in-transit encryption, leading them to pick option A.

How to eliminate wrong answers

Option A is wrong because AWS KMS is used for encryption at rest (server-side encryption) and does not enforce encryption in transit; KMS keys encrypt data on disk, not over the wire. Option B is wrong because S3 Transfer Acceleration speeds up transfers using AWS edge locations but does not enforce encryption; it can be used with HTTP or HTTPS. Option D is wrong because CloudFront with HTTPS only encrypts data between the client and CloudFront, but the origin connection to S3 might still use HTTP unless separately configured; moreover, the question specifies direct HTTPS transfer to S3, so CloudFront is unnecessary and does not enforce encryption for direct S3 access.

1127
MCQmedium

A security engineer is analyzing a potential security incident involving an Amazon RDS for MySQL database. The engineer suspects that a SQL injection attack was successful. Which AWS service can the engineer use to review the actual SQL queries that were executed against the database?

A.VPC Flow Logs
B.Amazon GuardDuty
C.AWS CloudTrail
D.Amazon RDS Audit Logs
AnswerD

Amazon RDS Audit Logs are the correct source because they record the actual SQL statements executed against the database, along with the connecting user, source IP, and timestamp. For RDS MySQL or MariaDB, you enable the audit_log plugin via a DB parameter group and then export the logs to CloudWatch Logs; for PostgreSQL, you use the pgaudit extension. Misconfigured database users or SQL injection attempts will appear in these logs, making them the definitive forensic evidence during a security incident.

Why this answer

Amazon RDS for MySQL supports audit logs that capture detailed records of database activities, including the actual SQL queries executed. By enabling the `audit_log` plugin and configuring the `server_audit_events` parameter, the engineer can review the exact SQL statements that were run, which is essential for identifying a SQL injection attack. This is the only AWS service that provides query-level visibility into RDS database operations.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which logs control-plane API calls) with database audit logs (which log data-plane SQL queries), leading them to incorrectly select CloudTrail for reviewing executed SQL statements.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture metadata about network traffic (IP addresses, ports, protocols) but do not log the content of SQL queries or database operations. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes AWS CloudTrail events, VPC Flow Logs, and DNS logs for suspicious activity, but it does not provide direct access to the SQL queries executed against an RDS database. Option C is wrong because AWS CloudTrail records API calls made to the RDS service (e.g., creating a DB instance) but does not log the data-plane SQL queries executed within the database itself.

1128
MCQmedium

A company uses Amazon CloudFront with an Application Load Balancer (ALB) as the origin. The security team wants to restrict access to the ALB so that it only accepts traffic from CloudFront. Which configuration should be used?

A.Configure the ALB to be internal and place it in a VPC with a CloudFront VPC origin.
B.Configure the ALB to require a specific header 'X-CloudFront-Origin' and reject requests without it.
C.Configure the ALB to use an IAM role that allows only CloudFront to invoke the ALB.
D.Configure the ALB security group to allow inbound traffic only from the CloudFront origin IP ranges published by AWS.
AnswerD

This is the correct and recommended approach: AWS publishes the complete set of CloudFront IP addresses used to fetch content from origins in the ip-ranges.json file, with a specific service indicator (CLOUDFRONT_ORIGIN_FACING). By adding a security group rule that allows inbound TCP 80/443 only from those CIDR blocks, the ALB will refuse connections from any other public IP, including direct internet clients that bypass CloudFront. You can implement this effectively using a managed prefix list that AWS keeps updated, or by periodically refreshing your security group rules from the published ranges.

Why this answer

CloudFront publishes a list of its origin-facing IP address ranges, and you can restrict the ALB's security group to allow inbound traffic only from those ranges. This ensures that only CloudFront can reach the ALB directly, preventing bypass attacks. AWS provides these IP ranges in the ip-ranges.json file, which can be used to automate security group updates.

Exam trap

The trap here is that candidates often confuse CloudFront's viewer-facing IP ranges with its origin-facing IP ranges, or they assume that a custom header (like 'X-CloudFront-Origin') is a built-in CloudFront feature, when in fact AWS recommends using security group restrictions as the primary defense.

How to eliminate wrong answers

Option A is wrong because CloudFront cannot use a VPC origin with an internal ALB; CloudFront origins must be publicly accessible over the internet, and internal ALBs are not reachable from CloudFront. Option B is wrong because there is no standard 'X-CloudFront-Origin' header; while you can use a custom header like 'X-Origin-Verify' to authenticate requests, this is not a built-in CloudFront feature and relies on a shared secret, which is less secure than network-layer restriction. Option C is wrong because IAM roles are used for API-level authorization (e.g., invoking Lambda functions), not for network traffic control to an ALB; ALBs do not evaluate IAM roles for incoming HTTP requests.

1129
Multi-Selectmedium

A security engineer is designing a CI/CD pipeline that deploys AWS infrastructure using AWS CloudFormation. The pipeline must assume an IAM role in each target account to create and update stacks. Which TWO steps are required to allow cross-account access for CloudFormation? (Choose TWO.)

Select 2 answers
A.Create a service role for CloudFormation in the pipeline account with a trust policy for the target account.
B.Store the target account root credentials in AWS Secrets Manager and retrieve them in the pipeline.
C.Configure the pipeline's IAM role with a trust policy that allows the target account to access it.
D.Use AWS STS AssumeRole in the pipeline to obtain temporary credentials for the target account role.
E.Create an IAM role in the target account with a trust policy allowing the pipeline account to assume it.
AnswersD, E

The pipeline must call the AWS Security Token Service (STS) AssumeRole API using the pipeline's existing IAM role or a dedicated deployment role, passing the ARN of the target-account role as the RoleArn parameter. STS then returns temporary, automatically expiring credentials (access key, secret key, and session token) that grant exactly the permissions defined in the target role's permissions policy. These temporary credentials can be passed to AWS SDK clients or exported as environment variables so that the deployment commands interact with the target account without human involvement or long-lived secrets.

Why this answer

Option E is correct because cross-account access requires a role in the target account whose trust policy explicitly allows the pipeline account (or its principal) to assume it via sts:AssumeRole. Option D is correct because the pipeline must call AWS STS AssumeRole to obtain temporary credentials for that target-account role before CloudFormation can create or update stacks there. Together, E establishes the destination role and D obtains the credentials to use it.

Option A is wrong because a service role in the pipeline account with a trust policy for the target account does not grant the pipeline permission to act in the target account. Option B is wrong because using root credentials is insecure and unnecessary when role assumption is available. Option C is wrong because configuring the pipeline role to trust the target account reverses the trust direction and does not let the pipeline assume a role in the target account.

Exam trap

SCS-C02 often tests the direction of trust policies in cross-account access, tricking candidates into placing the trust policy on the wrong account or using long-term credentials instead of STS AssumeRole.

1130
MCQeasy

A company has a requirement to detect and alert on S3 objects that contain personally identifiable information (PII) being shared publicly. Which AWS service should be used?

A.Amazon CloudWatch
B.Amazon GuardDuty
C.Amazon Inspector
D.Amazon Macie
AnswerD

Amazon Macie is purpose-built to discover and protect sensitive data in Amazon S3, using machine learning and pattern matching to identify personally identifiable information (PII), credentials, and other categories. After you enable Macie, it automatically inventories S3 buckets and continuously evaluates objects for sensitive content, generating alerts when it finds them. This directly aligns with the company's requirement to detect and alert on S3 object content.

Why this answer

Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to discover, classify, and protect sensitive data such as personally identifiable information (PII) stored in Amazon S3. It can automatically generate alerts when S3 objects containing PII are made publicly accessible, meeting the requirement to detect and alert on such events.

Exam trap

The trap here is that candidates often confuse Amazon GuardDuty's threat detection capabilities (which focus on API calls and network behavior) with Macie's data classification and content inspection, leading them to select GuardDuty when the requirement specifically involves detecting PII in S3 objects.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch is a monitoring and observability service for metrics, logs, and alarms, not a data classification or PII detection service; it cannot natively inspect S3 object content for PII. Option B is wrong because Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior using VPC Flow Logs, DNS logs, and CloudTrail events, but it does not perform content inspection of S3 objects for PII. Option C is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances and container workloads for software vulnerabilities and unintended network exposure, not S3 object content or data classification.

1131
MCQeasy

A company needs to protect data at rest on Amazon EBS volumes attached to EC2 instances. Which solution provides the most control over the encryption keys?

A.Use a customer managed KMS key with EBS encryption.
B.Encrypt data using client-side encryption before writing to EBS.
C.Use an AWS managed KMS key for EBS encryption.
D.Enable EBS encryption by default in the account.
AnswerA

Using a customer managed KMS key with EBS encryption is the correct approach because it gives you full control over the key lifecycle, key policy, and permissions, allowing you to restrict access to specific principals or services. EBS encryption uses envelope encryption where a CMK generates a data key to encrypt the volume, and you can audit key usage through CloudTrail. This provides a native, seamless encryption solution for data at rest without requiring application changes, and it supports compliance requirements that mandate customer-controlled keys.

Why this answer

A customer managed KMS key gives the account owner full control over the key policy, rotation, grants, and deletion, which is the maximum control available for EBS encryption at rest. AWS managed keys (aws/ebs) are controlled by AWS and cannot be customized or have their policies modified by the customer. Enabling EBS encryption by default only sets a default key but does not by itself provide the most control.

Client-side encryption is a different layer and does not address EBS-native encryption key control.

Exam trap

SCS-C02 often tests the distinction between AWS managed and customer managed KMS keys; candidates incorrectly assume that enabling EBS encryption by default or using an AWS managed key provides the same level of control as a customer managed key.

How to eliminate wrong answers

Option B is wrong because client-side encryption occurs before data reaches EBS and does not leverage EBS/KMS key management; it provides confidentiality but not the granular KMS key control the question asks for. Option C is wrong because AWS managed KMS keys are owned and managed by AWS, with fixed key policies and no customer ability to rotate, restrict, or audit key usage beyond CloudTrail. Option D is wrong because enabling EBS encryption by default simply ensures new volumes are encrypted with a default key (often the AWS managed key) and does not grant additional key control.

1132
MCQeasy

A company wants to ensure that all data sent to an S3 bucket is encrypted in transit. Which policy statement should be added to the bucket policy?

A.Allow if aws:SecureTransport is false
B.Deny unless aws:SecureTransport is false
C.Allow if aws:SecureTransport is true
D.Deny if aws:SecureTransport is false
AnswerD

This is the correct pattern because it explicitly denies every request where aws:SecureTransport is false, i.e., plaintext HTTP, while leaving HTTPS requests unaffected and able to be allowed by other statements. An explicit Deny always overrides any Allow, so even a broad bucket policy cannot accidentally permit insecure HTTP traffic. This is the standard, recommended way to enforce TLS for S3 data in transit.

Why this answer

The correct answer is D: Deny if aws:SecureTransport is false. The aws:SecureTransport condition key evaluates to true when the request is made over HTTPS (TLS) and false when made over HTTP. To enforce encryption in transit, you must explicitly deny requests where aws:SecureTransport is false, ensuring that any unencrypted HTTP request is rejected.

This is the standard pattern for S3 bucket policies to enforce TLS-only access.

Exam trap

SCS-C02 often tests the difference between Allow and Deny effects and the logical inversion of condition keys, so candidates may mistakenly choose an Allow statement with aws:SecureTransport true, not realizing that an explicit Deny is required to block insecure requests when other allows exist.

How to eliminate wrong answers

Option A is wrong because it allows requests when aws:SecureTransport is false, which means it permits unencrypted HTTP traffic, directly contradicting the goal. Option B is wrong because it denies requests when aws:SecureTransport is false, but the condition is inverted: it would deny secure HTTPS requests and allow insecure HTTP requests, which is the opposite of what is needed. Option C is wrong because it only allows requests when aws:SecureTransport is true, but it does not explicitly deny insecure requests; if there are other allow statements in the bucket policy, HTTP requests could still be permitted.

An explicit deny is required to guarantee enforcement.

1133
Multi-Selecteasy

A company wants to use AWS CloudTrail to log all API calls in an AWS account. The security engineer needs to ensure that the logs are encrypted at rest and are accessible only to authorized personnel. Which THREE steps should the engineer take? (Choose THREE.)

Select 3 answers
A.Enable MFA delete on the S3 bucket.
B.Enable server-side encryption on the S3 bucket that stores CloudTrail logs.
C.Attach a service control policy (SCP) to the root account.
D.Create an IAM policy that grants access to the S3 bucket only to specific users or roles.
E.Configure the S3 bucket policy to require encrypted connections (aws:SecureTransport).
AnswersB, D, E

Enabling server-side encryption on the S3 bucket that stores CloudTrail logs ensures that every delivered log object is encrypted at rest, either with SSE-S3 using Amazon-managed keys or with SSE-KMS using a customer-managed key. This directly protects the audit trail from being read by anyone who obtains the underlying storage, and it is a core requirement for compliance frameworks that mandate encrypted audit data. CloudTrail supports SSE-KMS through its own integration, allowing you to control the encryption key separately from the bucket.

Why this answer

Option B is correct because enabling server-side encryption (SSE-S3, SSE-KMS, or SSE-C) on the S3 bucket that stores CloudTrail logs ensures the log objects are encrypted at rest, satisfying the encryption requirement. Option D is correct because an IAM policy scoped to specific users or roles enforces least-privilege access, ensuring only authorized personnel can read the CloudTrail log objects. Option E is correct because a bucket policy condition requiring aws:SecureTransport=true denies any non-TLS (HTTP) requests, protecting logs in transit and preventing unencrypted access.

Option A does not belong because MFA delete protects against accidental or malicious deletion of objects but does not provide encryption at rest or restrict read access to authorized personnel. Option C does not belong because an SCP attached to the root account only sets permission guardrails for accounts in an organization and does not encrypt CloudTrail logs or grant/restrict access to the specific S3 bucket.

Exam trap

SCS-C02 often tests the difference between encryption at rest, encryption in transit, and access control — candidates incorrectly pick MFA Delete or SCPs thinking they provide confidentiality of log data.

1134
MCQhard

A security engineer is investigating a compromised IAM user whose access key was leaked. The engineer uses the AWS CLI to review CloudTrail event history but notices that recent management events performed by the compromised access key are missing. The CloudTrail trail is configured to log management events for all Regions and delivers to an S3 bucket. The engineer needs to determine whether the missing events indicate that the attacker is evading detection or that the engineer is querying the wrong data source. Which action should the engineer take FIRST to confirm the source of the discrepancy?

A.Query Amazon GuardDuty findings for the IAM user to see whether GuardDuty recorded the API calls, then correlate the GuardDuty finding timestamps with the CloudTrail event history.
B.Verify that the CloudTrail trail is logging and that the S3 bucket policy, KMS key policy, and CloudTrail service principal permissions allow the trail to deliver logs, then check the S3 bucket for the expected log file prefix and timestamps.
C.Enable AWS CloudTrail Insights on the trail to detect unusual API call rates, then review the Insights events in the S3 bucket for the compromised access key.
D.Use the AWS CloudTrail console or the aws cloudtrail lookup-events command to query the last 90 days of event history, since the event history is retained for 90 days and is separate from the trail's S3 delivery.
AnswerB

The trail delivers logs to S3 only if the bucket policy, KMS key policy, and CloudTrail service principal have the required permissions. If delivery fails, events will not appear in S3 even though the trail is enabled. Checking the bucket for the expected prefix and recent timestamps confirms whether the trail is actually delivering, which directly addresses the discrepancy before assuming attacker evasion.

Why this answer

When CloudTrail events appear missing, the first step is to confirm that the trail is actually delivering logs to its destination. A trail can be enabled yet fail delivery because the S3 bucket policy, KMS key policy, or CloudTrail service principal lacks required permissions, or because the trail was modified. Inspecting the S3 bucket for the expected log file prefix and recent timestamps distinguishes a delivery failure from attacker evasion, and it is faster and more definitive than querying event history or GuardDuty.

Exam trap

The trap here is assuming that missing CloudTrail events automatically indicate attacker evasion, when a common cause is failed log delivery due to S3 bucket policy, KMS key policy, or service principal permission issues.

