Courseiva

AWS Certified Security Specialty SCS-C02 (SCS-C02) — Questions 301–375

1205 questions total · 17pages · All types, answers revealed

Page 4

Page 5 of 17

Page 6
301
MCQhard

A company has a VPC with a public subnet and a private subnet. An Amazon RDS instance is in the private subnet, and an application server is in the public subnet. The security team needs to allow the application server to connect to the RDS instance on port 3306 (MySQL). Which configuration will meet this requirement securely?

A.Add an inbound rule to the RDS security group that allows traffic from the VPC CIDR on port 3306.
B.Add an inbound rule to the RDS security group that allows traffic from the security group of the application server on port 3306.
C.Add an inbound rule to the RDS security group that allows traffic from the subnet CIDR of the application server on port 3306.
D.Add an inbound rule to the RDS security group that allows traffic from 0.0.0.0/0 on port 3306.
AnswerB

This is the correct approach: referencing the application server's security group (SG) as the source in the RDS inbound rule permits only traffic originating from network interfaces attached to that specific SG. This pattern—often called SG chaining—is dynamically updated if the instance's private IP changes, is not tied to subnet boundaries, and automatically covers any additional instances that later receive the same SG, making it the most precise and maintainable solution.

Why this answer

It uses a security group reference as the source in the inbound rule for the RDS security group. This allows traffic only from the specific application server(s) associated with that security group, regardless of their IP addresses, and automatically scales if the application server is replaced or scaled. This is the most secure and AWS-recommended method for controlling traffic between resources within a VPC.

Exam trap

The trap here is that candidates often confuse security group references with CIDR-based rules, mistakenly thinking that allowing traffic from the subnet CIDR (Option C) is equivalent to allowing traffic from the application server, when in fact it permits any resource in that subnet to connect.

How to eliminate wrong answers

Option A is wrong because allowing traffic from the entire VPC CIDR is overly permissive; any resource in the VPC, including unintended instances or services, could connect to the RDS instance, violating the principle of least privilege. Option C is wrong because allowing traffic from the subnet CIDR of the application server permits any resource launched in that subnet (e.g., other instances or containers) to access the RDS instance, not just the intended application server. Option D is wrong because allowing traffic from 0.0.0.0/0 exposes the RDS instance to the entire internet, which is a severe security risk and contradicts the requirement to keep the RDS instance in a private subnet.

302
Multi-Selecthard

A company needs to protect data in Amazon S3 by ensuring that only authorized users can access objects, and all access is logged. Which TWO services should be used together? (Choose TWO.)

Select 2 answers
A.AWS Identity and Access Management (IAM)
B.AWS CloudTrail
C.AWS KMS
D.AWS WAF
E.Amazon CloudWatch
AnswersA, B

AWS Identity and Access Management enforces authentication and authorisation through policies, satisfying the stem's requirement that only authorised users access S3 objects. It provides the permission boundary, while a logging service supplies the audit trail of that access.

Why this answer

AWS Identity and Access Management (IAM) is correct because it enables you to define granular permissions for S3 objects, ensuring that only authorized users or roles can access them via IAM policies or S3 bucket policies. AWS CloudTrail is correct because it logs all API calls made to S3, including object-level operations like GetObject and PutObject, providing an audit trail for access. Together, they satisfy the requirement of controlling access and logging all access.

Exam trap

The trap here is that candidates often confuse AWS KMS with access control because encryption is related to data protection, but KMS does not authorize user access or log access events, which are the core requirements in this question.

303
MCQeasy

A company needs to be alerted when root account credentials are used in their AWS account. Which service should be used to create a metric filter and alarm for this event?

A.Amazon GuardDuty
B.AWS Config
C.AWS CloudTrail
D.Amazon CloudWatch Logs
AnswerD

Amazon CloudWatch Logs can receive CloudTrail events and apply a metric filter, for example matching $.userIdentity.type = 'Root' and $.eventName = 'ConsoleLogin', to count root credential activity. A CloudWatch alarm on that metric threshold can then trigger an SNS notification to alert the company in near real time. This is the correct service because it directly enables custom, log-driven alerting on the root account usage pattern.

Why this answer

Amazon CloudWatch Logs can monitor CloudTrail log events for root account usage by creating a metric filter that matches the `userIdentity.type` field with a value of `Root`. When the filter detects a match, it triggers a CloudWatch alarm to notify the operations team. This is the standard AWS-recommended approach for alerting on root activity.

Exam trap

The trap here is that candidates confuse CloudTrail (the log source) with CloudWatch Logs (the service that processes and alerts on logs), assuming CloudTrail itself can create alarms when it only delivers logs to S3 or CloudWatch Logs.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that uses machine learning to identify malicious activity, but it does not natively support creating custom metric filters or alarms for specific CloudTrail events like root login. Option B is wrong because AWS Config is a service for evaluating resource configurations against rules, not for monitoring API call patterns in logs; it cannot create metric filters or alarms on CloudTrail events. Option C is wrong because AWS CloudTrail itself records API activity and delivers log files, but it does not provide the ability to create metric filters or alarms; that functionality is delegated to CloudWatch Logs.

304
Multi-Selecthard

Which THREE are best practices for securing AWS CloudTrail log files? (Choose three.)

Select 3 answers
A.Restrict access to the S3 bucket using a bucket policy that requires MFA and encryption.
B.Enable CloudTrail log file integrity validation.
C.Enable server-side encryption (SSE) for the S3 bucket.
D.Deliver logs to an S3 bucket in the same region as the trail.
E.Set a lifecycle policy to delete logs after 30 days.
AnswersA, B, C

Restricting access to the S3 bucket with a bucket policy that includes the aws:MultiFactorAuthPresent condition ensures that every request requires MFA authentication, significantly reducing the risk of unauthorized log access even if a user's long-term credentials are compromised. Adding an encryption enforcement condition, such as requiring TLS (aws:SecureTransport) or mandatory SSE-KMS headers, further protects the logs in transit and at rest. This layered access control is a best practice because it hardens the audit trail against both external attacks and accidental exposure.

Why this answer

Restricting access to the S3 bucket with a bucket policy that requires MFA (Multi-Factor Authentication) and encryption (e.g., aws:MultiFactorAuthPresent and aws:SecureTransport conditions) ensures that only authenticated and authorized users can access CloudTrail logs, and that data is encrypted in transit. This prevents unauthorized deletion or modification of log files, which is critical for maintaining an immutable audit trail.

Exam trap

The trap here is that candidates often confuse operational convenience (e.g., same-region delivery or short retention) with security best practices, forgetting that security requires cross-region resilience and long-term retention for auditability.

305
MCQhard

A company uses AWS CloudTrail to log all API calls across multiple accounts in AWS Organizations. The security team notices that management events are being logged, but data events for Amazon S3 are not appearing in the CloudTrail logs for any account. The team needs to enable data event logging for S3 across all accounts. Currently, the organization trail is configured in the management account, and all member accounts have default CloudTrail configurations. What is the MOST efficient way to enable S3 data event logging for all current and future accounts in the organization?

A.Ask each member account to create a new trail in their own account with S3 data events enabled.
B.Update the existing organization trail's event selectors in the management account to include S3 data events for all accounts.
C.Enable S3 server access logging on all S3 buckets across the organization and aggregate logs in a central S3 bucket.
D.Create a new organization trail in the management account with S3 data events enabled, and share it with member accounts.
AnswerB

In the management account, edit the existing organization trail and update its event selectors to include S3 data events, choosing 'All S3 buckets' for object-level operations such as GetObject, PutObject, and DeleteObject. CloudTrail propagates this configuration to every member account, so all current and future accounts are captured automatically without per-account changes. This is the intended, least-effort method and keeps delivery centralized in the original destination bucket.

Why this answer

An organization trail in the management account can have its event selectors updated to include S3 data events for all accounts in the organization. This change automatically applies to all existing and future member accounts, as organization trails are replicated to all accounts by AWS CloudTrail. No additional configuration is needed in member accounts, making it the most efficient approach.

Exam trap

The trap here is that candidates may think they need to create a new organization trail or involve member accounts, but the most efficient solution is to update the existing organization trail's event selectors, which automatically applies to all current and future accounts.

How to eliminate wrong answers

Option A is wrong because asking each member account to create a separate trail is inefficient and does not scale for future accounts; it also duplicates effort and log storage. Option C is wrong because S3 server access logging logs object-level access requests (e.g., GET, PUT) but is not CloudTrail data event logging; it does not integrate with CloudTrail's event history or organization-wide trails. Option D is wrong because you cannot 'share' a trail with member accounts; organization trails are created in the management account and automatically applied to all accounts in the organization—creating a new trail is unnecessary when the existing organization trail can be updated.

306
MCQeasy

A company wants to encrypt data stored in Amazon S3 using server-side encryption with customer-provided keys (SSE-C). Which statement is correct regarding SSE-C?

A.The customer provides the encryption key in each request to S3.
B.AWS manages the encryption keys.
C.The same encryption key is used for all objects in the bucket.
D.The encryption key is stored in AWS KMS.
AnswerA

Under SSE-C, the customer must provide the encryption key in the headers of every S3 request, such as x-amz-server-side-encryption-customer-key. S3 uses that key to encrypt the object at write time and to decrypt it at read time, then discards the key after the request completes. Because the key is never stored by AWS, it must be supplied again for each upload, download, or header retrieval.

Why this answer

SSE-C requires the customer to provide the encryption key and its MD5 digest in every PUT or GET request to Amazon S3. S3 uses the key to encrypt the object at rest and then discards the key; it is never stored by AWS. This ensures the customer retains full control over the encryption key material.

Exam trap

The trap here is that candidates confuse SSE-C with SSE-S3 or SSE-KMS, assuming AWS manages the keys or that keys are stored in KMS, when in fact SSE-C requires the customer to supply the key with every request and AWS never retains it.

How to eliminate wrong answers

Option B is wrong because SSE-C explicitly does not involve AWS managing the keys; the customer provides and manages the key. Option C is wrong because SSE-C requires a unique encryption key per request; the same key is not reused for all objects in the bucket unless the customer deliberately sends the same key each time. Option D is wrong because the encryption key is not stored in AWS KMS; SSE-C keys are provided by the customer in each request and are not persisted by AWS.

307
MCQeasy

A company wants to monitor CPU utilization of their EC2 instances and receive an alert when utilization exceeds 80% for 5 consecutive minutes. Which AWS service should be used to set up this metric alarm?

A.Amazon CloudWatch Alarms
B.Amazon Inspector
C.AWS Config
D.AWS CloudTrail
AnswerA

Amazon CloudWatch Alarms watch the EC2 instance's CPUUtilization metric published to CloudWatch and transition to ALARM when the value crosses a defined threshold for consecutive evaluation periods. Because this metric and the alarm's state are specifically designed for performance monitoring, an alarm can directly trigger actions such as SNS notifications or Auto Scaling policies when CPU load becomes unacceptable.

Why this answer

Amazon CloudWatch Alarms is the correct service because it is specifically designed to monitor CloudWatch metrics, such as EC2 CPU utilization, and trigger actions (e.g., SNS notifications) when a metric crosses a defined threshold for a specified number of consecutive evaluation periods. In this scenario, you would create a CloudWatch Alarm on the `CPUUtilization` metric with a threshold of 80%, set the period to 1 minute, and configure the alarm to evaluate 5 consecutive datapoints (periods) to meet the '5 consecutive minutes' requirement.

Exam trap

The trap here is that candidates often confuse AWS Config (configuration compliance) or CloudTrail (API auditing) with CloudWatch Alarms, because they all involve 'monitoring' in a broad sense, but only CloudWatch Alarms handles metric-based threshold alerts for performance data like CPU utilization.

How to eliminate wrong answers

Option B (Amazon Inspector) is wrong because it is a vulnerability management service that scans EC2 instances for software vulnerabilities and unintended network exposure, not for monitoring CPU utilization metrics. Option C (AWS Config) is wrong because it is a service for evaluating and recording resource configuration changes and compliance against rules, not for real-time metric monitoring or alarm thresholds. Option D (AWS CloudTrail) is wrong because it records API activity and user actions for auditing and governance, not for monitoring performance metrics like CPU utilization.

308
MCQeasy

A company needs to encrypt data at rest in its Amazon EBS volumes. The company wants to use an encryption key that is automatically rotated every year without any manual intervention. Which key type should be used?

A.Imported key material in a customer managed key
B.AWS managed key for EBS
C.Customer managed key with manual rotation
D.Default EBS encryption using an AWS managed key
AnswerB

The AWS managed key for EBS (aws/ebs) is a KMS key that AWS creates and manages in the customer's account, and AWS KMS automatically rotates it once per year. Because EBS volumes can use this key by default and no customer action is required for rotation, it satisfies the requirement for automatic rotation. This is the key type that the question is asking to identify.

Why this answer

AWS managed keys are automatically rotated annually. Option B (AWS managed key for EBS) is correct because this key type handles rotation automatically without any manual intervention. Option A (Imported key material in a customer managed key) is incorrect because imported key material does not support automatic rotation.

Option C (Customer managed key with manual rotation) is incorrect because even though automatic rotation can be enabled on a customer managed key, the key type itself requires enabling rotation; the question implies a managed solution without manual setup. Option D (Default EBS encryption using an AWS managed key) is incorrect because it refers to an encryption setting, not a key type, and the question asks for the key type.

309
MCQmedium

A security engineer is investigating a potential credential compromise. An IAM user's access key was used to launch EC2 instances in a region where the user has never operated before. The engineer wants to quickly identify all API calls made by this user in the last 24 hours, including the source IP addresses. Which AWS service or feature should be used?

A.AWS CloudTrail
B.VPC Flow Logs
C.AWS Trusted Advisor
D.Amazon CloudWatch Logs
AnswerA

AWS CloudTrail is the authoritative audit trail for AWS API activity, recording every management and data event with the invoking IAM identity, source IP address, user agent, and timestamp. For a credential investigation, CloudTrail lets you reconstruct exactly which programmatic or console actions were performed with the suspected credentials, including failed authentication attempts and sign-in events from the us-east-1 region. It can also be configured to deliver those immutable logs to S3 for long-term forensics and to CloudWatch Logs for real-time alerting, making it the primary service to answer 'who did what, when, and from where'.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made by IAM users, including the source IP address, user identity, and request details. By querying CloudTrail logs for the specific IAM user's access key over the last 24 hours, the engineer can identify every EC2-related and other API call, along with the originating IP addresses, enabling rapid investigation of the potential credential compromise.

Exam trap

The trap here is that candidates may confuse VPC Flow Logs (network-level traffic) with CloudTrail (API-level activity), mistakenly thinking flow logs can identify which IAM user performed an action, when in fact flow logs only show IP addresses and ports without user identity.

How to eliminate wrong answers

Option B (VPC Flow Logs) is wrong because it captures network traffic metadata (IP addresses, ports, protocols) at the VPC level, not API calls made by IAM users; it cannot show which user or access key initiated an EC2 instance launch. Option C (AWS Trusted Advisor) is wrong because it provides best-practice checks and recommendations (e.g., security groups, cost optimization), not a record of API activity or source IPs for user actions. Option D (Amazon CloudWatch Logs) is wrong because it is a service for monitoring, storing, and accessing log files from various AWS resources (e.g., application logs, Lambda logs), but it does not natively capture IAM user API call history; CloudTrail logs can be sent to CloudWatch Logs, but CloudWatch Logs itself is not the source of API call records.

310
MCQmedium

A company has a security requirement to capture all DNS queries made by EC2 instances for threat analysis. Which AWS service can provide this capability with minimal configuration?

A.VPC Flow Logs
B.Amazon Inspector
C.Amazon Route 53 Resolver DNS Firewall
D.AWS CloudTrail
AnswerC

Amazon Route 53 Resolver DNS Firewall enables you to filter and log DNS queries that are made through Amazon Provided DNS within a VPC. By associating DNS Firewall rule groups with a VPC and enabling Route 53 Resolver query logging, you capture detailed DNS query metadata, including the queried domain name, query type, response code, and the source IP of the requester. This makes it a direct fit for the security requirement to capture all DNS queries, because it both monitors and optionally blocks DNS traffic at the resolver level.

