Courseiva

AWS Certified Security Specialty SCS-C02 (SCS-C02) — Questions 76–150

1205 questions total · 17pages · All types, answers revealed

Page 1

Page 2 of 17

Page 3
76
MCQmedium

A company uses AWS CloudTrail and wants to ensure that logs are encrypted at rest using a customer-managed KMS key. The CloudTrail trail is configured to deliver logs to an S3 bucket. After enabling SSE-KMS on the S3 bucket, the logs are not being delivered. What is the most likely cause?

A.CloudTrail does not support SSE-KMS.
B.The KMS key is in a different AWS account.
C.The S3 bucket policy does not allow CloudTrail to write logs.
D.The KMS key policy does not grant CloudTrail permission to use the key.
AnswerD

For CloudTrail to encrypt log files with a customer managed KMS key, the key policy must grant the CloudTrail service principal (cloudtrail.amazonaws.com) permissions for kms:GenerateDataKey and kms:Decrypt. If these permissions are missing, CloudTrail cannot generate the data key needed to encrypt the logs, and log delivery will fail or produce unencrypted logs. This is the exact cause described in the question, making it the correct answer.

Why this answer

CloudTrail requires explicit permissions in the KMS key policy to use the key for encrypting log files. Even if SSE-KMS is enabled on the S3 bucket, CloudTrail must have `kms:GenerateDataKey` and `kms:Decrypt` permissions granted via the key policy. Without these, CloudTrail cannot encrypt the logs, causing delivery to fail.

Exam trap

The trap here is that candidates often assume enabling SSE-KMS on the S3 bucket is sufficient, overlooking that CloudTrail must also be explicitly authorized in the KMS key policy to use the key for encryption operations.

How to eliminate wrong answers

Option A is wrong because CloudTrail fully supports SSE-KMS with customer-managed KMS keys; it is a common and documented configuration. Option B is wrong because CloudTrail can use a KMS key from a different AWS account as long as the key policy grants cross-account permissions, and the question does not indicate a cross-account scenario. Option C is wrong because the S3 bucket policy is not the primary issue here; the logs are not being delivered due to encryption failure, not a write permission denial, and CloudTrail typically has the necessary S3 write permissions via its service principal.

77
MCQeasy

A company wants to receive an alert when an IAM user creates a new access key. Which AWS service should be used to trigger the alert?

A.Amazon CloudWatch Logs
B.Amazon GuardDuty
C.AWS CloudTrail and Amazon CloudWatch Events
D.AWS Config
AnswerC

AWS CloudTrail records every CreateAccessKey management event as a CloudTrail event containing the user identity, timestamp, source IP, and request details. Amazon CloudWatch Events (now Amazon EventBridge) can evaluate those CloudTrail events with an event pattern for eventName equal to CreateAccessKey and then route the matching event to an SNS topic or Lambda function to send the alert. Together, these two services provide the required real-time, event-driven notification.

Why this answer

AWS CloudTrail captures API calls made by or on behalf of an IAM user, including CreateAccessKey events. These events can be sent to Amazon CloudWatch Events (now part of Amazon EventBridge) using a rule that matches the specific API call, which then triggers an alert (e.g., via SNS or Lambda). This combination enables real-time monitoring and notification for security-sensitive actions like access key creation.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail with Amazon CloudWatch Logs, thinking CloudWatch Logs alone can trigger alerts, but CloudWatch Logs requires a metric filter and alarm setup, whereas CloudWatch Events directly matches API events without needing log ingestion.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs is used for storing, monitoring, and accessing log files from various sources, but it does not natively parse AWS API events or trigger alerts based on specific IAM actions without additional integration with CloudTrail and CloudWatch Events. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail management events for malicious activity, but it does not provide custom alerting for specific IAM user actions like creating an access key; it focuses on anomaly detection rather than policy-based triggers. Option D is wrong because AWS Config is a service for evaluating resource configurations against desired policies and tracking changes over time, but it does not trigger real-time alerts for API calls; it records configuration changes and can invoke rules for compliance, but not for event-driven notifications like access key creation.

78
MCQhard

A company uses AWS Organizations with many accounts. The security team wants to ensure that no account can disable AWS CloudTrail or stop logging. Which configuration should be used?

A.Enable CloudTrail log file validation.
B.Attach an IAM policy to the root user in each account.
C.Use AWS Config rules to detect and alert when CloudTrail is modified.
D.Apply an SCP that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail.
AnswerD

A service control policy (SCP) that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail is the correct preventive control because SCPs are account permission boundaries applied at the organization, organizational unit, or account level, and they apply to every IAM principal, including the root user. Once attached to all member accounts, it blocks these API calls before they execute, ensuring that no user or role—even with administrator privileges—can disable or delete CloudTrail. This centralizes protection and is the only option that directly prevents the malicious actions.

Why this answer

Service Control Policies (SCPs) in AWS Organizations are the only mechanism that can enforce a hard deny across all accounts in an organization, preventing even account root users from performing specified actions. By applying an SCP that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail, the security team ensures no account can disable or delete CloudTrail trails, regardless of IAM permissions within the account. SCPs define the maximum available permissions for accounts in the organization.

Exam trap

SCS-C02 often tests the distinction between preventive controls (SCPs) and detective controls (Config, CloudTrail validation), so candidates who pick alerting mechanisms instead of enforcement mechanisms fall into the trap.

How to eliminate wrong answers

Option A is wrong because CloudTrail log file validation only detects whether log files have been tampered with after delivery — it does not prevent anyone from stopping or deleting the trail in the first place. Option B is wrong because IAM policies attached to root users in each account are still modifiable by those root users and do not provide organization-wide enforcement; a root user could simply remove the policy. Option C is wrong because AWS Config rules are detective controls that alert after a change occurs — they do not prevent the action, and a malicious actor could disable CloudTrail before the rule fires or the alert is acted upon.

79
MCQeasy

A company wants to block traffic from a specific IP address range from accessing an Application Load Balancer (ALB). Which AWS feature should be used?

A.Network ACL
B.Security Group for the ALB
C.Route53
D.AWS WAF
AnswerD

AWS WAF is the correct service because it attaches as a web access control list (web ACL) directly to the Application Load Balancer. You can create an IP set match rule to block the specific IPv4 or IPv6 address before the request reaches the ALB, and WAF inspects each HTTP/HTTPS request at Layer 7. It also offers managed rules, rate-based rules, and geo-matching for more granular traffic control, and its integration is a one-click attachment to ALBs.

Why this answer

AWS WAF is the correct feature to block traffic from a specific IP address range from accessing an Application Load Balancer. WAF integrates directly with ALB and allows you to create rules based on IP addresses, which can be used to allow or block requests. Network ACLs and security groups operate at the network layer and are not specific to ALB traffic inspection.

Exam trap

SCS-C02 often tests the difference between security groups, NACLs, and WAF, and candidates may incorrectly choose security groups because they think they can block IPs, but security groups only allow.

How to eliminate wrong answers

Option A is wrong because Network ACLs are stateless and operate at the subnet level, not directly on the ALB; they can block IP ranges but are not the recommended way to filter traffic for an ALB and lack application-layer awareness. Option B is wrong because Security Groups for the ALB control inbound traffic to the ALB but only support allow rules, not explicit deny rules for specific IP ranges; you cannot block a specific IP range with a security group. Option C is wrong because Route53 is a DNS service and cannot block traffic based on IP addresses; it can be used for DNS-based filtering but not for blocking traffic to an ALB.

80
MCQmedium

A company uses Amazon RDS for MySQL with automated backups enabled. The security team suspects that a database administrator (DBA) with full RDS access has exfiltrated data by creating a snapshot of the database and sharing it with an external AWS account. The team wants to detect such exfiltration in the future. Which step should the team take to detect and alert on snapshot sharing?

A.Use AWS Config to detect changes to RDS snapshot attributes.
B.Enable Amazon GuardDuty with RDS Protection.
C.Create an Amazon EventBridge rule that triggers on the `ModifyDBSnapshotAttribute` API call and sends an alert via Amazon SNS.
D.Enable AWS CloudTrail and review logs manually.
AnswerC

Amazon EventBridge can receive AWS API events from CloudTrail and match a custom event pattern for the ModifyDBSnapshotAttribute API call from the rds source, then route that event to an SNS topic for immediate alerting. This gives you a near-real-time, automated response based on the exact administrative action, with no need to poll or manually review logs. Because the rule uses an event pattern keyed on the API name, it fires precisely when the snapshot attribute is modified and can be extended to trigger Lambda remediations.

Why this answer

The `ModifyDBSnapshotAttribute` API call is the specific action used to share an RDS snapshot with an external AWS account. By creating an Amazon EventBridge rule that triggers on this API call, the team can immediately send an alert via Amazon SNS, enabling real-time detection and response to unauthorized snapshot sharing. This approach is automated, event-driven, and directly targets the exfiltration vector.

Exam trap

The trap here is that candidates often confuse AWS Config (which is configuration-aware but not real-time) with EventBridge (which is event-driven and real-time), or they mistakenly think GuardDuty RDS Protection covers all RDS-related threats, including data exfiltration via snapshot sharing, when it actually focuses on database-level threats like brute-force attacks or anomalous queries.

How to eliminate wrong answers

Option A is wrong because AWS Config can detect changes to RDS snapshot attributes, but it is a compliance-oriented service that evaluates resource configurations periodically (e.g., every 10 minutes) and does not provide real-time alerting on API calls; it would also require custom rules and lacks the immediate notification capability needed for security incidents. Option B is wrong because Amazon GuardDuty with RDS Protection focuses on detecting suspicious login attempts, anomalous access patterns, and potential compromise of the RDS instance itself, not on monitoring API-level actions like snapshot sharing. Option D is wrong because enabling AWS CloudTrail and manually reviewing logs is reactive, not proactive; it does not provide automated alerting and would be impractical for timely detection of exfiltration events.

81
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to centrally manage IAM policies across all accounts. Which AWS feature should the team use to enforce permissions across member accounts?

A.IAM roles with cross-account access
B.Service Control Policies (SCPs)
C.AWS Config rules
D.AWS CloudTrail trails
AnswerB

Service Control Policies (SCPs) are AWS Organizations policies that centrally manage the maximum available permissions for identities and resources in member accounts. They act as guardrails that restrict what IAM users, roles, and even the root user can do in an account, without granting any permissions themselves. By attaching SCPs to accounts or organizational units, you can enforce consistent permission boundaries across the entire organization, which directly matches the requirement for central permission control.

Why this answer

Service Control Policies (SCPs) allow central control over permissions for all accounts in an organization. Option A is wrong because IAM roles with cross-account access provide temporary access but do not enforce policies centrally. Option C is wrong because AWS Config rules are for compliance monitoring, not permission enforcement.

Option D is wrong because AWS CloudTrail is for auditing, not enforcement.

82
Multi-Selectmedium

Which TWO statements are true about IAM roles? (Choose two.)

Select 2 answers
A.IAM roles can be used by federated users.
B.IAM roles are specific to an AWS region.
C.IAM roles cannot be attached to an EC2 instance.
D.IAM roles have permanent access keys.
E.IAM roles can be assumed by AWS services like EC2.
AnswersA, E

Federated users, such as those authenticated by an external identity provider via SAML 2.0 or web identity federation, can assume an IAM role to obtain temporary AWS credentials. The user's original identity is mapped to a role, and AWS STS issues scoped, time-limited access keys that abide by the role's trust and permissions policies. This allows external identities to access AWS resources without creating an IAM user and without distributing permanent credentials.

Why this answer

Option A is correct because IAM roles support identity federation: users authenticated by an external identity provider (via SAML 2.0 or OIDC, or via AWS STS AssumeRoleWithSAML/AssumeRoleWithWebIdentity) receive temporary credentials scoped to the role's permissions rather than needing IAM user accounts. Option E is correct because AWS services can assume roles through a trust policy that names the service principal (for example, ec2.amazonaws.com), which is exactly how an instance profile lets EC2 instances obtain temporary credentials from the instance metadata service. Option B is wrong because IAM roles, like IAM users and policies, are global resources not tied to a specific AWS region.

Option C is wrong because roles are in fact attached to EC2 instances via instance profiles. Option D is wrong because roles never issue permanent access keys; they provide temporary credentials through AWS STS with automatic rotation and expiration.

Exam trap

SCS-C02 often tests the characteristics of IAM roles, and candidates might mistakenly think roles are regional or provide permanent credentials; the key is that roles are global and provide temporary credentials.

83
MCQhard

A security engineer is configuring AWS WAF to protect an Application Load Balancer (ALB) from SQL injection attacks. The engineer must ensure that only requests with a specific header are allowed and that SQL injection attempts are blocked. Which combination of AWS WAF components should the engineer use?

A.A web ACL with a rule that blocks requests missing the required header, and a rule that uses the SQL injection match condition to block malicious requests.
B.A web ACL with a rule that allows requests with the header and a rule that uses the SQL injection match condition to count malicious requests.
C.A web ACL with a rule that blocks requests missing the header, and a rule that uses a regex pattern set to block SQL injection attempts.
D.A web ACL with a rate-based rule to limit requests and a rule that uses the SQL injection match condition to block malicious requests.
AnswerA

AWS WAF web ACLs contain rules that can inspect headers and use match conditions like SQL injection. A rule to block requests missing the header enforces the header requirement, and a SQL injection match condition blocks malicious payloads. Both can be combined in a single web ACL associated with the ALB.

Why this answer

AWS WAF web ACLs can contain multiple rules. To enforce a required header, a rule that blocks requests missing that header is needed. To block SQL injection, the built-in SQL injection match condition is the appropriate choice.

Combining these two rules in a web ACL associated with the ALB meets both requirements.

Exam trap

The trap here is confusing count and block actions, or assuming that a rate-based rule or regex pattern set can replace the dedicated SQL injection match condition and header check.

84
MCQhard

A company uses AWS Direct Connect to connect its on-premises data center to a VPC. The security team wants to encrypt all traffic between on-premises and the VPC. Which solution should be used?

A.Enable encryption on the Direct Connect virtual interface
B.Use VPC Peering with encryption
C.Set up an IPsec VPN over the Direct Connect connection
D.Configure TLS on all applications
AnswerC

Yes—this is the standard pattern when you need encryption over Direct Connect. You can deploy a site-to-site VPN on a public virtual interface, or terminate a software VPN on an EC2 instance behind a private VIF, so IPsec encapsulates the IP packets and secures the entire path while still benefiting from Direct Connect's bandwidth and latency. IPsec provides authenticity, integrity, and confidentiality for all traffic, making it the appropriate answer for the stated requirement.

Why this answer

Direct Connect does not natively encrypt traffic; it provides a private, low-latency connection but the data traverses it in cleartext. By establishing an IPsec VPN tunnel over the Direct Connect link (often called a 'Direct Connect VPN' or using a virtual private gateway with a VPN attachment), you encrypt all traffic between on-premises and the VPC at the network layer, meeting the security team's requirement for encryption.

Exam trap

The trap here is that candidates assume Direct Connect inherently provides encryption because it is a private connection, but AWS explicitly states that Direct Connect does not encrypt traffic, and the correct approach is to overlay an IPsec VPN tunnel.

How to eliminate wrong answers

Option A is wrong because Direct Connect virtual interfaces (private, public, or transit) do not support native encryption; they operate at Layer 2/3 without any built-in encryption mechanism. Option B is wrong because VPC Peering does not provide encryption; it is a Layer 3 connection that routes traffic over the AWS backbone without encryption, and it cannot be used to connect an on-premises data center to a VPC. Option D is wrong because configuring TLS on all applications only encrypts application-layer traffic for specific protocols (e.g., HTTPS), leaving other traffic (e.g., SSH, database connections, or custom protocols) unencrypted and does not provide a comprehensive network-layer encryption solution.

85
MCQmedium

A financial services company runs a production AWS account. A security engineer must ensure that IAM users cannot disable AWS CloudTrail logging in any region. The engineer attaches a permissions boundary to every IAM user. Which permissions boundary policy statement BEST enforces this requirement?