1135
MCQeasy

Refer to the exhibit. A security engineer is analyzing VPC Flow Logs and notices a pattern of outbound traffic from an EC2 instance to an external IP on port 22 (SSH). The engineer wants to identify which instances are initiating SSH connections to the internet. Which field in the flow log record indicates the source of the connection?

A.The first IP address in the log entry (srcaddr)
B.The second IP address (dstaddr)
C.The first port number (srcport)
D.The second port number (dstport)
AnswerA

The srcaddr field in VPC Flow Logs records the source IP address of the traffic. For outbound flows, this is the private IP address of the EC2 instance's network interface that generated the traffic. Because the question asks to identify the instance that sent the suspicious traffic, srcaddr is the correct field to filter on; it uniquely points to the originating instance within the VPC.

Why this answer

In VPC Flow Logs, the `srcaddr` field records the source IP address of the traffic. Since the engineer is looking for which EC2 instances are initiating outbound SSH connections (port 22), the source IP in the flow log entry (srcaddr) directly identifies the instance that started the connection. The direction of the traffic is determined by the source and destination fields, not by the port numbers alone.

Exam trap

The trap here is that candidates confuse the source port (srcport) with the source address (srcaddr), mistakenly thinking the port number identifies the initiating instance, when in fact the source IP address is the correct field to determine which EC2 instance started the connection.

How to eliminate wrong answers

Option B is wrong because `dstaddr` is the destination IP address (the external server), not the source EC2 instance. Option C is wrong because `srcport` is the source port number (a random ephemeral port used by the client), not the IP address of the initiating instance. Option D is wrong because `dstport` is the destination port (22 for SSH), which identifies the service but not the source of the connection.

1136
Multi-Selecthard

A security engineer is investigating a potential security incident. The engineer has enabled CloudTrail and VPC Flow Logs. Which THREE pieces of information can the engineer obtain from CloudTrail logs that are NOT available in VPC Flow Logs? (Choose three.)

Select 3 answers
A.The payload of the API request.
B.The AWS Region where the API call was made.
C.The destination IP address and port of the network traffic.
D.The IAM user or role that performed the API call.
E.The source IP address of the API call.
AnswersB, D, E

The AWS Region where the API call was made is a definitive field in CloudTrail's event history (the awsRegion attribute), whereas VPC Flow Logs are tied to a specific VPC and only describe traffic within that VPC's region. An API call's endpoint region may differ from the region of the VPC through which the traffic flows, so only CloudTrail provides this region information.

Why this answer

CloudTrail logs capture management-plane API calls, including the AWS Region where the call was made (via the 'awsRegion' field). VPC Flow Logs only capture network-level metadata (IP addresses, ports, protocols) and have no visibility into the AWS Region of an API call because they operate at Layer 3/4 of the OSI model and do not log control-plane events. Therefore, the Region information is uniquely available in CloudTrail.

Exam trap

The trap here is that candidates assume CloudTrail logs contain the full request payload (Option A) because they confuse CloudTrail with AWS Config or data-plane logging, but CloudTrail explicitly excludes payload data to avoid storing sensitive information.

1137
Multi-Selectmedium

A company uses AWS KMS to encrypt data in Amazon RDS. The security team wants to ensure that the KMS key can be used only by specific IAM roles and that all usage of the key is logged. Which TWO actions should the team take?

Select 2 answers
A.Apply an S3 bucket policy to the RDS automated backup bucket
B.Enable automatic key rotation
C.Enable AWS CloudTrail to log KMS API calls
D.Modify the key policy to grant kms:Encrypt and kms:Decrypt only to the required IAM roles
E.Create a cross-account key policy to allow all IAM roles in the account
AnswersC, D

Enabling AWS CloudTrail to log KMS API calls provides a detailed audit trail of every kms:Encrypt, kms:Decrypt, GenerateDataKey, and other KMS operation, including the IAM principal, source IP, and request timestamp. This is a detective control that lets security engineers monitor and investigate who is using the key and when, which is the correct approach when the goal is visibility into KMS usage. CloudTrail does not prevent or allow operations, so it complements, rather than replaces, access-control policies.

Why this answer

To restrict KMS key usage to specific IAM roles, the key policy must be modified to grant only those roles the kms:Encrypt and kms:Decrypt permissions (option D). To log all usage of the key, enable AWS CloudTrail to capture KMS API calls (option C). Option A is incorrect because an S3 bucket policy does not control KMS key usage.

Option B is incorrect because key rotation does not restrict access. Option E is incorrect because cross-account access is not specified as a requirement.

1138
MCQhard

A security engineer needs to ensure that all data in transit between an Application Load Balancer (ALB) and EC2 instances is encrypted. What configuration is required?

A.Configure the security group to allow traffic on port 443.
B.Configure the ALB listener with HTTPS protocol.
C.Configure the ALB to terminate TLS connections.
D.Configure the target group to use HTTPS protocol.
AnswerD

Setting the target group protocol to HTTPS instructs the ALB to establish a new TLS session with each registered EC2 target rather than forwarding plaintext HTTP. This encrypts the second segment of the request path, so combined with an HTTPS listener the data is encrypted end to end. It directly addresses the missing encryption between the load balancer and the instances, making it the correct action.

Why this answer

Encryption in transit between an ALB and its targets is controlled by the target group protocol, not the listener. Setting the target group to HTTPS makes the ALB initiate TLS connections to the EC2 instances, encrypting the backend leg. The listener protocol only governs the client-to-ALB leg.

Exam trap

The trap is assuming that configuring the ALB listener for HTTPS automatically encrypts the backend leg — candidates forget that the target group protocol is a separate setting that controls ALB-to-instance encryption.

How to eliminate wrong answers

Option A is wrong because security groups control network reachability (ports and sources), not encryption; allowing port 443 does not force TLS between the ALB and targets. Option B is wrong because configuring the ALB listener with HTTPS only encrypts traffic from the client to the ALB; the ALB still communicates with targets using whatever protocol the target group specifies. Option C is wrong because terminating TLS at the ALB means the ALB decrypts client traffic and then forwards it — if the target group is HTTP, the backend leg is plaintext, which is the opposite of what is required.

Option D is correct because the target group protocol setting is what determines whether the ALB re-encrypts traffic to the instances.

1139
MCQeasy

A security engineer needs to grant an EC2 instance access to an S3 bucket without storing long-term credentials on the instance. Which approach should the engineer use?

A.Generate an access key and secret key for an IAM user and store them in the EC2 instance.
B.Use an SCP to allow the EC2 instance to access the S3 bucket.
C.Store the credentials in the AMI used to launch the instance.
D.Create an IAM role with the required permissions and attach it to the EC2 instance as an instance profile.
AnswerD

An instance profile is a container for an IAM role that you attach to an EC2 instance, and its trust policy allows the EC2 service to assume the role on behalf of the instance. When the instance calls the instance metadata service (IMDS) at 169.254.169.254, it receives temporary security credentials with the role's permissions, and these credentials are automatically rotated before they expire. This eliminates the need to store any long-term access key on the instance, keeps permissions centrally managed, and is the secure AWS-recommended approach for granting instance-level access to resources like S3.

Why this answer

An IAM role attached to an EC2 instance via an instance profile allows the instance to obtain temporary, automatically rotated credentials from the EC2 Instance Metadata Service (IMDS) at 169.254.169.254. This eliminates the need to embed long-term access keys anywhere on the instance or in the AMI. The instance assumes the role and receives short-lived STS credentials scoped to the role's permissions.

Exam trap

SCS-C02 often tests whether candidates confuse identity-based permission grants (IAM roles/instance profiles) with permission boundaries or guardrails (SCPs), leading them to pick an SCP as if it granted access.

How to eliminate wrong answers

Option A is wrong because generating long-term IAM user access keys and storing them on the instance creates a persistent credential that can be exfiltrated and has no automatic rotation. Option B is wrong because an SCP is an AWS Organizations policy that sets permission guardrails on accounts/OUs — it does not grant permissions to an EC2 instance and cannot by itself authorize S3 access. Option C is wrong because baking credentials into an AMI embeds static secrets in an image that may be shared, copied, or launched by others, and the credentials never rotate.

1140
MCQmedium

A security engineer needs to ensure that all API activity in an AWS account is logged and that the logs are retained for 10 years for compliance. The engineer enables AWS CloudTrail with a multi-Region trail and delivers logs to an Amazon S3 bucket. The engineer must prevent any user, including administrators, from deleting or altering the logs during the retention period. Which solution meets these requirements?

A.Enable S3 Object Lock in compliance mode on the S3 bucket with a retention period of 10 years.
B.Apply an S3 bucket policy that denies s3:DeleteObject and s3:PutObject for all principals except the CloudTrail service.
C.Configure AWS CloudTrail to use a customer-managed AWS KMS key to encrypt the logs and enable key rotation.
D.Enable S3 Versioning and configure a lifecycle rule to transition objects to S3 Glacier Deep Archive after 30 days.
AnswerA

S3 Object Lock in compliance mode prevents any user, including the root user, from deleting or overwriting objects until the retention period expires. This satisfies the requirement for immutability for 10 years. The other options either do not prevent deletion by administrators or do not provide the required retention guarantee.

Why this answer

S3 Object Lock in compliance mode provides immutable storage for a specified retention period, even preventing the root user from deleting objects. This is the only option that guarantees logs cannot be deleted or altered for 10 years. Other options either allow administrators to bypass protections or do not enforce retention.

Exam trap

The trap here is assuming that S3 Versioning or bucket policies alone provide immutability, but they can be bypassed by users with sufficient permissions.

1141
MCQhard

A security engineer is auditing the AWS Organizations structure. The engineer notices that the 'Management' account (111111111111) has a status of 'ACTIVE' and joined method 'CREATED'. The engineer is concerned about potential security risks. Which action should the engineer take to improve security?

A.Remove the management account from the organization.
B.Delete the management account and create a new one.
C.Create a new root user for the management account and delete the old one.
D.Enable multi-factor authentication (MFA) for the root user of the management account.
AnswerD

Enabling multi-factor authentication (MFA) on the management account's root user is a mandatory security best practice because the root user holds unrestricted permissions across the entire organization, including billing and the ability to close accounts. Without MFA, a compromised password or access key for the root user grants an attacker complete control of the organization's structure and member accounts. MFA forces a second authentication factor, mitigating password theft or phishing attacks on that critical identity.

Why this answer

The management account in AWS Organizations is the account that created the organization and has full administrative access. It is critical to secure this account, and enabling multi-factor authentication (MFA) for the root user is a fundamental security best practice. Option A is incorrect because you cannot remove the management account from the organization; it is the foundational account.

Option B is incorrect because you cannot delete the management account; you would need to delete the entire organization. Option C is incorrect because you cannot delete the root user; it is a built-in user that cannot be removed. Therefore, enabling MFA on the root user of the management account is the appropriate action to improve security.

1142
MCQmedium

A company uses AWS CloudTrail and wants to ensure that all log files are encrypted at rest using a customer-managed AWS KMS key. The CloudTrail trail is configured to use a KMS key, but some log files appear to be encrypted with the default Amazon S3 managed key (SSE-S3). What is the most likely cause?

A.The KMS key policy does not grant CloudTrail permission to use the key.
B.The CloudTrail trail is configured to use SSE-S3 instead of SSE-KMS.
C.The KMS key is in a different AWS region than the S3 bucket.
D.The S3 bucket has default encryption set to SSE-S3.
AnswerA

The KMS key policy is the most likely root cause. When a trail is configured with SSE-KMS, CloudTrail must call kms:GenerateDataKey and kms:Decrypt on the customer-managed key to encrypt and decrypt log files. If the key policy does not grant these permissions to the `cloudtrail.amazonaws.com` service principal, CloudTrail cannot use that key and silently falls back to encrypting the log files with SSE-S3, which is exactly the observed behavior. You must add a policy statement that allows CloudTrail to use the key, and you may also need to grant the CloudTrail IAM role the corresponding kms:Decrypt permission.

Why this answer

The most likely cause is that the KMS key policy does not grant CloudTrail the necessary permissions to use the key for encryption. When a CloudTrail trail is configured with a customer-managed KMS key, the key policy must include a statement that allows the CloudTrail service principal (cloudtrail.amazonaws.com) to perform the kms:GenerateDataKey and kms:Decrypt actions. Without these permissions, CloudTrail falls back to encrypting log files with the default Amazon S3 managed key (SSE-S3), resulting in some logs appearing encrypted with SSE-S3 instead of SSE-KMS.

Exam trap

The trap here is that candidates often assume the S3 bucket's default encryption setting (SSE-S3) overrides the trail's KMS configuration, but in reality, CloudTrail explicitly requests encryption and only falls back to SSE-S3 when the KMS key cannot be used due to permission issues.

How to eliminate wrong answers

Option B is wrong because if the CloudTrail trail were configured to use SSE-S3 instead of SSE-KMS, then all log files would be encrypted with SSE-S3, not just some; the question states that some log files appear encrypted with SSE-S3, indicating a partial failure rather than a misconfiguration. Option C is wrong because CloudTrail and KMS keys can be in different regions as long as the S3 bucket is in the same region as the trail; cross-region KMS key usage is supported and would not cause a fallback to SSE-S3. Option D is wrong because S3 bucket default encryption settings do not override the encryption specified by CloudTrail; CloudTrail explicitly requests encryption using the configured KMS key, and if that fails, it falls back to SSE-S3, not because of bucket-level default encryption.

1143
MCQmedium

A company stores sensitive data in an Amazon S3 bucket. They want to ensure that data is encrypted in transit when accessed from the internet. Which policy should they attach to the bucket?

A.{"Effect": "Deny", "Principal": "*", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"StringNotEquals": {"aws:SourceVpc": "vpc-12345"}}}
B.{"Effect": "Allow", "Principal": "*", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"Bool": {"aws:SecureTransport": "false"}}}
C.{"Effect": "Deny", "Principal": "*", "Action": "s3:*", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"Bool": {"aws:SecureTransport": "false"}}}
D.{"Effect": "Deny", "Principal": "*", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"IpAddress": {"aws:SourceIp": "0.0.0.0/0"}}}
AnswerC

This is the correct policy because it denies all S3 actions (s3:*) when the request is not using secure transport, as indicated by aws:SecureTransport being false. By using Deny on the entire action set and the Bool condition, it ensures that any request over HTTP is rejected, while HTTPS requests remain unaffected. This is the standard AWS recommended pattern for enforcing encryption in transit on an S3 bucket.

Why this answer

It uses a Deny effect with the aws:SecureTransport condition set to 'false', which explicitly blocks any request that does not use HTTPS/TLS. This ensures that all S3 operations (s3:*) on the bucket objects require encryption in transit, as any HTTP request will be denied. The Deny effect overrides any Allow, making this a robust policy to enforce encrypted access from the internet.

Exam trap

The trap here is that candidates often choose an Allow policy (like Option B) thinking it will permit only encrypted traffic, but they forget that an Allow with a condition does not block unencrypted requests—only a Deny can explicitly block them, and the condition must be inverted (e.g., 'false' to block HTTP).

How to eliminate wrong answers

Option A is wrong because it restricts access based on the source VPC (aws:SourceVpc), which controls network origin but does not enforce encryption in transit; requests from outside the VPC could still use HTTP. Option B is wrong because it uses an Allow effect with aws:SecureTransport set to 'false', which would allow only unencrypted requests (the opposite of the requirement) and also fails to deny encrypted requests. Option D is wrong because it denies requests from all IP addresses (0.0.0.0/0), which would block all internet traffic regardless of encryption, rather than selectively enforcing HTTPS.

1144
MCQeasy

A company uses AWS Organizations with multiple accounts. The security team wants to enforce that all Amazon S3 buckets across the organization have server-side encryption (SSE-S3 or SSE-KMS) enabled. Which approach should be used to enforce this policy?