Why this answer

Amazon Route 53 Resolver DNS Firewall can capture and log all DNS queries made by EC2 instances by enabling DNS query logging to Amazon S3 or CloudWatch Logs. This requires minimal configuration because it integrates directly with the VPC's DNS resolver, automatically capturing outbound DNS traffic without needing agents or changes to instance configurations.

Exam trap

The trap here is that candidates confuse VPC Flow Logs (which capture network traffic metadata) with DNS query logging, not realizing that DNS queries are application-layer (Layer 7) and require a DNS-specific logging mechanism like Route 53 Resolver DNS Firewall's query logging feature.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture IP traffic metadata (source/destination IPs, ports, protocols) but do not capture DNS query names or content; they operate at Layer 3/4, not Layer 7. Option B is wrong because Amazon Inspector is a vulnerability assessment service that scans for software vulnerabilities and network exposure, not a DNS query logging or threat analysis tool. Option D is wrong because AWS CloudTrail records API calls made to AWS services (e.g., EC2 RunInstances), not network-level DNS queries from instances.

311
MCQeasy

A company needs to ensure that data in transit between an on-premises data center and Amazon S3 is encrypted. Which AWS service should be used to establish a dedicated encrypted connection?

A.AWS Transit Gateway
B.AWS Site-to-Site VPN
C.AWS Direct Connect with VPN
D.AWS Client VPN
AnswerC

AWS Direct Connect with VPN is the correct combination because Direct Connect gives you a dedicated, private network connection that bypasses the public internet, offering consistent latency and bandwidth. Since Direct Connect alone does not encrypt your traffic, the VPN overlay (typically IPsec) is added to encrypt data in transit over that private connection. This pairing satisfies both explicit requirements: a dedicated transport path and encryption for all data between the on-premises environment and AWS.

Why this answer

AWS Direct Connect provides a dedicated, private network connection from an on-premises data center to AWS, but it does not inherently encrypt data in transit. By combining Direct Connect with a VPN (IPsec tunnel), you get both a dedicated connection and encryption of all traffic between the on-premises network and Amazon S3. This ensures data in transit is protected while avoiding the public internet.

Exam trap

The trap here is that candidates often assume Direct Connect alone provides encryption, but it does not—it only provides a private, dedicated physical link; encryption must be added via a VPN overlay, which is why the combination is the correct answer.

How to eliminate wrong answers

Option A is wrong because AWS Transit Gateway is a network transit hub that connects VPCs and on-premises networks, but it does not itself provide encryption or a dedicated connection; it can route traffic over VPN or Direct Connect but is not the service that establishes the encrypted link. Option B is wrong because AWS Site-to-Site VPN uses the public internet to create an encrypted tunnel, which does not provide a dedicated connection; it relies on internet routing and can suffer from variable latency and bandwidth. Option D is wrong because AWS Client VPN is a managed remote access VPN service for individual clients (e.g., laptops) to connect to AWS, not for establishing a dedicated encrypted connection between an entire on-premises data center and S3.

312
MCQmedium

A security engineer is reviewing the security group rules for a web server. The security group currently has the following inbound rules: allow HTTP from 0.0.0.0/0, allow HTTPS from 0.0.0.0/0, and allow SSH from 0.0.0.0/0. Which change should the engineer make to improve security?

A.Remove the HTTP rule and keep only HTTPS.
B.Change the SSH rule to allow from the VPC CIDR only.
C.Change the SSH rule to allow from a specific IP range used by the company's administrators.
D.Add a rule to allow ICMP from 0.0.0.0/0.
AnswerC

This is correct because it follows the principle of least privilege by limiting SSH inbound traffic to the specific IP range (or security group) that represents the company's administrators. By restricting the source to known administrative egress addresses, the attack surface is dramatically reduced and unauthorized internal or external actors cannot initiate SSH connections. For a production web tier, SSH should typically be allowed only from a bastion jump host or a dedicated admin VPN CIDR, not from a broad public range. This ensures that only authenticated, expected users can establish a management session.

Why this answer

Restricting SSH access (TCP port 22) to a specific IP range used by the company's administrators follows the principle of least privilege. The current rule allows SSH from 0.0.0.0/0, which exposes the server to brute-force attacks and unauthorized access from the entire internet. By limiting the source to only trusted administrative IPs, the attack surface is significantly reduced while still allowing necessary remote management.

Exam trap

The trap here is that candidates may think restricting SSH to the VPC CIDR (Option B) is sufficient, but the exam expects you to recognize that the VPC CIDR can include many hosts, and the most secure approach is to limit to the specific administrative IP range, not just the internal network.

How to eliminate wrong answers

Option A is wrong because removing HTTP (port 80) while keeping only HTTPS (port 443) would break access for clients that do not support HTTPS or for redirects, and it does not address the critical SSH exposure; the question asks for a security improvement, not a change to web traffic rules. Option B is wrong because allowing SSH from the VPC CIDR only is too permissive if the VPC CIDR is large (e.g., 10.0.0.0/16) and includes non-administrative instances or subnets, still exposing SSH to potential internal threats; it is better to restrict to a specific IP range used by administrators. Option D is wrong because adding an ICMP (ping) rule from 0.0.0.0/0 increases the attack surface unnecessarily, as ICMP can be used for network reconnaissance and does not improve security for the web server.

313
MCQhard

A company uses Amazon Route 53 for DNS and wants to log all DNS queries made from its VPC. The logs must be stored in Amazon S3 for compliance purposes. Which solution meets these requirements?

A.Enable Route 53 Resolver query logging and publish to an S3 bucket.
B.Install a CloudWatch Logs agent on each EC2 instance and configure it to send DNS logs to CloudWatch Logs.
C.Enable AWS CloudTrail for DNS API calls and deliver to an S3 bucket.
D.Enable VPC Flow Logs and publish to an S3 bucket.
AnswerA

Route 53 Resolver query logging captures DNS queries from within a VPC and can deliver them directly to an S3 bucket, meeting both the query-visibility and compliance-storage requirements. Resolver logging is the VPC-scoped mechanism; public hosted zone logging would not capture instance queries.

Why this answer

Route 53 Resolver query logging is the native AWS feature designed to capture DNS queries that originate from resources within a VPC. By enabling this feature and specifying an S3 bucket as the destination, you can log all DNS queries made by EC2 instances, Lambda functions, and other VPC resources without needing any additional agents or configuration. This directly meets the requirement for storing DNS query logs in S3 for compliance.

Exam trap

The trap here is confusing data-plane DNS query logs (Route 53 Resolver query logging) with control-plane API logs (CloudTrail) or network flow logs (VPC Flow Logs), leading candidates to select options that log the wrong type of information for the stated requirement.

How to eliminate wrong answers

Option B is wrong because installing a CloudWatch Logs agent on each EC2 instance captures only the DNS queries made by that specific instance's operating system, not all DNS queries from the VPC (e.g., queries from other services or from the Route 53 Resolver itself), and it requires manual agent management. Option C is wrong because AWS CloudTrail logs API calls made to Route 53 (e.g., creating hosted zones), not the DNS query traffic itself; DNS queries are data-plane operations, not control-plane API calls. Option D is wrong because VPC Flow Logs capture metadata about network traffic (IP addresses, ports, protocols) but do not log the content or queries of DNS traffic; they cannot provide the actual DNS query names or types.

314
MCQmedium

A security engineer needs to centrally aggregate AWS CloudTrail management events from all accounts in an AWS Organizations organization and retain them for 7 years in immutable storage. The engineer has already created an organization trail that delivers to a central S3 bucket in the security account. Which additional configuration is required to make the logs tamper-evident and to detect if any account attempts to disable CloudTrail?

A.Enable S3 Versioning and MFA Delete on the central bucket, then configure AWS Config to record the cloudtrail:StopLogging API as a configuration change.
B.Enable S3 Object Lock in compliance mode on the central bucket and enable CloudTrail log file validation, then create an Amazon EventBridge rule for the CloudTrail StopLogging API call.
C.Enable AWS CloudTrail Insights on the organization trail and configure an Amazon SNS topic to notify the security team when unusual API activity is detected.
D.Enable Amazon Macie on the central bucket to detect anomalous access and configure an S3 bucket policy that denies s3:DeleteObject to all principals except the CloudTrail service principal.
AnswerB

S3 Object Lock in compliance mode prevents deletion or overwrite of log objects for the retention period, satisfying the immutability requirement. CloudTrail log file validation adds a digest file so tampering with delivered logs is detectable. An EventBridge rule matching the StopLogging event (and other trail-modification APIs) provides the alerting on attempts to disable logging.

Why this answer

Immutability and tamper detection are two distinct controls. S3 Object Lock in compliance mode enforces WORM retention so logs cannot be altered or deleted for the retention period, and CloudTrail log file validation produces digest files that let you verify delivered logs were not modified. Because disabling a trail stops future delivery, an EventBridge rule matching the StopLogging event (and related trail APIs) is needed to alert the security team immediately.

Exam trap

The trap here is assuming that S3 Versioning or MFA Delete alone provides immutability, when those only protect against deletion and do not prevent overwrites or prove log integrity.

315
MCQhard

During an incident response, a security engineer needs to preserve the state of an EC2 instance for forensic analysis. The instance is running a production workload that cannot be interrupted. Which of the following actions should the engineer take FIRST to ensure data integrity?

A.Run the dd command to clone the root volume to another EBS volume.
B.Create an AMI from the instance while it is running.
C.Take a snapshot of the attached EBS volumes while the instance is running.
D.Use AWS Systems Manager Run Command to create a memory dump and store it in S3.
AnswerD

AWS Systems Manager Run Command can invoke a memory acquisition utility on the live instance, such as one using the Linux kernel module LiME, to copy the contents of RAM to an EBS volume or S3 without requiring a reboot or instance stop. This preserves volatile evidence like loaded kernel modules, open network sockets, and running processes, which are essential for determining the scope of compromise. Storing the memory dump in S3 protects chain of custody if versioning and object lock are enabled, and it does not alter the underlying disk volumes.

Why this answer

During an incident response, preserving volatile data (such as memory contents) is critical before any other action that might alter the system state. AWS Systems Manager Run Command can execute a command (e.g., using `dd` or `LiME`) to capture a memory dump and store it in Amazon S3 without interrupting the production workload. This ensures that forensic artifacts like running processes, network connections, and encryption keys are preserved before any disk-level operations that could overwrite or modify evidence.

Exam trap

The trap here is that candidates often prioritize disk-level preservation (snapshots or AMIs) as the first step, forgetting that volatile memory contains critical evidence that is lost the moment the instance is stopped or snapshotted, and that AWS Systems Manager can capture this data without interrupting the workload.

How to eliminate wrong answers

Option A is wrong because running the `dd` command to clone the root volume to another EBS volume requires the volume to be unmounted or in a consistent state; doing so on a running production instance can cause data corruption or I/O errors, and it does not capture volatile memory. Option B is wrong because creating an AMI from a running instance without first freezing the filesystem (e.g., using `fsfreeze`) can result in an inconsistent image due to ongoing writes, and it does not capture memory contents. Option C is wrong because taking a snapshot of attached EBS volumes while the instance is running does not guarantee crash consistency unless all volumes are snapshotted simultaneously (multi-volume snapshot), and it still fails to preserve volatile memory data that is essential for forensic analysis.

316
MCQmedium

A company wants to allow its employees to authenticate to the AWS Management Console using their existing corporate credentials. Which AWS service should be used to integrate with the company's identity provider?

A.AWS Secrets Manager
B.AWS Directory Service for Microsoft Active Directory
C.AWS Certificate Manager
D.AWS IAM Identity Center (AWS SSO)
AnswerD

AWS IAM Identity Center (formerly AWS SSO) is the purpose-built service for centrally managing workforce access and single sign-on across multiple AWS accounts, business applications, and SAML 2.0/OIDC-capable solutions. It can connect to an external identity provider (such as Okta or Azure AD) and map that provider's identity groups to AWS permission sets, issuing temporary credentials for the console or CLI. This makes it the correct choice for allowing employees to authenticate to AWS with their existing corporate credentials.

Why this answer

AWS IAM Identity Center (formerly AWS SSO) is the correct service because it is specifically designed to enable single sign-on (SSO) from an external identity provider (IdP) to AWS accounts and business applications. It supports federation via SAML 2.0 or OIDC, allowing employees to authenticate using their existing corporate credentials and then access the AWS Management Console without needing separate IAM users.

Exam trap

The trap here is that candidates often confuse AWS Directory Service for Microsoft Active Directory with federation, but Directory Service is for managing AD domains in AWS, not for integrating with an external corporate IdP to provide SSO to the AWS console—that requires IAM Identity Center or IAM SAML federation.

How to eliminate wrong answers

Option A is wrong because AWS Secrets Manager is a service for securely storing and rotating secrets (e.g., database credentials, API keys), not for federating identity or integrating with an external IdP for console access. Option B is wrong because AWS Directory Service for Microsoft Active Directory is used to create a managed Microsoft AD domain in AWS or connect to an on-premises AD, but it does not directly provide the federation layer to authenticate corporate users to the AWS Management Console via an external IdP; that requires IAM Identity Center or IAM SAML federation. Option C is wrong because AWS Certificate Manager (ACM) manages SSL/TLS certificates for securing network traffic, not identity federation or authentication to the AWS console.

317
MCQeasy

A company is migrating sensitive data to Amazon S3. The data must be encrypted at rest using keys managed by the company. The company also requires an audit trail of key usage. Which solution meets these requirements?

A.Use SSE-S3 with default encryption.
B.Use SSE-C and store the keys in AWS Secrets Manager.
C.Use SSE-KMS with a customer-managed key and enable CloudTrail for KMS.
D.Use AWS CloudHSM to generate and store keys, and use Amazon S3 with SSE-KMS.
AnswerC

SSE-KMS with a customer-managed key gives you independent control over the CMK, including the ability to set key policies, grant and revoke permissions, and force rotation. With CloudTrail for KMS enabled, every Decrypt, GenerateDataKey, and ReEncrypt request against that key is recorded with the user, role, and principal ARN, directly tying each S3 object access to an auditable event. Customer-managed keys also let you align the key with your own governance model, and because the key is in KMS, you can use key policies to enforce conditions (such as VPC endpoints or MFA) and can respond to a breach by disabling the key to instantly block all future decrypt operations.

Why this answer

SSE-KMS with a customer-managed key and CloudTrail for KMS. This solution meets both requirements: the company manages its own keys (customer-managed CMK) and CloudTrail logs every KMS API call, providing an audit trail of key usage. Option A (SSE-S3) uses Amazon-managed keys, so no customer control or audit trail.

Option B (SSE-C) requires the customer to manage keys themselves but does not integrate with CloudTrail for key usage auditing; also, storing keys in Secrets Manager does not provide an audit trail of KMS key usage. Option D (CloudHSM) can be used, but it requires more complex setup for auditing; SSE-KMS with CloudTrail is the simpler and more direct solution.

318
MCQmedium

A company uses IAM roles for cross-account access. Developers in Account A need to assume a role in Account B. What must be true for the AssumeRole call to succeed?

A.Account A must have an SCP that allows sts:AssumeRole
B.The user in Account A must have MFA enabled
C.The role's trust policy must allow Account A and the user must have sts:AssumeRole permission
D.The role in Account B must have a permissions boundary
AnswerC

Correct. The trust policy of the role in Account B must include Account A as a trusted entity, and the user in Account A must have the sts:AssumeRole permission (via an IAM policy attached to their user or group).

Why this answer

For a cross-account AssumeRole call to succeed, two conditions must be met: the role in Account B must have a trust policy that allows Account A (or specific principals in Account A) to assume it, and the IAM user or role in Account A must have an identity-based policy granting sts:AssumeRole on that role. Both are required; missing either results in Access Denied.

Exam trap

SCS-C02 often tests the two-sided nature of AssumeRole — candidates frequently forget that both the trust policy and the caller's identity policy must allow the action, and may incorrectly select an answer that only addresses one side or confuses SCPs with permission grants.