A.An Allow statement for cloudtrail:StopLogging with a condition that the request originates from the corporate CIDR range.
B.A Deny statement for cloudtrail:StopLogging with no conditions, plus an Allow statement for all other actions the users need.
C.A Deny statement for cloudtrail:StopLogging with a condition that aws:PrincipalTag/role equals 'security-auditor'.
D.An Allow statement for cloudtrail:* with a condition that aws:RequestedRegion is not the production region.
AnswerB

A permissions boundary with an explicit Deny for cloudtrail:StopLogging and Allow for required actions ensures no identity-based policy can override the deny. The boundary caps maximum permissions, so even if an administrator later attaches a broad policy, the deny remains effective. This directly enforces the requirement without blocking unrelated operations.

Why this answer

A permissions boundary defines the maximum permissions an identity can have, and an explicit Deny within it cannot be overridden by identity-based policies. Combining a Deny for cloudtrail:StopLogging with Allow for needed actions prevents any user from disabling logging while preserving normal access. Conditional or tag-scoped statements leave gaps that allow the prohibited action.

Exam trap

The trap here is assuming that an Allow statement with a restrictive condition is equivalent to a Deny, when only an explicit Deny in a permissions boundary can guarantee the action is blocked.

86
MCQeasy

A security engineer needs to ensure that an EC2 instance can only be accessed using SSH key pairs, not passwords. Which configuration is required?

A.Use EC2 Instance Connect instead of SSH
B.Set 'PasswordAuthentication no' in /etc/ssh/sshd_config on the EC2 instance
C.Attach an IAM role to the instance that denies password-based access
D.Configure the security group to allow SSH only from specific IP addresses
AnswerB

Forcing key-based authentication on an EC2 instance requires disabling password logins at the OpenSSH daemon level by setting 'PasswordAuthentication no' in /etc/ssh/sshd_config and restarting sshd. This directly changes how the SSH server validates users: public key cryptography becomes the only accepted method, and password prompts are no longer offered. Because sshd reads this configuration on startup, the setting takes effect for all SSH connections, making it a true enforcement mechanism rather than a workflow convenience.

Why this answer

SSH password authentication is controlled by the `PasswordAuthentication` directive in `/etc/ssh/sshd_config`. Setting it to `no` disables password-based logins, forcing users to authenticate using SSH key pairs (public-key cryptography). This is the standard, OS-level method to enforce key-only SSH access on an EC2 instance.

Exam trap

The trap here is that candidates confuse network-level controls (security groups) or IAM permissions with OS-level authentication settings, assuming AWS services can enforce SSH password policies when only the instance's SSH daemon configuration can do so.

How to eliminate wrong answers

Option A is wrong because EC2 Instance Connect is a service that uses SSH keys (or AWS-provided keys) to connect, but it does not disable password authentication on the instance; it merely provides an alternative connection method. Option C is wrong because IAM roles control AWS API-level permissions (e.g., starting/stopping instances) and cannot enforce OS-level SSH authentication settings like password vs. key-based login. Option D is wrong because security group rules restrict network access by source IP, not the authentication method; they do not prevent password-based SSH logins if the instance allows them.

87
MCQeasy

A company wants to securely store and manage SSL/TLS certificates for use with CloudFront. Which AWS service should be used?

A.AWS Identity and Access Management (IAM)
B.AWS Key Management Service (AWS KMS)
C.AWS Certificate Manager (ACM)
D.AWS CloudHSM
AnswerC

AWS Certificate Manager provisions SSL/TLS certificates for public and private domains, handles domain validation via DNS or email, and automatically renews eligible certificates before expiry. It natively deploys the certificate to integrated AWS services such as Application Load Balancers, CloudFront, and API Gateway, eliminating manual installation and tracking. Because the private key is generated in and protected by AWS-managed hardware, ACM is the correct service for the stated requirement to securely store and manage SSL/TLS certificates.

Why this answer

AWS Certificate Manager (ACM) is the correct service because it is specifically designed to provision, manage, and deploy public and private SSL/TLS certificates for use with AWS services like CloudFront. ACM integrates directly with CloudFront to automatically renew certificates before expiration, eliminating manual renewal overhead. It also handles the complex certificate chain and private key management securely, ensuring HTTPS termination at CloudFront edge locations.

Exam trap

The trap here is that candidates often confuse AWS KMS or IAM Server Certificate Store as viable options for CloudFront, but ACM is the only service that provides automatic renewal and native integration with CloudFront, and certificates must be in us-east-1.

How to eliminate wrong answers

Option A is wrong because AWS Identity and Access Management (IAM) is a service for managing user identities, permissions, and access control, not for storing or managing SSL/TLS certificates; while IAM can store server certificates for use with Elastic Load Balancers (ELBs) via the IAM Server Certificate Store, it does not support CloudFront and lacks automatic renewal features. Option B is wrong because AWS Key Management Service (AWS KMS) is a managed service for creating and controlling encryption keys used to encrypt data at rest, not for managing SSL/TLS certificates; KMS does not handle certificate issuance, renewal, or integration with CloudFront. Option D is wrong because AWS CloudHSM provides dedicated hardware security modules (HSMs) for cryptographic key storage and operations, but it is not designed for SSL/TLS certificate lifecycle management; using CloudHSM for certificates would require custom development and manual renewal, and it does not natively integrate with CloudFront.

88
MCQmedium

A company's AWS Lambda function that processes sensitive data is triggering unexpectedly. The security team wants to investigate using AWS CloudTrail. What should they look for?

A.`UpdateFunctionConfiguration` events in CloudTrail from the Lambda service.
B.`CreateFunction` events in CloudTrail from the Lambda service.
C.`Invoke` events in CloudTrail from the Lambda service.
D.`PutSubscriptionFilter` events in CloudTrail from CloudWatch Logs.
AnswerC

Invoke events are the Lambda data-plane records logged to CloudTrail every time the function is actually called; each event captures the function name, qualifier, timestamp, request parameters, and invoking principal. Enabling data events on Lambda in a CloudTrail trail is what makes these entries appear, and they are precisely what an auditor needs to see who invoked the function and when. This is why Invoke is the correct way to audit that sensitive-data processing occurred.

Why this answer

`Invoke` events in CloudTrail record every invocation of a Lambda function, including the source (e.g., AWS service, SDK, or console) and the identity that triggered it. By analyzing these events, the security team can identify unexpected triggers, such as unauthorized IAM users or roles invoking the function, or anomalous invocation patterns that indicate a potential security issue.

Exam trap

The trap here is that candidates may confuse configuration or creation events with invocation events, mistakenly thinking that `UpdateFunctionConfiguration` or `CreateFunction` would show who triggered the function, when in fact only `Invoke` events capture the actual execution requests.

How to eliminate wrong answers

Option A is wrong because `UpdateFunctionConfiguration` events record changes to the function's configuration (e.g., memory, timeout, environment variables), not the actual invocations that would reveal unexpected triggers. Option B is wrong because `CreateFunction` events record the creation of new Lambda functions, not the triggering of an existing function. Option D is wrong because `PutSubscriptionFilter` events from CloudWatch Logs are used to configure log subscription filters for streaming log data, not to capture Lambda invocation events.

89
MCQmedium

A company has an S3 bucket with a bucket policy that grants access to an IAM role used by an application running on EC2. The application is unable to read objects from the bucket, even though the IAM role has the necessary permissions. What is the most likely cause?

A.The bucket is in a different AWS account.
B.The bucket policy denies access to the IAM role.
C.The bucket policy does not explicitly allow the IAM role.
D.The IAM role has an explicit deny statement.
AnswerB

An explicit Deny statement in the bucket policy takes precedence over every Allow, including the IAM role's identity-based permissions. In AWS authorization, the evaluation first defaults to deny, then any allow from identity-based or resource-based policy, but if an explicit deny exists in either policy, the final decision is deny. Thus if the bucket policy contains a statement that denies this role (or the role's account) the s3 operation, access will be blocked even though the role policy appears to grant the necessary permissions.

Why this answer

The most likely cause is that the bucket policy explicitly denies access to the IAM role. Even though the IAM role has the necessary permissions via its attached policies, an explicit deny in the bucket policy overrides any allow, resulting in denied access. Option A is incorrect because cross-account access can be granted with proper permissions.

Option C is incorrect because while a missing explicit allow would also deny access by default, the question says the IAM role has the necessary permissions, implying the issue is an explicit deny. Option D is incorrect because if the IAM role had an explicit deny, it would also deny access, but the role is stated to have the necessary permissions.

90
MCQmedium

A security engineer needs to protect sensitive data stored in an Amazon S3 bucket. The data must be encrypted at rest using a customer managed key in AWS KMS, and the engineer wants to ensure that all requests to upload objects without encryption are automatically denied. The bucket is in account 111122223333. Which S3 bucket policy statement should the engineer use?

A.A statement that denies s3:PutObject if the request includes the s3:x-amz-server-side-encryption header with value aws:kms.
B.A statement that denies s3:PutObject if the request lacks the s3:x-amz-server-side-encryption header with value aws:kms.
C.A statement that denies s3:PutObject if the request does not include the s3:x-amz-server-side-encryption header with value AES256.
D.A statement that allows s3:PutObject only if the request includes the s3:x-amz-server-side-encryption header with value AES256.
AnswerB

This policy uses a Deny effect with a condition that checks for the presence and value of the s3:x-amz-server-side-encryption header. If a PutObject request does not include the header with aws:kms, the request is denied. This enforces encryption with SSE-KMS for all uploads. It is the standard way to require a specific encryption method for objects uploaded to an S3 bucket.

Why this answer

To enforce that all objects uploaded to an S3 bucket are encrypted with SSE-KMS, the bucket policy must include a Deny statement that blocks PutObject requests when the s3:x-amz-server-side-encryption header is missing or not set to aws:kms. This ensures that any upload without the required encryption header is rejected. Allow statements alone do not prevent non-compliant uploads, and conditions specifying AES256 enforce SSE-S3, not SSE-KMS.

Exam trap

The trap here is using an Allow statement instead of a Deny statement, or confusing the header value for SSE-S3 (AES256) with SSE-KMS (aws:kms).

91
MCQhard

A company has a requirement to retain CloudTrail logs for 7 years to meet regulatory compliance. They want to minimize storage costs while ensuring logs are immutable and cannot be deleted by anyone, including the root user. What should they do?

A.Configure the S3 bucket with MFA Delete enabled.
B.Use CloudTrail log file validation and enable AWS CloudTrail Insights.
C.Store the logs in Amazon S3 Glacier Deep Archive with a vault lock policy.
D.Enable S3 Object Lock in Compliance mode on the destination bucket.
AnswerD

Enabling S3 Object Lock in Compliance mode places a retention lock on objects until a specified date; during that retention period no user, not even the AWS account root user, can delete or overwrite them. Compliance mode is the strongest Object Lock mode because the retention protection cannot be shortened, removed, or bypassed by any principal. When used as the destination for CloudTrail logs, this guarantees the logs are retained for the full seven years and satisfies the stated requirement.

Why this answer

S3 Object Lock in Compliance mode prevents any user, including the root user, from deleting or overwriting objects for the specified retention period. This meets the immutability and retention requirements for CloudTrail logs, and by using S3 lifecycle policies to transition logs to lower-cost storage classes (e.g., S3 Glacier Deep Archive) after the initial retention period, storage costs can be minimized while maintaining compliance.

Exam trap

The trap here is that candidates may confuse S3 Glacier Vault Lock (which applies to Glacier archives, not S3 objects) with S3 Object Lock, or assume MFA Delete provides sufficient immutability, when in fact only S3 Object Lock in Compliance mode guarantees that no user, including root, can delete objects before the retention period ends.

How to eliminate wrong answers

Option A is wrong because MFA Delete only requires multi-factor authentication for delete operations but does not prevent the root user from deleting objects if they have the MFA device; it also does not enforce immutability or a fixed retention period. Option B is wrong because CloudTrail log file validation provides integrity verification (detecting tampering) but does not prevent deletion or enforce retention; AWS CloudTrail Insights is for detecting unusual activity, not for immutability or retention. Option C is wrong because S3 Glacier Deep Archive with a vault lock policy can enforce write-once-read-many (WORM) compliance, but CloudTrail logs are stored in S3 buckets, not directly in Glacier vaults; the vault lock policy applies to archives in Glacier, not to S3 objects, and transitioning logs to Glacier Deep Archive via S3 lifecycle policies does not inherently provide immutability unless combined with S3 Object Lock.

92
MCQeasy

A security engineer needs to ensure that all Amazon EBS volumes attached to EC2 instances in a production account are encrypted at rest. The engineer wants to enforce this requirement automatically and prevent the creation of unencrypted volumes. Which action should the engineer take?

A.Attach a bucket policy to the EBS service that requires encryption.
B.Enable EBS encryption by default in the AWS Region.
C.Create an IAM policy that denies the ec2:CreateVolume action unless the encrypted parameter is true.
D.Use AWS Config to monitor for unencrypted volumes and automatically delete them.
AnswerB

Enabling EBS encryption by default ensures that all new EBS volumes created in the Region are automatically encrypted using the default KMS key for EBS encryption. This enforces encryption at rest without requiring manual intervention for each volume. It also prevents the creation of unencrypted volumes, meeting the requirement.

Why this answer

Enabling EBS encryption by default in the Region ensures that all new EBS volumes are automatically encrypted at rest. This is a simple, effective way to enforce encryption and prevent the creation of unencrypted volumes. It applies to all new volumes regardless of how they are created, providing a robust control.

Exam trap

The trap here is thinking that IAM policies or AWS Config are the primary enforcement mechanisms, when the simplest and most direct method is enabling encryption by default.

93
MCQeasy

A company wants to receive real-time notifications for every root user login to the AWS Management Console. Which service should be used?

A.Amazon GuardDuty
B.AWS CloudTrail
C.Amazon CloudWatch Events
D.AWS Config
AnswerC

Amazon CloudWatch Events (and its successor Amazon EventBridge) is correct because it can ingest CloudTrail events and apply an event pattern that matches a root user console login. A rule can specify the event source as aws.signin, the detail.eventName as ConsoleLogin, and the userIdentity.userName as root, routing matches to an SNS topic for immediate delivery. This pattern-based routing reacts in near real time, typically within seconds of the API call, and can also capture failed login attempts and MFA-related details. Since the requirement is real-time notifications for every root login, CloudWatch Events with an SNS target is exactly the alerting layer that CloudTrail alone lacks.

Why this answer

Amazon CloudWatch Events (now part of Amazon EventBridge) can capture AWS API calls via CloudTrail and trigger a rule that matches the 'RootLogin' event. This allows real-time notification through SNS, Lambda, or other targets whenever a root user signs in to the Management Console.

Exam trap

The trap here is that candidates often choose AWS CloudTrail because it records root logins, but they overlook that CloudTrail alone does not provide real-time notifications; it requires CloudWatch Events/EventBridge to trigger alerts.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes logs for malicious activity, but it does not provide real-time event-driven notifications for specific API calls like root logins. Option B is wrong because AWS CloudTrail records API activity and delivers log files to S3, but it does not natively trigger real-time notifications; it requires integration with CloudWatch Events for that purpose. Option D is wrong because AWS Config evaluates resource configurations against desired policies and tracks configuration changes, but it does not monitor or notify on IAM user login events.

94
Multi-Selecthard

A company is implementing AWS Organizations with multiple accounts. Which THREE are benefits of using service control policies (SCPs)? (Choose three.)

Select 3 answers
A.Grant cross-account access
B.Prevent users from disabling CloudTrail
C.Enforce compliance requirements
D.Manage consolidated billing
E.Centrally restrict permissions across accounts
AnswersB, C, E

Specifically, SCPs can deny the CloudTrail management actions such as cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail, preventing even the root user in a member account from disabling audit logging. Because SCPs act as an overlay on all IAM identities within the affected accounts, they are an effective detective and preventive control for maintaining an immutable trail record. This is a common pattern for meeting audit and security requirements.

Why this answer

Option B is correct because an SCP can deny the cloudtrail:StopLogging and cloudtrail:DeleteTrail actions at the OU or account level, ensuring member accounts cannot disable or delete CloudTrail trails even if their IAM policies allow it. Option C is correct because SCPs let you codify and enforce organizational compliance guardrails—such as blocking use of unapproved regions or services—uniformly across all accounts in an OU. Option E is correct because SCPs are the AWS Organizations mechanism for centrally setting the maximum available permissions for principals in member accounts, restricting what IAM policies can grant.