A.Create an S3 bucket policy in each account to deny access to unencrypted buckets.
B.Use AWS Config rules to detect buckets without encryption and send alerts.
C.Create an IAM role in each account that requires encryption when creating buckets.
D.Create a service control policy (SCP) that denies s3:CreateBucket if the bucket does not have encryption enabled.
AnswerD

An SCP in AWS Organizations can apply a deny to s3:CreateBucket for every principal in the organization by using the condition key s3:x-amz-server-side-encryption to require an encryption header such as AES256 or aws:kms. Because service control policies are evaluated before any IAM policy and apply across the root, OU, or account level, they act as a centrally managed preventive control that blocks the creation of unencrypted buckets in all member accounts. With the correct condition, any request that omits or misconfigures the encryption parameter will be denied, meeting the company's objective.

Why this answer

Service Control Policies (SCPs) in AWS Organizations allow you to centrally deny API actions across all accounts. By creating an SCP that denies `s3:CreateBucket` unless the request includes encryption parameters (SSE-S3 or SSE-KMS), you enforce encryption at the point of bucket creation, preventing non-compliant buckets from ever being created. This is the only approach that proactively enforces the policy across the entire organization, rather than relying on detection or per-account configurations.

Exam trap

The trap here is that candidates often confuse detective controls (like AWS Config) with preventive controls (like SCPs), or assume that bucket policies or IAM roles can enforce encryption at creation time, when only SCPs can centrally deny the API call across an entire organization.

How to eliminate wrong answers

Option A is wrong because S3 bucket policies control access to existing buckets, not the creation of buckets; they cannot prevent an unencrypted bucket from being created. Option B is wrong because AWS Config rules are detective, not preventive; they can alert on non-compliant buckets but do not enforce encryption at creation time. Option C is wrong because IAM roles are per-account and cannot enforce a policy across all accounts in an organization; additionally, IAM roles control who can create buckets but do not enforce encryption requirements on the bucket itself.

1145
MCQeasy

A security engineer needs to generate a report of all AWS Identity and Access Management (IAM) users who have not used their access keys in the last 90 days. Which AWS service can provide this information?

A.AWS IAM Credentials Report
B.AWS CloudTrail
C.Amazon GuardDuty
D.AWS Config
AnswerA

The AWS IAM Credentials Report is a built-in console or API-generated CSV that inventories every IAM user and the root user, listing each access key's ID, status, creation date, and the exact date and time it was last used. This report is the authoritative source for producing a usage report because it directly provides last-used timestamps without requiring log mining. Generating it is a single action, and it can be refreshed on demand to reflect the most recent activity.

Why this answer

AWS IAM Credentials Report provides a CSV file with details about IAM users, including last activity dates. Option B is wrong because AWS CloudTrail logs API calls but does not provide a summary report. Option C is wrong because Amazon GuardDuty does not track IAM key usage.

Option D is wrong because AWS Config evaluates configurations, not usage.

1146
Multi-Selecteasy

A security engineer needs to detect and respond to malware on an EC2 instance. Which TWO AWS services can be used together to achieve this? (Choose TWO.)

Select 2 answers
A.Amazon Inspector
B.AWS Lambda
C.Amazon CloudWatch
D.AWS WAF
E.Amazon GuardDuty with Malware Protection
AnswersB, E

AWS Lambda is correct for the response side of the detect-and-respond workflow. You can configure Lambda as the target of an Amazon GuardDuty finding through EventBridge rules, then execute a custom response playbook—such as isolating the EC2 instance by detaching security groups, stopping the instance, or capturing a forensic snapshot. This serverless execution gives security teams a fast, reproducible, and policy-driven way to contain malware without provisioning a dedicated incident-response server.

Why this answer

AWS Lambda is correct because it can be used as a serverless compute target to automate incident response actions when malware is detected. For example, a Lambda function can be triggered by a GuardDuty finding to isolate the compromised EC2 instance by modifying security group rules or detaching the instance from an Auto Scaling group, enabling rapid, automated remediation without manual intervention.

Exam trap

The trap here is that candidates often confuse Amazon Inspector's vulnerability scanning with malware detection, or assume CloudWatch alone can perform automated incident response, when in fact GuardDuty's Malware Protection is the only AWS-native service that directly detects malware on EC2, and Lambda is required for automated remediation.

1147
Multi-Selecteasy

A company uses AWS Systems Manager Session Manager to provide SSH access to EC2 instances without needing to open inbound ports. The security team wants to ensure that all session activity is logged and that only authorized users can start sessions. Which combination of actions should be taken? (Choose TWO.)

Select 2 answers
A.Configure the EC2 instances to require SSH key pairs for authentication.
B.Enable AWS CloudTrail to log StartSession API calls.
C.Enable VPC Flow Logs to monitor network traffic.
D.Create IAM policies that allow the ssm:StartSession action only for specific users or roles.
E.Use security groups to restrict inbound traffic to the Session Manager endpoints.
AnswersB, D

CloudTrail is the correct choice because it records StartSession API calls as management events, capturing the IAM principal, source IP, and timestamp of each session request. This gives you a detective control to answer who initiated a session and when, which is essential for security auditing and alerting on unusual activity.

Why this answer

Option B is correct because Session Manager records session activity through the StartSession API, and enabling AWS CloudTrail captures those API calls for auditing who started sessions and when. Option D is correct because IAM policies scoping the ssm:StartSession action to specific users or roles enforce authorization, ensuring only approved principals can initiate sessions. Option A is incorrect because Session Manager does not rely on SSH key pairs; it uses the SSM Agent and IAM credentials, so requiring SSH keys does not meet the logging or authorization goal.

Option C is incorrect because VPC Flow Logs capture IP traffic metadata, not the session-level activity or API authorization events the team needs. Option E is incorrect because Session Manager is designed to avoid inbound ports and security groups restricting inbound traffic to Session Manager endpoints is neither required nor how access control is enforced.

Exam trap

Candidates may think that VPC Flow Logs or security groups are needed for Session Manager, but Session Manager is designed to avoid inbound ports and uses IAM and CloudTrail for access control and logging.

1148
MCQeasy

A company wants to allow an IAM user to list only the objects in a specific S3 bucket named 'my-bucket'. Which IAM policy statement should be used?

A.{"Effect":"Allow","Action":"s3:GetObject","Resource":"arn:aws:s3:::my-bucket/*"}
B.{"Effect":"Allow","Action":"s3:ListBucket","Resource":"arn:aws:s3:::my-bucket"}
C.{"Effect":"Allow","Action":"s3:ListBucket","Resource":"arn:aws:s3:::my-bucket/*","Condition":{"StringEquals":{"s3:prefix":""}}}
D.{"Effect":"Allow","Action":"s3:*","Resource":"arn:aws:s3:::my-bucket/*"}
AnswerB

This is the correct least-privilege policy because s3:ListBucket is the only permission needed to list the objects in a bucket, and it must be applied to the bucket ARN (arn:aws:s3:::my-bucket). Unlike object-level actions such as GetObject, ListBucket is evaluated against the bucket resource itself, so adding an object-path wildcard would make the ARN invalid. This statement grants exactly the ability to list keys and nothing else, such as reading or writing object contents.

Why this answer

The s3:ListBucket action operates on the bucket itself, so the Resource must be the bucket ARN without the /* wildcard: arn:aws:s3:::my-bucket. This grants permission to list objects in that specific bucket only. The /* suffix is used for object-level actions like s3:GetObject, not for ListBucket.

Exam trap

The trap is mixing up bucket-level and object-level ARNs — candidates often append /* to ListBucket or use GetObject when the requirement is to list objects, confusing 'listing' with 'reading'.

How to eliminate wrong answers

Option A is wrong because s3:GetObject is an object-level action that grants read access to object contents, not the ability to list objects, and its resource uses the /* wildcard. Option C is wrong because while it uses s3:ListBucket, the resource ARN includes /* (which is incorrect for bucket-level actions) and the condition with an empty s3:prefix is unnecessary and does not match the requirement. Option D is wrong because s3:* on the object ARN grants all object-level actions (including delete, put) but not ListBucket, and it is overly permissive.

1149
MCQeasy

A company needs to audit all changes to IAM policies in their AWS account for compliance. Which AWS service should be enabled to record the API calls that modify IAM policies?

A.Amazon CloudWatch Logs
B.AWS Config
C.AWS CloudTrail
D.VPC Flow Logs
AnswerC

AWS CloudTrail is the native service that records management events in the AWS control plane, including every IAM policy change such as PutRolePolicy, AttachUserPolicy, and DeletePolicy. Each event includes the requesting principal, source IP, timestamp, and request/response details, giving you a complete audit trail. You can configure a trail to deliver these logs to S3 or CloudWatch Logs for long-term storage, analysis, and alerting on unauthorized IAM modifications.

Why this answer

AWS CloudTrail records API activity in an AWS account, including all calls that modify IAM policies such as CreatePolicy, PutRolePolicy, AttachRolePolicy, and DeletePolicy. Enabling CloudTrail (which is on by default for management events) provides the audit trail of who made the change, when, and from where. This is the correct service for auditing IAM policy modifications.

Exam trap

SCS-C02 often tests the difference between CloudTrail (who did what API call) and AWS Config (what the resource configuration was) — candidates confuse 'audit API calls' with 'track configuration changes' and pick AWS Config.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs is a log storage and analysis service — it can receive CloudTrail logs, but it does not itself record API calls that modify IAM policies. Option B is wrong because AWS Config records resource configuration changes and evaluates compliance, but it does not provide the API-level audit trail of who made the change; Config shows the before/after state, not the API caller identity. Option D is wrong because VPC Flow Logs capture IP traffic metadata (source/destination IP, port, protocol) for network interfaces, not AWS API calls.

1150
MCQhard

During an incident, a security engineer needs to isolate a compromised Amazon EC2 instance without losing the ability to capture forensic data from its EBS volumes. What is the best course of action?

A.Terminate the instance immediately and take a snapshot after termination.
B.Take a snapshot of the EBS volumes, then detach the instance from the Auto Scaling group and modify the security group to deny all traffic.
C.Stop the instance, detach the volumes, and attach them to a forensic instance.
D.Change the security group to restrict traffic to only the forensic team's IP addresses.
AnswerB

This is the correct order: first snapshot the EBS volumes to preserve point-in-time disk evidence before any destructive or state-changing action occurs, then detach the instance from the Auto Scaling group so it won't be terminated or replaced by the group, and finally modify the security group by removing all inbound and outbound allow rules to block all network traffic and isolate the host.

Why this answer

Taking a snapshot of the EBS volumes preserves the forensic data before any changes occur, while detaching the instance from the Auto Scaling group prevents automatic replacement, and modifying the security group to deny all traffic isolates the instance without losing the running state or the ability to capture additional volatile data. This approach balances isolation with forensic preservation, ensuring the instance remains available for further analysis if needed.

Exam trap

The trap here is that candidates often confuse 'stopping' an instance with 'isolating' it, not realizing that stopping triggers OS shutdown processes that can destroy volatile evidence, whereas modifying the security group to deny all traffic achieves isolation without altering the instance state.

How to eliminate wrong answers

Option A is wrong because terminating the instance destroys the running state and any volatile data (e.g., memory, process list), and while a snapshot can be taken after termination, the EBS volumes may have been altered or deleted, losing critical forensic evidence. Option C is wrong because stopping the instance clears the instance store (if used) and may trigger OS-level shutdown scripts that could overwrite or delete forensic data; detaching volumes and attaching them to a forensic instance is a valid step but should be done after taking a snapshot to ensure a point-in-time copy, and stopping the instance is unnecessary and risky. Option D is wrong because restricting traffic to only the forensic team's IP addresses does not fully isolate the instance from lateral movement or external threats; the instance remains accessible and could still be compromised or used as a pivot point, and it does not prevent the instance from being terminated or altered by an attacker.

1151
MCQeasy

A security engineer needs to ensure that all data stored in a new Amazon DynamoDB table is encrypted at rest using a key that the company can manage, audit, and rotate. The company also wants to receive alerts if the key is used in an unauthorized way. Which solution meets these requirements with the LEAST operational effort?

A.Use AWS KMS customer managed keys with DynamoDB encryption at rest.
B.Use AWS CloudHSM to generate and store keys, and integrate with DynamoDB encryption.
C.Enable DynamoDB encryption at rest with AWS owned keys.
D.Implement client-side encryption using a key stored in AWS Secrets Manager.
AnswerA

DynamoDB encryption at rest integrates with AWS KMS, allowing the use of customer managed keys. This provides control over key policies, enables auditing via AWS CloudTrail, and supports automatic rotation. It requires minimal operational effort because DynamoDB manages the encryption and decryption transparently, and KMS handles key management, meeting all requirements.

Why this answer

AWS KMS customer managed keys with DynamoDB encryption at rest provide customer control, auditability through CloudTrail, and automatic rotation with minimal effort. AWS owned keys lack customer control and auditing. Client-side encryption with Secrets Manager or CloudHSM introduces extra operational burden and does not integrate natively with DynamoDB encryption at rest.

Exam trap

The trap here is thinking that AWS owned keys provide customer management, when they are fully managed by AWS and cannot be audited or rotated by the customer.

1152
MCQeasy

Refer to the exhibit. A security engineer runs this CloudWatch Logs Insights query on a log group. What is the purpose of this query?

A.Retrieve the 20 most recent log events that contain only 'ERROR'.
B.Retrieve the 20 most recent log events that contain 'ERROR' or 'WARN'.
C.Display all log events grouped by log level.
D.Count the number of ERROR and WARN events in the last hour.
AnswerB

This is correct because the CloudWatch Logs Insights query uses `filter @message like /ERROR|WARN/` to match any log event containing either substring, and then `sort @timestamp desc | limit 20` orders by timestamp descending and returns the 20 newest matching events. That combination of a regex-style filter and a descending sort with a limit accomplishes exactly the stated goal, making it the only option that describes what the exhibited query does.

Why this answer

The CloudWatch Logs Insights query uses `filter @message like /(?i)(ERROR|WARN)/` to match log events containing either 'ERROR' or 'WARN' (case-insensitive), then `sort @timestamp desc` orders them by most recent first, and `limit 20` restricts the output to the top 20 results. This retrieves the 20 most recent log events that contain either term, making option B correct.

Exam trap

The trap here is that candidates may overlook the regex alternation `(ERROR|WARN)` and assume the query only filters for 'ERROR', or they may misinterpret the `limit` and `sort` as performing a count or grouping operation.

How to eliminate wrong answers

Option A is wrong because the query uses a regex alternation `(ERROR|WARN)`, which matches events containing 'ERROR' or 'WARN', not only 'ERROR'. Option C is wrong because the query does not include any `stats count(*) by @logLevel` or similar aggregation to group events by log level; it simply filters and sorts raw log events. Option D is wrong because the query does not use a time range filter (e.g., `filter @timestamp > ...`) to restrict to the last hour, nor does it use `stats count(*)` to count events; it retrieves up to 20 events without counting.

1153
Multi-Selectmedium

A security engineer needs to monitor DNS query logs for malicious domain names. Which THREE services can be used together to collect, analyze, and alert on DNS logs? (Choose THREE.)

Select 3 answers
A.Amazon CloudWatch Logs
B.AWS Lambda
C.Amazon Route 53 Resolver Query Logs
D.Amazon GuardDuty
E.Amazon Athena
AnswersA, B, C

Amazon CloudWatch Logs acts as the aggregation and monitoring layer for Route 53 Resolver query logs. The resolver service can publish DNS query logs directly to a CloudWatch Logs log group, where you can create metric filters and subscription filters to detect suspicious queries. CloudWatch Logs supports near-real-time querying with Logs Insights, making it a central destination for ongoing monitoring.

Why this answer

Amazon Route 53 Resolver Query Logs (C) is the correct source because it captures DNS queries made by resources in a VPC, including the queried domain name, query type, and response code, which is exactly the raw DNS log data needed for detecting malicious domains. Amazon CloudWatch Logs (A) is correct because Resolver query logs can be published to a CloudWatch Logs log group, where they are stored and made available for metric filters, subscriptions, and retention management. AWS Lambda (B) is correct because a CloudWatch Logs subscription filter can stream matching log events to a Lambda function, which can then parse the DNS records, check domains against threat intelligence, and trigger alerts via SNS or other services.