How to eliminate wrong answers

Option A is wrong because SCPs apply only to accounts in AWS Organizations and restrict permissions — they do not grant permissions, and they are not required for cross-account access unless the account is in an organization with restrictive SCPs. Option B is wrong because MFA is not a default requirement for AssumeRole; it can be enforced via a condition in the trust policy, but it is not mandatory. Option D is wrong because a permissions boundary sets the maximum permissions for an identity, but it does not grant the ability to assume a role — it is a limiting factor, not a granting mechanism.

319
MCQhard

Refer to the exhibit. An AWS Config rule checks that S3 buckets deny HTTP requests. The bucket 'my-bucket' is reported as non-compliant. Which change would make the bucket compliant?

A.Add a bucket policy that allows only HTTPS requests.
B.Change the Effect to Allow.
C.Add the bucket ARN to the Resource element in the policy.
D.Remove the Condition element from the policy.
AnswerC

The current policy only lists the object ARN (arn:aws:s3:::bucket/*) in the Resource element, so the Deny statement applies to object-level operations like s3:GetObject and s3:PutObject. To also block bucket-level actions such as s3:ListBucket, the Resource must include the bucket ARN itself (arn:aws:s3:::bucket). Adding the bucket ARN (without the trailing /*) ensures both the bucket and its objects are covered by the Deny, satisfying the rule's requirement for bucket-level HTTP denial.

Why this answer

The bucket policy denies actions when 'aws:SecureTransport' is false (HTTP). However, the policy only applies to the bucket's objects (arn:aws:s3:::my-bucket/*), not to the bucket itself. To deny HTTP requests to the bucket as well, the resource should include the bucket ARN (arn:aws:s3:::my-bucket).

The rule likely checks that both bucket and objects are denied.

320
MCQmedium

A company uses AWS WAF to protect a web application. The security team wants to block requests that contain SQL injection patterns. Which WAF rule type should be used?

A.IP set rule
B.Geographic match rule
C.Rate-based rule
D.SQL injection match rule
AnswerD

An SQL injection match rule in AWS WAF inspects the request components you configure—such as the query string, body, header, or cookie values—for known SQLi signatures like ' OR '1'='1, UNION SELECT, or comment and quote sequences. It uses pattern matching, optionally normalized with rule-specific text transformations to reduce evasive bypasses like URL encoding or case variation. This is the only rule type among the options that performs payload-level content inspection and produces a match based on the actual malicious input in the request, making it the correct choice for detecting SQL injection.

Why this answer

AWS WAF provides a dedicated SQL injection match rule that inspects incoming requests for SQL injection patterns in the URI, query string, or body. This rule uses a set of predefined SQL-like patterns (e.g., 'OR 1=1', 'UNION SELECT') to detect and block malicious input, directly addressing the security team's requirement.

Exam trap

The trap here is that candidates may confuse a rate-based rule (which controls request volume) with a content-based rule (which inspects payloads), leading them to pick Option C instead of the correct SQL injection match rule.

How to eliminate wrong answers

Option A is wrong because an IP set rule matches requests based on source IP addresses, not on content patterns like SQL injection. Option B is wrong because a geographic match rule filters traffic based on the country of origin, not on request payload content. Option C is wrong because a rate-based rule limits the number of requests from a single IP over a time window, which is used for DDoS mitigation, not for detecting SQL injection patterns.

321
MCQeasy

A company requires that all access to its S3 buckets be logged for compliance. Which AWS service should be used to record API calls to S3?

A.Amazon GuardDuty
B.Amazon Inspector
C.AWS Config
D.AWS CloudTrail
AnswerD

AWS CloudTrail records S3 API activity, including object-level data events when enabled, satisfying the compliance requirement to log all bucket access. Unlike S3 server access logging, which captures only bucket-level requests, CloudTrail delivers detailed API call records to an S3 bucket or CloudWatch Logs for auditing.

Why this answer

AWS CloudTrail records API calls for auditing purposes, making it the correct service for logging access to S3 buckets. Option A is incorrect because Amazon GuardDuty is a threat detection service, not a logging service. Option B is incorrect because Amazon Inspector assesses vulnerabilities.

Option C is incorrect because AWS Config tracks resource configuration changes, not API calls.

322
MCQeasy

A Security Engineer needs to block SSH traffic (port 22) from the internet to all EC2 instances in a VPC. Which approach is the most secure and scalable?

A.Add a security group rule to deny inbound traffic on port 22 from 0.0.0.0/0.
B.Add a network ACL rule to deny inbound traffic on port 22 from 0.0.0.0/0 at the subnet level.
C.Add a network ACL rule to allow inbound traffic on port 22 from 0.0.0.0/0 and then add a deny rule for the same traffic.
D.Add a security group rule to block inbound traffic on port 22 from 0.0.0.0/0 at the VPC level.
AnswerB

A network ACL (NACL) is a stateless firewall applied at the subnet level, and it explicitly supports both allow and deny rules. By adding a deny rule for inbound TCP port 22 from 0.0.0.0/0 with a low rule number, you block all SSH traffic from any source from entering the subnet. This is the correct method because security groups cannot provide an explicit deny, and the NACL rule operates at the subnet boundary rather than at individual resources.

Why this answer

Network ACLs (NACLs) are stateless and operate at the subnet level, allowing you to explicitly deny inbound SSH traffic from 0.0.0.0/0. This approach is more secure and scalable than security group rules because NACLs can block traffic before it reaches the instance, and they support explicit deny rules, which security groups do not. Security groups only support allow rules, so you cannot add a deny rule to block SSH traffic; you must omit the allow rule, which is less explicit and can be accidentally overridden.

Exam trap

The trap here is that candidates often confuse security groups with network ACLs, assuming security groups can have explicit deny rules, when in fact only NACLs support deny rules and operate at the subnet level.

How to eliminate wrong answers

Option A is wrong because security groups do not support deny rules; they only support allow rules, so adding a 'deny' rule is syntactically invalid and cannot be implemented. Option C is wrong because NACLs evaluate rules in order by rule number, and an allow rule with a lower number would permit the traffic before a deny rule with a higher number is evaluated, making the deny ineffective; additionally, allowing then denying the same traffic is redundant and not a best practice. Option D is wrong because security groups cannot be applied at the VPC level; they are associated with individual ENIs or instances, not the entire VPC, and they do not support deny rules.

323
Multi-Selectmedium

A security engineer is investigating a potential data exfiltration incident where an attacker used a compromised EC2 instance to transfer data to an external IP. Which TWO AWS services can provide evidence of the network traffic and the API calls made from the instance?

Select 2 answers
A.VPC Flow Logs
B.AWS Config
C.Amazon GuardDuty
D.Amazon Inspector
E.AWS CloudTrail
AnswersA, E

VPC Flow Logs capture metadata about IP traffic to and from network interfaces, including source and destination IPs, ports, protocol, and packet/byte counts. This enables you to see large outbound transfers to an unusual external IP, which is a classic sign of data exfiltration. Note that flow logs do not contain payload contents, but they are the foundational raw network log for investigating suspected exfiltration.

Why this answer

VPC Flow Logs capture metadata about IP traffic going to and from network interfaces, including the source/destination IP, ports, protocol, and packet/byte counts. This provides direct evidence of data being transferred to an external IP address from the compromised EC2 instance. AWS CloudTrail records API calls made within the AWS environment, such as those executed by the EC2 instance's IAM role or the instance itself (e.g., via the AWS CLI or SDK), which can reveal actions like starting data transfers or modifying security groups to allow exfiltration.

Exam trap

The trap here is that candidates often confuse Amazon GuardDuty as a source of raw evidence (like logs) when it is actually a detection service that consumes logs from other services (VPC Flow Logs, CloudTrail, DNS logs) to generate alerts, not a storage or retrieval service for the underlying traffic or API data.

324
MCQeasy

A security team needs to audit all changes to IAM policies in their AWS account. Which AWS service should they use to record policy changes?

A.Amazon Inspector
B.AWS CloudTrail
C.Amazon GuardDuty
D.AWS Config
AnswerB

AWS CloudTrail is the correct service because it provides a continuous, immutable audit log of every API call made in your AWS account, including the IAM actions that modify policies such as PutRolePolicy, AttachUserPolicy, and DeletePolicy. Each event captures the identity of the caller, the source IP, the time, and the request parameters, making it the definitive source for security audits of IAM changes. CloudTrail's event history is viewable for 90 days, and you can extend retention with a trail that delivers events to an S3 bucket or CloudWatch Logs for long-term compliance.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made in the AWS account, including IAM policy changes (e.g., CreatePolicy, PutRolePolicy, AttachUserPolicy). These events are captured as CloudTrail log entries, providing a complete audit trail of who made the change, when, and from which source IP. This directly meets the requirement to audit all changes to IAM policies.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks resource configuration state) with CloudTrail (which tracks API call history), leading them to choose AWS Config because it can detect drift, but it does not provide the detailed audit trail of who made the change and when.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability assessment service that scans for software vulnerabilities and unintended network exposure, not a service that records API activity or policy changes. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes DNS logs, VPC flow logs, and CloudTrail events for malicious activity, but it does not itself record or store the raw API call history for IAM policy changes. Option D is wrong because AWS Config evaluates and records resource configuration changes (e.g., whether an IAM policy is attached to a user) and can trigger rules, but it does not capture the API call details (who, when, source IP) that are required for a complete audit trail of policy changes; that is CloudTrail's role.

325
Multi-Selectmedium

Which THREE actions should be taken when preserving forensic evidence from an EC2 instance during an incident? (Select THREE.)

Select 3 answers
A.Reboot the instance to clear any malicious processes.
B.Create an EBS snapshot of all volumes.
C.Terminate the instance to prevent further compromise.
D.Capture a memory dump using a tool like LiME.
E.Detach the instance from the network by modifying the security group.
AnswersB, D, E

An EBS snapshot captures a point-in-time, block-level copy of every attached volume, preserving disk artefacts such as logs, malware and deleted files without altering the running instance. It satisfies evidence preservation while keeping the original instance available for further collection.

Why this answer

Option B is correct because creating an EBS snapshot of all attached volumes captures a point-in-time, block-level copy of the instance's disk data (including the root volume) that can later be restored and analyzed without altering the original evidence. Option D is correct because volatile memory contains artifacts such as running processes, network connections, and encryption keys that are lost on shutdown, so capturing a memory dump with a tool like LiME preserves this critical evidence. Option E is correct because modifying the security group to remove inbound/outbound rules isolates the instance from the network, preventing further compromise or data exfiltration while keeping the instance running so volatile evidence remains intact.

Option A is not appropriate because rebooting destroys volatile memory and can trigger anti-forensic behavior, and Option C is not appropriate because terminating the instance destroys the ephemeral storage and volatile state and may delete the very evidence needed for investigation.

Exam trap

The SCS-C02 exam often tests the misconception that rebooting or terminating an instance is a safe containment step, but in forensic contexts these actions destroy volatile evidence and should be avoided until after memory and disk acquisition.

326
MCQmedium

The above IAM policy is attached to an AWS Lambda function. The function is failing to write logs to CloudWatch Logs. What is the likely cause?

A.The resource ARN does not include the log group itself; only log streams
B.The actions list does not include logs:DescribeLogGroups
C.The policy is missing an explicit deny for other actions
D.The region in the ARN does not match the Lambda function's region
AnswerA

PutLogEvents requires access to the log group resource as well.

Why this answer

The IAM policy grants `logs:CreateLogStream` and `logs:PutLogEvents` with a resource ARN that correctly targets log streams under the specified log group. However, the policy lacks any statement that grants permission on the log group resource itself. If the log group does not already exist, the Lambda function requires `logs:CreateLogGroup` permission on the log group ARN (`arn:aws:logs:us-east-1:123456789012:log-group:MyLogGroup`) to create it.

Without this, the function cannot create the log group, causing the write to fail. The resource ARN in the policy does not include the log group itself, only log streams, which is why the function lacks the necessary permissions to interact with the log group resource.

Exam trap

The trap here is that candidates focus on the actions (e.g., missing `logs:DescribeLogGroups`) rather than the resource ARN, which must include the log group itself (not just log streams) for the initial log group creation or access check.

How to eliminate wrong answers

Option B is wrong because `logs:DescribeLogGroups` is not required for writing logs; the Lambda execution role typically needs `logs:CreateLogGroup` on the log group resource to allow the function to create the log group if it doesn't exist, but the core issue is the resource ARN mismatch, not the missing action. Option C is wrong because an explicit deny is not needed; IAM defaults to an implicit deny for any action not explicitly allowed, so missing an explicit deny does not cause failures. Option D is wrong because the region in the ARN (`us-east-1`) matches the Lambda function's region in the scenario; the question does not indicate a region mismatch, and even if it did, the error would be a different one (e.g., cross-region access denied), not the specific failure to write logs.

327
MCQhard

A company uses AWS Organizations with multiple accounts and has enabled AWS Security Hub in the management account. The security team wants to automatically remediate a specific finding type that appears in Security Hub. Which combination of services should be used to achieve this?

A.Amazon EventBridge and AWS Lambda
B.AWS Config conformance packs and AWS Systems Manager Automation
C.Amazon Inspector and AWS Step Functions
D.Amazon GuardDuty and AWS Lambda
AnswerA

Security Hub natively publishes findings to an Amazon EventBridge default event bus, so a rule in the administrator account can match the source 'aws.securityhub' and invoke a Lambda function for immediate remediation. The Lambda function can parse the finding ID, AwsAccountId, and compliance status, then execute corrective action such as modifying an IAM policy or enabling encryption. In a multi-account organization, this is the intended native path for turning Security Hub findings into automated responses, especially when cross-Region aggregation is enabled.

Why this answer

Amazon EventBridge can capture Security Hub findings as events using an event rule that matches the specific finding type. When the rule triggers, it invokes an AWS Lambda function that contains the remediation logic, such as modifying security group rules or disabling access keys. This combination provides a serverless, event-driven architecture for automated response to Security Hub findings.

Exam trap

The trap here is that candidates may confuse Security Hub's integration with other AWS security services (GuardDuty, Inspector) as the trigger mechanism, when in fact EventBridge is the standardized event bus that Security Hub uses to emit findings for automated response.

How to eliminate wrong answers

Option B is wrong because AWS Config conformance packs are used to evaluate resource compliance against rules, not to reactively remediate specific Security Hub findings; while Systems Manager Automation can run remediation, the integration with Security Hub is typically done via EventBridge, not directly through conformance packs. Option C is wrong because Amazon Inspector is a vulnerability assessment service that generates its own findings, not a service for remediating Security Hub findings; Step Functions could orchestrate remediation but the trigger from Security Hub still requires EventBridge. Option D is wrong because Amazon GuardDuty is a threat detection service that generates its own findings, not a service for remediating Security Hub findings; while Lambda can be used for remediation, the correct trigger for Security Hub findings is EventBridge, not GuardDuty.

328
MCQeasy

A security engineer needs to detect suspicious API calls across multiple AWS accounts. The engineer has enabled AWS CloudTrail in each account and is sending logs to a central S3 bucket. Which additional step should the engineer take to analyze the logs for potential threats?

A.Enable AWS Config rules to monitor CloudTrail configuration.
B.Enable AWS Trusted Advisor in the management account.
C.Enable Amazon GuardDuty in each account.
D.Enable VPC Flow Logs in each account.
AnswerC

Amazon GuardDuty is a continuous, intelligent threat detection service that ingests CloudTrail management events, VPC Flow Logs, and DNS query logs to detect suspicious API calls. It builds a baseline of normal account behavior and uses anomaly detection, machine learning, and threat intelligence to identify actions such as unusual logins, IAM privilege escalation, or resource exposure. Enabling it in each account gives complete coverage of API activity across the organization.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior, including suspicious API calls, by analyzing CloudTrail management and data events, VPC Flow Logs, and DNS logs. By enabling GuardDuty in each account, the security engineer can automatically detect potential threats across all accounts without manual log analysis. This directly addresses the need to analyze CloudTrail logs for suspicious API calls at scale.

Exam trap

The trap here is that candidates may confuse VPC Flow Logs (network traffic) with CloudTrail logs (API activity), or think that Config rules or Trusted Advisor can detect suspicious API calls, when in fact GuardDuty is the dedicated threat detection service for this purpose.

