Courseiva

AWS Certified Security Specialty SCS-C02 (SCS-C02) — Questions 376–450

1205 questions total · 17pages · All types, answers revealed

Page 5

Page 6 of 17

Page 7
376
MCQhard

A company has a requirement that all access keys for IAM users must be rotated every 90 days. A security engineer needs to implement an automated solution to identify and disable keys that are older than 90 days. Which approach meets the requirement with the least operational overhead?

A.Use AWS Trusted Advisor to check key age and send notifications.
B.Use AWS CloudTrail to monitor CreateAccessKey events and trigger a Lambda function to check key age.
C.Use IAM Access Analyzer to generate findings for unused keys and manually disable them.
D.Use an AWS Config rule with auto-remediation to disable keys older than 90 days.
AnswerD

AWS Config continuously evaluates keys against a custom rule and auto-remediation invokes a remediation action to disable non-compliant keys, removing manual checks. This satisfies the 90-day rotation requirement with least operational overhead, since detection and disabling happen automatically without custom scheduling infrastructure.

Why this answer

AWS Config can evaluate IAM access key age against a desired rule (e.g., 'iam-access-key-rotated') and trigger automatic remediation using SSM Automation documents to disable keys older than 90 days. This provides a fully automated, low-overhead solution that continuously enforces the requirement without manual intervention.

Exam trap

The trap is selecting a monitoring or notification service (Trusted Advisor, CloudTrail, Access Analyzer) instead of an enforcement service (Config with auto-remediation) when the requirement explicitly asks for automated disabling with least operational overhead.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor only provides notifications and does not automatically disable keys, requiring manual action and thus higher operational overhead. Option B is wrong because CloudTrail logs CreateAccessKey events but does not natively evaluate key age; building a custom Lambda solution adds development and maintenance overhead. Option C is wrong because IAM Access Analyzer identifies unused permissions and generates findings, but it does not automatically disable keys and still requires manual remediation.

377
MCQmedium

A company wants to allow users from its corporate Active Directory to access AWS resources. The company has set up an IAM identity provider for SAML. What must be created in IAM to map users to permissions?

A.An IAM role with a trust policy for the SAML provider
B.An OIDC identity provider
C.An IAM user for each Active Directory user
D.A federation role type
AnswerA

For SAML federation, the correct pattern is an IAM role with a trust policy that grants sts:AssumeRoleWithSAML to the SAML identity provider you create in IAM. The corporate Active Directory is the external IdP (for example, AD FS or Shibboleth), and the trust policy uses the IAM SAML provider's ARN as the principal, often with an audience condition of urn:amazon:webservices. When a user authenticates to AD, the IdP issues a SAML assertion, AWS validates it against the SAML provider, and the user receives temporary credentials scoped by that role's permissions. This achieves single sign-on without creating or maintaining AWS credentials for each AD user.

Why this answer

A is correct because when using SAML-based federation, IAM roles are the mechanism to grant permissions to federated users. The role must have a trust policy that specifies the SAML identity provider as the principal, allowing users authenticated by the corporate Active Directory to assume the role and obtain temporary AWS credentials. This maps the SAML assertion attributes (such as the user's group or role) to IAM permissions via the role's permissions policy.

Exam trap

The trap here is that candidates confuse the IAM role trust policy with the SAML identity provider configuration itself, thinking the provider alone grants permissions, rather than understanding that the role bridges the SAML assertion to AWS permissions.

How to eliminate wrong answers

Option B is wrong because OIDC (OpenID Connect) is a separate identity federation protocol used for web identity providers like Google or Amazon Cognito, not for SAML-based Active Directory federation. Option C is wrong because creating an IAM user for each Active Directory user defeats the purpose of federation—it would require managing duplicate identities and credentials outside the corporate directory. Option D is wrong because 'federation role type' is not a valid IAM entity; IAM roles are categorized by trust policy type (e.g., service role, cross-account role, or identity provider role), but there is no distinct 'federation role type' in the AWS API or console.

378
MCQhard

Refer to the exhibit. After invoking the Lambda function, why are there no log streams in the log group?

A.The CloudWatch Logs log group retention policy is set to 0 days.
B.The Lambda function is not configured with a CloudWatch Logs log group.
C.The Lambda function timed out before writing logs.
D.The Lambda function's execution role lacks permissions to write to CloudWatch Logs.
AnswerD

To stream logs, Lambda's execution role must have IAM permissions for logs:CreateLogStream and logs:PutLogEvents on the target log group. Even when the log group exists, a restrictive or missing execution role policy prevents the log stream from being created, so no logs appear. Because no log streams exist despite the log group being present, the most plausible root cause is that the role lacks the necessary CloudWatch Logs permissions.

Why this answer

Lambda writes logs to CloudWatch Logs using the permissions granted to its execution role. If that role lacks the required actions (logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents), the function still executes but the log writes are silently denied, so no log streams appear in the log group. This is the classic cause of an empty log group after a successful invocation.

Exam trap

SCS-C02 often tests the misconception that Lambda needs a pre-created log group or that timeouts/retention settings suppress log delivery, when the real culprit in an empty log group is almost always missing CloudWatch Logs permissions on the execution role.

