Courseiva

AWS Certified Security Specialty SCS-C02 (SCS-C02) — Questions 1201–1205

1205 questions total · 17pages · All types, answers revealed

Page 16

Page 17 of 17

1201
MCQhard

A company has an S3 bucket with a bucket policy that grants access to an IAM role. The security team wants to restrict access to only requests that originate from the company's VPC. How can this be achieved?

A.Create a new IAM role that can only be assumed by instances in the VPC.
B.Add a condition in the IAM role policy using aws:SourceVpce.
C.Add a condition in the bucket policy using aws:SourceIp with the VPC CIDR range.
D.Add a condition in the bucket policy using aws:SourceVpce with the VPC endpoint ID.
AnswerD

Adding a bucket policy condition with the aws:SourceVpce key set to the specific VPC endpoint ID is the correct approach because this condition is automatically populated when a request reaches S3 through that exact endpoint. This ensures that only requests that travel via the designated VPC endpoint are allowed, effectively bounding access to instances in the associated VPC. It is a recommended, unambiguous way to enforce network-level restrictions on S3 resources and works in tandem with IAM policies that grant permissions.

Why this answer

To restrict S3 bucket access to requests originating from a VPC, you add a condition to the bucket policy using the aws:SourceVpce condition key with the VPC endpoint ID. This ensures that only requests traversing the specified VPC endpoint (and thus originating from within the VPC) are allowed, which is the standard, secure way to enforce VPC-origin access for S3.

Exam trap

The trap is confusing IAM policy condition keys with bucket policy condition keys — candidates often pick aws:SourceVpce in an IAM role policy, but the exam expects you to know it must be in the bucket policy to enforce VPC endpoint origin.

How to eliminate wrong answers

Option A is wrong because creating an IAM role assumable only by VPC instances does not restrict S3 access to VPC-originated requests — the role could still be used from outside the VPC if credentials leak, and it doesn't enforce network origin. Option B is wrong because aws:SourceVpce is a bucket-policy condition key, not an IAM role policy condition key; using it in an IAM role policy will not enforce VPC endpoint origin for S3 access. Option C is wrong because aws:SourceIp with the VPC CIDR range is unreliable — it can be spoofed or bypassed via NAT/proxy, and it doesn't guarantee the request came through the VPC endpoint; it also fails for private IP ranges that aren't routable on the public internet.

1202
Multi-Selectmedium

A security engineer is configuring automated incident response for Amazon GuardDuty findings. The engineer wants to isolate a compromised EC2 instance by changing its security group and stopping the instance. Which THREE services should the engineer use together to achieve this? (Choose THREE.)

Select 3 answers
A.Amazon EC2
B.AWS Config
C.AWS Systems Manager
D.Amazon EventBridge
E.AWS Lambda
AnswersC, D, E

AWS Systems Manager is the correct choice because its Automation service provides pre-built and custom runbooks that can execute the remediation workflow, such as isolating an EC2 instance using the aws:stopInstance or aws:executeAwsApi actions. These runbooks can be triggered by an EventBridge rule that filters GuardDuty findings, and they support step-by-step error handling, conditional logic, and IAM-based approvals for safe, auditable incident response. This makes SSM the orchestrator that actually performs the automated isolation.

Why this answer

AWS Systems Manager (SSM) is correct because it provides the Automation runbook capability that can be used to stop an EC2 instance and modify its security groups as part of an incident response workflow. SSM Automation can be triggered by an EventBridge rule and can invoke Lambda functions or run commands directly on the instance to isolate it. This allows the security engineer to automate the isolation and stopping of the compromised instance without manual intervention.

Exam trap

The trap here is that candidates may think AWS Config can directly remediate findings (e.g., via AWS Config Rules with auto-remediation), but Config only triggers evaluations and cannot perform actions like stopping instances or modifying security groups without a separate automation service like SSM or Lambda.

1203
MCQmedium

A security administrator discovers that an IAM user has been deleted accidentally. What is the correct way to restore the user's access?

A.Contact AWS Support to undo the deletion
B.Use the AWS IAM console to undelete the user
C.Restore the user from a backup of IAM
D.Create a new IAM user with the same name and attach the same policies
AnswerD

The only viable recovery is to create a new IAM user with the same name and reattach the same managed or inline policies, group memberships, and permissions boundaries, because the deleted user object is permanently irrecoverable. Be aware that the new user receives a different internal unique ID and you must reset the console password and generate new access keys, since all prior credentials—including the old secret access key—were destroyed at deletion and cannot be recovered.

Why this answer

IAM does not support undeletion or restoration of deleted users. When an IAM user is deleted, all associated credentials, permissions, and metadata are permanently removed. The only way to restore access is to create a new IAM user with the same name and manually reattach the same policies, groups, and tags, and then regenerate access keys and passwords as needed.

Exam trap

The trap here is that candidates may assume AWS provides an 'undelete' or 'restore from backup' feature for IAM users, similar to features in other AWS services like S3 versioning or RDS snapshots, but IAM has no such recovery mechanism.