How to eliminate wrong answers

Option A is wrong because AWS Config rules monitor resource configuration compliance (e.g., ensuring CloudTrail is enabled), not the content of API calls for threat detection. Option B is wrong because AWS Trusted Advisor provides best-practice recommendations for cost, performance, and security, but does not analyze CloudTrail logs for suspicious API calls. Option D is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) and are useful for network-level threat detection, but they do not analyze CloudTrail API call logs for suspicious activity.

329
Multi-Selectmedium

Which TWO of the following are valid ways to enforce encryption at rest for data in Amazon S3? (Choose TWO.)

Select 2 answers
A.Use SSL/TLS
B.Use IAM policies
C.Use AWS CloudTrail
D.Use SSE-KMS
E.Use SSE-C
AnswersD, E

SSE-KMS (Server-Side Encryption with AWS KMS) instructs S3 to encrypt each object at rest using a customer managed KMS key, AWS managed KMS key, or AWS owned key. S3 calls KMS to generate a plaintext data key and an encrypted copy of that key, using envelope encryption to protect the object while maintaining the ability to rotate the KMS key independently. This gives you separation of duties, centralized key management, and auditability, making it a valid way to enforce at-rest encryption.

Why this answer

SSE-KMS (option D) is correct because it enforces server-side encryption at rest by having Amazon S3 encrypt objects with keys managed in AWS KMS, providing envelope encryption and auditability via CloudTrail. SSE-C (option E) is also correct because it enforces server-side encryption at rest using a customer-provided encryption key that S3 applies to the object, so data is stored encrypted on disk. Option A (SSL/TLS) is incorrect because it only protects data in transit between the client and S3, not data at rest.

Option B (IAM policies) is incorrect because IAM controls authorization and permissions, not the encryption of stored objects. Option C (CloudTrail) is incorrect because it records API activity for auditing, not encryption of data at rest.

Exam trap

SCS-C02 often tests the difference between encryption in transit and at rest; candidates may select SSL/TLS or IAM policies, but those do not enforce encryption at rest.

330
MCQmedium

Refer to the exhibit. A security engineer finds this CloudTrail log entry. What is the most significant security concern indicated by this event?

A.The security group rule allows SSH access from any IP address (0.0.0.0/0).
B.The event is a normal administrative action and poses no security concern.
C.The user did not have MFA enabled when assuming the AdminRole.
D.The source IP address (203.0.113.5) is from an unusual location.
AnswerA

Ingress from 0.0.0.0/0 on port 22 exposes SSH to the entire internet, permitting brute-force and credential-stuffing attempts against every instance in that security group. This unrestricted CIDR is the concrete exposure the log reveals, regardless of other fields present.

Why this answer

The CloudTrail log entry shows an `AuthorizeSecurityGroupIngress` API call that adds a rule allowing SSH (port 22) from 0.0.0.0/0. This is a critical security concern because it exposes the EC2 instance to SSH access from any IP address on the internet, creating a high risk of brute-force attacks, unauthorized access, and potential compromise. Security best practices mandate restricting SSH access to specific trusted IP ranges, not the entire internet.

Exam trap

The trap here is that candidates may focus on the source IP address or MFA status, but the core security concern is the overly permissive security group rule that grants unrestricted SSH access to the internet.

How to eliminate wrong answers

Option B is wrong because the event is not a normal administrative action; it explicitly opens SSH to the world, which is a significant security risk and should be flagged as a concern. Option C is wrong because the CloudTrail log does not indicate whether MFA was enabled or not; the event shows the user assumed the AdminRole, but MFA status is not recorded in this log entry, so it cannot be concluded as a security concern from this event alone. Option D is wrong because the source IP address 203.0.113.5 is a documentation/test IP range (RFC 5737) and is not necessarily unusual; more importantly, the security concern is the open SSH rule, not the source IP of the API call.

331
MCQhard

A security engineer notices that an S3 bucket policy allows access to a principal from another AWS account. Which AWS feature can be used to check if this external access is intended?

A.AWS Trusted Advisor bucket permissions check
B.AWS Config rule s3-bucket-public-read-prohibited
C.AWS CloudTrail event history
D.AWS IAM Access Analyzer
AnswerD

IAM Access Analyzer continuously analyzes resource-based policies and creates findings whenever access to a resource like an S3 bucket is granted to an external principal — an AWS account outside your zone of trust or an anonymous principal. Each finding details the external account/principal, the exact actions allowed, and the policy statement causing the access, so you can determine whether that access is intended. In the console you can then mark the finding as 'Archive' for intended access or take remediation action for unintended access, which is the only option here that directly answers the security engineer's question.

Why this answer

IAM Access Analyzer generates findings for external access to S3 buckets. You can review and archive findings if intended.

332
MCQmedium

A company has a multi-account AWS environment using AWS Organizations. The security team wants to centrally manage VPC security group rules across all accounts. Which AWS service should they use?

A.AWS Network Firewall
B.AWS Firewall Manager
C.AWS Config
D.Amazon Route 53 Resolver DNS Firewall
AnswerB

AWS Firewall Manager is the designated service for centrally managing VPC security group rules across all accounts and resources within an AWS Organization. It allows administrators to create security group policies, enforce common security group rules, remediate noncompliant rules automatically, and apply consistent protection to new accounts as they join the organization. This directly matches the requirement for central management of security group rules, making it the correct answer.

Why this answer

AWS Firewall Manager is designed to centrally manage security policies across all accounts in an AWS Organization, including VPC security group rules. It allows you to define a security group policy that automatically applies to existing and new resources, ensuring consistent enforcement across the organization. This is the only service among the options that provides centralized, cross-account management of security groups.

Exam trap

SCS-C02 often tests the distinction between services that can audit security groups (AWS Config) and those that can centrally manage and enforce rules (AWS Firewall Manager). Candidates frequently confuse AWS Config's compliance checks with actual enforcement capabilities.

How to eliminate wrong answers

Option A is wrong because AWS Network Firewall is a managed network firewall service that provides traffic filtering at the VPC level, but it does not centrally manage security group rules across accounts. Option C is wrong because AWS Config is a configuration assessment and auditing service that can detect non-compliant security groups but cannot enforce or centrally manage rules across accounts. Option D is wrong because Amazon Route 53 Resolver DNS Firewall filters DNS queries, not VPC security group rules, and it does not provide cross-account management of security groups.

333
MCQmedium

A security engineer needs to ensure that all Amazon S3 buckets in an AWS account have server-side encryption (SSE) enabled. The engineer wants to automatically remediate any bucket that is created without SSE. Which solution should the engineer implement?

A.Use S3 bucket policies to deny access to objects without encryption.
B.Apply an IAM policy that requires SSE for all S3 actions.
C.Use AWS Config with a managed rule (s3-bucket-server-side-encryption-enabled) and an automatic remediation action.
D.Create a service control policy (SCP) that denies creation of buckets without encryption.
AnswerC

AWS Config's managed rule `s3-bucket-server-side-encryption-enabled` continuously evaluates each S3 bucket for the presence of server-side encryption. When a bucket is found non-compliant, an automatic remediation action—typically a Systems Manager Automation document that calls `PutBucketEncryption`—is invoked to enable default encryption on that bucket. This provides a closed loop that both detects drift and corrects it for existing and newly created buckets, making it the only option that satisfies 'ensure all S3 buckets' proactively and reactively.

Why this answer

AWS Config's managed rule s3-bucket-server-side-encryption-enabled continuously evaluates every S3 bucket in the account and flags any that lack default encryption. Pairing it with an automatic remediation action (typically an SSM Automation document such as AWS-EnableS3BucketEncryption) means newly created non-compliant buckets are remediated without human intervention, satisfying the 'automatically remediate' requirement. This is the canonical AWS-native pattern for continuous compliance enforcement on S3.

Exam trap

SCS-C02 often tests the distinction between preventive controls (SCPs, bucket policies, IAM) and detective-plus-remediation controls (AWS Config + SSM Automation) — candidates pick SCPs or bucket policies because they sound like 'enforcement' but they cannot automatically remediate existing resources.

How to eliminate wrong answers

Option A is wrong because an S3 bucket policy can deny unencrypted PUT requests (e.g., via s3:PutObject with a Null condition on s3:x-amz-server-side-encryption), but it does not enable SSE on the bucket itself and does not remediate existing buckets — it only blocks certain writes. Option B is wrong because IAM policies control identity permissions, not bucket-level encryption configuration; IAM cannot force a bucket to have default encryption enabled. Option D is wrong because an SCP can only deny the s3:CreateBucket action or require a condition, but it cannot retroactively enable encryption on existing buckets and does not provide automatic remediation — it merely blocks creation, leaving the account without a compliant bucket.

334
MCQhard

A company is designing a network architecture for a critical application that must meet strict compliance requirements. The application consists of Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The instances need to access an Amazon RDS database in a different VPC. The company wants to minimize exposure to the internet. Which solution should the company use?

A.Use a site-to-site VPN connection between the VPCs.
B.Use a NAT gateway in the database VPC and route traffic through it.
C.Use a VPC Peering connection between the two VPCs.
D.Use an internet gateway and route traffic over the internet with security groups.
AnswerC

A VPC peering connection privately connects two VPCs using AWS's internal backbone, with no traffic traversing the public internet and no need for a public IP address, VPN appliance, or gateway. It creates direct layer-3 route table entries between the VPC CIDRs, and because the relationship is native to AWS, traffic stays isolated from external carriers. For a single application-to-database pair with non-overlapping CIDRs, VPC peering is the simplest and most cost-effective way to establish low-latency private connectivity.

Why this answer

VPC Peering establishes a private, direct network connection between two VPCs using AWS's internal infrastructure, with no exposure to the internet. Traffic stays within the AWS global network, meeting strict compliance requirements for minimizing internet exposure. This allows EC2 instances in the application VPC to communicate with the RDS database in the database VPC securely and with low latency, using private IP addresses.

Exam trap

The trap here is that candidates often confuse VPC Peering with site-to-site VPN, thinking VPN is required for cross-VPC connectivity, but VPC Peering is the correct AWS-native solution for private VPC-to-VPC communication without internet exposure.

How to eliminate wrong answers

Option A is wrong because a site-to-site VPN connection is used to connect an on-premises network to a VPC, not to connect two VPCs within AWS; it would introduce internet exposure (via the VPN tunnel over the public internet) and unnecessary complexity. Option B is wrong because a NAT gateway is designed to allow instances in a private subnet to initiate outbound traffic to the internet, not to enable private communication between two VPCs; routing traffic through a NAT gateway would force traffic over the internet and break the requirement to minimize exposure. Option D is wrong because using an internet gateway and routing traffic over the internet with security groups exposes the traffic to the public internet, violating the compliance requirement to minimize internet exposure; security groups alone cannot prevent the inherent risk of internet-based communication.

335
Multi-Selectmedium

A security engineer is designing a network architecture for a multi-tier application. The web servers must be accessible from the internet, while the application servers must only be accessible from the web servers. Which TWO configurations should be used? (Choose TWO.)

Select 2 answers
A.Configure a NAT gateway in the private subnet for the application servers.
B.Place the web servers in a public subnet with a route to an internet gateway.
C.Use a network ACL on the application subnet to allow inbound traffic from the web subnet's IP range.
D.Place the application servers in a public subnet with a route to an internet gateway.
E.Configure the application servers' security group to allow traffic only from the web servers' security group.
AnswersB, E

A public subnet routes 0.0.0.0/0 to an internet gateway, so web servers can receive inbound internet traffic and respond outbound. This satisfies the requirement that web servers be internet-accessible, while application servers remain in private subnets with no such route.

Why this answer

Option B is correct because placing the web servers in a public subnet with a route to an internet gateway (0.0.0.0/0 → igw-xxxx) is exactly what makes them reachable from the internet, satisfying the requirement that web servers be internet-accessible. Option E is correct because referencing the web servers' security group as the source in the application servers' security group inbound rules enforces that only instances in that web security group can reach the application tier, which is the recommended, identity-based way to restrict access in a multi-tier design. Option A is not needed here: a NAT gateway provides outbound-only internet access for private subnets and does not control inbound access from the web tier, so it does not satisfy the stated requirement.

Option C is not the best fit because network ACLs are stateless subnet-level filters based on CIDR ranges; while they can restrict traffic, they are not the mechanism that ties access to the web servers' identity, and the question asks for the configuration that limits application access to the web servers specifically. Option D is wrong because putting the application servers in a public subnet with an internet gateway route would expose them to the internet, directly violating the requirement that they be reachable only from the web servers.

Exam trap

The trap here is that candidates often confuse network ACLs with security groups, incorrectly assuming that a stateless network ACL with IP-based rules is the correct way to restrict traffic between tiers, when in fact security group references provide a more secure and manageable solution.

336
MCQmedium

A company uses AWS CloudTrail to log management events. The security team wants to be alerted when an IAM user creates a new access key. Which solution would meet this requirement with the least operational overhead?

A.Create a CloudWatch Logs metric filter on the CloudTrail log group for CreateAccessKey events and set an alarm.
B.Create an Amazon EventBridge rule that matches the CreateAccessKey event and triggers an Amazon SNS notification.
C.Write a Python script that uses the CloudTrail LookupEvents API and run it on a scheduled basis using Amazon EventBridge Scheduler.
D.Develop a custom AWS Lambda function that queries CloudTrail logs in S3 every hour.
AnswerB

EventBridge is the least-overhead, near-real-time option because CloudTrail automatically delivers all management events to the default EventBridge bus without extra configuration. A rule with an event pattern that matches eventSource="iam.amazonaws.com" and eventName="CreateAccessKey" triggers an SNS topic immediately when the API call occurs, enabling instantaneous security notifications. This is fully event-driven and serverless: there is no polling, no custom code, no log parsing, and no separate metric filter to maintain, which makes it the architecturally cleanest solution.

Why this answer

Amazon EventBridge can directly capture CloudTrail API calls (like CreateAccessKey) as events and route them to an SNS topic for notification, requiring no custom code or polling. This serverless, event-driven approach minimizes operational overhead by eliminating the need to manage log groups, metric filters, or scheduled scripts.

Exam trap

The trap here is that candidates often assume CloudWatch Logs metric filters are the standard way to monitor CloudTrail events, but EventBridge is the native, lower-overhead service for reacting to specific API calls in real time without needing to ship logs to CloudWatch Logs first.

How to eliminate wrong answers

Option A is wrong because CloudTrail logs management events to CloudTrail itself, not to a CloudWatch Logs log group by default; you would need to explicitly configure CloudTrail to deliver events to CloudWatch Logs, and then create a metric filter and alarm, which adds unnecessary complexity. Option C is wrong because writing a Python script to call the CloudTrail LookupEvents API on a schedule introduces polling overhead, latency, and maintenance burden compared to the real-time, push-based EventBridge approach. Option D is wrong because developing a custom Lambda function to query CloudTrail logs in S3 every hour is overly complex, introduces at least one hour of delay, and requires managing S3 bucket notifications or scheduled invocations, all of which are unnecessary when EventBridge can react instantly.

337
MCQmedium

Refer to the exhibit. A company uses this CloudFormation template. What security best practice is being violated?

A.The instance type is too small for production workloads.
B.The security group allows SSH access from all IP addresses.
C.The AMI ID is not specified as a parameter.
D.The EBS volume is not encrypted.
AnswerB

Allowing SSH (port 22) from 0.0.0.0/0 in the security group exposes the instance's administration interface to the entire internet, enabling brute-force attacks, credential stuffing, and potential unauthorized access. This directly violates the principle of least privilege and is a well-known high-severity misconfiguration, making it the most immediate security risk in the template.

Why this answer

The security group allows SSH access from all IP addresses (0.0.0.0/0), which is a significant security risk that exposes the instance to unauthorized access. Option A is wrong because the instance type is a performance consideration, not a security best practice. Option C is wrong because specifying the AMI ID as a parameter is not a security requirement; it is a parameterization best practice but not security-related.

Option D is wrong because while encryption is a security best practice, the most critical violation here is the open SSH access, as it directly exposes the instance to potential attacks.

