Courseiva

AWS Certified Security Specialty SCS-C02 (SCS-C02) — Questions 151–225

1205 questions total · 17pages · All types, answers revealed

Page 2

Page 3 of 17

Page 4
151
MCQmedium

A company uses S3 to store sensitive customer data. They want to ensure that all S3 buckets have encryption enabled at rest. Which S3 feature should be used to automatically enforce encryption on all newly created objects?

A.S3 Block Public Access
B.S3 Object Lock
C.S3 Bucket Policy with a condition requiring server-side encryption
D.S3 Inventory
AnswerC

A bucket policy can enforce server-side encryption by using the request header condition keys `s3:x-amz-server-side-encryption` and `s3:x-amz-server-side-encryption-aws-kms-key-id`. For instance, a `Deny` statement with `StringNotEquals` on `s3:x-amz-server-side-encryption` for `aws:kms`, combined with a `Null` condition that denies uploads where the header is absent, will reject every `PutObject` and `InitiateMultipartUpload` that does not specify SSE-KMS. This is a direct, request-time enforcement mechanism.

Why this answer

An S3 bucket policy with a condition requiring server-side encryption (e.g., 's3:x-amz-server-side-encryption': 'aws:kms' or 'AES256') can deny any PutObject request that does not include the encryption header, thereby automatically enforcing encryption on all newly created objects. Option A is incorrect because S3 Block Public Access controls public access, not encryption. Option B is incorrect because S3 Object Lock is for write-once-read-many (WORM) retention, not encryption enforcement.

Option D is incorrect because S3 Inventory provides a list of objects and their metadata but does not enforce encryption.

152
MCQeasy

A solutions architect needs to design a system where an EC2 instance can write logs to CloudWatch Logs. Which IAM entity should be used to grant permissions to the EC2 instance?

A.A resource-based policy on the EC2 instance
B.An IAM role with an instance profile
C.An IAM user with access keys stored on the instance
D.An IAM group
AnswerB

An IAM role with an instance profile is the correct approach because it provides temporary credentials to the EC2 instance through the instance metadata service (IMDSv2). The EC2 service assumes the role on behalf of the instance, and the credentials are automatically rotated and never stored as static secrets on disk. This follows the AWS security best practice of using temporary credentials for all applications running on EC2.

Why this answer

An IAM role with an instance profile is the correct approach because it allows the EC2 instance to assume temporary, rotated credentials via the AWS Security Token Service (STS). The instance profile is attached to the EC2 instance, and the AWS SDK or CLI automatically retrieves credentials from the instance metadata service (IMDS) to authenticate API calls to CloudWatch Logs. This eliminates the need to store long-term credentials on the instance and follows the principle of least privilege.

Exam trap

The trap here is that candidates may confuse IAM groups with IAM roles, thinking a group can be attached to an EC2 instance, but groups only apply to IAM users and cannot be assumed by AWS services.

How to eliminate wrong answers

Option A is wrong because a resource-based policy on an EC2 instance does not exist; EC2 instances use IAM roles (via instance profiles) for permissions, not resource-based policies like those for S3 buckets or KMS keys. Option C is wrong because storing IAM user access keys on the EC2 instance is a security risk—keys are long-term credentials that can be compromised, and AWS best practices mandate using IAM roles with temporary credentials instead. Option D is wrong because an IAM group is a container for IAM users and cannot be directly attached to an EC2 instance; permissions must be assigned via an IAM role with an instance profile.

153
Multi-Selecteasy

Which TWO actions are best practices for securing an AWS account's root user? (Choose 2.)

Select 2 answers
A.Share the root user password with the team for emergency access
B.Use a strong password and store it securely
C.Enable multi-factor authentication (MFA) on the root user
D.Use the root user for daily administrative tasks
E.Create access keys for the root user for programmatic access
AnswersB, C

A strong, uniquely complex root password stored securely reduces the risk of credential compromise, since the root user cannot be restricted by IAM policies and has unrestricted account access. This satisfies the best-practise requirement for protecting that identity.

Why this answer

Option B is correct because the root user has unrestricted access to all AWS resources and billing, so it must be protected with a strong, complex password stored in a secure location such as a password manager or secrets vault. Option C is correct because enabling MFA on the root user adds a critical second authentication factor, ensuring that a compromised password alone cannot grant full account control. Options A, D, and E are not best practices: sharing the root password violates least privilege and accountability, using root for daily administrative tasks should be avoided in favor of IAM users or roles, and creating root access keys is discouraged because long-lived root credentials cannot be scoped down and pose a severe security risk.

Exam trap

The trap here is that candidates often think sharing the root password with the team (Option A) is a valid emergency access strategy, but AWS explicitly recommends using IAM roles with a break-glass process (e.g., AWS Systems Manager Incident Manager) instead, as shared passwords create auditability and credential rotation issues.

154
MCQmedium

A company has a multi-account AWS environment managed with AWS Organizations. The security team wants to ensure that no EC2 instance in any account can be launched without a specific tag 'CostCenter'. The team has created a Service Control Policy (SCP) that denies the ec2:RunInstances action if the request does not include the tag 'CostCenter'. However, they find that instances are still being launched without the tag in some accounts. What is the most likely reason?

A.The SCP uses the wrong condition key; it should use 'aws:ResourceTag' instead.
B.The accounts launching instances without tags are the management account.
C.The SCP does not include an explicit allow for the action.
D.The SCP is not attached to the organizational units containing the accounts.
AnswerB

In AWS Organizations, the management account is explicitly exempt from all SCPs; SCPs can only restrict access for member accounts. If the SCP is attached at the root or to the relevant OUs and untagged instances still appear, the launches must be originating from the management account, whose principals are not evaluated against any SCP and therefore retain full permissions.

Why this answer

The most likely reason is that the accounts launching instances without the tag are the management account. Service Control Policies (SCPs) do not affect the management account in AWS Organizations; they only apply to member accounts. Therefore, if the security team is testing from the management account, the SCP denying ec2:RunInstances without the 'CostCenter' tag will not be enforced.

Option A is incorrect because 'aws:RequestTag' is the correct condition key for tagging requests, not 'aws:ResourceTag'. Option C is incorrect because SCPs work by denying actions, not by requiring explicit allows. Option D is incorrect because the SCP would still prevent unauthorized launches even without an explicit allow.

The issue is specifically that SCPs do not apply to the management account.

155
MCQmedium

A company uses Amazon CloudWatch Logs to collect application logs from EC2 instances. The security team wants to create an alarm that triggers when a specific error pattern appears in the logs. They have set up a metric filter and an alarm. However, the alarm is not triggering even though the error pattern exists in the logs. What is the most likely cause?

A.The log group retention period is set to 1 day.
B.The metric filter uses a custom namespace that is not allowed.
C.The metric filter was created before the log group.
D.The metric filter is only applied to log events that occur after the filter is created.
AnswerD

When you create a metric filter, CloudWatch Logs begins applying it only to new log events that arrive after creation; it does not scan or backfill the log group's existing history. Any events that were recorded before the filter existed will never be evaluated, even if they match the pattern. This is why a newly added filter often shows no metrics until subsequent log events are generated.

Why this answer

CloudWatch Logs metric filters are not retroactive: they only evaluate log events that are ingested after the filter is created. If the error pattern existed in the logs before the metric filter was created, those events will not generate metric data points, so the alarm will not trigger based on historical events. This is the most likely cause of the alarm not firing.

Exam trap

SCS-C02 often tests the misconception that CloudWatch metric filters retroactively evaluate existing log data — candidates must remember that metric filters only apply to log events ingested after the filter is created, so historical errors will not trigger alarms.

How to eliminate wrong answers

Option A is wrong because a 1-day retention period would only delete old logs; it would not prevent the metric filter from matching new events that contain the error pattern, so it does not explain why the alarm fails to trigger. Option B is wrong because CloudWatch supports custom namespaces for metric filters; there is no restriction that disallows custom namespaces, so this is not a valid cause. Option C is wrong because creating a metric filter before the log group is not a supported operation — the log group must exist first — and even if recreated, the ordering does not explain the alarm not triggering for new events.

156
MCQmedium

A company is designing a data protection strategy for its Amazon RDS for MySQL database. The database contains sensitive data that must be encrypted at rest. The company also needs to manage the encryption keys using its own HSM. Which solution should be used?

A.Use client-side encryption with a key from CloudHSM
B.Use AWS CloudHSM to generate a key and import it into RDS
C.Enable encryption at rest using the default AWS KMS key
D.Use AWS KMS with a custom key store backed by AWS CloudHSM
AnswerD

This is the correct approach because AWS KMS custom key stores let you create a CMK whose key material is stored in a CloudHSM cluster that you fully control. When you enable RDS encryption at rest, RDS uses this CMK to encrypt the storage, and the key material never leaves your HSM. This gives you the dual benefit of RDS-native transparent encryption and the cryptographic ownership of an HSM, satisfying the data protection strategy.

Why this answer

To encrypt an Amazon RDS for MySQL database at rest while managing keys in a customer-owned HSM, you must use AWS KMS with a custom key store backed by AWS CloudHSM. This allows you to use keys from your own CloudHSM cluster for RDS encryption. Option D is correct.

Option A is incorrect because client-side encryption is not for at-rest encryption of the RDS instance itself. Option B is incorrect because you cannot directly import keys from CloudHSM into RDS; the integration is through KMS custom key store. Option C is incorrect because the default AWS KMS key does not allow you to manage the key in your own HSM.

157
MCQeasy

A company wants to block SSH access (port 22) to all EC2 instances from the internet, but allow SSH from a specific management VPN IP range (10.0.0.0/16). Which configuration should be used?

A.Configure a security group to allow inbound SSH from 10.0.0.0/16 only.
B.Use an IAM policy to restrict SSH access to the management IP range.
C.Configure a network ACL to allow inbound SSH from 10.0.0.0/16 and deny from 0.0.0.0/0.
D.Configure a security group to allow inbound SSH from 0.0.0.0/0 and deny from 10.0.0.0/16.
AnswerA

A security group acts as a stateful instance-level firewall with an implicit deny-all for inbound traffic, so configuring a rule that allows inbound TCP port 22 from only 10.0.0.0/16 satisfies the requirement. Because security groups only contain permissive rules, any SSH connection sourced outside that CIDR is automatically blocked by the default deny, without needing an explicit deny. This approach also automatically allows return traffic for established sessions due to statefulness, so no separate outbound rule is required.

Why this answer

Security groups are stateful firewalls that control inbound and outbound traffic at the instance level. By configuring a security group to allow inbound SSH (port 22) only from the management VPN IP range (10.0.0.0/16), all other inbound traffic on port 22 is implicitly denied because security groups operate on a default-deny principle. This meets the requirement to block SSH from the internet while permitting access from the specified internal range.

Exam trap

The trap here is that candidates often confuse the stateless nature of network ACLs with the stateful behavior of security groups, leading them to choose a network ACL solution (Option C) without considering the need for explicit outbound rules, or they incorrectly think security groups can deny specific IP ranges (Option D).

How to eliminate wrong answers

Option B is wrong because IAM policies control permissions for AWS API actions (e.g., ec2:AuthorizeSecurityGroupIngress), not network traffic at the packet level; they cannot filter SSH connections to EC2 instances. Option C is wrong because network ACLs are stateless and require explicit inbound and outbound rules; allowing inbound SSH from 10.0.0.0/16 and denying from 0.0.0.0/0 would work for inbound traffic, but the outbound return traffic must also be explicitly allowed, and the question asks for a configuration that blocks SSH from the internet—security groups are the simpler, correct choice for instance-level control. Option D is wrong because security groups only support allow rules; you cannot explicitly deny traffic from a specific IP range within a security group, and allowing from 0.0.0.0/0 would permit SSH from the internet, which contradicts the requirement.

158
MCQmedium

A company has an S3 bucket policy that allows cross-account access for a specific IAM role in another account. The bucket policy includes a Principal element with the ARN of the role. However, users in the other account that assume the role are unable to access the bucket. Which of the following is the MOST likely cause?

A.The IAM role does not have a permissions policy granting s3:GetObject on the bucket.
B.The bucket policy has an explicit Deny statement that overrides the Allow.
C.The role's trust policy does not allow the S3 service to assume the role.
D.The bucket policy uses the role ARN in the Principal element instead of the AWS account ID.
AnswerA

In cross-account S3 access, the requesting IAM role must have an identity-based permissions policy that explicitly allows s3:GetObject on the specific bucket. The bucket policy alone is insufficient; if the role lacks the necessary IAM permissions, the request is denied even when the bucket policy states that access is allowed. This missing permissions policy is the most common root cause when a role cannot read from a bucket it was supposedly granted access to.

Why this answer

For cross-account access using an S3 bucket policy, the IAM role in the trusted account must have a permissions policy that grants the necessary S3 actions (e.g., s3:GetObject). Without this policy, even if the bucket policy allows the role, the role itself does not have permission to perform the action. Options B, C, and D are less likely: B is possible but not the most common; C is incorrect because the trust policy allows users to assume the role, not the S3 service; D is incorrect because role ARNs are valid principals in S3 bucket policies.

Exam trap

Candidates often forget that the IAM role itself needs both a trust policy and a permissions policy. The bucket policy grants access to the role, but the role must also have the required permissions.

How to eliminate wrong answers

Option A is wrong because the question states the bucket policy allows cross-account access for a specific IAM role, and the issue is about the policy's Principal element, not the role's permissions policy; even if the role had an s3:GetObject permission, the bucket policy's Principal mismatch would still block access. Option B is wrong because there is no mention of an explicit Deny statement in the scenario; the problem is that the Allow statement itself is misconfigured due to the Principal element, not overridden by a Deny. Option C is wrong because the role's trust policy controls which entities can assume the role, not whether the S3 service can assume it; S3 does not assume roles—users or services assume roles, and the trust policy is irrelevant to S3 bucket policy evaluation.

159
Multi-Selectmedium

A company wants to enforce that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. Which THREE steps should the company take?

Select 3 answers
A.Create an IAM policy that denies all actions if aws:MultiFactorAuthPresent is false.
B.Enable CloudTrail to monitor MFA usage.
C.Attach the MFA enforcement policy to all IAM users or groups.
D.Set the password policy to require MFA.
E.Enable MFA for each IAM user.
AnswersA, C, E

This is the correct foundational enforcement mechanism: a Deny statement with a Bool condition on aws:MultiFactorAuthPresent. When the key evaluates to "false", the request is denied, so any API or console action by a user who did not authenticate with MFA fails. The policy can be scoped with NotAction to permit MFA self-management tasks, ensuring users can enroll without being locked out. This condition-based denial is what actually enforces MFA, unlike audit-only measures.

Why this answer

The correct steps are to enable MFA for each IAM user (E), create an IAM policy that denies all actions if `aws:MultiFactorAuthPresent` is false (A), and attach the policy to all IAM users or groups (C). Enabling MFA per user is a prerequisite. The policy enforces MFA usage by denying API calls when MFA is not present.

Attaching the policy ensures it applies to users. Option B (CloudTrail) is for auditing, not enforcement. Option D (password policy) does not enforce MFA for console access; it only sets password requirements.

160
Multi-Selecteasy

Which TWO AWS services can be used to detect and alert on unauthorized API calls in real time?

Select 2 answers
A.Amazon CloudWatch Alarms
B.AWS KMS
C.Amazon EventBridge
D.AWS IAM
E.AWS Config
AnswersA, C

CloudWatch Alarms work with CloudTrail by using metric filters that are applied to log groups containing CloudTrail events. When the metric filter detects a pattern such as a specific unauthorized API action or a spike in failed calls, the alarm shifts to ALARM and publishes to an SNS topic to alert operators. This threshold-based approach is one of the standard ways to turn historical CloudTrail logs into actionable alerts.

Why this answer

Amazon CloudWatch Alarms (A) is correct because you can create metric filters on CloudTrail log groups that match unauthorized API calls (e.g., AccessDenied or specific error codes), and the alarm triggers an SNS notification in near real time. Amazon EventBridge (C) is correct because it can receive CloudTrail management events, match patterns for unauthorized API activity (such as errorCode values), and route them to targets like SNS, Lambda, or SQS for immediate alerting. AWS KMS (B) is a key management service, not an API-call detection or alerting service.