How to eliminate wrong answers

Option A is wrong because AWS Support cannot undo an IAM user deletion; IAM user deletions are irreversible and not stored in any recoverable state. Option B is wrong because the AWS IAM console does not provide an 'undelete' feature; once a user is deleted, it is permanently removed from the IAM service. Option C is wrong because IAM does not have a native backup or restore mechanism; while you can use AWS CloudTrail logs or infrastructure-as-code templates to recreate configurations, there is no backup of the user object itself.

1204
MCQhard

A security engineer is troubleshooting connectivity issues between an Amazon EC2 instance in a VPC and an on-premises server over a Direct Connect virtual interface. The EC2 instance has a security group that allows outbound traffic to the on-premises CIDR block (10.0.0.0/16). The VPC has a route table entry pointing the on-premises CIDR to the virtual private gateway. The on-premises firewall shows that packets are received from the EC2 instance but responses are not reaching the instance. What is the most likely cause?

A.The on-premises router does not have a route pointing the VPC CIDR back to the Direct Connect interface.
B.The network ACL for the subnet is blocking outbound traffic to the on-premises CIDR.
C.The virtual private gateway is not attached to the VPC.
D.The security group does not allow inbound traffic from the on-premises server.
AnswerA

The VPC has a route for the on-premises CIDR pointing to the virtual private gateway, so outbound packets traverse the Direct Connect virtual interface. However, for successful two-way communication, the on-premises router must have a route for the VPC CIDR that points back to the same Direct Connect interface. Because this return route is missing, response packets are either sent to a default route or dropped, so hosts in the VPC see no replies. This is a classic asymmetric routing failure.

Why this answer

The on-premises firewall logs show packets are received from the EC2 instance, but responses are not reaching it. This indicates a routing issue on the on-premises side: the on-premises router must have a route pointing the VPC CIDR back to the Direct Connect interface (virtual interface) for return traffic to be forwarded correctly. Without this return route, the on-premises server sends responses via its default route (likely the internet), which are dropped by the VPC security group or never reach the EC2 instance.

Exam trap

The trap here is that candidates often assume security groups or network ACLs are the cause of asymmetric connectivity issues, but the real problem is the missing return route on the on-premises side, which is a common misconfiguration in hybrid networking scenarios.

How to eliminate wrong answers

Option B is wrong because the network ACL for the subnet is not blocking outbound traffic to the on-premises CIDR; the question states the EC2 instance can send packets (they are received on-premises), so outbound ACL rules are not the issue. Option C is wrong because if the virtual private gateway were not attached to the VPC, the EC2 instance would not be able to send packets to the on-premises CIDR at all (the route table entry would be invalid), yet packets are received on-premises. Option D is wrong because the security group does not need to allow inbound traffic from the on-premises server for the response to reach the EC2 instance; security groups are stateful, so if the outbound traffic is allowed, the return traffic is automatically permitted regardless of inbound rules.

1205
Multi-Selecteasy

A company wants to detect anomalous behavior in their AWS environment. Which THREE AWS services can be used for threat detection? (Choose THREE.)

Select 3 answers
A.AWS Trusted Advisor
B.AWS Security Hub
C.AWS Config
D.Amazon GuardDuty
E.Amazon Inspector
AnswersB, D, E

AWS Security Hub is correct because it acts as a central aggregation point for security findings from multiple AWS services, including GuardDuty, Inspector, Macie, and Config, as well as partner products. It normalizes findings using the AWS Security Finding Format (ASFF) and applies consolidated security standards like CIS AWS Foundations and the AWS Foundational Security Best Practices. While it can perform correlation and enrichment, Security Hub itself does not analyze raw telemetry for anomalies; its value is in unifying and prioritizing signals across accounts and regions.

Why this answer

Amazon GuardDuty (D) is correct because it is a managed threat detection service that continuously monitors VPC Flow Logs, AWS CloudTrail management and S3 data events, and DNS logs to identify malicious or anomalous activity such as cryptocurrency mining, credential compromise, and reconnaissance. AWS Security Hub (B) is correct because it aggregates and correlates findings from GuardDuty, Inspector, Macie, and other sources, applies security standards checks, and surfaces prioritized threat-detection insights across accounts and Regions. Amazon Inspector (E) is correct because it performs automated vulnerability management by scanning EC2 instances, container images in ECR, and Lambda functions for software vulnerabilities and unintended network exposure, which supports detecting risky or anomalous configurations.

AWS Trusted Advisor (A) is not a threat-detection service; it provides best-practice checks on cost, performance, security, fault tolerance, and service quotas. AWS Config (C) is a configuration recording and compliance-evaluation service that tracks resource changes and rule compliance, but it does not itself detect threats or malicious behavior.

Exam trap

The trap here is that candidates often confuse AWS Trusted Advisor's security checks (like open port alerts) with threat detection, but Trusted Advisor is a best-practice advisor, not a real-time threat detection service—it lacks the ML-based anomaly detection and threat intelligence that GuardDuty and Security Hub provide.

Page 16

Page 17 of 17