Courseiva

AWS Certified Security Specialty SCS-C02 (SCS-C02) — Questions 226–300

1205 questions total · 17pages · All types, answers revealed

Page 3

Page 4 of 17

Page 5
226
MCQmedium

A company uses AWS CloudFormation to deploy infrastructure. The security team wants to ensure that no sensitive data, such as database passwords, is exposed in plaintext in the CloudFormation templates. What is the MOST secure way to handle secrets?

A.Use AWS KMS to encrypt the secrets and include the ciphertext in the template.
B.Use AWS Systems Manager Parameter Store or AWS Secrets Manager with dynamic references in the template.
C.Store the secrets in an encrypted S3 bucket and include the S3 URL in the template.
D.Pass the secrets as plaintext parameters to the stack at launch time.
AnswerB

Using CloudFormation dynamic references to AWS Systems Manager Parameter Store or AWS Secrets Manager lets the service fetch the secret value at stack create/update time, so the actual secret never appears in the template, AWS CloudFormation API calls, or stack logs. With a parameter reference like 'ssm-secure:MyParameter' or a secretsmanager reference, CloudFormation passes the resolved value directly to the resource while the template retains only the reference. This aligns with least-privilege access and supports rotation, because you can attach a version to the reference and rotate the backing secret without editing the template.

Why this answer

AWS Systems Manager Parameter Store and AWS Secrets Manager support dynamic references in CloudFormation templates, allowing you to reference secret values without exposing them in plaintext. CloudFormation resolves these references at deployment time, retrieving the actual secret value from the secure store, and never stores the secret in the template or stack metadata. This approach ensures secrets are managed, rotated, and audited centrally, adhering to security best practices.

Exam trap

The trap here is that candidates may think encrypting the secret with KMS (Option A) or storing it in an encrypted S3 bucket (Option C) is sufficient, but they overlook that the encrypted data or reference URL is still exposed in the template, and the decryption key or bucket access must be managed separately, which is less secure than using a dedicated secrets service with dynamic references.

How to eliminate wrong answers

Option A is wrong because including ciphertext in the template still exposes the encrypted secret in the template itself, and you would need to manage the KMS key and decryption logic separately, which is less secure and more complex than using a native secrets service. Option C is wrong because storing secrets in an encrypted S3 bucket and including the S3 URL in the template still exposes the URL (and potentially the bucket name) in plaintext, and the template would need IAM permissions to access the bucket, increasing the attack surface. Option D is wrong because passing secrets as plaintext parameters at launch time means the secret value is visible in the CloudFormation console, API logs (AWS CloudTrail), and any automation scripts, violating the requirement to avoid plaintext exposure.

227
MCQhard

A security team uses Amazon Macie to discover sensitive data in S3. They have configured Macie to run automated sensitive data discovery jobs. After reviewing the findings, they notice that some S3 objects containing personally identifiable information (PII) are not being flagged. What is the most likely cause?

A.The Macie service-linked role does not have permissions to read the objects.
B.The S3 bucket is in a different AWS Region than the Macie job.
C.The S3 objects are encrypted with SSE-S3.
D.The PII is in a format that Macie's managed data identifiers do not recognize, and no custom data identifier is configured.
AnswerD

This is correct because Macie relies on managed data identifiers that recognize common PII patterns, such as US Social Security numbers and credit card numbers. If the PII is in a proprietary or less common format that these built-in identifiers do not match, Macie will not flag it. Since no custom data identifier was created to define that specific format, Macie has no way to detect the sensitive data, so the data goes undiscovered.

Why this answer

Macie uses managed data identifiers to detect PII based on predefined patterns. If the PII in the S3 objects is in a format that does not match any of these managed identifiers (e.g., a non-standard date format or a custom ID number), and no custom data identifier has been configured to recognize that specific pattern, Macie will not flag the objects. This is the most likely cause given that the security team has already configured automated discovery jobs and other common issues like permissions or encryption are not preventing scanning.

Exam trap

The trap here is that candidates often assume encryption (SSE-S3) or cross-region issues block Macie, but Macie is designed to handle both seamlessly, and the real limitation is the scope of its pattern-matching identifiers.

How to eliminate wrong answers

Option A is wrong because the Macie service-linked role (AWSServiceRoleForAmazonMacie) is automatically created and granted the necessary permissions (e.g., s3:GetObject, s3:ListBucket) to read objects in S3 buckets that are in scope for the discovery job; if the role lacked permissions, Macie would report an access error, not silently skip objects. Option B is wrong because Macie supports cross-region analysis: a single Macie job can analyze S3 buckets in any AWS Region, as long as the bucket is in the same AWS partition and the Macie service is enabled in the job's home Region. Option C is wrong because Macie can scan objects encrypted with SSE-S3 (Amazon S3-managed keys) without any additional configuration; SSE-S3 encryption does not block Macie's read access because Macie uses the service-linked role to decrypt the objects via S3's server-side decryption.

228
MCQeasy

A security engineer is investigating a potential data exfiltration from an S3 bucket. The engineer needs to identify which IAM role or user accessed the bucket and from which IP address. Which AWS service should the engineer use to obtain this information?

A.AWS CloudTrail
B.AWS Config
C.VPC Flow Logs
D.Amazon GuardDuty
AnswerA

AWS CloudTrail is the correct choice because, for S3 data-plane operations, it logs every API request — including GetObject, PutObject, and ListObjects — with the authenticated IAM principal, source IP, user agent, and the bucket/key requested. Management events like bucket policy changes are also captured. This enables a security engineer to trace exactly who accessed and extracted objects, and when, providing the access-level history needed to investigate exfiltration.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to S3, including the IAM role or user identity (via the `userIdentity` field) and the source IP address (via the `sourceIPAddress` field). For data exfiltration investigation, you need these specific details from management events or data events (e.g., `GetObject`, `PutObject`), which CloudTrail captures. Other services either lack identity-level detail or focus on network-level traffic without user attribution.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (which show network traffic but not user identity) with CloudTrail (which shows API calls with identity), leading them to select VPC Flow Logs for IP-based investigation without realizing they need the IAM role or user context.

How to eliminate wrong answers

Option B (AWS Config) is wrong because it evaluates resource configuration compliance and records configuration changes, not API-level access logs with user identity and source IP. Option C (VPC Flow Logs) is wrong because it captures network traffic metadata (IPs, ports, protocols) at the VPC level but does not include IAM user or role identity, nor does it log S3 API operations. Option D (Amazon GuardDuty) is wrong because it is a threat detection service that analyzes CloudTrail logs, VPC Flow Logs, and DNS logs to identify anomalies; it does not directly provide raw access logs with user identity and source IP for forensic investigation.

229
Multi-Selectmedium

Which TWO actions are valid ways to restrict access to an Amazon S3 bucket using a bucket policy? (Choose two.)

Select 2 answers
A.Use the aws:SourceIp condition key to allow access only from a specific IP range.
B.Use the iam:RoleName condition key to allow access only from a specific IAM role.
C.Use the aws:Referer condition key to allow access only from a specific HTTP referer.
D.Use the aws:SourceVpce condition key to allow access only from a specific VPC.
E.Use the kms:EncryptionContext condition key to require that objects are encrypted with a specific KMS key.
AnswersA, C

The aws:SourceIp condition key is a global condition key that can be used in an S3 bucket policy's Condition block with the IpAddress operator to allow access only from a specific public IP range, such as a corporate egress CIDR. This is valid because S3 evaluates the requester's IP address for most API calls, though it does not apply when the request is made through a VPC endpoint, in which case the source IP is from the endpoint itself.

Why this answer

The `aws:SourceIp` condition key in an S3 bucket policy allows you to restrict access based on the requester's IP address. This is a standard AWS IAM condition that evaluates the source IP of the request, enabling you to permit or deny access from a specific CIDR range. It is commonly used to limit S3 bucket access to a corporate network or a known set of public IPs.

Exam trap

The SCS-C02 exam often tests the distinction between `aws:SourceVpce` (for VPC endpoints) and `aws:SourceVpc` (for VPC-level restrictions), and candidates mistakenly choose `aws:SourceVpce` when the question asks for VPC-wide access control.

230
Multi-Selecthard

A company wants to ensure that all S3 buckets are encrypted at rest. Which THREE services can be used to detect and alert on unencrypted buckets?

Select 3 answers
A.AWS Config
B.Amazon CloudWatch Logs Insights
C.Amazon VPC Flow Logs
D.AWS Security Hub
E.AWS CloudTrail with Amazon CloudWatch Events
AnswersA, D, E

AWS Config provides a managed rule, s3-bucket-server-side-encryption-enabled, that continuously evaluates each S3 bucket's configuration to determine whether default encryption is set to SSE-S3, SSE-KMS, or DSSE. It records the compliance state as a resource configuration history and can trigger automatic remediation actions, such as enabling encryption via a Systems Manager automation document. This gives you ongoing, real-time visibility into unencrypted buckets rather than relying on post-hoc event detection.

Why this answer

AWS Config can evaluate S3 bucket configurations against managed rules like 's3-bucket-server-side-encryption-enabled' to detect unencrypted buckets. When a bucket violates the rule, AWS Config can trigger an Amazon SNS notification or invoke a Lambda function for remediation, enabling real-time alerting.

Exam trap

The trap here is that candidates may think Amazon CloudWatch Logs Insights or VPC Flow Logs can be used for configuration auditing, but they are designed for log analysis and network monitoring, not for detecting resource configuration states like encryption settings.

231
MCQhard

A company has a security requirement to automatically isolate an Amazon EC2 instance that is generating high network traffic to a known malicious IP address. The company uses Amazon GuardDuty and AWS Lambda. Which combination of services and configurations should be used to achieve the isolation?

A.Use VPC Flow Logs to send logs to CloudWatch Logs, then create a metric filter that triggers a Lambda function.
B.Use Amazon GuardDuty to send findings to AWS Systems Manager Automation to run a document that isolates the instance.
C.Use Amazon GuardDuty to send findings to Amazon CloudWatch Events, which triggers an AWS Lambda function that modifies the security group to remove the instance.
D.Use AWS Config rules to detect the traffic and invoke a Lambda function to change the security group.
AnswerC

Amazon GuardDuty is purpose-built to generate security findings based on threat intelligence and anomaly detection, including malicious IP addresses attempting to communicate with EC2 instances. These findings can be delivered as events to Amazon CloudWatch Events (or Amazon EventBridge) using a rule that matches specific finding types, and that rule triggers an AWS Lambda function. The Lambda function can then programmatically modify the instance's security group—removing its association or revoking ingress/egress rules—to automatically isolate the compromised resource. This is a well-established, near-real-time automated response pattern that requires no manual intervention and directly ties a confirmed threat to an infrastructure-level containment action.

Why this answer

Amazon GuardDuty generates findings for threats like communication with known malicious IPs, and these findings can be sent to Amazon CloudWatch Events (now Amazon EventBridge). CloudWatch Events can then trigger an AWS Lambda function that modifies the security group associated with the EC2 instance to remove its inbound/outbound rules, effectively isolating the instance. This automated workflow meets the security requirement without manual intervention.

Exam trap

The trap here is that candidates may think GuardDuty can directly trigger Systems Manager Automation (Option B) without the intermediate CloudWatch Events step, or they may confuse AWS Config's compliance evaluation with real-time network threat detection (Option D).

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs are used for network traffic analysis and logging, not for real-time threat detection; creating a metric filter to trigger a Lambda function would require custom logic to identify malicious IPs and would not leverage GuardDuty's built-in threat intelligence. Option B is wrong because while AWS Systems Manager Automation can run documents to isolate instances, GuardDuty does not natively send findings directly to Systems Manager Automation; it sends findings to CloudWatch Events, which can then trigger Systems Manager Automation, but the option omits the necessary CloudWatch Events integration. Option D is wrong because AWS Config rules are designed for compliance and resource configuration changes, not for detecting network traffic patterns or malicious IP communication; they cannot evaluate VPC Flow Logs or network traffic in real time.

232
Multi-Selecteasy

Which TWO AWS services can be used to detect anomalous API calls in an AWS account?

Select 2 answers
A.AWS CloudTrail with Amazon CloudWatch Logs metric filters.
B.AWS Shield Advanced.
C.Amazon GuardDuty.
D.AWS Config with managed rules.
E.AWS WAF.
AnswersA, C

CloudTrail records all AWS API activity, and when its logs are streamed to CloudWatch Logs, you can create metric filters that match patterns such as repeated AccessDenied errors or a high volume of failed AssumeRole calls. These metric filters feed CloudWatch alarms, enabling near-real-time detection of anomalous API call patterns without requiring external threat feeds or ML models.

Why this answer

AWS CloudTrail with Amazon CloudWatch Logs metric filters is correct because CloudTrail records all API calls, and you can create metric filters on CloudWatch Logs to match patterns indicative of anomalous activity (e.g., unauthorized API calls, root user activity). When the filter triggers a threshold, it can send an alarm via Amazon SNS, enabling detection of anomalous API calls in near real-time.

Exam trap

The trap here is that candidates often confuse AWS Config's compliance evaluation (which checks resource configurations) with API call monitoring, leading them to select AWS Config instead of recognizing that only CloudTrail and GuardDuty (which uses CloudTrail logs and VPC Flow Logs for anomaly detection) can detect anomalous API calls.

233
MCQhard

A company uses AWS Organizations with multiple accounts. The security team wants to ensure that no IAM user in any account can create or modify IAM roles. What is the MOST effective way to enforce this?

A.Use AWS Config rules to detect role creation and automatically delete the roles.
B.Set up a Lambda function that monitors CloudTrail and revokes role creation permissions.
C.Create an SCP that denies iam:CreateRole and iam:UpdateAssumeRolePolicy and attach it to the root organizational unit.
D.Create an IAM policy that denies role creation and attach it to each user in every account.
AnswerC

This is the correct answer because an SCP attached to the root organizational unit is immediately inherited by all member accounts and acts as a preventive guardrail that cannot be overridden by any IAM policy, including the account administrator. Explicitly denying iam:CreateRole stops creation of new roles, and denying iam:UpdateAssumeRolePolicy prevents an attacker from modifying an existing role's trust policy to assume it from an untrusted account. Unlike reactive controls, SCPs take effect before the API call is allowed, and they can be managed centrally by the organization's management account.

Why this answer

The most effective way to enforce a deny across all accounts in AWS Organizations is a Service Control Policy (SCP) attached to the root organizational unit, denying iam:CreateRole and iam:UpdateAssumeRolePolicy. SCPs set the maximum permissions boundary for all principals in member accounts, so attaching a deny SCP at the root OU ensures no IAM user in any account can create or modify roles, regardless of their IAM policies. This is centralized, preventive, and cannot be bypassed by account-level admins.

Exam trap

SCS-C02 often tests the difference between preventive controls (SCPs) and detective/reactive controls (Config, Lambda) — candidates who pick reactive options miss the 'MOST effective' preventive requirement.

How to eliminate wrong answers

Option A is wrong because AWS Config rules are detective and reactive — they detect role creation after the fact and trigger deletion, which is not preventive and leaves a window of exposure. Option B is wrong because a Lambda-based revocation is also reactive, adds latency, and is operationally fragile compared to a native preventive control. Option D is wrong because attaching an IAM deny policy to each user in every account is not scalable, can be removed by account admins, and does not cover new users or accounts — SCPs are the correct centralized mechanism.

234
MCQmedium

A security engineer runs the above AWS CLI command. The engineer notices that the security group has no outbound rules. What is the implication of this configuration?

A.The EC2 instances in this security group cannot initiate outbound connections
B.The EC2 instances cannot receive inbound HTTP traffic
C.The security group allows all outbound traffic by default
D.Outbound traffic is allowed because security groups are stateful
AnswerA

Security groups are stateful and allow all outbound traffic by default; removing every outbound rule leaves no permit, so instances cannot initiate connections. Return traffic for inbound-initiated flows still passes, but new outbound sessions are blocked.

Why this answer

Security groups are stateful and, by default, allow all outbound traffic; however, if outbound rules are explicitly removed, the group has no rule permitting egress, so instances cannot initiate outbound connections. Return traffic for allowed inbound connections is still permitted due to statefulness, but new outbound-initiated flows are blocked. Thus the correct implication is that outbound connections cannot be initiated.

Exam trap

The trap is assuming statefulness means outbound is always allowed — statefulness only covers return traffic for established flows, not new outbound-initiated connections when no egress rule exists.

How to eliminate wrong answers

Option B is wrong because inbound HTTP traffic is governed by inbound rules, not the absence of outbound rules; the scenario says nothing about inbound being blocked. Option C is wrong because while security groups allow all outbound by default, the question states outbound rules were removed, so the default no longer applies. Option D is wrong because statefulness only permits return traffic for established inbound flows; it does not permit new outbound-initiated connections when no outbound rule allows them.