AWS IAM (D) controls authentication and authorization but does not itself detect or alert on unauthorized calls. AWS Config (E) evaluates resource configuration compliance and records configuration changes, not real-time API-call alerting.

Exam trap

SCS-C02 often tests the distinction between detection services (GuardDuty, CloudWatch, EventBridge) and configuration/identity services (Config, IAM, KMS) — candidates may pick AWS Config thinking it alerts on API calls, but Config is for compliance evaluation, not real-time API monitoring.

161
Drag & Dropmedium

Drag and drop the steps to implement a secure CI/CD pipeline with AWS CodePipeline and IAM in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Secure pipeline requires encrypted artifact bucket, IAM roles, source repo, build project with security scanning, and pipeline.

162
MCQeasy

A company needs to monitor for root account usage and receive immediate notifications. Which combination of AWS services should be used?

A.AWS Config and AWS Lambda
B.Amazon GuardDuty and AWS Lambda
C.S3 server access logs and Amazon Inspector
D.AWS CloudTrail, Amazon CloudWatch Logs, and Amazon SNS
AnswerD

AWS CloudTrail is the audit service that records every root account sign-in (eventName ConsoleLogin with userIdentity.type Root) and every root-initiated API call, and a trail can deliver those events to CloudWatch Logs. A CloudWatch Logs metric filter can match root events and publish a metric, and a CloudWatch alarm based on that metric then invokes an SNS topic to notify administrators in real time. This combination provides deterministic, account-wide monitoring of root usage and is the standard AWS-recommended pattern.

Why this answer

AWS CloudTrail captures all root account API calls, CloudWatch Logs can monitor those events for root activity using a metric filter, and Amazon SNS delivers immediate notifications when the filter triggers. This combination provides the logging, monitoring, and alerting pipeline required for real-time root account usage detection.

Exam trap

The trap here is that candidates often assume GuardDuty or Config can directly alert on root activity, but they lack the native log-to-notification pipeline that CloudTrail, CloudWatch Logs, and SNS provide together.

How to eliminate wrong answers

Option A is wrong because AWS Config is designed for resource compliance and configuration history, not for real-time monitoring of API calls like root account usage; Lambda alone cannot capture the root activity without a triggering event source like CloudTrail. Option B is wrong because Amazon GuardDuty focuses on threat detection from VPC Flow Logs, DNS logs, and CloudTrail management events, but it does not provide a native mechanism for immediate SNS notifications specifically for root account usage without additional services. Option C is wrong because S3 server access logs record object-level requests to S3, not root account API calls, and Amazon Inspector is a vulnerability assessment service that does not monitor or alert on root account activity.

163
Multi-Selecteasy

A company wants to restrict access to an S3 bucket so that only traffic from a specific VPC can download objects. Which combination of actions should the company take? (Choose TWO.)

Select 2 answers
A.Attach an Internet gateway to the VPC and route traffic through it.
B.Attach a security group to the S3 bucket.
C.Create an S3 bucket policy that allows access only from the VPC using the aws:SourceVpc condition.
D.Create a NAT gateway in the VPC for outbound traffic.
E.Create a VPC endpoint for Amazon S3 in the VPC.
AnswersC, E

Create a bucket policy whose Principal is the intended IAM role or account and add a Condition using the aws:SourceVpc key set to the VPC ID. This allows requests only when they originate from that exact VPC, so traffic from any other VPC or the public internet is blocked. To make this work, requests must arrive through a VPC endpoint for S3, because the aws:SourceVpc condition key is populated only for traffic that uses an endpoint.

Why this answer

To restrict access to an S3 bucket so that only traffic from a specific VPC can download objects, the correct combination is to create an S3 bucket policy that uses the aws:SourceVpc condition (Option C) and create a VPC endpoint for Amazon S3 in the VPC (Option E). The bucket policy with aws:SourceVpc ensures that only requests originating from the specified VPC are allowed, while the VPC endpoint enables private connectivity between the VPC and S3 without traversing the internet. Option A (Internet gateway) would make the VPC publicly accessible and is not required for private access.

Option B (NAT gateway) is used for outbound internet access from private subnets, not for restricting access to S3. Option D (security group) cannot be attached to an S3 bucket; security groups apply to EC2 instances or other resources, not to S3.

164
MCQeasy

A company wants to detect and alert on SSH brute force attacks on EC2 instances. Which AWS service should be used?

A.AWS Config
B.Amazon GuardDuty
C.Amazon Inspector
D.AWS CloudTrail
E.AWS Shield
AnswerB

Amazon GuardDuty is purpose-built for threat detection, analyzing continuous data from VPC Flow Logs, AWS CloudTrail events, and DNS query logs with machine learning and threat intelligence. It recognizes SSH brute force patterns, such as a single source IP making a large number of TCP connections to port 22 on an EC2 instance, and surfaces findings like UnauthorizedAccess:EC2/SSHBruteForce. Those findings can be pushed to Amazon EventBridge to trigger automated alerting or remediation, making it the correct service here.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior, including SSH brute force attacks. It uses machine learning and integrated threat intelligence to analyze VPC Flow Logs, DNS logs, and CloudTrail events, and can generate findings for 'UnauthorizedAccess:EC2/SSHBruteForce' when repeated failed SSH login attempts are detected.

Exam trap

The trap here is that candidates often confuse Amazon Inspector (which scans for vulnerabilities) with GuardDuty (which detects active threats), or they assume CloudTrail alone can alert on brute force attacks without realizing it lacks built-in threat analysis and alerting capabilities.

How to eliminate wrong answers

Option A is wrong because AWS Config is a configuration management and compliance service that evaluates resource configurations against rules, not a threat detection service; it cannot analyze network traffic or login patterns for brute force attacks. Option C is wrong because Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and unintended network exposure, not real-time threat detection like brute force attacks. Option D is wrong because AWS CloudTrail records API activity and can log SSH login events (via EC2 instance metadata or Systems Manager), but it does not analyze logs for malicious patterns or generate security alerts on its own.

Option E is wrong because AWS Shield is a DDoS protection service that defends against volumetric and application-layer attacks, not SSH brute force attacks which are authentication-based threats.

165
MCQhard

A company uses AWS KMS to encrypt data in Amazon S3. The security team receives an alert that an IAM user is attempting to decrypt data using a key that they do not have access to. Which AWS service can be used to monitor and alert on such unauthorized KMS API calls?

A.Amazon GuardDuty
B.AWS Config
C.AWS CloudTrail with CloudWatch Alarms
D.Amazon Inspector
AnswerC

AWS CloudTrail captures every KMS API request as a management event, including kms:Encrypt, kms:Decrypt, and kms:ScheduleKeyDeletion, and delivers those logs to an S3 bucket. You can then define a CloudWatch Logs metric filter on the JSON field of the CloudTrail event to match a specific KMS action, and attach a CloudWatch Alarm to that metric to trigger an SNS notification. This combination provides the required trackable, alertable audit trail for KMS API calls made when S3 encrypts objects using customer-managed KMS keys.

Why this answer

AWS CloudTrail logs all KMS API calls, and CloudWatch Alarms can be configured to trigger on specific unauthorized API calls, such as Decrypt attempts with a key the user does not have access to. Option A is incorrect because Amazon GuardDuty is a threat detection service that focuses on identifying malicious activity, but it does not provide detailed monitoring of specific KMS API calls. Option B is incorrect because AWS Config evaluates resource configurations and compliance, not API calls.

Option D is incorrect because Amazon Inspector is a vulnerability assessment service for EC2 instances and does not monitor API calls.

166
MCQhard

Refer to the exhibit. A security engineer runs the iptables command on an EC2 instance in a VPC. The instance has a security group that allows all outbound traffic and inbound SSH from 0.0.0.0/0, HTTP from 0.0.0.0/0, and HTTPS from 0.0.0.0/0. A user from IP 203.0.113.5 tries to connect to the instance over HTTP. What will happen?

A.The connection succeeds because the security group allows HTTP.
B.The connection succeeds because iptables allows HTTP from anywhere.
C.The connection is dropped by iptables.
D.The connection is dropped by the security group.
AnswerC

When the HTTP packet from the public client reaches the instance, the security group already allows it, so it is not rejected at the VPC edge. In the INPUT chain, the ACCEPT rule for 10.0.0.0/16 does not match because the source IP is outside that range, and the subsequent DROP rule or default policy DROP terminates the packet. This drop happens inside the instance OS, not in the security group.

Why this answer

The iptables command shown in the exhibit (not provided here but implied to have a default DROP or REJECT policy on the INPUT chain, or a specific rule that drops HTTP traffic) overrides the security group's permissive rules. Security groups act as a virtual firewall at the instance level, but iptables operates within the instance's OS kernel netfilter framework and is evaluated after the security group. Since iptables drops the HTTP connection, the packet is discarded before reaching the application, regardless of the security group allowing HTTP from 0.0.0.0/0.

Exam trap

The trap here is that candidates assume security groups are the only firewall layer and forget that iptables rules within the instance can override them, leading them to incorrectly choose option A or B.

How to eliminate wrong answers

Option A is wrong because the security group allows HTTP, but iptables rules are evaluated after the security group and can override its permissions; the connection is dropped by iptables. Option B is wrong because iptables does not allow HTTP from anywhere; the exhibit's iptables configuration (implied) drops HTTP traffic, so the connection fails. Option D is wrong because the security group allows HTTP from 0.0.0.0/0, so it does not drop the connection; the drop occurs due to iptables.

167
MCQmedium

A financial services company uses AWS CloudTrail to log all API calls in their account. They store the logs in an S3 bucket with server-side encryption using AWS KMS (SSE-KMS). The security team needs to ensure that only authorized users can decrypt and read the logs. They have created a KMS key with a key policy that grants decrypt permissions to the security team's IAM roles. However, when a security engineer tries to download a log file from the S3 bucket using the AWS CLI, they receive an 'AccessDenied' error. The engineer has s3:GetObject permission on the bucket. What is the most likely cause?

A.The CloudTrail trail is not configured to use SSE-KMS.
B.The S3 bucket has a bucket policy that denies access to the engineer's IAM role.
C.The S3 bucket policy does not allow the engineer to read objects.
D.The KMS key policy does not grant the engineer's role permission to decrypt.
AnswerD

To read SSE-KMS-encrypted CloudTrail logs, an IAM principal must have both s3:GetObject on the object and kms:Decrypt on the key. The KMS key policy is a resource-based policy that must include a statement allowing the engineer's role to call kms:Decrypt. If that grant is absent, the S3 GET can succeed but retrieval fails during decryption, causing the access denied error. This option correctly identifies the missing authorization.

Why this answer

The engineer has s3:GetObject permission, but the S3 object is encrypted with SSE-KMS. To decrypt and read the object, the engineer also needs kms:Decrypt permission on the KMS key. The key policy grants decrypt permissions to the security team's IAM roles, but the engineer's role may not be included.

The most likely cause is that the KMS key policy does not grant the engineer's role permission to decrypt.

Exam trap

The trap is focusing only on S3 permissions and forgetting that SSE-KMS requires additional KMS permissions; candidates might overlook the need for kms:Decrypt and the role of the key policy.

How to eliminate wrong answers

Option A is wrong because if the trail were not configured to use SSE-KMS, the object would not be encrypted with KMS, and the engineer would not need kms:Decrypt; but the scenario states it is SSE-KMS, so this is not the cause. Option B is wrong because the engineer has s3:GetObject permission, and there is no mention of a bucket policy denying access; if there were, the error would still be AccessDenied, but the most likely cause given the KMS key policy is the missing decrypt permission. Option C is wrong because the engineer already has s3:GetObject permission, so the bucket policy does not need to allow it; the issue is KMS permissions.

168
MCQmedium

A company uses Amazon GuardDuty and wants to automatically isolate a compromised EC2 instance by removing it from the security group. Which approach should be used?

A.Set up an AWS Config rule to detect the finding and remediate.
B.Configure GuardDuty to directly modify the security group.
C.Create an Amazon EventBridge rule that triggers an AWS Lambda function to remove the instance from the security group.
D.Use AWS Systems Manager Automation to automatically modify the security group based on GuardDuty findings.
AnswerC

This is the correct approach because GuardDuty publishes each finding to Amazon EventBridge as an event, and EventBridge rules can target a Lambda function with an event pattern that matches the finding's type or severity. The Lambda function can then call the ec2:RevokeSecurityGroupIngress or ModifyInstanceAttribute API to remove the instance from the offending security group, providing automated, near-real-time remediation without manual intervention. EventBridge handles the event delivery, Lambda executes the remediation logic, and IAM roles grant the necessary permissions, forming the standard architecture for GuardDuty-based automated responses.

Why this answer

Amazon GuardDuty publishes findings to Amazon EventBridge, which can be used to trigger an AWS Lambda function. The Lambda function can then call the EC2 API to modify the security group and remove the compromised instance, achieving automated isolation without requiring direct GuardDuty integration with security groups.

Exam trap

The trap here is that candidates assume GuardDuty can directly perform remediation actions (Option B) or that AWS Config is the primary service for event-driven remediation (Option A), when in reality EventBridge is the standard integration point for triggering automated responses to GuardDuty findings.

How to eliminate wrong answers

Option A is wrong because AWS Config rules evaluate resource compliance and can trigger remediation actions, but they do not natively consume GuardDuty findings; you would need a custom Lambda or Systems Manager automation to bridge them, making this an indirect and less efficient approach. Option B is wrong because GuardDuty is a threat detection service that cannot directly modify security groups; it only generates findings and has no built-in remediation capabilities. Option D is wrong because AWS Systems Manager Automation can run remediation workflows, but it requires a separate trigger (e.g., EventBridge) to start the automation document based on GuardDuty findings, making it an extra layer of complexity compared to directly invoking Lambda via EventBridge.

169
MCQmedium

A company wants to centrally manage IAM users and allow them to access multiple AWS accounts using a single set of credentials. Which AWS service should be used?

A.AWS IAM Identity Center (AWS SSO)
B.IAM roles with cross-account trust
C.AWS Organizations consolidated billing
D.Amazon Cognito user pools
AnswerA

AWS IAM Identity Center (AWS SSO) is the correct service for centrally managing IAM users across multiple AWS accounts because it provides a single identity source and allows users to sign in once with temporary credentials issued through AWS STS. It supports creating users directly, connecting an external identity provider for federation, and assigning permission sets that control access across all accounts in an AWS Organization, eliminating the need for long-lived IAM user access keys and enabling a single sign-on experience.

Why this answer

AWS IAM Identity Center (formerly AWS SSO) is the correct service because it provides a centralized identity source that allows users to sign in once with a single set of credentials and then access multiple AWS accounts and business applications. It integrates with AWS Organizations to automatically manage permissions across accounts, eliminating the need for separate IAM users in each account.

Exam trap

The trap here is that candidates often confuse IAM roles with cross-account trust as a centralized solution, but they require manual role setup and do not provide a single sign-on portal or unified credential management across accounts.

How to eliminate wrong answers

Option B is wrong because IAM roles with cross-account trust allow users in one account to assume roles in another account, but they still require separate IAM users in the originating account and do not provide a single sign-on experience with a unified credential set. Option C is wrong because AWS Organizations consolidated billing only aggregates billing and payment across accounts; it does not manage user identities or provide authentication. Option D is wrong because Amazon Cognito user pools are designed for customer-facing identity and access management for web and mobile applications, not for centrally managing IAM users accessing multiple AWS accounts.

170
MCQeasy

A security engineer discovers an Amazon GuardDuty finding of type 'UnauthorizedAccess:EC2/SSHBruteForce' for an EC2 instance. The instance is part of an Auto Scaling group and has a public IP address. What is the MOST effective immediate step to mitigate the threat?

A.Modify the network ACL to block SSH traffic from the attacker's IP.
B.Terminate the instance without detaching it from the Auto Scaling group.
C.Update the security group to restrict SSH access to known IP addresses.
D.Detach the instance from the Auto Scaling group and terminate it.
AnswerD

Detaching the instance from the Auto Scaling group before termination marks it as a manual removal from the group's lifecycle, so the scaling policy does not immediately spin up a replacement. After detaching, you can terminate it to stop the attack or preserve it for forensic analysis, while maintaining the group's desired capacity if you intentionally adjust it. This is the correct immediate response because it eliminates the compromised resource and prevents the same vulnerable workload from being automatically reintroduced.