Option A is not a benefit of SCPs because SCPs only filter/limit permissions; they never grant access, so cross-account access must be established with IAM roles, resource policies, or identity federation. Option D is not a benefit of SCPs because consolidated billing is a separate AWS Organizations feature handled by the management account's payment method, not by service control policies.

Exam trap

SCS-C02 often tests the misconception that SCPs grant permissions or handle billing, when they only restrict permissions and consolidated billing is a separate Organizations feature.

95
MCQmedium

A security engineer needs to ensure that all EC2 instances launched in a development account are tagged with a cost center. What is the most effective way to enforce this?

A.Use AWS Config to detect untagged instances and send alerts
B.Use AWS Systems Manager to tag instances after launch
C.Create a tag policy in AWS Organizations requiring the cost center tag
D.Use an IAM policy that denies ec2:RunInstances unless the request includes the cost center tag
AnswerD

An IAM policy can explicitly deny ec2:RunInstances when a condition key such as ec2:RequestTag/cost-center is absent from the API request—for example, by using a Null condition set to true. Because IAM policies are evaluated before the API call is executed, any launch attempt that omits the cost-center tag is immediately rejected, before any instance is created. This is a true preventive control and is the only listed option that stops the launch itself.

Why this answer

Using an IAM policy with a condition key (e.g., `aws:RequestTag`) that denies `ec2:RunInstances` unless the `cost center` tag is specified in the API call enforces tagging at launch time. This prevents any untagged instance from being created, providing proactive enforcement rather than reactive detection or remediation.

Exam trap

The trap here is that candidates often choose AWS Config (Option A) because it is a common governance tool, but they miss that Config only detects non-compliance after the fact, whereas IAM policies provide preventive enforcement at the API level.

How to eliminate wrong answers

Option A is wrong because AWS Config can only detect and alert on untagged instances after they are launched, not prevent their creation, leaving a window of non-compliance. Option B is wrong because AWS Systems Manager can tag instances after launch, but this is a reactive measure that does not enforce tagging at creation time and may miss instances that are not managed by Systems Manager. Option C is wrong because tag policies in AWS Organizations are used to enforce consistent tagging across accounts but do not prevent the launch of untagged resources; they only provide a compliance check and can mark non-compliant resources, not block the action.

96
MCQhard

A security engineer is configuring AWS IAM Identity Center (successor to AWS Single Sign-On) for a company that uses an external identity provider (IdP) supporting SAML 2.0. The company wants to assign users to AWS accounts based on their groups in the IdP. The engineer has already configured the IdP and the SAML trust. What is the next step to ensure that users can access the correct AWS accounts with the appropriate permissions?

A.Use AWS Organizations SCPs to grant permissions to IdP groups based on their group names.
B.Configure IAM roles in each AWS account with trust policies that allow the IdP to assume them, and then map groups to roles.
C.In IAM Identity Center, create permission sets that define the policies, then assign the IdP groups to AWS accounts with those permission sets.
D.Create IAM users in each AWS account and map them to the IdP groups.
AnswerC

This is the correct next step. Permission sets define the level of access (e.g., read-only, admin) and are assigned to IdP groups for specific AWS accounts. This leverages the group membership from the IdP to grant access without creating individual IAM users. It centralizes management and ensures that users get the right permissions in the right accounts.

Why this answer

After configuring the SAML trust with the external IdP, the next step in IAM Identity Center is to create permission sets that define the policies for access, and then assign those permission sets to the IdP groups for specific AWS accounts. This maps group memberships to AWS permissions without creating IAM users, enabling centralized and scalable access management.

Exam trap

The trap here is thinking that IAM users or manually created IAM roles are needed when using IAM Identity Center with an external IdP, when in fact permission sets and group assignments handle everything.

97
MCQeasy

A company wants to automatically isolate an EC2 instance that is suspected to be compromised. What is the MOST effective AWS-native approach?

A.Terminate the instance immediately
B.Use Amazon GuardDuty to detect the compromise and automatically modify the instance's security group to deny all traffic
C.Use AWS Config to change the instance's IAM role
D.Use AWS Systems Manager to run a script that stops the instance
AnswerB

Amazon GuardDuty consumes VPC DNS logs, flow logs, and other telemetry to identify suspicious behavior such as outbound traffic to known command-and-control IPs. A high-severity finding can be sent to Amazon EventBridge, which invokes an AWS Lambda function that replaces the instance's security group with a quarantine security group containing a deny-all inbound and outbound rule, instantly severing network connectivity. This agentless containment preserves the running instance and its memory for investigation and is the recommended automated isolation pattern.

Why this answer

Amazon GuardDuty can detect suspicious activity on an EC2 instance (e.g., cryptocurrency mining, unusual outbound traffic) and, when integrated with Amazon EventBridge and AWS Lambda, automatically modify the instance's security group to deny all traffic. This approach isolates the instance without terminating it, preserving forensic evidence and allowing further investigation. It is the most effective AWS-native approach because it combines threat detection with automated, least-privilege response actions.

Exam trap

The trap here is that candidates often choose termination (Option A) thinking it is the fastest way to stop the threat, but the exam emphasizes preserving forensic evidence and using automated, reversible isolation mechanisms like security group modification.

How to eliminate wrong answers

Option A is wrong because terminating the instance destroys volatile forensic data (memory, disk) and prevents post-incident analysis, which is contrary to incident response best practices. Option C is wrong because changing the instance's IAM role does not affect network traffic; the instance remains accessible over the network, so it does not isolate the compromised instance. Option D is wrong because using AWS Systems Manager to run a script that stops the instance still leaves the instance accessible until the stop completes, and stopping does not block network access immediately; additionally, Systems Manager requires the instance to have network connectivity to receive the command, which may not be reliable if the instance is already compromised.

98
MCQmedium

A company wants to detect and alert on suspicious IAM role usage, such as a role being assumed from an unusual geographic location. Which AWS service should be used to generate the alerts?

A.AWS IAM Access Analyzer
B.Amazon GuardDuty
C.AWS CloudTrail
D.Amazon CloudWatch
AnswerB

Amazon GuardDuty continuously monitors CloudTrail management events, including IAM role assumptions and API activity, using machine learning and threat intelligence to detect suspicious behavior such as credential exfiltration or anomalous role usage. It generates findings that can trigger alerts via EventBridge, making it the correct choice for detecting and alerting on suspicious IAM role activity.

Why this answer

Amazon GuardDuty is the correct choice because it is a threat detection service that continuously monitors for suspicious activity, including unusual IAM role usage such as a role being assumed from an anomalous geographic location. It uses machine learning, anomaly detection, and integrated threat intelligence to analyze CloudTrail management events and VPC flow logs, generating alerts (findings) for deviations from baseline behavior. This directly meets the requirement to detect and alert on suspicious role assumptions without needing to write custom rules.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail's logging capability with detection, assuming that because CloudTrail records the AssumeRole event, it can also alert on it, but CloudTrail requires an additional service like GuardDuty or CloudWatch with custom rules to generate alerts, whereas GuardDuty provides built-in, automated anomaly detection for this exact scenario.

How to eliminate wrong answers

Option A is wrong because AWS IAM Access Analyzer is designed to identify resources shared with external entities by analyzing resource-based policies, not to detect anomalous IAM role usage or generate real-time alerts based on geographic location. Option C is wrong because AWS CloudTrail is a logging service that records API activity but does not natively analyze logs for suspicious patterns or generate alerts; it requires additional services like CloudWatch Logs or GuardDuty to process and alert on the data. Option D is wrong because Amazon CloudWatch is a monitoring and observability service that can trigger alarms based on metrics or log patterns, but it lacks built-in anomaly detection for IAM role usage from unusual locations and would require custom metric filters and manual threshold configuration, making it less effective and more complex than GuardDuty's purpose-built capabilities.

99
Multi-Selecteasy

Which TWO of the following are AWS best practices for managing access keys? (Choose 2.)

Select 2 answers
A.Use the same access key for multiple users.
B.Share access keys via email.
C.Delete unused access keys.
D.Rotate access keys regularly.
E.Embed access keys directly in application code.
AnswersC, D

Unused access keys are dormant credentials that an attacker can abuse without the legitimate owner noticing, and they are frequently omitted from routine code and permission reviews. AWS provides the IAM credential report and the LastUsed timestamp for each key, so you should regularly identify keys that have not been used for 90 days and deactivate or delete them to reduce the total attack surface and simplify incident investigation.

Why this answer

AWS best practices recommend deleting unused access keys to reduce the risk of unauthorized access. Unused keys represent a potential attack vector, as they may be forgotten and left active, allowing an attacker who discovers them to gain access to AWS resources. By regularly auditing and removing keys that are no longer in use, you minimize the exposure of long-lived credentials.

Exam trap

The trap here is that candidates may think embedding keys in code is acceptable if the code is in a private repository, but AWS explicitly prohibits this practice and recommends using IAM roles or AWS Secrets Manager instead.

100
MCQeasy

A security engineer is investigating a potential data breach and finds this CloudTrail log entry. What does this entry indicate?

A.A user encrypted data using a KMS key
B.A user decrypted data using a KMS key
C.An anonymous user accessed the KMS key
D.The KMS key was deleted
AnswerB

The wrong options are eliminated because this is a Decrypt event: a user invoked the KMS Decrypt API to reveal plaintext from previously encrypted data. In an investigation, this event is significant because it shows the KMS key was used to turn ciphertext into plaintext, which is how an attacker or insider would access data after exfiltrating it. Therefore, this interpretation correctly matches the CloudTrail record and indicates a potential data disclosure.

Why this answer

The CloudTrail entry shows a Decrypt API call against a KMS key, which indicates a principal used the key to decrypt ciphertext. This is the standard CloudTrail event emitted when KMS performs a cryptographic decryption operation.

Exam trap

The trap here is that candidates see a KMS-related CloudTrail entry and assume encryption or key deletion, when the specific eventName (Decrypt) is the decisive detail that must be read carefully.

How to eliminate wrong answers

Option A is wrong because encryption would appear as an Encrypt event, not Decrypt. Option C is wrong because CloudTrail records the authenticated principal's ARN; anonymous access to KMS is not possible since KMS requires IAM authentication. Option D is wrong because key deletion appears as ScheduleKeyDeletion or DisableKey, not Decrypt.

101
MCQeasy

A company uses AWS Secrets Manager to store database credentials. The security team needs to ensure that secrets are automatically rotated every 30 days. Which configuration should be used?

A.Manually update the secret in Secrets Manager every 30 days.
B.Use Amazon Macie to detect when secrets are stale.
C.Set an expiration date on the secret and recreate it.
D.Enable automatic rotation using an AWS Lambda function.
AnswerD

Secrets Manager natively supports automatic rotation by invoking an AWS Lambda function that updates the secret and the database credential in a coordinated fashion. The Lambda function follows the rotation schedule you configure (for example, every 30 days) and uses staged steps to ensure the secret is valid before promoting it, while also updating the target database. This fully automates the credential lifecycle, eliminates manual intervention, and is the correct way to enforce periodic rotation for database credentials stored in Secrets Manager.

Why this answer

AWS Secrets Manager provides a built-in mechanism to automatically rotate secrets using an AWS Lambda function. By configuring a rotation schedule (e.g., every 30 days), Secrets Manager invokes the Lambda function to create a new version of the secret and update the database credentials, ensuring compliance without manual intervention.

Exam trap

The trap here is that candidates may confuse setting an expiration date (Option C) with automatic rotation, but expiration only triggers deletion or recreation, not the seamless, scheduled credential update that a Lambda-based rotation provides.

How to eliminate wrong answers

Option A is wrong because manually updating the secret every 30 days is not automated and violates the requirement for automatic rotation; it also introduces human error risk and operational overhead. Option B is wrong because Amazon Macie is a data discovery and classification service that identifies sensitive data in S3, not a tool for detecting stale secrets or managing rotation schedules in Secrets Manager. Option C is wrong because setting an expiration date on a secret only marks it for deletion or forces recreation, but does not automatically rotate the secret; the secret must be manually recreated, and the rotation process is not triggered by expiration alone.

102
MCQmedium

A security engineer reviews the CloudTrail log entry in the exhibit. The engineer notices that an EC2 instance was launched using an AdminRole. Which additional information would help determine if this is a legitimate action or a potential compromise?

A.The AMI ID ami-0abcdef1234567890 is not a standard Amazon-provided AMI.
B.The source IP address 203.0.113.50 is from an unexpected geographic location not associated with the company.
C.The instance type m5.xlarge is unusually large compared to previous launches.
D.The security group sg-0123456789abcdef0 allows inbound SSH from 0.0.0.0/0.
AnswerB

The source IP address 203.0.113.50 is recorded in the CloudTrail event as sourceIPAddress, and it originates from a geographic region outside the company's known operating footprint. Anomalous source IPs are a well-known indicator of compromised credentials or unauthorized access, especially when combined with API calls that create resources. This is the only option that represents an actual observable anomaly in the log entry itself, making it the strongest sign of suspicious activity.

Why this answer

The source IP address 203.0.113.50 is from an unexpected geographic location not associated with the company. In CloudTrail, the `sourceIPAddress` field records the originating IP of the API call. If an AdminRole is used from an IP outside the company's known CIDR ranges or geographic regions, it strongly indicates a potential compromise—such as stolen credentials or an attacker using the role from an unauthorized network.

This is a key indicator of anomalous behavior in threat detection.

Exam trap

The trap here is that candidates focus on technical misconfigurations (like open security groups or unusual AMIs) rather than the behavioral anomaly of an administrative action originating from an unexpected IP, which is the most direct indicator of a potential compromise in CloudTrail logs.

How to eliminate wrong answers

Option A is wrong because an AMI ID that is not a standard Amazon-provided AMI could be a custom or marketplace AMI, which is common in legitimate environments; it does not alone indicate compromise. Option B is correct as explained. Option C is wrong because an instance type like m5.xlarge may be larger than usual but could be legitimate for a specific workload; size alone is not a reliable indicator of compromise without context like cost anomalies or unusual launch patterns.

Option D is wrong because a security group allowing inbound SSH from 0.0.0.0/0 is a misconfiguration that increases risk, but it does not directly indicate that the launch action itself was unauthorized or compromised—it is a separate security issue.

103
Multi-Selectmedium

A company is designing a data protection strategy for its Amazon S3 bucket that stores sensitive documents. The security team requires that all data be encrypted in transit and at rest, and that any accidental deletion of objects can be reversed within 30 days. Additionally, the company must be able to audit all access attempts to the bucket, including failed attempts. Which TWO actions should the company take to meet these requirements? (Choose two.)

Select 2 answers
A.Enable default encryption on the bucket using SSE-S3.
B.Enable AWS CloudTrail with data events for S3.
C.Enable S3 Versioning on the bucket.
D.Enable S3 server access logs and send them to a separate bucket.
E.Enable MFA Delete on the bucket.
AnswersB, C

Enabling CloudTrail with data events for an S3 bucket records object-level operations such as GetObject, PutObject, DeleteObject, and HeadObject, capturing the IAM principal, source IP, and whether the request succeeded or failed. This creates an authoritative, queryable audit trail that can be searched in CloudTrail Lake or Athena and is essential for incident investigation, compliance reporting, and detecting compromised credentials. Unlike server access logs, CloudTrail data events reliably include failed attempts.

Why this answer

AWS CloudTrail with data events for S3 is correct because it captures all S3 API calls, including GetObject, PutObject, and DeleteObject, and records both successful and failed access attempts. This meets the auditing requirement for all access attempts, including failed ones, as CloudTrail logs the request details, error codes, and source IP addresses.

Exam trap

The trap here is that candidates often confuse S3 server access logs (which log successful requests only) with CloudTrail data events (which log all API calls, including failures), leading them to select Option D instead of Option B.

104
Multi-Selecteasy

Which TWO AWS services can be used to detect and alert on suspicious activity in near real-time?