How to eliminate wrong answers

Option A is wrong because a retention policy of 0 days is not a valid CloudWatch Logs setting — retention values are 1 day, 3, 5, 7, 14, 30, 60, 90, 120, 150, 180, 365, 400, 545, 731, 1096, 1827, 2192, 2557, 2922, 3288, 3653, or 'Never expire'; retention only deletes old events, it never prevents new log streams from being created. Option B is wrong because Lambda does not require you to pre-configure a log group — if the execution role has the proper permissions, Lambda automatically creates the /aws/lambda/<function-name> log group on first invocation. Option C is wrong because a timeout does not suppress log delivery; Lambda flushes buffered logs even when a function times out, and a timeout would still produce a log stream with a START, END, and Report line.

379
Multi-Selecthard

A security engineer is designing a network architecture in AWS. The engineer needs to ensure that all outbound traffic from a VPC goes through a centrally managed NAT device for logging and filtering. The VPC has multiple private subnets. Which TWO steps are required to accomplish this? (Choose TWO.)

Select 2 answers
A.Deploy an HTTP forward proxy in the public subnet.
B.Create a route table for the private subnets with a default route (0.0.0.0/0) pointing to the NAT device.
C.Set up a transit gateway and attach the VPC to it.
D.Create a gateway endpoint for Amazon S3.
E.Place the NAT device in a public subnet with a route to an internet gateway.
AnswersB, E

Private subnets lack a route to the internet, so their route tables must direct 0.0.0.0/0 to the central NAT device's elastic network interface. This satisfies the requirement that all outbound traffic traverses the NAT for logging and filtering.

Why this answer

Option B is correct because the private subnets' route table must have a default route (0.0.0.0/0) whose target is the central NAT device (e.g., a NAT instance or NAT Gateway), which forces all outbound traffic to be sent to that device for logging and filtering instead of going directly to an internet gateway. Option E is correct because the NAT device itself must reside in a public subnet and have a route to an internet gateway so it can forward the private subnets' traffic to the internet while performing the required logging and filtering. Option A is not required because an HTTP forward proxy is an application-layer solution and is not the mechanism that routes VPC subnet traffic to a NAT device; the question asks for the routing/placement steps.

Option C is unnecessary because a transit gateway is used to interconnect VPCs or on-premises networks, not to route a single VPC's outbound traffic through a NAT device. Option D is incorrect because a gateway endpoint for Amazon S3 only provides private access to S3 and does not handle general outbound internet traffic through a NAT device.

Exam trap

SCS-C02 often tests the confusion between a NAT gateway (which requires a public subnet and IGW route) and a transit gateway or VPC endpoint, tricking candidates into selecting connectivity services that do not provide NAT.

380
MCQhard

A company uses AWS CloudHSM to generate and store encryption keys for a custom application. The application runs on Amazon EC2 instances and uses the PKCS#11 interface to interact with the HSM. The security team recently discovered that a former employee may have obtained a copy of the cryptographic materials from the HSM. What should the security team do to minimize the impact?

A.Use AWS KMS to create a new key and re-encrypt all data. Then revoke the old key.
B.Delete the CloudHSM backup from the backup service. Then rotate all keys that were stored in the HSM.
C.Change the HSM administrator password and the crypto user passwords.
D.Delete the HSM cluster and create a new one. Restore the backup from a known good time.
AnswerB

Deleting the CloudHSM backup from the backup service ensures that the copied encrypted key material that was exfiltrated cannot be restored to a new or existing HSM, eliminating the attacker's ability to recover the keys. After that, rotating every key that was stored in the HSM—generating new keys and re-encrypting data with them—renders any previously copied key material useless because the data is now protected by fresh keys. This two-step approach directly addresses both ways the compromise can be exploited: backup restoration and continued use of the old key material.

Why this answer

Deleting the CloudHSM backup prevents the former employee from restoring the HSM's contents from a backup. Rotating all keys ensures that any keys the employee may have copied are no longer valid for encrypting/decrypting data, minimizing the impact of the exposure. Option A is incorrect because AWS KMS cannot manage keys stored in CloudHSM.

Option C is incorrect because changing passwords does not invalidate cryptographic material that has already been copied. Option D is incorrect because deleting the HSM cluster alone does not delete the backup, and restoring from an old backup may reintroduce the compromised keys.

381
MCQmedium

A company has an Amazon S3 bucket that stores sensitive data. The security team wants to ensure that all access to the bucket is made only via HTTPS. Which policy should be used?

A.Enable CloudFront with HTTPS-only viewer protocol policy.
B.Use a VPC endpoint for S3 with a bucket policy that restricts access to the VPC endpoint.
C.Enable 'Block public access' on the bucket.
D.Add a bucket policy that denies access when aws:SecureTransport is false.
AnswerD

A bucket policy that explicitly denies requests when aws:SecureTransport equals false is correct because aws:SecureTransport is a global IAM condition key that is true for HTTPS and false for HTTP. Using a Bool condition with a Deny effect overrides any other allow statement in the policy, so every S3 operation, including from authorized IAM principals, must arrive over TLS. This is the standard way to enforce HTTPS at the S3 API level, and it cannot be bypassed by accessing the bucket directly.