Amazon GuardDuty (D) is not part of this collection/analysis/alerting pipeline for raw DNS query logs; it is a managed threat detection service that analyzes its own findings rather than ingesting and processing Resolver query logs for custom alerting. Amazon Athena (E) is a query service for data in S3 and, while it can analyze logs stored in S3, it is not one of the three services used together here to collect, process, and alert on DNS logs in this scenario.

Exam trap

The trap here is that candidates often confuse Amazon GuardDuty's DNS-based threat detection capabilities with the ability to directly collect and alert on custom DNS query logs, but GuardDuty operates on its own internal data sources and does not provide the same level of custom log monitoring and alerting as the combination of Route 53 Resolver Query Logs, CloudWatch Logs, and Lambda.

1154
Multi-Selecteasy

A company wants to monitor for unauthorized changes to security group rules in their VPC. Which TWO AWS services can be used together to detect and alert on such changes?

Select 2 answers
A.AWS CloudTrail
B.AWS Config
C.VPC Flow Logs
D.Amazon GuardDuty
E.Amazon Macie
AnswersA, B

AWS CloudTrail is the correct answer because it records management events for all API calls made in your account, including ec2:AuthorizeSecurityGroupIngress, ec2:RevokeSecurityGroupIngress, and ec2:CreateSecurityGroup. Each event captures the identity of the caller, the source IP address, and a timestamp, giving you full attribution for who changed a security group rule and when. This makes CloudTrail the go-to service for auditing who took a specific action against a security group, which directly answers the requirement to monitor for unauthorized changes.

Why this answer

AWS CloudTrail is correct because it records API calls made to the EC2 service, including AuthorizeSecurityGroupIngress, RevokeSecurityGroupEgress, and CreateSecurityGroup. By monitoring CloudTrail events for these specific API actions, you can detect unauthorized changes to security group rules. AWS Config is correct because it provides a managed rule called 'restricted-common-ports' or custom rules that can evaluate security group configurations against desired policies, and it can trigger alerts via Amazon SNS when a security group rule is changed.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (which show traffic) with CloudTrail (which shows API calls), or think GuardDuty monitors configuration changes when it actually focuses on threat detection in network and account activity.

1155
MCQhard

Refer to the exhibit. A security engineer is reviewing this CloudFormation template. What security risk is present in this configuration?

A.The template does not associate the security group with the instance, so the instance has no security group.
B.HTTP access is allowed from all IP addresses (0.0.0.0/0) which is a security risk.
C.SSH access is allowed from a large internal CIDR block (10.0.0.0/8) which could expose the instance to unnecessary internal threats.
D.The template uses SecurityGroups property instead of SecurityGroupIds, which is deprecated.
AnswerC

The 10.0.0.0/8 CIDR block is the entire RFC1918 Class A private address space, covering every possible 10.x.x.x network used by VPCs and internal environments. Opening SSH to this range allows any compromised host in that vast address space to attempt to connect to the instance, which is an unnecessary and overly permissive ingress rule. Best practice is to scope SSH to a specific management CIDR or single IP to maintain least privilege.

Why this answer

Allowing SSH (TCP port 22) from the entire 10.0.0.0/8 CIDR block is overly permissive. This range encompasses all RFC 1918 private addresses in the 10.x.x.x space, which could include many internal subnets, VPNs, or peered VPCs that do not require administrative access. Unnecessarily broad internal access increases the attack surface and violates the principle of least privilege.

Exam trap

The trap here is that candidates often focus on the obvious risk of opening SSH to 0.0.0.0/0, but the question tests whether they recognize that an overly broad internal CIDR (10.0.0.0/8) is also a significant security risk, especially when SSH is involved.

How to eliminate wrong answers

Option A is wrong because the SecurityGroups property in the AWS::EC2::Instance resource directly associates the security group by name or reference; the instance will have the specified security group attached. Option B is wrong because the template does not define any HTTP (port 80) ingress rule; the security group only allows SSH (port 22) and ICMP, so HTTP from 0.0.0.0/0 is not present. Option D is wrong because SecurityGroups is a valid property for EC2 instances in CloudFormation and is not deprecated; SecurityGroupIds is used when referencing security groups by ID, but both are supported.

1156
MCQmedium

Refer to the exhibit. A KMS key policy allows decryption only when the request comes through S3 in us-east-1. An application in account 111122223333 tries to decrypt an S3 object using the KMS key directly via the KMS API (not through S3). What will happen?

A.The decryption succeeds because the principal is the root user.
B.The decryption fails because the policy is invalid.
C.The decryption succeeds because the principal is allowed.
D.The decryption fails because the condition on kms:ViaService is not satisfied.
AnswerD

The key policy's Allow for kms:Decrypt is explicitly conditioned on kms:ViaService matching the S3 service endpoint, for example s3.us-east-1.amazonaws.com. When the call is made directly to KMS or through any service other than S3, that condition key does not match. Since the condition is false, the Allow is not applied and KMS returns AccessDenied. The decryption therefore fails precisely because the request did not come via Amazon S3.

Why this answer

The KMS key policy includes a condition that restricts decryption to requests that come through S3 in us-east-1, using the kms:ViaService condition key. When the application calls the KMS Decrypt API directly (not through S3), the kms:ViaService condition is not satisfied, so the request is denied. This is the intended behavior of the policy.

Exam trap

SCS-C02 often tests the kms:ViaService condition and candidates may assume that having kms:Decrypt permission is enough, forgetting that the condition must be satisfied.

How to eliminate wrong answers

Option A is wrong because being the root user does not bypass explicit deny conditions in a key policy; the policy's condition still applies. Option B is wrong because the policy is valid — it correctly uses the kms:ViaService condition key, which is a supported feature. Option C is wrong because the principal being allowed is not sufficient; the condition on kms:ViaService must also be met, and it is not when calling KMS directly.

1157
MCQmedium

Refer to the exhibit. An IAM policy is attached to a group. An IAM user in that group attempts to stop an EC2 instance from IP address 198.51.100.10. What will happen?

A.The action is allowed because the first statement allows StopInstances
B.The action is allowed because the resource is '*'
C.The action is denied because the source IP does not match the allowed range
D.The action is denied only if the user is not using MFA
AnswerC

The Deny statement blocks requests from IPs not in the allowed range.

Why this answer

The IAM policy includes a `Deny` statement with a `NotIpAddress` condition that restricts all actions (including `StopInstances`) to the IP range `10.0.0.0/8`. Since the user's source IP is `198.51.100.10`, which falls outside this range, the deny statement explicitly blocks the action. In IAM, an explicit deny always overrides any allow, so the request is denied regardless of the allow statement in the first policy block.

Exam trap

The trap here is that candidates assume the allow statement with `Effect: Allow` and `Action: ec2:StopInstances` will grant permission, forgetting that an explicit deny with a condition that does not match the request context takes precedence over any allow.

How to eliminate wrong answers

Option A is wrong because the explicit deny statement with the `NotIpAddress` condition overrides the allow statement; IAM evaluates deny before allow, and an explicit deny cannot be bypassed by a separate allow. Option B is wrong because while the resource is `*`, the deny statement applies to all resources and actions, and the condition key `aws:SourceIp` is evaluated against the source IP, not the resource ARN. Option D is wrong because the policy does not include any condition requiring MFA (`aws:MultiFactorAuthPresent`); the denial is based solely on the source IP mismatch.

1158
MCQeasy

A company is using Amazon S3 to store confidential documents. They want to ensure that all data is encrypted in transit between the S3 bucket and their on-premises application. Which of the following should be enforced?

A.Add a bucket policy that denies access unless 'aws:SecureTransport' is true.
B.Use Amazon CloudFront with a custom origin pointing to the S3 bucket.
C.Use a VPC endpoint for S3.
D.Enable default encryption (SSE-S3) on the bucket.
AnswerA

The aws:SecureTransport condition key evaluates the request's protocol, so denying when it is false blocks any plain HTTP request to the bucket. This enforces TLS for data in transit between the on-premises application and S3.

Why this answer

A bucket policy that denies requests unless `aws:SecureTransport` is true enforces TLS for all access to the bucket, including from on-premises applications. This is the canonical AWS pattern for requiring encryption in transit to S3. The other options either do not enforce TLS or address different concerns (encryption at rest, network path).

Exam trap

SCS-C02 often tests whether candidates conflate encryption at rest (SSE-S3) with encryption in transit, or assume a VPC endpoint enforces TLS — only the `aws:SecureTransport` bucket policy condition actually does.

How to eliminate wrong answers

Option B is wrong because CloudFront with a custom origin does not by itself enforce TLS between the origin (S3) and the on-premises application — it only affects the client-to-CloudFront leg and does not guarantee HTTPS to S3. Option C is wrong because a VPC endpoint provides private network connectivity from a VPC to S3 but does not enforce TLS; traffic over a VPC endpoint can still be HTTP unless the bucket policy requires SecureTransport. Option D is wrong because SSE-S3 provides encryption at rest, not in transit, and does nothing to require TLS for data moving between the bucket and on-premises systems.

1159
Multi-Selectmedium

Which TWO actions should a security engineer take to investigate a potential AWS API credential leak? (Choose two.)

Select 2 answers
A.Use AWS CloudTrail to review API calls made with the compromised keys.
B.Change the IAM user's password.
C.Disable all AWS services in the account.
D.Immediately rotate the compromised access keys.
E.Delete the IAM user and recreate it with the same permissions.
AnswersA, D

AWS CloudTrail is the authoritative audit service that records API calls made in your account, including the exact access key ID that signed each request. By querying CloudTrail events with the compromised access key ID, a security engineer can reconstruct the attacker's actions, identify which AWS resources were accessed or modified, and determine the scope of potential data exposure. This read-only forensic step does not alter the environment and should be performed immediately to capture evidence while the trail is still available.

Why this answer

AWS CloudTrail logs all API calls made within an AWS account, including those using compromised access keys. By reviewing these logs, a security engineer can identify the scope of the breach, such as which resources were accessed, from which IP addresses, and at what times. This is a critical first step in incident response to understand the impact and gather forensic evidence.

Exam trap

The trap here is that candidates often confuse 'rotating the keys' with 'changing the password' (Option B), not realizing that access keys and passwords are independent credentials, and that immediate rotation (Option D) is the correct containment action alongside forensic investigation (Option A).

1160
MCQmedium

During a security incident, a security engineer needs to verify whether an EC2 instance's security group allowed inbound SSH from a specific IP address at the time of the incident. Which AWS service or feature should the engineer use to obtain this historical information?

A.Amazon CloudTrail event history.
B.AWS Systems Manager Inventory.
C.VPC Flow Logs.
D.AWS Config configuration history.
AnswerD

AWS Config configuration history is the correct choice because it records the complete configuration of supported AWS resources, including security groups, whenever a change occurs. Each configuration item is timestamped, so you can retrieve the exact set of security group rules at any point in time, including during the incident. This provides a reliable, auditable point-in-time state without needing to reconstruct it from API calls or traffic logs.

Why this answer

AWS Config configuration history records changes to security group rules, including the addition or removal of inbound SSH allow rules. By querying the configuration history for the specific security group, the engineer can determine the exact state of the rules at the time of the incident, including whether a specific IP address was allowed. This is the only service that provides a historical record of security group rule configurations.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (which show traffic) with security group configuration history, but Flow Logs only show whether traffic was permitted or denied based on the rules at that time, not the rules themselves.

How to eliminate wrong answers

Option A is wrong because CloudTrail event history logs API calls (e.g., AuthorizeSecurityGroupIngress) but does not capture the actual state of the security group rules at a point in time; it only shows when changes were made, not the current or historical configuration. Option B is wrong because AWS Systems Manager Inventory collects software and configuration data from managed instances, not security group rule history. Option C is wrong because VPC Flow Logs capture network traffic metadata (source/destination IP, port, protocol) but do not record security group rule configurations; they show traffic that was allowed or denied, not the rules themselves.

1161
MCQhard

A company wants to audit all API calls made to Amazon S3 within a specific AWS account. Which combination of services should be used to meet this requirement?

A.AWS CloudTrail and Amazon CloudWatch Logs.
B.Amazon Inspector and Amazon CloudWatch Logs.
C.Amazon GuardDuty and Amazon CloudWatch Logs.
D.AWS Config and Amazon CloudWatch Logs.
AnswerA

Amazon CloudTrail is the authoritative source for S3 API activity, capturing both management events (e.g., CreateBucket, DeleteBucket) and, when enabled, data events for object-level actions such as PutObject, GetObject, and DeleteObject. By delivering those CloudTrail logs to Amazon CloudWatch Logs, you can create metric filters and alarms for real-time monitoring of API calls, making this the correct combination for a complete S3 audit trail.

Why this answer

AWS CloudTrail is the service that records all API calls made to Amazon S3 (and other AWS services) within an AWS account, capturing details such as the identity of the caller, the time of the call, the source IP address, and the request parameters. By delivering these logs to Amazon CloudWatch Logs, you can monitor, search, and set alarms on the API activity in real time, enabling comprehensive auditing of S3 operations.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks configuration changes) with CloudTrail (which tracks API calls), leading them to select Option D, but only CloudTrail provides the detailed audit trail of API activity required for this use case.

How to eliminate wrong answers

Option B is wrong because Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, not a service that records API calls. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes logs (like VPC Flow Logs and DNS logs) for malicious activity, but it does not itself capture or audit API calls to S3. Option D is wrong because AWS Config is a service that evaluates resource configurations against desired policies and tracks configuration changes, not API call history.

1162
MCQmedium

A DevOps engineer notices that an EC2 instance's CloudWatch agent is not sending custom metrics to CloudWatch. The agent is installed and the configuration file is valid. The instance has an IAM role attached. What is the most likely reason for the failure?

A.The instance does not have internet access to reach CloudWatch endpoints.
B.The CloudWatch agent is not running as root.
C.The CloudWatch agent configuration file has a syntax error.
D.The IAM role attached to the instance does not have the cloudwatch:PutMetricData permission.
AnswerD

The CloudWatch agent needs IAM permissions to publish metrics to CloudWatch; specifically, the instance's attached IAM role must include cloudwatch:PutMetricData. The managed policy CloudWatchAgentServerPolicy grants this permission, and without it the agent can collect data but every publish attempt is denied by CloudWatch, resulting in no metrics appearing in the console.

Why this answer

The CloudWatch agent requires IAM permissions to publish custom metrics. Even if the agent is installed, running, and has a valid configuration, it will fail to send metrics if the attached IAM role lacks the `cloudwatch:PutMetricData` action. This is a common misconfiguration where the instance has an IAM role, but the role's policy does not explicitly grant the necessary CloudWatch write permissions.

Exam trap

The trap here is that candidates assume internet access is required for CloudWatch communication, but AWS services can be reached via VPC endpoints or private links without internet, and the question's focus on IAM permissions is the key differentiator.

How to eliminate wrong answers

Option A is wrong because the CloudWatch agent can send metrics to CloudWatch endpoints via the AWS public endpoint or a VPC endpoint (e.g., com.amazonaws.region.monitoring) without requiring general internet access; the instance only needs network connectivity to the specific CloudWatch service endpoint, which can be achieved through a VPC endpoint or NAT gateway. Option B is wrong because the CloudWatch agent does not require root privileges to run; it can run as any user with appropriate permissions, and the agent's default installation runs as the `cwagent` user. Option C is wrong because the question explicitly states that the configuration file is valid, eliminating syntax errors as the cause.

1163
MCQmedium

A company uses AWS IAM Identity Center (SSO) for managing access to multiple AWS accounts. A user reports that they can log in to the SSO portal but cannot see any AWS accounts in their dashboard. What is the most likely cause?

A.The user has not been assigned to any AWS accounts in IAM Identity Center.
B.The user's identity source (e.g., Active Directory) is not synchronized correctly.
C.The user's session token has expired.
D.The permission set assigned to the user does not grant any permissions.
AnswerA

This is correct because the user successfully authenticated to IAM Identity Center (the portal loaded and they can log in), but the portal only displays AWS accounts to which the user has been explicitly granted access. In IAM Identity Center, administrators must create an account assignment that pairs a principal (user or group) with a permission set for a specific AWS account. If no such assignment exists for this user, the login succeeds but the account list is empty, so the user sees no accounts to choose from.