Why this answer

The instance is compromised and part of an Auto Scaling group. Detaching it first prevents the Auto Scaling group from immediately replacing it with a new instance that might inherit the same vulnerability, allowing for forensic analysis. Terminating it after detachment stops the SSH brute force attack at its source without risking automatic re-provisioning of a similarly exposed instance.

Exam trap

The trap here is that candidates assume terminating the instance directly (Option B) is sufficient, failing to recognize that Auto Scaling groups automatically replace terminated instances, which can immediately re-expose the environment to the same threat.

How to eliminate wrong answers

Option A is wrong because network ACLs are stateless and modifying them to block only the attacker's IP is ineffective against distributed brute force attacks; also, this does not address the compromised instance itself. Option B is wrong because terminating an instance that is part of an Auto Scaling group triggers the group to launch a replacement instance immediately, potentially recreating the same vulnerability if the underlying AMI or configuration is unchanged. Option C is wrong because updating the security group to restrict SSH access to known IPs is a preventive measure, not an immediate incident response step; it does not stop the ongoing attack on the already compromised instance.

171
MCQmedium

A security engineer is troubleshooting why CloudTrail logs are not being delivered to an S3 bucket. The bucket policy allows CloudTrail to write objects, and the trail is configured to log management events. However, no log files appear in the bucket. What is the MOST likely cause?

A.The trail is not logging data events.
B.The S3 bucket uses SSE-KMS encryption and the trail does not have permission to use the KMS key.
C.The S3 bucket is in a different AWS account.
D.The bucket policy is missing a Deny statement.
AnswerB

When an S3 bucket uses SSE-KMS encryption, CloudTrail must have permission to call the KMS key to encrypt each delivered log file. Specifically, CloudTrail needs kms:Decrypt and kms:GenerateDataKey actions in the key policy. If those permissions are missing, CloudTrail cannot write the encrypted log objects and stops delivering logs, producing a delivery failure shown on the trail configuration page.

Why this answer

When an S3 bucket uses SSE-KMS encryption, CloudTrail requires explicit permission to use the KMS key for encrypting log files. Even if the bucket policy allows CloudTrail to write objects, the trail will fail to deliver logs if the KMS key policy does not grant the `kms:GenerateDataKey` and `kms:Decrypt` actions to the CloudTrail service principal. This is the most likely cause because the bucket policy appears correct, but the KMS key permissions are missing.

Exam trap

The trap here is that candidates assume a correct bucket policy is sufficient, overlooking that SSE-KMS encryption introduces a separate permission layer via the KMS key policy, which must explicitly authorize the CloudTrail service principal.

How to eliminate wrong answers

Option A is wrong because CloudTrail logs management events by default and does not require data events to be enabled for log delivery to an S3 bucket; data events are an additional configuration for tracking object-level operations. Option C is wrong because CloudTrail can deliver logs to an S3 bucket in a different AWS account, provided the bucket policy grants cross-account access to the CloudTrail service principal. Option D is wrong because a Deny statement is not required for CloudTrail to write logs; the bucket policy only needs an Allow statement for the CloudTrail service principal, and a missing Deny statement would not prevent delivery.

172
MCQhard

A security engineer is investigating a potential breach. The engineer notices that an EC2 instance's security group allows inbound SSH (port 22) from 0.0.0.0/0. The instance is in a public subnet and has a public IP address. However, the engineer finds that SSH access is only possible from a specific IP address. What is the most likely explanation?

A.The network ACL allows inbound SSH from 0.0.0.0/0
B.The security group rule is being overridden by a more restrictive security group attached to the same instance
C.The security group rule is being evaluated but the instance's operating system firewall is blocking SSH
D.The network ACL denies inbound SSH from all IPs except the specific IP
AnswerD

Network ACLs are stateless and can explicitly deny traffic. If the NACL denies SSH from all IPs except the specific one, it would override the permissive security group rule, explaining why only that IP can connect.

Why this answer

Security groups in AWS are stateful and allow-only — they cannot deny traffic. If a security group permits SSH from 0.0.0.0/0 but access is restricted to one IP, the restriction must come from a stateless network ACL, which supports both allow and deny rules and is evaluated before the security group. A network ACL that denies SSH from all sources except the specific IP would produce exactly this observed behavior.

This is the only option that explains a restriction despite a permissive security group.

Exam trap

SCS-C02 often tests the misconception that security groups can deny traffic or that multiple security groups override each other, when in fact security groups are allow-only and additive — only NACLs can deny.

How to eliminate wrong answers

Option A is wrong because a network ACL allowing SSH from 0.0.0.0/0 would permit, not restrict, traffic — it cannot explain why only one IP can connect. Option B is wrong because security groups are additive and allow-only; a more restrictive security group attached to the same instance cannot override a permissive rule, it can only add more allows. Option C is wrong because while an OS-level firewall could block SSH, the question asks for the most likely explanation given the AWS-native controls described, and a network ACL deny is the canonical AWS mechanism that produces this pattern; an OS firewall is possible but less likely and not the best answer.

173
MCQmedium

A company has multiple AWS accounts and wants to centrally manage access using IAM Identity Center (AWS SSO). Which feature allows the company to define permissions once and reuse them across multiple accounts?

A.Application assignments
B.Identity providers
C.Permission sets
D.Account assignments
AnswerC

Permission sets are the correct IAM Identity Center construct because they define reusable collections of AWS permissions, similar to IAM roles, that can be assigned to users or groups across multiple AWS accounts. You attach managed policies, customer managed policies, inline policies, permissions boundaries, and session duration to a permission set, then assign it to accounts and principals. Using permission sets lets you enforce least privilege consistently across the entire AWS Organization and change permissions in one place, which is exactly what a multi-account user-access solution requires.

Why this answer

Permission sets in IAM Identity Center define a collection of administrator-defined policies that grant specific permissions to users or groups. Once created, a permission set can be assigned to any number of AWS accounts within the organization, enabling centralized permission management and reuse across multiple accounts without duplicating policy definitions.

Exam trap

The trap here is confusing the assignment action (account assignments) with the reusable permission definition (permission sets), leading candidates to select 'Account assignments' because they focus on the deployment step rather than the reusable policy object.

How to eliminate wrong answers

Option A is wrong because application assignments are used to grant users access to third-party SAML 2.0 or OIDC applications, not to define reusable permissions for AWS accounts. Option B is wrong because identity providers (IdPs) are external authentication sources (e.g., Active Directory, Okta) that federate identities into IAM Identity Center, but they do not define or reuse permissions across accounts. Option D is wrong because account assignments associate a user or group with a specific permission set in a particular AWS account; they are the mechanism for applying permissions, not the reusable permission definition itself.

174
MCQmedium

A security team needs to ensure that all API calls made in the AWS account are logged and the logs are stored in a central S3 bucket that is encrypted with a KMS key. Which combination of steps should the team take to achieve this?

A.Enable AWS Config and have it deliver configuration history to an encrypted S3 bucket.
B.Enable CloudWatch Logs and stream logs to an encrypted S3 bucket.
C.Enable VPC Flow Logs and publish to an encrypted S3 bucket.
D.Enable CloudTrail and configure it to deliver logs to an encrypted S3 bucket.
AnswerD

AWS CloudTrail is the service explicitly designed to log every API call made in your AWS account, recording details like caller identity, source IP, request parameters, and response data. You can configure a trail to deliver these JSON log files to an S3 bucket, and enabling encryption on that bucket (e.g., with SSE-KMS or SSE-S3) protects the logs at rest. This satisfies the requirement to ensure all API calls are logged and stored securely.

Why this answer

AWS CloudTrail records all API calls made in an AWS account, including management events and optionally data events, and can be configured to deliver log files to a central S3 bucket. By enabling CloudTrail with an S3 bucket destination and configuring the bucket with SSE-KMS encryption using a KMS key, the team meets both requirements: logging all API calls and storing logs encrypted with KMS. This is the standard AWS approach for API activity auditing.

Exam trap

The trap is confusing services that log activity (CloudTrail for API calls, Config for resource changes, VPC Flow Logs for network traffic) and selecting one that does not capture API calls.

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configuration changes and compliance, not API calls; it does not provide a complete API call audit trail. Option B is wrong because CloudWatch Logs captures log data from services and applications but does not natively log all AWS API calls; it is not the API auditing service. Option C is wrong because VPC Flow Logs capture IP traffic metadata to and from network interfaces, not API calls, and cannot log AWS API activity.

175
MCQmedium

A company uses AWS CloudTrail to log all API calls. The security team needs to be alerted when an IAM user creates a new access key. Which approach is most efficient?

A.Enable AWS Config managed rule to detect access key creation and trigger an SNS notification.
B.Create a CloudWatch Events rule that matches the CreateAccessKey event and targets an SNS topic.
C.Use CloudWatch Logs Insights to run a query every minute on CloudTrail logs and send results to SNS.
D.Configure CloudTrail to send logs to an S3 bucket and enable S3 event notifications to an SNS topic.
AnswerB

A CloudWatch Events rule pattern-matching the CreateAccessKey API call routes the event straight to an SNS topic, delivering near-real-time alerting. This event-driven approach is more efficient than polling or log-scanning because CloudTrail already streams management events to CloudWatch Events.

Why this answer

CloudWatch Events (now part of Amazon EventBridge) can directly match the CreateAccessKey API call from AWS CloudTrail in real time and trigger an SNS notification. This approach is the most efficient as it requires no polling, no additional infrastructure, and provides immediate alerting with minimal latency.

Exam trap

The trap here is that candidates may confuse AWS Config's resource compliance monitoring with real-time event detection, or assume that S3 event notifications are suitable for low-latency security alerts, when in fact EventBridge rules are purpose-built for this use case.

How to eliminate wrong answers

Option A is wrong because AWS Config managed rules evaluate resource configurations periodically or on configuration changes, but they are not designed to detect API events like CreateAccessKey in real time; they would require a custom rule and still introduce delay. Option C is wrong because running a CloudWatch Logs Insights query every minute is inefficient, introduces up to a minute of latency, and incurs unnecessary costs for repeated scanning of log data. Option D is wrong because CloudTrail logs delivered to S3 have a delivery latency of up to 15 minutes, and S3 event notifications are not designed for real-time security alerting on API calls; this approach adds significant delay and complexity.

176
MCQeasy

A security engineer needs to capture all DNS queries made by EC2 instances in a VPC and send them to a security analytics tool. Which AWS service should be used to capture this traffic?

A.AWS Network Firewall
B.VPC Flow Logs
C.AWS CloudTrail
D.Amazon GuardDuty
AnswerA

AWS Network Firewall is correct because it can perform stateful inspection of DNS traffic at the application layer and log each DNS request that traverses the firewall. To capture the queries, you configure a stateful rule group with the DNS protocol and enable logging to Amazon S3, CloudWatch Logs, or Kinesis Data Firehose. The resulting DNS logs include the queried domain name and the source interface, allowing the security engineer to retain a complete record of DNS activity.

Why this answer

AWS Network Firewall can be configured with stateful rule groups that inspect and log DNS traffic. By enabling DNS logging on the firewall, it captures all DNS queries and responses passing through the VPC, which can then be sent to a security analytics tool via Amazon S3, CloudWatch Logs, or Kinesis Data Firehose. This makes it the correct service for capturing DNS queries from EC2 instances.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (which show IP-level metadata) with the ability to capture DNS query content, not realizing that only a stateful inspection service like Network Firewall or Route 53 Resolver query logging can log the actual domain names being resolved.

How to eliminate wrong answers

Option B (VPC Flow Logs) is wrong because it captures IP traffic metadata (source/destination IP, ports, protocol, packet counts) but does not capture the content of DNS queries or responses, such as domain names being resolved. Option C (AWS CloudTrail) is wrong because it logs API calls made to AWS services (e.g., EC2 RunInstances, S3 PutObject) and does not capture network-level DNS traffic. Option D (Amazon GuardDuty) is wrong because it is a threat detection service that analyzes existing logs (like VPC Flow Logs, DNS logs from Route 53 Resolver) for anomalies; it does not capture or generate DNS query logs itself.

177
MCQhard

A company stores data in Amazon S3 and uses AWS KMS with Customer Master Keys (CMKs) for encryption. The security team wants to audit when the CMK is used to decrypt data. Which of the following will provide this information?

A.AWS Config
B.Amazon CloudWatch Logs
C.AWS CloudTrail
D.S3 server access logs
AnswerC

AWS CloudTrail is the authoritative source for KMS API activity because it records KMS calls as data events, including Decrypt, Encrypt, GenerateDataKey, and ReEncrypt. Each KMS data event in CloudTrail includes the key ID, whether decryption succeeded, the principal and ARN of the caller, the source IP, and the request timestamp. By enabling CloudTrail data events for a customer-managed KMS key, you get a complete audit trail that you can search in Athena or deliver to CloudWatch Logs for alerting.

Why this answer

AWS CloudTrail logs all KMS Decrypt API calls, which is exactly what is needed to audit CMK decryption. Option A (AWS Config) records configuration changes, not API calls. Option B (Amazon CloudWatch Logs) can store logs but does not generate the KMS decrypt logs itself; CloudTrail generates them.

Option D (S3 server access logs) record requests to S3 objects, not the KMS decryption calls that happen when accessing encrypted objects.

178
MCQhard

During a security incident, a security engineer needs to capture network traffic between an EC2 instance and an attacker's IP address for forensic analysis. The engineer has already identified the attacker's IP from CloudTrail logs. Which action captures the traffic without affecting the instance?

A.Update the network ACL to log all traffic to and from the attacker's IP.
B.Enable VPC Flow Logs on the subnet and query logs for the attacker's IP.
C.SSH into the instance and run tcpdump with a filter for the attacker's IP.
D.Create a VPC Traffic Mirroring session targeting the instance's ENI and mirror the traffic to a Network Load Balancer for capture.
AnswerD

VPC Traffic Mirroring copies traffic from the instance's ENI to a specified target—such as a Network Load Balancer configured with a capture appliance—without installing agents or SSHing into the instance. Because the mirroring runs in the VPC data path (at the hypervisor), it is transparent to the instance and does not alert the attacker or affect system performance. This makes it the recommended approach for real-time, full-packet capture during incident response while preserving the integrity of the evidence.

Why this answer

VPC Traffic Mirroring captures all network traffic at the Elastic Network Interface (ENI) level without any performance impact or configuration change on the EC2 instance itself. It copies the traffic to a Network Load Balancer (NLB) or another target for capture and analysis, making it ideal for forensic investigation without disrupting the running instance.

Exam trap

The trap here is that candidates confuse VPC Flow Logs (which only provide metadata) with full packet capture capabilities, or they assume that SSHing into the instance is acceptable despite the risk of altering the instance state during an active incident.

How to eliminate wrong answers

Option A is wrong because network ACLs do not log traffic; they only allow or deny traffic based on rules, and they operate at the subnet level, not per-instance. Option B is wrong because VPC Flow Logs capture metadata (source/destination IP, ports, protocol, packets) but not the actual packet payload, so they cannot provide the full network traffic needed for deep forensic analysis. Option C is wrong because SSHing into the instance and running tcpdump would alter the instance's state (e.g., by installing or running a process) and could interfere with the incident or be blocked if the instance is compromised.

179
Multi-Selecthard

Which THREE of the following are required to use client-side encryption with Amazon S3 using AWS KMS? (Choose three.)

Select 3 answers
A.An S3 bucket policy that forces encryption.
B.The encrypted data key is stored as metadata with the S3 object.
C.A KMS key policy that allows the S3 service to decrypt.
D.Permissions for the IAM user or role to call kms:GenerateDataKey.
E.The AWS SDK Encryption Client library.
AnswersB, D, E

In the client-side encryption envelope scheme, the SDK creates a one-time data key, encrypts the object with it, then wraps that data key with a KMS customer master key. The resulting encrypted data key is stored in the S3 object's metadata, for example the x-amz-meta-x-amz-key-v2 attributes, so a decrypter can later retrieve it and unwrap it to get the plaintext data key. Without this metadata, the ciphertext cannot be decrypted, so this storage step is a required part of client-side encryption.