Why this answer

The condition `aws:SecureTransport` evaluates to `false` when the request is made over HTTP instead of HTTPS. By adding a bucket policy that denies all S3 actions when `aws:SecureTransport` is `false`, the company enforces HTTPS-only access at the policy level, regardless of how the request originates.

Exam trap

The trap here is that candidates often confuse network-level controls (like VPC endpoints or CloudFront) with transport-level encryption enforcement, mistakenly thinking they guarantee HTTPS when they only control the network path or the viewer-to-edge segment.

How to eliminate wrong answers

Option A is wrong because enabling CloudFront with an HTTPS-only viewer protocol policy only enforces HTTPS between viewers and CloudFront, not between CloudFront and the S3 origin; the S3 bucket itself could still be accessed directly via HTTP. Option B is wrong because a VPC endpoint for S3 with a bucket policy restricting access to the VPC endpoint controls network path but does not enforce HTTPS; requests over the VPC endpoint can still use HTTP. Option C is wrong because enabling 'Block public access' prevents public access but does not enforce HTTPS; authenticated users or applications could still make HTTP requests.

382
Multi-Selecthard

A company needs to enforce that all Amazon S3 buckets are encrypted at rest. Which TWO actions should be taken? (Choose two.)

Select 2 answers
A.Enable AWS CloudTrail to log S3 API calls.
B.Use bucket policies to deny write operations without encryption.
C.Enable default encryption on each S3 bucket.
D.Create a KMS key and apply it to all buckets.
E.Use a service control policy (SCP) to deny the s3:PutBucketPublicAccessBlock action.
AnswersB, C

Bucket policies that deny s3:PutObject unless the request includes encryption headers block unencrypted uploads at the authorisation layer, enforcing encryption at rest for every write. This satisfies the requirement to prevent plaintext objects from being stored.

Why this answer

Option B is correct because a bucket policy with a Deny effect on s3:PutObject when the request lacks the s3:x-amz-server-side-encryption header (or uses an unapproved algorithm) actively blocks unencrypted uploads, enforcing encryption at rest at the object level. Option C is correct because enabling default encryption (SSE-S3 or SSE-KMS) on each bucket ensures any object PUT without explicit encryption headers is automatically encrypted at rest. Option A is incorrect because CloudTrail only records API activity for auditing; it does not enforce encryption.

Option D is incorrect because creating a KMS key alone does not apply it to buckets or enforce encryption; the key must be referenced in bucket policies or default encryption settings. Option E is incorrect because denying s3:PutBucketPublicAccessBlock addresses public access blocking, not encryption at rest.

Exam trap

Candidates often mistake SCPs or public access blocking as mechanisms to enforce encryption at rest. However, only default encryption and bucket policies with condition keys like s3:x-amz-server-side-encryption directly enforce encryption at rest.

383
MCQeasy

A security team wants to receive real-time notifications when an IAM user makes a change to a security group. Which AWS service should be used to trigger the notification?

A.AWS Config
B.AWS CloudTrail with Amazon CloudWatch Events
C.Amazon S3 event notifications
D.Amazon GuardDuty
AnswerB

AWS CloudTrail captures all supported API calls as events, and CloudWatch Events (or EventBridge) can filter those events by service, action, and other fields using event patterns. Once matched, a rule can immediately invoke a Lambda function, SNS topic, or SQS queue to deliver the notification. This combination provides near-real-time alerting on specific API calls, which is exactly what the security team needs.

Why this answer

AWS CloudTrail captures API calls made by IAM users, including changes to security groups (e.g., AuthorizeSecurityGroupIngress, RevokeSecurityGroupEgress). By sending these CloudTrail events to Amazon CloudWatch Events (now part of Amazon EventBridge), you can create a rule that matches specific API calls and triggers a notification via SNS, Lambda, or other targets in real time.

Exam trap

The trap here is that candidates often confuse AWS Config's compliance evaluation (which can detect drift but not real-time API calls) with CloudTrail's event-driven notification capability, or they mistakenly think S3 event notifications can be applied to EC2 resources.

How to eliminate wrong answers

Option A is wrong because AWS Config is a configuration auditing and compliance service that evaluates resource configurations against rules, but it does not provide real-time event-driven notifications for API calls; it operates on a periodic or configuration-change detection basis, not on the exact moment an IAM user makes a change. Option C is wrong because Amazon S3 event notifications are designed for object-level events in S3 buckets (e.g., PUT, POST, DELETE), not for IAM user actions on security groups in EC2. Option D is wrong because Amazon GuardDuty is a threat detection service that analyzes logs (e.g., VPC Flow Logs, DNS logs) for malicious activity, but it does not trigger notifications for routine IAM user changes to security groups.

384
MCQhard

A security engineer is using Amazon GuardDuty in a multi-account environment managed by AWS Organizations. The engineer wants to ensure that GuardDuty findings from all member accounts are centrally visible and that new accounts are automatically enrolled. What should the engineer do?