338
MCQhard

Refer to the exhibit. A security engineer has attached this IAM policy to a user. What is the effect of this policy?

A.Allows uploads with KMS encryption or without encryption.
B.Allows uploads only when encryption is not specified.
C.Denies uploads when encryption is not provided.
D.Allows uploads only when using KMS encryption.
AnswerA

The bucket policy contains two separate allow statements that combine as an OR. One allow statement grants s3:PutObject when the request header s3:x-amz-server-side-encryption is set to aws:kms, covering KMS-encrypted uploads. The second allow statement grants s3:PutObject when the encryption header is absent, covering unencrypted uploads. Because AWS policies evaluate allow statements additively, the effective permission is exactly that uploads with KMS encryption or without encryption are allowed.

Why this answer

The IAM policy uses a `Deny` effect with a `NotPrincipal` condition that denies uploads unless the request includes the `s3:x-amz-server-side-encryption` header with value `aws:kms`. However, the `Condition` block uses `StringNotEquals`, which means any request that does NOT have the encryption header set to `aws:kms` is denied. This effectively allows uploads with KMS encryption (header matches) or without encryption (no header present, because `StringNotEquals` does not match a missing header — the condition evaluates to false, so the Deny does not apply).

Therefore, uploads without encryption are allowed by default (since there is no explicit Allow), and uploads with KMS encryption are also allowed.

Exam trap

The trap here is that candidates assume `StringNotEquals` on a header condition will deny requests that omit the header, but in AWS IAM, missing condition keys cause the condition to evaluate to false, so the Deny does not apply — leaving unencrypted uploads allowed.

How to eliminate wrong answers

Option B is wrong because the policy does not require encryption to be absent; it denies only when encryption is specified but not equal to `aws:kms`, so uploads without any encryption header are allowed. Option C is wrong because the policy does not deny uploads when encryption is not provided; it only denies when encryption is provided but is not KMS (i.e., `AES256`). Option D is wrong because the policy does not require KMS encryption for all uploads; it allows uploads without any encryption header as well.

339
MCQeasy

Refer to the exhibit. A security engineer runs the above AWS CLI command to encrypt a secret file. The command succeeds and returns a base64-encoded ciphertext. Which of the following statements is correct?

A.The command returns a plaintext data key and an encrypted copy.
B.The command will fail because fileb:// is not a valid prefix.
C.The command returns a base64-encoded ciphertext that can be decrypted with the same KMS key.
D.The command will fail because encryption context is required.
AnswerC

The kms encrypt API returns a CiphertextBlob, and the AWS CLI base64-encodes this binary field in its JSON output. The ciphertext is encrypted under the customer master key specified in the command, so the same KMS key can decrypt it by calling kms decrypt after base64-decoding the blob. This matches the actual behavior of the command and is therefore the correct answer.

Why this answer

The command encrypts the plaintext file using the specified KMS key and returns the ciphertext as base64-encoded output. Option A is wrong because the command does not specify an encryption context; it's optional. Option B is wrong because the command uses fileb:// which reads binary data; it will succeed if the file exists.

Option D is wrong because the output is the ciphertext, not a data key.

340
MCQmedium

A company uses AWS Secrets Manager to rotate database credentials automatically. The security team wants to ensure that while the secret is being rotated, applications can always retrieve a valid credential. Which rotation strategy should be used?

A.Use AWS IAM database authentication instead.
B.Use a single user rotation with immediate update.
C.Disable automatic rotation and manually update credentials.
D.Use the alternating users rotation strategy.
AnswerD

The alternating users rotation strategy creates a second set of database credentials while the original remains valid, then promotes the new credentials to AWSCURRENT and demotes the old ones to AWSPREVIOUS. Applications can continue using either credential during the transition, so there is no window where no valid password exists. This makes it the right choice when a database cannot tolerate even brief downtime during Secrets Manager rotation.

Why this answer

The alternating users rotation strategy (Option D) is correct because it creates two sets of credentials—one active and one pending—so that during rotation, at least one set remains valid for applications. Option A (IAM database authentication) is not a rotation strategy for Secrets Manager. Option B (single user rotation with immediate update) would cause a brief period where the credential is invalid, leading to potential downtime.

Option C (disabling automatic rotation) defeats the purpose of automated rotation.

Exam trap

Candidates may mistakenly believe that single user rotation (Option B) is acceptable, but it causes a temporary gap in valid credentials. The alternating users strategy avoids this gap.

341
MCQeasy

A security team needs to audit all changes to IAM policies in their AWS account. Which AWS service should be used?

A.AWS Config
B.Amazon CloudWatch
C.IAM Access Analyzer
D.AWS CloudTrail
AnswerD

AWS CloudTrail is the correct service because it records management events for all IAM actions, including CreatePolicy, PutRolePolicy, AttachUserPolicy, and DetachUserPolicy, and includes the identity of the caller, the time of the request, source IP, request parameters, and response elements. Management events are logged by default for every region, and you can create a trail to deliver them to S3 for long-term retention and protection with features such as S3 object lock and CloudWatch Logs integration. This gives the security team a complete, chronological audit trail of every IAM policy change.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made in the AWS account, including IAM policy changes such as CreatePolicy, PutRolePolicy, and AttachUserPolicy. These events are captured as CloudTrail log entries, which can be audited to track who made the change, when it was made, and from which source IP. CloudTrail is the primary service for auditing and logging all management events across AWS services.

Exam trap

The trap here is that candidates often confuse AWS Config (which checks compliance of current configurations) with CloudTrail (which records the history of API calls), leading them to select Config for auditing changes instead of CloudTrail.

How to eliminate wrong answers

Option A is wrong because AWS Config is a service for evaluating resource configurations against desired rules (e.g., checking if an IAM policy is compliant), not for recording the history of changes or API calls. Option B is wrong because Amazon CloudWatch is a monitoring service for metrics, logs, and alarms; it does not natively capture IAM policy change events unless CloudTrail logs are streamed to it, but CloudWatch itself is not the audit trail source. Option C is wrong because IAM Access Analyzer is used to identify resources shared with external principals (e.g., analyzing resource-based policies for unintended access), not for auditing the history of policy changes.

342
MCQhard

A company stores sensitive data in an Amazon S3 bucket. The security team wants to ensure that all objects are encrypted with SSE-KMS using a specific customer managed key, and that any attempt to upload an object without this encryption is denied. The bucket policy must enforce this. Which bucket policy statement should the security engineer use?

A.Two deny statements for s3:PutObject: one where StringNotEquals on s3:x-amz-server-side-encryption is 'aws:kms', and another where StringNotEquals on s3:x-amz-server-side-encryption-aws-kms-key-id is the ARN of the specific KMS key.
B.A deny statement for s3:PutObject where the condition StringNotEquals on s3:x-amz-server-side-encryption is 'aws:kms' AND StringNotEquals on s3:x-amz-server-side-encryption-aws-kms-key-id is the ARN of the specific KMS key.
C.A deny statement for s3:PutObject where the condition StringNotEquals on s3:x-amz-server-side-encryption-aws-kms-key-id is the ARN of the specific KMS key.
D.A deny statement for s3:PutObject where the condition StringNotEquals on s3:x-amz-server-side-encryption is 'aws:kms'.
AnswerA

Two separate deny statements ensure that an upload is denied if it lacks the correct encryption algorithm or if it uses a different KMS key. The first statement denies any upload not using aws:kms. The second denies any upload not using the specified key ARN. Together they enforce both requirements. This is the recommended approach in AWS documentation.

Why this answer

To enforce a specific KMS key for SSE-KMS, the bucket policy must deny uploads that either do not use SSE-KMS or do not use the specified key. Using two separate deny statements with StringNotEquals conditions on s3:x-amz-server-side-encryption and s3:x-amz-server-side-encryption-aws-kms-key-id achieves this. A single statement with AND logic would not correctly deny when only one condition is violated.

Exam trap

The trap here is combining conditions with AND in a single deny statement, which fails to deny when only one condition is not met, leaving a gap in enforcement.

343
Multi-Selectmedium

A security team wants to detect and alert on potential security threats such as compromised instances or malicious activity within their AWS environment. Which TWO AWS services should be used together to provide comprehensive threat detection?

Select 2 answers
A.AWS Security Hub
B.AWS CloudTrail
C.Amazon Inspector
D.AWS Config
E.Amazon GuardDuty
AnswersA, E

Security Hub aggregates and prioritises findings from GuardDuty, which performs the actual threat detection for compromised instances and malicious activity. Together they satisfy the requirement for comprehensive detection plus centralised alerting across the AWS environment.

Why this answer

Amazon GuardDuty (E) is correct because it is the AWS managed threat detection service that continuously monitors VPC Flow Logs, DNS logs, and CloudTrail management/event logs using machine learning and threat intelligence feeds to identify compromised instances, reconnaissance, and malicious activity. AWS Security Hub (A) is correct because it aggregates and prioritizes findings from GuardDuty and other services into a single dashboard, enabling centralized alerting and automated response workflows for comprehensive threat visibility. Together, GuardDuty provides the detection engine while Security Hub provides aggregation and alerting.

AWS CloudTrail (B) only records API activity for auditing and does not itself detect or alert on threats. Amazon Inspector (C) is a vulnerability management service that scans EC2 instances and container images for software vulnerabilities and unintended network exposure, not runtime threat detection. AWS Config (D) evaluates resource configuration compliance against rules and does not perform threat detection or alerting on malicious behavior.

Exam trap

The trap here is that candidates often confuse logging services (CloudTrail, Config) or vulnerability scanners (Inspector) with active threat detection, but GuardDuty and Security Hub are the only pair that provide continuous, intelligent threat monitoring and centralized alerting.

344
MCQhard

A financial services company uses AWS KMS to encrypt sensitive data. The security team has a requirement to rotate the CMK every 90 days and to maintain a record of all previous key versions for decryption of historical data. The team creates a new CMK every 90 days and manually updates applications to use the new key. This process is error-prone and causes downtime. What is the MOST operationally efficient solution that meets the requirements?

A.Enable automatic key rotation on the existing CMK.
B.Create a new CMK every 90 days and update the alias to point to the new key. Applications reference the alias.
C.Use a CMK with imported key material and rotate the material every 90 days.
D.Continue creating new CMKs but use a script to update the application configuration files.
AnswerB

Creating a new CMK every 90 days and then updating the alias to reference the new key provides a stable abstraction because applications point to the alias, not the key ID. The alias update is immediate and atomic, requiring no application changes, restarts, or downtime; the old CMK remains enabled to decrypt data encrypted under previous keys. This pattern is the recommended AWS KMS approach for custom rotation periods and satisfies crypto-period separation.

Why this answer

It uses aliases to decouple the key identifier from the application configuration. By creating a new CMK every 90 days and updating the alias to point to the new key, applications that reference the alias automatically use the new key without code changes, eliminating downtime. AWS KMS aliases are mutable pointers that can be reassigned to different CMKs, and the old key versions remain available for decryption of historical data.

Exam trap

The trap here is that candidates often confuse automatic key rotation (which only rotates backing keys within the same CMK) with creating a new CMK and using aliases, failing to recognize that automatic rotation does not meet a 90-day schedule and does not create a separate CMK for audit or compliance purposes.

How to eliminate wrong answers

Option A is wrong because automatic key rotation on an existing CMK creates new backing key versions every year (not 90 days) and does not create a new CMK; it only rotates the cryptographic material within the same CMK, which does not meet the 90-day rotation requirement. Option C is wrong because using a CMK with imported key material and rotating the material every 90 days still does not create a new CMK; it only replaces the key material within the same CMK, and the old key material is deleted, preventing decryption of historical data. Option D is wrong because it continues the error-prone manual process of updating application configuration files, which causes downtime and operational overhead, and does not leverage AWS KMS aliases for a seamless transition.

345
Multi-Selecthard

Which THREE are features of Amazon GuardDuty that help with threat detection? (Select THREE.)

Select 3 answers
A.Analyzes AWS Config configuration history.
B.Analyzes S3 object content for malware.
C.Analyzes VPC Flow Logs.
D.Analyzes DNS query logs.
E.Analyzes AWS CloudTrail management events.
AnswersC, D, E

GuardDuty ingests VPC Flow Logs from enabled VPCs to analyze network traffic metadata, including source and destination IPs, ports, and packet counts. It uses this telemetry to detect malicious activities like port scanning, brute-force attempts, and communication with known command-and-control or cryptocurrency-mining infrastructure. Flow Logs must be enabled for the VPCs you want monitored, and GuardDuty consumes them through an integrated service-linked role.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior. It ingests and analyzes VPC Flow Logs (option C) to detect suspicious network traffic patterns, such as port scans or data exfiltration attempts. This analysis is a core feature of GuardDuty's threat detection capabilities.

Exam trap

The trap here is that candidates may confuse GuardDuty's core log sources (VPC Flow Logs, DNS logs, CloudTrail) with other AWS security services like AWS Config (for configuration history) or Amazon Macie (for S3 data classification), leading them to select options A or B incorrectly.

346
MCQmedium

A company's security policy requires that all S3 buckets be encrypted at rest. An security engineer needs to detect any S3 bucket that does not have default encryption enabled. Which AWS service should the engineer use to continuously monitor and alert on non-compliant buckets?

A.AWS CloudTrail
B.AWS Config
C.AWS Trusted Advisor
D.Amazon GuardDuty
AnswerB

AWS Config continuously records S3 bucket configuration and evaluates it against managed or custom rules, flagging buckets lacking default encryption. This satisfies the requirement for ongoing detection and alerting, unlike one-off scans or CloudTrail, which logs API activity rather than resource compliance state.

Why this answer

AWS Config is the correct service because it provides continuous monitoring and evaluation of your AWS resource configurations against desired policies. You can create an AWS Config rule, such as the managed rule 's3-bucket-default-encryption-enabled', which automatically checks each S3 bucket for the presence of default encryption (SSE-S3 or SSE-KMS) and triggers an alert or remediation action for any non-compliant bucket. This aligns directly with the requirement to detect and alert on buckets lacking encryption at rest.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which logs API calls) with AWS Config (which evaluates resource configurations), leading them to choose CloudTrail for monitoring encryption settings when it only records the actions that change encryption, not the current state of encryption on each bucket.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity (e.g., PutBucketEncryption calls) but does not continuously evaluate the current configuration state of resources; it is an audit trail, not a compliance checker. Option C is wrong because AWS Trusted Advisor provides one-time or periodic checks for best practices (including S3 bucket permissions) but does not offer continuous, customizable monitoring or alerting for specific encryption settings like default encryption. Option D is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events for malicious activity; it does not evaluate resource configurations for compliance with encryption policies.

347
MCQmedium

A company uses AWS Transit Gateway to connect multiple VPCs and on-premises networks via AWS Site-to-Site VPN. Security engineers need to ensure that traffic between VPCs is inspected by a third-party firewall appliance deployed in a centralized inspection VPC. Which architecture should be used?

A.Use security groups in each VPC to allow only traffic from the firewall appliance's IP.
B.Establish VPC Peering connections between each VPC and the inspection VPC.
C.Configure Network ACLs in each VPC to deny traffic that does not originate from the inspection VPC.
D.Create a central inspection VPC with the firewall appliance. Configure Transit Gateway route tables to route traffic between VPCs through the inspection VPC.
AnswerD

Create a dedicated inspection VPC that hosts a firewall appliance or a Gateway Load Balancer, and use separate Transit Gateway route tables to force inter-VPC traffic through that VPC. For example, associate each spoke VPC attachment with a route table that has a target route pointing to the inspection VPC attachment for all destination CIDRs, while the inspection VPC uses its own route table to reach the final destination VPCs. This design leverages Transit Gateway's transitive routing and supports high availability through multiple firewall instances behind a Gateway Load Balancer. It is a best practice for centralized east-west traffic inspection in a multi-VPC topology.

Why this answer

Transit Gateway route tables can force traffic between VPCs through the inspection VPC by attaching the firewall appliance and using specific routing entries. Option A is incorrect because security groups only control traffic at the instance level and cannot redirect traffic to an inspection appliance. Option B is incorrect because VPC Peering does not support transitive routing, so traffic between two VPCs cannot go through a third VPC.