Why this answer

Option B is correct because with client-side encryption using the AWS SDK Encryption Client, the SDK generates a data key, encrypts the object locally, and stores the encrypted (wrapped) data key as metadata alongside the S3 object so it can be retrieved and unwrapped later. Option D is correct because the caller must have IAM permissions to invoke kms:GenerateDataKey (and typically kms:Decrypt) so the SDK can obtain a plaintext data key and a wrapped copy from AWS KMS. Option E is correct because client-side encryption is performed by the AWS SDK Encryption Client library (e.g., AmazonS3EncryptionClient), which handles key generation, local encryption, and metadata storage; S3 itself never sees plaintext.

Option A is not required because a bucket policy forcing encryption governs server-side encryption at the S3 service level and is irrelevant to client-side encryption, which happens before data reaches S3. Option C is not required because the KMS key policy must grant the calling IAM principal (user or role) access to the key, not the S3 service, since S3 is not involved in the KMS operations for client-side encryption.

Exam trap

The trap is confusing client-side encryption with server-side encryption (SSE-KMS) — options about bucket policies and S3 service decrypt permissions belong to SSE, not client-side encryption.

180
Multi-Selecteasy

A company wants to detect and respond to potential security threats in near real-time. Which TWO services should the company use together to achieve this? (Choose TWO.)

Select 2 answers
A.AWS Config
B.Amazon Inspector
C.AWS CloudTrail
D.AWS Security Hub
E.Amazon GuardDuty
AnswersD, E

AWS Security Hub is the correct choice because it aggregates and correlates security findings from multiple sources, including GuardDuty, Inspector, and Config, into a single, prioritized view. It applies continuous security best-practice and compliance checks, and its integration with Amazon EventBridge allows you to automate responses by triggering AWS Lambda, Systems Manager, or Step Functions workflows. This centralized detect-and-respond architecture is exactly what the company needs for operational security monitoring.

Why this answer

AWS Security Hub (D) aggregates security findings from multiple AWS services, including Amazon GuardDuty, and provides a comprehensive view of security alerts and compliance status. Amazon GuardDuty (E) is a threat detection service that continuously monitors for malicious activity and unauthorized behavior using machine learning and integrated threat intelligence. Together, they enable near real-time detection and response by centralizing findings from GuardDuty in Security Hub, which can trigger automated remediation workflows via Amazon EventBridge.

Exam trap

The trap here is that candidates often confuse AWS Config or CloudTrail as threat detection services, but they are primarily configuration auditing and API logging tools, respectively, and lack the real-time threat analysis capabilities of GuardDuty and Security Hub.

181
MCQmedium

A security engineer is troubleshooting connectivity issues between two EC2 instances in the same VPC but different subnets. Both instances have security groups that allow all traffic from each other's security group. However, traffic is still blocked. What is the most likely cause?

A.The instances are in different VPCs.
B.The network ACL for one or both subnets is blocking the traffic.
C.The route tables do not have a route between the subnets.
D.VPC Flow Logs are not enabled.
AnswerB

Network ACLs are stateless filters applied at the subnet boundary and are evaluated before Security Groups. A custom network ACL with an explicit deny rule, or with an inbound allow rule that lacks a matching outbound ephemeral-port allow rule, will drop traffic even when Security Groups permit it. Since stateful Security Groups do not validate the complete bidirectional flow, a misconfigured network ACL remains a common cause of unexplained communication failures between instances.

Why this answer

The most likely cause is that the network ACL (NACL) for one or both subnets is blocking the traffic. Security groups are stateful and allow traffic based on rules, but NACLs are stateless and require explicit inbound and outbound rules for traffic to flow. Even if security groups permit all traffic between the instances, a NACL denying the traffic (e.g., by having a default deny rule or missing ephemeral port ranges) will block it.

Since the instances are in different subnets, the NACL associated with each subnet must allow the traffic in both directions.

Exam trap

The trap here is that candidates often assume security groups alone control all traffic and overlook the stateless nature of network ACLs, especially when instances are in different subnets where NACLs apply at the subnet boundary.

How to eliminate wrong answers

Option A is wrong because the question states both instances are in the same VPC, so being in different VPCs is not applicable. Option C is wrong because route tables in a VPC automatically have a local route that enables communication between subnets within the same VPC, so no additional route is needed. Option D is wrong because VPC Flow Logs are a monitoring feature that logs traffic metadata but do not affect traffic flow; they cannot block or allow traffic.

182
MCQmedium

A company wants to protect sensitive data stored in Amazon S3 by enforcing encryption in transit. Which policy should be used to deny requests that do not use HTTPS?

A.{"Effect": "Deny", "Principal": "*", "Action": "s3:*", "Resource": "*", "Condition": {"Bool": {"aws:SecureTransport": "true"}}}
B.{"Effect": "Deny", "Principal": "*", "Action": "s3:*", "Resource": "*", "Condition": {"Bool": {"aws:SecureTransport": "false"}}}
C.{"Effect": "Deny", "Principal": "*", "Action": "s3:*", "Resource": "*", "Condition": {"Null": {"s3:x-amz-server-side-encryption": "true"}}}
D.{"Effect": "Deny", "Principal": "*", "Action": "s3:*", "Resource": "*"}
AnswerB

This policy correctly denies S3 actions when aws:SecureTransport is false, meaning it blocks all HTTP requests that do not use TLS. The aws:SecureTransport key is true only for requests made over HTTPS, so this conditional deny rejects any insecure request while allowing encrypted traffic. This is the AWS-recommended bucket policy pattern for enforcing encryption in transit and satisfies the requirement.

Why this answer

It uses the aws:SecureTransport condition set to 'false' to deny requests that are not using HTTPS. Option A is incorrect because it denies requests when SecureTransport is 'true', meaning it would block legitimate HTTPS traffic. Option C is incorrect because it checks for the presence of the s3:x-amz-server-side-encryption header, which relates to encryption at rest, not encryption in transit.

Option D is incorrect because it denies all requests unconditionally, which would block all traffic, including HTTPS.

183
MCQmedium

A company uses AWS Organizations with a service control policy (SCP) that denies all actions except those explicitly listed. A developer in a member account needs to launch an EC2 instance with an IAM role that grants access to an S3 bucket. The SCP currently allows ec2:RunInstances and s3:GetObject but denies iam:PassRole. What is the MOST likely effect?

A.The developer can launch the instance, but the instance will not be able to assume the IAM role because iam:PassRole is denied.
B.The developer can launch the instance, and the instance will use the role's permissions because the SCP only applies to the developer, not the instance.
C.The developer can launch the instance if they use an existing instance profile instead of passing the role directly.
D.The developer cannot launch the instance because the SCP denies iam:PassRole, which is required to associate the role with the instance.
AnswerD

To launch an EC2 instance with an IAM role, the caller must have iam:PassRole permission for that role. An SCP that denies iam:PassRole blocks this action, so the RunInstances call fails. Even though ec2:RunInstances is allowed, the missing PassRole permission prevents the role association, making the launch unsuccessful. This is the intended security control.

Why this answer

iam:PassRole is mandatory for a principal to associate an IAM role with an EC2 instance. When an SCP denies iam:PassRole, the RunInstances action fails even if ec2:RunInstances is allowed. This prevents unauthorized role escalation.

The other options incorrectly assume the launch can succeed or misunderstand the scope of SCPs.

Exam trap

The trap here is thinking that ec2:RunInstances alone is sufficient to launch an instance with a role, forgetting that iam:PassRole is a separate required permission.

184
MCQeasy

An IAM user reports that they are unable to launch an EC2 instance in us-east-1. The IAM policy attached to the user allows ec2:RunInstances but with a condition that the instance type must be t2.micro. What could be the reason for the failure?

A.The user is trying to launch an instance type other than t2.micro.
B.The user has not attached a security group to the instance.
C.The IAM policy does not include ec2:RunInstances for us-east-1.
D.The user's account has reached the EC2 instance limit.
AnswerA

The IAM policy grants ec2:RunInstances but includes a Condition element that restricts the ec2:InstanceType to t2.micro. When the user attempts to launch any other instance type, the condition fails, causing the action to be denied even though the principal has an Allow for the action. This is an implicit deny resulting from the condition not being satisfied, not a missing action or a separate limitation. Thus, the exact reason the launch is blocked is the requested instance type falls outside the allowed value.

Why this answer

The IAM policy condition restricts ec2:RunInstances to t2.micro instances only. If the user attempts to launch any other instance type, the condition evaluates to false and the request is denied. The most likely reason for the failure is that the user is requesting a non-t2.micro instance type, which violates the policy condition.

Exam trap

SCS-C02 often tests whether candidates recognize that IAM condition keys cause implicit denies when the request does not match, rather than assuming the policy is missing the action or region.

How to eliminate wrong answers

Option B is wrong because a missing security group would cause a different error (or default to the default security group) and is not related to the IAM condition on instance type. Option C is wrong because the policy already allows ec2:RunInstances and the condition is on instance type, not region — the scenario states the user is launching in us-east-1. Option D is wrong because an EC2 instance limit would produce a different error message and is unrelated to the IAM condition on instance type.

185
MCQmedium

A company is using AWS Config to track resource changes. They want to receive notifications when a security group is modified to allow inbound traffic from 0.0.0.0/0. What is the most efficient way to achieve this?

A.Use IAM Access Analyzer to detect publicly accessible security groups.
B.Enable Amazon GuardDuty and use its findings for security group changes.
C.Create a custom AWS Config rule with an AWS Lambda function that checks for public inbound traffic.
D.Create a CloudTrail trail and filter on AuthorizeSecurityGroupIngress events.
AnswerC

A custom AWS Config rule powered by a Lambda function can evaluate security groups on every configuration change. The Lambda function uses the AWS Config API to receive the resource's details, parses the IpPermissions, and checks for any rule with CidrIp 0.0.0.0/0 or ::/0. If public inbound traffic is found, the function returns NON_COMPLIANT, enabling continuous, automated compliance monitoring and remediation. This is exactly the kind of custom, resource-specific logic that Config supports.

Why this answer

AWS Config custom rules allow you to define a Lambda function that evaluates security group configurations against your compliance requirements. By writing a rule that checks for inbound rules with '0.0.0.0/0' on ports like SSH (22) or RDP (3389), you can trigger notifications via Amazon SNS when non-compliant changes occur. This is the most efficient approach as it directly monitors the desired condition without relying on external services or manual log analysis.

Exam trap

The trap here is that candidates often confuse CloudTrail's ability to log API calls (Option D) with the ability to evaluate the resulting resource state; CloudTrail only records the action, not the rule's content, so you would need additional logic to determine if the inbound rule actually allows 0.0.0.0/0.

How to eliminate wrong answers

Option A is wrong because IAM Access Analyzer analyzes resource policies for cross-account access, not security group rules; it does not detect inbound traffic from 0.0.0.0/0. Option B is wrong because Amazon GuardDuty focuses on threat detection (e.g., malicious activity, compromised instances) and does not provide real-time notifications for security group configuration changes. Option D is wrong because CloudTrail trails capture API calls like AuthorizeSecurityGroupIngress, but filtering these events requires additional processing (e.g., Athena queries or custom scripts) and does not directly evaluate the actual inbound rule for 0.0.0.0/0; it only logs the API call, not the rule's content.

186
MCQhard

Refer to the exhibit. A security engineer is analyzing a CloudTrail log entry for an EC2 RunInstances call. The engineer needs to determine if the instance launch was authorized by an IAM policy. Which field should the engineer check to identify the IAM policy that was used to authorize the action?

A.The 'vpcEndpointId' field to see if the call came through a VPC endpoint.
B.The 'sourceIP' field to identify the IP address.
C.The 'eventType' field to determine the type of event.
D.The 'userIdentity' field to identify the IAM user or role that made the call.
AnswerD

The userIdentity block in a CloudTrail record is the authoritative field for identifying the principal, containing the ARN, type (IAMUser, AssumedRole, Root, etc.), and session context for the call. By inspecting this block, the security engineer can determine the exact IAM user or role and then review the identity-based and attached policies that governed the request. Without userIdentity, there is no reliable way to map an API call to the IAM entity whose permissions should be audited.

Why this answer

The 'userIdentity' field in a CloudTrail log entry contains details about the IAM user or role that made the API call, including the ARN and the access key ID. To identify the specific IAM policy that authorized the action, the security engineer must first know the identity (user/role) from the 'userIdentity' field, then cross-reference that identity with the IAM policies attached to it. The policy itself is not directly listed in the log entry, but the identity is the key to tracing authorization.

Exam trap

The trap here is that candidates may think the 'eventType' or 'sourceIP' fields directly reveal authorization details, but CloudTrail does not log the specific policy that was evaluated; instead, the 'userIdentity' field is the critical link to identify the IAM entity whose policies were applied.

How to eliminate wrong answers

Option A is wrong because the 'vpcEndpointId' field indicates whether the call originated from a VPC endpoint, which is relevant for network-level logging and VPC endpoint policies, not for identifying the IAM policy that authorized the RunInstances action. Option B is wrong because the 'sourceIP' field shows the IP address from which the call was made, which is used for network-level analysis or source IP conditions in policies, but does not directly identify the IAM policy that authorized the action. Option C is wrong because the 'eventType' field indicates whether the event is an API call (AwsApiCall), a console login, or a service event, but it provides no information about the specific IAM policy used for authorization.

187
MCQhard

A company uses AWS SSO to manage access to multiple accounts. An employee leaves the company. What is the most efficient way to revoke all AWS access for that employee?

A.Deactivate the user in the connected identity provider (e.g., Active Directory).
B.Delete the corresponding IAM user in every AWS account.
C.Remove the user from all groups in AWS SSO.
D.Delete the IAM role that the user assumes in each account.
AnswerA

Deactivating the user in the connected identity provider is the correct action because AWS SSO relies on the IdP as the authoritative identity source. Once the user is disabled in Active Directory (or another connected IdP), they can no longer authenticate to the AWS access portal, so no new SSO sessions or temporary AWS credentials can be issued. Any active role sessions inherited from a prior sign-in remain only until their configured session duration expires, but this operation is the only option that cleanly terminates access at the identity's source.

Why this answer

The most efficient way to revoke all AWS access for a former employee is to deactivate the user in the connected identity provider (e.g., Active Directory). AWS SSO relies on the external IdP for authentication; once the user is deactivated there, they cannot authenticate to AWS SSO, and all active SSO sessions are invalidated. This single action immediately blocks access across all accounts and applications federated through AWS SSO, without needing to touch individual IAM roles or accounts.

Exam trap

The trap here is that candidates may think AWS SSO groups or IAM roles are the primary control point, but the exam tests the understanding that the identity provider is the authoritative source for authentication, and deactivating there is the single, most efficient revocation point.

How to eliminate wrong answers

Option B is wrong because AWS SSO does not create IAM users in each account; it uses IAM roles for federated access, so there are no IAM users to delete. Option C is wrong because removing the user from all groups in AWS SSO would revoke permissions, but it requires multiple steps and does not invalidate existing sessions immediately; deactivating the user in the IdP is more efficient and ensures no new authentication is possible. Option D is wrong because deleting the IAM role that the user assumes in each account would break access for other users who might need to assume that same role, and it is an inefficient, account-by-account approach compared to a single IdP deactivation.

188
MCQeasy

A security engineer is reviewing AWS CloudTrail logs and notices repeated `CreateTrail` API calls from an IAM user that is not authorized to create trails. What is the MOST likely cause of these log entries?

A.The IAM user attempted to create a trail but was denied due to lack of permissions.
B.AWS GuardDuty is generating simulated events.
C.S3 server access logs are enabled for the trail's S3 bucket.
D.CloudTrail is configured to log only data events.
AnswerA

CloudTrail is designed to record every API request made on an account, including actions that fail authorization. When the IAM user attempts CreateTrail, CloudTrail writes a management event with the userIdentity of that user, even if the call is denied with AccessDenied and an errorCode and errorMessage. The presence of this attempt in the logs is therefore normal, and it does not indicate that a trail was successfully created.