A.Create an Amazon EventBridge rule in each account that forwards GuardDuty findings to a central event bus.
B.Enable GuardDuty in each member account and configure each account to publish findings to a central SNS topic.
C.Designate a delegated administrator for GuardDuty in the organization and enable GuardDuty for all accounts.
D.Use AWS Security Hub to aggregate GuardDuty findings from all accounts.
AnswerC

Designating a delegated administrator allows a member account to manage GuardDuty for the entire organization. The administrator can enable GuardDuty for all existing and new accounts automatically. Findings from all accounts are aggregated in the delegated administrator account, providing central visibility. This is the recommended approach for multi-account GuardDuty management.

Why this answer

Designating a delegated administrator for GuardDuty in AWS Organizations allows centralized management, automatic enrollment of new accounts, and aggregation of findings. This is the most efficient and recommended method for multi-account GuardDuty deployment. Other options require manual configuration and do not provide automatic enrollment or central visibility.

Exam trap

The trap here is assuming that Security Hub or EventBridge can manage GuardDuty enrollment, when only the delegated administrator feature provides automatic enablement and central management.

385
MCQhard

A company uses Amazon SQS to decouple its microservices. The messages contain personally identifiable information (PII). The security team requires that all messages be encrypted at rest. Currently, SQS is configured with SSE enabled using a customer managed KMS key. However, the team discovers that some messages are still being stored in plaintext in the dead-letter queue (DLQ) after the maximum receives are exceeded. The DLQ is also an SQS queue. What is the MOST likely reason?

A.The source queue's SSE is configured with AWS managed KMS key, which does not support cross-account DLQ.
B.The DLQ does not have SSE enabled, so messages are stored in plaintext.
C.The source queue's SSE configuration uses a different KMS key than the DLQ, causing decryption failure.
D.The KMS key policy does not allow the SQS service to decrypt the messages before moving them to the DLQ.
AnswerB

This is correct. SSE is a per-queue setting, so enabling it on the source queue does not automatically protect the DLQ. When a message is redriven, SQS decrypts it from the source queue and writes it to the DLQ using whatever encryption the DLQ has configured. If the DLQ has no SSE, the message is stored as plaintext, directly violating the company's requirement that messages be encrypted at rest.

Why this answer

SSE is configured per queue, not inherited. Enabling SSE with a customer-managed KMS key on the source queue does not automatically encrypt the DLQ; if the DLQ was created without SSE, messages moved there are stored using SQS's default (no encryption at rest) behavior, exposing the PII in plaintext. Each SQS queue, including a DLQ, must have its own encryption configuration.

Exam trap

The trap is assuming encryption settings propagate from a source queue to its DLQ; in SQS, SSE is per-queue, so the DLQ must be encrypted separately.

How to eliminate wrong answers

Option A is wrong because AWS managed keys (aws/sqs) do support DLQs, including cross-account DLQs when the key policy and queue policy permit it; the encryption type is not the cause of plaintext storage. Option C is wrong because using different KMS keys on source and DLQ does not cause decryption failure — SQS decrypts on receive and re-encrypts on send, so the DLQ simply uses its own key; a mismatch does not produce plaintext. Option D is wrong because the KMS key policy governs who can use the key, not whether SQS stores messages encrypted; if the key policy blocked SQS, message delivery would fail with an error rather than silently store plaintext.

386
MCQeasy

A company wants to enforce that all IAM users use multi-factor authentication (MFA) to access the AWS Management Console. Which AWS service can be used to enforce this requirement?

A.AWS Organizations
B.AWS Config
C.AWS Identity and Access Management (IAM)
D.Amazon Cognito
AnswerC

AWS Identity and Access Management (IAM) is correct because MFA enforcement is implemented with an identity-based policy that uses the global condition key aws:MultiFactorAuthPresent. You attach a Deny statement with "BoolIfExists": {"aws:MultiFactorAuthPresent": "false"} to a user or group, which blocks every API action unless the principal signed in with a valid MFA token. This makes MFA a native part of IAM's authentication and authorization flow, directly satisfying the company's requirement for all IAM users.

Why this answer

AWS IAM allows you to create a policy with a condition that requires MFA for console access. Option A is wrong because AWS Organizations is used to manage multiple accounts, not to enforce MFA on individual users. Option B is wrong because AWS Config can check compliance but cannot enforce the requirement; it only evaluates resource configurations.

Option D is wrong because Amazon Cognito is used for external identity federation, not for enforcing MFA on IAM users.

387
MCQeasy

A company uses Amazon GuardDuty to detect threats. The security team wants to be alerted when GuardDuty generates a finding with a severity level of HIGH or CRITICAL. Which AWS service should the team use to send notifications based on GuardDuty findings?

A.Amazon Simple Queue Service (SQS)
B.Amazon EventBridge and Amazon Simple Notification Service (SNS)
C.AWS Lambda
D.Amazon CloudWatch Logs and Amazon Simple Notification Service (SNS)
AnswerB

Amazon EventBridge and Amazon Simple Notification Service (SNS) form the canonical real-time alerting pattern for GuardDuty. GuardDuty automatically publishes every finding to the default EventBridge bus, and a rule can filter on fields like severity, finding type, or affected resource before targeting an SNS topic. SNS then fans out the notification to email, SMS, HTTP/S endpoints, or mobile push, ensuring security analysts are immediately notified without custom code or polling. This native integration is the recommended and fully managed approach.