235
MCQmedium

A security engineer is setting up automated incident response for a compromised IAM user. The engineer wants to automatically revoke the user's access keys and attach a deny-all policy when a GuardDuty finding of type 'UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration' is generated. Which services should be used to achieve this automation?

A.Amazon Simple Notification Service (SNS) and AWS Lambda
B.AWS Config and AWS Lambda
C.Amazon CloudWatch Events and AWS Lambda
D.AWS Systems Manager Automation and AWS Lambda
AnswerC

Amazon CloudWatch Events (now Amazon EventBridge) detects the GuardDuty finding via a rule filtering on the specific finding type, then invokes an AWS Lambda function. The Lambda function executes the IAM API calls to revoke access keys and attach a deny-all policy, satisfying the requirement for automated, event-driven remediation without manual intervention.

Why this answer

Amazon CloudWatch Events (now part of Amazon EventBridge) can capture GuardDuty findings in real-time and trigger a Lambda function to revoke IAM user access keys and attach a deny-all policy. This is the native, event-driven pattern for automated incident response to GuardDuty findings, as CloudWatch Events directly supports GuardDuty as an event source.

Exam trap

The trap here is that candidates often confuse CloudWatch Events with SNS or Config, not realizing that CloudWatch Events is the only service that natively integrates with GuardDuty as an event source for real-time, automated remediation workflows.

How to eliminate wrong answers

Option A is wrong because Amazon SNS alone cannot trigger a Lambda function in response to GuardDuty findings; SNS requires a subscription and does not natively filter GuardDuty events. Option B is wrong because AWS Config is designed for resource compliance and configuration history, not for real-time event-driven response to security findings like GuardDuty. Option D is wrong because AWS Systems Manager Automation is intended for managing EC2 instances and on-premises servers, not for revoking IAM user credentials or attaching IAM policies.

236
MCQhard

A company has a VPC with a public subnet and a private subnet. The public subnet hosts a NAT instance (Amazon Linux) that provides internet access to instances in the private subnet. The security team notices that the NAT instance is receiving high inbound traffic on port 22 from an external IP address. The team wants to block this traffic at the network layer without affecting other traffic. What is the most effective solution?

A.Move the NAT instance to a private subnet and use a NAT gateway instead.
B.Modify the security group attached to the NAT instance to block inbound SSH from the specific IP.
C.Use AWS WAF to block the IP address.
D.Add a network ACL rule on the public subnet to deny inbound traffic from the specific IP on port 22.
AnswerD

A network ACL is a stateless, subnet-level firewall that supports explicit DENY rules with numeric precedence, allowing you to block traffic from a specific source IP on a specific port. Adding a deny rule for that IP and port 22 on the public subnet's NACL will be evaluated before traffic reaches the NAT instance, while still permitting all other inbound traffic. This is the correct approach because NACLs operate at the VPC edge and support the granular, deny-based filtering that security groups cannot provide.

Why this answer

A network ACL (NACL) operates at the subnet level (layer 3/4) and is stateless, meaning it can explicitly deny inbound traffic from a specific IP on port 22 before it reaches the NAT instance. This blocks the traffic at the network layer without affecting other traffic, as NACLs evaluate rules in order and deny rules override allow rules for the specified traffic. Unlike security groups, NACLs do not require the traffic to first reach the instance, making them ideal for blocking unwanted traffic at the subnet boundary.

Exam trap

The trap here is that candidates often choose security groups (Option B) because they are familiar with them, but the question explicitly requires blocking at the network layer, and NACLs are the correct layer 3/4 subnet-level control, while security groups are instance-level and stateful, making them unsuitable for this specific requirement.

How to eliminate wrong answers

Option A is wrong because moving the NAT instance to a private subnet and using a NAT gateway does not block the inbound SSH traffic; it only changes the architecture and still leaves the NAT instance (or gateway) exposed to the same traffic if the subnet's route table or ACLs are not updated. Option B is wrong because modifying the security group attached to the NAT instance to block inbound SSH from the specific IP would work at the instance level, but security groups are stateful and operate at the instance level, not the network layer; the traffic would still reach the instance's network interface before being evaluated, and the question specifically asks to block at the network layer. Option C is wrong because AWS WAF is a web application firewall that operates at layer 7 (application layer) and is designed to protect web applications (e.g., ALB, CloudFront), not to block SSH traffic at the network layer; it cannot filter SSH traffic on port 22.

237
MCQhard

A company runs a critical application on EC2 instances behind an Application Load Balancer. The security team suspects that a DDoS attack is targeting the application. Which AWS service can be used to absorb and mitigate the attack at the network layer before traffic reaches the ALB?

A.AWS WAF
B.AWS Identity and Access Management (IAM)
C.Network ACLs
D.AWS Shield Advanced
AnswerD

AWS Shield Advanced is the purpose-built DDoS mitigation service that protects at the network and transport layers (Layers 3 and 4), covering SYN floods, UDP reflection attacks, and other high-volume floods against EC2 instances and associated Elastic IPs. It provides always-on detection, automatic inline mitigation, and access to the AWS DDoS Response Team (DRT) for rapid manual intervention in complex attacks. For a critical EC2 application, Shield Advanced is the correct choice because it is designed to maintain availability when incoming attack traffic saturates the network path, and it offers cost protection against scaling charges triggered by attacks.

Why this answer

AWS Shield Advanced provides enhanced protections against larger and more sophisticated DDoS attacks, including network-layer (Layer 3/4) attacks such as UDP floods, SYN floods, and reflection attacks. It integrates directly with Application Load Balancers to absorb and mitigate malicious traffic before it reaches the ALB, ensuring the application remains available. This makes it the correct choice for mitigating a DDoS attack at the network layer.

Exam trap

The trap here is that candidates often confuse AWS WAF (Layer 7) with network-layer protection, or assume that Network ACLs can handle DDoS attacks, but only AWS Shield Advanced provides dedicated, scalable mitigation for Layer 3/4 attacks at the network perimeter.

How to eliminate wrong answers

Option A is wrong because AWS WAF operates at Layer 7 (application layer) and is designed to filter HTTP/HTTPS requests based on rules like SQL injection or cross-site scripting, not to absorb network-layer DDoS attacks. Option B is wrong because AWS Identity and Access Management (IAM) is a service for managing user permissions and access control, not for mitigating DDoS attacks. Option C is wrong because Network ACLs are stateless firewall rules that filter traffic at the subnet level, but they cannot absorb or scale to mitigate large volumetric DDoS attacks; they are also not designed for attack mitigation and can be overwhelmed by high-volume traffic.

238
MCQmedium

A security engineer is designing an automated incident response workflow for an Amazon EC2 instance that is compromised. The workflow must isolate the instance by removing it from the security group that allows SSH access. The engineer wants to use AWS Systems Manager Automation to run a document. What is the most secure way to grant the automation the necessary permissions to modify the security group?

A.Create a Systems Manager Automation service role with a least-privilege policy that includes ec2:ModifySecurityGroupRules and use that role in the automation.
B.Create an AWS Lambda function with permissions to modify the security group and call it from the automation.
C.Use the IAM user's permissions that trigger the automation.
D.Attach an IAM policy to the EC2 instance's instance profile that allows ec2:ModifySecurityGroupRules.
AnswerA

The correct approach is to create a dedicated Systems Manager Automation service role with a least-privilege IAM policy that grants only ec2:ModifySecurityGroupRules (ideally scoped to specific security group resource ARNs). During execution, the Automation document assumes this service role to call EC2 APIs directly via aws:executeAwsApi, so the user who triggers the run only needs ssm:StartAutomationExecution and iam:PassRole. This keeps the blast radius minimal and follows the principle of least privilege, as the service role exists solely for the automation's intended actions.

Why this answer

Systems Manager Automation can assume a dedicated service role with a least-privilege IAM policy that includes the specific action `ec2:ModifySecurityGroupRules`. This follows the security best practice of granting only the permissions required for the automation to modify the security group, without exposing broader privileges or relying on user or instance credentials.

Exam trap

The trap here is that candidates often confuse the instance profile role (used for the EC2 instance's own actions) with the automation service role (used for the Systems Manager service to perform actions on behalf of the engineer), leading them to incorrectly choose Option D.

How to eliminate wrong answers

Option B is wrong because introducing an AWS Lambda function adds unnecessary complexity and an additional attack surface; the automation can directly modify the security group via an assumed role without needing a middleman. Option C is wrong because using the IAM user's permissions violates the principle of least privilege and creates a security risk if the user has more permissions than needed; the automation should use a dedicated role, not inherit user credentials. Option D is wrong because attaching a policy to the EC2 instance profile grants permissions to the instance itself, not to the Systems Manager Automation service; the automation runs independently of the compromised instance and should not rely on the instance's role for incident response actions.

239
Multi-Selectmedium

A security engineer is designing a centralized logging solution for multiple AWS accounts. Which TWO services should be used to aggregate logs from all accounts into a single account? (Choose TWO.)

Select 2 answers
A.AWS Config
B.VPC Flow Logs
C.Amazon CloudWatch Logs
D.Amazon S3
E.AWS CloudTrail
AnswersC, E

Amazon CloudWatch Logs is correct because you can create a cross-account destination in a central account—for example, a Kinesis Data Streams stream or an Amazon OpenSearch Service cluster—and attach a subscription filter in each source account's log group to stream log events to that destination. The CloudWatch Logs destination resource holds the ARN of the central resource and an IAM role that grants the source account permission to send data. This natively supports the real-time, centralized log collection that the scenario requires.

Why this answer

Amazon CloudWatch Logs can receive log data from multiple AWS accounts via cross-account subscription filters, allowing a centralized logging account to aggregate logs from all source accounts. AWS CloudTrail can be configured to deliver trail logs from multiple accounts to a single S3 bucket in a central account, enabling consolidated audit logging. Together, these two services provide a comprehensive centralized logging solution for multi-account environments.

Exam trap

The trap here is that candidates often confuse log destinations (like S3) with log aggregation services, failing to recognize that S3 is a passive storage target and does not actively collect or aggregate logs from multiple accounts without the orchestration provided by CloudWatch Logs or CloudTrail.

240
MCQmedium

A company wants to securely store secrets used by an application running on EC2 instances. The secrets include database credentials and API keys. What is the MOST secure and manageable approach?

A.Store the secrets in the EC2 instance user data and retrieve them from the metadata service.
B.Embed the secrets in the application code and encrypt the code with a KMS key.
C.Use AWS Secrets Manager and attach an IAM role to the EC2 instance with permission to access the secrets.
D.Use AWS Systems Manager Parameter Store with a SecureString parameter and reference it in the application code.
AnswerC

Correct. AWS Secrets Manager integrates with IAM roles for EC2 instances, providing fine-grained access control, automatic secret rotation, and auditing. This is the most secure and manageable approach for storing database credentials and API keys.

Why this answer

AWS Secrets Manager is purpose-built for storing, rotating, and retrieving secrets such as database credentials and API keys. Attaching an IAM role to the EC2 instance allows the application to retrieve secrets securely without hardcoding credentials, and Secrets Manager supports automatic rotation, auditing via CloudTrail, and fine-grained access control. This is the most secure and manageable approach.

Exam trap

The trap is choosing Parameter Store SecureString because it is also secure and cheaper; however, the question emphasizes 'most secure and manageable,' and Secrets Manager's native rotation and management features make it the better answer.

How to eliminate wrong answers

Option A is wrong because user data and the metadata service are not secure for secrets — user data is visible in the console and metadata can be accessed by any process on the instance, and there is no rotation or auditing. Option B is wrong because embedding secrets in code (even encrypted) is an anti-pattern; secrets become part of the deployment artifact and are hard to rotate. Option D is wrong because while Parameter Store SecureString is secure, it lacks native rotation and is less feature-rich for secret management compared to Secrets Manager; the question asks for the MOST secure and manageable, and Secrets Manager with IAM role is the best fit.

241
MCQeasy

Refer to the exhibit. A security engineer is reviewing an S3 bucket policy. The policy is intended to allow access only from the corporate network (10.0.0.0/8). What is a potential security issue with this policy?

A.The policy allows anonymous access from the specified IP range.
B.The policy grants access to all actions, not just GetObject.
C.The policy resource is incorrect; it should be the bucket ARN without the /*.
D.The policy does not include a condition to require MFA.
AnswerA

The policy's Principal element is set to "*", which means every principal—whether an authenticated IAM identity or an anonymous internet client—is a match. The only limiting factor is the IpAddress condition, so any request originating from the specified CIDR range is allowed without requiring AWS credentials. This effectively exposes the objects to anonymous read access from that IP range, which is exactly the vulnerability described.

Why this answer

The policy's `Principal: "*"` element allows anonymous access from any IP address, and the `Condition` block only restricts the source IP to 10.0.0.0/8. This means any unauthenticated request originating from within the corporate network (10.0.0.0/8) is permitted, effectively granting anonymous access to the S3 bucket. The intended goal of restricting access to authenticated corporate users is not achieved, as no `aws:userid` or `aws:username` condition is enforced.

Exam trap

The trap here is that candidates assume an IP address condition in a bucket policy automatically implies authenticated access, but AWS explicitly allows anonymous access when `Principal: "*"` is used, even with IP restrictions.

How to eliminate wrong answers

Option B is wrong because the policy uses `Action: "s3:GetObject"` which is a specific read action, not all actions; the issue is about authentication, not action scope. Option C is wrong because the resource ARN `arn:aws:s3:::example-bucket/*` is correct for object-level operations like GetObject; the bucket ARN without `/*` would be needed for bucket-level operations (e.g., ListBucket). Option D is wrong because MFA is not required by the scenario; the policy's flaw is allowing anonymous access, not the absence of MFA, and MFA is typically enforced via a separate condition key (`aws:MultiFactorAuthPresent`).

242
Multi-Selecthard

A company uses AWS CloudTrail to log all API activity. The security team wants to detect when an IAM user creates an access key for another user, which is a potential privilege escalation. Which TWO actions should the team take to set up this detection?

Select 2 answers
A.Create an AWS Config managed rule to detect CreateAccessKey calls.
B.Create a CloudWatch alarm based on the metric filter.
C.Create a CloudWatch Logs metric filter that matches the event CreateAccessKey.
D.Use Amazon EventBridge to create a rule that matches the CloudTrail event and triggers an AWS Lambda function.
E.Enable Amazon GuardDuty and create a custom threat list.
AnswersB, C

A CloudWatch alarm triggered by a metric filter converts matching CloudTrail events into an actionable notification. The filter patterns on CreateAccessKey events, and the alarm fires when the threshold is breached, satisfying the requirement to detect access key creation for another user.

Why this answer

Option C is correct because CloudTrail delivers API activity to a CloudWatch Logs log group, and a metric filter with a filter pattern matching the eventName "CreateAccessKey" converts those log events into a numeric CloudWatch metric that can be alarmed on. Option B is correct because a CloudWatch alarm on that metric filter's metric fires when the metric crosses the threshold, which is the standard way to detect and notify on the specific CreateAccessKey activity. Option A is not appropriate because AWS Config managed rules evaluate resource configuration compliance, not individual API calls.

Option D is not correct for this two-action pair because an EventBridge rule that triggers a Lambda function is a separate single-step alternative, not one of the two actions needed in the CloudWatch Logs metric filter and alarm setup. Option E is wrong because GuardDuty custom threat lists are for IP addresses and domains, not for detecting specific IAM API calls.

Exam trap

The trap here is that candidates often confuse AWS Config managed rules (which evaluate resource state) with CloudTrail event detection (which requires log-based monitoring), leading them to select Option A instead of the correct CloudWatch Logs metric filter and alarm pair.

243
MCQeasy

A security engineer needs to ensure that an Amazon RDS database instance is not accessible from the internet. Which configuration step will achieve this?

A.Deploy the DB instance in a multi-AZ configuration.
B.Set the DB instance to be publicly accessible and restrict security group inbound rules.
C.Set the DB instance to be not publicly accessible and place it in a private subnet.
D.Use the default VPC security group for the DB instance.
AnswerC

Marking the DB instance as not publicly accessible prevents RDS from assigning any public IP address, and placing it in a private subnet with no route to an internet gateway ensures no inbound traffic can reach it from the internet. The database will only be reachable through its private IP address within the VPC, and clients must connect via resources in the same VPC, a VPN, or a bastion host. This configuration is the AWS best practice for database isolation.

Why this answer

Setting a DB instance to be not publicly accessible ensures that it does not receive a public IP address, and placing it in a private subnet (one without a route to an internet gateway) prevents any direct inbound or outbound traffic from the internet. This combination guarantees that the RDS instance is isolated from the public internet, aligning with the security requirement.

Exam trap

The trap here is that candidates often assume security group rules alone can fully control internet access, overlooking the critical distinction between public and private IP assignment and subnet routing that determines actual internet reachability.