Why this answer

In IAM Identity Center, users see AWS accounts in their portal only if they have been assigned to those accounts via account assignments (which link a user/group, a permission set, and an AWS account). If no account assignments exist, the user can authenticate successfully but will see an empty dashboard. This is the most common cause of the reported symptom.

Exam trap

SCS-C02 often tests the distinction between authentication (can I log in?) and authorization (what can I see/do?) — a successful login with an empty dashboard points to missing assignments, not auth failure.

How to eliminate wrong answers

Option B is wrong because identity source synchronization issues typically prevent login or cause missing user attributes, not a successful login with an empty account list. Option C is wrong because an expired session token would prevent portal access entirely, not just hide accounts. Option D is wrong because a permission set with no permissions would still show the account in the dashboard — the user would just get access-denied errors when trying to use it.

1164
MCQmedium

A security engineer is configuring a VPC flow log to detect unusual traffic patterns. The engineer notices that some traffic between two EC2 instances in the same VPC appears in the flow logs as NODATA records, and other connections appear as REJECT records. The engineer must determine what each record type indicates before building detections. Which statement correctly describes the difference?

A.NODATA indicates that a security group blocked the traffic, while REJECT indicates that a network ACL blocked the traffic.
B.NODATA indicates that no traffic matched the flow log record during the aggregation interval, while REJECT indicates that traffic was present but was blocked by a security group or network ACL.
C.NODATA indicates that traffic was rejected by an AWS WAF rule, while REJECT indicates that traffic was allowed by a security group.
D.NODATA indicates that the flow log was disabled for the resource, while REJECT indicates that the destination port was unreachable.
AnswerB

NODATA means the capture window closed with no matching packets, which is common for flows that are logging only accepted or only rejected traffic. REJECT means packets were observed but denied by a security group, network ACL, or similar control, so the connection attempt is visible in the record.

Why this answer

VPC flow logs emit ACCEPT, REJECT, and NODATA records. A REJECT record means packets were seen but denied, typically by a security group or network ACL, while NODATA means the aggregation interval elapsed with no matching packets captured, which is useful for confirming that a monitored flow simply never occurred.

Exam trap

The trap here is reading NODATA as evidence of a blocked connection, when it actually only indicates that no matching traffic was observed in the interval.

1165
MCQhard

A security engineer is designing an incident response plan for a containerized application running on Amazon ECS with Fargate. The engineer needs to ensure that if a container is compromised, the incident response team can capture a memory dump and disk snapshot for forensic analysis. The containers are stateless and use ephemeral storage. Which approach provides the necessary forensic data?

A.Configure the container to stream /dev/mem to CloudWatch Logs.
B.Enable ECS task memory dumps to CloudWatch Logs.
C.Use ECS Exec to access the container and capture a memory dump; snapshot the task's ephemeral storage.
D.Stop the task and create a new task from the same image.
AnswerC

ECS Exec uses the ExecuteCommand API to open an interactive shell in a running container without opening inbound ports, allowing you to run forensic utilities like 'dd' or 'gcore' to capture volatile memory from inside the container's PID namespace. Before the task is stopped, you can also snapshot the task's ephemeral storage by copying files to an external volume or using an EBS-optimized instance to preserve the disk state. This preserves both volatile and persistent evidence, unlike stopping the task first.

Why this answer

ECS Exec allows interactive access to a running container without stopping it, enabling the capture of a memory dump (e.g., via `gcore` or `/proc/kcore`). Additionally, the task's ephemeral storage can be snapshotted while the container is still running, preserving disk state for forensic analysis. This approach aligns with incident response best practices for stateless containers on Fargate, where traditional host-level forensics are unavailable.

Exam trap

The trap here is that candidates assume stopping the task (Option D) is safe because containers are stateless, but they overlook that forensic data (memory and ephemeral disk) is lost upon task termination, making live capture via ECS Exec (Option C) the only viable method.

How to eliminate wrong answers

Option A is wrong because `/dev/mem` is not accessible in Fargate containers (no kernel-level access) and streaming it to CloudWatch Logs would not produce a usable memory dump; CloudWatch Logs is for log data, not binary forensic artifacts. Option B is wrong because ECS does not have a native feature to send task memory dumps to CloudWatch Logs; memory dumps require explicit capture via tools like `gcore` or `dd` from within the container. Option D is wrong because stopping the task destroys the ephemeral storage and the container's memory, losing all forensic evidence; creating a new task from the same image provides no snapshot of the compromised state.

1166
MCQeasy

A security engineer needs to audit all IAM role creations across an AWS account. Which AWS service should be used to log these API calls?

A.Amazon GuardDuty
B.AWS Config
C.Amazon CloudWatch Logs
D.AWS CloudTrail
AnswerD

AWS CloudTrail is the correct choice because it is the native AWS service for recording management events such as the CreateRole API call, capturing the requesting IAM principal, source IP, request parameters, and timestamp. By default, CloudTrail logs management events for all IAM actions, and you can deliver these logs to an S3 bucket or CloudWatch Logs for long-term retention and analysis. This makes CloudTrail the authoritative audit trail for answering 'who created this IAM role and when'.

Why this answer

AWS CloudTrail records all API calls made in an AWS account, including IAM role creation events (CreateRole). CloudTrail captures the identity of the caller, the time, source IP, and request parameters, making it the authoritative audit log for API activity. GuardDuty, Config, and CloudWatch Logs do not provide a complete API call history for IAM actions.

Exam trap

SCS-C02 often tests the confusion between CloudTrail (API activity auditing) and AWS Config (resource configuration history), causing candidates to pick Config for 'audit all IAM role creations' when the question asks for API call logging.

How to eliminate wrong answers

Option A is wrong because GuardDuty is a threat detection service that analyzes logs for malicious activity; it does not log every API call or provide an audit trail of IAM role creations. Option B is wrong because AWS Config records resource configuration changes and compliance, but it does not capture the full API call details (who made the call, from where) for IAM role creation events. Option C is wrong because CloudWatch Logs is a log storage and monitoring service; it does not natively capture AWS API calls unless CloudTrail is configured to send them there.

1167
MCQmedium

A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no IAM user in any account can create access keys. Which policy type should be used to enforce this restriction across all accounts?

A.IAM identity-based policy
B.Resource-based policy
C.Permissions boundary
D.Service Control Policy (SCP)
AnswerD

Service Control Policies (SCPs) are organization policies attached to the AWS Organizations root, an organizational unit, or an individual account, and they apply to every IAM principal—including the root user—within the affected accounts. An explicit Deny in an SCP overrides any Allow generated by identity-based, resource-based, or permissions-boundary policies, but an SCP itself never grants permissions. This makes SCP the correct choice for an account-wide, centrally managed restriction that cannot be bypassed by individual principals.

Why this answer

Service Control Policies (SCPs) in AWS Organizations define the maximum permissions for all IAM principals in member accounts. An SCP that denies the iam:CreateAccessKey action applied at the organization or OU level prevents any IAM user in any account from creating access keys, regardless of their identity-based policies. This is the correct mechanism for enforcing restrictions across all accounts.

Exam trap

SCS-C02 often tests the distinction between SCPs (organization-wide guardrails) and permissions boundaries (per-entity limits), so candidates who pick permissions boundaries miss the cross-account enforcement requirement.

How to eliminate wrong answers

Option A is wrong because IAM identity-based policies are attached to users, groups, or roles within a single account and cannot enforce a restriction across all accounts in an organization. Option B is wrong because resource-based policies are attached to resources (e.g., S3 buckets, KMS keys) and control who can access that resource — they cannot prevent the creation of access keys. Option C is wrong because a permissions boundary sets the maximum permissions for a single IAM entity (user or role) and must be attached per entity; it does not scale across an entire organization.

1168
MCQhard

A company is designing a data protection strategy for an Amazon RDS for MySQL database. The database is 2 TB in size and stores financial data. The compliance team requires that database snapshots be encrypted at rest and that encryption keys be rotated every year. Which solution meets these requirements with the LEAST operational overhead?

A.Copy each snapshot to a new snapshot encrypted with a new KMS key
B.Export snapshots to S3 and use S3 Batch Operations to re-encrypt them
C.Use a different KMS key for each snapshot and rotate the key manually
D.Enable automatic key rotation in AWS KMS for the KMS key used for RDS encryption
AnswerD

Enabling automatic key rotation in AWS KMS for the customer-managed KMS key used by RDS meets the data protection requirement with minimal operational overhead. AWS KMS rotates the cryptographic backing key each year while keeping the same KMS key ID, so the RDS instance, its storage, and all future snapshots continue using the same key reference with zero manual intervention. Existing data remains decryptable via the previous backing key, and new writes automatically use the new backing key, providing continuous protection.

Why this answer

Enabling automatic key rotation in AWS KMS for the KMS key used for RDS encryption meets the compliance requirement of yearly key rotation without any manual effort. RDS automatically uses the rotated key for new snapshots, and existing snapshots remain encrypted with the original key but can be decrypted with the new key as KMS maintains the key hierarchy. Option A is wrong because copying snapshots to re-encrypt with a new KMS key requires manual scripting and adds operational overhead.

Option B is wrong because exporting snapshots to S3 and using S3 Batch Operations is complex and unnecessary. Option C is wrong because using a different KMS key for each snapshot and manually rotating adds significant operational overhead and does not leverage the automatic rotation capability of KMS.

1169
Multi-Selecthard

A security engineer is investigating a potential compromise. The engineer has captured a memory dump from an EC2 instance and needs to analyze it for malware. Which TWO actions should the engineer take to preserve the chain of custody? (Choose TWO.)

Select 2 answers
A.Create an EBS snapshot of the instance's root volume.
B.Analyze the memory dump on the same EC2 instance.
C.Record the date, time, and digital signature of the acquisition.
D.Generate a cryptographic hash of the memory dump file.
E.Upload the memory dump to a public S3 bucket for analysis.
AnswersC, D

Recording the date, time, and digital signature of the acquisition is a cornerstone of establishing chain of custody, demonstrating exactly when the dump was taken and by whom. A digital signature binds the acquisition record to the responder and protects against later allegations that the evidence was fabricated or altered during collection. This documentation is distinct from, but complements, the hash verification that protects the integrity of the dump file itself.

Why this answer

Recording the date, time, and digital signature of the acquisition establishes a clear audit trail, which is essential for proving that the evidence has not been tampered with. In forensic investigations, this metadata is part of the standard chain-of-custody documentation that demonstrates who collected the evidence, when, and that it remains unaltered. A digital signature (e.g., using a tool like gpg or a signed hash) provides non-repudiation and integrity verification beyond a simple hash.

Exam trap

The trap here is that candidates confuse preserving the chain of custody with preserving the data itself, leading them to choose Option A (EBS snapshot) as a backup method, when in fact chain of custody is about documentation and integrity verification, not data preservation.

1170
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants a centralized view of all security alerts and findings from services like GuardDuty, Security Hub, and Inspector across all accounts. What is the MOST efficient way to achieve this?

A.Use AWS Systems Manager OpsCenter to centrally view all security findings.
B.Use individual service consoles (GuardDuty, Security Hub, Inspector) for each account.
C.Use Amazon CloudWatch Logs to collect logs from each account and create custom dashboards.
D.Use AWS Security Hub with cross-account aggregation in the management account.
AnswerD

AWS Security Hub cross-account aggregation in the management account consolidates findings from GuardDuty, Inspector and Security Hub across every member account into one pane, satisfying the centralized-view requirement. It uses the Organizations management account as the aggregation administrator, avoiding per-account tooling or duplicated dashboards.

Why this answer

AWS Security Hub is designed to aggregate findings from multiple security services (GuardDuty, Inspector, etc.) across accounts. By enabling cross-account aggregation in the management account of AWS Organizations, Security Hub provides a single, centralized dashboard for all security alerts and findings without needing to collect raw logs or build custom dashboards. This is the most efficient and native approach for a multi-account environment.

Exam trap

The trap here is that candidates may think CloudWatch Logs or OpsCenter are suitable for centralized security findings, but they lack the native cross-account aggregation and structured finding format that Security Hub provides, which is the most efficient and purpose-built solution.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager OpsCenter is primarily for operational issues and incident management, not for aggregating security findings from GuardDuty, Security Hub, or Inspector across accounts; it lacks native cross-account security finding aggregation. Option B is wrong because using individual service consoles for each account is inefficient and does not provide a centralized view; it requires manual logins and lacks cross-account aggregation. Option C is wrong because Amazon CloudWatch Logs can collect logs, but building custom dashboards for security findings is complex, requires additional parsing, and does not natively aggregate structured findings from GuardDuty, Security Hub, or Inspector as Security Hub does.

1171
MCQmedium

Refer to the exhibit. A security engineer runs the 'simulate-custom-policy' command to test a policy. The output shows 'explicitDeny' for ec2:RunInstances. What is the most likely reason?

A.The policy does not include ec2:RunInstances in the Action list
B.The policy includes an explicit Deny statement for ec2:RunInstances
C.The policy allows ec2:Describe* but the action ec2:RunInstances is not a Describe action
D.The policy uses a Resource of '*' which does not include the required resources
AnswerB

An explicit Deny statement always overrides any Allow in IAM policy evaluation. The simulate-custom-policy output returning explicitDeny confirms a matching Deny statement exists for ec2:RunInstances, so the request is blocked regardless of any Allow statements present.

Why this answer

In AWS IAM policy evaluation, an explicit Deny statement always overrides any Allow. The simulate-custom-policy command returns 'explicitDeny' when the action is explicitly denied by a Deny statement in the policy. Therefore, the most likely reason is that the policy includes an explicit Deny for ec2:RunInstances.

Exam trap

SCS-C02 often tests the difference between implicit and explicit deny, and candidates may incorrectly attribute an explicit deny to a missing Allow statement rather than an actual Deny statement.

How to eliminate wrong answers

Option A is wrong because if the action is not included in any Allow statement, the result would be 'implicitDeny', not 'explicitDeny'. Option C is wrong because the absence of an Allow for ec2:RunInstances would also result in 'implicitDeny', not 'explicitDeny'. Option D is wrong because a Resource of '*' does not cause an explicit deny; it would allow the action if the Action is allowed, or result in implicit deny if not allowed.

1172
MCQmedium

A company wants to enforce that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. Which policy should be attached to the IAM users or group to enforce this requirement?

A.Allow access if MFA is present
B.Deny access if MFA is not present
C.Deny access if MFA is present
D.Grant access with a condition requiring MFA
AnswerB

An explicit deny statement using the condition 'aws:MultiFactorAuthPresent' equals 'false' will reject any IAM user request that did not authenticate with MFA. Because AWS IAM evaluation logic gives explicit deny precedence over every allow, this pattern universally blocks non-MFA access while still permitting MFA-authenticated requests. Correctly scoped, this is the standard and reliable way to enforce MFA across all users, including those with other grants.

Why this answer

The correct policy is to explicitly deny access when MFA is not present. In IAM, an explicit Deny overrides any Allow, so attaching a policy with a Deny statement conditioned on 'aws:MultiFactorAuthPresent' being false ensures that users without MFA are blocked from accessing the console. This is the standard pattern to enforce MFA because it cannot be bypassed by other permissive policies.

Exam trap

SCS-C02 often tests the difference between Allow and Deny in IAM policies, and candidates may incorrectly choose an Allow with a condition, not realizing that an explicit Deny is required to enforce MFA.

How to eliminate wrong answers

Option A is wrong because allowing access if MFA is present does not enforce MFA; users without MFA would still be allowed by other policies. Option C is wrong because denying access if MFA is present would block users who have MFA, which is the opposite of the requirement. Option D is wrong because granting access with a condition requiring MFA is an Allow statement, which can be overridden by other Allow statements and does not guarantee enforcement; an explicit Deny is needed.

1173
MCQhard

A company has multiple AWS accounts and wants to allow a user in the production account to assume a role in the development account. The role in the development account has a trust policy that allows the production account to assume it. What additional configuration is required?