Why this answer

Amazon EventBridge can capture GuardDuty findings as events using a rule that matches the 'GuardDuty Finding' event type. The rule can then invoke an SNS topic to send email or SMS notifications. This is the recommended pattern because EventBridge provides native integration with GuardDuty and supports filtering by finding severity using event patterns, while SNS handles the actual notification delivery.

Exam trap

The trap here is that candidates often assume GuardDuty findings go directly to CloudWatch Logs or that Lambda is required for filtering, but the native integration with EventBridge eliminates the need for custom processing or intermediate services.

How to eliminate wrong answers

Option A is wrong because Amazon SQS is a message queue service for decoupling application components, not for sending notifications; it would require a separate consumer to poll and send alerts. Option C is wrong because AWS Lambda alone cannot send notifications; it would need to invoke SNS or another service, making it an unnecessary intermediate step when EventBridge can directly route to SNS. Option D is wrong because GuardDuty findings are not automatically sent to CloudWatch Logs; GuardDuty publishes events to EventBridge, not to CloudWatch Logs, so this option introduces an incorrect data flow.

388
Matchingmedium

Match each AWS security control to its category.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Stateful firewall at instance level

Stateless firewall at subnet level

Centralized management of firewall rules

Managed firewall for VPCs

Why these pairings

Security Groups are stateful instance-level firewalls, Network ACLs are stateless subnet-level firewalls. Common confusions involve mixing statefulness and level of operation.

389
Multi-Selecthard

A company has a VPC with public and private subnets. An EC2 instance in a private subnet needs to download patches from the internet. Which combination of components provides a highly available, managed solution? (Select TWO.)

Select 2 answers
A.Add a route to the private subnet's route table pointing 0.0.0.0/0 to the NAT gateway.
B.Launch a NAT instance in a public subnet.
C.Create a VPC endpoint for Amazon S3.
D.Create a NAT gateway in each Availability Zone.
E.Attach an internet gateway to the VPC.
AnswersA, D

Adding a route to the private subnet's route table with destination 0.0.0.0/0 and target the NAT gateway is the precise mechanism that enables outbound internet access from private instances. The NAT gateway itself resides in a public subnet and relies on its own route to the internet gateway, but private subnets require this explicit route to direct traffic to the NAT gateway. Without this route, private instances have no path to the internet, making this the correct action to satisfy the requirement.

Why this answer

A NAT gateway enables outbound internet access for instances in a private subnet while preventing inbound connections from the internet. It is a managed AWS service that automatically scales and is highly available within a single Availability Zone. By adding a route for 0.0.0.0/0 to the NAT gateway in the private subnet's route table, traffic destined for the internet is forwarded to the NAT gateway, which then uses an internet gateway to reach the internet.

Exam trap

The trap here is that candidates often think a single NAT gateway is sufficient for high availability, but AWS requires one NAT gateway per Availability Zone to survive an AZ failure, and they may also confuse a VPC endpoint for S3 as a general internet access solution.

390
MCQhard

A security engineer is configuring Amazon GuardDuty in a multi-account environment using AWS Organizations. The engineer wants to ensure that all member accounts send findings to the delegated administrator account. However, some member accounts are not sending findings. What is the most likely cause?

A.The GuardDuty service-linked role is missing in the member accounts.
B.AWS CloudTrail is not enabled in the member accounts.
C.GuardDuty is not enabled in the member accounts, or they have not accepted the invitation.
D.VPC Flow Logs are not enabled in the member accounts.
AnswerC

In a GuardDuty multi-account setup, the administrator account sends invitations to member accounts. Each member account must explicitly enable GuardDuty and accept the invitation before it can begin sending findings to the administrator. If a member account has not enabled GuardDuty or has not accepted the invitation, no findings are received from that account. This is the most common reason for missing findings in the administrator console.

Why this answer

GuardDuty requires that each member account has the service explicitly enabled and has accepted the invitation from the delegated administrator account. Without these steps, the member accounts cannot send findings to the administrator, even if AWS Organizations is configured correctly. The delegated administrator can only manage findings from accounts that have completed the onboarding process.

Exam trap

The trap here is that candidates often assume that enabling GuardDuty via AWS Organizations automatically activates it in all member accounts and forwards findings, but in reality, each member account must either accept the invitation or be explicitly enabled by the delegated administrator using the appropriate API call.

How to eliminate wrong answers

Option A is wrong because the GuardDuty service-linked role (AWSServiceRoleForAmazonGuardDuty) is automatically created when GuardDuty is enabled in an account; its absence is a symptom of GuardDuty not being enabled, not a separate cause. Option B is wrong because AWS CloudTrail is a data source for GuardDuty but is not required for findings to be sent; GuardDuty can still generate findings from VPC Flow Logs and DNS logs even if CloudTrail is disabled. Option D is wrong because VPC Flow Logs are another optional data source; GuardDuty can still send findings based on other threat detection feeds without VPC Flow Logs being enabled.

391
MCQmedium

A security engineer is investigating an AWS CloudTrail log entry that shows an unauthorized API call to delete an S3 bucket. Which service should the engineer use to analyze the log data for patterns of similar malicious activity?