How to eliminate wrong answers

Option A is wrong because deploying in a multi-AZ configuration provides high availability and failover support, but does not affect network accessibility; the DB instance can still be publicly accessible if configured otherwise. Option B is wrong because setting the DB instance to be publicly accessible assigns a public IP address, and while restricting security group inbound rules can limit traffic, the instance itself remains reachable from the internet, violating the requirement. Option D is wrong because using the default VPC security group does not inherently prevent internet access; the default security group typically allows all outbound traffic and may have permissive inbound rules, and the instance could still be publicly accessible if placed in a public subnet.

244
MCQhard

A company uses AWS KMS to encrypt data in Amazon S3. The security team needs to audit all KMS key usage, including who used the key, when, and what operation was performed. Which AWS service should be used to meet this requirement?

A.AWS CloudTrail
B.Amazon GuardDuty
C.AWS Config
D.AWS CloudHSM
AnswerA

AWS CloudTrail is correct because it records KMS API calls, including management-plane operations like CreateKey, ScheduleKeyDeletion, and PutKeyPolicy, and data-plane operations such as Encrypt, Decrypt, and GenerateDataKey when data events are enabled. When an S3 object encrypted with SSE-KMS is accessed, CloudTrail generates an event for the corresponding KMS Decrypt call, providing a complete audit trail of who used which key, when, and from what context. These logs can be delivered to an S3 bucket and optionally sent to CloudWatch Logs for alerting and forensic analysis, making CloudTrail the definitive service for KMS-related audit and compliance.

Why this answer

AWS CloudTrail is the correct service because it records all AWS KMS API calls as events, including who made the request, the source IP address, the time of the request, and the specific operation performed (e.g., Encrypt, Decrypt, GenerateDataKey). These audit logs are stored in an S3 bucket and can be analyzed to meet the security team's requirement for full key usage auditing.

Exam trap

The trap here is that candidates often confuse AWS Config's compliance monitoring with CloudTrail's API auditing, or assume GuardDuty's threat detection includes detailed usage logs, when in fact only CloudTrail provides the granular, user-specific API call records required for auditing KMS key usage.

How to eliminate wrong answers

Option B (Amazon GuardDuty) is wrong because it is a threat detection service that monitors for malicious activity using anomaly detection and threat intelligence, not a service that records detailed API-level audit logs of KMS key usage. Option C (AWS Config) is wrong because it evaluates resource configurations and compliance rules (e.g., whether KMS keys have automatic rotation enabled), but it does not capture who performed KMS operations or when they occurred. Option D (AWS CloudHSM) is wrong because it provides dedicated hardware security modules for key generation and storage, but it does not generate audit logs of API calls; CloudHSM logs are limited to HSM-level events and require separate integration with CloudTrail for API auditing.

245
MCQeasy

A company has a requirement to audit all API calls made to AWS services in their account. Which AWS service should be used to meet this requirement?

A.AWS Config
B.Amazon Inspector
C.Amazon GuardDuty
D.AWS CloudTrail
AnswerD

AWS CloudTrail is the correct service because it logs every API call made to AWS services as an event, capturing the identity of the caller, the time of the call, source IP address, request parameters, and the response returned. These events can be delivered to Amazon S3 and CloudWatch Logs, and queried via Athena, enabling a complete, tamper-evident audit trail. CloudTrail trails can record management events, data events, and insights events, making it the authoritative source for API auditing across the account or organization.

Why this answer

AWS CloudTrail records all API calls made to AWS services in an account, capturing the identity of the caller, the time, the source IP, the request parameters, and the response. It is the authoritative service for auditing API activity across the AWS account, and it can deliver logs to S3, CloudWatch Logs, or EventBridge for analysis and alerting. Enabling CloudTrail in all regions with log file validation is a standard compliance requirement.

Exam trap

The trap is confusing CloudTrail (API audit logging) with AWS Config (resource configuration history) or GuardDuty (threat detection) — candidates often pick Config because it also provides a history, but only CloudTrail logs every API call.

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configuration changes and evaluates compliance against rules, but it does not log every API call — it tracks resource state, not the full API audit trail. Option B is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances, container images, and Lambda functions for software vulnerabilities and network exposure, not API activity. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes CloudTrail, VPC Flow Logs, and DNS logs for malicious activity, but it does not itself provide the raw audit log of all API calls — that is CloudTrail's role.

246
Multi-Selectmedium

Which TWO actions can be taken to improve the security of an Amazon RDS for MySQL database instance? (Choose TWO.)

Select 2 answers
A.Place the RDS instance in a private subnet and restrict inbound traffic to the application security group.
B.Disable automated backups to reduce storage costs.
C.Enable Multi-AZ deployment for fault tolerance.
D.Assign a public IP address to the RDS instance for easier access from the internet.
E.Enable encryption at rest using AWS KMS.
AnswersA, E

Placing the RDS instance in a private subnet removes any route to an internet gateway, so it cannot be reached directly from the internet. Restricting inbound rules to the application's security group enforces least-privilege access, permitting only the application tier on the MySQL port.

Why this answer

Option A is correct because placing the RDS for MySQL instance in a private subnet removes it from direct internet reachability, and restricting inbound traffic to only the application's security group enforces least-privilege network access at the database port (3306 for MySQL). Option E is correct because enabling encryption at rest with AWS KMS protects the underlying storage, automated backups, read replicas, and snapshots, so data cannot be read if the storage media is compromised. Option B is incorrect because disabling automated backups reduces recoverability and does not improve security.

Option C is incorrect because Multi-AZ is a high-availability/fault-tolerance feature, not a security control. Option D is incorrect because assigning a public IP address exposes the database to the internet and increases the attack surface.

Exam trap

The trap here is that candidates often confuse high availability (Multi-AZ) or cost-saving measures (disabling backups) with security controls, when in fact they do not address confidentiality, integrity, or access control.

247
MCQmedium

A company is using Amazon S3 to store backup files that must be retained for 7 years. The files are accessed infrequently but must be available within minutes when needed. The company wants to minimize storage costs while ensuring data is encrypted at rest. Which storage class and encryption combination is most cost-effective?

A.S3 Glacier Instant Retrieval with SSE-S3
B.S3 Glacier Deep Archive with SSE-S3
C.S3 Glacier Flexible Retrieval with SSE-KMS
D.S3 Standard-IA with SSE-KMS
AnswerA

S3 Glacier Instant Retrieval provides millisecond access to backup files while offering a lower storage price than S3 Standard-IA, making it both fast and cost-effective for backups that must be available immediately. Using SSE-S3 for encryption adds no per-object or per-API charges, so you satisfy the server-side encryption requirement without increasing the cost of the solution. This combination directly meets the stated need for instant retrieval and economical long-term storage.

Why this answer

S3 Glacier Instant Retrieval provides millisecond retrieval (meeting the 'within minutes' requirement) at lower cost than S3 Standard-IA, and SSE-S3 provides encryption at rest at no additional cost. This combination minimizes storage costs while meeting access and encryption requirements.

Exam trap

The trap is choosing Glacier Deep Archive for cost savings while ignoring the retrieval time requirement, or assuming SSE-KMS is required for encryption when SSE-S3 is sufficient and free.

How to eliminate wrong answers

Option B is wrong because Glacier Deep Archive has retrieval times of 12 hours, not minutes, so it fails the availability requirement. Option C is wrong because Glacier Flexible Retrieval has retrieval times of 1-5 minutes (or minutes to hours), which may meet 'within minutes' but is more expensive than Instant Retrieval for frequent access, and SSE-KMS adds cost. Option D is wrong because S3 Standard-IA is more expensive than Glacier Instant Retrieval for long-term storage and SSE-KMS adds KMS costs.

248
MCQeasy

A company uses S3 to store sensitive customer data. Which AWS service can automatically discover and classify this data to help meet compliance requirements?

A.Amazon GuardDuty
B.AWS Config
C.Amazon CloudWatch
D.Amazon Macie
AnswerD

Amazon Macie is purpose-built to discover, monitor, and classify sensitive data stored in Amazon S3 using machine learning and built-in managed data identifiers such as personally identifiable information (PII), financial data, and credentials. It automatically inventories buckets, evaluates object-level risk, and generates actionable findings/alerts when sensitive data is detected. This makes Macie the correct answer for automatically discovering and classifying sensitive customer data.

Why this answer

Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data stored in Amazon S3. It specifically identifies PII, PHI, credentials, and other sensitive content, generating findings that support compliance requirements such as GDPR, HIPAA, and PCI-DSS. This is the exact purpose for which Macie was designed.

Exam trap

SCS-C02 often tests the distinction between services that detect threats (GuardDuty) versus services that classify data content (Macie) — candidates frequently confuse GuardDuty's S3 protection with Macie's data classification role.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior using VPC Flow Logs, CloudTrail, and DNS logs — it does not classify or discover sensitive data content in S3. Option B is wrong because AWS Config is a configuration compliance service that records resource configuration changes and evaluates them against rules; it does not inspect data content for sensitive information. Option C is wrong because Amazon CloudWatch is a monitoring and observability service for metrics, logs, and alarms — it has no data classification or sensitive-data discovery capability.

249
MCQhard

An IAM policy has the following statement: {"Effect":"Deny","Action":"*","Resource":"*","Condition":{"Bool":{"aws:SecureTransport":"false"}}}. What does this policy achieve?

A.Denies all actions that are not made over HTTPS
B.Allows all actions only when using HTTPS
C.Enforces HTTPS for S3 bucket policies only
D.Blocks all actions for a specific AWS service
AnswerA

This IAM policy statement uses a Deny effect with the aws:SecureTransport condition key set to 'false', so it blocks any API call that was not transmitted over a TLS/HTTPS connection. Because an explicit Deny takes precedence over all Allow statements, the policy stops every non-HTTPS request to any AWS service, while leaving HTTPS requests unaffected. The condition applies to the transport-layer security of the request itself, not to the specific action or resource, making the statement a global enforcement of HTTPS for all AWS API operations.

Why this answer

This policy statement uses the `aws:SecureTransport` condition key with a `Bool` condition set to `false`. When the condition evaluates to true (i.e., the request is not using HTTPS/TLS), the `Deny` effect applies to all actions on all resources. This effectively denies any API call made over HTTP (non-secure transport), ensuring that only HTTPS requests are allowed.

The policy does not explicitly allow anything; it only denies non-HTTPS traffic, so all actions are implicitly allowed when made over HTTPS.

Exam trap

The trap here is that candidates often confuse a `Deny` with a `Bool` condition as an implicit `Allow` for the opposite condition, but the policy only denies non-HTTPS requests and does not grant any explicit allow, so all actions are allowed by default when HTTPS is used.

How to eliminate wrong answers

Option B is wrong because the policy does not contain an `Allow` statement; it only denies non-HTTPS requests, so it does not affirmatively allow actions. Option C is wrong because the policy applies to all AWS services and resources, not just S3 bucket policies; the `Resource` is `*`, meaning it covers every service. Option D is wrong because the policy does not block all actions for a specific service; it blocks all actions across all services only when the request is not using HTTPS.

250
MCQmedium

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The security team requires that all traffic between the ALB and EC2 instances be encrypted. Which configuration ensures this requirement is met?

A.Use an HTTPS listener on the ALB and configure the target group with HTTPS.
B.Use a TCP listener on the ALB and a TCP target group.
C.Configure security group inbound rules to allow only HTTPS traffic.
D.Use an HTTP listener on the ALB and HTTP on the target group.
AnswerA

Configuring the ALB listener for HTTPS encrypts client-to-ALB traffic, and setting the target group protocol to HTTPS makes the ALB re-encrypt traffic to the EC2 instances. This end-to-end TLS configuration satisfies the requirement that ALB-to-instance traffic be encrypted.

Why this answer

It ensures end-to-end encryption between the ALB and EC2 instances. By configuring an HTTPS listener on the ALB, traffic from clients to the ALB is encrypted. Then, by setting the target group protocol to HTTPS, the ALB re-encrypts the traffic before forwarding it to the EC2 instances, fulfilling the security team's requirement that all traffic between the ALB and EC2 instances be encrypted.

Exam trap

The trap here is that candidates assume an HTTPS listener alone encrypts all traffic end-to-end, forgetting that the ALB-to-instance leg must also use HTTPS; otherwise, traffic between the ALB and EC2 instances is in plaintext.

How to eliminate wrong answers

Option B is wrong because a TCP listener and TCP target group operate at Layer 4 and do not provide encryption; they forward raw TCP traffic without TLS/SSL termination or re-encryption. Option C is wrong because security group inbound rules only control access at the network level (allowing or denying traffic based on port/protocol) and do not encrypt traffic; encryption is a function of the protocol (HTTPS/TLS), not security group rules. Option D is wrong because using HTTP on both the listener and target group means traffic is transmitted in plaintext at every hop, with no encryption between the ALB and EC2 instances.

251
MCQeasy

A company uses Amazon GuardDuty to detect threats. The security team wants to receive real-time notifications for all GuardDuty findings with a severity of HIGH or CRITICAL. What is the MOST efficient way to achieve this?

A.Create a CloudWatch Events rule that matches GuardDuty findings with severity HIGH or CRITICAL and targets an SNS topic.
B.Use the GuardDuty console to set up email alerts for high-severity findings.
C.Configure GuardDuty to export findings to an S3 bucket and use S3 event notifications to trigger an SNS topic.
D.Stream GuardDuty findings to CloudWatch Logs and create a metric filter to trigger an alarm.
AnswerA

GuardDuty publishes every finding to Amazon EventBridge (formerly CloudWatch Events) in near real-time as it is generated, with the finding's severity encoded in the detail.payload.severity field. A rule with an event pattern matching severity labels HIGH or CRITICAL (numeric values 7 and 8) can invoke an SNS topic, giving you the lowest-latency, fully managed notification path. This is the correct approach because it uses the native event bus rather than relying on polling or periodic exports.

Why this answer

Amazon GuardDuty integrates natively with Amazon CloudWatch Events (now part of Amazon EventBridge) to emit findings as events. By creating a CloudWatch Events rule that filters for findings with a severity value of 7.0 or higher (HIGH or CRITICAL), you can directly target an Amazon SNS topic to send real-time notifications. This approach is the most efficient as it avoids intermediate storage or polling, providing near-instantaneous alerting with minimal latency and operational overhead.

Exam trap

The trap here is that candidates may think exporting to S3 or CloudWatch Logs is necessary for analysis, but for real-time notifications, CloudWatch Events (EventBridge) is the direct and most efficient integration, avoiding unnecessary intermediate steps.

How to eliminate wrong answers

Option B is wrong because the GuardDuty console does not provide a native feature to set up email alerts directly; it relies on integrations like CloudWatch Events or SNS for automated notifications. Option C is wrong because exporting findings to an S3 bucket and using S3 event notifications introduces unnecessary latency and complexity, as S3 event notifications are not designed for real-time alerting and may have delays of several minutes. Option D is wrong because streaming findings to CloudWatch Logs and creating a metric filter to trigger an alarm adds extra steps and potential delays, whereas CloudWatch Events provides a more direct and real-time path without the need for log ingestion and metric evaluation.

252
MCQeasy

A company wants to enforce that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. The security team creates an IAM policy that denies all actions unless MFA is present. However, users report they can still perform actions without MFA. What is the most likely reason for this?

A.MFA policies only apply to API calls, not console access.
B.The policy does not include a condition to check for MFA, or the condition is incorrect.
C.The users are using root account credentials, which bypass MFA policies.
D.The policy was attached to the wrong IAM group.
AnswerB

This is the most likely reason. To enforce MFA, the policy must include a condition such as 'aws:MultiFactorAuthPresent': 'true' in a Deny statement. If the condition is missing or misspelled, the deny will not trigger. Additionally, the condition must be in a policy that applies to the users' actions. Often, administrators forget to include the condition or use the wrong key, allowing actions without MFA.

Why this answer

The most likely reason is that the policy does not include a condition to check for MFA, or the condition is incorrect. To enforce MFA, the policy must include a Deny statement with a condition like 'aws:MultiFactorAuthPresent': 'false' or 'true' depending on the logic. If the condition is missing, the deny will not be effective.

It is also important to ensure the policy is attached to all users or groups.

Exam trap

The trap here is assuming that simply creating a policy with a deny statement automatically enforces MFA, when in fact the policy must include the correct MFA condition key and be properly attached.

253
MCQhard

A company uses Amazon GuardDuty to monitor for malicious activity in its AWS environment. The security team receives a high number of findings, many of which are false positives. They want to reduce noise by suppressing findings for known benign activities, such as internal vulnerability scans performed by the security team. GuardDuty has a feature to create suppression rules based on finding criteria. However, the team also wants to ensure that if a new type of threat is detected, it is immediately escalated. What is the MOST effective way to manage GuardDuty findings?