A.Attach a policy to the user in the production account allowing sts:AssumeRole for the development role ARN.
B.Modify the trust policy of the role in the development account to allow the user ARN instead of the account ARN.
C.Set up a VPC peering connection between the accounts.
D.Create a new IAM user in the development account with the same name.
AnswerA

This is correct because cross-account role assumption requires two halves: the role's trust policy in the development account must list the production account (or the user ARN) as a trusted principal, and the user in the production account must have an IAM identity policy that explicitly grants sts:AssumeRole against the development role's ARN. Without this identity-side permission, the user is not authorized to call AssumeRole even though the role trusts the account. Attaching the policy to the user therefore completes the authorization chain and allows the user to receive temporary credentials for the development role.

Why this answer

The user in the production account must have an IAM policy that allows sts:AssumeRole targeting the development account role ARN. Option B is wrong because the trust policy is already set. Option C is wrong because the role must be created in the development account.

Option D is wrong because the trust policy should reference the production account.

1174
MCQmedium

A company wants to restrict access to an S3 bucket so that only requests from a specific VPC Endpoint are allowed. Which policy element should be used in the bucket policy?

A.aws:SourceVpc
B.aws:VpcSourceIp
C.aws:SourceIp
D.aws:SourceVpce
AnswerD

The aws:SourceVpce condition key is the correct way to restrict an S3 bucket to requests that came through a specific VPC endpoint. You write it in the bucket policy's Condition block using StringEquals and set the value to the full VPC endpoint ID, such as vpce-0abcdef123456789. Because this key is present in the request context only when the request traffic actually travels through the specified VPC endpoint, it gives the most precise endpoint-level control among the listed options.

Why this answer

The aws:SourceVpce condition key is the correct choice because it specifically evaluates the VPC endpoint ID (e.g., vpce-12345678) that the request traversed to reach S3. When you attach a bucket policy that denies all traffic except requests originating from a particular VPC endpoint, you use a Condition block with StringEquals on aws:SourceVpce to match that endpoint ID. This is the only key that directly identifies the endpoint itself, making it the precise tool for restricting access to a specific VPC endpoint.

Exam trap

SCS-C02 often tests the confusion between aws:SourceVpc (VPC ID) and aws:SourceVpce (VPC endpoint ID), causing candidates to pick the VPC-level key when the question specifically asks for endpoint-level restriction.

How to eliminate wrong answers

Option A is wrong because aws:SourceVpc evaluates the VPC ID (e.g., vpc-abc123) from which the request originated, not the VPC endpoint ID; it cannot distinguish between multiple endpoints in the same VPC. Option B is wrong because aws:VpcSourceIp is not a valid AWS condition key—it does not exist in IAM policy evaluation. Option C is wrong because aws:SourceIp checks the public or private IP address of the requester, which is not reliable for VPC endpoint traffic since the source IP may be a private address that is not unique to the endpoint and can be spoofed or shared.

1175
MCQmedium

A security team needs to audit all changes to security group rules across multiple AWS accounts in an organization. Which combination of services should be used to meet this requirement?

A.Amazon CloudWatch Logs and AWS CloudTrail.
B.Amazon GuardDuty and AWS Security Hub.
C.AWS Trusted Advisor and AWS Config.
D.AWS Config and AWS CloudTrail.
AnswerD

AWS Config continuously records the configuration state of security groups, including each ingress and egress rule change, and can deliver configuration-history timelines and compliance snapshots. AWS CloudTrail captures the API actions that initiate those changes, logging the principal, user agent, and request parameters for every management event. Together they provide both the 'what' (configuration state via Config) and the 'who/when/how' (API activity via CloudTrail), enabling a complete audit trail of security group changes. For example, when a rule is removed, Config shows the new state while CloudTrail reveals the identity of the caller.

Why this answer

AWS Config continuously records changes to resource configurations, including security group rules, and can evaluate them against desired configurations. AWS CloudTrail captures API activity, so it logs the actual API calls that modify security groups (e.g., AuthorizeSecurityGroupIngress). Together, Config provides the configuration change history and CloudTrail provides the who, what, when, and from where for each change.

This combination is the standard AWS approach for auditing security group modifications across multiple accounts, especially when centralized via AWS Organizations and a delegated administrator.

Exam trap

SCS-C02 often tests the misconception that AWS Config alone can provide a full audit trail of who made changes, when in fact CloudTrail is required to capture the API-level identity and request details.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs is for storing and analyzing log data (e.g., from applications or flow logs), not for recording resource configuration changes; CloudTrail alone records API calls but does not provide a configuration timeline or compliance evaluation of security group rules. Option B is wrong because GuardDuty is a threat detection service that identifies malicious activity, and Security Hub aggregates and prioritizes findings; neither records configuration changes or provides a full audit trail of security group rule modifications. Option C is wrong because Trusted Advisor offers best-practice checks and recommendations, not a detailed configuration change history, and AWS Config alone (without CloudTrail) lacks the API-level audit trail of who made each change.

1176
MCQmedium

A company wants to use AWS CloudTrail to log all API activity across multiple accounts in AWS Organizations. Which configuration meets the requirement of centralized logging with minimal operational overhead?

A.Create a CloudTrail trail in each account and aggregate logs to a common S3 bucket
B.Enable CloudTrail in each account and use cross-account roles to centralize logs
C.Use AWS Config to record API calls and send to CloudWatch Logs
D.Create an organization trail in the management account that applies to all accounts
AnswerD

When you create a CloudTrail trail in the management account with the 'Apply trail to my organization' option enabled, CloudTrail automatically creates and configures trails in every member account, delivering all management events to a single S3 bucket. The trail is managed centrally by the organization management account, and any new accounts that join the organization are automatically included without additional manual setup. This provides the lowest operational overhead and ensures comprehensive, centralized logging of API activity across the entire AWS organization, which is exactly what the requirement demands.

Why this answer

Creating an organization trail in the management account automatically applies to all accounts in AWS Organizations, centralizing CloudTrail logs into a single S3 bucket without requiring per-account configuration. This approach minimizes operational overhead by leveraging the Organizations integration, which handles log delivery from member accounts transparently.

Exam trap

The trap here is that candidates often think they need to manually configure trails per account or use cross-account roles, missing the fact that AWS Organizations provides a native, low-overhead solution through organization trails that automatically centralize logging.

How to eliminate wrong answers

Option A is wrong because creating a trail in each account and aggregating logs to a common S3 bucket requires manual setup and maintenance per account, increasing operational overhead and risking inconsistent configurations. Option B is wrong because enabling CloudTrail in each account and using cross-account roles to centralize logs adds complexity with IAM role management and does not provide the automatic, unified logging that an organization trail offers. Option C is wrong because AWS Config records resource configuration changes, not API calls; it cannot replace CloudTrail for logging API activity, and sending to CloudWatch Logs does not centralize logs across accounts.

1177
MCQhard

A company's security team is designing an incident response plan for AWS resources. They want to ensure that when a security incident is detected in a production account, a pre-defined runbook is executed automatically. The runbook includes steps to isolate the compromised resource and collect forensic evidence. Which combination of services should the team use to implement this automation?

A.Amazon EventBridge and AWS Lambda
B.AWS Config and Amazon EC2 Auto Scaling
C.AWS Step Functions and AWS Lambda
D.AWS Systems Manager Incident Manager and AWS Systems Manager Automation
AnswerD

AWS Systems Manager Incident Manager is purpose-built to manage the full incident lifecycle—it creates an incident record, routes notifications to on-call responders, aggregates related findings, and provides a status page. Systems Manager Automation publishes runbooks (SSM documents) that can perform defined remediation steps, such as isolating an EC2 instance or revoking IAM permissions, either automatically for pre-approved actions or with manual approval. Together they give a security team a closed-loop incident response capability that can reduce mean time to respond and maintain a post-incident audit trail.

Why this answer

AWS Systems Manager Incident Manager provides the incident management lifecycle, including automated response plans that trigger runbooks when an incident is detected. AWS Systems Manager Automation runbooks contain predefined steps (e.g., isolating EC2 instances, capturing memory dumps, and collecting logs) that can be executed automatically. This combination directly meets the requirement for a pre-defined runbook that isolates the compromised resource and collects forensic evidence.

Exam trap

The trap here is that candidates often choose EventBridge and Lambda (Option A) because they are familiar with event-driven automation, but they overlook that Incident Manager provides the required incident lifecycle, response plans, and pre-built runbook templates specifically designed for security incident response.

How to eliminate wrong answers

Option A is wrong because Amazon EventBridge and AWS Lambda can trigger actions based on events, but they lack a built-in incident management lifecycle, runbook orchestration, and the ability to execute complex, multi-step forensic workflows without custom code. Option B is wrong because AWS Config evaluates resource compliance and EC2 Auto Scaling manages instance scaling; neither provides incident response automation or runbook execution for security incidents. Option C is wrong because AWS Step Functions orchestrates workflows and Lambda executes code, but this combination does not include incident detection, alerting, or the pre-defined, auditable runbook capabilities that Systems Manager Incident Manager and Automation provide.

1178
MCQmedium

A company uses AWS CloudTrail to log all API activity. A security analyst notices that some delete operations on S3 buckets are missing from the CloudTrail logs. What is the MOST likely reason?

A.The S3 bucket has server access logging enabled, which overrides CloudTrail.
B.The trail is configured to log only management events, not data events.
C.The delete operations are performed by a cross-account role, which CloudTrail does not log.
D.The root user of the account is excluded from CloudTrail logging.
AnswerB

A CloudTrail trail defaults to recording only management events, which cover control-plane operations such as creating or deleting buckets, not data-plane operations like deleting objects within an S3 bucket. Object-level S3 activities, including DeleteObject and PutObject, are classified as data events and must be explicitly enabled using data event selectors in the trail configuration. Since only management events are being logged, the DeleteObject API calls will not appear in CloudTrail event history, matching the scenario exactly.

Why this answer

CloudTrail trails can be configured to log management events (control plane operations like CreateBucket) and/or data events (data plane operations like GetObject, DeleteObject). By default, a trail logs only management events. S3 delete operations on objects within a bucket are data events, so if the trail is not configured to log data events, those delete operations will not appear in CloudTrail logs.

Exam trap

The trap here is that candidates often assume CloudTrail logs all API activity by default, failing to distinguish between management events and data events, which require separate configuration.

How to eliminate wrong answers

Option A is wrong because server access logging logs HTTP requests to the bucket and does not override CloudTrail; both can operate independently. Option C is wrong because CloudTrail does log API calls made by cross-account roles, provided the trail is configured to capture those events. Option D is wrong because CloudTrail logs all root user activity by default; there is no exclusion for the root user in CloudTrail logging.

1179
MCQmedium

A company has a requirement to grant cross-account access to an S3 bucket named 'shared-data' in Account A (111111111111) to users in Account B (222222222222). The security team has set up a bucket policy in Account A that grants read-only access to the IAM role 'DataReader' in Account B. The bucket policy is as follows: {"Version":"2012-10-17","Statement":[{"Effect":"Allow","Principal":{"AWS":"arn:aws:iam::222222222222:role/DataReader"},"Action":["s3:GetObject"],"Resource":"arn:aws:s3:::shared-data/*"}]}. A user in Account B assumes the 'DataReader' role, but when trying to read an object from the bucket, they receive an 'Access Denied' error. What is the MOST likely reason for this error?

A.The bucket policy principal must be the IAM user ARN, not the role ARN.
B.The bucket policy is missing the 's3:ListBucket' action, which is required to read objects.
C.The IAM role 'DataReader' does not have an IAM policy that allows s3:GetObject on the bucket.
D.The bucket objects are encrypted with a KMS key, and the role does not have permission to decrypt.
AnswerC

For cross-account S3 access, the IAM role must have an identity-based policy that explicitly allows s3:GetObject on the target bucket. Even if the bucket policy trusts the role, the role's own permissions are evaluated independently; without that allow, the request fails with Access Denied. This is the classic root cause of this scenario.

Why this answer

The most likely reason for the Access Denied error is that the IAM role 'DataReader' in Account B does not have an IAM policy that allows s3:GetObject on the bucket. For cross-account access, both the bucket policy in Account A and the IAM policy in Account B must grant the necessary permissions. The bucket policy alone is not sufficient; the role must also have an identity-based policy allowing the action.

Exam trap

SCS-C02 often tests the dual-permission requirement for cross-account access; candidates may assume the bucket policy alone is sufficient, forgetting the need for an identity-based policy in the trusted account.

How to eliminate wrong answers

Option A is wrong because the bucket policy can specify a role ARN as the principal; it does not have to be an IAM user ARN. Option B is wrong because s3:ListBucket is not required to read a specific object; it is only needed to list objects in the bucket. The error is Access Denied on GetObject, not on ListBucket.

Option D is wrong because while KMS encryption could cause Access Denied if the role lacks decrypt permissions, the question does not mention encryption, and the most common cause is missing IAM policy. Additionally, if the object were encrypted with KMS, the error would typically mention KMS access, but the question states the bucket policy grants read-only access, implying no encryption issue.

1180
MCQmedium

A company uses AWS CloudTrail to log management events in all regions. The security team notices that some API calls made by an IAM user are not appearing in the CloudTrail event history. What is the most likely reason?

A.The user used the AWS Management Console, not the CLI
B.The trail is configured for a single region only
C.The API calls were read-only and excluded by default
D.CloudTrail event history only retains events for 90 days; older events are not visible
AnswerD

CloudTrail event history is a built-in feature that provides a view of the last 90 days of account activity, and this retention period is not configurable. Once an event is older than 90 days, it is no longer visible in event history, and the only way to retain it is to configure a trail that delivers CloudTrail log files to Amazon S3 (and optionally CloudWatch Logs) with a suitable lifecycle policy. This 90-day limit applies uniformly to all management events, regardless of the client, region scope, or whether the calls are read-only or write-only.

Why this answer

D is correct because CloudTrail event history only retains the last 90 days of events. If the API calls were made more than 90 days ago, they would no longer appear in the event history, even though the trail itself may still be delivering log files to an S3 bucket for longer-term storage. The security team is likely looking at the event history rather than querying the S3 bucket or using Athena for older events.

Exam trap

The trap here is that candidates often assume missing API calls are due to configuration issues (like single-region trails or console-only access) rather than the 90-day retention limit of the event history, which is a fundamental but easily overlooked CloudTrail behavior.

How to eliminate wrong answers

Option A is wrong because CloudTrail logs API calls regardless of whether they are made via the AWS Management Console, CLI, or SDK; all management events are captured. Option B is wrong because the question states the trail is configured for all regions, so a single-region trail would not explain missing events across all regions. Option C is wrong because CloudTrail does not exclude read-only API calls by default; management events include both read and write events unless specifically filtered.

1181
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to centralize the collection of VPC Flow Logs and AWS CloudTrail logs from all accounts into a single Amazon S3 bucket in the management account. The S3 bucket policy must allow cross-account log delivery. Which condition in the bucket policy should be used to restrict log delivery to only the organization's accounts?

A.aws:SourceArn
B.aws:SourceOrgId
C.aws:SourceAccount
D.aws:PrincipalOrgID
AnswerD

aws:PrincipalOrgID is a global IAM condition key that compares the unique organization ID of the principal's AWS account to the value you specify. In an S3 bucket policy, setting "aws:PrincipalOrgID": "o-12345" allows any principal from any account within that organization to deliver logs, automatically covering new accounts as they join. Because it operates on the principal's organization rather than the request source, it is the most scalable and appropriate condition for this cross-account logging scenario.

Why this answer

The correct condition key is `aws:PrincipalOrgID`, which restricts access to principals (accounts, IAM roles, or users) that are members of the specified AWS Organization. When used in a bucket policy, it ensures that only accounts within the company's organization can deliver logs to the S3 bucket, even if the source account ID changes. Note that `aws:SourceOrgId` is not a valid AWS condition key; `aws:PrincipalOrgID` is the appropriate key for this purpose.

Exam trap

Candidates often confuse `aws:PrincipalOrgID` with `aws:SourceOrgId`. However, `aws:SourceOrgId` is not a valid AWS condition key. The correct key for restricting based on organization membership is `aws:PrincipalOrgID`.

For cross-account log delivery, `aws:PrincipalOrgID` ensures that only accounts within the specified organization can perform the action.