A.AWS Config
B.Amazon CloudWatch Logs Insights
C.AWS Artifact
D.Amazon GuardDuty
AnswerB

Amazon CloudWatch Logs Insights is a log query and analysis engine, not a purpose-built threat detection service. While it can search CloudTrail logs if they are streamed to Amazon CloudWatch Logs, it lacks GuardDuty's machine-learning models, anomaly detection, and integrated threat intelligence to automatically identify suspicious API activity. It requires you to manually craft queries based on prior knowledge of attack patterns, making it a reactive tool rather than a proactive detector of malicious behavior.

Why this answer

Amazon CloudWatch Logs Insights is the service designed for interactively querying and analyzing log data stored in CloudWatch Logs. In this scenario, the security engineer already has a CloudTrail log entry and needs to search through the logs for patterns of similar malicious activity. CloudWatch Logs Insights allows running queries to identify such patterns.

Amazon GuardDuty is a threat detection service that automatically monitors for malicious activity, but it does not provide a means for the engineer to directly analyze log data; it generates findings based on its own analysis.

Exam trap

The trap is that candidates may choose GuardDuty because it is a threat detection service, but the question specifically asks for a service the engineer should use to analyze log data. That is a manual query task, which CloudWatch Logs Insights handles, not GuardDuty.

How to eliminate wrong answers

Option A is wrong because AWS Config is a service for evaluating resource configurations and compliance against rules, not for analyzing CloudTrail log patterns for malicious activity; it lacks threat detection capabilities. Option B is wrong because Amazon CloudWatch Logs Insights is a query tool for searching and analyzing log data, but it does not provide automated threat detection or pattern recognition for malicious activity; it requires manual querying and lacks built-in threat intelligence. Option C is wrong because AWS Artifact is a self-service portal for downloading AWS compliance reports and agreements, with no capability to analyze CloudTrail logs or detect unauthorized activity.

392
MCQmedium

A security engineer is reviewing AWS CloudTrail logs and finds that an IAM user 'developer1' deleted an S3 bucket. The engineer needs to determine the source IP address of the delete operation. Which field in the CloudTrail log record contains this information?

A.userIdentity
B.requestParameters
C.eventTime
D.sourceIPAddress
AnswerD

sourceIPAddress is the dedicated top-level field in CloudTrail log events that holds the IP address from which the API call was made. This is the exact field a security engineer should examine to identify the origin of a request, whether it comes from a user's public IP, a NAT gateway address, or an AWS service's internal IP. For console-session actions, CloudTrail populates this field with the IP of the user's browser, making it the authoritative source for network origin in log review.

Why this answer

The `sourceIPAddress` field in a CloudTrail log record captures the IP address from which the API call was made. For S3 bucket deletion via the AWS Management Console, AWS CLI, or SDK, this field records the originating IP address, enabling the security engineer to trace the delete operation back to its source.

Exam trap

The trap here is that candidates may confuse `sourceIPAddress` with `userIdentity` or `requestParameters`, mistakenly thinking the IP address is embedded in the user details or request payload, when in fact it is a separate top-level field in the CloudTrail log record.

How to eliminate wrong answers

Option A is wrong because `userIdentity` contains details about the IAM user or role that made the request (e.g., ARN, type, access key ID), not the network source IP. Option B is wrong because `requestParameters` includes the bucket name and other parameters sent in the API call (e.g., `bucketName`), but not the IP address. Option C is wrong because `eventTime` records the timestamp of the API call (in UTC), which is useful for chronology but does not contain IP address information.

393
MCQmedium

A security engineer needs to monitor for unusual outbound network traffic from an EC2 instance. Which AWS service provides this capability?

A.Amazon CloudWatch Logs agent
B.VPC Flow Logs
C.Amazon Inspector
D.AWS Config
AnswerB

VPC Flow Logs are the native AWS feature that captures IP traffic information for network interfaces in a VPC, recording metadata such as source and destination IP addresses, source and destination ports, protocol, and whether the traffic was accepted or rejected. These logs can be published to Amazon CloudWatch Logs or Amazon S3, where they can be analyzed with CloudWatch Logs Insights, Athena, or third-party tools to detect anomalous outbound connections like data exfiltration or beaconing. Because they capture all network flows at the ENI level, they are the appropriate service for monitoring unusual outbound traffic.

Why this answer

VPC Flow Logs capture metadata about IP traffic going to and from network interfaces in a VPC, including source/destination IPs, ports, protocols, and packet counts. This allows a security engineer to analyze outbound traffic patterns from an EC2 instance and detect anomalies such as data exfiltration or communication with known malicious IPs. The logs can be published to Amazon CloudWatch Logs or Amazon S3 for further analysis with tools like Amazon Athena or third-party SIEMs.

Exam trap

The trap here is that candidates confuse the CloudWatch Logs agent (which sends application logs) with VPC Flow Logs (which capture network traffic metadata), leading them to select Option A because they think 'monitoring logs' implies network visibility.