Select 2 answers
A.Amazon CloudWatch Events
B.Amazon Inspector
C.Amazon GuardDuty
D.AWS CloudTrail
E.AWS Config
AnswersA, C

Amazon CloudWatch Events (now Amazon EventBridge) is the alerting and event-routing mechanism: you can define rules that match GuardDuty findings or specific CloudTrail API calls and automatically send them to an SNS topic, Lambda function, or Systems Manager automation. For example, a rule with event source 'aws.guardduty' and detail-type 'GuardDuty Finding' can trigger an SNS notification whenever a suspicious finding is generated. This makes CloudWatch Events the delivery/alerting layer in a detection pipeline, not a source of security data itself.

Why this answer

Amazon CloudWatch Events (now part of Amazon EventBridge) can detect suspicious activity by monitoring AWS API calls, resource state changes, and custom application events in near real-time. It can trigger automated responses, such as invoking a Lambda function or sending an SNS notification, when specific patterns (e.g., unauthorized API calls or unusual resource modifications) are detected. This makes it suitable for near real-time alerting on suspicious activity.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail's logging capability with real-time detection, but CloudTrail delivers log files with a delay (typically 5-15 minutes) and does not natively analyze or alert on suspicious activity without additional services like CloudWatch Events or GuardDuty.

105
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team needs to enforce that all S3 buckets in the organization block public access. Which policy should be attached to the root organizational unit to achieve this?

A.Enable AWS CloudTrail to log public access attempts and alert the security team.
B.Use AWS Config rules to remediate non-compliant buckets automatically.
C.Attach a service control policy (SCP) that denies s3:PutBucketPublicAccessBlock.
D.Create an IAM role with a bucket policy that blocks public access.
AnswerC

SCPs can be attached to OUs to centrally restrict permissions.

Why this answer

Attach a service control policy (SCP) that denies s3:PutBucketPublicAccessBlock. SCPs can be applied at the root organizational unit to centrally restrict permissions across all accounts, preventing any account from allowing public access to S3 buckets. Option A (CloudTrail) only logs events, not block access.

Option B (AWS Config) can detect non-compliance but requires additional automation to enforce; the question asks for enforcement directly. Option D (IAM role) is account-specific and cannot enforce globally.

106
MCQeasy

A company is using AWS Organizations with multiple accounts. The security team wants to ensure that all IAM users in the organization have multi-factor authentication (MFA) enabled. Which combination of actions should be taken to enforce this requirement?

A.Create an SCP that denies IAM actions without MFA and attach it to the IAM group that contains all users.
B.Create an SCP that denies IAM actions without MFA and attach it to the root organizational unit (OU).
C.Create an SCP that denies IAM actions without MFA and attach it to each IAM user.
D.Create an SCP that denies IAM actions without MFA and attach it to the management account.
AnswerB

Attaching the SCP to the root organizational unit places it in the hierarchy of every OU and member account in the organization, so the deny rule with aws:MultiFactorAuthPresent applies to every IAM user in those accounts. Because a root-level SCP is evaluated as an organizational permission boundary before IAM authorization, an IAM action without MFA is blocked throughout the member accounts.

Why this answer

Service Control Policies (SCPs) in AWS Organizations can be attached to the root organizational unit (OU) to apply a blanket denial of IAM actions when MFA is not present, affecting all accounts and users within the organization. This leverages the `aws:MultiFactorAuthPresent` condition key in an SCP to enforce MFA at the organization level, ensuring that even if IAM users are created in member accounts, they cannot perform IAM actions without MFA. Attaching the SCP to the root OU ensures the policy cascades down to all child OUs and accounts, providing centralized enforcement.

Exam trap

The trap here is that candidates mistakenly think SCPs can be attached to IAM users or groups, but SCPs are organization-level policies that only apply to OUs, accounts, or the root, not to individual IAM entities.

How to eliminate wrong answers

Option A is wrong because SCPs cannot be attached to IAM groups; SCPs are applied to OUs, accounts, or the root of the organization, not to IAM entities like groups, users, or roles. Option C is wrong because SCPs cannot be attached directly to IAM users; they are only applicable to AWS Organizations entities (OUs, accounts, or the root). Option D is wrong because attaching the SCP to the management account would only affect that single account, not the member accounts; SCPs must be attached to the root OU or relevant OUs to enforce policies across the entire organization.

107
MCQhard

A security engineer is configuring a VPC endpoint for Amazon S3 and wants to ensure that only traffic from specific IAM roles can access the S3 bucket through the endpoint. Which policy element should the engineer use?

A.aws:SourceVpc
B.aws:PrincipalArn
C.aws:username
D.aws:SourceVpce
AnswerB

The aws:PrincipalArn condition key matches the full ARN of the IAM principal (user or role) that is making the request. For a VPC endpoint policy controlling access to Amazon S3, you can specify a role ARN as the value, ensuring only requests signed with that role's credentials are allowed through the endpoint. This is the correct way to restrict access to a specific IAM role because it directly inspects the principal identity rather than the network source.

Why this answer

Aws:PrincipalArn. This condition key allows you to specify the ARN of an IAM role (or user) to control access to the S3 bucket through the VPC endpoint. Option A (aws:SourceVpc) restricts traffic to a specific VPC, not an IAM role.

Option C (aws:username) is used for IAM users, not roles. Option D (aws:SourceVpce) restricts traffic to a specific VPC endpoint, not a role.

108
MCQeasy

A company wants to centrally manage access keys for IAM users. Which AWS service can generate and rotate access keys automatically?

A.AWS CloudHSM
B.AWS KMS
C.AWS Systems Manager Parameter Store
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager automatically rotates secrets, including IAM user access keys, using a Lambda function built-in or custom. It can store the secret as AWSCURRENT and manage rotations with defined schedules, and also provides access policy and audit capabilities. This makes Secrets Manager the correct service for centrally managing and rotating IAM access keys.

Why this answer

AWS Secrets Manager is the correct service because it natively supports automatic rotation of secrets, including IAM user access keys. You can configure a rotation schedule (e.g., every 30 days) and Secrets Manager will generate a new access key pair, update the IAM user, and optionally disable or delete the old key. This provides a fully managed, centralized solution for rotating access keys without custom scripting.

Exam trap

The trap here is that candidates often confuse AWS KMS (which handles encryption keys) with Secrets Manager (which handles secrets like passwords and access keys), or they assume Parameter Store can rotate secrets automatically, but only Secrets Manager provides built-in, configurable rotation for IAM access keys.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides hardware security modules for cryptographic key storage and operations, but it does not generate or rotate IAM access keys. Option B is wrong because AWS KMS manages encryption keys (symmetric and asymmetric) and performs cryptographic operations, but it cannot create or rotate IAM user access keys. Option C is wrong because AWS Systems Manager Parameter Store can store secrets as parameters, but it lacks built-in rotation capabilities; you would need to implement custom rotation logic using Lambda, whereas Secrets Manager provides native rotation.

109
MCQhard

A company runs a critical application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application processes financial transactions and must store transaction logs in an Amazon S3 bucket. The security team requires that all API calls to AWS services are logged and that the logs are stored in a secure, tamper-proof manner. The team enables AWS CloudTrail to log management events and Amazon S3 server access logs for the S3 bucket. They also enable AWS Config to track resource changes. The compliance team wants to ensure that no one can disable CloudTrail logging or delete the CloudTrail log files. The security engineer proposes a solution using an SCP in AWS Organizations to deny actions that would disable CloudTrail or delete log files. However, the engineer is concerned that the SCP might be applied too broadly and affect legitimate administrative actions. The engineer wants to ensure that only the security team’s IAM role (SecurityAdminRole) can perform these restricted actions, while all other principals (including IAM users, roles, and the root user) are denied. The engineer creates an SCP that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, and s3:DeleteObject on the CloudTrail S3 bucket. The SCP includes a condition that allows the action if the principal is SecurityAdminRole. However, after applying the SCP, the security team finds that even SecurityAdminRole is unable to stop CloudTrail logging. What is the most likely cause of this issue?

A.The condition in the SCP is incorrectly scoped, causing the deny to apply to all principals including SecurityAdminRole.
B.The SCP is applied to the root organizational unit (OU), which includes the management account where the root user is not affected by SCPs.
C.The SecurityAdminRole does not have the necessary IAM permissions to stop CloudTrail logging.
D.The S3 bucket policy on the CloudTrail bucket denies access to the SecurityAdminRole.
AnswerA

A service control policy (SCP) acts as a permission boundary for all IAM principals in an AWS account. In this scenario, the SCP's condition was written with incorrect scoping—it likely used a condition key that did not match the SecurityAdminRole's principal ARN, or failed to include an exclusion for that role—so the explicit deny in the SCP applied to every principal, including SecurityAdminRole. Because an explicit deny in an SCP overrides any allow from an identity-based policy, the role's IAM permission to call cloudtrail:StopLogging was ineffective, leaving the deny intact and blocking the stop action.

Why this answer

Option A is correct because the SCP's condition is likely misconfigured — for example, using a StringNotEquals on aws:PrincipalArn without accounting for the role's assumed-role ARN format, or placing the condition on the wrong element — causing the Deny to apply to all principals including SecurityAdminRole. SCPs are evaluated as a union of allows and an intersection of denies, so a mis-scoped Deny overrides any Allow.

Exam trap

SCS-C02 often tests the subtlety that SCP Deny statements with misconfigured principal conditions block everyone, including the intended exempt role — candidates forget that assumed-role ARNs differ from role ARNs.

How to eliminate wrong answers

Option B is wrong because while SCPs do not affect the management account, the scenario states SecurityAdminRole itself is blocked, which points to the condition logic, not OU placement. Option C is wrong because if the role lacked IAM permissions, the error would be an access denied from IAM, not from the SCP; the scenario says the SCP was applied and then the role was blocked. Option D is wrong because the issue is about stopping CloudTrail logging, not S3 object deletion, and a bucket policy would not block cloudtrail:StopLogging.

110
MCQmedium

A company is designing a VPC for a three-tier web application that must be accessible from the internet only via HTTPS. The web servers must be able to initiate outbound connections to the internet for software updates, but the database servers must have no direct internet access. Which architecture meets these requirements?

A.Web servers in private subnets, database servers in public subnets, both behind an Application Load Balancer
B.Web servers in public subnets, database servers in private subnets with a route to a NAT Gateway in a public subnet
C.Web servers in private subnets with a route to a NAT Gateway, database servers in private subnets with no route to the NAT Gateway, both behind an Application Load Balancer in public subnets
D.Web servers in public subnets with Elastic IPs, database servers in private subnets with a route to an internet gateway
AnswerC

This architecture correctly places the web servers in private subnets with a 0.0.0.0/0 route to a NAT gateway in public subnets, so the web servers can download patches and updates but cannot be directly reached from the internet. The database servers are in separate private subnets with no route to the NAT gateway or to an internet gateway, giving them no internet path at all—protecting against both inbound attacks and outbound data exfiltration. The internet-facing Application Load Balancer resides in public subnets, accepts HTTPS traffic on port 443, terminates TLS, and forwards requests to the web servers over private IPs, while the web servers communicate with the database over the VPC internal network only.

Why this answer

Web servers in private subnets behind an Application Load Balancer (ALB) in public subnets can receive internet traffic via the ALB, and they can initiate outbound internet connections via a NAT Gateway. Database servers in private subnets with no route to the NAT Gateway have no internet access, meeting the requirement. This architecture isolates the database tier while allowing web tier outbound updates.

Exam trap

SCS-C02 often tests the misconception that private subnets always have no internet access, when in fact a private subnet with a route to a NAT Gateway allows outbound internet, which may violate strict isolation requirements for database tiers.

How to eliminate wrong answers

Option A is wrong because database servers in public subnets would have direct internet access, violating the requirement. Option B is wrong because web servers in public subnets would be directly accessible from the internet, and the database servers would have a route to a NAT Gateway, giving them outbound internet access, which is not allowed. Option D is wrong because web servers in public subnets with Elastic IPs are directly accessible, and database servers with a route to an internet gateway would have internet access, violating the requirement.

111
MCQeasy

A company wants to automate the enforcement of security best practices across all AWS accounts in an organization. The solution should automatically remediate noncompliant resources. Which AWS service should be used to achieve this?

A.AWS Organizations service control policies (SCPs)
B.AWS IAM Access Analyzer
C.Amazon GuardDuty
D.AWS Config rules with auto-remediation
AnswerD

AWS Config rules evaluate resource configurations against desired policies and, when a rule is noncompliant, can trigger an associated AWS Systems Manager Automation runbook to automatically perform the necessary corrective action. This combination of continuous evaluation and auto-remediation directly addresses the need to automate enforcement of security best practices. For example, a Config rule can detect an S3 bucket without encryption and invoke an Automation document to enable default encryption, all without manual intervention.

Why this answer

AWS Config rules evaluate resource configurations against desired states and can trigger automatic remediation via SSM Automation documents when a resource is noncompliant. With AWS Organizations integration, Config can aggregate compliance across all accounts and apply remediation centrally, making it the correct choice for automated enforcement with remediation.

Exam trap

The trap is confusing preventive controls (SCPs) with detective-and-remediative controls (Config rules); the question's keyword 'automatically remediate' rules out SCPs, which only block actions.

How to eliminate wrong answers

Option A is wrong because SCPs restrict what actions principals can perform but do not evaluate resource compliance or perform remediation; they are preventive, not detective/remediative. Option B is wrong because IAM Access Analyzer identifies overly permissive resource policies and unused access, but it does not remediate noncompliant resources automatically. Option C is wrong because GuardDuty is a threat detection service that identifies malicious activity; it does not enforce configuration best practices or remediate resources.

112
Multi-Selectmedium

A company wants to protect sensitive data stored in S3 from being accessed by unauthorized users. Which TWO actions should be taken? (Choose two.)

Select 2 answers
A.Use IAM policies to restrict access to the bucket.
B.Enable S3 Versioning.
C.Enable default encryption on all S3 buckets.
D.Enable S3 Block Public Access at the account level.
E.Enable MFA Delete on the bucket.
AnswersA, D

IAM policies are the primary identity-based access control in AWS. They allow you to grant specific principals, such as IAM users or roles, explicit Allow or Deny permissions for S3 actions on a given bucket and its objects. When combined with resource-based bucket policies, IAM enables fine-grained authorization, such as requiring s3:GetObject only for certain prefixes, which directly prevents unauthorized access to sensitive data.

Why this answer

Option A is correct because IAM policies define which principals (users, roles, groups) can perform which S3 actions (such as s3:GetObject or s3:PutObject) on specific bucket or object ARNs, directly controlling authorized access to sensitive data. Option D is correct because enabling S3 Block Public Access at the account level applies account-wide safeguards that reject bucket policies or ACLs granting public access, preventing accidental exposure of sensitive objects to anonymous users. Option B is not correct because S3 Versioning only preserves multiple object versions for recovery and does not by itself prevent unauthorized access.

Option C is not correct because default encryption protects data at rest but does not stop an authorized-but-malicious or improperly permissioned principal from reading the data. Option E is not correct because MFA Delete only requires multi-factor authentication for permanently deleting object versions or changing versioning state, which is a deletion control rather than an access control.

Exam trap

The trap is confusing encryption with access control; candidates may think enabling default encryption prevents unauthorized access, but it only protects data at rest, not from authorized users with excessive permissions.

113
MCQmedium

A security engineer is investigating a potential data exfiltration from an S3 bucket that is configured to allow public access. The engineer wants to determine who accessed the bucket and from which IP addresses. Which AWS capability should be used?

A.Amazon S3 server access logs
B.AWS IAM Access Analyzer
C.AWS CloudTrail data events for S3
D.Amazon VPC Flow Logs
AnswerC

CloudTrail data events for S3 capture object-level API calls such as GetObject, PutObject, and ListBucket, recording the IAM principal, source IP address, timestamp, and specific request parameters. Unlike management events, data events require explicit enablement on the trail or bucket, but once enabled they provide queryable, near real-time records of exactly the operations an attacker would perform to extract data. This gives investigators the necessary combination of user identity, network origin, and object-level action to confirm or refute exfiltration, making it the correct choice.

Why this answer

AWS CloudTrail data events for S3 capture detailed API activity at the object level, including GetObject, PutObject, and DeleteObject calls. This allows the security engineer to identify exactly who accessed the bucket (via the user identity) and from which IP address (via the sourceIPAddress field in the CloudTrail event). Unlike management events, data events must be explicitly enabled and provide the granularity needed for this investigation.