A.Set GuardDuty to only generate findings for medium and high severity, ignoring low severity findings.
B.Create a suppression rule that blocks all findings from the internal IP range used by the security team.
C.Disable the specific GuardDuty finding types that generate false positives.
D.Create suppression rules that automatically archive findings matching the known benign activity criteria, and periodically review the suppressed findings.
AnswerD

Creating suppression rules that match the exact criteria of the known benign activity lets GuardDuty automatically archive those findings while still generating every other finding for review. Because suppression does not delete findings, you can periodically audit the Suppressed tab to ensure the criteria still reflect genuinely innocuous behavior and to adjust for evolving threat intelligence or environment changes. This reduces alert noise without sacrificing visibility and follows GuardDuty's recommended best practice of using scoped filters and suppression instead of disabling broad detection capabilities.

Why this answer

GuardDuty suppression rules automatically archive findings that match specified criteria (e.g., a known internal scanner IP), removing them from the active findings list without disabling detection. Periodically reviewing suppressed findings ensures that if the benign activity pattern changes or a real threat reuses that IP, the team can catch it. This balances noise reduction with the requirement to escalate genuinely new threats.

Exam trap

SCS-C02 often tests the misconception that suppression equals disabling detection — candidates may pick 'disable the finding type' or 'block all findings from an IP,' but the correct answer preserves detection while archiving known-benign matches and reviewing them periodically.

How to eliminate wrong answers

Option A is wrong because filtering by severity would suppress low-severity findings that may still be meaningful (e.g., reconnaissance), and it does not address the specific false positives from internal scans. Option B is wrong because a blanket suppression rule blocking all findings from the internal IP range would also hide genuine compromises originating from or targeting that range, violating the requirement to escalate new threats. Option C is wrong because disabling finding types entirely stops detection of those threats across the whole account, which is far more dangerous than suppressing specific known-benign instances.

254
MCQmedium

During a security review, a security engineer notices that an S3 bucket contains sensitive data but has a bucket policy that allows access from any principal in the account. The engineer needs to identify any unintended cross-account access to this bucket. Which AWS service should be used?

A.AWS Config
B.AWS IAM Access Analyzer
C.AWS Trusted Advisor
D.Amazon Macie
AnswerB

AWS IAM Access Analyzer is specifically designed to identify unintended access to your resources from external entities. It applies automated reasoning to resource-based policies and generates findings that list the external principal, the resource, and the specific action granted, helping security engineers quickly identify and remediate cross-account access. This makes it the correct service for a security review focused on discovering whether any external accounts have been granted access to your resources.

Why this answer

AWS IAM Access Analyzer helps identify resources that are shared with external principals by analyzing resource-based policies (like S3 bucket policies). In this scenario, the bucket policy allows access from any principal in the account, but IAM Access Analyzer can detect if the policy also grants access to principals outside the AWS account (cross-account access). It generates findings for any policy that allows access from an external entity, making it the correct service to identify unintended cross-account access.

Exam trap

The trap here is that candidates often confuse AWS Config (which can detect public S3 buckets) with IAM Access Analyzer (which specifically detects cross-account access), leading them to choose Config when the question explicitly asks for unintended cross-account access, not just public access.

How to eliminate wrong answers

Option A is wrong because AWS Config evaluates resource compliance against rules but does not specifically analyze bucket policies for cross-account access; it can detect public access but not granular cross-account sharing. Option C is wrong because AWS Trusted Advisor provides best-practice checks (including S3 bucket permissions) but only flags buckets that are publicly accessible or open to all authenticated AWS users, not specifically cross-account access from a specific external account. Option D is wrong because Amazon Macie discovers and classifies sensitive data using machine learning, but it does not analyze bucket policies for cross-account permissions; it focuses on data content, not access controls.

255
MCQhard

Refer to the exhibit. A security engineer is reviewing the bucket encryption configuration. The bucket is used to store sensitive data. The company policy requires that all objects be encrypted using AWS KMS with a customer managed key. What should the engineer do to meet the policy?

A.Enable the bucket key and set SSEAlgorithm to AES256
B.Use client-side encryption with a KMS key
C.Update the bucket encryption configuration to use SSEAlgorithm: aws:kms and specify a KMS key ID
D.Add a bucket policy that requires kms:Encrypt permission for all PutObject requests
AnswerC

Changes default encryption to SSE-KMS.

Why this answer

The company policy requires AWS KMS with a customer managed key, which corresponds to SSE-KMS with SSEAlgorithm set to aws:kms and an explicit KMS key ID (or ARN) in the bucket's default encryption configuration. Updating the bucket encryption configuration via PutBucketEncryption with the KMS key ARN satisfies the requirement for all newly uploaded objects.

Exam trap

The trap is equating 'encrypted at rest' with 'KMS customer managed key' — SSE-S3 also encrypts at rest but gives the customer no control over key rotation, which is the actual policy requirement.

How to eliminate wrong answers

Option A is wrong because AES256 corresponds to SSE-S3 (Amazon S3-managed keys), not KMS customer managed keys; bucket keys are a cost optimization for SSE-KMS, not a substitute for it. Option B is wrong because client-side encryption shifts key management to the application and does not use the bucket's default encryption configuration — it also does not meet a policy that specifically mandates AWS KMS with a CMK. Option D is wrong because a bucket policy requiring kms:Encrypt controls authorization, not the actual encryption mechanism; without the bucket encryption configuration set to aws:kms, objects could still be stored with SSE-S3.

256
MCQeasy

A security engineer is setting up Amazon GuardDuty in a new AWS account. The engineer wants to ensure that GuardDuty can detect compromised EC2 instances that are exhibiting unusual network behavior, such as cryptocurrency mining. Which GuardDuty feature should the engineer enable to monitor network traffic for such threats?

A.GuardDuty VPC Flow Logs and DNS Logs analysis
B.GuardDuty EKS Protection
C.GuardDuty S3 Protection
D.GuardDuty Runtime Monitoring
AnswerA

GuardDuty analyzes VPC Flow Logs and DNS logs to detect unusual network behavior, such as communication with known malicious IPs or domains associated with cryptocurrency mining. This is a core capability of GuardDuty and is enabled by default. It does not require additional agents and provides network-level threat detection for EC2 instances.

Why this answer

GuardDuty continuously monitors VPC Flow Logs and DNS logs to identify unusual network activity, including connections to known malicious IPs or domains used for cryptocurrency mining. This network-based detection is a fundamental feature of GuardDuty and is enabled by default. Other features like S3 Protection, EKS Protection, and Runtime Monitoring address different threat vectors and are not the primary mechanism for detecting network-based threats on EC2 instances.

Exam trap

The trap here is confusing GuardDuty's network monitoring capabilities with its other protections, such as S3 or EKS, which are specific to those services and not for EC2 network traffic.

257
MCQhard

Refer to the exhibit. A security engineer is unable to SSH into an EC2 instance in subnet-12345678. The instance's security group allows inbound SSH from 10.0.0.0/8, and the instance has a public IP. What is the most likely reason for the failure?

A.The security group egress rule is blocking return traffic.
B.The security group inbound rule restricts SSH to the 10.0.0.0/8 range, blocking the engineer's IP.
C.The network ACL's default deny rule (32767) is blocking all inbound traffic.
D.The network ACL inbound rule for SSH is misconfigured, denying all traffic.
AnswerB

The security group inbound rule permits SSH only from sources within the private 10.0.0.0/8 CIDR range, which does not include the security engineer's public IP address. Security groups act as a stateful virtual firewall that filters packets before they reach the instance; if the source IP does not match an allow rule, the packet is silently dropped. This source-restricted SSH rule is the root cause of the connection failure.

Why this answer

The network ACL allows inbound SSH from 0.0.0.0/0, but the security group only allows SSH from 10.0.0.0/8. Since the engineer is connecting from an IP outside that range, the security group blocks the connection.

258
Multi-Selecthard

A security engineer is designing a permissions boundary for an IAM user. Which TWO statements about permissions boundaries are correct?

Select 2 answers
A.Permissions boundaries can be applied to service-linked roles.
B.Permissions boundaries can only be applied to IAM users, not roles.
C.The effective permissions are the intersection of the identity-based policy and the permissions boundary.
D.Permissions boundaries can override resource-based policies.
E.A permissions boundary alone does not grant permissions; an identity-based policy is also required.
AnswersC, E

A permissions boundary caps identity-based policies: the principal can only perform actions allowed by both. Effective permissions therefore equal the intersection, so an action permitted by the identity policy but absent from the boundary is denied.

Why this answer

Option C is correct because AWS evaluates a permissions boundary as a filter: the effective permissions for an IAM principal are the intersection of what the identity-based policy allows and what the permissions boundary allows, so an action must be permitted by both to succeed. Option E is correct because a permissions boundary is only a maximum-permissions guardrail; it never grants access by itself, and the principal still needs an identity-based policy (or another applicable policy) that allows the action. Options A and B are wrong because permissions boundaries can be attached to IAM users and IAM roles (including service roles), but not to service-linked roles, which are managed by AWS and do not support permissions boundaries.

Option D is wrong because permissions boundaries only limit identity-based permissions and cannot expand or override resource-based policies; resource-based policies are evaluated separately and can grant access independently of the boundary.

259
MCQmedium

A company wants to ensure that IAM users with console access have strong passwords. Which IAM password policy setting should the company configure to enforce the use of at least one uppercase letter?

A.MinimumPasswordLength
B.RequireUppercaseCharacters
C.RequireNumbers
D.RequireSymbols
AnswerB

RequireUppercaseCharacters is the password policy parameter that forces every IAM user password to contain at least one uppercase letter, directly satisfying the stated requirement for console users. Setting it to true makes IAM reject any password lacking an uppercase character at creation or change time.

Why this answer

The IAM password policy setting `RequireUppercaseCharacters` specifically enforces that IAM user passwords contain at least one uppercase letter (A-Z). When enabled, any password created or changed must include an uppercase character, otherwise IAM rejects it. This directly satisfies the requirement to enforce uppercase letters for console users.

Exam trap

SCS-C02 often tests the specific IAM password policy settings and their exact enforcement, so candidates must distinguish between length, uppercase, lowercase, numbers, and symbols requirements rather than assuming any complexity setting enforces uppercase.

How to eliminate wrong answers

Option A is wrong because `MinimumPasswordLength` only sets the minimum number of characters (e.g., 8 to 128) and does not enforce character composition like uppercase letters. Option C is wrong because `RequireNumbers` enforces at least one numeric digit (0-9), not an uppercase letter. Option D is wrong because `RequireSymbols` enforces at least one non-alphanumeric symbol (e.g., ! @ # $ % ^ & * ( ) _ + - = [ ] { } | '), not an uppercase letter.

260
MCQeasy

A security engineer is investigating a potential data exfiltration incident. The engineer suspects that an attacker is using an Amazon S3 bucket to exfiltrate data. Which AWS service can be used to analyze S3 access logs and detect anomalous patterns?

A.Amazon CloudFront
B.Amazon Athena
C.AWS Shield
D.AWS WAF
AnswerB

Amazon Athena is a serverless, interactive query service that allows you to analyze data directly in Amazon S3 using standard SQL without managing any infrastructure. A security engineer investigating potential data exfiltration can use Athena to run ad-hoc queries over S3 server access logs to identify unusual patterns such as repeated GET operations, large data transfers, or requests from unexpected IP addresses. Because Athena charges per query and requires no cluster setup, it is the appropriate tool for on-demand log analysis in an S3-centric investigation.

Why this answer

Amazon Athena is the correct choice because it allows you to run SQL queries directly against Amazon S3 access logs stored in S3, enabling you to analyze large volumes of log data for anomalous patterns such as unusual data transfer volumes, repeated access from unfamiliar IP ranges, or unexpected object reads. This serverless query service is purpose-built for ad-hoc analysis of structured and semi-structured data in S3 without needing to load data into a separate database, making it ideal for incident response investigations.

Exam trap

The trap here is that candidates often confuse AWS WAF or CloudFront as log analysis tools because they are associated with web traffic inspection, but neither provides the ability to query S3 access logs for data exfiltration patterns.

How to eliminate wrong answers

Option A is wrong because Amazon CloudFront is a content delivery network (CDN) that accelerates static and dynamic content delivery; it does not provide query capabilities for S3 access logs and cannot analyze log data for anomalies. Option C is wrong because AWS Shield is a managed Distributed Denial of Service (DDoS) protection service that safeguards against network and transport layer attacks; it does not inspect or analyze S3 access logs for data exfiltration patterns. Option D is wrong because AWS WAF is a web application firewall that filters HTTP/HTTPS traffic based on rules to protect against common web exploits; it operates at the application layer and cannot query or analyze S3 access logs.

261
MCQmedium

A security engineer notices that an EC2 instance is sending outbound traffic to a known malicious IP address. The engineer needs to immediately block the traffic and capture a packet capture for forensic analysis. Which combination of actions should the engineer take?

A.Use Amazon GuardDuty to block the IP and enable VPC Traffic Mirroring.
B.Add a network ACL deny rule for the malicious IP, and enable VPC Traffic Mirroring.
C.Stop the EC2 instance and enable VPC Flow Logs.
D.Modify the security group to deny outbound traffic to the IP, and enable VPC Flow Logs.
AnswerB

Network ACLs act as a stateless firewall at the subnet level, and they explicitly support deny rules that are evaluated in numeric order before traffic reaches the EC2 instance. Adding a deny rule for the malicious IP immediately blocks both inbound and outbound traffic from that source at the subnet boundary. VPC Traffic Mirroring complements this by capturing full packet payloads, giving the security engineer the packet-level forensic data needed to investigate the incident without disrupting the traffic flow.

Why this answer

A network ACL (NACL) is a stateless firewall that operates at the subnet level, allowing immediate blocking of traffic to/from a specific IP address without affecting the instance's security group rules. Enabling VPC Traffic Mirroring captures a full packet-level copy of the traffic for forensic analysis, which is superior to VPC Flow Logs (which only capture metadata). This combination provides both rapid containment and deep forensic data.

Exam trap

The trap here is that candidates confuse security groups (stateful, allow-only) with network ACLs (stateless, allow/deny) and mistakenly think a security group can block a specific IP, or they assume VPC Flow Logs provide packet-level capture when they only provide metadata.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service, not a blocking mechanism; it cannot directly block traffic, and VPC Traffic Mirroring is not enabled via GuardDuty. Option C is wrong because stopping the EC2 instance halts all traffic but prevents capturing live malicious traffic for analysis, and VPC Flow Logs only provide metadata (source/destination IP, ports, protocol) not full packet payloads. Option D is wrong because security groups are stateful and cannot deny outbound traffic to a specific IP address; they only support allow rules, and VPC Flow Logs do not capture packet contents.

262
MCQhard

A security engineer is troubleshooting an issue where an Amazon RDS for MySQL DB instance is not encrypting data at rest. The DB instance was created without encryption. The engineer needs to enable encryption without significant downtime. What is the MOST effective approach?

A.Take a snapshot of the DB instance and enable encryption on the snapshot
B.Take a snapshot, copy it with encryption enabled, and restore a new DB instance from the encrypted snapshot
C.Modify the DB instance and enable encryption in the console
D.Create a read replica with encryption and promote it
AnswerB

Take a manual snapshot of the unencrypted DB instance, then use the AWS CLI or console to copy that snapshot into a new snapshot encrypted with a KMS key (for example, with the copy-db-snapshot command and a --kms-key-id parameter). Once the encrypted snapshot is available, restore a new DB instance from it. The restored instance inherits the encrypted storage from the snapshot, and after updating the application connection string to the new endpoint, the original unencrypted instance can be decommissioned.

Why this answer

To enable encryption on an unencrypted RDS DB instance with minimal downtime, you must take a snapshot, copy it with encryption enabled, and then restore a new DB instance from the encrypted snapshot. This creates a new encrypted instance, and you can then switch applications to it. The process requires some downtime during the switch, but it's the most effective method because RDS does not support enabling encryption in-place on an existing unencrypted instance.

Exam trap

SCS-C02 often tests the misconception that you can enable encryption on an existing RDS instance via modification; candidates may select option C, not realizing encryption must be set at creation or via snapshot restore.

How to eliminate wrong answers

Option A is wrong because you cannot enable encryption directly on an existing snapshot; you must copy it with encryption. Option C is wrong because you cannot modify an existing DB instance to enable encryption; encryption can only be set at creation. Option D is wrong because creating an encrypted read replica is not possible if the source is unencrypted; read replicas inherit the encryption status of the source.

263
MCQmedium

A company has a multi-account AWS Organization with 50 accounts. The security team uses AWS CloudTrail to log all API calls and sends the logs to a central S3 bucket in the security account. The team wants to ensure that any attempt to disable CloudTrail logging or delete the trail is detected and automatically remediated within 5 minutes. They have configured an AWS Config rule that triggers an AWS Lambda function when the CloudTrail configuration changes. However, the Lambda function is not being invoked when they test by stopping the trail. The Lambda function's IAM role has permissions to start and update CloudTrail. CloudTrail logs show that the Config rule is evaluating the resource, but the Lambda function is not triggered. What is the most likely cause?