How to eliminate wrong answers

Option A is wrong because `aws:SourceArn` is used to restrict access based on the exact ARN of the resource making the request, which is not suitable for cross-account log delivery from multiple accounts where the source ARN varies. Option C is wrong because `aws:SourceAccount` restricts based on a single AWS account ID, which would require listing every account in the organization and would not automatically include new accounts added later. Option D is wrong because `aws:PrincipalOrgID` is the correct key, but the option is mislabeled as `aws:SourceOrgId` in the question; the actual correct key is `aws:PrincipalOrgID`, not `aws:SourceOrgId`.

1182
MCQhard

A security engineer is configuring AWS KMS for a multi-Region application that uses Amazon S3 and Amazon RDS in us-east-1 and eu-west-1. The company requires that encryption keys be available in both Regions and that data encrypted in one Region can be decrypted in the other without re-encrypting. The company also wants to minimize latency for cryptographic operations. Which solution meets these requirements?

A.Use an AWS CloudHSM cluster in each Region and replicate keys between them.
B.Enable automatic key rotation on a single KMS key and use it in both Regions.
C.Use AWS KMS multi-Region keys with a primary key in us-east-1 and a replica in eu-west-1.
D.Create a customer managed key in us-east-1 and grant cross-Region access to principals in eu-west-1.
AnswerC

Multi-Region keys are a set of interoperable KMS keys in different Regions that share the same key material and key ID. They allow data encrypted in one Region to be decrypted in another without re-encryption. Creating a primary key and a replica in the second Region provides availability and low-latency access, meeting all requirements.

Why this answer

AWS KMS multi-Region keys allow the same key material to be used in multiple Regions, so data encrypted in one Region can be decrypted in another without re-encryption. Creating a primary key and a replica in the second Region provides availability and low-latency access. Single-Region keys, CloudHSM replication, and rotation do not meet the cross-Region decryption requirement.

Exam trap

The trap here is assuming that a single KMS key can be used across Regions, when KMS keys are strictly regional and multi-Region keys are required for cross-Region decryption.

1183
MCQmedium

A company has a requirement to automatically rotate encryption keys for Amazon EBS volumes every 90 days. The EBS volumes are encrypted using AWS KMS. What is the simplest way to meet this requirement?

A.Use AWS Secrets Manager to rotate the KMS key automatically.
B.Create a new KMS key every 90 days and re-encrypt volumes using a script.
C.Switch to client-side encryption and rotate keys manually.
D.Enable automatic key rotation on the existing KMS key.
AnswerB

To satisfy a 90-day rotation requirement, you must perform manual key rotation by creating a new KMS key every 90 days and then re-encrypting your EBS volumes with that new key. A typical scripted approach creates an encrypted snapshot of each volume using the new key, creates a new volume from that snapshot, and attaches it to the instance after detaching the old volume. This changes the actual key ID and re-encrypts the volume data, which is the only way to meet a sub-yearly rotation schedule because KMS automatic rotation only occurs every year.

Why this answer

KMS automatic key rotation creates new backing keys yearly, not every 90 days. To meet the 90-day rotation requirement, you must manually create a new KMS key every 90 days and then re-encrypt the EBS volumes (e.g., by taking a snapshot, copying it with the new key, and restoring). Option A is incorrect because AWS Secrets Manager manages secrets, not KMS keys; it cannot rotate KMS keys.

Option C is incorrect because client-side encryption would require managing keys outside of KMS, which adds complexity and does not meet the requirement of using AWS KMS. Option D is incorrect because automatic key rotation on the existing KMS key only rotates the backing key once per year, not every 90 days.

1184
MCQeasy

A company wants to receive real-time notifications when specific API calls are made in their AWS account, such as creating a new IAM user. Which AWS service should be used to trigger a notification based on CloudTrail events?

A.AWS Config
B.Amazon EventBridge
C.Amazon Inspector
D.Amazon VPC Flow Logs
AnswerB

Amazon EventBridge is a serverless event bus that can consume AWS service events, including CloudTrail API call events, via a custom or the default event bus. You can define fine-grained event patterns that match specific API actions, resources, or principals, and route matched events to targets like Lambda, SNS, or SQS with low latency. This event-driven mechanism is exactly what enables real-time notifications when a specified AWS API call occurs.

Why this answer

Amazon EventBridge is the correct service because it can ingest CloudTrail events in near real-time and use event rules to match specific API calls, such as CreateUser, and then route those events to targets like SNS topics to send notifications. EventBridge provides a serverless event bus that directly integrates with CloudTrail, enabling you to react to API activity without custom polling or additional infrastructure.

Exam trap

The trap here is that candidates often confuse AWS Config's configuration change detection with real-time event-driven monitoring, but Config operates on a compliance evaluation cycle and does not provide sub-second notification for specific API calls like EventBridge does.

How to eliminate wrong answers

Option A is wrong because AWS Config is a service for evaluating resource configurations against rules and tracking configuration changes over time, not for reacting to real-time API calls from CloudTrail. Option C is wrong because Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, not for monitoring API activity. Option D is wrong because VPC Flow Logs capture IP traffic metadata at the network interface level, not API calls or IAM user creation events.

1185
MCQmedium

Refer to the exhibit. An EC2 instance with an IAM role attached attempts to access an S3 bucket, but receives an 'AccessDenied' error. The role has an attached policy allowing s3:GetObject on the bucket. What is the most likely cause?

A.The S3 bucket policy denies access to the role.
B.The IAM policy is not attached to the role.
C.The trust policy does not allow the EC2 service to assume the role.
D.The EC2 instance does not have an instance profile associated with the role.
AnswerA

An explicit deny in the S3 bucket policy takes precedence over any allow granted by the IAM policy attached to the role. When the role attempts to access the bucket, S3 evaluates the bucket policy alongside the IAM policy; if it contains a Deny statement that applies to the role's ARN (or any principal that includes the role), the request fails with AccessDenied. This is the most direct cause here because the role and instance are otherwise correctly configured, isolating the issue to the resource policy.

Why this answer

When an IAM role has an identity-based policy allowing s3:GetObject but access is still denied, the most likely cause is an explicit Deny in the S3 bucket policy, because in AWS an explicit Deny anywhere in the evaluation chain overrides any Allow. The bucket policy is a resource-based policy evaluated alongside the identity-based policy, and a Deny there will block the role even though the IAM policy grants permission.

Exam trap

SCS-C02 often tests the policy evaluation order, and the trap is assuming the IAM identity policy is the only relevant policy — candidates forget that an explicit Deny in a resource-based policy (like an S3 bucket policy) overrides any Allow.

How to eliminate wrong answers

Option B is wrong because the question states the role has an attached policy allowing s3:GetObject — if the policy weren't attached, the role wouldn't have the permission at all, but the scenario explicitly says it does. Option C is wrong because if the trust policy didn't allow EC2 to assume the role, the instance wouldn't have credentials at all and would receive a credential/assume-role error, not an S3 AccessDenied. Option D is wrong because without an instance profile, the EC2 instance couldn't retrieve temporary credentials from the metadata service, again producing a credential error rather than an S3 authorization denial.

1186
MCQmedium

A security engineer needs to ensure that all API calls made to AWS are logged and retained for at least 7 years for compliance. Which AWS service should be enabled to meet this requirement?

A.Amazon GuardDuty
B.AWS Config
C.Amazon Inspector
D.AWS CloudTrail
AnswerD

AWS CloudTrail is the service designed to record API activity across AWS, capturing the identity of the caller, source IP address, event time, request parameters, and response elements for management events by default. You can create trails that deliver compressed event logs to an Amazon S3 bucket, CloudWatch Logs, or CloudTrail Lake for long-term retention and analysis. For complete coverage, use a multi-region trail with management events enabled and add data events for S3, Lambda, and other services as needed, because CloudTrail is the authoritative source for ensuring all API calls are auditable.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to AWS, including the identity of the caller, the time of the call, the source IP address, and the request parameters. CloudTrail logs can be stored in an S3 bucket with lifecycle policies to retain logs for exactly 7 years, meeting the compliance requirement for long-term retention.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks resource configuration changes) with CloudTrail (which tracks API calls), but Config does not record the API calls themselves—only the resulting state changes, which may not satisfy compliance requirements for full API audit trails.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes CloudTrail logs, VPC Flow Logs, and DNS logs for malicious activity, but it does not itself log API calls or provide long-term retention of API activity records. Option B is wrong because AWS Config is a configuration management and compliance service that records resource configuration changes and evaluates them against rules, but it does not log API calls; it focuses on resource state rather than API activity. Option C is wrong because Amazon Inspector is a vulnerability assessment service that scans EC2 instances and container images for software vulnerabilities and unintended network exposure, not for logging API calls.

1187
MCQeasy

A company is using AWS Shield Advanced to protect its web application against DDoS attacks. Which additional AWS service can be used to automatically mitigate application layer attacks?

A.AWS Network Firewall
B.Amazon GuardDuty
C.AWS Firewall Manager
D.AWS WAF
AnswerD

AWS WAF is a web application firewall that monitors and filters HTTP(S) requests based on conditions like IP reputation, country, URI, and SQL injection signatures. When integrated with AWS Shield Advanced, it provides the primary mechanism for application layer (L7) DDoS mitigation—enabling you to add rate-based rules and block anomalous traffic before it reaches the origin. This direct, request-level inspection makes it the correct option for protecting a web application.

Why this answer

AWS WAF is the correct choice because it integrates directly with AWS Shield Advanced to provide application-layer (Layer 7) DDoS mitigation. Shield Advanced handles network and transport layer attacks, while AWS WAF uses web access control lists (ACLs) to inspect HTTP/HTTPS traffic and block malicious requests such as SQL injection or cross-site scripting, which are common application-layer attack vectors.

Exam trap

The trap here is that candidates often confuse AWS WAF with AWS Network Firewall or Firewall Manager, mistakenly believing that any firewall service can handle application-layer attacks, but only AWS WAF provides Layer 7 inspection and mitigation for HTTP/HTTPS traffic.

How to eliminate wrong answers

Option A is wrong because AWS Network Firewall operates at Layers 3 and 4 (network and transport) and does not inspect or filter application-layer HTTP/HTTPS payloads, making it unsuitable for mitigating application-layer DDoS attacks. Option B is wrong because Amazon GuardDuty is a threat detection service that identifies malicious activity via logs and network metadata, but it does not actively block or mitigate traffic at the application layer. Option C is wrong because AWS Firewall Manager is a policy management tool that centrally configures rules across multiple accounts and resources, but it does not itself perform application-layer traffic inspection or mitigation.

1188
MCQeasy

A company wants to allow its users to assume an IAM role in a different AWS account. What must the company configure to enable cross-account access?

A.In the source account, create an S3 bucket policy that allows access from the target account.
B.In the target account, create an IAM role with a trust policy that allows the source account, and attach a permissions policy to that role. In the source account, allow users to call sts:AssumeRole.
C.In the target account, create an IAM user and share the access keys securely with the source account users.
D.In the target account, attach a trust policy to an IAM group that allows the source account.
AnswerB

Cross-account access requires two sides: the target account's role trust policy naming the source account as principal, plus a permissions policy granting the needed actions. The source account must additionally let its users call sts:AssumeRole, otherwise the role cannot be assumed.

Why this answer

Cross-account access requires creating an IAM role in the target account with a trust policy that specifies the source account as a trusted entity, and attaching a permissions policy that defines what actions the role can perform. The source account must then have a policy that allows its users to call sts:AssumeRole for that role. Option A is incorrect because S3 bucket policies are used for resource-based access, not for role assumption.

Option C is incorrect because sharing access keys violates security best practices and does not provide the controlled, temporary access that IAM roles offer. Option D is incorrect because trust policies are attached to roles, not IAM groups.

1189
MCQeasy

A company wants to run a security assessment that checks for vulnerabilities in an EC2 instance. Which AWS service should be used?

A.Amazon Inspector
B.AWS WAF
C.Amazon GuardDuty
D.AWS Shield Advanced
AnswerA

Amazon Inspector is a vulnerability management service that automatically scans Amazon EC2 instances, container images in Amazon ECR, and Lambda functions for software vulnerabilities and unintentional network exposure. It assesses the OS and application packages against known CVE databases and CIS benchmarks, producing a risk score. This is precisely the security assessment tool suited for checking compute workloads for weaknesses.

Why this answer

Amazon Inspector automatically assesses EC2 instances for vulnerabilities and network exposure.

1190
MCQhard

A company is using Amazon CloudWatch Logs to collect logs from its EC2 instances. The security team wants to ensure that logs are encrypted at rest and that access to the logs is controlled. Which solution should the team implement?

A.Enable encryption using AWS KMS customer managed keys (CMK) and apply IAM policies to control access.
B.Use SSE-C with a customer-provided key to encrypt log data.
C.Use SSE-S3 to encrypt the log data in CloudWatch Logs.
D.Enable default encryption on the log group and use S3 bucket policies.
AnswerA

CloudWatch Logs supports server-side encryption with customer-managed KMS keys (CMKs). When you associate a CMK with a log group, the service uses envelope encryption: it calls KMS to generate a data key that encrypts your log data, and that data key is then encrypted by the CMK. To control access, you must configure both the KMS key policy and IAM policies that grant or deny actions such as kms:Decrypt and logs:DescribeLogGroups. This is the only method natively supported by CloudWatch Logs for customer-controlled encryption keys.

Why this answer

CloudWatch Logs supports encryption at rest using AWS KMS customer managed keys (CMK), which allows the security team to control access to the encrypted log data via IAM policies and key policies. This ensures both encryption and fine-grained access control, meeting the requirements.

Exam trap

The trap here is that candidates confuse S3 encryption options (SSE-S3, SSE-C) with CloudWatch Logs encryption, or assume that S3 bucket policies can be applied to CloudWatch Logs, when in fact CloudWatch Logs uses KMS for encryption and IAM for access control.

How to eliminate wrong answers

Option B is wrong because SSE-C (Server-Side Encryption with Customer-Provided Keys) is used with Amazon S3, not CloudWatch Logs; CloudWatch Logs does not support customer-provided keys for encryption. Option C is wrong because SSE-S3 (Server-Side Encryption with S3-Managed Keys) is an S3 feature, not applicable to CloudWatch Logs; CloudWatch Logs uses KMS for encryption, not SSE-S3. Option D is wrong because CloudWatch Logs does not support 'default encryption on the log group' as a setting, and S3 bucket policies cannot directly control access to CloudWatch Logs data; access to log groups is managed via IAM policies, not S3 bucket policies.

1191
Matchingmedium

Match each AWS CloudTrail log type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Control plane operations

Resource operations like S3 object access

Unusual activity detection

Invocation of Lambda function URLs

Why these pairings

CloudTrail has three main log types: Management events (control plane, logged by default), Data events (data plane, optional), and Insight events (anomaly detection, optional). Common confusions include swapping management vs data definitions, or misunderstanding insight events as real-time logs.

1192
Multi-Selecthard

Which THREE of the following are valid key management features of AWS KMS? (Choose THREE.)

Select 3 answers
A.Importing key material
B.Key policies
C.SSL certificate management
D.Password generation
E.Automatic key rotation
AnswersA, B, E

KMS allows you to create a customer managed key with your own cryptographic key material rather than using AWS-generated bytes. This import capability is essential for organizations needing to retain exclusive control over key material to satisfy regulatory or compliance mandates. However, once you import key material, you cannot enable automatic rotation of that KMS key, so you must plan for manual rotation or replacement.

Why this answer

AWS KMS allows you to import your own key material (BYOK) for use with KMS keys, which is a valid key management feature. This is done via the 'ImportKeyMaterial' API, enabling you to create a KMS key with no key material and then upload your own symmetric key material. This feature is essential for meeting compliance requirements that mandate control over the key material lifecycle.

Exam trap

The trap here is that candidates may confuse KMS's key management capabilities with other AWS security services, mistakenly thinking KMS handles SSL certificates or password generation, when in reality those are separate services with distinct purposes.

1193
MCQhard

A company has a VPC with a public subnet and a private subnet. An EC2 instance in the private subnet needs to download patches from the internet. The company wants to minimize costs and avoid NAT Gateway or NAT Instance charges. Which solution should be used?