How to eliminate wrong answers

Option A is wrong because the Amazon CloudWatch Logs agent is a software component installed on an EC2 instance to send application and OS logs (e.g., syslog, Apache logs) to CloudWatch Logs; it does not capture network traffic metadata or provide visibility into outbound network flows. Option C is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances for software vulnerabilities and unintended network exposure; it does not monitor real-time outbound network traffic or provide flow-level logs. Option D is wrong because AWS Config is a service for recording and evaluating configuration changes of AWS resources against desired policies; it does not capture or analyze network traffic data.

394
MCQmedium

An organization uses AWS Organizations with multiple accounts. The security team needs a centralized location to collect and analyze security findings from GuardDuty, Inspector, and Macie. Which AWS service should they use?

A.Amazon Detective
B.AWS Security Hub
C.Amazon CloudWatch
D.AWS Config
AnswerB

AWS Security Hub is the correct choice because it is purpose-built to aggregate security findings from AWS native services and third-party partner products into one place, while supporting multi-account architectures through a delegated administrator and cross-region finding aggregation. It consolidates alerts into the AWS Foundational Security Best Practices, CIS, and PCI DSS standards, and outputs normalized findings via the Security Finding Format API, making it the central command console for security status across the organization.

Why this answer

AWS Security Hub is the correct service because it provides a centralized view of security alerts and compliance status across multiple AWS accounts. It aggregates findings from GuardDuty, Inspector, and Macie, normalizing them into the AWS Security Finding Format (ASFF), enabling the security team to analyze and prioritize threats in a single dashboard.

Exam trap

The trap here is that candidates confuse Amazon Detective’s investigative capabilities with Security Hub’s aggregation role, assuming Detective can centralize findings, when in fact Detective is a post-finding analysis tool that requires Security Hub or GuardDuty to provide the initial findings.

How to eliminate wrong answers

Option A is wrong because Amazon Detective is designed for in-depth investigation of security findings by analyzing VPC Flow Logs, CloudTrail, and GuardDuty data, but it does not aggregate findings from multiple services like Inspector and Macie into a single location. Option C is wrong because Amazon CloudWatch is a monitoring service for metrics, logs, and alarms, not a security findings aggregator; it lacks the native integration to collect and normalize findings from GuardDuty, Inspector, and Macie into a unified format. Option D is wrong because AWS Config is a resource inventory and compliance auditing service that tracks configuration changes, not a centralized hub for security findings from threat detection services.

395
MCQeasy

A company has a VPC with a public subnet and a private subnet. An EC2 instance in the private subnet needs to download patches from the internet. Which AWS service should be used to allow this without assigning a public IP address to the instance?

A.Internet Gateway
B.VPC Endpoint
C.NAT Gateway
D.VPN Connection
AnswerC

A NAT Gateway is a fully managed AWS service that enables instances in a private subnet to initiate outbound connections to the internet while preventing unsolicited inbound connections. It sits in a public subnet, uses an Elastic IP for source NAT, and forwards traffic through the Internet Gateway. Because it preserves the flow state, return traffic from the internet is translated back to the private instance, but no external host can directly initiate a session into the private subnet.

Why this answer

A NAT Gateway is the correct service because it allows instances in a private subnet to initiate outbound connections to the internet (e.g., to download patches) while remaining unreachable from the internet and without needing a public IP. The NAT Gateway resides in a public subnet, has an Elastic IP, and performs source NAT (SNAT) on traffic from the private subnet, translating the private source IP to its own public IP. This satisfies the requirement of outbound-only internet access without exposing the instance.

Exam trap

The trap is assuming a VPC Endpoint provides internet access — candidates conflate private connectivity to AWS services with general internet egress, but only a NAT Gateway (or NAT instance) enables outbound internet for private subnets without public IPs.

How to eliminate wrong answers

Option A is wrong because an Internet Gateway provides bidirectional internet connectivity and requires the instance to have a public IP or Elastic IP and a route in a public subnet — it does not enable private-subnet instances to reach the internet without a public IP. Option B is wrong because a VPC Endpoint (Interface or Gateway) provides private connectivity to specific AWS services (e.g., S3, DynamoDB, SSM) over the AWS backbone, not general internet access for downloading patches from arbitrary external repositories. Option D is wrong because a VPN Connection links your on-premises network to the VPC; it does not provide internet egress for private-subnet instances unless you route through on-premises, which is not the intended solution and adds complexity.

396
MCQhard

A company uses AWS Transit Gateway to connect multiple VPCs and on-premises networks. The security team wants to inspect all traffic between VPCs using a third-party firewall appliance. Which architecture should be used?

A.Set up AWS Direct Connect and route all traffic through the on-premises firewall.
B.Use Transit Gateway with appliance mode and route tables to direct traffic through a firewall appliance in a central VPC.
C.Create VPC peering connections between each VPC and the firewall VPC.
D.Configure network ACLs in each VPC to block traffic unless it comes from the firewall.
AnswerB

Transit Gateway with appliance mode enables asymmetric routing support, allowing a gateway route table to forward traffic from source VPCs to the central inspection VPC, while the firewall appliance then routes return traffic back through the same appliance, ensuring both directions are inspected. By using separate route tables associated with each VPC attachment, you can force all inter-VPC and outbound traffic through the firewall appliance, which scales horizontally and keeps security inspection centralized.