A.The S3 bucket policy does not allow CloudTrail to write logs.
B.The Lambda function's IAM role does not have permission to modify CloudTrail.
C.The CloudTrail trail does not have permission to send logs to the S3 bucket.
D.The AWS Config service does not have permission to invoke the Lambda function.
AnswerD

For a custom AWS Config rule backed by Lambda, AWS Config must be explicitly allowed to invoke the Lambda function. This is done by adding a resource-based policy to the Lambda function that grants the `config.amazonaws.com` service principal permission to call `lambda:InvokeFunction`. Without that policy, AWS Config returns an access denied error when it attempts to trigger the Lambda for each configuration snapshot. The Lambda execution role is irrelevant to this authorization step, which is why the invocation fails despite the role having CloudTrail permissions.

Why this answer

AWS Config uses a service-linked role or a configured IAM role to invoke the Lambda function as the remediation action. If the Config service does not have permission to invoke the Lambda function — typically because the Lambda function's resource-based policy does not grant config.amazonaws.com the lambda:InvokeFunction permission, or the Config service role lacks the necessary trust — the rule will evaluate the resource but the remediation action will silently fail to trigger the Lambda. The question states the Lambda role already has CloudTrail permissions, so the missing link is Config's ability to invoke Lambda.

Exam trap

The trap here is that candidates focus on the Lambda execution role's permissions (which are already correct) and overlook the separate requirement that the AWS Config service itself must be granted permission to invoke the Lambda function via the function's resource-based policy.

How to eliminate wrong answers

Option A is wrong because the S3 bucket policy controlling CloudTrail log delivery is unrelated to whether the Config rule can invoke a Lambda function; CloudTrail logs are already being delivered since the team can see Config rule evaluations. Option B is wrong because the question explicitly states the Lambda function's IAM role already has permissions to start and update CloudTrail, so this is not the missing permission. Option C is wrong because the CloudTrail trail's permission to send logs to S3 is also unrelated to the Config-to-Lambda invocation path, and CloudTrail logging is clearly working since the team can observe Config rule evaluations and CloudTrail logs.

264
MCQmedium

A company uses AWS Organizations to manage multiple accounts. The security team wants to enable CloudTrail for all accounts and centrally store logs. What is the most efficient way to achieve this?

A.Use an S3 bucket policy to allow cross-account log delivery
B.Create a CloudTrail trail in the management account and apply it to all accounts in the organization
C.Use AWS Lambda to create trails in each account
D.Ask each account admin to create their own CloudTrail trail and deliver to a central S3 bucket
AnswerB

Creating the trail in the management account with organisation-wide application lets CloudTrail deliver every member account's events to one central S3 bucket, satisfying the centralised-storage constraint. This is the native AWS Organizations integration, avoiding per-account trail duplication and the operational overhead of manual configuration across accounts.

Why this answer

AWS Organizations allows you to create a single CloudTrail trail in the management account that automatically applies to all member accounts within the organization. This is the most efficient method as it eliminates the need for manual per-account configuration or custom automation, and it ensures consistent logging across the entire organization with centralized log delivery to a single S3 bucket.

Exam trap

The trap here is that candidates often assume cross-account S3 bucket policies (Option A) are sufficient, overlooking the native organization-wide trail capability that automates trail creation and management across all accounts.

How to eliminate wrong answers

Option A is wrong because while an S3 bucket policy can allow cross-account log delivery, it does not automate the creation of CloudTrail trails in each account; each account would still need to manually create its own trail, which is inefficient and error-prone. Option C is wrong because using AWS Lambda to create trails in each account introduces unnecessary complexity, potential latency, and maintenance overhead compared to the native organization-wide trail feature. Option D is wrong because asking each account admin to create their own trail is not only inefficient but also risks inconsistent configurations, missing logs, and increased administrative burden.

265
MCQhard

A company uses Amazon RDS for MySQL and needs to monitor database activity for suspicious queries, such as unauthorized access attempts or SQL injection. The security team wants to centralize the logs from multiple RDS instances and analyze them in near real-time. Which solution should be implemented?

A.Enable RDS Enhanced Monitoring and stream the metrics to Amazon CloudWatch.
B.Enable VPC Flow Logs for the RDS instances and analyze the logs using Amazon Athena.
C.Enable AWS CloudTrail for RDS API calls and use Amazon GuardDuty to analyze the logs.
D.Enable database audit logs on each RDS instance, stream them to Amazon CloudWatch Logs, and use CloudWatch Logs Insights to query the logs.
AnswerD

Streaming RDS audit logs to CloudWatch Logs satisfies the centralisation and near real-time analysis constraints: multiple instances publish to one log service, and Logs Insights queries them interactively. Unlike RDS Performance Insights, which reports load metrics rather than statement text, audit logging captures suspicious queries such as SQL injection attempts for investigation.

Why this answer

RDS for MySQL audit logs capture detailed database-level activity, including login attempts, query execution, and SQL injection patterns. Streaming these logs to CloudWatch Logs enables near real-time analysis using CloudWatch Logs Insights, which supports querying and alerting on suspicious queries across multiple RDS instances from a centralized location.

Exam trap

The trap here is confusing database-level audit logs (which capture SQL queries and authentication events) with infrastructure-level logs like Enhanced Monitoring or VPC Flow Logs, leading candidates to choose options that monitor performance or network traffic instead of actual database activity.

How to eliminate wrong answers

Option A is wrong because RDS Enhanced Monitoring provides OS-level metrics (CPU, memory, disk I/O) but does not capture database query content or authentication events needed to detect suspicious queries or SQL injection. Option B is wrong because VPC Flow Logs record network traffic metadata (IP addresses, ports, protocols) but do not include database query text or user authentication details; they cannot identify SQL injection or unauthorized access attempts at the database level. Option C is wrong because AWS CloudTrail logs RDS API calls (e.g., CreateDBInstance, ModifyDBInstance) but does not capture database engine-level activity such as SQL queries or login attempts; GuardDuty analyzes CloudTrail, VPC Flow Logs, and DNS logs for threats but cannot inspect database query content.

266
MCQhard

A company is deploying a multi-tier web application on AWS. The application uses an Application Load Balancer (ALB) to distribute traffic to EC2 instances in private subnets. The security team wants to protect the application from common web exploits like SQL injection and cross-site scripting. Which AWS service should be used?

A.AWS WAF.
B.AWS Network Firewall.
C.AWS Shield Advanced.
D.AWS Security Hub.
AnswerA

AWS WAF is a Layer 7 web application firewall that inspects HTTP/HTTPS requests before they reach the web tier. It runs managed rule groups, including AWS Managed Rules for SQL injection and cross-site scripting, and can be deployed on an Application Load Balancer, Amazon CloudFront, or Amazon API Gateway. Because it can parse the request body and headers, it can block malicious signatures while letting legitimate traffic through.

Why this answer

AWS WAF is a web application firewall that helps protect web applications from common web exploits such as SQL injection and cross-site scripting (XSS). It integrates directly with an Application Load Balancer (ALB) to inspect HTTP/HTTPS requests and filter malicious traffic based on customizable rules, including managed rule groups for OWASP Top 10 threats.

Exam trap

The trap here is that candidates often confuse AWS Network Firewall (Layer 3/4 filtering) with a web application firewall, not realizing that SQL injection and XSS require Layer 7 HTTP payload inspection, which only AWS WAF provides.

How to eliminate wrong answers

Option B (AWS Network Firewall) is wrong because it operates at the network layer (Layer 3/4) and stateful inspection, not at the application layer (Layer 7), so it cannot inspect HTTP payloads for SQL injection or XSS. Option C (AWS Shield Advanced) is wrong because it provides DDoS protection against volumetric and state-exhaustion attacks, not application-layer web exploit filtering. Option D (AWS Security Hub) is wrong because it is a centralized security posture management service that aggregates findings from multiple AWS services, not a real-time traffic inspection or filtering service.

267
MCQmedium

A company uses AWS CloudTrail to log API activity across multiple accounts. The security team wants to ensure that any S3 bucket created with public read access is detected within minutes. Which solution is MOST efficient?

A.Create an Amazon EventBridge rule that matches CloudTrail CreateBucket API calls and triggers a Lambda function that inspects the bucket's public access settings and alerts if public.
B.Use AWS Config rules to check S3 bucket public access settings and trigger an AWS Lambda function to send alerts.
C.Use S3 server access logs and run a daily script to parse the logs for PutBucketAcl actions.
D.Enable CloudTrail log file validation and use Athena to query logs hourly for CreateBucket events with public ACLs.
AnswerA

An EventBridge rule can pattern-match CloudTrail API events as they are emitted, meaning a CreateBucket call with a public access configuration triggers the Lambda function within seconds of the API completing. The Lambda can then use GetPublicAccessBlock, GetBucketPolicyStatus, or GetBucketAcl to determine whether the bucket is actually public and immediately alert a security team, making this the only option that combines near-real-time detection with direct inspection of the resulting bucket configuration.

Why this answer

It uses an Amazon EventBridge rule to capture the CloudTrail `CreateBucket` API call in near real-time, then triggers a Lambda function to immediately inspect the bucket's public access settings. This approach detects public buckets within minutes without polling or batch processing, making it the most efficient solution for the stated requirement.

Exam trap

The trap here is that candidates often choose AWS Config rules (Option B) because they associate Config with compliance checks, but they overlook the latency of Config evaluations versus the near-real-time capability of EventBridge for API-driven detection.

How to eliminate wrong answers

Option B is wrong because AWS Config rules evaluate resource configurations on a periodic basis (e.g., every 10 minutes or hourly) or on configuration changes, but they do not guarantee detection within minutes of the bucket creation; the evaluation delay can exceed the required time window. Option C is wrong because S3 server access logs are delivered on a best-effort basis, often with delays of several hours, and a daily script would not meet the 'within minutes' requirement. Option D is wrong because CloudTrail log file validation only ensures integrity, not real-time detection, and using Athena to query logs hourly introduces at least a one-hour delay, failing the 'within minutes' requirement.

268
MCQmedium

A security engineer is troubleshooting an issue where CloudTrail logs are not being delivered to the specified S3 bucket. The bucket policy allows CloudTrail to write objects. What is the MOST likely cause?

A.The S3 bucket uses server-side encryption with customer-provided keys (SSE-C).
B.The S3 bucket has a bucket policy that denies access to the CloudTrail service principal.
C.The S3 bucket does not have versioning enabled.
D.The S3 bucket is in a different AWS account.
AnswerB

An explicit Deny statement in the destination bucket policy that references the CloudTrail service principal (cloudtrail.amazonaws.com) will override any Allow that CloudTrail receives through its service role or resource-based policies. In AWS IAM policy evaluation, an explicit deny acts as an absolute veto, so CloudTrail's attempts to perform s3:PutObject and s3:GetBucketAcl fail with Access Denied. Because this would block delivery regardless of encryption, versioning, or account location, it is the likely root cause.

Why this answer

The most likely cause is that the S3 bucket policy explicitly denies access to the CloudTrail service principal. Even if a bucket policy allows CloudTrail to write logs, an explicit deny statement overrides any allow, preventing log delivery. This is a common misconfiguration where a deny rule is inadvertently applied to the CloudTrail principal.

Exam trap

The trap here is that candidates often overlook explicit deny statements in bucket policies, assuming that an allow statement alone is sufficient for CloudTrail log delivery, but AWS IAM policy evaluation always prioritizes explicit denies over allows.

How to eliminate wrong answers

Option A is wrong because SSE-C does not prevent CloudTrail from writing logs; CloudTrail supports SSE-C and can deliver logs to buckets using customer-provided keys. Option C is wrong because S3 versioning is not required for CloudTrail log delivery; CloudTrail can write objects to a bucket without versioning enabled. Option D is wrong because CloudTrail can deliver logs to an S3 bucket in a different AWS account, provided the bucket policy grants the necessary permissions to the CloudTrail service principal from the source account.

269
Multi-Selecteasy

A security engineer is configuring automated response to a specific GuardDuty finding type. The engineer wants to automatically block the offending IP address in the security group when a finding is generated. Which TWO AWS services should the engineer use together to achieve this? (Choose TWO.)

Select 2 answers
A.AWS Lambda
B.AWS Config
C.Amazon Simple Notification Service (SNS)
D.Amazon EventBridge
E.Amazon CloudWatch Logs
AnswersA, D

Lambda executes custom remediation logic when GuardDuty publishes a finding to EventBridge, calling EC2 APIs to revoke the offending IP from the security group. It supplies the compute that performs the block, which the detection service alone cannot do.

Why this answer

Amazon EventBridge [CORRECT] is the right service to detect the GuardDuty finding event, because GuardDuty publishes its findings as events to the default EventBridge event bus, and an EventBridge rule can match the specific finding type (e.g., source aws.guardduty with the desired detail-type) and route it to a target for automated response. AWS Lambda [CORRECT] is the correct target to perform the remediation, since a Lambda function can call the EC2 APIs (such as AuthorizeSecurityGroupIngress/RevokeSecurityGroupIngress or ModifyNetworkInterfaceAttribute) to block the offending IP address in the security group. AWS Config is for recording resource configuration changes and evaluating compliance rules, not for event-driven remediation of GuardDuty findings.

Amazon SNS can deliver notifications but cannot itself modify security groups, so it does not perform the blocking action. Amazon CloudWatch Logs stores log data but does not react to GuardDuty findings or execute remediation logic.

Exam trap

The trap here is that candidates often choose SNS because it is commonly associated with GuardDuty alerts, but they overlook that SNS cannot perform API actions like modifying security groups—only Lambda or Step Functions can execute the remediation logic.

270
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to centrally collect and analyze VPC Flow Logs from all accounts. What is the MOST efficient way to achieve this?

A.Use AWS Firewall Manager to deploy VPC Flow Logs and aggregate logs in a single account.
B.Configure VPC Flow Logs to deliver to a central CloudWatch Logs log group in the management account.
C.Configure VPC Flow Logs to deliver to a central S3 bucket in the security account, and use a bucket policy that grants the source accounts permission to write.
D.Set up VPC Flow Logs in each account to deliver to local S3 buckets, then use S3 replication to copy to a central bucket.
AnswerC

VPC Flow Logs natively support delivering to an S3 bucket that is owned by a different account, such as a security account. The central bucket policy must grant the delivery.logs.amazonaws.com service principal permission to PutObject, with an aws:SourceAccount condition restricting writes to the authorized source accounts. This configures direct, server-side log delivery without any interim services or replication.

Why this answer

It uses a central S3 bucket in the security account with a bucket policy that grants the PutObject permission to the VPC Flow Logs delivery service from each source account. This is the most efficient approach as it avoids per-account configuration overhead, eliminates the need for cross-account replication, and provides a single location for centralized analysis using services like Amazon Athena or Amazon QuickSight.

Exam trap

The trap here is that candidates assume Firewall Manager (Option A) handles log aggregation, but it only manages the configuration policy, not the actual log delivery destination; similarly, many mistakenly think CloudWatch Logs (Option B) supports cross-account delivery natively, which it does not.

How to eliminate wrong answers

Option A is wrong because AWS Firewall Manager can centrally deploy VPC Flow Logs configurations but does not aggregate the logs themselves; it only manages the policy, and logs still need to be delivered to a central destination. Option B is wrong because CloudWatch Logs log groups cannot be written to cross-account by default; VPC Flow Logs can only deliver to a CloudWatch Logs log group in the same account, and centralizing requires additional infrastructure like a subscription filter or Lambda to forward logs. Option D is wrong because it introduces unnecessary complexity and cost by requiring S3 replication, which adds latency and storage overhead, and is less efficient than direct cross-account delivery to a central bucket.

271
MCQhard

A company's security team discovers that an EC2 instance in the production account has been compromised. The instance has an IAM role attached that allows it to read from an S3 bucket containing sensitive data. The team needs to immediately stop the data exfiltration while preserving the evidence. What should the team do first?

A.Detach the S3 bucket from the VPC endpoint.
B.Apply an inline policy to the IAM role that denies all S3 actions.
C.Remove the IAM role from the EC2 instance.
D.Terminate the compromised EC2 instance immediately.
AnswerB

Attaching an inline policy with an explicit deny for all S3 actions to the EC2 instance's IAM role immediately blocks all S3 API calls because explicit denies override any allow statements, and IAM policies are evaluated at request time. This containment works for any temporary credentials already issued, since every request is re-authorized against the role's current policies, and it does not destroy the instance or remove evidence needed for investigation. This is the fastest, least invasive way to stop S3 exfiltration.

Why this answer

The correct first step because applying an inline policy that denies all S3 actions to the IAM role immediately stops the compromised instance from accessing the S3 bucket, preventing data exfiltration while preserving the instance's state for forensic investigation. Option A is incorrect because detaching the S3 bucket from the VPC endpoint does not affect the instance's ability to access S3 through the internet or other endpoints. Option C is incorrect because removing the IAM role from the instance may not take effect immediately if the role's credentials are cached, and it could disrupt evidence collection.

Option D is incorrect because terminating the instance would destroy volatile evidence and might not stop exfiltration in time if the instance is already sending data.