Why this answer

The repeated `CreateTrail` API calls in CloudTrail logs indicate that an IAM user is attempting to create a trail. Since the user lacks the required `cloudtrail:CreateTrail` permission, the API call is recorded as an attempted action that was denied by AWS Identity and Access Management (IAM) policy evaluation. CloudTrail logs all API calls, including those that fail due to insufficient permissions, which is why these entries appear in the logs.

Exam trap

The trap here is that candidates may think CloudTrail only logs successful API calls, but in reality, it logs all API calls, including those that are denied, which is why the repeated `CreateTrail` entries appear even though the user is not authorized.

How to eliminate wrong answers

Option B is wrong because AWS GuardDuty generates security findings and simulated events related to threats, not CloudTrail `CreateTrail` API calls; GuardDuty does not produce CloudTrail log entries. Option C is wrong because S3 server access logs record requests made to an S3 bucket, such as GET or PUT operations, not CloudTrail API calls like `CreateTrail`. Option D is wrong because CloudTrail's data events configuration controls which data plane operations are logged (e.g., S3 object-level events), but it does not affect the logging of management events like `CreateTrail`; the API call would still be logged regardless of data event settings.

189
Multi-Selectmedium

A company uses AWS CloudFormation to deploy infrastructure. The security team wants to ensure that all S3 buckets created by CloudFormation have encryption enabled by default. Which TWO approaches can achieve this?

Select 2 answers
A.Create an AWS Config rule that checks for S3 bucket encryption and auto-remediates
B.Enable S3 Block Public Access at the account level
C.Attach a service control policy (SCP) to the root OU that denies S3 bucket creation without encryption
D.Attach an IAM role to the CloudFormation service that grants permissions to encrypt buckets
E.Use a CloudFormation stack policy to deny creation of S3 buckets without encryption
AnswersA, C

The AWS Config managed rule s3-bucket-server-side-encryption-enabled evaluates every S3 bucket against your encryption policy and marks those without default encryption as non-compliant. By attaching an automatic remediation action, Config invokes an SSM Automation document that runs PutBucketEncryption on the non-compliant bucket, bringing it into compliance without manual intervention. This detects buckets that CloudFormation created without encryption and repairs them, making it an effective retrospective and continuous control.

Why this answer

An AWS Config rule can check that S3 buckets have encryption enabled and automatically remediate any non-compliant buckets. Option C is correct because a service control policy (SCP) can be attached to the root OU to deny the creation of S3 buckets without encryption, using a condition on the s3:x-amz-server-side-encryption header. Option B is incorrect because S3 Block Public Access does not enforce encryption.

Option D is incorrect because attaching an IAM role to CloudFormation only grants permissions but does not enforce encryption. Option E is incorrect because CloudFormation stack policies only protect existing resources from updates and cannot enforce conditions on bucket creation.

190
Multi-Selectmedium

Which TWO actions can be used to restrict access to an S3 bucket to only requests that originate from a specific VPC?

Select 2 answers
A.Use a security group to allow inbound traffic from the VPC to S3.
B.Use an IAM policy with a condition key aws:SourceVpce to restrict access to the VPC endpoint.
C.Configure a VPC endpoint for S3 and attach a bucket policy that allows access only from that endpoint.
D.Use a network ACL to allow traffic from the VPC to S3.
E.Use an IAM policy with a condition key aws:SourceIp to restrict access to the VPC CIDR.
AnswersB, C

When a request reaches S3 through a VPC endpoint, the request context includes the endpoint ID, so an IAM policy can use the aws:SourceVpce condition to require that the request came from that specific endpoint. This effectively blocks access from public internet or other VPCs even if the IAM principal is valid. It is a common pattern for enforcing network-layer isolation in addition to identity-based permissions.

Why this answer

The `aws:SourceVpce` condition key in an IAM policy allows you to restrict access to an S3 bucket to requests that originate from a specific VPC endpoint (VPC Endpoint ID). This ensures that only traffic coming through that VPC endpoint can access the bucket, effectively limiting access to the VPC. Option C is also correct because you can configure a VPC endpoint for S3 and attach a bucket policy that explicitly allows access only from that endpoint using the `aws:SourceVpce` condition, achieving the same restriction.

Exam trap

The trap here is that candidates often confuse IAM policies with bucket policies or think that security groups or network ACLs can directly control access to S3, but S3 is a managed service and does not process security group or NACL rules; only bucket policies and IAM policies with VPC endpoint conditions can enforce such restrictions.

191
MCQhard

A company stores sensitive customer data in Amazon S3. The security team has enabled default encryption with SSE-S3 on the bucket. The compliance team requires that all access to the bucket be logged and that any unauthorized access attempts be detected in real time. The company has AWS CloudTrail enabled. Which additional steps should the security team take to meet the compliance requirements?

A.Enable S3 server access logs and enable Amazon GuardDuty with S3 protection
B.Enable AWS Config rules to detect unauthorized access
C.Enable CloudTrail data events for the S3 bucket and use Amazon Detective
D.Enable VPC Flow Logs and use Amazon Athena to analyze logs
AnswerA

S3 server access logs capture every request made to the bucket, including requester IP, IAM role/user, action, and HTTP status, providing a detailed audit trail for forensic analysis. Amazon GuardDuty's S3 protection continuously monitors object-level operations and uses threat intelligence and anomaly detection to flag suspicious patterns, such as mass downloads or access from unusual geographies, in near-real time. Together they deliver both historical evidence and proactive alerting, making this the only option that addresses both detection and investigation of unauthorized access.

Why this answer

Enabling S3 server access logs captures all requests to the bucket, satisfying the logging requirement, and Amazon GuardDuty with S3 protection can detect suspicious activity in real time, meeting the requirement for real-time detection of unauthorized access. Option B is incorrect because AWS Config rules monitor configuration changes, not real-time threat detection. Option C is incorrect because CloudTrail data events can log S3 operations, but Amazon Detective is for post-incident analysis, not real-time detection.

Option D is incorrect because VPC Flow Logs log network traffic, not S3 access, and Amazon Athena is a query service, not a real-time detection tool.

192
Multi-Selecthard

Which TWO of the following are valid use cases for IAM permissions boundaries? (Choose TWO.)

Select 2 answers
A.To allow cross-account access to an S3 bucket
B.To prevent an IAM user from escalating privileges
C.To allow developers to create roles with limited permissions
D.To delegate permission management to non-administrators
E.To restrict access to an S3 bucket based on IP address
AnswersB, C

Permissions boundaries are a valid use case to prevent IAM users from escalating privileges because they set a hard ceiling on the maximum permissions a principal can receive. Even if a user is allowed to attach IAM policies to their own role, the effective permissions are the intersection of the attached policy and the boundary, so they cannot grant themselves additional privileges beyond the boundary. This mitigates the risk of an IAM user creating an administrative policy or modifying their own permissions to gain elevated access.

Why this answer

IAM permissions boundaries are a feature that allows you to set the maximum permissions that an identity-based policy can grant to an IAM entity. By attaching a permissions boundary to a user or role, you can prevent that entity from creating or modifying IAM resources (such as roles or policies) to escalate their privileges, even if their attached policies would otherwise allow it. This acts as a guardrail to enforce a hard limit on what actions the entity can perform, directly addressing privilege escalation risks.

Exam trap

The trap here is that candidates often confuse permissions boundaries with service control policies (SCPs) or resource-based policies, leading them to select options like cross-account access or IP-based restrictions, which are handled by entirely different AWS mechanisms.

193
MCQhard

A company uses AWS CloudHSM to generate and store encryption keys for a custom database. The security team needs to back up the keys to another AWS Region for disaster recovery. What is the most secure and efficient way to achieve this?

A.Create a backup of the source CloudHSM cluster and copy the backup to the destination Region.
B.Export the keys from the source CloudHSM cluster and import them into a destination cluster in the other Region.
C.Enable cross-Region replication on the CloudHSM cluster.
D.Use the key_mgmt_util command-line tool to copy the keys to an on-premises HSM, then upload to the destination Region.
AnswerA

AWS CloudHSM supports taking point-in-time backups of an entire cluster, and those backups can be copied to other regions using the CopyBackupToRegion API or the console. After copying, you restore the backup in the destination region to create a new cluster that contains all original keys, HSMs, and settings. This preserves FIPS 140-2 validated protection because key material never leaves the HSM boundary, and it is the officially supported method for cross-region disaster recovery.

Why this answer

AWS CloudHSM allows you to create a backup of a cluster and copy that backup to another region using the AWS CLI or console. This is the most secure method as it avoids exporting keys in plaintext. Option B is incorrect because CloudHSM does not support exporting keys directly; you must use backups.

Option C is incorrect because CloudHSM does not have a cross-region replication feature for clusters. Option D is incorrect because copying keys via an on-premises HSM is unnecessary and less secure than using CloudHSM's built-in backup copy functionality.

194
MCQeasy

An administrator needs to allow a Lambda function to write logs to CloudWatch Logs. What is the BEST way to grant these permissions?

A.Store AWS credentials in the Lambda function code.
B.Attach a resource-based policy to the Lambda function.
C.Create an IAM role with the necessary CloudWatch Logs permissions and assign it as the Lambda function's execution role.
D.Attach the AdministratorAccess managed policy to the Lambda function's execution role.
AnswerC

Create an IAM execution role granting the Lambda function the minimal CloudWatch Logs permissions required (e.g., logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents) and attach that role to the function via the function's configuration. This identity-based policy defines what the function can do as its authorized identity, allowing it to write logs securely. Following least privilege here is correct because the role grants only the specific log-writing actions, not broader access.

Why this answer

Lambda functions assume an IAM execution role at runtime, and all AWS API calls the function makes (including CloudWatch Logs PutLogEvents) are authorized against that role's identity-based policies. Creating a role with only the required CloudWatch Logs permissions and assigning it as the execution role follows least privilege and is the standard, supported mechanism. This avoids embedding long-lived credentials and grants exactly the access needed.

Exam trap

SCS-C02 often tests whether candidates confuse resource-based policies (which grant inbound access to a resource) with execution roles (which grant outbound permissions to the function), leading them to pick option B.

How to eliminate wrong answers

Option A is wrong because hardcoding AWS credentials in Lambda code exposes long-lived secrets in source control and environment variables, violates least privilege, and is unnecessary since Lambda can assume an execution role automatically. Option B is wrong because resource-based policies are attached to resources (like S3 buckets, SNS topics, or Lambda itself for invocation) to grant other principals access, not to grant the Lambda function outbound permissions to CloudWatch Logs. Option D is wrong because AdministratorAccess grants full access to all AWS services, violating least privilege and creating a severe blast-radius risk when only logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents are required.

195
MCQmedium

Refer to the exhibit. A security engineer runs the CLI command and receives the output shown. The engineer expects to see flow logs for a specific subnet, but the output shows the resource ID as a VPC. What is the most likely reason?

A.The flow log is not active; it shows ACTIVE, so that's not the issue.
B.The flow log is configured to deliver to CloudWatch, but the log group name is incorrect.
C.The IAM role does not have permissions to deliver logs for subnets.
D.The flow log was created at the VPC level, not at the subnet level.
AnswerD

The resource ID in the flow log output is prefixed with "vpc-", which indicates the flow log was created at the VPC level rather than at the subnet level. As a result, the flow log captures all traffic in the VPC, and the query is not filtering for the specific subnet due to the resource scope. To see subnet-specific flow logs, you must create a separate flow log with the subnet ID as the resource ID.

Why this answer

The output shows the resource ID as a VPC (vpc-xxxx), but the security engineer expected to see flow logs for a specific subnet. This indicates that the flow log was created at the VPC level, not at the subnet level. In AWS, VPC Flow Logs can be created at the VPC, subnet, or network interface level, and the resource ID in the flow log output reflects the level at which the log was configured.

Since the engineer expected subnet-level logs, the most likely reason is that the flow log was created for the entire VPC instead of the specific subnet.

Exam trap

The trap here is that candidates may assume the flow log is misconfigured due to permissions or delivery settings, when the real issue is the scope at which the flow log was created—a common confusion between VPC-level and subnet-level flow logs.

How to eliminate wrong answers

Option A is wrong because the flow log is indeed active (ACTIVE status), so inactivity is not the issue. Option B is wrong because the log group name being incorrect would not cause the resource ID to show a VPC instead of a subnet; it would affect log delivery but not the resource identifier in the output. Option C is wrong because IAM role permissions for delivering logs to CloudWatch are not related to the level (VPC vs. subnet) at which the flow log is created; permissions issues would prevent log delivery entirely, not change the resource ID shown.

196
MCQhard

A security engineer notices that an Amazon EC2 instance has a security group that allows inbound SSH (port 22) from 0.0.0.0/0. The instance is a bastion host. What is a more secure alternative to this configuration?

A.Change the SSH port to a non-standard port to avoid automated attacks.
B.Restrict the inbound SSH rule to a single IP address from the corporate network.
C.Replace the security group rule with a network ACL that allows SSH from 0.0.0.0/0.
D.Remove the inbound SSH rule and use AWS Systems Manager Session Manager to access the instance.
AnswerD

Removing the inbound SSH rule and using AWS Systems Manager Session Manager closes the port 22 listener entirely, so the instance is not reachable over SSH from the network. Session Manager authenticates the user through IAM, authorizes actions with IAM policies, and sends the interactive shell session over an encrypted channel initiated by the SSM Agent. Sessions can be audited and recorded via S3 or CloudWatch Logs, and you can use a VPC endpoint so traffic never traverses an open internet-facing port. This avoids the need for SSH key management and eliminates brute-force exposure.

Why this answer

AWS Systems Manager Session Manager provides secure, auditable, and keyless shell access to EC2 instances without opening any inbound ports. It uses the AWS Systems Manager agent to initiate an outbound connection to the AWS SSM endpoint over HTTPS (port 443), eliminating the need for a bastion host or any inbound SSH rule. This approach also integrates with AWS Identity and Access Management (IAM) for fine-grained access control and AWS CloudTrail for full session logging.

Exam trap

The trap here is that candidates often think restricting SSH to a single IP (Option B) is the most secure approach, but the exam tests the concept of eliminating inbound access entirely through agent-based outbound-only solutions like Session Manager, which is a key principle of the AWS Well-Architected Framework's security pillar.

How to eliminate wrong answers

Option A is wrong because changing the SSH port to a non-standard port only obscures the service from automated scans but does not prevent targeted attacks or port scanning; it violates security by obscurity principles and is not a secure alternative. Option B is wrong because restricting the inbound SSH rule to a single corporate IP address still leaves the bastion host exposed to SSH vulnerabilities, requires maintaining a bastion host, and does not eliminate the attack surface of an open SSH port. Option C is wrong because replacing the security group rule with a network ACL that allows SSH from 0.0.0.0/0 is actually less secure—network ACLs are stateless and do not provide the same stateful filtering as security groups, and they still expose the instance to inbound SSH traffic from the entire internet.

197
Multi-Selectmedium

A security engineer is building an incident response playbook for compromised IAM credentials. The engineer wants to automatically revoke access and preserve evidence when an access key is suspected of being compromised. Which TWO actions should be included in the playbook? (Choose two.)

Select 2 answers
A.Rotate the access key by creating a new key and attaching it to the same IAM user, then delete the old key.
B.Deactivate the access key and attach an explicit deny policy to the IAM user to prevent any further API calls.
C.Capture the current IAM user policy, access key metadata, and recent CloudTrail events for the key before making changes.
D.Delete the IAM user and all associated access keys to ensure the compromised identity cannot be used again.
E.Disable AWS CloudTrail logging to prevent the attacker from observing the security team's remediation actions.
AnswersB, C

Deactivating the access key immediately stops its use, and attaching an explicit deny policy blocks the user from making further calls with any credentials or sessions. This revokes access quickly while preserving the key's metadata and the user's configuration for later analysis, which supports evidence preservation.

Why this answer

A credential compromise playbook must both revoke access and preserve evidence. Deactivating the key and attaching an explicit deny policy stops further API calls immediately while keeping the identity intact for analysis. Capturing the user's policies, key metadata, and recent CloudTrail events before changes preserves the activity history needed to determine impact and support notifications.

Deleting the user, rotating the key, or disabling logging would destroy evidence or fail to revoke access effectively.