Option C is incorrect because Network ACLs are stateless and can only filter traffic based on IP/port, not route traffic through an inspection appliance.

348
MCQeasy

A company is using AWS CloudFormation to deploy a web application. The template includes an EC2 instance with a security group that allows inbound HTTP traffic from 0.0.0.0/0. The security team wants to ensure that this security group is never used in production. Which AWS service can automatically remediate this noncompliant configuration?

A.AWS Identity and Access Management (IAM)
B.AWS Config
C.Amazon GuardDuty
D.AWS CloudTrail
AnswerB

AWS Config continuously records each supported resource's configuration history and evaluates that state against customizable rules and conformance packs. When a resource violates a rule, Config can invoke an AWS Systems Manager Automation document to perform auto-remediation, such as restoring security group rules or untagging resources. This combination of continuous evaluation and corrective action is exactly what is needed to enforce the intended deployed state from CloudFormation.

Why this answer

AWS Config is the correct service because it provides managed rules (e.g., 'restricted-ssh' or 'incoming-ssh-disabled') that can evaluate security group configurations against desired compliance. When a noncompliant resource is detected, AWS Config can trigger an automatic remediation action via Systems Manager Automation documents (e.g., AWSConfigRemediation-RevokeUnusedSecurityGroupIngress) to remove the overly permissive inbound rule. This directly addresses the security team's requirement to prevent the use of a security group allowing HTTP traffic from 0.0.0.0/0 in production.

Exam trap

The trap here is that candidates often confuse AWS Config's detective and preventive capabilities with those of GuardDuty or CloudTrail, mistakenly thinking that threat detection or logging services can automatically fix misconfigurations, when only AWS Config with remediation actions can do so.

How to eliminate wrong answers

Option A is wrong because AWS Identity and Access Management (IAM) manages user permissions and access control, not resource configuration compliance or automated remediation of security group rules. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events for malicious activity; it does not evaluate or remediate security group configurations. Option D is wrong because AWS CloudTrail records API calls for auditing and governance, but it cannot automatically remediate noncompliant resources; it only provides logs for manual review or downstream processing.

349
MCQmedium

Refer to the exhibit. A security engineer reviews the AWS WAF web ACL configuration. What is the effect of this configuration?

A.It blocks IPs that send more than 2000 requests and allows requests containing '<script>' in the body.
B.It allows all traffic because the rules are misconfigured.
C.It blocks both SQL injection and XSS attacks.
D.It blocks SQL injection attacks and allows XSS attacks.
AnswerA

The web ACL contains two rules evaluated in order. The first is a rate-based rule with a threshold of 2,000 requests per IP address over the evaluation window; when that limit is exceeded, the Block action immediately terminates the request. Requests that stay below the threshold continue to the second rule, an XSS match rule whose action is set to Allow, so any request with `<script>` in its body is explicitly permitted rather than blocked. The net effect is therefore IP-based volumetric blocking only, with no content-based blocking.

Why this answer

The first rule (SQLiRule) is actually a rate-based rule that blocks IPs exceeding 2000 requests, not SQL injection. The second rule (XSSRule) has an Allow action, which would allow requests containing '<script>' in the body, defeating the purpose of blocking XSS.

350
MCQmedium

A company is using Amazon Route 53 and wants to log DNS queries for investigative purposes. The logs must be stored in a centralized S3 bucket in the security account. What is the MOST efficient way to achieve this?

A.Enable VPC Flow Logs and analyze DNS traffic.
B.Enable CloudWatch Logs for Route 53 and stream to a Lambda function that writes to S3.
C.Configure Route 53 Resolver query logging to deliver to the central S3 bucket.
D.Use a custom Lambda function to poll Route 53 logs and write to S3.
AnswerC

Route 53 Resolver query logging is the native capability that records the full DNS query and response data for queries handled by Route 53 Resolver, including those from VPCs, inbound, and outbound endpoints. It can directly write logs to a central S3 bucket, and using a cross-account bucket policy, you can allow Route 53 in your account to deliver into the consolidated logging bucket. This approach avoids any intermediate compute, scales automatically, and is the most straightforward secure delivery mechanism.

Why this answer

Route 53 Resolver query logging natively supports delivering DNS query logs directly to an S3 bucket, including cross-account S3 buckets, without requiring any intermediate services. This is the most efficient method because it eliminates the need for additional compute resources or manual polling, and it directly satisfies the requirement for centralized logging in the security account.

Exam trap

The trap here is that candidates may confuse VPC Flow Logs (which capture network flows) with DNS query logs, or assume that CloudWatch Logs or Lambda are required for S3 delivery, when Route 53 Resolver query logging can directly write to S3 with minimal configuration.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) but do not log DNS query details such as domain names or query types. Option B is wrong because Route 53 does not natively send logs to CloudWatch Logs; you would need to configure query logging to CloudWatch Logs first, then use a subscription filter to stream to Lambda, which adds unnecessary complexity and cost compared to direct S3 delivery. Option D is wrong because there is no native 'Route 53 logs' API to poll; Route 53 Resolver query logging can be configured to deliver directly to S3, making a custom polling Lambda redundant and inefficient.

351
MCQhard

Refer to the exhibit. A security engineer runs the command above and sees that the flow log status is ACTIVE. However, the engineer notices that no logs are appearing in the CloudWatch log group. What is the most likely cause?

A.The TrafficType is set to ALL, which captures too much data and causes throttling.
B.The IAM role specified in DeliverLogsPermissionArn does not have permissions to PutLogEvents.
C.The flow log is attached to an ENI instead of a subnet.
D.The flow log destination is set to CloudWatch Logs but the log group is encrypted with KMS.
AnswerB

The DeliverLogsPermissionArn role must have a trust policy allowing vpc-flow-logs.amazonaws.com to assume it and an IAM permissions policy granting logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents. Without logs:PutLogEvents, the Flow Logs service cannot append records to the CloudWatch log stream, so the flow log remains in a FAILED state. Adding the missing PutLogEvents permission is the standard fix for this symptom.

Why this answer

The most likely cause is that the IAM role specified in the DeliverLogsPermissionArn does not have the necessary permissions to call PutLogEvents on the CloudWatch Logs log group. Even if the flow log status is ACTIVE, the delivery of log records will silently fail if the role lacks the required logs:PutLogEvents, logs:CreateLogStream, and logs:DescribeLogStreams actions. The ACTIVE status only indicates that the flow log configuration is valid and the service is attempting to deliver logs, not that delivery is succeeding.

Exam trap

The trap here is that candidates assume an ACTIVE status guarantees logs are being delivered, but AWS explicitly documents that ACTIVE only means the configuration is valid, not that delivery is succeeding; the real test is whether the IAM role has the correct permissions to write to CloudWatch Logs.

How to eliminate wrong answers

Option A is wrong because setting TrafficType to ALL captures all accepted and rejected traffic, which can generate large volumes of data, but CloudWatch Logs throttling is based on the log group's throughput limits and the IAM role's permissions, not the TrafficType setting; throttling would produce a different symptom (e.g., logs appearing slowly or with delays) rather than no logs at all. Option C is wrong because attaching a flow log to an ENI is a valid and common configuration; flow logs can be created at the VPC, subnet, or ENI level, and all are supported, so this would not prevent logs from appearing. Option D is wrong because if the log group is encrypted with a KMS key, the IAM role must also have kms:Decrypt and kms:GenerateDataKey permissions on that key; however, the absence of KMS permissions would cause a different error (e.g., 'AccessDenied' in the flow log status or CloudWatch Logs), but the question states the flow log status is ACTIVE, which implies the KMS permissions are likely correct or the log group is not encrypted; the core issue is the missing PutLogEvents permission.

352
MCQhard

A company requires real-time analysis of AWS CloudTrail logs to detect unauthorized API calls. The logs are stored in Amazon S3. Which architecture minimizes latency and cost?

A.Use AWS Glue to crawl S3 and load into Amazon Redshift for analysis
B.Send CloudTrail logs to Amazon CloudWatch Logs, then use a subscription filter to Amazon Kinesis Data Firehose delivering to Amazon OpenSearch Service
C.Query CloudTrail logs directly using Amazon Athena
D.Configure S3 event notifications to invoke an AWS Lambda function that writes to Amazon OpenSearch Service
AnswerB

CloudTrail can be configured to deliver events to Amazon CloudWatch Logs within minutes, and a subscription filter can immediately forward matching events to Amazon Kinesis Data Firehose. Firehose then buffers and delivers a continuous stream to Amazon OpenSearch Service, which indexes documents as they arrive for near-real-time search and visualization with OpenSearch Dashboards/Kibana. This managed pipeline gives the low-latency ingestion and querying the requirement asks for.

Why this answer

It provides the lowest-latency path for real-time analysis: CloudTrail logs are delivered to CloudWatch Logs in near real-time, and a subscription filter streams them to Kinesis Data Firehose, which buffers and delivers directly to Amazon OpenSearch Service for immediate indexing and search. This architecture avoids batch processing, minimizes data movement overhead, and uses managed services that scale automatically, keeping both latency and cost low.

Exam trap

The trap here is that candidates often assume S3 event notifications (Option D) are the fastest path for real-time processing, but they overlook the inherent delivery delay of CloudTrail to S3 (up to 15 minutes) and the risk of Lambda concurrency limits causing dropped events under high log volume.

How to eliminate wrong answers

Option A is wrong because AWS Glue crawling S3 and loading into Amazon Redshift introduces significant batch processing latency (minutes to hours) and incurs high costs for Redshift compute and storage, making it unsuitable for real-time analysis. Option C is wrong because querying CloudTrail logs directly with Amazon Athena requires scanning the entire S3 object set per query, which adds seconds to minutes of latency and incurs per-scan costs that become prohibitive for continuous real-time detection. Option D is wrong because S3 event notifications for CloudTrail logs are typically delivered with a delay (up to 15 minutes) and invoking a Lambda function per object to write to OpenSearch Service creates a tight coupling that can lead to throttling, data loss under high volume, and higher operational overhead compared to the managed streaming pipeline in B.

353
Matchingmedium

Match each AWS security tool to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Automated vulnerability assessment

Threat detection service

Centralized security findings aggregation

Investigation and analysis of security issues

Resource configuration monitoring and compliance

Why these pairings

Correct matches: AWS Shield protects against DDoS, AWS WAF filters web traffic, and GuardDuty provides threat detection. Common confusions include swapping Shield with WAF and Inspector with Macie.

354
MCQmedium

A security engineer is investigating an IAM role that was used to access AWS resources from an external account. The role has a trust policy that allows the external account to assume it. Which of the following is a required step for the external account to use the role?

A.Configure the role to require MFA for the external account.
B.Create a new IAM role in the external account with a trust policy allowing the role's ARN.
C.Add the external account's root user ARN to the role's trust policy.
D.Attach an IAM policy to an IAM user in the external account that allows sts:AssumeRole for the role ARN.
AnswerD

Cross-account access needs two sides: the trust policy in the owning account and an identity-based policy in the external account granting sts:AssumeRole on the role ARN. Without that permission attached to the calling principal, the AssumeRole call is denied.

Why this answer

For an external account to assume an IAM role in another account, an IAM user or role in the external account must have an IAM policy that allows the sts:AssumeRole action for the role's ARN. This is a required step because the external account's identity needs permission to call AssumeRole. The trust policy on the role allows the external account to assume it, but the external account must also grant its own identity the permission to assume that role.

Exam trap

SCS-C02 often tests the two-sided permission requirement for cross-account role assumption; candidates may forget that the external account must also have an identity-based policy allowing sts:AssumeRole, not just the trust policy on the role.

How to eliminate wrong answers

Option A is wrong because requiring MFA is an optional security enhancement, not a required step for the external account to use the role. Option B is wrong because creating a new IAM role in the external account with a trust policy allowing the role's ARN is not required; the external account can use an IAM user or role with the appropriate AssumeRole policy. Option C is wrong because adding the external account's root user ARN to the trust policy is not required; the trust policy typically specifies the account ID or a specific principal, and the root user is not the only way.

355
MCQmedium

A security engineer is designing a network architecture for a three-tier web application. The web tier must be accessible from the internet, but the application and database tiers must not. Which VPC configuration should be used?

A.Place web and app tiers in public subnets, database in private subnet.
B.Place web tier in public subnets, app and database tiers in private subnets.
C.Place all tiers in private subnets and use a VPN for external access.
D.Place all tiers in public subnets with security groups restricting access.
AnswerB

This standard three-tier design places only the web tier in public subnets with a route to an internet gateway so it can serve external users. The app and database tiers are in private subnets with no internet gateway route, preventing direct inbound connections from the internet; the app tier receives traffic from the web tier through an internal load balancer or security group rules, and the database is isolated to app-tier-only access. This minimizes the attack surface and is the correct pattern for a public-facing web application.

Why this answer

It places the web tier in public subnets with an internet gateway for direct internet access, while the application and database tiers reside in private subnets with no direct internet route. This ensures that only the web tier is exposed, and the app and database tiers can only be reached through the web tier via internal routing, aligning with the principle of least privilege for a three-tier architecture.

Exam trap

The trap here is that candidates often confuse security groups with subnet routing, assuming that restrictive security groups alone can prevent internet access even when the subnet is public, but the route table's default route to an internet gateway still allows inbound traffic from the internet.

How to eliminate wrong answers

Option A is wrong because placing the app tier in a public subnet exposes it to the internet, violating the requirement that only the web tier be accessible from the internet. Option C is wrong because using a VPN for external access would require all traffic to go through the VPN, which is unnecessary and adds complexity; the web tier is meant to be publicly accessible without VPN. Option D is wrong because placing all tiers in public subnets, even with security groups, still exposes the app and database tiers to potential internet-facing risks, as security groups alone do not prevent direct internet access from the subnet's route table.

356
Multi-Selecthard

Which TWO AWS services can be used to enforce that specific resource types (e.g., EC2 instances) are tagged with a 'CostCenter' tag? (Choose two.)

Select 2 answers
A.AWS Organizations tag policies
B.AWS Service Catalog
C.AWS Config
D.AWS CloudFormation
E.AWS IAM
AnswersA, C

AWS Organizations tag policies are a centralized policy type that define which tag keys and values are allowed on resources across all accounts in the organization. Attached to the root, an OU, or an account, they act as a preventive guardrail during resource creation and modification, so a resource that is tagged outside the allowed rules can be denied. This makes them the native service for enforcing specific tags organization-wide.

Why this answer

AWS Config can evaluate resource tagging and AWS Organizations can use tag policies. IAM is for permissions, not enforcement; CloudFormation can be used but not for existing resources; Service Catalog is for provisioning, not enforcement.

357
MCQeasy

What is the purpose of an AWS Service Control Policy (SCP) in AWS Organizations?

A.To grant specific permissions to users in member accounts.
B.To restrict only the root user of each member account.
C.To monitor and log API activity across the organization.
D.To set permission guardrails that restrict what actions accounts in the organization can perform.
AnswerD

SCPs set permission guardrails by defining the maximum actions that principals in an account or organizational unit can perform. When attached at the organization, OU, or account level, an SCP constrains all IAM users and roles in that account—including the account root user—by filtering what identity-based and resource-based policies are allowed to grant. They act as a boundary that limits, but never grants, permissions, making them the correct mechanism for organization-wide controls such as denying the deletion of CloudTrail logs or restricting access to certain AWS services.

Why this answer

SCPs are used to centrally control the maximum available permissions for all accounts in an organization. Option A is wrong because SCPs do not grant permissions; they restrict them. Option B is wrong because SCPs apply to all users and roles, not just root.

Option C is wrong because SCPs are not for monitoring; they are permission guardrails.

358
MCQhard

During incident response, a security engineer needs to preserve the state of a running EC2 instance for forensic analysis without losing volatile data. The instance is in an Auto Scaling group. Which action should the engineer take FIRST?