272
MCQhard

Refer to the exhibit. A security engineer created this S3 bucket policy to allow CloudTrail to deliver logs from account 123456789012 to the bucket my-trail-bucket. However, CloudTrail logs are not being delivered. What is the most likely reason?

A.The Principal should be the CloudTrail service principal for the specific region.
B.The Action should be s3:PutObjectAcl instead of s3:PutObject.
C.The resource ARN does not include the bucket name.
D.The policy is missing s3:GetBucketAcl permission.
AnswerD

CloudTrail requires not only write permission via s3:PutObject but also s3:GetBucketAcl to inspect the bucket's ACL and confirm it is not publicly writable. Without this permission, CloudTrail aborts log delivery even if the bucket policy allows PutObject, which is why this option identifies the real defect. Granting both actions fixes the configuration.

Why this answer

CloudTrail requires both s3:PutObject and s3:GetBucketAcl permissions on the destination S3 bucket to validate that the bucket policy grants the necessary access. Without s3:GetBucketAcl, CloudTrail cannot confirm the bucket's ACL allows log delivery, causing delivery to fail.

Exam trap

The trap here is that candidates focus on the obvious s3:PutObject action and overlook the required s3:GetBucketAcl permission, which is a subtle but critical prerequisite for CloudTrail log delivery.

How to eliminate wrong answers

Option A is wrong because CloudTrail uses a service principal (cloudtrail.amazonaws.com) that is region-agnostic; specifying a region-specific principal is unnecessary and not the cause of the failure. Option B is wrong because CloudTrail uses s3:PutObject to deliver logs, not s3:PutObjectAcl; ACLs are managed separately via bucket policies or ACLs, not through the PutObject action. Option C is wrong because the resource ARN in the exhibit includes the bucket name (my-trail-bucket), so the ARN is correctly formatted; the issue is missing permissions, not an incorrect ARN.

273
Multi-Selectmedium

A security engineer is designing a VPC with private and public subnets. Which TWO actions improve network security? (Choose two.)

Select 2 answers
A.Use a single subnet for all resources to simplify network rules.
B.Use security groups to restrict traffic to the database from only the application tier.
C.Place database instances in a public subnet for easier management.
D.Use a NAT gateway in a public subnet for outbound traffic from private subnets.
E.Place an internet gateway in a private subnet.
AnswersB, D

Security groups act as a stateful, instance-level firewall that lets you reference another security group as the source. By placing the database in a private subnet and attaching a security group that allows inbound traffic only from the application tier's security group (not from a CIDR), you ensure that only instances with that specific security group can reach the database. This rule automatically accommodates new instances added to the application tier and blocks all other traffic, including from other subnets or external sources, without exposing the database to the internet.

Why this answer

Security groups act as a stateful virtual firewall at the instance level, allowing you to restrict inbound traffic to the database instances to only the application tier's security group. This ensures that only traffic originating from the application instances can reach the database, effectively implementing a least-privilege security model.

Exam trap

The trap here is that candidates often confuse security groups (stateful, instance-level) with network ACLs (stateless, subnet-level) and may incorrectly think that a single subnet simplifies security, when in fact it eliminates the network segmentation that is critical for defense in depth.

274
Multi-Selectmedium

Which TWO are best practices for managing IAM policies? (Select TWO.)

Select 2 answers
A.Use wildcards (*) to simplify policy management
B.Use inline policies instead of managed policies
C.Use SCPs to enforce permissions
D.Grant least privilege by using specific actions and resources
E.Use AWS managed policies when possible
AnswersD, E

Granting least privilege means constructing IAM policies so that every Action and Resource element is scoped to the specific operations and ARNs the principal actually needs, and where applicable adding condition keys such as 'aws:PrincipalTag' or 'aws:RequestedRegion' to further constrain access. For example, instead of allowing 's3:ListBucket' on all buckets, the policy should list the exact bucket name in the Resource and restrict the action to relevant key prefixes, while also avoiding overly broad Principal elements in resource policies. This practice reduces the attack surface, limits the impact of compromised credentials, and is a foundational requirement of the AWS Well-Architected Framework's security pillar.

Why this answer

The principle of least privilege is a foundational security best practice in AWS IAM. By specifying exact actions (e.g., s3:GetObject) and resources (e.g., arn:aws:s3:::example-bucket/*) instead of using wildcards, you minimize the blast radius of a compromised credential or misconfigured policy. This aligns with the AWS Well-Architected Framework's security pillar, which mandates granting only the permissions required to perform a task.

Exam trap

The trap here is that candidates often confuse SCPs as a method to grant permissions, when in fact SCPs only define a maximum permission boundary and cannot grant any access—permissions must still be explicitly allowed by IAM policies within the account.

275
MCQeasy

A company wants to ensure that all traffic to an Amazon S3 bucket is encrypted in transit. Which bucket policy condition should be used?

A.aws:SourceVpce
B.aws:SecureTransport
C.s3:x-amz-server-side-encryption
D.aws:SourceIp
AnswerB

The aws:SecureTransport condition key is a boolean context key that indicates whether the request was sent over SSL/TLS: it is true for HTTPS and false for plaintext HTTP. In a bucket policy, you can add a Deny statement with a condition like {"Bool":{"aws:SecureTransport":"false"}} to block all unencrypted requests. This directly ensures that every request to the S3 bucket is encrypted during transit.

Why this answer

The `aws:SecureTransport` condition key checks whether the request was sent using SSL/TLS (i.e., HTTPS). Setting it to `false` in a deny statement ensures that any HTTP request to the S3 bucket is rejected, thereby enforcing encryption in transit. This is the correct condition for the stated requirement.

Exam trap

The trap here is confusing encryption in transit (HTTPS/TLS) with encryption at rest (server-side encryption), leading candidates to incorrectly select `s3:x-amz-server-side-encryption` instead of `aws:SecureTransport`.

How to eliminate wrong answers

Option A is wrong because `aws:SourceVpce` restricts access based on the VPC endpoint ID, which controls network path but does not enforce encryption in transit. Option C is wrong because `s3:x-amz-server-side-encryption` enforces encryption at rest (server-side encryption), not encryption in transit. Option D is wrong because `aws:SourceIp` restricts access based on the client's IP address, which has no bearing on whether the transport layer uses HTTPS.

276
MCQeasy

Which AWS service can be used to create a private network connection between a VPC and an on-premises data center over dedicated physical lines?

A.AWS Transit Gateway
B.AWS Site-to-Site VPN
C.AWS Direct Connect
D.VPC Peering
AnswerC

AWS Direct Connect delivers a dedicated physical Ethernet-based connection from your on-premises data center to AWS Direct Connect locations, bypassing the public internet entirely. This dedicated link provides consistent network performance, lower latency, and can be scaled from 1 to 100 Gbps depending on the port and partner offerings. A direct connection is established via a cross-connect in a Direct Connect facility or through an AWS Direct Connect Partner, and can be divided into multiple virtual interfaces (VLANs) for accessing public and private AWS resources. This precisely matches the requirement of creating a private network connection using dedicated lines.

Why this answer

AWS Direct Connect is the correct service because it establishes a dedicated, private network connection from an on-premises data center to a VPC using physical Ethernet cables routed through an AWS Direct Connect location. This bypasses the public internet entirely, providing consistent latency, higher bandwidth, and a more reliable connection than internet-based options.

Exam trap

The trap here is that candidates confuse AWS Site-to-Site VPN with a dedicated connection, but VPNs always traverse the public internet and do not provide the physical isolation or consistent performance of Direct Connect.

How to eliminate wrong answers

Option A is wrong because AWS Transit Gateway is a network transit hub that interconnects VPCs and on-premises networks, but it does not itself provide the physical dedicated lines; it requires an underlying connection like Direct Connect or VPN to attach to. Option B is wrong because AWS Site-to-Site VPN creates an encrypted tunnel over the public internet, not over dedicated physical lines, so it does not meet the requirement for a private connection over dedicated infrastructure. Option D is wrong because VPC Peering connects two VPCs within AWS using the AWS global network, but it cannot connect to an on-premises data center and does not involve dedicated physical lines.

277
MCQeasy

A security engineer is investigating a potential data exfiltration incident where an EC2 instance is sending large volumes of data to an unknown IP address. Which AWS service should the engineer use to capture and analyze the network traffic for evidence?

A.AWS WAF
B.AWS Shield
C.Amazon Inspector
D.VPC Traffic Mirroring
AnswerD

VPC Traffic Mirroring captures IP traffic flowing to and from an EC2 instance's elastic network interface and copies it to a chosen destination—such as a security appliance or a workload running another ENI—for inspection and storage. It supports both inbound and outbound traffic, can mirror multiple ENIs, and allows filtering by protocol, source, destination, port, or TCP flags, enabling the security engineer to focus on suspicious or unauthorized transfers. Unlike the other services, it provides full packet contents, not just metadata or aggregated flow logs, so it is the appropriate method to investigate and potentially prove data exfiltration from a compromised instance. Note, it is not a native log store; the mirrored traffic must be sent to a tool like a network analyzer or a custom capture environment, but that is exactly why it is suitable for an in-depth forensic investigation.

Why this answer

VPC Traffic Mirroring is the correct choice because it allows you to capture and inspect network traffic from an EC2 instance by mirroring the traffic to a monitoring appliance or a security tool. This enables deep packet inspection to analyze the contents of the data being sent to the unknown IP address, providing evidence for data exfiltration. Unlike other services, Traffic Mirroring operates at the network level, copying all packets (including payloads) without affecting the source instance.

Exam trap

The trap here is that candidates often confuse VPC Traffic Mirroring with VPC Flow Logs, but Flow Logs only capture metadata (source/destination IP, ports, protocol, packet count) and not the actual packet payloads, making them insufficient for evidence of data exfiltration content.

How to eliminate wrong answers

Option A is wrong because AWS WAF is a web application firewall that inspects HTTP/HTTPS traffic at the application layer (Layer 7) and cannot capture or analyze raw network packets or non-HTTP traffic. Option B is wrong because AWS Shield is a DDoS protection service that mitigates volumetric attacks but does not provide packet capture or forensic analysis of outbound traffic. Option C is wrong because Amazon Inspector is a vulnerability assessment service that scans for software vulnerabilities and network exposure, not a tool for capturing or analyzing live network traffic.

278
MCQeasy

A security engineer is investigating a potential security incident and needs to determine if an EC2 instance was launched with a specific AMI ID. Which AWS log should be examined?

A.AWS Config timeline
B.VPC Flow Logs
C.AWS CloudTrail
D.Amazon CloudWatch Logs (EC2 agent logs)
AnswerC

AWS CloudTrail is the correct source because it records the RunInstances API call as a management event, and the event's requestParameters field contains the ImageId (AMI ID) as well as instance type, key name, security groups, and subnet. The event's userIdentity and sourceIPAddress/vpcEndpoint fields identify exactly which IAM principal or role launched the instance and from where. CloudTrail EventHistory is normally searchable for 90 days; for older incidents, you must query the delivery to an S3 bucket or CloudTrail Lake.

Why this answer

AWS CloudTrail records all API calls made within an AWS account, including the RunInstances API call that launches an EC2 instance. The CloudTrail event for RunInstances contains the AMI ID in the request parameters, allowing you to determine if a specific AMI was used. This makes CloudTrail the correct log to examine for this investigation.

Exam trap

The trap here is that candidates often confuse AWS Config (which shows resource configuration history) with CloudTrail (which logs API calls), leading them to choose AWS Config timeline even though it does not capture the AMI ID parameter from the launch request.

How to eliminate wrong answers

Option A is wrong because AWS Config timeline shows configuration changes and compliance history of resources over time, but it does not log the specific AMI ID used at launch; it records the resulting configuration state, not the API call parameters. Option B is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) and have no visibility into EC2 instance launch details like AMI IDs. Option D is wrong because Amazon CloudWatch Logs with the EC2 agent collect OS-level logs (syslog, application logs) from inside the instance, which cannot capture the AMI ID used to launch the instance, as that information is not available to the guest OS.

279
MCQeasy

A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no resources can be created in a specific AWS Region except for the us-east-1 Region. Which policy type should the security team use?

A.IAM permissions boundary
B.IAM policy applied to the root user
C.Resource-based policy
D.Service control policy (SCP)
AnswerD

Service control policies are the correct account-level control because they establish permission guardrails that apply to every IAM principal and the root user in all linked accounts within an AWS Organization. An SCP can deny actions using a condition such as aws:RequestedRegion, effectively preventing users from making API calls in designated Regions across the entire organization. SCPs do not grant permissions themselves; they just set the maximum allowed access, and they do not affect the management account, which is an important nuance when designing Region restrictions.

Why this answer

Service control policies (SCPs) are the correct choice because they allow you to centrally control the maximum available permissions for all accounts in an AWS Organization. By applying an SCP that denies all actions in a specific region (except us-east-1), the security team can enforce a region restriction across all member accounts, regardless of any IAM policies attached to users or roles. SCPs do not grant permissions themselves but act as a guardrail that limits what IAM policies can allow.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies, thinking that a simple IAM policy denying region access can achieve the same result, but SCPs are the only mechanism that can enforce restrictions across all users and roles in multiple accounts within an organization.

How to eliminate wrong answers

Option A is wrong because IAM permissions boundaries set the maximum permissions for an IAM user or role within a single account, but they cannot enforce region restrictions across multiple accounts in an organization. Option B is wrong because an IAM policy applied to the root user only affects the root user of a single account and does not scale to all accounts in the organization; also, AWS recommends against using root user credentials for daily operations. Option C is wrong because resource-based policies are attached to individual resources (e.g., S3 buckets, Lambda functions) and control access to that specific resource, not the ability to create resources in a region across an entire account or organization.

280
MCQhard

A security engineer needs to monitor for unauthorized API calls in real-time. Which combination of services should be used?

A.Amazon S3 event notifications and AWS Lambda
B.AWS CloudTrail and Amazon CloudWatch Logs with metric filters
C.AWS Config and Amazon SNS
D.Amazon GuardDuty and AWS CloudTrail
AnswerB

CloudTrail records every management and data API call as a JSON log entry containing the requesting IAM principal, the action, and the service, including access-denied errors such as UnauthorizedOperation or AccessDenied. When the trail is configured to deliver to CloudWatch Logs, you can create a metric filter with a pattern that matches specific error codes, and then attach a CloudWatch Alarm to that metric to notify on unauthorized API calls. This creates a deterministic, near-real-time alerting pipeline across the entire AWS account, which is exactly what the security engineer needs.

Why this answer

AWS CloudTrail records all API calls in an AWS account, and CloudWatch Logs can ingest those logs. By creating metric filters on CloudWatch Logs, you can define patterns that match unauthorized API calls (e.g., AccessDenied errors) and trigger alarms in real time. This combination provides the necessary logging and real-time monitoring capability.

Exam trap

The SCS-C02 exam often tests the distinction between services that log events (CloudTrail) versus services that detect threats (GuardDuty) versus services that monitor configuration (Config), leading candidates to choose GuardDuty because it sounds security-focused, but it does not provide real-time metric-based alerting on raw API calls.

How to eliminate wrong answers

Option A is wrong because Amazon S3 event notifications are designed to notify on S3 object-level events (e.g., PUT, DELETE), not on API calls across all AWS services; they lack the ability to monitor unauthorized API calls broadly. Option C is wrong because AWS Config is a service for resource inventory, configuration history, and compliance rules, not for real-time monitoring of API call logs; Amazon SNS alone cannot parse or filter API call data. Option D is wrong because Amazon GuardDuty is a threat detection service that analyzes findings from multiple sources (including CloudTrail) but does not provide real-time monitoring of raw API calls itself; it relies on CloudTrail for data but adds latency for threat analysis rather than immediate metric-based alerting.

281
MCQhard

A security engineer applies the above S3 bucket policy. An application tries to upload an object with the header "x-amz-server-side-encryption: AES256". What will happen?

A.The upload succeeds because the policy allows SSE-S3.
B.The upload fails because the encryption header does not match 'aws:kms'.
C.The upload succeeds because the object is encrypted.
D.The upload fails because the header is missing.
AnswerB

The bucket policy condition requires the aws:kms encryption algorithm, but the request specifies AES256. Since the header value fails the condition, S3 rejects the PutObject call with an access denied error rather than storing the object.

Why this answer

The bucket policy explicitly requires the condition that the encryption header equals 'aws:kms', which enforces SSE-KMS. When the application sends 'x-amz-server-side-encryption: AES256' (which requests SSE-S3), the request does not satisfy the policy condition, so S3 denies the upload with an AccessDenied error. The policy's condition is a hard gate, not a preference.

Exam trap

SCS-C02 often tests the difference between 'the request is encrypted' and 'the request satisfies the policy condition' — candidates see AES256 and assume encryption is enough, missing that the policy demands a specific encryption type.