Exam trap

The trap here is that candidates often confuse S3 server access logs (which also log IPs and request details) with CloudTrail data events, but server access logs lack IAM user identity information and are not integrated with AWS CloudTrail's centralized audit trail, making CloudTrail the correct choice for identity-aware investigation.

How to eliminate wrong answers

Option A is wrong because Amazon S3 server access logs provide detailed records of requests made to a bucket, including IP addresses and requester information, but they are delivered as log files to a target bucket and are not real-time; they also do not capture IAM user identity details as comprehensively as CloudTrail. Option B is wrong because AWS IAM Access Analyzer is used to identify resources shared with external entities by analyzing resource-based policies, not to track who accessed a bucket or from which IP addresses. Option D is wrong because Amazon VPC Flow Logs capture IP traffic metadata at the network interface level, but they do not log S3 API operations or the identity of the requester; S3 access via the internet or AWS PrivateLink may not even traverse a VPC flow log.

114
MCQeasy

A company wants to grant an IAM user the ability to rotate their own access keys. What is the least privileged IAM policy that allows this?

A.A policy with Action: 'iam:*AccessKey*' and Resource: 'arn:aws:iam::*:user/*'
B.A policy with Action: 'iam:ListAccessKeys' and 'iam:GetAccessKeyLastUsed' and Resource: '*'
C.A policy with Action: 'iam:CreateAccessKey', 'iam:DeleteAccessKey', 'iam:UpdateAccessKey' and Resource: 'arn:aws:iam::*:user/${aws:username}'
D.A policy with Action: 'iam:*' and Resource: '*'
AnswerC

This is the correct minimum-privilege policy because it grants exactly the three write actions required for access key rotation: 'iam:CreateAccessKey' to generate a new key pair, 'iam:UpdateAccessKey' to change the old key's status to Inactive, and 'iam:DeleteAccessKey' to remove the old key. The resource ARN 'arn:aws:iam::*:user/${aws:username}' uses the policy variable '${aws:username}', which is dynamically replaced with the caller's IAM user name, so each user can only manage their own access keys. This adheres to least privilege and is the AWS-recommended pattern for self-service key rotation.

Why this answer

It grants only the specific actions required to rotate access keys (CreateAccessKey, DeleteAccessKey, UpdateAccessKey) and restricts the resource to the user's own path using the ${aws:username} variable. This ensures the IAM user can only manage their own keys, adhering to the least privilege principle.

Exam trap

The trap here is that candidates often choose Option A or D because they assume wildcard actions are acceptable, but the exam tests the precise least privilege requirement by including unnecessary actions or overly broad resources that violate the principle.

How to eliminate wrong answers

Option A is wrong because 'iam:*AccessKey*' is a wildcard that includes actions like GetAccessKeyLastUsed and ListAccessKeys, which are not needed for rotation, and the resource ARN 'arn:aws:iam::*:user/*' allows access to all users, violating least privilege. Option B is wrong because it only grants read-only actions (ListAccessKeys, GetAccessKeyLastUsed) and does not include the write actions (Create, Delete, Update) necessary to actually rotate keys. Option D is wrong because 'iam:*' grants full administrative access to all IAM actions and resources, which is far beyond the minimal permissions needed for key rotation.

115
Multi-Selecthard

Which THREE of the following are best practices for securing an Amazon RDS database instance? (Select THREE.)

Select 3 answers
A.Enable encryption at rest using AWS KMS
B.Place the RDS instance in a private subnet
C.Use strong passwords and rotate them regularly
D.Enable public accessibility for ease of management
E.Use the default database port
AnswersA, B, C

RDS encryption at rest uses AWS KMS envelope encryption, where a customer master key (CMK) encrypts the data keys that encrypt your database storage, automated backups, snapshots, and read replicas. If the underlying EBS volumes are compromised, the encrypted data remains unreadable without KMS key access, and you also get a compliance benefit. Note that you must enable encryption at launch because you cannot encrypt an existing unencrypted RDS instance in place.

Why this answer

Enabling encryption at rest using AWS KMS ensures that the underlying storage for the RDS instance, automated backups, read replicas, and snapshots are encrypted using AES-256. This protects data at rest from unauthorized physical access or storage media theft, and is a fundamental security best practice for compliance frameworks like PCI DSS and HIPAA.

Exam trap

The trap here is that candidates often confuse 'public accessibility' with necessary management access, but AWS explicitly recommends placing RDS in a private subnet and using a bastion host or AWS Systems Manager Session Manager for secure administrative access, not a public IP.

116
MCQeasy

An application running on an EC2 instance needs to access an S3 bucket. What is the most secure way to grant the EC2 instance the necessary permissions?

A.Create an IAM role with the necessary S3 permissions and attach it to the EC2 instance as an instance profile.
B.Store the credentials in an encrypted file on the EC2 instance and decrypt them at runtime.
C.Store the AWS access key and secret key in the application code.
D.Use an S3 bucket policy that allows access from the EC2 instance's public IP address.
AnswerA

Creating an IAM role with the necessary S3 permissions and attaching it as an instance profile is the AWS-recommended best practice. The EC2 instance receives temporary security credentials through the instance metadata service (IMDS), and the AWS SDKs automatically retrieve and refresh those credentials before they expire. This avoids storing any long-term keys on the instance, enforces least-privilege permissions scoped to the role, and gives you automatic rotation without manual intervention.

Why this answer

Attaching an IAM role to an EC2 instance via an instance profile delivers temporary, automatically rotated credentials through the Instance Metadata Service (IMDS), so no long-lived secrets exist on disk or in code. This is the AWS best practice for granting AWS service permissions to EC2 workloads and eliminates the risk of credential leakage.

Exam trap

SCS-C02 often tests whether candidates understand that instance profiles provide temporary credentials via IMDS, not static keys — the trap is choosing 'encrypted credentials on disk' because it sounds secure, when it still involves long-lived secrets.

How to eliminate wrong answers

Option B is wrong because storing credentials in an encrypted file still requires a decryption key on the instance, creating a bootstrap/secret-zero problem and leaving long-lived credentials that can be exfiltrated if the instance is compromised. Option C is wrong because hardcoding access keys in application code is the worst practice — keys end up in source control, logs, and container images, and they never rotate automatically. Option D is wrong because an S3 bucket policy keyed on the instance's public IP is fragile (IPs change on stop/start, and NAT gateways share IPs), does not authenticate the instance identity, and grants access to anyone behind that IP — it is not a secure identity-based control.

117
MCQhard

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The ALB is configured to terminate SSL/TLS and forward traffic to the instances over HTTP. The security team wants to ensure that the instances only accept traffic from the ALB, not from any other source. How can this be achieved?

A.Configure the instance security group to allow HTTP traffic only from the VPC CIDR block.
B.Configure the instance security group to allow HTTP traffic only from the ALB's security group.
C.Configure the network ACL on the instance's subnet to allow HTTP traffic only from the ALB's private IP address.
D.Configure the instance security group to allow HTTP traffic only from the subnet CIDR block where the ALB resides.
AnswerB

Referencing the ALB's security group as the source in the instance security group rule limits inbound HTTP to traffic originating from the elastic network interfaces that actually belong to the ALB nodes. This SG-to-SG association follows the ALB as it scales or replaces its ENIs across Availability Zones, because any ENI that is a member of the ALB security group is automatically allowed. It is the recommended, least-privilege approach for placing an EC2 instance behind an Application Load Balancer.

Why this answer

Referencing the ALB's security group in the instance security group rule allows traffic only from the ALB, regardless of the ALB's IP address changes. This leverages AWS security group referencing, which is a managed and scalable way to restrict traffic to a specific source security group. The ALB's security group acts as a logical identifier, ensuring that only traffic forwarded by the ALB reaches the instances.

Exam trap

The trap here is that candidates often confuse security group referencing with IP-based rules, mistakenly thinking that using the ALB's subnet CIDR or VPC CIDR is sufficient, when in fact those approaches allow traffic from any resource in those ranges, not just the ALB.

How to eliminate wrong answers

Option A is wrong because allowing HTTP traffic from the entire VPC CIDR block would permit any resource within the VPC (including compromised instances or unauthorized services) to directly access the instances, bypassing the ALB. Option C is wrong because network ACLs are stateless and operate at the subnet level, not the instance level; they cannot restrict traffic based on the ALB's private IP address reliably since ALB IPs can change, and they would require managing both inbound and outbound rules, which is less secure and more complex than security group referencing. Option D is wrong because allowing traffic from the subnet CIDR block where the ALB resides would permit any resource in that subnet (including other instances or services) to access the instances, not just the ALB itself.

118
MCQhard

A security engineer notices that an IAM user has been inactive for 90 days. What is the best way to identify and disable such users?

A.Use CloudTrail to identify users with no recent events
B.Use AWS Config rule to detect inactive users
C.Use IAM Credential Report and disable users with no activity in 90 days
D.Use AWS Organizations to disable users
AnswerC

The IAM Credential Report lists every user's password and access key usage with timestamps, letting the engineer identify accounts with no activity for 90 days and then disable them. It provides the credential-age and last-used data the scenario requires.

Why this answer

The IAM Credential Report provides a comprehensive CSV export of all IAM users in the account, including the `password_last_used` and `access_key_last_used_date` columns. This allows a security engineer to directly identify users who have had no activity for 90 days and then disable them by applying an IAM policy with a `Deny` effect or removing their credentials. It is the most straightforward, native, and accurate method for this specific task.

Exam trap

The trap here is that candidates confuse CloudTrail (which logs events) with the IAM Credential Report (which directly reports user activity), or they assume AWS Config can evaluate user inactivity when it is designed for resource configuration compliance, not behavioral monitoring.

How to eliminate wrong answers

Option A is wrong because CloudTrail records API activity but does not natively aggregate or report on user inactivity over a 90-day period; you would need to write custom queries and there is no built-in 'inactive user' view. Option B is wrong because AWS Config rules evaluate resource configurations (e.g., whether an IAM user has a policy attached) but cannot directly detect user login or API activity inactivity; there is no managed Config rule for 'inactive IAM user'. Option D is wrong because AWS Organizations is a service for managing multiple AWS accounts centrally, not for disabling individual IAM users within a single account.

119
MCQmedium

Refer to the exhibit. An IAM policy is attached to a user. The user attempts to upload an object to my-bucket using server-side encryption with AWS KMS (SSE-KMS). What is the outcome?

A.The upload fails because the Deny statement denies any PutObject that does not use AES256 encryption.
B.The upload fails because the Allow statement requires AES256 encryption.
C.The upload succeeds because the policy does not explicitly deny SSE-KMS.
D.The upload succeeds because the Allow statement matches the s3:PutObject action.
AnswerA

The upload fails because the Deny statement is explicit and takes precedence over any Allow. Since the request either omits the encryption header or uses a different value (e.g., aws:kms), the Deny's StringNotEquals condition matches, and IAM denies s3:PutObject before the Allow can be evaluated. This is the only correct outcome.

Why this answer

The policy contains an explicit Deny for s3:PutObject when the request does not use AES256 server-side encryption. In IAM, an explicit Deny always overrides any Allow, so a PutObject using SSE-KMS (aws:kms) fails even though the Allow statement matches the action and resource. The Deny condition effectively whitelists only AES256, making any other encryption mode—including SSE-KMS—blocked.

Exam trap

SCS-C02 often tests the misconception that a matching Allow statement can override an explicit Deny, when in fact explicit Deny always takes precedence in IAM evaluation.

How to eliminate wrong answers

Option B is wrong because the Allow statement does not require AES256; it merely permits the action, and Allow statements cannot enforce encryption requirements on their own—only Deny with conditions can. Option C is wrong because IAM evaluation is deny-first: an explicit Deny does not need to name SSE-KMS specifically; it denies everything not matching the AES256 condition, which includes SSE-KMS. Option D is wrong because a matching Allow is irrelevant when an explicit Deny applies to the same action; explicit Deny always wins in IAM policy evaluation.

120
MCQhard

Refer to the exhibit. A user named John encrypts a file using the AWS CLI. John then tries to decrypt the file but receives an AccessDenied error. John has full administrator permissions in IAM. What is the most likely cause?

A.The ciphertext blob is malformed because it was not base64-decoded before decryption.
B.John's IAM policy denies the kms:Decrypt action.
C.The KMS key policy does not grant John the kms:Decrypt permission.
D.The key ID used for encryption is different from the key used for decryption.
AnswerC

A KMS key policy is a resource-based policy that defines which principals may use that key, and it must explicitly grant the decrypt permission to John. Even with admin IAM permissions, if John isn't listed as a principal in the key policy, AWS KMS denies the decryption call with AccessDenied. The correction is to add John as a principal with kms:Decrypt action in the key policy or configure the key policy to allow IAM policies, then keep his IAM permission.

Why this answer

The most likely cause is that the KMS key policy does not grant John the kms:Decrypt permission. Even though John has full administrator permissions in IAM, KMS key policies are resource-based policies that must explicitly allow the principal to use the key. If the key policy does not grant John decrypt permissions, access is denied.

Exam trap

SCS-C02 often tests the interaction between IAM policies and KMS key policies; candidates may assume that IAM admin permissions are sufficient for KMS operations, ignoring key policy requirements.

How to eliminate wrong answers

Option A is wrong because the AWS CLI automatically handles base64 encoding/decoding for ciphertext blobs; a malformed blob would typically result in a different error. Option B is wrong because John has full administrator permissions, so an IAM policy deny is unlikely unless there is an explicit deny, but the question states he has full admin. Option D is wrong because using a different key ID would result in a different error, such as InvalidCiphertextException, not AccessDenied.

121
MCQeasy

An application running on Amazon EC2 needs to access an S3 bucket containing sensitive data. The security team wants to avoid storing long-term AWS credentials on the instance. How should the EC2 instance be configured to access S3 securely?

A.Assign an IAM role with S3 permissions to the EC2 instance via an instance profile.
B.Store IAM user access keys in the instance's user data.
C.Attach a KMS key policy that allows the instance to decrypt S3 objects.
D.Generate S3 pre-signed URLs for all objects the instance needs to access.
AnswerA

An instance profile delivers temporary, automatically rotated credentials to the EC2 instance through the instance metadata service, so no long-term access keys are stored on disk. The attached IAM role scopes S3 permissions precisely, satisfying the requirement to avoid embedded credentials.

Why this answer

Assigning an IAM role to an EC2 instance via an instance profile is the AWS-recommended way to grant AWS service permissions without embedding long-term credentials. The instance profile delivers temporary, automatically rotated credentials through the EC2 Instance Metadata Service (IMDS) at 169.254.169.254, which the SDK/CLI retrieves transparently. This satisfies the security team's requirement to avoid storing long-term AWS credentials on the instance while still allowing least-privilege S3 access.

Exam trap

SCS-C02 often tests the misconception that a KMS key policy or pre-signed URLs can substitute for IAM role-based instance permissions, when in fact only an instance profile grants the instance itself AWS API authorization.

How to eliminate wrong answers

Option B is wrong because storing IAM user access keys in user data embeds long-term credentials in the instance, which are visible to anyone with metadata/console access and violate the no-long-term-credentials requirement. Option C is wrong because a KMS key policy only governs who may use a KMS key for encryption/decryption — it does not grant S3 API permissions and cannot by itself authorize the instance to call S3. Option D is wrong because pre-signed URLs are time-limited, per-object, and typically generated by an already-authorized principal; they are not a scalable or secure mechanism for an application to continuously access a bucket.

122
MCQhard

A company has a multi-account AWS environment using AWS Organizations. The security team wants to centrally manage VPC security group rules across all accounts. Which solution should be used?

A.Use AWS Firewall Manager to define security group policies and enforce them across accounts.
B.Use AWS Organizations Service Control Policies to restrict security group modifications.
C.Use AWS Config rules to automatically remediate non-compliant security groups.
D.Use AWS Network Firewall to inspect traffic and block unauthorized connections.
AnswerA

AWS Firewall Manager is the correct service for centrally managing security group rules across all accounts in an AWS Organization. You can create a security group policy that defines baseline ingress/egress rules, and Firewall Manager automatically applies that policy to compliant and non-compliant resources in every member account, including new accounts added later. This is proactive enforcement, not just detection, and it also supports audit policies that continuously check and report security group drift.