A.Detach the instance from the Auto Scaling group.
B.Stop the instance to preserve its EBS volumes.
C.Take an AMI of the instance immediately.
D.Suspend the `HealthCheck` and `ReplaceUnhealthy` processes on the Auto Scaling group.
AnswerD

Suspending HealthCheck and ReplaceUnhealthy stops the Auto Scaling group terminating or replacing the instance while it is isolated for forensics. This preserves volatile memory and disk state, which would otherwise be lost if the group launched a replacement.

Why this answer

Suspending the `HealthCheck` and `ReplaceUnhealthy` processes on the Auto Scaling group prevents the group from detecting the instance as unhealthy and terminating it while the engineer preserves volatile data. This is the first step to ensure the instance remains running and accessible for forensic collection (e.g., memory dump) before any other actions that could alter its state.

Exam trap

The trap here is that candidates often choose to stop the instance or take an AMI first, not realizing that those actions destroy volatile data or require a stable state, whereas the correct first step is to prevent the Auto Scaling group from interfering with the running instance.

How to eliminate wrong answers

Option A is wrong because detaching the instance from the Auto Scaling group does not prevent the group from launching a replacement instance, but more critically, it does not protect the running instance from being terminated by other processes or manual actions; it also does not preserve volatile data. Option B is wrong because stopping the instance immediately loses volatile data (RAM, network connections, process state) which is critical for forensic analysis; the goal is to preserve the running state, not halt it. Option C is wrong because taking an AMI of the instance requires the instance to be in a stable state (often stopped or with consistent filesystem), and it does not capture volatile memory; it also takes time and could alter the instance state during the snapshot process.

359
MCQhard

A company is deploying a web application on EC2 instances behind an Application Load Balancer. The security team requires that all traffic between the ALB and the EC2 instances be encrypted. Which configuration should the engineer implement?

A.Configure the ALB listener with HTTP protocol and the target group with HTTP protocol, then use a security group to restrict traffic.
B.Configure the ALB listener with HTTPS protocol and the target group with HTTP protocol.
C.Configure the ALB listener with TCP protocol and the target group with TCP protocol, then install SSL certificates on the EC2 instances.
D.Configure the ALB listener with HTTPS protocol and the target group with HTTPS protocol, and install SSL certificates on the EC2 instances.
AnswerD

End-to-end encryption requires TLS on both hops: an HTTPS listener terminates client TLS, while an HTTPS target group re-encrypts traffic to the instances. Installing certificates on the EC2 instances lets them present them, satisfying the requirement that ALB-to-instance traffic is encrypted.

Why this answer

It ensures end-to-end encryption between the ALB and EC2 instances. The ALB listener uses HTTPS to terminate client SSL/TLS, and the target group uses HTTPS to re-encrypt traffic to the instances, requiring SSL certificates on the EC2 instances to decrypt and re-encrypt. This satisfies the security requirement that all traffic between the ALB and EC2 instances be encrypted.

Exam trap

The trap here is that candidates often assume HTTPS on the listener alone is sufficient, overlooking that the target group protocol must also be HTTPS to encrypt traffic between the ALB and instances, not just between clients and the ALB.

How to eliminate wrong answers

Option A is wrong because using HTTP on both the listener and target group means traffic is in plaintext, violating the encryption requirement. Option B is wrong because while the listener uses HTTPS, the target group uses HTTP, so traffic between the ALB and EC2 instances is unencrypted, which does not meet the requirement. Option C is wrong because TCP protocol at the listener and target group does not provide application-layer encryption; SSL certificates on EC2 instances alone do not encrypt traffic without HTTPS configuration on the target group.

360
MCQmedium

A company's security policy requires that all S3 bucket access logs be delivered to a central S3 bucket in the security account. A security engineer notices that some buckets are not delivering logs. The engineer needs to identify which buckets are not logging and ensure compliance. Which service should the engineer use to continuously monitor and report on S3 bucket logging?

A.Amazon Macie
B.Amazon S3 Inventory
C.AWS Config
D.AWS CloudTrail
AnswerC

AWS Config is the correct answer because its managed rule "s3-bucket-logging-enabled" checks the configuration state of each S3 bucket and determines whether server access logging is pointed at a valid destination bucket. AWS Config records bucket resource configurations as configuration items, evaluates them against desired policies, and provides continuous compliance results, which matches the security requirement precisely. It can optionally trigger automatic remediation via Systems Manager Automation if a bucket is found noncompliant.

Why this answer

AWS Config is the correct service because it provides continuous monitoring and evaluation of AWS resource configurations against desired policies. By using an AWS Config managed rule like `s3-bucket-logging-enabled`, the security engineer can automatically detect S3 buckets that do not have logging enabled and receive compliance notifications, ensuring ongoing adherence to the security policy.

Exam trap

The trap here is confusing AWS CloudTrail (which logs API calls) with AWS Config (which evaluates resource configurations), leading candidates to mistakenly choose CloudTrail for configuration compliance checks instead of Config.

How to eliminate wrong answers

Option A is wrong because Amazon Macie is a data security service that uses machine learning to discover, classify, and protect sensitive data in S3, not to monitor bucket logging configurations. Option B is wrong because Amazon S3 Inventory provides a list of objects and their metadata for auditing or lifecycle management, but it does not evaluate or report on the logging configuration of the buckets themselves. Option D is wrong because AWS CloudTrail records API activity for governance and auditing, but it does not continuously assess the configuration state of S3 bucket logging settings.

361
Multi-Selectmedium

Which THREE of the following are best practices for managing IAM access keys? (Choose THREE.)

Select 3 answers
A.Use IAM roles for EC2 instances instead of access keys
B.Use long-lived access keys for applications
C.Delete unused access keys
D.Embed access keys in application code for convenience
E.Rotate access keys regularly
AnswersA, C, E

IAM roles for Amazon EC2 instances provide temporary security credentials through the instance metadata service, eliminating the need to store any long-term secret material inside the instance. These credentials are automatically rotated and can be scoped with a precise permissions policy, so even if the instance is compromised, the blast radius is limited. This approach also simplifies key management because there is no auth material to embed, rotate, or revoke individually.

Why this answer

Option A is correct because IAM roles deliver temporary credentials to EC2 instances via the instance metadata service, eliminating the need to store long-lived access keys on the instance and automatically rotating credentials. Option C is correct because unused access keys represent an unnecessary attack surface; deleting them (or deactivating them first) removes the risk of leaked or forgotten credentials being abused. Option E is correct because regularly rotating access keys limits the window of exposure if a key is compromised and aligns with AWS guidance to rotate keys periodically.

Options B and D are not best practices: long-lived keys increase exposure risk, and embedding keys in application code makes them hard to rotate and easy to leak through source control or logs.

Exam trap

SCS-C02 often tests the misconception that long-lived access keys are acceptable for convenience — candidates may pick 'use long-lived keys' or 'embed keys in code' as valid practices when they are explicitly discouraged.

362
MCQeasy

A company wants to allow its developers to SSH into EC2 instances only from the corporate network IP range (203.0.113.0/24). Which configuration should be used to enforce this restriction?

A.Configure a network ACL on the subnet to allow inbound SSH from the corporate range and deny all other inbound traffic.
B.Use AWS Systems Manager Session Manager to connect to instances instead of SSH.
C.Add an IAM policy that allows `ec2:RunInstances` only if the request includes the corporate IP.
D.Add a security group rule that allows inbound SSH (port 22) from the corporate IP range.
AnswerD

Adding a security group rule to allow inbound SSH (port 22) only from the corporate IP range is the correct solution because security groups are stateful and act at the instance's network interface level. This rule denies all other inbound SSH traffic by default, since security groups have an implicit deny-all inbound rule, and because it is stateful, return traffic for allowed connections (e.g., ephemeral ports) is automatically permitted. This directly restricts SSH to the corporate range without requiring separate outbound rules, making it the appropriate mechanism for this use case.

Why this answer

A security group rule can restrict inbound SSH to the specific IP range. Security groups act as a virtual firewall for EC2 instances, and by adding a rule that allows inbound SSH only from the corporate IP range (203.0.113.0/24), all other inbound traffic on port 22 is implicitly denied. Option A is incorrect because network ACLs are stateless and apply at the subnet level, not the instance level, and the question asks for a configuration to enforce SSH restriction on EC2 instances.

Option B is incorrect because AWS Systems Manager Session Manager does not use SSH; it provides browser-based shell access without inbound ports. Option C is incorrect because IAM policies control permissions for API actions, not network traffic.

363
MCQeasy

A company wants to automate the enforcement of security best practices across all AWS accounts. Which AWS service provides pre-built rules for security compliance?

A.Amazon GuardDuty
B.Amazon Inspector
C.AWS Security Hub
D.AWS Config
AnswerC

AWS Security Hub aggregates security findings from across AWS accounts and services and runs automated, continuous compliance checks against standards such as CIS AWS Foundations, AWS Foundational Best Practices, and PCI DSS. It provides a consolidated security score and actionable insights, enabling automated enforcement of security best practices. This integration and standard-based evaluation make it the correct service for the stated requirement.

Why this answer

AWS Security Hub is the correct answer because it provides a comprehensive view of security alerts and compliance status across AWS accounts, and it includes pre-built security standards and automated compliance checks based on frameworks such as the AWS Foundational Security Best Practices (FSBP), CIS AWS Foundations Benchmark, and PCI DSS. These pre-built rules allow you to automate the enforcement of security best practices without manual configuration.

Exam trap

The trap here is that candidates often confuse AWS Config's managed rules (which evaluate resource configurations) with Security Hub's pre-built security compliance standards, but Security Hub is specifically designed for aggregating and automating security best practices across accounts, while Config is a configuration auditing tool without built-in security compliance frameworks.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior using machine learning and threat intelligence, but it does not provide pre-built rules for security compliance or automated compliance checks. Option B is wrong because Amazon Inspector is an automated vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, but it does not offer pre-built compliance rules or enforce security best practices across accounts. Option D is wrong because AWS Config is a service that evaluates your resource configurations against desired configurations using custom or managed rules, but it does not provide pre-built security compliance standards or a consolidated dashboard for security best practices across accounts; it focuses on resource configuration auditing rather than security compliance enforcement.

364
MCQeasy

A company uses AWS CloudTrail to log API activity. The security team wants to ensure that any modification to CloudTrail configuration is logged and that the logs are tamper-proof. Which feature should be enabled?

A.S3 MFA Delete on the CloudTrail S3 bucket
B.S3 Versioning on the CloudTrail S3 bucket
C.CloudTrail Log File Integrity Validation
D.CloudWatch Logs log stream encryption
AnswerC

CloudTrail Log File Integrity Validation is correct because it generates a SHA-256 hash of each log file and signs it with a private key, enabling you to detect any tampering or deletion of log files. You can retrieve the public key from a pre-signed URL to verify both the hash and the digital signature, ensuring the logs have not been altered. This provides strong, cryptographic proof of integrity, which is exactly what the requirement demands.

Why this answer

CloudTrail Log File Integrity Validation (option C) uses a hash chain and digital signatures (SHA-256 hashing with RSA) to verify that log files have not been modified, deleted, or tampered with after delivery to the S3 bucket. This feature creates a digest file that contains the hash of each log file, and the digest files themselves are signed, enabling the security team to detect any unauthorized changes to CloudTrail configuration logs.

Exam trap

The trap here is that candidates often confuse S3 Versioning (which provides object recovery) with cryptographic integrity validation, failing to recognize that only Log File Integrity Validation provides tamper-proof verification through digital signatures and hash chains.

How to eliminate wrong answers

Option A is wrong because S3 MFA Delete requires multi-factor authentication to delete objects or suspend versioning on the bucket, but it does not provide tamper-proof verification of log file integrity after the logs are written. Option B is wrong because S3 Versioning preserves previous versions of objects, which helps recover from accidental deletion or overwrite, but it does not cryptographically verify that log files have not been altered. Option D is wrong because CloudWatch Logs log stream encryption (using AWS KMS) protects data at rest in CloudWatch Logs, but it does not apply to CloudTrail logs stored in S3 and does not provide integrity validation for the log files themselves.

365
MCQeasy

Refer to the exhibit. An AWS KMS key policy includes the statement shown. The AdminRole tries to decrypt a ciphertext that was encrypted using the same KMS key with encryption context 'department=engineering'. What will happen?

A.The decrypt operation succeeds because the role has kms:Decrypt permission.
B.The decrypt operation succeeds because the encryption context is ignored during decryption.
C.The decrypt operation fails because the policy does not allow kms:Decrypt without matching context.
D.The decrypt operation fails because the encryption context does not match the condition.
AnswerD

The key policy scopes kms:Decrypt to calls whose encryption context contains department=finance. The decrypt request supplies a different encryption context, so the kms:EncryptionContext:department condition key does not match. As a result, the condition in the key policy is false and KMS denies the Decrypt operation. This is expected behavior: encryption context conditions are a way to limit key usage to specific data or workloads.

Why this answer

The KMS key policy includes a condition that requires the encryption context to be 'department=finance' for decryption. When the AdminRole attempts to decrypt, the encryption context must match both the encryption context used during encryption and any conditions in the key policy. Since the ciphertext was encrypted with 'department=engineering', the decryption fails because the encryption context does not satisfy the policy condition, even though the role has kms:Decrypt permission.

Exam trap

The trap here is that candidates assume kms:Decrypt permission alone is sufficient for decryption, overlooking that encryption context conditions in the key policy can override the permission and cause a failure even when the IAM role has the correct action allowed.

How to eliminate wrong answers

Option A is wrong because having kms:Decrypt permission alone is insufficient; the policy also includes a condition that restricts decryption to requests with a matching encryption context. Option B is wrong because the encryption context is not ignored during decryption; AWS KMS requires the same encryption context to be provided for decryption as was used during encryption, and the policy enforces this with a condition. Option C is wrong because the policy does allow kms:Decrypt, but only when the encryption context matches; the failure is due to the context mismatch, not a lack of permission.

366
MCQeasy

A company wants to allow an external auditor to assume a read-only role in their AWS account. The auditor's AWS account ID is 123456789012. Which trust policy should be attached to the role?

A.{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::123456789012:root" }, "Action": "sts:AssumeRole", "Condition": { "Bool": { "aws:MultiFactorAuthPresent": "true" } } } ] }
B.{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::123456789012:root" }, "Action": "sts:AssumeRole" } ] }
C.{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::123456789012:user/Auditor" }, "Action": "sts:AssumeRole" } ] }
D.{ "Version": "2012-10-17", "Statement": [ { "Effect": "Deny", "Principal": { "AWS": "123456789012" }, "Action": "sts:AssumeRole" } ] }
AnswerA

This trust policy is correct because it grants the external account's root principal (arn:aws:iam::123456789012:root) permission to call sts:AssumeRole only when the aws:MultiFactorAuthPresent condition evaluates to true. This enforces that any IAM principal from that account must have authenticated with an MFA device before assuming the role, which is a security best practice for external auditors. Using the account root ARN as Principal is the standard pattern because it delegates the actual user and role management to the external account.

Why this answer

It grants the external auditor's AWS account (via its root principal ARN) permission to assume the read-only role, while enforcing multi-factor authentication (MFA) as a security best practice. The `sts:AssumeRole` action is the standard mechanism for cross-account role assumption, and the `aws:MultiFactorAuthPresent` condition ensures the auditor uses MFA, reducing the risk of compromised credentials.

Exam trap

The trap here is that candidates often overlook the MFA condition or incorrectly specify a specific user ARN, failing to recognize that the root principal ARN is the correct way to grant access to an entire external account while maintaining flexibility and security.

How to eliminate wrong answers

Option B is wrong because it lacks the MFA condition, which is a critical security control for external access; without it, the auditor could assume the role without MFA, violating the principle of least privilege and increasing risk. Option C is wrong because it specifies a specific IAM user (`user/Auditor`) rather than the entire account (`root`), which is inflexible and would require updating the policy if the auditor's username changes or if multiple auditors need access. Option D is wrong because it uses `Deny` instead of `Allow`, which would explicitly block the auditor from assuming the role, and the principal format is invalid (missing `arn:aws:iam::` prefix).

367
MCQhard

A company has a multi-account AWS environment using AWS Organizations. The security team wants to ensure that all API activity across all accounts is logged and immutable. CloudTrail is enabled in all accounts, but the logs are stored in individual account buckets. The team wants to centralize logs and prevent any account from disabling logging. What should they do?