How to eliminate wrong answers

Option A is wrong because although SSE-S3 is a valid encryption method, the bucket policy does not allow it — the policy specifically conditions on 'aws:kms', so a valid encryption method that doesn't match the policy still fails. Option C is wrong because the object being encrypted is irrelevant; the policy evaluates the request headers against the condition, and the header value 'AES256' fails the 'aws:kms' check. Option D is wrong because the header is present — it's just the wrong value; the failure is a mismatch, not a missing header.

282
MCQmedium

A company has an EC2 instance that needs to access an S3 bucket. The security team wants to use the principle of least privilege. Which method should be used to grant access?

A.Use a security group to allow outbound traffic to S3.
B.Store AWS access keys on the instance and use them in the application.
C.Create an IAM role with an S3 access policy and attach it to the EC2 instance profile.
D.Create a bucket policy that grants access to the EC2 instance ID.
AnswerC

Create an IAM role with a policy allowing the required S3 actions and attach that role to the EC2 instance via an instance profile. The instance then obtains temporary credentials from the instance metadata service, which are automatically rotated and used by the AWS SDK for signing S3 API requests. This is the secure, recommended pattern because it avoids persistent keys and follows least privilege.

Why this answer

It follows the principle of least privilege by using an IAM role with a scoped S3 access policy, which is then attached to the EC2 instance profile. This allows the EC2 instance to obtain temporary security credentials from the AWS STS service, avoiding long-term access keys and ensuring permissions are granted only as needed.

Exam trap

The trap here is that candidates confuse network-level controls (security groups) with IAM authorization, or mistakenly believe that an instance ID can be used as a principal in a bucket policy, which is not supported by AWS IAM.

How to eliminate wrong answers

Option A is wrong because security groups operate at the network layer (stateful firewall) and cannot grant IAM-level permissions to access S3; they control traffic but not authentication or authorization. Option B is wrong because storing long-term AWS access keys on the instance violates the principle of least privilege, increases the risk of credential exposure, and requires manual rotation. Option D is wrong because bucket policies cannot grant access based on an EC2 instance ID; they support principal ARNs (like IAM roles or users) but not instance IDs, and instance IDs are not IAM principals.

283
MCQeasy

A company needs to ensure that data in transit between an EC2 instance and an RDS database is encrypted. Which solution meets this requirement?

A.Use a VPN connection between the VPC and the database
B.Enable encryption at rest on the RDS instance
C.Enable SSL/TLS on the database connection
D.Use client-side encryption on the application
AnswerC

Enabling SSL/TLS encrypts the wire protocol between the EC2 client and the RDS endpoint, directly satisfying the in-transit encryption requirement. RDS supports TLS via certificate-based handshake, so the connection itself is protected regardless of storage-level encryption. This is the only option addressing data moving across the network.

Why this answer

SSL/TLS is the appropriate solution to encrypt data in transit between the EC2 instance and the RDS database. It ensures that data is encrypted during transmission, preventing eavesdropping or tampering. Option A is incorrect because a VPN connection encrypts traffic between networks but is unnecessary for direct connectivity within the same VPC; SSL/TLS is more straightforward.

Option B is incorrect because encryption at rest protects data stored on disk, not data in motion. Option D is incorrect because client-side encryption would require modifying the application to encrypt data before sending, which does not guarantee encryption of the entire communication channel.

284
MCQmedium

A security engineer is designing a multi-tier web application. The application uses an Application Load Balancer (ALB) to distribute traffic to EC2 instances in private subnets. The engineer needs to ensure that the EC2 instances only accept traffic from the ALB and not from any other source. Which security group configuration should the engineer use?

A.Allow inbound HTTP traffic from the ALB's public IP address on the EC2 instances' security group.
B.Allow inbound HTTP traffic from the VPC CIDR range on the EC2 instances' security group.
C.Allow inbound HTTP traffic from the ALB's security group on the EC2 instances' security group.
D.Allow inbound HTTP traffic from 0.0.0.0/0 on the EC2 instances' security group.
AnswerC

This is correct because referencing the ALB's security group as the source limits inbound HTTP to only traffic originating from the ALB's elastic network interfaces. When the ALB forwards requests to the instances, it uses its ENIs as the source IPs, which are associated with the ALB's security group, so such traffic matches the rule. Any other traffic, including direct internet access, is implicitly denied, providing a least-privilege security control.

Why this answer

It uses a security group reference to allow inbound HTTP traffic from the ALB's security group. This ensures that only traffic originating from the ALB (which has that security group attached) can reach the EC2 instances, regardless of the ALB's IP addresses or changes in the VPC CIDR. This is the recommended AWS best practice for securing traffic between an ALB and backend instances.

Exam trap

The trap here is that candidates often think they need to use the ALB's public IP address (Option A) or the VPC CIDR (Option B) as the source, not realizing that security group referencing is the correct and more secure method for allowing traffic from an ALB to backend instances.

How to eliminate wrong answers

Option A is wrong because the ALB's public IP addresses are dynamic and can change, making this approach unreliable and insecure; also, the ALB's public IPs are not the source IP of traffic reaching the instances (the ALB uses private IPs). Option B is wrong because allowing traffic from the entire VPC CIDR would permit any resource in the VPC (including compromised instances or unauthorized services) to reach the EC2 instances, violating the principle of least privilege. Option D is wrong because allowing traffic from 0.0.0.0/0 would expose the EC2 instances to the internet, defeating the purpose of placing them in private subnets and creating a severe security risk.

285
MCQhard

During an incident response, a security engineer needs to collect volatile memory from a compromised EC2 instance without affecting the running system. The instance is critical and cannot be stopped. Which approach is most appropriate?

A.Stop the instance, detach the root volume, and attach it to a forensics instance for analysis.
B.Use AWS License Manager to create a snapshot of the instance memory.
C.Use Amazon EC2 Rescue to collect memory dump.
D.Use AWS Systems Manager Run Command to execute a memory capture utility.
AnswerD

AWS Systems Manager Run Command offers a way to execute an approved memory capture utility (e.g., LiME, DumpIt, or a custom script) directly on the live instance without stopping it, preserving the volatile memory contents. Because the command runs in the guest OS via the SSM Agent, it can invoke kernel-level memory dumping tools with the appropriate privileges, and the captured image can be streamed to S3 for forensic analysis. This approach minimizes disruption and avoids alerting the attacker, making it the correct choice among the options.

Why this answer

AWS Systems Manager Run Command allows you to execute a memory capture utility (such as WinPmem or LiME) on the EC2 instance without stopping it, preserving volatile memory for forensic analysis. This approach uses the SSM Agent to run commands remotely, minimizing impact on the running system while collecting critical evidence like running processes, network connections, and kernel data.

Exam trap

The trap here is that candidates may think stopping the instance (Option A) is safe for forensics, but they forget that volatile memory is lost on shutdown, making it useless for memory analysis.

How to eliminate wrong answers

Option A is wrong because stopping the instance destroys volatile memory (RAM contents are lost on power-off), defeating the purpose of collecting a memory dump. Option B is wrong because AWS License Manager is a service for managing software licenses, not for capturing instance memory; it has no capability to snapshot RAM. Option C is wrong because Amazon EC2 Rescue is a tool for diagnosing and troubleshooting EC2 issues (e.g., collecting logs and configuration data), but it does not perform a full memory dump; it focuses on system health, not forensic memory acquisition.

286
MCQhard

A company is using AWS Transit Gateway to connect multiple VPCs and on-premises networks. The Security Engineer needs to ensure that traffic between VPCs is inspected by a central network appliance. Which architecture should the Engineer implement?

A.Use Transit Gateway with appliance mode enabled on the attachments to the inspection VPC, and route inter-VPC traffic through the inspection VPC.
B.Use VPC Peering connections between all VPCs and route traffic through the inspection VPC.
C.Place the network appliance in a public subnet of the inspection VPC and use internet gateways for routing.
D.Use Transit Gateway with route tables that point to the network appliance's ENI for all inter-VPC traffic.
AnswerA

Transit Gateway appliance mode on the attachments to the inspection VPC is the correct approach because it enables the Transit Gateway to forward packets to the network appliance even when return traffic would enter through a different attachment or follow a different path. This is critical for stateful appliances that must inspect both directions of a connection. Inter-VPC traffic is routed via TGW route tables to the inspection VPC attachment, and the appliance's ENI is the next hop inside that VPC. Without appliance mode, asymmetric routing could cause the appliance or the Transit Gateway to drop packets.

Why this answer

Enabling appliance mode on the Transit Gateway attachments to the inspection VPC forces the Transit Gateway to preserve the source and destination MAC addresses of packets, ensuring that asymmetric routing does not cause the network appliance to drop traffic. By routing inter-VPC traffic through the inspection VPC, the appliance can inspect all packets, and appliance mode ensures that return traffic is sent back through the same appliance, maintaining stateful inspection.

Exam trap

The trap here is that candidates often assume that simply routing traffic through an inspection VPC via Transit Gateway is sufficient, without understanding that appliance mode is required to prevent asymmetric routing and ensure stateful inspection works correctly.

How to eliminate wrong answers

Option B is wrong because VPC Peering does not support transitive routing; each peering connection is a one-to-one relationship, so traffic cannot be routed through a central inspection VPC without creating a full mesh of connections and complex routing. Option C is wrong because placing the appliance in a public subnet with an internet gateway would expose it to the internet and is not designed for private inter-VPC traffic inspection; internet gateways are for internet-bound traffic, not VPC-to-VPC routing. Option D is wrong because simply pointing route tables to the network appliance's ENI does not enable appliance mode; without appliance mode, the Transit Gateway may perform MAC address rewriting, causing asymmetric routing and stateful inspection failures.

287
MCQmedium

A company wants to allow users from an external AWS account to assume an IAM role in its account. What must be configured in both accounts?

A.An IAM password policy in both accounts.
B.Only the trusting account's role trust policy.
C.Only the external account's IAM policy to allow sts:AssumeRole.
D.Both the trusting account's role trust policy and the external account's IAM policy to allow sts:AssumeRole.
AnswerD

Cross-account role assumption requires two grants: the trusting account's role trust policy must name the external principal, and the external account's IAM policy must permit that principal to call sts:AssumeRole. Both sides must allow it.

Why this answer

Cross-account role assumption requires a two-sided trust relationship. The trusting account (where the role lives) must have a trust policy that names the external account as a Principal and allows sts:AssumeRole. The external account must also grant its users or roles an IAM policy permitting sts:AssumeRole on the role ARN, otherwise the request is denied even if the trust policy allows it.

Exam trap

The trap is assuming that a trust policy alone is sufficient for cross-account access, when in fact AWS requires permissions on both the trusting and the calling side — a classic two-sided authorization misconception.

How to eliminate wrong answers

Option A is wrong because an IAM password policy only governs console password complexity and rotation; it has no effect on programmatic role assumption via STS. Option B is wrong because configuring only the trusting account's trust policy is insufficient — the caller's identity in the external account still needs an explicit IAM permission to call sts:AssumeRole. Option C is wrong because configuring only the external account's IAM policy is insufficient — without a trust policy in the trusting account naming the external principal, STS will reject the AssumeRole call.

288
MCQmedium

A security engineer discovers that an IAM policy allows 'iam:CreateUser' and 'iam:CreateAccessKey' for all users in the account. Which risk does this pose?

A.Users can create new IAM users and programmatic access keys
B.Users can disable CloudTrail logging
C.Users can decrypt data in S3
D.Users can modify VPC security groups
AnswerA

The policy explicitly grants IAM permissions such as iam:CreateUser and iam:CreateAccessKey. This allows an authenticated user to provision a new IAM identity and associated programmatic credentials, effectively creating a backdoor account with permissions that can be escalated to full administrative access. Because the new user and access key are fully functional and can be granted additional policies, this action represents a high-risk privilege escalation vector.

Why this answer

The IAM policy allows 'iam:CreateUser' and 'iam:CreateAccessKey', which enables users to create new IAM users and programmatic access keys, leading to unauthorized access and privilege escalation. Option B is incorrect because the policy does not grant permissions to disable CloudTrail logging. Option C is incorrect because creating users/keys does not allow decrypting data in S3.

Option D is incorrect because it does not allow modifying VPC security groups.

289
MCQmedium

A security engineer is investigating a potential security incident involving an EC2 instance. The engineer needs to determine if any unauthorized SSH keys were added to the instance's authorized_keys file. Which AWS service should be used to detect this change?

A.Amazon Inspector
B.AWS CloudTrail
C.Amazon GuardDuty
D.AWS Config
AnswerD

AWS Config is the correct service because it records configuration state changes and can track software and file inventory from managed instances through an integration with AWS Systems Manager Inventory. When SSM Inventory collects file attributes such as path, size, and modification time, AWS Config can use custom rules or advanced queries to flag deviations from a known-good baseline. This makes AWS Config the service that directly supports file-change audits and compliance enforcement in response to suspected tampering.

Why this answer

AWS Config is the correct service because it can be used to monitor configuration changes to EC2 instances, including changes to the authorized_keys file when integrated with AWS Systems Manager. While AWS Config does not natively track guest OS file changes, you can create a custom AWS Config rule that invokes a Lambda function to check the instance's Systems Manager inventory or run a command to verify the file contents. CloudTrail tracks API calls but does not monitor internal OS changes.

Amazon Inspector and GuardDuty focus on vulnerabilities and threats, not configuration changes. Therefore, AWS Config, with appropriate custom rules, is the best choice among the options.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail's ability to track API-level changes (e.g., modifying an EC2 instance) with the need to monitor guest OS file changes, which requires a configuration management service like AWS Config, not CloudTrail.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and unintended network exposure, not for tracking file changes like SSH authorized_keys. Option B is wrong because AWS CloudTrail records API calls made to the AWS environment, such as launching or modifying EC2 instances, but it does not monitor changes inside the guest OS, such as modifications to the authorized_keys file. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes logs (e.g., VPC Flow Logs, DNS logs) for malicious activity, but it does not track configuration changes to files within an EC2 instance.

290
MCQhard

Refer to the exhibit. A security engineer applied the bucket policy shown. What is the effect of this policy?

A.All PutObject requests are denied.
B.Only GetObject requests that use HTTP are denied.
C.Only GetObject requests from specific IP ranges are denied.
D.All GetObject requests to the bucket are denied.
AnswerB

Correct. The policy denies GetObject requests when aws:SecureTransport is false (HTTP).

Why this answer

The bucket policy includes a Deny statement for s3:GetObject requests that are not using HTTPS. The condition `aws:SecureTransport` is set to false, meaning the request is over HTTP. Therefore, any GetObject request made over HTTP is denied.

PutObject requests are not affected, and GetObject requests over HTTPS are allowed regardless of IP address.

Exam trap

The trap here is that candidates overlook the `Null` condition on `aws:SecureTransport` and assume the `NotIpAddress` condition alone denies all requests from outside the IP range, missing that the policy only triggers when the request is over HTTP.

How to eliminate wrong answers

Option A is wrong because the policy only denies `s3:GetObject`, not `s3:PutObject`, so PutObject requests are not denied. Option C is wrong because the policy denies requests from IPs outside the specified range only when the request uses HTTP; it does not deny requests from specific IP ranges—it denies requests not from that range, but only under the HTTP condition. Option D is wrong because the policy does not deny all GetObject requests; it only denies those made over HTTP, leaving HTTPS GetObject requests unaffected.

291
MCQmedium

A security engineer needs to restrict outbound traffic from a VPC to only allow HTTPS traffic to specific domains (e.g., api.example.com). The VPC has a NAT gateway in a public subnet. What is the most secure way to implement this restriction?

A.Configure security group egress rules to allow HTTPS to 0.0.0.0/0.
B.Deploy an AWS Network Firewall in the VPC and configure domain filtering rules.
C.Configure network ACL outbound rules to allow HTTPS to the IP addresses of the allowed domains.
D.Create a VPC endpoint for Amazon S3 and route traffic through it.
AnswerB

AWS Network Firewall is a managed, stateful intrusion prevention system that can perform application-layer inspection of outbound traffic, including domain name filtering. It can decrypt TLS traffic via TLS inspection or evaluate the Server Name Indication (SNI) in the handshake to allow or block specific domain names, regardless of the underlying IP address. By deploying Network Firewall in a VPC with a stateful rule group referencing allowed domains, the engineer can enforce the required domain-based restriction accurately.

Why this answer

AWS Network Firewall provides stateful, application-layer inspection that can filter outbound HTTPS traffic based on domain names (SNI/TLS hostnames), not just IP addresses. This allows you to restrict traffic to specific domains like api.example.com even if their IP addresses change, which is more secure and manageable than IP-based rules. Security groups and network ACLs cannot filter by domain name, and VPC endpoints are for specific AWS services, not general HTTPS domains.

Exam trap

The trap here is that candidates assume network ACLs or security groups can filter by domain name, but they operate only at Layers 3 and 4, whereas domain filtering requires Layer 7 inspection provided by AWS Network Firewall.