Exam trap

The trap here is choosing to delete the compromised IAM user, which feels decisive but destroys the metadata and audit trail needed for the investigation.

198
MCQmedium

A company stores sensitive customer data in Amazon S3. To comply with data protection regulations, they need to automatically prevent any new objects from being made publicly accessible. Which S3 feature should they configure?

A.Enable S3 Block Public Access at the account level.
B.Configure a bucket policy that denies s3:PutObject with a condition for public access.
C.Use S3 default encryption with SSE-S3.
D.Enable S3 Object Lock in governance mode.
AnswerA

Account-level S3 Block Public Access is a set of controls (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, and RestrictPublicBuckets) that act as a centralized guardrail across every bucket in the AWS account. When enabled, it overrides any bucket policy, owner policy, or object ACL that would grant public access, and it blocks both existing public grants and future attempts to make objects or buckets public. This is the most comprehensive control because it applies even if a developer mistakenly attaches a permissive bucket policy or uploads an object with a public-read ACL.

Why this answer

S3 Block Public Access at the account level applies a blanket deny on any policy or ACL that would make an object or bucket public, and it overrides bucket policies and ACLs. Enabling it at the account level ensures all current and future buckets in the account are protected from accidental public exposure. This is the AWS-recommended preventive control for data protection compliance.

Exam trap

SCS-C02 often tests the misconception that encryption (SSE-S3) or Object Lock provides access control — candidates confuse confidentiality-at-rest with public-access prevention, when only Block Public Access directly blocks public exposure.

How to eliminate wrong answers

Option B is wrong because a bucket policy denying s3:PutObject with a public-access condition is difficult to express correctly — S3 PutObject requests do not carry a reliable 'public' flag, and ACLs/policies set after upload could still expose objects; it is not a preventive account-wide control. Option C is wrong because SSE-S3 provides encryption at rest only; it has no relationship to public accessibility and does not prevent objects from being made public. Option D is wrong because S3 Object Lock (governance mode) prevents deletion or overwrite of object versions for a retention period — it addresses immutability/WORM compliance, not public access prevention.

199
MCQmedium

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The application uses an Amazon RDS for MySQL database. The security team requires that all data in transit between the EC2 instances and the database be encrypted. The database is in a private subnet. The EC2 instances are in a public subnet. The security team also wants to minimize latency. What should be done to meet these requirements?

A.Use AWS Certificate Manager to issue a certificate for the RDS endpoint
B.Set up a VPN connection between the EC2 instances and the RDS instance using an IPsec VPN
C.Place the EC2 instances and RDS in the same subnet and use a NAT gateway
D.Enable SSL/TLS on the RDS instance and configure the application to use encrypted connections
AnswerD

Enabling SSL/TLS on the RDS instance forces the database server to accept only encrypted connections, typically by setting the force_ssl parameter (for PostgreSQL) or the SSL/TLS requirement (for MySQL) in the DB parameter group. The application must then connect using TLS with the RDS-generated CA certificate in its trust store, and it should enforce certificate verification to prevent man-in-the-middle attacks. This encrypts all data in transit between the EC2 instances and the RDS endpoint, satisfying the confidentiality requirement with minimal latency overhead and without needing extra networking equipment.

Why this answer

In a typical AWS environment, data in transit between an application and an RDS database can be encrypted using SSL/TLS. RDS for MySQL supports SSL/TLS connections. To meet the requirement, enable SSL/TLS on the RDS instance by downloading the certificate bundle and configuring the DB instance to require encrypted connections.

Then, configure the application to use SSL/TLS when connecting to the database. This approach encrypts data in transit with minimal overhead compared to a VPN, which can introduce latency. Option A (using AWS Certificate Manager for the RDS endpoint) is incorrect because ACM is typically used for load balancers and CloudFront, not for direct database connections.

While ACM can provide certificates for applications, RDS itself uses its own certificate authority for SSL/TLS. Option B (setting up an IPsec VPN) is unnecessary and adds complexity and latency without providing encryption specific to the database connection; SSL/TLS already meets the requirement. Option C (placing instances in the same subnet and using a NAT gateway) does not encrypt data in transit and increases latency via NAT gateway.

200
MCQeasy

A company wants to use AWS CloudFormation to manage infrastructure. The security team requires that all templates are scanned for security vulnerabilities before deployment. Which service should be integrated into the pipeline?

A.Amazon Inspector
B.AWS CloudFormation Guard
C.AWS Config
D.AWS Shield Advanced
AnswerB

AWS CloudFormation Guard is the correct choice because it is a policy-as-code engine designed to validate CloudFormation templates (and JSON/YAML in general) against custom rules before deployment. You define guards, such as 'every S3 bucket must have encryption enabled' or 'no IAM user with administrator access', and the Guard CLI or CI/CD integration checks the template's structure and properties. Any noncompliant resource is flagged in the pre-deployment phase, letting you fail the pipeline before infrastructure is created.

Why this answer

AWS CloudFormation Guard (cfn-guard) is a policy-as-code tool that allows you to define rules to validate CloudFormation templates against security best practices before deployment. It integrates into CI/CD pipelines to enforce compliance with organizational policies, such as ensuring encryption is enabled or public access is restricted, directly addressing the requirement to scan templates for security vulnerabilities.

Exam trap

The trap here is confusing runtime vulnerability scanning (Amazon Inspector) with pre-deployment template validation (CloudFormation Guard), leading candidates to choose Inspector because they associate 'security vulnerabilities' with runtime scanning rather than infrastructure-as-code compliance.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability management service that scans running EC2 instances, container images, and Lambda functions for software vulnerabilities and network exposure, not CloudFormation templates. Option C is wrong because AWS Config is a service for evaluating and auditing the configuration of deployed AWS resources against desired policies, not for scanning infrastructure-as-code templates before deployment. Option D is wrong because AWS Shield Advanced is a managed Distributed Denial of Service (DDoS) protection service for applications running on AWS, not a tool for scanning CloudFormation templates.

201
MCQmedium

A security engineer is designing a cross-account access policy. The engineer has an S3 bucket in Account A and wants to grant read access to a user in Account B. Which combination of policies is required?

A.A bucket policy in Account A that allows access to the user in Account B.
B.A bucket ACL in Account A granting access to the user in Account B.
C.An IAM policy in Account B that grants s3:GetObject to the bucket.
D.A bucket policy in Account A allowing the user, and an IAM policy in Account B granting s3:GetObject.
AnswerD

This is correct. The bucket policy in Account A acts as a resource-based policy that grants the external user access to the object, while the IAM policy in Account B gives that user the identity-based permission to make the request. Both policies are evaluated, and the union of permissions allows the cross-account S3 GetObject. This follows the standard S3 cross-account access model where both the resource-based and identity-based policies must allow the action.

Why this answer

Cross-account access to an S3 bucket requires both a resource-based policy (bucket policy) in Account A that grants permissions to the user in Account B, and an identity-based policy (IAM policy) in Account B that allows the user to perform the s3:GetObject action. Without both, access is denied. Option A is wrong because a bucket policy alone is insufficient; the user still needs an IAM policy in their own account to allow the action.

Option B is wrong because bucket ACLs are a legacy mechanism and do not effectively support cross-account access for specific IAM users; they would still require an IAM policy in Account B. Option C is wrong because an IAM policy in Account B alone is insufficient; the bucket policy in Account A must explicitly grant access to the user, as the bucket's default policy denies access from other accounts.

202
MCQmedium

A security engineer is designing a VPC with public and private subnets in two Availability Zones. The company requires that all outbound traffic from private subnets to the internet must go through a single, centrally managed NAT gateway. Which combination of resources and route table entries should be used?

A.A single NAT gateway in a public subnet, and a default route (0.0.0.0/0) in each private subnet route table pointing to that NAT gateway.
B.A single NAT gateway in a private subnet, and a default route in each private subnet pointing to the NAT gateway.
C.One NAT gateway per private subnet, each with a route to an internet gateway.
D.One NAT gateway per Availability Zone, with routes to the internet gateway.
AnswerA

A NAT gateway must reside in a public subnet with an internet gateway as the next-hop for 0.0.0.0/0 so it can perform source NAT for outbound traffic. Placing a single NAT gateway there and adding a 0.0.0.0/0 route in every private subnet route table pointing to that gateway ID centralizes internet egress while keeping instances private. This is the standard minimal design, though it is a single point of failure if that availability zone goes down.

Why this answer

A single NAT gateway placed in a public subnet (with an Internet Gateway route) can be used by multiple private subnets across different Availability Zones. Each private subnet's route table must have a default route (0.0.0.0/0) pointing to the NAT Gateway's elastic network interface (ENI) or NAT Gateway ID, ensuring all outbound traffic from private instances is source-NATed through that single, centrally managed device.

Exam trap

The trap here is that candidates often assume a NAT gateway must be in a private subnet because it handles private traffic, but AWS requires NAT gateways to be in a public subnet with an IGW route to function correctly.

How to eliminate wrong answers

Option B is wrong because a NAT gateway must reside in a public subnet (with a route to an Internet Gateway) to translate private IPs and reach the internet; placing it in a private subnet would block outbound traffic as the NAT gateway itself would have no internet path. Option C is wrong because it violates the requirement for a single, centrally managed NAT gateway; using one NAT gateway per private subnet would create multiple egress points and increase cost and management overhead. Option D is wrong because it also violates the single-NAT requirement; deploying one NAT gateway per Availability Zone creates multiple egress points and is typically used for high availability, not central management.

203
MCQhard

A company has a multi-account AWS Organization with hundreds of accounts. The security team wants to prevent any IAM user from creating access keys in any account. What is the most scalable and secure approach?

A.Use IAM Access Analyzer to generate findings when access keys are created.
B.Configure IAM password policies in each account to disallow access keys.
C.Apply an SCP that denies the IAM:CreateAccessKey action to all accounts in the organization.
D.Create an AWS Config rule in each account to automatically delete access keys.
AnswerC

A service control policy attached to the organization root, an OU, or individual accounts can explicitly deny the IAM:CreateAccessKey action, and because SCP deny statements override all identity-based and resource-based allows in the affected accounts, no principal in those accounts can create a new access key. This provides a centralized, preventive guardrail that scales across all accounts without requiring per-account configuration or custom automation. It is important to note that an SCP only prevents future creation and does not remove or invalidate access keys that already exist.

Why this answer

Service Control Policies (SCPs) applied at the organization or OU level deny the IAM:CreateAccessKey action across every account in one place, which is the most scalable and preventive control. Because SCPs are inherited, a single policy blocks access key creation in all current and future accounts without per-account configuration.

Exam trap

SCS-C02 often tests the difference between preventive controls (SCPs) and detective controls (Config, Access Analyzer) — candidates pick Config or Access Analyzer because they sound like governance tools, missing that only SCPs block the action before it happens.

How to eliminate wrong answers

Option A is wrong because IAM Access Analyzer generates findings about externally accessible resources; it does not detect or block access key creation. Option B is wrong because IAM password policies govern password complexity and rotation for console users — they have no effect on access keys, which are a separate credential type. Option D is wrong because an AWS Config rule is detective and per-account; it would require deployment in every account and only deletes keys after they are created, which is neither preventive nor scalable.

204
MCQmedium

Refer to the exhibit. A security engineer is investigating a potential unauthorized VPC creation. What does the evidence suggest?

A.The user admin created two VPCs, but one was deleted shortly after creation.
B.The CloudTrail log is incomplete; both VPCs exist.
C.Both VPCs were created successfully and still exist.
D.The user admin only created one VPC; the second event is a duplicate.
AnswerA

Each CreateVpc API call in CloudTrail is recorded with a distinct event ID and returns a unique VPC ID. The current describe-vpcs output shows only one VPC, so one of the two created VPC IDs is absent. That absence indicates a DeleteVpc call (or another deletion mechanism) removed the VPC after creation; CloudTrail's management events would capture that deletion, confirming the lifecycle.

Why this answer

The CloudTrail log shows two CreateVpc events by user admin. One VPC exists (vpc-12345678), but the other (vpc-87654321) does not exist, indicating that it was deleted after creation. This could indicate malicious activity where a VPC was created and then deleted to cover tracks.

205
Multi-Selectmedium

A security engineer is investigating a potential data exfiltration from an AWS account. Which TWO CloudTrail events would be MOST indicative of data exfiltration via S3?

Select 2 answers
A.`PutObject` API calls from a known internal IP.
B.`CopyObject` API calls from a production bucket to a bucket in another AWS account.
C.`ListObjects` API calls from an EC2 instance in the same VPC.
D.`GetObject` API calls from an IP address in an unfamiliar geographic region.
E.`DeleteObject` API calls from the root user.
AnswersB, D

A `CopyObject` call that copies objects from a production bucket to a bucket in another AWS account is a direct, API-driven transfer of data to an external destination. This operation effectively bypasses traditional network egress controls because the data moves over AWS's internal infrastructure to an account outside the organization's management. It is a common exfiltration technique used by attackers with compromised credentials to quietly duplicate sensitive objects to a location they control.

Why this answer

`CopyObject` API calls from a production bucket to a bucket in another AWS account indicate data being replicated or moved across account boundaries, which is a strong signal of potential data exfiltration. This action bypasses typical network controls and can transfer large volumes of data without requiring a download, making it a common exfiltration technique.

Exam trap

The trap here is that candidates often focus on `GetObject` as the primary exfiltration vector, but `CopyObject` is equally dangerous because it can move data directly to another account without leaving a network egress trail.

206
MCQhard

During a security incident, a security engineer needs to preserve forensic evidence from an EC2 instance that may be compromised. The instance is running a critical application. Which approach minimizes data loss while ensuring the integrity of the evidence?

A.Create an EBS snapshot, then isolate the instance by modifying the security group and removing it from the load balancer.
B.Immediately terminate the instance to stop any ongoing malicious activity.
C.SSH into the instance and run forensic tools to capture memory.
D.Detach the instance from the Auto Scaling group and leave it running without changes.
AnswerA

Taking an EBS snapshot first preserves the root and data volumes as a point-in-time forensic copy of the disk, while leaving the instance running so volatile state is not yet lost. Then you isolate the instance by swapping its security group to a deny-all rule set and deregistering it from the load balancer, which cuts all network paths without modifying the guest OS or killing processes. This containment step prevents lateral movement and further data exfiltration while preserving the ability to later analyze memory, network connections, and disk state.

Why this answer

Creating an EBS snapshot preserves the disk state at the point of the incident, capturing forensic evidence without altering the running instance. Isolating the instance by modifying the security group (e.g., removing all inbound/outbound rules) and removing it from the load balancer stops network traffic and prevents further compromise, minimizing data loss while maintaining the integrity of the evidence for later analysis.

Exam trap

The trap here is that candidates may think terminating the instance is the safest way to stop malicious activity, but they overlook the irreversible loss of forensic evidence and the need to preserve the disk state for investigation.

How to eliminate wrong answers

Option B is wrong because immediately terminating the instance destroys volatile data (e.g., memory, running processes) and the disk state, losing critical forensic evidence and preventing root cause analysis. Option C is wrong because SSH-ing into a potentially compromised instance risks alerting the attacker, altering evidence, or allowing the attacker to cover tracks; forensic memory capture should be done via hypervisor-level tools (e.g., AWS Nitro System's memory capture) or by attaching a forensic instance to the EBS volume. Option D is wrong because leaving the instance running without changes allows ongoing malicious activity to continue, potentially corrupting evidence or causing further damage; isolation (via security group and load balancer removal) is necessary to preserve the state.

207
MCQmedium

A company uses Amazon GuardDuty and AWS Security Hub in a single AWS account. The security team has created a custom action in Security Hub to send findings to a custom Lambda function for automated response. The Lambda function is designed to take remediation actions based on the finding type. During testing, the team notices that the Lambda function is not being invoked when new findings are generated. The Lambda function's resource-based policy allows invocations from Security Hub, and the function's execution role has necessary permissions. What is the most likely reason for the failure?