A.Create a new CloudTrail trail for each account and configure S3 bucket policies to allow cross-account access.
B.Enable S3 MFA Delete on each account's log bucket and require MFA for IAM users.
C.Use CloudWatch Logs to aggregate logs and set a retention policy of 10 years.
D.Apply an SCP to deny cloudtrail:StopLogging and cloudtrail:DeleteTrail, and create an organization trail that delivers logs to a central S3 bucket with a bucket policy that prevents deletion.
AnswerD

Applying an SCP to the organization root or to all member accounts that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail ensures that even an IAM admin or the root user in a member account cannot disable or delete the trail. An organization trail automatically delivers CloudTrail logs from every account to a designated central S3 bucket, and the bucket policy can explicitly Deny actions such as s3:DeleteBucket, s3:DeleteBucketPolicy, and s3:DeleteObject for all principals, making the log data tamper-proof. This combination provides a centralized, immutable audit record while removing the ability of individual account administrators to interfere with logging. It directly satisfies the requirement to prevent disabling and to protect the integrity of the logs.

Why this answer

It uses an SCP to prevent disabling CloudTrail (denying cloudtrail:StopLogging and cloudtrail:DeleteTrail) and creates an organization trail that delivers logs to a central S3 bucket. The central bucket policy prevents deletion of logs, ensuring immutability and centralized logging across all accounts in the AWS Organization.

Exam trap

The trap here is that candidates often confuse S3 MFA Delete or cross-account bucket policies as sufficient for immutability and centralization, but they fail to address the core requirement of preventing accounts from disabling CloudTrail itself, which requires an SCP or organization trail.

How to eliminate wrong answers

Option A is wrong because creating separate trails per account does not centralize logs into a single location, and cross-account S3 bucket policies alone do not prevent individual accounts from disabling their own CloudTrail. Option B is wrong because enabling S3 MFA Delete on each account's log bucket only protects against accidental deletion of objects, but does not prevent an account from stopping or deleting the CloudTrail trail itself, nor does it centralize logs. Option C is wrong because CloudWatch Logs aggregation does not provide immutability; logs can be deleted or altered in CloudWatch Logs, and a retention policy of 10 years does not prevent deletion of the log group or stream.

368
MCQhard

A company is using Amazon GuardDuty to detect threats in its AWS environment. The security team notices that GuardDuty is generating a high number of 'UnauthorizedAccess:IAMUser/MaliciousIPCaller' findings for an IAM user that is used by a legacy application. The security team has verified that the IP addresses flagged are not malicious but are legitimate IPs used by the application's third-party service. The company wants to suppress these findings without disabling GuardDuty entirely. Which solution is the MOST effective and secure?

A.Disable the specific finding type in GuardDuty settings.
B.Create a GuardDuty suppression rule that automatically archives findings for that IAM user.
C.Create a VPC flow log filter to exclude traffic from those IP addresses.
D.Modify the IAM user's permissions to restrict the IP addresses it can use.
AnswerB

A suppression rule filters findings matching specified criteria, such as the IAM user's principal ID, and automatically archives them so the security team stops receiving alerts. This satisfies the requirement to suppress the false-positive findings while keeping GuardDuty fully enabled and monitoring all other activity.

Why this answer

GuardDuty suppression rules allow you to automatically archive findings that match specific criteria (such as a particular finding type and IAM user) without disabling the detector or the finding type entirely. This is the most effective and secure way to reduce noise from known-legitimate activity while preserving GuardDuty's ability to detect other threats.

Exam trap

The trap is choosing to disable the finding type or alter IAM permissions instead of using suppression rules — the exam tests whether you know suppression rules archive findings without losing detection capability.

How to eliminate wrong answers

Option A is wrong because disabling the specific finding type in GuardDuty settings would stop detection of that threat across the entire account, potentially missing real malicious IP caller findings for other users. Option C is wrong because VPC flow log filters do not affect GuardDuty findings — GuardDuty analyzes CloudTrail, VPC Flow Logs, and DNS logs independently, and filtering flow logs does not suppress findings. Option D is wrong because modifying IAM permissions to restrict IP addresses does not suppress GuardDuty findings and may break the legacy application; it also doesn't address the root cause of noise.

369
MCQhard

A security engineer is designing a solution to centrally manage security findings from multiple AWS services across an organization. The engineer needs to aggregate findings from Amazon GuardDuty, Amazon Inspector, and IAM Access Analyzer into a single view and take automated remediation actions based on severity. Which combination of AWS services should the engineer use?

A.AWS Trusted Advisor with Amazon EventBridge rules to trigger AWS Lambda for remediation.
B.AWS Security Hub with custom actions and Amazon EventBridge rules to trigger AWS Lambda for remediation.
C.Amazon CloudWatch Logs with metric filters and alarms to trigger AWS Lambda for remediation.
D.AWS Config with remediation actions and AWS Systems Manager Automation documents.
AnswerB

Security Hub aggregates findings from GuardDuty, Inspector, and IAM Access Analyzer into a single view. Custom actions allow you to define remediation steps, and EventBridge rules can trigger Lambda functions to automate remediation based on severity. This meets the requirement for centralized management and automated response.

Why this answer

AWS Security Hub is the central service that aggregates findings from GuardDuty, Inspector, IAM Access Analyzer, and other AWS services. By using Security Hub custom actions and EventBridge rules, you can automate remediation with Lambda based on severity, providing a single view and automated response.

Exam trap

The trap here is assuming that AWS Config or CloudWatch Logs can aggregate findings from multiple security services, when only Security Hub provides that centralized aggregation.

370
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to centrally collect and analyze CloudTrail logs from all accounts in a single S3 bucket. What is the most efficient way to achieve this?

A.Create a CloudTrail trail in each account and configure the same S3 bucket as the destination.
B.Use CloudWatch Logs subscription filter to send logs from each account to a central account.
C.Create a single organization trail in the management account that logs all accounts.
D.Use S3 cross-region replication to copy logs from each account's bucket to a central bucket.
AnswerC

An organization trail created in the management account automatically logs events from every member account into one S3 bucket, removing the need to configure and maintain individual trails per account. This directly satisfies the centralised collection requirement.

Why this answer

AWS Organizations supports creating a single organization trail in the management account that automatically logs CloudTrail events for all accounts in the organization. This centralizes log collection into one S3 bucket without needing to configure trails per account, making it the most efficient and scalable approach for multi-account environments.

Exam trap

The trap here is that candidates often assume each account must have its own trail (Option A) or that a streaming solution like CloudWatch Logs (Option B) is required, overlooking the native organization-level trail feature that simplifies centralization.

How to eliminate wrong answers

Option A is wrong because creating a trail in each account and pointing to the same S3 bucket requires manual setup per account, does not scale efficiently, and can lead to permission conflicts or log overwrites if bucket policies are not correctly configured. Option B is wrong because CloudWatch Logs subscription filters are designed to stream log data to a central account for real-time processing, but they are not the most efficient way to collect CloudTrail logs for long-term storage in S3; they add complexity and cost for a task that organization trails handle natively. Option D is wrong because S3 cross-region replication copies objects between buckets in different regions, but it does not centralize logs from multiple accounts into a single bucket; it requires each account to have its own bucket and replication rules, adding overhead and potential for configuration errors.

371
MCQeasy

A security engineer needs to monitor AWS account activity for suspicious API calls and receive alerts. Which AWS service should the engineer use to meet this requirement?

A.VPC Flow Logs
B.AWS Config with AWS Config Rules
C.AWS CloudTrail with CloudWatch Alarms
D.Amazon GuardDuty
AnswerC

AWS CloudTrail is the authoritative service for recording API activity: it captures every management and data event with details such as the event name, IAM user or role that made the call, source IP address, request parameters, and response elements. When you send those CloudTrail events to CloudWatch Logs via a trail, you can define a metric filter on a specific pattern — such as eventName for a sensitive action or an errorCode indicating failed access — and attach a CloudWatch Alarm to trigger an SNS notification. That pipeline gives a deterministic, near-real-time alert for account activity, which is exactly what the security engineer needs.

Why this answer

AWS CloudTrail records all API calls made to the AWS environment, providing a detailed audit trail of account activity. By sending these logs to Amazon CloudWatch, you can create metric filters that match suspicious API call patterns and trigger CloudWatch Alarms to send notifications via SNS. This combination directly meets the requirement to monitor and alert on specific API calls.

Exam trap

The trap here is that candidates confuse GuardDuty's threat detection with the ability to monitor and alert on specific API calls, but GuardDuty does not provide customizable metric filters or alarms for arbitrary API patterns; CloudTrail with CloudWatch Alarms is the correct service for that precise requirement.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol) at the network interface level, not API-level activity; they cannot monitor or alert on specific AWS API calls. Option B is wrong because AWS Config with Config Rules evaluates resource configuration compliance against desired states (e.g., checking if S3 buckets are public), not API call activity; it does not record or alert on individual API operations. Option D is wrong because Amazon GuardDuty uses threat intelligence and machine learning to detect anomalous behavior and potential threats (e.g., compromised credentials, crypto-mining), but it does not provide a direct, customizable alerting mechanism for specific API calls; it focuses on broader threat detection rather than monitoring defined API call patterns.

372
Multi-Selecthard

A company uses Amazon GuardDuty and has enabled EKS audit logs as a data source. The security team wants to detect potential container escape attempts. Which TWO findings would indicate a container escape attempt? (Choose TWO.)

Select 2 answers
A.Execution:ECS/SuspiciousCommand
B.UnauthorizedAccess:EC2/SSHBruteForce
C.CryptoCurrency:EC2/BitcoinTool.B
D.PrivilegeEscalation:EKS/KubernetesAPICallFromContainer
E.Persistence:EKS/ContainerWithSensitiveMount
AnswersD, E

PrivilegeEscalation:EKS/KubernetesAPICallFromContainer is correct because GuardDuty specifically samples Kubernetes audit logs and correlates the source IP and user agent to identify when a container makes API calls to the Kubernetes control plane. A container that calls sensitive APIs, such as creating privileged pods, binding cluster roles, or listing secrets, may be attempting to escalate privileges and potentially escape the container runtime. Since this finding directly matches the suspicious API activity from a container using EKS audit logs, it is the most appropriate detection for a container escape.

Why this answer

The PrivilegeEscalation:EKS/KubernetesAPICallFromContainer finding specifically detects when a container makes Kubernetes API calls that indicate an attempt to escalate privileges, such as creating pods with elevated permissions or accessing cluster-admin roles. This is a direct indicator of a container escape attempt, as the container is interacting with the Kubernetes control plane to gain unauthorized access to the host or other resources.

Exam trap

The trap here is that candidates may confuse ECS-specific findings (like SuspiciousCommand) with EKS findings, or mistake general EC2 threats (like SSH brute force or crypto mining) as indicators of container escape, when only findings directly tied to Kubernetes API calls or sensitive mounts are relevant.

373
Multi-Selecthard

A company is designing a data protection strategy for Amazon EFS file systems. The security team requires encryption at rest and in transit. Additionally, the team needs to control which KMS keys can be used to encrypt the file system. Which THREE steps should the team take?

Select 3 answers
A.Configure a KMS key policy that allows the EFS service to use the key.
B.Enable encryption at rest using a customer-managed KMS key when creating the EFS file system.
C.Enable default encryption on the EFS file system using SSE-S3.
D.Use an IAM policy to restrict which users can create encrypted file systems.
E.Enable encryption of data in transit using the mount helper's tls option on the client.
AnswersA, B, E

The KMS key policy acts as the resource-based authorization for the key and must explicitly grant the Amazon EFS service principal (elasticfilesystem.amazonaws.com) the kms:GenerateDataKeyWithoutPlaintext, kms:Decrypt, and kms:DescribeKey permissions. Without these grants in the key policy, EFS cannot create or use data keys to encrypt or decrypt the file system, even if the IAM principal has full EFS permissions. This is a mandatory, non-optional part of enabling EFS encryption at rest — the key policy is the authoritative control over which AWS services may use the CMK. Therefore, configuring the key policy correctly is a required action, not merely a best practice.

Why this answer

Option A is correct because the KMS key policy must explicitly grant the EFS service principal (elasticfilesystem.amazonaws.com) permission to use the customer-managed key for cryptographic operations; without this, EFS cannot use the key to encrypt or decrypt file data. Option B is correct because encryption at rest on EFS is enabled at file-system creation time by specifying a customer-managed KMS key, which is exactly how the team controls which key protects the file system. Option E is correct because EFS encryption in transit is achieved by mounting with the TLS option via the EFS mount helper (for example, using -o tls with amazon-efs-utils), which enforces TLS 1.2 for NFS traffic.

Option C is wrong because EFS does not support SSE-S3; that is an Amazon S3 server-side encryption option, and EFS uses KMS keys instead. Option D is wrong because an IAM policy restricting who can create encrypted file systems does not itself enable encryption at rest or in transit, nor does it control which KMS keys are used for a given file system.

Exam trap

The trap is confusing EFS encryption with S3 SSE-S3 or thinking IAM policies can control KMS key usage; EFS uses KMS and requires key policy configuration.

374
MCQeasy

A company is using an Application Load Balancer (ALB) to distribute traffic to a set of EC2 instances in private subnets. The security team wants to ensure that only traffic from the ALB can reach the EC2 instances. Which security group configuration should be applied to the EC2 instances?

A.Allow inbound HTTP/HTTPS from the security group attached to the ALB.
B.Configure the network ACL to allow traffic from the ALB's private IP addresses.
C.Allow inbound HTTP/HTTPS from 0.0.0.0/0.
D.Allow inbound HTTP/HTTPS from the VPC CIDR block.
AnswerA

Referencing the ALB's security group as the source is a security group-to-security group rule: it dynamically matches any IP address associated with an elastic network interface that belongs to that ALB security group. This means EC2 instances behind the ALB accept traffic only from the ALB's ENIs, even as the ALB scales and its private IPs change. The rule is stateful, so return traffic flows automatically, and no internet CIDR is ever exposed. This is the AWS-recommended pattern for placing an ALB in front of a web tier.

Why this answer

Referencing the security group of the Application Load Balancer as the source in the inbound rule ensures that only traffic coming from the ALB can reach the EC2 instances. Option B is incorrect because network ACLs are stateless and cannot reference security groups; they also operate at the subnet level, not at the instance level. Option C is incorrect because allowing traffic from 0.0.0.0/0 would expose the instances to the internet.

Option D is incorrect because allowing traffic from the VPC CIDR would permit any instance in the VPC to access the EC2 instances, not just the ALB.

375
Multi-Selecteasy

Which TWO are IAM best practices? (Choose two.)

Select 2 answers
A.Avoid using IAM roles and instead attach policies directly to users.
B.Use the root user for everyday administrative tasks.
C.Grant broad permissions to all users to simplify management.
D.Use conditions in IAM policies to restrict access based on tags or IP addresses.
E.Use IAM roles for applications that run on EC2 instances.
AnswersD, E

IAM policy conditions allow you to add context-aware requirements to an allow statement, such as restricting the source IP with 'aws:SourceIp', requiring an MFA token with 'aws:MultiFactorAuthPresent', or limiting EC2 actions based on resource tags with 'ec2:ResourceTag'. This goes beyond identity alone by enforcing that the request also looks like it comes from a trusted network or satisfies other organizational controls. Conditions are a core defense against stolen credentials and are essential for implementing least privilege in real-world environments where access should depend on more than just who is calling.

Why this answer

Using conditions in IAM policies (e.g., `aws:SourceIp`, `aws:RequestTag`) allows you to enforce fine-grained access control based on contextual attributes like IP addresses or resource tags. This follows the principle of least privilege by restricting permissions to only the necessary scope, reducing the attack surface. For example, you can deny access to S3 buckets unless the request originates from a corporate IP range.

Exam trap

The trap here is that candidates often confuse IAM roles with IAM users, mistakenly thinking roles are only for cross-account access, when in fact roles are the recommended mechanism for granting permissions to AWS services like EC2, Lambda, and ECS.

Page 4

Page 5 of 17

Page 6