Why this answer

AWS Firewall Manager is the correct choice because it provides centralized management of security group rules across multiple accounts in an AWS Organization. It allows the security team to define a common security group policy and automatically enforce it across all member accounts, ensuring consistent security posture without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Config's detection and remediation capabilities with centralized enforcement, not realizing that Config operates per-account and lacks the multi-account policy management that Firewall Manager provides.

How to eliminate wrong answers

Option B is wrong because AWS Organizations Service Control Policies (SCPs) are used to restrict permissions at the account level, not to manage or enforce specific security group rules; they can prevent modifications but cannot define or apply the rules themselves. Option C is wrong because AWS Config rules can detect non-compliant security groups and trigger remediation actions, but they do not provide centralized enforcement across accounts; each account must have its own Config setup and remediation logic. Option D is wrong because AWS Network Firewall is a managed firewall service that inspects network traffic at the VPC level, not a tool for managing security group rules; it operates at layers 3-7 and cannot define or enforce security group configurations.

123
MCQmedium

A company uses AWS KMS to encrypt data in Amazon RDS. They need to ensure that the key material is automatically rotated every year. Which key type should they use?

A.Custom key store
B.Customer managed key
C.AWS owned key
D.AWS managed key
AnswerD

AWS managed keys are KMS keys created automatically when a service first needs encryption, and Amazon RDS's AWS managed key (alias aws/rds) has automatic rotation enabled by default, rotating the backing key material every year. Because the key is managed in the AWS account's service space, you cannot disable rotation, which neatly matches a requirement for guaranteed automatic rotation without any administrative action.

Why this answer

AWS managed keys (D) are automatically rotated every year by AWS without any action required from the customer. For Amazon RDS encryption using AWS KMS, the default key (aws/rds) is an AWS managed key that supports automatic annual rotation, meeting the requirement exactly. Customer managed keys (B) also support automatic rotation, but the question specifies 'every year' and AWS managed keys are the simplest choice that satisfies this, as they are automatically rotated annually by default.

Exam trap

The trap here is that candidates often confuse 'AWS managed key' with 'customer managed key' because both can be rotated, but the question tests whether you know that AWS managed keys are the default, automatically rotated keys used by services like RDS, and that customer managed keys require manual configuration for rotation.

How to eliminate wrong answers

Option A is wrong because a custom key store uses a CloudHSM cluster to store key material, and automatic key rotation is not supported for keys in a custom key store; rotation must be manually managed. Option B is wrong because while customer managed keys can be configured for automatic annual rotation, the question does not specify a need for customer control over the key, and AWS managed keys are the default, simpler option that also rotates annually. Option C is wrong because AWS owned keys are not visible to customers and are used by AWS services internally; they cannot be selected or managed by the customer for RDS encryption, and their rotation policy is not under customer control.

124
MCQmedium

A security engineer is designing a solution to automatically remediate non-compliant resources in an AWS account. The engineer needs to trigger an AWS Lambda function when an EC2 instance is launched without the required tags. Which AWS service should be used to detect the non-compliant resource and invoke the Lambda function?

A.AWS CloudTrail
B.AWS Config
C.Amazon GuardDuty
D.AWS Systems Manager
AnswerB

AWS Config continuously records resource configurations and evaluates them against managed or custom rules, such as the required-tags rule that checks for specific tag keys. When a resource becomes noncompliant, Config can invoke remediation actions via Systems Manager Automation documents or Lambda functions, such as adding the missing tag automatically. This makes it the correct service for both detecting missing tags and automating their correction.

Why this answer

AWS Config is the correct service because it continuously evaluates resource configurations against desired rules. You can create a Config rule that checks for required tags on EC2 instances; when a non-compliant instance is detected, Config can automatically invoke a Lambda function via an remediation action. This native integration enables automatic, event-driven remediation without custom polling or additional services.

Exam trap

SCS-C02 often tests the difference between detection services (GuardDuty, CloudTrail) and compliance evaluation services (AWS Config), and candidates may confuse CloudTrail's logging with Config's compliance monitoring.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail only records API activity and does not evaluate resource compliance or trigger automated remediation. Option C is wrong because Amazon GuardDuty is a threat detection service that identifies malicious activity, not tag compliance. Option D is wrong because AWS Systems Manager is used for operational management (e.g., patching, automation) but does not natively detect non-compliant resource configurations based on tag policies.

125
Multi-Selecteasy

Which THREE are valid methods for authenticating to AWS APIs? (Choose THREE.)

Select 3 answers
A.Access key ID and secret access key
B.SSH key pair
C.SAML federation
D.Client certificate
E.IAM role temporary credentials
AnswersA, C, E

Long-term IAM user credentials, an access key ID and secret access key, are the canonical way to sign AWS API requests via Signature Version 4. These credentials are used for programmatic access through the AWS CLI, SDKs, or direct HTTP calls, and must be protected with least-privilege IAM policies and rotated regularly because they do not expire by default.

Why this answer

Option A (access key ID and secret access key) is correct because long-term IAM user credentials are signed into requests via SigV4 to authenticate to AWS APIs such as the CLI, SDKs, and REST endpoints. Option C (SAML federation) is correct because AWS supports SAML 2.0-based identity federation through IAM roles and STS (AssumeRoleWithSAML), letting corporate directory users obtain temporary AWS credentials for API access. Option E (IAM role temporary credentials) is correct because STS issues short-lived credentials (access key, secret key, and session token) via AssumeRole or instance profiles, which are a standard way to authenticate API calls.

Option B (SSH key pair) is not valid for AWS API authentication, as SSH keys are used for EC2 instance login, not for signing AWS API requests. Option D (client certificate) is not a general AWS API authentication method; mutual TLS client certificates are used for specific services like IoT or API Gateway custom authorizers, not as a standard AWS API credential type.

Exam trap

SCS-C02 often tests the confusion between authentication methods for AWS APIs versus other AWS services (e.g., SSH for EC2, client certificates for API Gateway), so candidates must remember that AWS APIs specifically use IAM credentials, federation, and temporary credentials.

126
Multi-Selecteasy

A Security Engineer is designing a secure VPC architecture. Which THREE components are essential for creating a public subnet that can host a web server accessible from the internet?

Select 3 answers
A.VPN connection to on-premises
B.Route table with a default route (0.0.0.0/0) pointing to the IGW
C.Security group allowing inbound HTTP/HTTPS from 0.0.0.0/0
D.NAT Gateway
E.Internet Gateway (IGW)
AnswersB, C, E

A route table entry for 0.0.0.0/0 targeting the Internet Gateway (IGW) is the core routing mechanism that makes a subnet public. Without this default route, the IGW exists but traffic from the subnet cannot reach it; the VPC's implicit local route only handles VPC-internal traffic. This route is required for the web server to receive inbound HTTP/HTTPS from the internet and to send responses back, making it a mandatory component of a public subnet design.

Why this answer

A public subnet requires a route table that directs traffic destined for 0.0.0.0/0 to an Internet Gateway (IGW). Without this default route, instances in the subnet cannot send or receive traffic from the internet, even if they have public IP addresses. The IGW acts as the target for this route, enabling bidirectional communication between the VPC and the internet.

Exam trap

The trap here is that candidates often confuse a NAT Gateway with an Internet Gateway, mistakenly thinking a NAT Gateway can provide inbound internet access to a public subnet, when in fact it only supports outbound traffic from private subnets.

127
MCQmedium

A company uses AWS Organizations with all features enabled. The security team wants to ensure that no IAM users are created in any account. Which approach should be used?

A.Use AWS Config rules to detect IAM users and notify via SNS.
B.Enable AWS CloudTrail Insights to detect anomalous IAM activity.
C.Attach a service control policy (SCP) that denies iam:CreateUser.
D.Apply an IAM policy to the root user to deny iam:CreateUser.
AnswerC

A service control policy (SCP) is an organizational policy that specifies the maximum allowed permissions for all principals, including the root user, in every account governed by an AWS Organizations hierarchy. Attaching an SCP that explicitly denies iam:CreateUser to the organization root or a specific OU prevents any principal in those accounts from creating IAM users, regardless of the permissions granted by IAM policies. Because all features are enabled, the SCP is enforced globally across member accounts, making it a true preventive control.

Why this answer

Service Control Policies (SCPs) in AWS Organizations allow you to centrally restrict permissions across all accounts in the organization. By attaching an SCP that denies the `iam:CreateUser` action, you prevent the creation of IAM users in any member account, regardless of any IAM policies attached to users or roles within those accounts. This provides a guardrail that cannot be overridden by account administrators, ensuring compliance with the security team's requirement.

Exam trap

The trap here is that candidates often confuse IAM policies with SCPs, thinking that an IAM policy attached to the root user can block actions across the account, but SCPs are the only mechanism that can enforce such restrictions across all principals in an organization.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can only detect and notify about IAM users after they are created; they do not prevent the creation of IAM users, so they fail to meet the requirement of ensuring no IAM users are created. Option B is wrong because AWS CloudTrail Insights is designed to detect anomalous API activity and generate insights, but it does not block or prevent IAM user creation; it only provides post-event analysis. Option D is wrong because applying an IAM policy to the root user does not prevent IAM user creation in other accounts or even in the same account, as the root user is not subject to IAM policies; additionally, IAM policies cannot be attached to the root user, and even if they could, they would not affect other users or roles in the account.

128
Drag & Dropmedium

Drag and drop the steps to set up a secure S3 bucket with encryption and access control in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Secure S3 bucket requires encryption, public access block, bucket policy, versioning, and access logging.

129
MCQhard

Refer to the exhibit. A security engineer runs the above AWS CLI command to search for CreateKeyPair events in CloudTrail. The command returns no results, but the engineer knows that a key pair was created during that time. What is the most likely reason for the missing events?

A.CreateKeyPair is a data event and not recorded by CloudTrail.
B.The command was run in a different region than where the key pair was created.
C.CloudTrail events are only available after 24 hours.
D.CloudTrail is not enabled for management events.
AnswerB

CloudTrail trails are scoped to a single Region unless they are organization trails or you have configured aggregation. If the CLI command ran in a different Region than where the key pair was created, the CreateKeyPair event would be delivered to the trail in the creation Region, not the one the engineer queried. The engineer would see nothing, not because the event wasn't recorded, but because they were looking in the wrong regional trail.

Why this answer

CloudTrail logs are region-specific. The `aws cloudtrail lookup-events` command without the `--region` flag defaults to the region configured in the AWS CLI (e.g., via `AWS_DEFAULT_REGION` or the CLI profile). If the CreateKeyPair event occurred in a different region, the command would return no results.

The engineer must specify the correct region using `--region` to retrieve events from that region.

Exam trap

The trap here is that candidates assume CloudTrail events are globally accessible or that the default region in the CLI will automatically include events from all regions, leading them to overlook the region-specific nature of the `lookup-events` command.

How to eliminate wrong answers

Option A is wrong because CreateKeyPair is a management (control plane) event, not a data event; CloudTrail records management events by default. Option C is wrong because CloudTrail events are typically available within minutes (up to 15 minutes), not after 24 hours. Option D is wrong because CloudTrail is enabled by default for management events in all AWS accounts, and no explicit enablement is required for management events like CreateKeyPair.

130
MCQmedium

A company uses AWS Key Management Service (KMS) to encrypt sensitive data in Amazon S3. The security team needs to ensure that the KMS key can only be used from within the company's VPC and not from the public internet. How can this be achieved?

A.Use an SCP to deny kms:Encrypt unless the request comes from the VPC.
B.Use AWS CloudTrail to monitor KMS calls and alert if they come from outside the VPC.
C.Create a VPC endpoint for KMS and modify the KMS key policy to allow usage only from the specified VPC endpoint.
D.Create a VPC endpoint for KMS and attach a bucket policy that requires the endpoint.
AnswerC

Creating an interface VPC endpoint for AWS KMS allows KMS API calls from your VPC to reach the service without traversing the public internet. The definitive control is to modify the KMS key policy to include a condition such as "aws:sourceVpce": "vpce-1234567890abcdef0" in the Allow statement, so that only requests that arrive through that specific VPC endpoint can use the key. This works because KMS evaluates the key policy with the sourceVpce context key, and requests that do not originate from the designated endpoint are implicitly denied, while requests from an EC2 instance or private subnet using the endpoint are allowed. The key policy must include the principal (e.g., the IAM role/account root) and the restriction to the VPC endpoint, because the VPC endpoint itself is the enforcement point that KMS trusts.

Why this answer

To restrict KMS key usage to a VPC, you create a VPC endpoint for KMS (an interface endpoint powered by AWS PrivateLink) and then modify the KMS key policy to allow usage only from that VPC endpoint. This ensures that requests to KMS must come through the VPC endpoint, not the public internet.

Exam trap

The trap is confusing S3 bucket policies with KMS key policies; candidates may think a bucket policy can restrict KMS usage, but KMS access is controlled by key policies and IAM policies, and VPC endpoint conditions must be in the key policy.

How to eliminate wrong answers

Option A is wrong because SCPs apply to AWS accounts and cannot condition on VPC endpoint; they cannot enforce that a request comes from a specific VPC. Option B is wrong because CloudTrail monitoring is detective, not preventive; it alerts but does not block public internet access. Option D is wrong because a bucket policy controls access to S3, not to KMS; while you can require a VPC endpoint for S3, it does not restrict KMS key usage.

131
MCQhard

Refer to the exhibit. A security engineer runs the describe-instances command for an EC2 instance. The instance has a public IP address. The security group "allow-ssh-http" has inbound rules that allow SSH from 0.0.0.0/0 and HTTP from 0.0.0.0/0. The engineer wants to block SSH access from the internet while keeping HTTP access. Which change should be made?

A.Remove the inbound rule that allows SSH from 0.0.0.0/0 from the security group.
B.Add a network ACL rule to deny SSH inbound from 0.0.0.0/0.
C.Disassociate the public IP address from the instance.
D.Modify the security group to add a deny rule for SSH from 0.0.0.0/0.
AnswerA

The security group acts as a stateful, allow-only firewall at the instance level. Removing the inbound SSH rule for 0.0.0.0/0 immediately denies all internet SSH traffic while leaving the HTTP rule intact. Since security groups contain no explicit deny rules, the absence of an allow rule is what blocks the connection. This is the precise, least-disruptive change because it only restricts SSH and does not affect HTTP reachability.

Why this answer

Security groups are stateful and support only allow rules; removing the inbound SSH rule from the security group effectively blocks SSH access from the internet (0.0.0.0/0) while the HTTP rule remains, allowing HTTP traffic. Since the instance already has a public IP address, removing the SSH rule is the simplest and most direct way to achieve the goal without affecting other traffic.

Exam trap

Candidates may incorrectly think security groups support deny rules (like network ACLs) or that adding a network ACL deny rule is the best solution. While a NACL deny rule can block SSH at the subnet level, it affects all instances in the subnet. Security groups are allow-only and provide instance-level control, so the correct action is to remove the SSH allow rule from the security group.

How to eliminate wrong answers

Option B is wrong because network ACLs are stateless and require both inbound and outbound rules to be explicitly configured; adding a deny rule for SSH inbound would still require a corresponding outbound rule to allow return traffic, and it would not override the security group's allow rule for SSH, which would still permit the traffic. Option C is wrong because disassociating the public IP address would block all internet access (including HTTP), not just SSH, which violates the requirement to keep HTTP access. Option D is wrong because security groups do not support deny rules; they only support allow rules, so you cannot add a deny rule for SSH; you must remove the allow rule instead.

132
MCQmedium

A security engineer needs to encrypt a 10 GB file before uploading it to Amazon S3. The encryption must use a customer managed key in AWS KMS, and the engineer wants to minimize the amount of data sent to KMS for encryption. Which approach should the engineer use?