A.No Amazon EventBridge rule is configured to send Security Hub findings to the Lambda function.
B.GuardDuty is not enabled for all required resource types.
C.The Lambda function's execution role does not have permission to access GuardDuty.
D.The Lambda function's resource-based policy does not include Security Hub as a principal.
AnswerA

Security Hub custom actions do not invoke Lambda functions directly. When an analyst triggers a custom action in the Security Hub console, Security Hub publishes an event to Amazon EventBridge with a detail-type like 'Security Hub Findings - Custom Action'. You must configure an EventBridge rule that matches this event and has the Lambda function as a target. Without that rule, the Lambda function receives no invocation, regardless of IAM roles or resource policies.

Why this answer

Security Hub custom actions do not automatically invoke a Lambda function. When a custom action is triggered, Security Hub publishes an event to the default EventBridge bus, and you must create an EventBridge rule that matches the custom action ARN and targets the Lambda function. Without that rule, the Lambda is never invoked, even though the resource-based policy and execution role are correctly configured.

Exam trap

SCS-C02 often tests the event-driven architecture behind Security Hub automation — candidates assume Security Hub invokes Lambda directly and overlook the mandatory EventBridge rule that sits between them.

How to eliminate wrong answers

Option B is wrong because GuardDuty resource type coverage affects which findings are generated, not whether Security Hub can invoke Lambda — the question states findings are being generated, so GuardDuty is working. Option C is wrong because the Lambda execution role does not need GuardDuty permissions to be invoked by Security Hub; it only needs permissions for the remediation actions it performs (e.g., EC2, S3). Option D is wrong because the question explicitly states the resource-based policy already allows invocations from Security Hub, so adding Security Hub as a principal is redundant and not the cause of the failure.

208
MCQeasy

Refer to the exhibit. A security engineer reviews the bucket policy for an S3 bucket. The engineer attempts to upload an object to the bucket using the AWS CLI without the --ssl flag (HTTP). What is the outcome?

A.The upload succeeds because the policy allows all actions.
B.The upload fails because the policy denies requests that are not using HTTPS.
C.The upload succeeds because the bucket has default encryption enabled.
D.The upload fails because the policy denies s3:PutObject only.
AnswerB

The bucket policy contains a Deny statement targeting all S3 actions and keyed on the Bool condition aws:SecureTransport=false. Requests made with HTTP set this key to false, so the condition evaluates true, the Deny is applied, and the PutObject upload is rejected. Only HTTPS requests would have SecureTransport=true and therefore would not match this particular Deny; however, an explicit Allow statement is still required to authorize the request.

Why this answer

The bucket policy includes a condition that explicitly denies all s3: actions (including s3:PutObject) when the request does not use HTTPS (SecureTransport is false). Since the engineer uses HTTP (no --ssl flag), the condition is met, and the upload is denied. Option A is incorrect because the policy does not allow all actions; it includes a conditional deny.

Option C is incorrect because default encryption does not override the explicit deny in the policy. Option D is incorrect because the policy denies all s3 actions, not just s3:PutObject.

209
MCQmedium

A company uses AWS KMS with a custom key store backed by AWS CloudHSM. The security team wants to ensure that the key material never leaves the HSM and that all cryptographic operations are performed within the HSM. Which of the following actions should the team take?

A.Create the KMS key as an asymmetric key in a custom key store and set the key usage to 'SIGN_VERIFY'.
B.Enable the 'Prevent key material export' option in the KMS key policy.
C.Create the KMS key as a symmetric key in the default key store.
D.Create the KMS key in a custom key store and set the key usage to 'ENCRYPT_DECRYPT'.
AnswerD

Creating a symmetric KMS key in a CloudHSM-backed custom key store with key usage set to ENCRYPT_DECRYPT ensures that the key material is generated and used only inside the customer's dedicated HSM cluster. The HSM performs all encryption and decryption operations for that key, and the unencrypted key material never leaves the HSM or becomes visible to AWS KMS service processes. This satisfies both the HSM residency requirement and the need for a general-purpose data encryption key.

Why this answer

To ensure key material never leaves the HSM and cryptographic operations are performed within the HSM, the team should create the KMS key in a custom key store (backed by CloudHSM) and set the key usage to ENCRYPT_DECRYPT. This ensures that the key material is stored and used only within the HSM. Option A is incorrect because asymmetric keys with SIGN_VERIFY usage are not the standard for encryption/decryption, and the key material could potentially be exported if the HSM allows.

Option B is incorrect because the 'Prevent key material export' option is not available in KMS; custom key stores inherently prevent export. Option C is incorrect because the default key store uses software-based keys, not HSM hardware. Therefore, Option D is the correct answer.

210
MCQeasy

A security analyst needs to receive an alert when an IAM user attempts to perform an action they are not authorized to perform. Which AWS service can be used to monitor and alert on such authorization failures?

A.AWS Organizations SCPs
B.AWS CloudTrail with CloudWatch metric filter and alarm
C.AWS IAM Access Analyzer
D.AWS Config
AnswerB

CloudTrail records every IAM API call as an event, including AccessDenied responses, and can deliver those events to CloudWatch Logs. A CloudWatch Logs metric filter can count occurrences of a specific pattern, such as an IAM-issued authorization failure, and a CloudWatch alarm can then trigger an Amazon SNS notification. This combination provides near-real-time detective monitoring without inserting latency into the original IAM request.

Why this answer

AWS CloudTrail logs all API calls made by IAM users, including authorization failures (e.g., AccessDenied errors). By creating a CloudWatch metric filter on CloudTrail logs for specific error codes like 'AccessDenied' or 'UnauthorizedOperation', you can trigger a CloudWatch alarm to send notifications via SNS. This is the standard AWS approach for monitoring and alerting on unauthorized actions.

Exam trap

The trap here is that candidates confuse IAM Access Analyzer's 'findings' about external access with real-time monitoring of authorization failures, or they think AWS Config's compliance rules can alert on API denials, but neither service processes CloudTrail API logs for this purpose.

How to eliminate wrong answers

Option A is wrong because AWS Organizations SCPs are used to centrally control the maximum permissions for accounts in an organization, not to monitor or alert on authorization failures. Option C is wrong because IAM Access Analyzer identifies resources shared with external entities by analyzing resource-based policies, but it does not monitor real-time authorization failures from API calls. Option D is wrong because AWS Config evaluates resource configurations against rules and tracks configuration changes, but it does not monitor API-level authorization failures or generate alerts for denied actions.

211
MCQeasy

A company has a serverless application using AWS Lambda functions that process sensitive data. The security team wants to detect potential data exfiltration via DNS queries from the Lambda functions. Which service should be enabled to monitor DNS requests?

A.Amazon Route 53 Resolver DNS Firewall
B.AWS WAF
C.Amazon CloudWatch Logs
D.AWS GuardDuty
AnswerA

Amazon Route 53 Resolver DNS Firewall is the correct answer because it operates at the DNS layer, inspecting outbound DNS queries from a VPC. It can both log full DNS query details (through Resolver query logging) and filter/block malicious or unwanted domains before resolution. This is directly applicable to a serverless Lambda application that needs DNS visibility and control, whereas other services operate at different layers or lack native DNS logging.

Why this answer

Amazon Route 53 Resolver DNS Firewall is the correct choice because it provides DNS-layer filtering for outbound DNS queries from VPCs, including those made by Lambda functions. It can log and block DNS requests to known malicious domains, enabling detection of data exfiltration attempts that use DNS tunneling or command-and-control (C2) communication. This service integrates with VPC flow logs and CloudWatch to monitor DNS query patterns specifically.

Exam trap

The trap here is that candidates often confuse AWS WAF (web application firewall) with DNS-layer filtering, or assume GuardDuty natively monitors DNS queries without realizing it requires Route 53 Resolver DNS Firewall as a prerequisite data source.

How to eliminate wrong answers

Option B (AWS WAF) is wrong because it operates at the application layer (HTTP/HTTPS) to protect web applications from common exploits, not at the DNS layer, and cannot inspect or log DNS queries. Option C (Amazon CloudWatch Logs) is wrong because it is a log storage and monitoring service, not a DNS-specific monitoring tool; it can store logs from other services but does not natively capture or analyze DNS queries from Lambda. Option D (AWS GuardDuty) is wrong because while it uses threat intelligence to detect malicious activity, it relies on DNS logs from Route 53 Resolver DNS Firewall or VPC DNS logs as a data source; it does not directly monitor or log DNS queries itself.

212
MCQeasy

A company needs to encrypt data in transit between an EC2 instance and an RDS database. Which option should be used?

A.Enable encryption at rest for the RDS instance
B.Configure the database to use SSL/TLS connections
C.Use an AWS KMS key to encrypt the connection
D.Enable EBS encryption on the EC2 instance
AnswerB

To encrypt data in transit, you must configure the database client and server to negotiate a TLS session. On RDS, this means importing the Amazon RDS CA certificate into the client's trust store and setting the database parameter group's `rds.force_ssl` (PostgreSQL) or `require_secure_transport` (MySQL/MariaDB) parameter to 1. Once enabled, TLS encrypts the entire database protocol stream, including authentication, query text, and result sets, and the client can verify that it is connecting to the genuine RDS endpoint, not an impostor.

Why this answer

Encrypting data in transit between an EC2 instance and an RDS database requires the use of SSL/TLS protocols to secure the communication channel. AWS RDS supports SSL/TLS connections by enabling the `require_secure_transport` parameter or using a certificate bundle on the client side, ensuring that all data transmitted over the network is encrypted and protected from eavesdropping or man-in-the-middle attacks.

Exam trap

The trap here is that candidates often confuse encryption at rest (EBS or RDS encryption) with encryption in transit, or mistakenly think that KMS keys can be directly applied to network connections, when in fact SSL/TLS is the correct mechanism for securing data in motion.

How to eliminate wrong answers

Option A is wrong because encryption at rest protects data stored on disk, not data transmitted over the network between EC2 and RDS. Option C is wrong because AWS KMS is used to manage encryption keys for data at rest or envelope encryption, not to directly encrypt network connections; SSL/TLS uses certificates and cipher suites, not KMS keys. Option D is wrong because EBS encryption protects data at rest on the EC2 instance's volumes, not data in transit between the instance and the RDS database.

213
MCQhard

A company uses AWS Organizations and has a requirement to enforce that all EC2 instances launched in any account must have a specific tag "Environment" with value "Production". The security team wants to prevent any instance without this tag from being launched. They implement a service control policy (SCP) that denies the ec2:RunInstances action if the request does not include the required tag. However, they find that users are still able to launch instances without the tag. The SCP is attached to the root OU. The team also has an IAM policy that allows ec2:RunInstances with no conditions. What is the most likely reason the SCP is not preventing the launches?

A.The SCP does not apply to the root user in member accounts.
B.The IAM policy allows the action, which overrides the SCP deny.
C.The SCP is applied to the management account, not the member accounts.
D.The SCP uses ec2:ResourceTag instead of aws:RequestTag for the condition.
AnswerD

For ec2:RunInstances, tags supplied in the request are evaluated through the aws:RequestTag condition key; ec2:ResourceTag evaluates tags on existing resources, which do not yet exist at launch. The SCP therefore never matches the request, so untagged instances launch despite the deny statement.

Why this answer

The SCP uses the condition key ec2:ResourceTag, which evaluates tags on the EC2 instance resource, but at the time of RunInstances, the instance does not yet exist, so the tag is not present. To enforce tagging at launch, the SCP must use the aws:RequestTag condition key, which checks tags included in the request. Therefore, the SCP fails to deny launches without the required tag.

Exam trap

The trap is confusing ec2:ResourceTag with aws:RequestTag; candidates often think that tagging an instance after launch can satisfy a ResourceTag condition, but the condition is evaluated at the time of the API call, and for RunInstances, the resource tag does not exist yet.

How to eliminate wrong answers

Option A is wrong because SCPs do apply to IAM users and roles in member accounts, including the root user of member accounts (though not the management account). Option B is wrong because SCPs take precedence over IAM policies; an explicit deny in an SCP overrides any allow in IAM. Option C is wrong because SCPs attached to the root OU apply to all member accounts, not the management account, but the issue is not about the management account.

214
MCQmedium

A company has a serverless application using AWS Lambda, API Gateway, and DynamoDB. The security team wants to detect and respond to potential SQL injection attempts in API requests. They have enabled AWS WAF on the API Gateway and created a rule to block SQL injection. However, they also want to capture the blocked requests for analysis and store them in an S3 bucket. The team has configured WAF to send logs to Amazon Kinesis Data Firehose, which delivers to an S3 bucket. After testing, the team notices that the logs are not being delivered. The Firehose delivery stream is in the same AWS account, and the S3 bucket policy allows the Firehose service to write. What is the most likely cause?

A.The WAF web ACL is not configured to log blocked requests.
B.The Kinesis Data Firehose delivery stream does not have an IAM role with permissions to write to the S3 bucket.
C.The S3 bucket policy does not grant write permissions to the Firehose delivery stream's IAM role.
D.Kinesis Data Firehose delivers logs in batches every 5 minutes, so the team should wait longer.
AnswerB

The Kinesis Data Firehose delivery stream is configured with an IAM role that it assumes to write to the destination S3 bucket. If that role does not have a permissions policy allowing s3:PutObject (and s3:GetBucketLocation) on the target bucket, Firehose attempts to deliver records but receives an AccessDenied error from S3. The delivery stream may still accept records from WAF, but the data is never written to the bucket, leaving the bucket empty. This is the most direct explanation for logs being absent, because the Firehose-to-S3 step is where the chain fails.

Why this answer

The most likely cause is that the Kinesis Data Firehose delivery stream lacks an IAM role with permissions to write to the S3 bucket. Even if the S3 bucket policy allows the Firehose service to write, Firehose assumes an IAM role to access the bucket. If that role does not have the necessary permissions (e.g., s3:PutObject), delivery fails.

The other options are less likely because WAF logging is configured (since logs are attempted), the S3 bucket policy is stated to allow write, and Firehose buffering is normal.

Exam trap

The trap is assuming that an S3 bucket policy alone is sufficient for Firehose to write. Candidates often overlook the need for an IAM role that Firehose assumes to access the bucket, leading them to choose option C instead of B.

How to eliminate wrong answers

Option A is wrong because if the web ACL were not configured to log blocked requests, no logs would be generated at all, but the team is seeing logs not delivered, implying logging is enabled. Option C is wrong because the scenario states the S3 bucket policy allows the Firehose service to write, so that is not the issue. Option D is wrong because Firehose buffering is expected, but if logs are not delivered after sufficient time, it indicates a permissions issue rather than a delay.

215
Multi-Selectmedium

A security engineer is investigating a potential security incident involving an Amazon RDS database. The engineer needs to identify which of the following actions should be taken during the forensic analysis phase? (Select TWO.)

Select 2 answers
A.Enable automatic backups if not already enabled.
B.Disable deletion protection to allow cleanup.
C.Modify the security group to restrict database access.
D.Take a manual snapshot of the RDS instance.
E.Review AWS CloudTrail logs for API calls related to the RDS instance.
AnswersD, E

A manual snapshot immediately captures a consistent, point-in-time copy of the RDS instance, including its data, storage configuration, and parameters, independent of the automated backup window. This snapshot can be stored even if automatic backups are disabled, and it can later be restored to an isolated instance for forensic analysis without affecting the original. It is the correct first step to preserve volatile database evidence that could otherwise be modified or deleted during the investigation.

Why this answer

Taking a manual snapshot preserves a point-in-time, immutable copy of the RDS instance for offline forensic analysis without altering the live database. This ensures that evidence is captured before any changes occur during the investigation, and the snapshot can be restored to a separate instance for safe examination.

Exam trap

The trap here is confusing containment actions (like modifying security groups) with forensic preservation actions, leading candidates to select Option C instead of recognizing that the first step in forensic analysis is to capture immutable evidence via a snapshot and review CloudTrail logs.

216
Multi-Selecteasy

A security engineer needs to protect an S3 bucket that contains sensitive data. Which two methods should the engineer use?

Select 2 answers
A.Use Amazon CloudFront to serve the content.
B.Enable VPC Flow Logs on the bucket.
C.Apply an S3 bucket policy that restricts access to specific IAM users or roles.
D.Use IAM policies to grant permissions to users and roles.
E.Enable S3 object ACLs.
AnswersC, D

An S3 bucket policy is a resource-based policy attached directly to the bucket, and it can specify which IAM users or roles are permitted to perform actions such as s3:GetObject or s3:PutObject. Since the policy is evaluated against the principal, action, resource, and conditions, it can restrict access to only specific AWS identities while denying all other principals. This is a native, effective way to protect the bucket and is the recommended resource-based control for enforcing such restrictions.