A.Deploy a proxy instance in a public subnet and configure the private instance to use the proxy.
B.Use an egress-only internet gateway for the private subnet.
C.Attach an internet gateway to the VPC and add a route to the private subnet route table pointing to the internet gateway.
D.Create a VPC Gateway Endpoint for S3 and configure the instance to download patches from S3.
AnswerD

A VPC Gateway Endpoint for S3 uses the AWS-managed prefix list (com.amazonaws.<region>.s3) as a route-table target in the private subnet, so traffic to S3 stays on the AWS backbone and never leaves the VPC. Instances do not need public IPs, NAT, or an internet gateway, and gateway endpoints do not incur hourly charges. Configuring the route table and endpoint policy enables the private instance to download patches from selected S3 buckets securely without altering the instance's public/private status.

Why this answer

A VPC Gateway Endpoint for S3 allows private subnet resources to access S3 over the AWS network without traversing the internet, avoiding NAT Gateway or NAT Instance charges. The patches can be stored in an S3 bucket and downloaded by the EC2 instance using the endpoint, which uses AWS PrivateLink and does not require an internet gateway or public IP.

Exam trap

The trap here is that candidates often assume a private subnet must use a NAT Gateway or NAT Instance for any internet-bound traffic, overlooking that VPC Gateway Endpoints provide free, private access to specific AWS services like S3, which can satisfy the requirement without incurring additional costs.

How to eliminate wrong answers

Option A is wrong because deploying a proxy instance in a public subnet still requires that proxy to have internet access (via an internet gateway and public IP), and the proxy itself incurs EC2 instance costs, which does not minimize costs compared to using a free VPC Gateway Endpoint. Option B is wrong because an egress-only internet gateway is designed for IPv6 traffic only and does not support IPv4, which is the typical protocol for patch downloads; it also does not eliminate the need for a NAT device for IPv4. Option C is wrong because adding a route to the private subnet route table pointing to an internet gateway is invalid—private subnets require a NAT device (NAT Gateway or NAT Instance) to route traffic to the internet gateway; directly routing to the internet gateway would not work without a public IP on the instance, and it would violate the requirement to avoid NAT charges.

1194
Multi-Selectmedium

Which TWO actions are effective for detecting and responding to unauthorized access in an AWS environment? (Choose two.)

Select 2 answers
A.Enable AWS CloudTrail and monitor logs for suspicious activity.
B.Deploy Amazon GuardDuty to analyze CloudTrail logs and VPC Flow Logs for threats.
C.Use AWS Security Hub to automatically block suspicious IP addresses.
D.Enable VPC Flow Logs to capture all network traffic.
E.Enable IAM Access Analyzer to detect unauthorized access attempts.
AnswersA, B

CloudTrail records all API activity in your account—who made the call, from which IP, when, and with what outcome—enabling you to audit for suspicious behavior like new keys or unusual regions. But simply enabling CloudTrail is not enough; you must actively monitor the logs via CloudWatch Logs, Athena, or a SIEM. This is a detective control, not a preventive one, so it requires continual human or automated review to catch anomalies.

Why this answer

AWS CloudTrail records all API activity in your AWS environment, including management and data plane events. By enabling CloudTrail and monitoring its logs for suspicious activity (e.g., unusual API calls, failed authentication attempts, or access from unexpected IP addresses), you can detect unauthorized access. This is a foundational detective control that provides the audit trail necessary for incident response.

Exam trap

The trap here is that candidates often confuse detection services (like GuardDuty and CloudTrail) with automated remediation services (like AWS WAF or Lambda-based blocking), leading them to incorrectly select Security Hub as a blocking mechanism or IAM Access Analyzer as a real-time detection tool.

1195
MCQhard

A developer is creating an AWS Lambda function that needs to read items from a DynamoDB table. The function is deployed in a VPC with no internet access. What is the MOST secure way to grant the Lambda function access to DynamoDB?

A.Attach a public IP to the Lambda function and use an IAM role with DynamoDB permissions.
B.Create an API Gateway REST API with a VPC link and DynamoDB integration.
C.Use a resource-based policy on the DynamoDB table allowing access from the Lambda function's ARN.
D.Create a VPC endpoint for DynamoDB and attach an IAM execution role to the Lambda function with the necessary permissions.
AnswerD

Creating a gateway VPC endpoint for DynamoDB gives the Lambda function's subnet a private route to the DynamoDB service, avoiding the public internet and any need for a NAT gateway. The Lambda execution role should carry an identity policy with the specific DynamoDB actions and resource (table ARN) so the function is both network-reachable and authorized to perform the operation. This combines the correct network path with the correct IAM authorization, and the endpoint works through a route-table prefix list rather than an ENI in the function's subnet.

Why this answer

A VPC endpoint for DynamoDB allows private connectivity from within a VPC to DynamoDB without requiring an internet gateway, NAT device, or VPN. Attaching an IAM execution role to the Lambda function with the necessary DynamoDB permissions grants the function the required access. This combination is the most secure because it keeps traffic within the AWS network and uses least privilege.

Exam trap

The trap is thinking that a resource-based policy on DynamoDB or an API Gateway integration is needed, when the correct solution is a VPC endpoint combined with an IAM execution role; candidates might also incorrectly assume that Lambda functions can have public IPs.

How to eliminate wrong answers

Option A is wrong because attaching a public IP to a Lambda function is not possible; Lambda functions in a VPC do not have public IPs, and even if they did, using the internet to access DynamoDB is less secure and requires a NAT gateway. Option B is wrong because creating an API Gateway REST API with a VPC link and DynamoDB integration adds unnecessary complexity and does not directly grant the Lambda function access; the Lambda function would still need permissions to call API Gateway, and the integration would need to be configured. Option C is wrong because a resource-based policy on the DynamoDB table allowing access from the Lambda function's ARN is not sufficient; the Lambda function also needs an IAM execution role with permissions to access DynamoDB, and resource-based policies on DynamoDB are not used for this purpose (DynamoDB supports resource-based policies for cross-account access, but the primary method is IAM roles).

1196
MCQhard

A company uses AWS Organizations with multiple accounts. The security team needs to ensure that all accounts have CloudTrail enabled and that logs are delivered to a central S3 bucket. A new member account is created and the security engineer wants to enforce this configuration automatically. Which approach meets these requirements with the least operational overhead?

A.Use AWS Config rules to detect accounts without CloudTrail and trigger a remediation via Systems Manager Automation.
B.Use AWS CloudFormation StackSets to deploy a CloudTrail template to all accounts in the organization.
C.Use an SCP to deny cloudtrail:StopLogging and cloudtrail:DeleteTrail actions.
D.Create an AWS Lambda function that runs periodically to check and enable CloudTrail in each account.
AnswerB

AWS CloudFormation StackSets with automatic deployment is the proactive, organization-native solution because it deploys a CloudTrail template to all current accounts and automatically to any new accounts that are added later. Using service-managed permissions, StackSets creates the trail, the logging S3 bucket, and the necessary IAM role in each account without custom code or manual steps. This ensures CloudTrail is enabled before any activity can occur in a new account, since the stack set rollout happens as part of account creation and organization integration. It is declarative, idempotent, and centrally managed from the management account.

Why this answer

AWS CloudFormation StackSets allows you to deploy a CloudTrail template across all accounts in an AWS Organization from a single administrative account. This approach ensures that every new member account automatically receives the CloudTrail configuration as part of the StackSet's automatic deployment to accounts added to the organization, providing a fully automated, infrastructure-as-code solution with minimal operational overhead.

Exam trap

The trap here is that candidates often confuse preventive controls (SCPs) with provisioning controls, mistakenly thinking that denying stop/delete actions is sufficient to enforce CloudTrail, when in fact it does not create or enable the trail in the first place.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can detect non-compliant accounts but require a remediation action (e.g., Systems Manager Automation) that adds complexity and latency; it is reactive rather than proactive and does not automatically enforce configuration on new accounts without additional setup. Option C is wrong because an SCP denying cloudtrail:StopLogging and cloudtrail:DeleteTrail only prevents disabling or deleting an existing trail but does not enable CloudTrail in the first place; it is a preventive control, not a provisioning mechanism. Option D is wrong because a periodic Lambda function introduces operational overhead for scheduling, error handling, and state management, and it is not a native, declarative, or organization-wide enforcement method; it also risks delays between account creation and log delivery.

1197
MCQeasy

A company wants to allow a developer to launch EC2 instances only in a specific subnet. The developer should not be able to use any other subnet. Which IAM policy action should be used to enforce this?

A.ec2:ModifySubnetAttribute
B.ec2:CreateTags
C.ec2:RunInstances
D.ec2:DescribeSubnets
AnswerC

This is the exact IAM action that authorizes the RunInstances API call, which provisions one or more EC2 instances along with associated root volumes and network interfaces. The action can be scoped with condition keys such as ec2:SubnetId to restrict launches to specific subnets, and it is the only action listed that creates the underlying compute resource. Therefore, this is the correct permission for allowing a developer to launch EC2 instances.

Why this answer

The ec2:RunInstances action is the correct IAM action to control EC2 instance launches. By attaching a condition key such as ec2:SubnetId to the ec2:RunInstances action in an IAM policy, you can restrict the developer to launching instances only in a specific subnet. Other actions like ModifySubnetAttribute, CreateTags, or DescribeSubnets do not govern the launch of new instances.

Exam trap

The trap here is that candidates often confuse read-only actions (like DescribeSubnets) or unrelated actions (like ModifySubnetAttribute) with the actual launch action, mistakenly thinking they can restrict subnet usage via those permissions instead of using ec2:RunInstances with a condition key.

How to eliminate wrong answers

Option A is wrong because ec2:ModifySubnetAttribute modifies subnet settings (e.g., auto-assign public IP) and does not control instance launches. Option B is wrong because ec2:CreateTags only allows tagging resources, not launching instances. Option D is wrong because ec2:DescribeSubnets is a read-only action that lists subnets but does not authorize instance creation.

1198
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to detect and automatically respond to suspicious API calls across all accounts. Which solution is the MOST efficient and scalable?

A.Use AWS Config rules to detect API calls and trigger Lambda functions
B.Deploy Amazon GuardDuty and use its automated response feature
C.Create a CloudTrail trail in each account and aggregate logs via cross-account S3 bucket
D.Enable AWS CloudTrail organization trail and use Amazon EventBridge to invoke automated responses
AnswerD

Enabling an AWS CloudTrail organization trail in the management account automatically delivers log files for all accounts in the AWS Organization to a single S3 bucket, centralizing API activity without per-account setup. Amazon EventBridge can then ingest CloudTrail events and use rules to match specific API calls, triggering automated responses via targets like Lambda functions, Step Functions, or SNS topics. This native integration provides real-time, account-wide monitoring and response, making it the recommended and most scalable pattern.

Why this answer

Enabling an AWS CloudTrail organization trail centrally logs all API calls from every account in the AWS Organization into a single Amazon S3 bucket and CloudWatch Logs log group. Amazon EventBridge can then be used to create event rules that match specific suspicious API calls (e.g., IAM DeleteRolePolicy) and automatically invoke target actions like AWS Lambda functions or AWS Systems Manager Automation, providing a scalable, centralized, and efficient detection and response mechanism without per-account management overhead.

Exam trap

The trap here is that candidates often confuse AWS Config rules (which evaluate configuration drift) with CloudTrail (which records API activity), or assume that GuardDuty's threat detection includes built-in automated response capabilities, when in fact both require EventBridge for custom automation, making the centralized CloudTrail organization trail plus EventBridge the most efficient and scalable solution.

How to eliminate wrong answers

Option A is wrong because AWS Config rules are designed to evaluate resource configurations and compliance, not to detect real-time API calls; they cannot directly capture or react to API events like CloudTrail does. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes DNS logs, VPC Flow Logs, and CloudTrail events for malicious activity, but it does not have a built-in 'automated response feature' for triggering custom remediation actions; any automated response would require integration with EventBridge or Lambda, making this option incomplete and less direct. Option C is wrong because creating a separate CloudTrail trail in each account and aggregating logs via a cross-account S3 bucket introduces significant operational overhead, duplication, and potential for inconsistent configuration, whereas an organization trail provides a single, automatically replicated trail across all accounts with no per-account setup.

1199
MCQeasy

A company wants to ensure that all data transferred between its on-premises data center and AWS is encrypted in transit. Which AWS service should be used to meet this requirement?

A.Amazon CloudFront
B.AWS Transit Gateway
C.AWS Direct Connect
D.AWS Site-to-Site VPN
AnswerD

AWS Site-to-Site VPN is the correct service because it builds an encrypted IPsec tunnel between a customer gateway and a virtual private gateway, encrypting all traffic in transit across the public internet. It uses IKE for key exchange and IPsec protocols like ESP to provide confidentiality and integrity for every packet. This directly satisfies the requirement to ensure all data transferred between the company's network and AWS is protected.

Why this answer

AWS Site-to-Site VPN encrypts data in transit between an on-premises network and AWS by establishing IPsec tunnels over the public internet, satisfying the requirement for encryption in transit. It uses IKE for key exchange and IPsec ESP for payload encryption, providing confidentiality and integrity for all traffic traversing the VPN connection. This is the standard AWS service for encrypted hybrid connectivity.

Exam trap

SCS-C02 often tests the misconception that AWS Direct Connect encrypts traffic by default — it does not, and candidates must recognize that Site-to-Site VPN (or MACsec on Direct Connect) is required for encryption in transit.

How to eliminate wrong answers

Option A is wrong because Amazon CloudFront is a content delivery network that terminates TLS at edge locations for HTTP(S) content — it does not provide encrypted site-to-site connectivity between on-premises and AWS. Option B is wrong because AWS Transit Gateway is a network hub that routes traffic between VPCs and on-premises connections, but by itself it does not encrypt traffic; it can carry unencrypted Direct Connect or VPN traffic. Option C is wrong because AWS Direct Connect is a dedicated private fiber connection that is not encrypted by default — it provides private connectivity but requires a VPN overlay or MACsec for encryption in transit.

1200
MCQhard

A company uses AWS CloudTrail to log all API calls. The security team wants to be alerted when an IAM user creates a new access key for another IAM user (an action that could indicate privilege escalation). What is the most effective way to detect this specific API call?

A.Query AWS CloudTrail logs using Amazon Athena on a schedule.
B.Use AWS Config to create a custom rule that checks for changes to IAM users.
C.Create an Amazon CloudWatch Events rule that matches the 'iam:CreateAccessKey' API call and sends a notification to an SNS topic.
D.Enable Amazon GuardDuty and look for the 'UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration' finding.
AnswerC

A CloudWatch Events rule (now Amazon EventBridge) can use an event pattern matching the iam:CreateAccessKey API call emitted by CloudTrail, specifying source as 'aws.iam' and eventName as 'CreateAccessKey'. The rule can invoke an SNS topic within seconds of the API call, allowing immediate email, SMS, or Lambda-based notifications. This is the only option that is event-driven, real-time, and precisely scoped to the security-sensitive action of creating an IAM access key.

Why this answer

Amazon CloudWatch Events (now Amazon EventBridge) can be configured with a rule that matches the specific 'iam:CreateAccessKey' API call as it occurs. When this API call is made, CloudTrail delivers the event in near real-time to CloudWatch Events, which can then trigger an SNS topic to send an alert. This provides immediate, event-driven detection without the latency of scheduled queries or the overhead of custom rules.

Exam trap

The trap here is that candidates confuse AWS Config (which evaluates resource state) with CloudTrail (which records API actions), leading them to choose Option B, but Config cannot detect the API call itself—only the resulting configuration change, which may be too late or ambiguous.

How to eliminate wrong answers

Option A is wrong because querying CloudTrail logs with Amazon Athena on a schedule introduces significant delay (minutes to hours) between the API call and detection, making it unsuitable for real-time alerting. Option B is wrong because AWS Config custom rules evaluate resource configuration changes, not API calls; they can detect that an access key exists but cannot detect the specific 'iam:CreateAccessKey' API action itself. Option D is wrong because GuardDuty's 'UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration' finding detects stolen credentials being used from an EC2 instance, not the creation of access keys for another user.

Page 15

Page 16 of 17

Page 17