A.Upload the file to S3 using SSE-KMS with the customer managed key, which encrypts the entire file with KMS.
B.Use the KMS Encrypt API directly to encrypt the entire file with the customer managed key, then upload the encrypted file to S3.
C.Use the AWS Encryption SDK with a customer managed KMS key to encrypt the file locally, then upload the encrypted file to S3.
D.Use S3 client-side encryption with a customer provided key (SSE-C) and store the key in AWS KMS.
AnswerC

The AWS Encryption SDK uses envelope encryption: it generates a data key, encrypts the file with that data key, and encrypts the data key with the KMS customer managed key. Only the small data key is sent to KMS, minimizing data transfer. The encrypted file and encrypted data key are stored together. This meets the requirement to minimize data sent to KMS.

Why this answer

The AWS Encryption SDK implements envelope encryption locally, using a KMS customer managed key only to encrypt a data key. This minimizes data sent to KMS because only the small data key is transmitted. The encrypted file is then uploaded to S3.

This meets the requirements for local encryption and efficient KMS usage.

Exam trap

The trap here is assuming that KMS can directly encrypt large files, when in fact the Encrypt API has a 4 KB limit, necessitating envelope encryption.

133
MCQeasy

A company wants to allow an EC2 instance to access a DynamoDB table without traversing the internet. Which AWS feature should be used?

A.VPC Peering
B.ClassicLink
C.NAT Gateway
D.VPC Gateway Endpoint for DynamoDB
AnswerD

A VPC Gateway Endpoint for DynamoDB is a logical gateway object added to the VPC route table, allowing instances to reach DynamoDB via AWS's private network without attaching an internet gateway or NAT device. It works by adding an entry to the route table that points DynamoDB's prefix list to the endpoint, and it supports IAM policies on the endpoint itself to restrict access. This is the recommended, private, and cost-effective solution for an EC2 instance to access DynamoDB securely and is the correct answer.

Why this answer

A VPC Gateway Endpoint for DynamoDB allows EC2 instances within a VPC to access DynamoDB without traversing the internet. It uses AWS PrivateLink to route traffic through the AWS network, ensuring low latency and enhanced security by keeping traffic within the AWS backbone.

Exam trap

The trap here is that candidates often confuse Gateway Endpoints with Interface Endpoints (for services like S3 or DynamoDB) or mistakenly think VPC Peering or NAT Gateway can provide private access to DynamoDB, but only Gateway Endpoints support DynamoDB without internet traversal.

How to eliminate wrong answers

Option A is wrong because VPC Peering connects two VPCs to enable communication between them, but it does not provide a direct, internet-free path to DynamoDB; DynamoDB is a managed service outside the VPC. Option B is wrong because ClassicLink allows EC2 instances in a classic network to communicate with a VPC, but it does not apply to DynamoDB access and is deprecated. Option C is wrong because a NAT Gateway enables outbound internet access for private subnets, but it forces traffic to traverse the internet, violating the requirement to avoid internet traversal.

134
MCQeasy

A company uses AWS CloudTrail to log API calls in all accounts. The security team wants to be notified immediately when an IAM user creates a new access key for another user. Which combination of services should the team use?

A.AWS Config and Amazon Simple Email Service (SES).
B.Amazon GuardDuty and Amazon Simple Notification Service (SNS).
C.Amazon Macie and AWS Lambda.
D.AWS CloudTrail, Amazon CloudWatch Logs, and Amazon Simple Notification Service (SNS).
AnswerD

AWS CloudTrail captures management events, including the CreateAccessKey API call, and can be configured to deliver those events to Amazon CloudWatch Logs. In CloudWatch Logs, a metric filter with a pattern like 'eventName: CreateAccessKey' creates a custom metric; a CloudWatch alarm on that metric then publishes a message to an SNS topic, which sends email or SMS notifications. This combination provides real-time alerting for the exact IAM event, making it the correct architecture.

Why this answer

It uses CloudTrail to capture the CreateAccessKey API call, sends those logs to CloudWatch Logs, and then triggers a CloudWatch alarm that publishes to an SNS topic for immediate notification. This combination provides real-time alerting on the specific IAM event without requiring additional services.

Exam trap

The trap here is that candidates often confuse AWS Config (which is reactive and compliance-focused) with CloudTrail (which is event-driven and real-time), leading them to choose Option A instead of the correct CloudTrail + CloudWatch Logs + SNS combination.

How to eliminate wrong answers

Option A is wrong because AWS Config is designed for resource compliance and configuration history, not real-time event-driven notification; SES is an email service that lacks the push notification capabilities needed for immediate alerts. Option B is wrong because GuardDuty focuses on threat detection using anomaly detection and threat intelligence feeds, not on monitoring specific IAM API calls like CreateAccessKey. Option C is wrong because Macie is a data security service that discovers and protects sensitive data in S3, not a service for monitoring IAM user activity or API calls.

135
MCQhard

A security engineer is investigating a potential data exfiltration incident. The engineer notices that an EC2 instance in a private subnet is making outbound connections to an external IP address on port 443. The VPC has a NAT gateway in a public subnet, and the route table for the private subnet directs 0.0.0.0/0 to the NAT gateway. The security group for the instance allows all outbound traffic. Which AWS service can the engineer use to determine which IAM role or user is responsible for launching the instance?

A.AWS Config
B.VPC Flow Logs
C.IAM Access Analyzer
D.AWS CloudTrail
AnswerD

AWS CloudTrail is the authoritative audit service for API activity in AWS, and it records RunInstances as a management event. Each CloudTrail event includes the userIdentity object with the IAM principal, role, or assumed-role session, along with sourceIPAddress, eventTime, userAgent, requestParameters, and responseElements containing the new instance IDs. By searching CloudTrail logs for RunInstances events, the security engineer can directly identify which IAM user or role launched the instance, enabling attribution and further investigation of the alleged data exfiltration.

Why this answer

AWS CloudTrail records API activity, including the RunInstances call that launched the EC2 instance, along with the identity (IAM user or role) that made the request. By querying CloudTrail events for the instance ID, the engineer can determine which principal launched it. This directly answers the attribution question.

Exam trap

SCS-C02 often tests the difference between network-level logs (VPC Flow Logs) and API-level audit logs (CloudTrail), so candidates pick Flow Logs when the question asks about identity attribution.

How to eliminate wrong answers

Option A is wrong because AWS Config tracks resource configuration changes and compliance, not the identity that performed API calls. Option B is wrong because VPC Flow Logs capture IP traffic metadata (source/dest, ports, accept/reject) but not IAM identity or API caller information. Option C is wrong because IAM Access Analyzer identifies resource policies that grant external access; it does not log who launched an instance.

136
MCQhard

During an incident response, a security engineer needs to capture a memory image of a compromised Amazon EC2 instance running Linux. The instance is in a production Auto Scaling group. Which approach is BEST?

A.Use AWS CloudFormation to create a new stack with a forensic instance and copy the compromised instance's data.
B.Terminate the instance immediately to prevent further damage and launch a replacement.
C.Detach the instance from the Auto Scaling group, isolate it by changing security groups, and use AWS Systems Manager Run Command to execute a memory acquisition tool.
D.Take a snapshot of the EBS volumes and attach them to a forensic instance to analyze memory.
AnswerC

Detaching from the Auto Scaling group prevents termination or replacement during acquisition, while security group changes isolate the instance from further compromise. Systems Manager Run Command then executes the memory capture tool without needing SSH access, preserving volatile data that would be lost on stop or reboot.

Why this answer

It preserves the volatile memory evidence by detaching the instance from the Auto Scaling group (preventing replacement) and isolating it via security group changes, then using AWS Systems Manager Run Command to execute a memory acquisition tool like LiME or AVML. This approach captures the memory image without shutting down the instance, which would destroy the evidence, and avoids the risk of the Auto Scaling group automatically terminating or replacing the instance during the investigation.

Exam trap

The trap here is that candidates confuse disk forensics (EBS snapshots) with memory forensics, assuming a snapshot captures RAM, or they prioritize immediate containment (termination) over evidence preservation, which violates the core incident response principle of 'preserve before remediate'.

How to eliminate wrong answers

Option A is wrong because AWS CloudFormation is an infrastructure-as-code service for provisioning resources, not a forensic tool; copying data from a compromised instance does not capture volatile memory, which is lost when the instance is stopped or terminated. Option B is wrong because terminating the instance immediately destroys the memory image and other volatile evidence, making forensic analysis impossible; incident response requires preserving evidence before remediation. Option D is wrong because an EBS snapshot captures only the persistent disk state (file system and storage), not the contents of RAM; memory analysis requires a dedicated memory acquisition tool executed on the running instance.

137
MCQmedium

A security engineer is designing a system to centrally manage security rules across multiple AWS accounts. The engineer wants to ensure that any resources that are non-compliant with security policies are automatically remediated. Which combination of services should the engineer use?

A.AWS CloudTrail with Amazon SNS
B.Amazon GuardDuty with AWS Step Functions
C.AWS Security Hub with Amazon EventBridge
D.AWS Config with AWS Lambda for automatic remediation
AnswerD

AWS Config continuously records resource configuration changes and evaluates them against managed or custom rules to determine compliance. When a resource drifts from the required policy, AWS Config can invoke an AWS Lambda function as a remediation action, which can automatically apply corrective changes such as updating security groups, enabling encryption, or deleting orphaned resources. This combination provides both the compliance evaluation and the automatic remediation needed for a central management system, making it the correct choice.

Why this answer

AWS Config continuously evaluates resource configurations against desired policies (Config Rules), and its remediation action feature can invoke an AWS Lambda function automatically when a resource is found non-compliant. This combination provides both centralized, multi-account compliance evaluation (via a Config aggregator) and automated remediation, which is exactly what the question requires. Lambda gives the custom logic needed to fix the non-compliant resource, making this the only option that delivers automatic remediation based on compliance state.

Exam trap

SCS-C02 often tests the distinction between detection/aggregation services (Security Hub, GuardDuty, CloudTrail) and the only service that natively evaluates configuration compliance and can trigger automatic remediation (AWS Config with Lambda/SSM Automation) — candidates frequently pick Security Hub with EventBridge because it sounds like centralized compliance management, but it lacks built-in remediation.

How to eliminate wrong answers

Option A is wrong because CloudTrail only records API activity for auditing and SNS merely delivers notifications — neither evaluates resource compliance nor performs remediation. Option B is wrong because GuardDuty is a threat-detection service that identifies malicious activity or compromised credentials; it does not assess resource configuration compliance, and Step Functions alone cannot remediate without a compliance signal. Option C is wrong because Security Hub aggregates and prioritizes findings from services like GuardDuty, Inspector, and Config, and EventBridge can route those findings, but this pairing only detects and routes events — it does not automatically remediate non-compliant resources without an additional remediation target such as Lambda or SSM Automation.

138
MCQhard

Refer to the exhibit. A security engineer applies this bucket policy to an S3 bucket. A user without HTTPS tries to download an object. What is the outcome?

A.The request is denied because the condition matches
B.The request fails because the condition does not match
C.The request succeeds because the policy has a Deny effect
D.The request succeeds because the resource is not specific enough
AnswerA

The request is denied because the condition matches — i.e., the request was made over plain HTTP, so the aws:SecureTransport boolean value is false, causing the condition "Bool": {"aws:SecureTransport": "false"} to evaluate true. When the Deny statement's condition is satisfied, the explicit deny overrides any Allow, so S3 returns 403 AccessDenied. The resource ARN covering the object bucket is also broad, but that is not the operative issue.

Why this answer

The bucket policy includes a condition that denies requests when `aws:SecureTransport` is `false`. Since the user attempts to download an object without HTTPS, the condition matches, and the explicit Deny effect overrides any Allow. Therefore, the request is denied.

Exam trap

The trap here is that candidates may think a Deny effect always denies, but they must check whether the condition evaluates to true; if the condition does not match, the Deny is not applied, and the request could succeed based on other policies.

How to eliminate wrong answers

Option B is wrong because the condition does match (the request lacks HTTPS, so `aws:SecureTransport` is false), so the Deny applies. Option C is wrong because the policy has a Deny effect, which denies the request, not allows it to succeed. Option D is wrong because the resource is specific enough (the bucket ARN is explicit), and the Deny effect is triggered by the condition, not by resource specificity.

139
Multi-Selecthard

A company has a requirement to detect and alert on anomalous IAM user behavior, such as a user logging in from an unusual geographic location. The company uses AWS Organizations and has multiple accounts. Which services should the company use to meet this requirement? (Choose two.)

Select 2 answers
A.Amazon CloudWatch Logs
B.AWS Config
C.Amazon GuardDuty
D.IAM Access Analyzer
E.AWS CloudTrail
AnswersC, E

Amazon GuardDuty is a managed threat detection service that continuously analyzes CloudTrail event logs, VPC Flow Logs, and DNS query logs using machine learning models and integrated threat intelligence to identify anomalous IAM behavior. It establishes a baseline of normal user activity and generates findings when it detects deviations, such as a logon from a known malicious IP, an unusual geolocation sign-in, or API calls made from a compromised credential. GuardDuty is purpose-built to alert on these anomalies and can automatically send findings to Amazon EventBridge for response.

Why this answer

Amazon GuardDuty (C) is correct because it uses machine learning to detect anomalous IAM user behavior, such as logins from unusual geographic locations, across multiple accounts when integrated with AWS Organizations. AWS CloudTrail (E) is correct because it records all IAM user sign-in events and API calls, providing the raw data that GuardDuty analyzes. CloudTrail is essential for capturing the logs that enable GuardDuty to detect anomalies.

IAM Access Analyzer (D) is incorrect because it focuses on resource policies and unintended external access, not user behavior anomalies like unusual login locations.

Exam trap

The trap is that candidates often choose only GuardDuty or mistakenly include IAM Access Analyzer. The correct pair is GuardDuty for detection and CloudTrail for logging the events that GuardDuty analyzes. CloudTrail alone does not detect anomalies, but it is necessary for providing the data.

140
Multi-Selecthard

A company wants to ensure that all API calls in their AWS account are logged and immutable. Which TWO actions should be taken? (Choose TWO.)

Select 2 answers
A.Enable MFA delete on the S3 bucket
B.Use AWS Config rules to monitor CloudTrail configuration
C.Enable S3 Object Lock on the CloudTrail S3 bucket
D.Encrypt the S3 bucket with AWS KMS
E.Enable AWS CloudTrail for all regions
AnswersC, E

Object Lock prevents log deletion or modification.

Why this answer

Enabling S3 Object Lock on the CloudTrail S3 bucket ensures that log files are immutable and cannot be overwritten or deleted by any user, including root. This is achieved through a write-once-read-many (WORM) model, which is essential for maintaining a tamper-proof audit trail of all API calls.

Exam trap

The trap here is that candidates often confuse encryption (Option D) with immutability, or they think MFA delete (Option A) provides sufficient protection, but neither prevents overwrites or ensures a WORM state, which is the core requirement for immutable logging.

141
Multi-Selecthard

Which THREE of the following are characteristics of IAM roles? (Choose 3.)

Select 3 answers
A.Roles have long-term credentials like access keys.
B.Roles require a password for assumption.
C.Roles can be assumed by IAM users in another AWS account.
D.Roles have a trust policy that specifies who can assume the role.
E.Roles can be attached to EC2 instances to grant permissions to applications.
AnswersC, D, E

IAM roles support cross-account access by allowing a principal from another AWS account to assume the role, provided the role's trust policy explicitly lists that account as a trusted entity. Once assumed, the principal gains the permissions attached to the role, enabling secure federation between accounts without sharing long-term credentials. This is a common pattern for centralized management or delegated administrative tasks across AWS environments.

Why this answer

Option C is correct because IAM roles are designed for cross-account access: a role in Account A can have a trust policy granting the principal in Account B permission to call sts:AssumeRole, so users in another AWS account can assume it. Option D is correct because every IAM role has a trust policy (the AssumeRolePolicyDocument) that defines which principals (users, accounts, services, federated identities) are allowed to assume the role. Option E is correct because an instance profile delivers a role's temporary credentials to an EC2 instance, letting applications on that instance call AWS APIs with the role's permissions without embedding long-term keys.

Option A is wrong because roles do not have long-term credentials like access keys; they issue temporary credentials via AWS STS. Option B is wrong because assuming a role uses the sts:AssumeRole API and the trust policy, not a password.