Why this answer

Option C is correct because an S3 bucket policy is a resource-based policy attached directly to the bucket that can explicitly allow or deny access based on principals (specific IAM users, roles, or accounts), conditions such as source VPC endpoint or IP range, and actions, making it the primary tool for restricting who can reach sensitive objects. Option D is correct because IAM policies are identity-based policies attached to users, groups, or roles that define which S3 actions (for example s3:GetObject, s3:PutObject) those identities may perform on the bucket and its objects; combined with the bucket policy, they enforce least-privilege access. Option A is not correct because CloudFront is a content-delivery service that can front an S3 bucket for performance or OAC-based access, but it does not by itself protect the bucket's data or restrict direct S3 access.

Option B is not correct because VPC Flow Logs capture IP traffic metadata for network interfaces in a VPC and have no relationship to S3 bucket access control. Option E is not correct because S3 object ACLs are legacy access-control lists that grant only coarse read/write permissions to individual objects and are not the recommended mechanism for restricting sensitive bucket data to specific IAM principals.

Exam trap

The trap here is that candidates often confuse resource-based policies (bucket policies) with identity-based policies (IAM policies) and may think only one is sufficient, but the question asks for two methods, and both C and D are correct because they work together to enforce least-privilege access.

217
Multi-Selecthard

An organization uses AWS CloudTrail with a multi-region trail. The security team suspects that an attacker has deleted logs. Which THREE findings would indicate that log deletion occurred? (Choose THREE.)

Select 3 answers
A.An S3 bucket with MFA Delete enabled.
B.A `StopLogging` API call from an unknown IP address.
C.A gap in CloudTrail logs for a period of time.
D.Multiple `StartLogging` API calls in the logs.
E.A `DeleteTrail` API call.
AnswersB, C, E

A StopLogging API call is the direct way to disable CloudTrail log delivery; if it originates from an unknown or unrecognized IP address, it strongly suggests an attacker is attempting to hide their activity by pausing audit logging. This action would create a window where no logs are recorded, allowing subsequent actions to go undetected. Because CloudTrail itself logs the StopLogging event in a separate admin trail (if one is configured) or via the CloudTrail management event log, its presence with an unusual source IP is a clear indicator of compromise.

Why this answer

A `StopLogging` API call from an unknown IP address indicates that logging was deliberately disabled, which an attacker could do to cover their tracks. CloudTrail records all `StopLogging` events, and an unexpected source IP is a strong indicator of unauthorized activity. This directly suggests log deletion or suppression, as stopping the trail prevents further log delivery.

Exam trap

The trap here is that candidates may confuse a security control (MFA Delete) with an indicator of compromise, or think that `StartLogging` calls imply deletion, when in fact they are normal operational events that do not directly signal log tampering.

218
MCQmedium

Refer to the exhibit. A security engineer reviews the CloudTrail trail configuration. What is a security concern?

A.The trail is not multi-region
B.The logs are not encrypted with a customer-managed KMS key
C.Log file validation is not enabled
D.CloudWatch Logs integration is missing
AnswerB

The real security gap is that `kmsKeyId` is null, meaning the CloudTrail log files are encrypted with S3-managed keys (SSE-S3) rather than a customer-managed AWS KMS key. With SSE-S3, AWS handles all key management, so the security team cannot control key rotation, define key policies, or revoke access for investigative or compliance purposes. Configuring a KMS key enables envelope encryption, provides a separate audit trail for KMS decrypt operations, and is the more secure option for CloudTrail log protection.

Why this answer

The security concern is that the CloudTrail logs are not encrypted with a customer-managed KMS key. By default, CloudTrail encrypts log files using SSE-S3 (S3-managed keys), which does not provide the customer with control over key rotation, access policies, or the ability to audit key usage. Using a customer-managed KMS key ensures that only authorized principals can decrypt the logs, and it enables fine-grained access control and audit trails via CloudTrail and CloudWatch Logs, which is critical for compliance and security monitoring.

Exam trap

The SCS-C02 exam often tests the misconception that default encryption (SSE-S3) is sufficient for compliance, but the exam expects you to recognize that customer-managed KMS keys provide additional control and auditability, making the lack of SSE-KMS a security concern.

How to eliminate wrong answers

Option A is wrong because a multi-region trail is not a mandatory security requirement; it is a configuration choice for aggregating logs from all regions, but the absence of multi-region does not directly expose logs to unauthorized access or tampering. Option C is wrong because log file validation provides integrity verification via hash digests, but it does not address encryption at rest; the lack of validation is a concern for integrity, not confidentiality, and the question specifically asks about a security concern related to the trail configuration shown. Option D is wrong because CloudWatch Logs integration is an optional feature for real-time monitoring and alerting, but its absence does not represent a direct security vulnerability; the primary concern is that logs are not encrypted with a customer-managed KMS key, which is a fundamental control for protecting sensitive audit data.

219
MCQeasy

A security engineer is configuring Amazon GuardDuty for the first time. The engineer wants to receive alerts when GuardDuty generates a finding of severity HIGH or higher. What is the simplest way to achieve this?

A.Create an Amazon EventBridge rule that matches GuardDuty findings and triggers an SNS topic.
B.Configure CloudWatch Logs to monitor GuardDuty logs and create a metric filter for high-severity findings.
C.Set up an S3 event notification on the GuardDuty findings bucket.
D.Configure GuardDuty to send email notifications for all findings.
AnswerA

Amazon GuardDuty publishes all generated findings to Amazon EventBridge (formerly CloudWatch Events) as events with a detail type of 'GuardDuty Finding'. By creating an EventBridge rule that matches the finding severity (for example, using the 'severity' field in the event detail) and setting the target to an SNS topic, you can send near-real-time alerts to security teams. This is the native, recommended integration path, and it also allows you to route findings to AWS Lambda, Step Functions, or other targets for automated remediation.

Why this answer

Amazon EventBridge can natively capture GuardDuty findings as events and route them to an SNS topic for alerting. This is the simplest approach because it requires no custom code, no log parsing, and no additional infrastructure—just a rule matching the `GuardDuty Finding` event type and a severity filter for HIGH or higher.

Exam trap

The trap here is that candidates may think GuardDuty has a native email notification feature or that findings are automatically stored in S3 or CloudWatch Logs, leading them to choose more complex or incorrect options.

How to eliminate wrong answers

Option B is wrong because GuardDuty does not write findings to CloudWatch Logs; it publishes events to EventBridge, and using CloudWatch Logs would require unnecessary log ingestion and metric filter setup. Option C is wrong because GuardDuty does not store findings in an S3 bucket by default; findings are stored in the GuardDuty service itself, and S3 event notifications are not applicable. Option D is wrong because GuardDuty does not have a built-in feature to send email notifications directly; it relies on integrations like EventBridge or SNS for alerting.

220
MCQmedium

A security engineer manages a fleet of Amazon EC2 instances in a VPC. The instances must be able to reach the internet for software updates, but they must not be directly reachable from the internet. The VPC has a private subnet with a route to a NAT gateway in a public subnet. The engineer notices that instances in the private subnet cannot reach the internet, and the NAT gateway's CloudWatch metrics show zero active connections. Which of the following is the MOST likely cause?

A.The security group on the instances does not allow outbound traffic to the NAT gateway.
B.The private subnet's route table does not have a route to the NAT gateway.
C.The NAT gateway is not associated with an Elastic IP address.
D.The network ACL on the private subnet is blocking outbound traffic to the NAT gateway.
AnswerB

For a private subnet to use a NAT gateway, its route table must have a route with destination 0.0.0.0/0 pointing to the NAT gateway. If that route is missing or misconfigured, instances cannot send traffic to the NAT gateway, resulting in zero active connections. This is the most likely cause given the symptoms.

Why this answer

The NAT gateway's zero active connections indicate that traffic from the private instances is not reaching it. The most common reason is a missing or incorrect route in the private subnet's route table directing internet-bound traffic to the NAT gateway. Without that route, instances have no path to the NAT gateway, so they cannot access the internet.

Exam trap

The trap here is assuming that a NAT gateway automatically enables internet access for private subnets without verifying the route table configuration.

221
Multi-Selectmedium

A company is using AWS CloudTrail to log API calls. The security team wants to ensure that the logs are protected from unauthorized access and deletion. Which TWO actions should be taken?

Select 2 answers
A.Enable server-side encryption using AWS KMS (SSE-KMS) on the S3 bucket.
B.Use S3 bucket ACLs to restrict access.
C.Enable CloudTrail log file validation.
D.Enable S3 Versioning on the bucket.
E.Enable multi-factor authentication (MFA) for CloudTrail.
AnswersA, C

Server-side encryption with AWS KMS (SSE-KMS) encrypts CloudTrail log objects at rest using envelope encryption with a customer-managed CMK, ensuring that the API activity data is unreadable to unauthorized parties. CloudTrail integrates natively with SSE-KMS, and you can configure the bucket to use a KMS key for all delivered logs, which also provides an additional layer of protection for sensitive information such as user credentials or IP addresses. This is the correct choice because it directly addresses the confidentiality of the logs, a fundamental security requirement.

Why this answer

Enabling server-side encryption using AWS KMS (SSE-KMS) on the S3 bucket that stores CloudTrail logs ensures that the log files are encrypted at rest, protecting them from unauthorized access. This encryption uses envelope encryption with a customer-managed or AWS-managed KMS key, providing an additional layer of access control via KMS key policies and IAM policies. Option C is correct because CloudTrail log file validation creates a signed digest file for each log file, allowing you to verify that the logs have not been tampered with, deleted, or modified after delivery.

This uses SHA-256 hashing and digital signing with the private key of AWS, ensuring integrity and authenticity of the log files.

Exam trap

The trap here is that candidates often confuse 'protecting logs from deletion' with 'preventing deletion' and incorrectly choose S3 Versioning (Option D) as a security control, when in fact versioning only helps recover from accidental deletion, not prevent malicious deletion by an authorized user.

222
MCQeasy

A company wants to monitor failed SSH login attempts to EC2 instances. Which approach should be used?

A.Use the CloudWatch Logs agent to send /var/log/auth.log to CloudWatch Logs
B.Enable AWS CloudTrail for EC2 instances
C.Enable VPC Flow Logs
D.Use AWS Config to detect SSH access
AnswerA

The unified CloudWatch Logs agent (or legacy logs agent) installed on the EC2 instance tails /var/log/auth.log and streams each new line to a CloudWatch Logs log group. Once the log data is in CloudWatch Logs, you can create a metric filter that matches patterns such as 'Failed password for' or 'authentication failure' and then alarm on that metric. The agent needs an IAM role with logs:PutLogEvents permissions, but no other AWS service can natively reach into the guest OS to read auth logs.

Why this answer

Failed SSH login attempts are logged by the SSH daemon (sshd) to the system's authentication log file, typically /var/log/auth.log on Debian-based systems or /var/log/secure on Red Hat-based systems. The CloudWatch Logs agent can be configured to tail this log file and send the entries to CloudWatch Logs, where you can create metric filters to detect patterns like 'Failed password' and trigger alarms or automated responses.

Exam trap

The trap here is that candidates confuse control-plane logging (CloudTrail) with OS-level logging, or assume VPC Flow Logs can inspect application-layer data, when in fact they only capture Layer 3/4 network metadata.

How to eliminate wrong answers

Option B is wrong because AWS CloudTrail records API calls made to the AWS control plane (e.g., RunInstances, CreateKeyPair) and does not capture OS-level events like SSH login attempts inside an EC2 instance. Option C is wrong because VPC Flow Logs capture metadata about network traffic (IP addresses, ports, protocols) but do not inspect the payload of packets, so they cannot determine whether an SSH login succeeded or failed. Option D is wrong because AWS Config is a service for evaluating resource configurations against rules (e.g., checking if security groups allow SSH from 0.0.0.0/0) and does not monitor real-time OS-level authentication events.

223
Multi-Selecthard

A security team wants to implement a centralized logging solution for multiple AWS accounts. The team needs to collect VPC Flow Logs, CloudTrail logs, and DNS query logs from all accounts. Which THREE services should the team use to aggregate these logs? (Choose THREE.)

Select 3 answers
A.AWS CloudHSM
B.AWS Config
C.Amazon Route 53 Resolver query logging
D.AWS CloudTrail
E.VPC Flow Logs
AnswersC, D, E

Amazon Route 53 Resolver query logging captures DNS queries made by resources within your VPCs, including queries to on-premises networks. It satisfies the stem's requirement to collect DNS query logs centrally, publishing them to CloudWatch Logs, S3, or Kinesis Data Firehose for aggregation across accounts.

Why this answer

Amazon Route 53 Resolver query logging (C) is correct because it captures DNS queries made by resources within a VPC, including queries to the Resolver, and can publish those logs to CloudWatch Logs, S3, or Kinesis Data Firehose for centralization. AWS CloudTrail (D) is correct because it records API activity and account events across accounts, and with an organization trail you can aggregate CloudTrail logs from all accounts into a single S3 bucket. VPC Flow Logs (E) is correct because it captures IP traffic metadata for network interfaces in a VPC and can deliver logs to CloudWatch Logs or S3, enabling centralized collection across accounts.

AWS CloudHSM (A) is not a logging service; it provides dedicated hardware security modules for cryptographic key operations. AWS Config (B) tracks resource configuration changes and compliance, not VPC Flow Logs, CloudTrail events, or DNS query logs, so it does not fulfill the aggregation requirement.

Exam trap

The trap here is that candidates may confuse AWS CloudHSM or AWS Config as logging services, but neither is designed for log collection or aggregation; CloudHSM is for key management and Config is for configuration auditing, not for aggregating VPC Flow Logs, CloudTrail logs, or DNS query logs.

224
Multi-Selecteasy

A security engineer is configuring VPC Flow Logs to capture network traffic metadata. Which TWO attributes can be captured in VPC Flow Logs? (Choose TWO.)

Select 2 answers
A.Packet payload
B.Source IP address
C.IAM user ID
D.Destination port
E.DNS query name
AnswersB, D

This is the correct answer. VPC Flow Logs capture the source IP address in the srcaddr field for every accepted or rejected network connection, as part of the standard flow log record. The srcaddr field is available in all flow log versions and is used to identify the origin of the traffic. It is recorded regardless of whether the traffic was allowed or denied by security groups or network ACLs.

Why this answer

VPC Flow Logs capture metadata about network traffic, including the source IP address (option B) and destination port (option D). The source IP address identifies the origin of the traffic, while the destination port indicates the application or service being targeted. These are standard fields in the flow log record format, as defined by AWS for capturing IP traffic metadata.

Exam trap

The trap here is that candidates often confuse network metadata with application-layer data, mistakenly thinking VPC Flow Logs can capture packet payloads or DNS query names, which are not part of the flow log record format.

225
Multi-Selectmedium

A company needs to monitor for unauthorized changes to security group rules. Which TWO AWS services can be used together to achieve this?

Select 2 answers
A.Amazon GuardDuty
B.AWS Config
C.Amazon Inspector
D.AWS CloudTrail
E.Amazon CloudWatch Events
AnswersB, E

AWS Config is purpose-built for recording configuration item changes and evaluating them against desired policies. When a security group rule is added, removed, or modified, Config generates a configuration item and can trigger an AWS Config rule (e.g., a managed rule or a custom Lambda rule) that determines whether the new state is compliant with the organization's requirements. It provides a timeline of every change, so you can identify exactly what was unauthorized and when it happened, and it can automatically remediate noncompliant rules via Systems Manager Automation. This is why AWS Config is the core service for this monitoring need.

Why this answer

Options B and E are correct. AWS Config can track changes to security group rules, and Amazon CloudWatch Events can trigger a notification when a Config rule detects a change. Option A (GuardDuty) is for threat detection.

Option C (Inspector) is for vulnerability scanning. Option D (CloudTrail) logs API calls but is not the best for direct rule-level monitoring.

Page 2

Page 3 of 17

Page 4