How to eliminate wrong answers

Option A is wrong because security group egress rules allow traffic to 0.0.0.0/0 for HTTPS, which permits outbound traffic to any destination, failing to restrict to specific domains. Option C is wrong because network ACLs are stateless and can only filter by IP addresses and ports, not domain names; IP addresses for domains like api.example.com can change, making this approach brittle and insecure. Option D is wrong because VPC endpoints are designed for private connectivity to AWS services (e.g., S3, DynamoDB) and cannot be used to restrict outbound HTTPS traffic to arbitrary external domains.

292
MCQhard

A security engineer is troubleshooting connectivity issues from an EC2 instance in a private subnet to an S3 bucket. The instance has a security group allowing outbound HTTPS (443) to 0.0.0.0/0, and the subnet's network ACL allows outbound HTTPS to 0.0.0.0/0. However, requests to S3 are timing out. Which additional configuration is most likely required?

A.Attach an IAM role to the EC2 instance with S3 permissions
B.Modify the security group to allow traffic to the S3 region-specific IP range
C.Add a VPC Gateway Endpoint for S3 and update the route table
D.Configure a TLS termination proxy
AnswerC

A VPC Gateway Endpoint for S3 is the correct fix because it installs a route entry in the private subnet's route table using the S3 prefix list, allowing traffic destined for S3 to traverse AWS's internal network instead of requiring an internet gateway or NAT device. Without this endpoint, an instance in a private subnet has no viable next hop for S3 public IP ranges, so TCP connections time out. Updating the route table to include the endpoint's prefix-list destination completes the configuration.

Why this answer

An EC2 instance in a private subnet has no route to the internet, so it cannot reach S3's public endpoints even though the security group and NACL allow outbound HTTPS. The correct fix is to create a VPC Gateway Endpoint for S3 and add a route in the subnet's route table pointing S3 traffic to the endpoint. This keeps traffic on the AWS private network and avoids the need for a NAT gateway.

Exam trap

The trap is assuming that a permissive security group and NACL are sufficient for outbound connectivity — candidates forget that a private subnet has no route to the internet and that S3 access requires either a NAT gateway or a VPC Gateway Endpoint.

How to eliminate wrong answers

Option A is wrong because an IAM role grants authorization (permission to call S3 APIs) but does not provide network reachability; without a route to S3, the request times out before any IAM evaluation occurs. Option B is wrong because S3 does not have a fixed region-specific IP range that a security group can target reliably — S3 uses a large, changing set of public IPs, and the security group already allows 0.0.0.0/0 on 443, so adding a narrower range would not solve the routing problem. Option D is wrong because a TLS termination proxy addresses encryption offloading, not network path availability; it does not create a route from a private subnet to S3.

293
MCQmedium

A security team discovers that an IAM user's credentials are being used from an unusual geographic location. Which AWS service can provide automated response to revoke the user's access immediately?

A.Amazon GuardDuty
B.AWS Systems Manager Automation
C.AWS Lambda
D.AWS Config
AnswerB

AWS Systems Manager Automation is a fully managed service that runs predefined runbooks to execute operational and security response workflows. For IAM credential compromise, runbooks such as AWSDisableIAMAccessKey can be invoked via an EventBridge rule that listens for GuardDuty findings, automatically disabling the affected access key. This provides policy-driven, serverless remediation without requiring custom code, and the runbook can be scoped to least-privilege permissions for the automation role, making it the correct choice for event-driven incident response.

Why this answer

AWS Systems Manager Automation is correct because it can be triggered by Amazon GuardDuty findings (e.g., UnauthorizedAccess:IAMUser/AnomalousBehavior) via Amazon EventBridge to run an automation document that immediately revokes the IAM user's access keys and applies a deny-all policy. This provides a fully automated, low-latency response without requiring manual intervention or custom code.

Exam trap

The trap here is that candidates often pick Amazon GuardDuty because they associate it with threat detection, but they overlook that GuardDuty only detects and alerts—it requires a separate automation service like Systems Manager Automation to actually perform the revocation.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that identifies anomalous activity but does not have built-in capabilities to automatically revoke IAM user credentials; it relies on downstream services like Systems Manager Automation or Lambda for response. Option C is wrong because AWS Lambda is a compute service that can execute custom code to revoke credentials, but it is not a managed automated response service itself—it requires you to write and maintain the function, whereas Systems Manager Automation provides a pre-built, auditable runbook. Option D is wrong because AWS Config is a resource compliance and configuration tracking service; it cannot directly revoke IAM credentials or respond to real-time security events.

294
MCQmedium

A security engineer notices that an EC2 instance in a private subnet is able to make outbound connections to the internet. The instance does not have a public IP, and there is no NAT gateway or instance in the VPC. What is the most likely cause?

A.The VPC has an egress-only internet gateway for IPv6 traffic.
B.The instance has a public IP assigned automatically via Auto-assign Public IP.
C.The instance is using a VPC endpoint (Gateway type) for S3.
D.The subnet's route table has a default route (0.0.0.0/0) pointing to an internet gateway.
AnswerA

An egress-only internet gateway (EIGW) is an IPv6-specific VPC component that enables instances with IPv6 addresses to initiate outbound connectivity to the internet, but it blocks all inbound connections from the internet. Because an EIGW is completely independent of IPv4 addressing, an instance can reside in a private subnet without a public IPv4 address and still reach the internet via a route table entry for ::/0 pointing to the EIGW. In this scenario, the observed internet access is therefore consistent with the VPC having an egress-only internet gateway for IPv6 traffic.

Why this answer

An egress-only internet gateway (EIGW) allows outbound IPv6 traffic from instances in a private subnet without requiring a public IPv4 address or NAT. Since the instance is making outbound connections to the internet and has no public IP or NAT, and the VPC likely has IPv6 enabled, the EIGW is the most plausible cause. Option D is incorrect because a default route to an internet gateway requires the instance to have a public IPv4 address for return traffic, which contradicts the scenario.

Exam trap

The trap here is that candidates assume a private subnet inherently blocks internet access, but the question tests whether they understand that a subnet's route table—not its public/private designation—determines outbound connectivity, and a 0.0.0.0/0 route to an IGW makes it a public subnet regardless of the instance's IP assignment.

How to eliminate wrong answers

Option A is wrong because an egress-only internet gateway (EIGW) only supports IPv6 traffic, and the question does not mention IPv6; it would not enable outbound IPv4 connections. Option B is wrong because the instance does not have a public IP, and Auto-assign Public IP only applies at launch; even if enabled, the instance would have a public IP, contradicting the premise. Option C is wrong because a VPC Gateway Endpoint for S3 only provides private connectivity to S3, not general internet access; it cannot route traffic to arbitrary internet destinations.

295
MCQmedium

A developer needs to allow an EC2 instance to read from a DynamoDB table named 'Orders' in the same account. The security team requires that the permissions be granted using an instance profile. Which steps should be taken?

A.Create an IAM role with a policy that allows dynamodb:GetItem on the 'Orders' table, create an instance profile, add the role to the profile, and launch the EC2 instance with the instance profile
B.Create an instance profile and attach a policy to it, then launch the EC2 instance with the instance profile
C.Create an IAM role with the required policy, then attach the role directly to the EC2 instance during launch
D.Create an IAM user with programmatic access, store the access key in a secure S3 bucket, and have the EC2 instance retrieve the credentials at startup
AnswerA

This is the correct and canonical method. Create an IAM role that includes a policy granting the `dynamodb:GetItem` action on the `Orders` table, define a trust policy that lets the EC2 service (`ec2.amazonaws.com`) assume it, and then create an instance profile containing that role. When you launch the EC2 instance with the instance profile, AWS automatically supplies temporary credentials through the instance metadata service (IMDSv2), so the SDK can read from DynamoDB without any stored keys. This avoids long-lived credentials and is the supported mechanism for giving an EC2 instance permissions.

Why this answer

The correct steps are to create an IAM role with the necessary policy, create an instance profile, add the role to the instance profile, and then launch the EC2 instance with that instance profile. This grants the EC2 instance temporary credentials to access DynamoDB. The instance profile is the container for the role and is required for EC2 to assume the role.

Exam trap

SCS-C02 often tests the difference between IAM roles and instance profiles. Candidates may think they can attach a role directly to an EC2 instance, but an instance profile is required. Also, they might confuse attaching policies to instance profiles instead of roles.

How to eliminate wrong answers

Option B is wrong because you cannot attach a policy directly to an instance profile; policies are attached to roles, and the role is added to the instance profile. Option C is wrong because you cannot attach an IAM role directly to an EC2 instance during launch; you must use an instance profile. Option D is wrong because using an IAM user with programmatic access and storing keys in S3 is insecure and not a best practice; it also violates the requirement to use an instance profile.

296
MCQeasy

A security engineer needs to audit all API calls made in an AWS account for the past 90 days. Which AWS service should the engineer use?

A.Amazon S3 access logs
B.AWS CloudTrail
C.AWS Config
D.Amazon CloudWatch Logs
AnswerB

AWS CloudTrail is the authoritative audit service that records every API call made in the account, including the identity of the principal, the source IP address, the time, and the request parameters. By default, it captures management events across all AWS services, and it can be configured to log data events for services like S3 and Lambda. These event logs are delivered to an S3 bucket and can be integrated with CloudWatch Logs for alerting and analysis, making it the correct choice for comprehensive API auditing.

Why this answer

AWS CloudTrail (Option B) is the correct service for auditing all API calls made in an AWS account over the past 90 days. It records API activity and can be configured to store logs for 90 days in the management event history. Option A (Amazon S3 access logs) logs access to S3 objects, not API calls.

Option C (AWS Config) tracks resource configuration changes, not API calls. Option D (Amazon CloudWatch Logs) is for monitoring, storing, and accessing log files from various sources, but it is not specifically designed for auditing API calls; CloudTrail is the primary service for that purpose.

297
MCQhard

Refer to the exhibit. An IAM policy is attached to a user. The user reports that they cannot upload objects to the S3 bucket 'example-bucket' using the AWS CLI from a remote location. What is the MOST likely cause?

A.The CLI is using HTTP instead of HTTPS.
B.The bucket policy denies access.
C.The bucket requires server-side encryption.
D.The user is not authorized to upload to the bucket.
E.The user does not have s3:PutObject permission.
AnswerA

The IAM policy includes a Deny statement that triggers when the `aws:SecureTransport` condition is false, which is exactly the case for HTTP requests. The AWS CLI can be configured to use an HTTP endpoint (e.g., via `--endpoint-url http://...`), and doing so causes the Deny to take precedence over the Allow for `s3:PutObject`. As a result, the upload is rejected with an AccessDenied error.

Why this answer

The IAM policy shown in the exhibit includes a `Deny` effect for `s3:PutObject` when the request does not use `aws:SecureTransport` (i.e., HTTPS). If the AWS CLI is configured to use HTTP instead of HTTPS, the condition `aws:SecureTransport=false` is met, and the explicit deny blocks the upload. The user reports the issue from a remote location, which often involves misconfigured endpoints or proxies that force HTTP.

Exam trap

The trap here is that candidates often focus on the `Allow` statement and overlook the `Deny` statement with the `aws:SecureTransport` condition, assuming the user lacks permission entirely rather than recognizing the protocol-level restriction.

How to eliminate wrong answers

Option B is wrong because the exhibit shows an IAM policy attached to the user, not a bucket policy; a bucket policy is a separate resource-based policy that could deny access, but the question states the policy is attached to the user, and no bucket policy is mentioned. Option C is wrong because the policy does not reference server-side encryption (e.g., `s3:x-amz-server-side-encryption`), and the error is about upload failure, not encryption mismatch. Option D is wrong because the user is authorized via the IAM policy's `Allow` statement for `s3:PutObject`; the issue is the `Deny` condition on `aws:SecureTransport`.

Option E is wrong because the user does have `s3:PutObject` permission granted by the `Allow` statement; the problem is the overriding `Deny` when HTTP is used.

298
Multi-Selectmedium

A security engineer is configuring a VPC for a web application. The VPC has public and private subnets. The web servers are in public subnets and the database servers are in private subnets. The engineer wants to ensure that the database servers are not accessible from the internet. Which two actions should the engineer take?

Select 2 answers
A.Place the database instances in a public subnet with a NAT gateway.
B.Assign public IP addresses to the database instances.
C.Ensure the route table for the database subnets does not have a default route to an Internet Gateway.
D.Create a security group for the database instances that allows inbound traffic only from the web servers' security group.
E.Configure a network ACL on the database subnets to deny all inbound traffic.
AnswersC, D

This is correct because omitting a 0.0.0.0/0 route to the internet gateway from the database subnet's route table makes it a private subnet, so unsolicited inbound traffic from the internet has no path to reach the database instances. This routing-layer control ensures that even if a security group rule were overly permissive, the network stack itself would still drop internet-originated packets destined for the database. This is a foundational defense-in-depth measure in VPC design and is required to keep database instances isolated from the public internet.

Why this answer

Removing the default route (0.0.0.0/0) to an Internet Gateway (IGW) from the route table associated with the database subnets ensures that traffic from those subnets cannot reach the internet, and the internet cannot initiate connections to instances in those subnets. This is the fundamental network-level isolation required for private subnets in a VPC.

Exam trap

The trap here is that candidates often confuse network ACLs with security groups, thinking a deny-all NACL is sufficient, but they overlook that NACLs are stateless and would block necessary return traffic, whereas security groups are stateful and automatically allow return traffic for permitted inbound connections.

299
MCQmedium

A security engineer configured the S3 bucket policy shown above for CloudTrail log delivery, but CloudTrail is not delivering logs. What is the MOST likely reason?

A.The policy does not include s3:GetBucketAcl permission.
B.The bucket is in the wrong region.
C.The resource ARN is incorrect.
D.The bucket does not have default encryption enabled.
AnswerA

CloudTrail's bucket policy must explicitly grant the service principal cloudtrail.amazonaws.com both s3:GetBucketAcl and s3:PutObject permissions for the target bucket. s3:GetBucketAcl is what lets CloudTrail verify that the bucket's access control list permits CloudTrail to write and manage log objects; without this permission, CloudTrail aborts the delivery configuration with an access denial even if PutObject is correctly allowed. Therefore, omitting s3:GetBucketAcl is a direct cause of the 'bucket policy does not allow for S3 access' error.

Why this answer

CloudTrail requires the s3:GetBucketAcl permission on the destination S3 bucket to verify that the bucket policy grants the necessary access. Without this permission, CloudTrail cannot confirm it has write access and will fail to deliver logs. The bucket policy must explicitly allow the CloudTrail service principal to perform GetBucketAcl and PutObject actions.

Exam trap

The trap here is that candidates often focus on the PutObject permission or the resource ARN, overlooking the mandatory GetBucketAcl permission that CloudTrail requires for initial validation.

How to eliminate wrong answers

Option B is wrong because CloudTrail can deliver logs to a bucket in any region as long as the bucket policy allows cross-region access; the bucket region does not prevent delivery. Option C is wrong because the resource ARN in the policy is typically correct when it matches the bucket name and account, and an incorrect ARN would cause an access denied error, but the most common missing permission is GetBucketAcl. Option D is wrong because default encryption on the S3 bucket is not a prerequisite for CloudTrail log delivery; CloudTrail can write unencrypted objects or use server-side encryption with S3-managed keys (SSE-S3) by default.

300
MCQeasy

A company wants to protect data in transit between an on-premises data center and Amazon S3. Which AWS service should be used to establish a dedicated, encrypted connection?

A.AWS Direct Connect without VPN
B.AWS Transit Gateway
C.AWS Direct Connect with an IPsec VPN
D.AWS Site-to-Site VPN over the internet
AnswerC

AWS Direct Connect with an IPsec VPN layers an encrypted VPN tunnel over a dedicated, private Direct Connect connection, giving you both isolation from the public internet and traffic confidentiality. The IPsec protocol authenticates and encrypts the packets, ensuring that data is protected in transit while still benefiting from the predictable latency and throughput of the physical link. This is the recommended pattern when you need both dedicated bandwidth and encryption.

Why this answer

AWS Direct Connect alone provides a dedicated private network path but does not encrypt traffic in transit. To achieve both a dedicated connection and encryption, you must pair Direct Connect with an IPsec VPN running over the dedicated link. This combination gives the private, consistent bandwidth of Direct Connect plus the encryption guarantees of IPsec, satisfying the requirement for encrypted data in transit.

Exam trap

SCS-C02 often tests the misconception that Direct Connect is encrypted by default — candidates must remember that encryption requires an explicit IPsec VPN or MACsec layer on top of the dedicated connection.

How to eliminate wrong answers

Option A is wrong because Direct Connect without VPN does not encrypt traffic — data travels in plaintext over the dedicated circuit. Option B is wrong because Transit Gateway is a network hub for connecting VPCs and on-premises networks, not an encryption or dedicated-connection service. Option D is wrong because Site-to-Site VPN over the public internet is encrypted but does not provide a dedicated connection, and its performance is subject to internet variability.

Page 3

Page 4 of 17

Page 5