Exam trap

The trap is confusing roles with IAM users, leading candidates to incorrectly believe roles have permanent credentials or require passwords, when roles actually use temporary credentials and trust policies.

142
Multi-Selecteasy

Which TWO of the following are valid AWS IAM security best practices?

Select 2 answers
A.Implement a strong password policy for IAM users.
B.Share IAM user access keys among team members for convenience.
C.Delete IAM users instead of disabling them when not needed.
D.Enable multi-factor authentication (MFA) for privileged users.
E.Use the AWS account root user for everyday administrative tasks.
AnswersA, D

A strong password policy enforces length, complexity and rotation, reducing credential-guessing and brute-force success against IAM users. It satisfies the stem's best-practise criterion by hardening the primary authentication secret before other controls are layered on.

Why this answer

Option A is correct because implementing a strong IAM account password policy enforces complexity requirements such as minimum length, uppercase/lowercase, numbers, symbols, and rotation, which reduces the risk of brute-force and credential-guessing attacks against IAM user sign-ins. Option D is correct because enabling MFA for privileged users adds a second authentication factor, so a compromised password alone is insufficient to perform sensitive actions, which is a core AWS IAM best practice. Option B is not a best practice because IAM access keys are long-term credentials tied to a specific identity and must never be shared; sharing them breaks accountability and complicates rotation and revocation.

Option C is not correct as stated because AWS recommends disabling (deactivating) credentials and removing permissions before deleting users, and deletion should be done only when the identity is truly no longer needed. Option E is not a best practice because the root user has unrestricted access and should be used only for the few tasks that require it, with MFA enabled and access keys removed.

Exam trap

SCS-C02 often tests the root-user and credential-sharing misconceptions; candidates who think deleting users is cleaner than disabling, or that root is fine for admin work, pick the wrong options.

143
Multi-Selectmedium

A security engineer is designing a system to allow an EC2 instance to write logs to an S3 bucket. Which TWO steps are required?

Select 2 answers
A.Configure the security group of the EC2 instance to allow outbound HTTPS traffic to S3.
B.Create a VPC endpoint for S3 in the same subnet as the EC2 instance.
C.Add a bucket policy that allows the IAM role to perform s3:PutObject.
D.Create an IAM role with a policy that allows s3:PutObject on the bucket and attach it to the EC2 instance.
E.Enable AWS CloudTrail to capture log write events.
AnswersC, D

Adding a bucket policy that explicitly allows the IAM role to perform s3:PutObject is a correct and often necessary step because S3 uses resource-based policies to control access at the bucket level. Even if the role has an identity-based policy permitting s3:PutObject, a bucket policy can grant the role as an explicit principal, which is particularly important in cross-account scenarios or when the bucket's AWS account uses S3 bucket owner enforced settings. In a same-account setup, this policy and the role policy work together to ensure the API call is allowed under the S3 policy evaluation model.

Why this answer

Options C and D are correct. The EC2 instance needs an IAM role with permissions to write to the bucket (D), and the bucket policy must allow the role to write (C). Option A is incorrect because a security group controls network traffic but does not grant IAM permissions.

Option B is incorrect because a VPC endpoint provides private connectivity but is not required for this task. Option E is incorrect because CloudTrail is for API logging, not application logs.

144
MCQhard

A company uses AWS Direct Connect to connect its on-premises data center to AWS. The connection is set up with a private VIF to a VPC using a virtual private gateway. The security team wants to encrypt all traffic between on-premises and the VPC. Which solution should be implemented?

A.Configure TLS on the applications
B.Set up an IPsec VPN over the Direct Connect private VIF
C.Use a site-to-site VPN over the internet instead of Direct Connect
D.Enable encryption on the Direct Connect private VIF
AnswerB

Setting up an IPsec VPN over the Direct Connect private VIF encapsulates all IP traffic between your on-premises network and the VPC, providing network-layer confidentiality and integrity while still using the private, low-latency Direct Connect path. IPsec operates at Layer 3, so it secures every protocol and service traversing the link, not just specific applications, and it is the standard way to add encryption because Direct Connect does not encrypt traffic natively. The VPN tunnel rides inside the private VIF, so you retain the dedicated bandwidth and avoid the public internet.

Why this answer

Direct Connect private VIFs do not natively encrypt traffic; they provide a private, dedicated network connection but the data traverses it in cleartext. By establishing an IPsec VPN tunnel over the private VIF, you encrypt all traffic between the on-premises network and the VPC, meeting the security team's requirement for encryption while still leveraging the low latency and reliability of Direct Connect.

Exam trap

The trap here is that candidates assume Direct Connect private VIFs are inherently encrypted because they are 'private,' but AWS explicitly states that Direct Connect does not provide encryption—you must add IPsec yourself.

How to eliminate wrong answers

Option A is wrong because TLS encrypts only application-layer traffic (e.g., HTTPS), not all IP traffic between the data center and VPC; it would require application-level changes and does not protect non-HTTP protocols. Option C is wrong because using a site-to-site VPN over the internet introduces internet-based latency, jitter, and potential reliability issues, and it abandons the dedicated Direct Connect link, which is already in place for performance and compliance reasons. Option D is wrong because Direct Connect private VIFs do not support native encryption; there is no toggle or feature to 'enable encryption' on a VIF—encryption must be added via an overlay like IPsec.

145
Multi-Selecthard

A security team is designing an automated incident response system. The system must meet the following requirements: (1) automatically respond to GuardDuty findings, (2) ensure that response actions are logged and immutable, and (3) allow for human approval before destructive actions. Which services should the team use? (Select THREE.)

Select 3 answers
A.Amazon EventBridge
B.AWS CloudTrail
C.AWS Step Functions
D.AWS Lambda
E.Amazon Simple Notification Service (SNS)
AnswersA, B, C

Amazon EventBridge is the correct entry point because GuardDuty publishes every finding to the default event bus as an event with a detail-type such as 'GuardDuty Finding'. A rule can filter on finding severity, account, or region and immediately invoke a Step Functions state machine or Lambda function, enabling real-time, event-driven response. Without EventBridge, you would have to poll the GuardDuty API, which introduces latency and bypasses the native event pattern that AWS services emit.

Why this answer

Amazon EventBridge (A) is correct because it can receive GuardDuty findings in near real-time and route them to downstream targets for automated response. This enables the first requirement by triggering workflows directly from GuardDuty events without custom polling.

Exam trap

The trap here is that candidates often select Lambda as the sole compute service, overlooking that Step Functions is required to orchestrate the human approval step and that CloudTrail is needed for immutable logging, not just EventBridge and Lambda alone.

146
MCQeasy

A company is experiencing unauthorized access attempts to an S3 bucket. Which AWS service can be used to detect and alert on such events in real time?

A.Amazon Macie
B.AWS Config
C.AWS CloudTrail
D.Amazon GuardDuty
AnswerD

Amazon GuardDuty is a threat detection service that continuously monitors for malicious and unauthorized behavior using integrated threat intelligence and machine learning. It ingests S3 data events from CloudTrail, as well as VPC flow logs and DNS logs, to identify anomalies like unusual access patterns, credential compromise, or suspicious source IPs. GuardDuty generates findings in near real time, making it the appropriate service for detecting unauthorized access attempts to S3.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior across AWS accounts and workloads. It uses machine learning, anomaly detection, and integrated threat intelligence to analyze AWS CloudTrail management and data events, VPC Flow Logs, and DNS logs. When it detects unauthorized access attempts to an S3 bucket, such as suspicious API calls or anomalous data access patterns, it generates real-time security findings that can be sent to Amazon CloudWatch Events for alerting and automated response.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail's logging capability with real-time threat detection, but CloudTrail only records events and does not analyze them for malicious patterns, whereas GuardDuty is purpose-built for continuous threat detection and alerting.

How to eliminate wrong answers

Option A is wrong because Amazon Macie is a data security and data privacy service that uses machine learning to discover, classify, and protect sensitive data stored in S3, but it does not detect or alert on unauthorized access attempts in real time; it focuses on data classification and compliance, not threat detection. Option B is wrong because AWS Config is a service that evaluates and records resource configurations and compliance against desired policies, but it does not analyze real-time API activity or network traffic for unauthorized access; it is a configuration auditing tool, not a threat detection service. Option C is wrong because AWS CloudTrail records API activity for audit and governance purposes, but it does not perform real-time threat detection or alerting on its own; it provides the raw event logs that services like GuardDuty consume, but CloudTrail itself does not analyze events for malicious patterns or generate security findings.

147
MCQeasy

A security engineer needs to ensure that an Amazon S3 bucket is not publicly accessible. Which AWS service can be used to continuously monitor and alert if the bucket becomes public?

A.AWS CloudTrail
B.AWS Config
C.AWS Trusted Advisor
D.Amazon GuardDuty
AnswerB

AWS Config continuously records the configuration state of your S3 bucket and evaluates it against managed rules such as s3-bucket-public-read-prohibited, s3-bucket-encryption-enabled, and s3-bucket-versioning-enabled. When a bucket configuration drifts from the expected baseline, AWS Config marks the resource noncompliant and can trigger remediation via Systems Manager Automation or alert you through Amazon SNS. This native configuration governance is precisely what is needed to ensure the bucket remains compliant, not merely observed or protected.

Why this answer

(AWS Config) is correct because AWS Config has managed rules such as 's3-bucket-public-read-prohibited' and 's3-bucket-public-write-prohibited' that can evaluate S3 bucket policies and ACLs, continuously monitor configurations, and trigger alerts via Amazon SNS when a bucket becomes public. Option A (AWS CloudTrail) is wrong because CloudTrail records API calls but does not evaluate resource configurations. Option C (AWS Trusted Advisor) provides best-practice checks but does not offer continuous monitoring and alerting for configuration changes.

Option D (Amazon GuardDuty) focuses on threat detection, not configuration compliance.

148
MCQhard

A company has a requirement to detect and respond to threats in near real-time by analyzing VPC Flow Logs. The logs are generated in a VPC and sent to CloudWatch Logs. What is the MOST efficient way to analyze these logs for suspicious patterns and trigger automated responses?

A.Stream logs to Amazon Elasticsearch Service and use Kibana alerts
B.Use S3 event notifications to trigger Lambda functions on new log files
C.Export logs to S3 and use Amazon Athena queries with scheduled rules
D.Use Amazon Kinesis Data Analytics for real-time analysis and AWS Lambda for automated response
AnswerD

Amazon Kinesis Data Analytics continuously processes streaming logs using SQL or Apache Flink, allowing pattern matching, anomaly detection, and aggregation over sliding windows in near-real-time—latency can be under a few seconds. It can output its results to a Lambda function (via a Kinesis Data Analytics destination or an intermediate Kinesis Data Stream) which then executes an automated response (e.g., updating security groups, invoking AWS WAF, or sending alerts). This stream-processing architecture directly meets the 'detect and respond' requirement with minimal delay, unlike batch-based alternatives.

Why this answer

Amazon Kinesis Data Analytics can process streaming VPC Flow Logs from CloudWatch Logs in near real-time using SQL or Apache Flink, enabling immediate detection of suspicious patterns. AWS Lambda can then be triggered to automate incident response actions, such as updating security groups or isolating instances, making this the most efficient solution for near real-time threat detection and response.

Exam trap

The trap here is that candidates often choose batch-oriented solutions like Athena or S3 event notifications, overlooking the explicit 'near real-time' requirement in the question, which demands a streaming analytics approach.

How to eliminate wrong answers

Option A is wrong because streaming logs to Amazon Elasticsearch Service (now OpenSearch Service) and using Kibana alerts introduces significant latency due to indexing and query overhead, and it is not designed for near real-time automated response. Option B is wrong because S3 event notifications trigger Lambda functions on new objects, but VPC Flow Logs are sent to CloudWatch Logs, not directly to S3, and this approach would require an additional export step, breaking near real-time analysis. Option C is wrong because exporting logs to S3 and using Athena with scheduled rules is a batch-oriented process that incurs minutes of delay, failing the near real-time requirement.

149
MCQhard

A security engineer attaches the above SCP to an OU containing development accounts. The engineer expects that only t3.micro instances can be launched, but developers report that they cannot launch any EC2 instances. What is the MOST likely reason?

A.The SCP syntax is invalid because it uses Deny without an explicit Allow.
B.The condition StringNotEquals is evaluated incorrectly for EC2 instance types.
C.The SCP is applied at the organization root and overrides the OU-level policy.
D.The SCP denies all ec2 actions because there is no explicit allow statement.
AnswerD

SCPs act as permission boundaries and never grant permissions; they only filter the actions that IAM policies allow. If an SCP contains only Deny statements and no Allow statement permitting EC2 actions, the implicit default deny applies to every EC2 API call, regardless of what IAM identity-based policies grant. This is why the policy denies all EC2 actions.

Why this answer

SCPs operate on a default-deny model: all actions are implicitly denied unless explicitly allowed. The policy only denies non-t3.micro instance types but does not include an explicit Allow statement for ec2:RunInstances or any other EC2 action. Without an explicit Allow, the implicit deny blocks all EC2 actions, including launching t3.micro instances.

Exam trap

The trap here is that candidates assume a Deny statement with a condition implicitly allows all other actions, forgetting that SCPs follow a default-deny model where any action not explicitly allowed is denied.

How to eliminate wrong answers

Option A is wrong because SCPs do not require an explicit Allow alongside a Deny; they can use Deny alone to restrict actions, but the issue here is the lack of any Allow statement. Option B is wrong because the StringNotEquals condition is evaluated correctly—it denies instance types that are not t3.micro, but the problem is the missing Allow for the action itself. Option C is wrong because the SCP is attached to the OU, not the root, and even if a root-level SCP existed, it would not override the OU-level policy unless explicitly set to deny; SCPs are additive and the most restrictive applies.

150
MCQhard

A security team wants to collect and analyze logs from multiple AWS services including CloudTrail, VPC Flow Logs, and AWS WAF. They need a centralized solution that can filter, transform, and route logs to multiple destinations in near real-time. Which AWS service should they use?

A.Amazon CloudWatch Logs Insights
B.Amazon CloudWatch Logs subscription filters with AWS Lambda
C.Amazon Kinesis Data Streams combined with Amazon Kinesis Data Firehose
D.Amazon S3 with S3 Event Notifications
AnswerC

Kinesis Data Streams provides durable, real-time ingestion for log data arriving from multiple sources, and Kinesis Data Firehose can buffer, transform, and deliver that data to multiple destinations such as Amazon S3, Redshift, or OpenSearch. The integration is the core of a managed log pipeline, enabling both real-time processing via stream consumers and reliable batch delivery. This directly addresses the need to collect and analyze logs from multiple sources.

Why this answer

Amazon Kinesis Data Streams combined with Amazon Kinesis Data Firehose is the correct choice because it provides a fully managed, scalable, and near real-time pipeline for collecting, filtering, transforming, and routing logs from multiple AWS services (CloudTrail, VPC Flow Logs, WAF) to multiple destinations such as Amazon S3, Amazon Redshift, or Amazon Elasticsearch Service. Kinesis Data Streams captures and stores the data stream, while Kinesis Data Firehose can invoke AWS Lambda for transformation and reliably deliver the processed logs to the specified sinks, meeting the requirement for centralized, near real-time log processing.

Exam trap

The trap here is that candidates often confuse Amazon CloudWatch Logs subscription filters with Lambda as a simple routing solution, but they overlook the requirement for multiple destinations and near real-time transformation, which Kinesis Data Streams and Firehose handle natively with built-in buffering, retry logic, and Lambda integration.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs Insights is a query and analysis tool for existing CloudWatch Logs data, not a service for collecting, filtering, transforming, and routing logs to multiple destinations in near real-time. Option B is wrong because CloudWatch Logs subscription filters with AWS Lambda can forward logs to a single destination (e.g., Kinesis, Lambda, or Elasticsearch) but cannot natively route to multiple destinations or perform complex transformations without custom code, and it lacks the built-in buffering and retry capabilities of Kinesis Data Firehose. Option D is wrong because Amazon S3 with S3 Event Notifications is an object storage service that triggers notifications on object creation, but it does not support near real-time log collection, filtering, or transformation before storage, and it cannot route logs to multiple destinations directly.

Page 1

Page 2 of 17

Page 3