Why this answer

Transit Gateway with appliance mode enables the firewall appliance in a central VPC to receive traffic from all attached VPCs with symmetric routing, ensuring that both forward and return traffic flows through the same appliance. By configuring route tables to direct inter-VPC traffic to the firewall appliance's elastic network interface (ENI), the security team can inspect all traffic without requiring complex peering or on-premises backhauling.

Exam trap

The trap here is that candidates may assume VPC peering or network ACLs can achieve transitive traffic inspection, but they fail to recognize that only Transit Gateway with appliance mode provides the necessary symmetric routing and transitive routing capabilities for centralized firewall inspection.

How to eliminate wrong answers

Option A is wrong because routing all traffic through an on-premises firewall via AWS Direct Connect introduces unnecessary latency, bandwidth costs, and dependency on the on-premises network, which is not a native AWS architecture for VPC-to-VPC inspection. Option C is wrong because VPC peering does not support transitive routing; each peering connection is a one-to-one relationship, so traffic between two VPCs would not automatically flow through a third-party firewall VPC unless complex routing and additional appliances are manually configured, making it unscalable. Option D is wrong because network ACLs are stateless and operate at the subnet level, not at the traffic inspection layer; they cannot force traffic through a firewall appliance or provide deep packet inspection, and blocking traffic based on source IP alone is insufficient for security policy enforcement.

397
MCQmedium

A company is using AWS KMS to encrypt S3 objects. The security team wants to ensure that only a specific IAM role can decrypt objects in a particular S3 bucket. Which KMS key policy configuration should be used?

A.Add a condition that allows decrypt only when kms:ViaService is s3.amazonaws.com and the caller role matches the specific role ARN.
B.Use an S3 bucket policy that denies decrypt for all principals except the specific IAM user.
C.Configure the IAM role with a policy that allows kms:Decrypt for the specific KMS key.
D.Attach a resource-based policy to the S3 bucket that grants decrypt permission to the IAM role.
AnswerA

The kms:ViaService condition restricts key usage to requests routed through S3, while the principal or ARN condition limits decryption to the named IAM role. Together they enforce least privilege, ensuring no other principal or direct KMS call can decrypt the bucket's objects.

Why this answer

A KMS key policy with a condition restricting kms:Decrypt to the specific IAM role ARN and kms:ViaService set to s3.amazonaws.com ensures only that role, acting through S3, can decrypt objects. This is the authoritative control because KMS key policies govern all access to the CMK, and the ViaService condition prevents the role from using the key directly outside S3.

Exam trap

SCS-C02 often tests the misconception that S3 bucket policies can control KMS decrypt — candidates conflate S3 authorization with KMS authorization, but KMS key policies are the authoritative gate.

How to eliminate wrong answers

Option B is wrong because an S3 bucket policy cannot grant or deny KMS decrypt permissions — KMS authorization is controlled by the key policy and IAM, not S3 policies. Option C is wrong because an IAM policy alone is insufficient; the KMS key policy must also allow the role, otherwise the request is denied (unless the key policy delegates to IAM). Option D is wrong because S3 resource-based policies do not govern KMS key usage; decrypt operations are authorized by KMS, not S3.

398
MCQhard

A security engineer needs to ensure that all objects uploaded to an S3 bucket are automatically scanned for malware before being made accessible to users. Which solution is MOST appropriate?

A.Enable VPC Flow Logs to capture all access to the bucket.
B.Enable S3 Object Lock on the bucket.
C.Configure Amazon CloudWatch Logs to monitor S3 access logs.
D.Use S3 event notifications to invoke an AWS Lambda function that runs a malware scanning solution.
AnswerD

S3 event notifications can be configured to publish PUT or POST events to AWS Lambda, triggering a function each time an object is uploaded. The Lambda function can then use GetObject to retrieve the object and run a malware scanning engine such as ClamAV, applying tags or deleting/quarantining the object based on the scan verdict. This serverless, event-driven pattern provides immediate, per-object inspection and scales automatically with upload volume.

Why this answer

S3 event notifications can be configured to trigger an AWS Lambda function upon object creation, allowing the Lambda function to run a malware scanning solution (e.g., using ClamAV or an AWS Marketplace partner) before the object is made accessible. This serverless approach ensures automated, near-real-time scanning without manual intervention, and the Lambda function can quarantine or delete malicious objects by adjusting S3 bucket policies or object ACLs.

Exam trap

The trap here is that candidates may confuse logging/monitoring services (VPC Flow Logs, CloudWatch Logs) with active security controls, failing to recognize that malware scanning requires compute-based content inspection, not just metadata or access logging.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture IP traffic metadata (source/destination IPs, ports, protocols) for network interfaces, not object-level operations or content within S3 buckets; they cannot scan objects for malware. Option B is wrong because S3 Object Lock prevents objects from being deleted or overwritten for a specified retention period, but it does not inspect or scan object content for malware. Option C is wrong because CloudWatch Logs can monitor S3 access logs (e.g., via AWS CloudTrail or server access logs) for auditing, but they cannot perform malware scanning on the uploaded objects themselves.

399
MCQmedium

A security engineer notices that an IAM role has a trust policy allowing any AWS account to assume it. Which attack is this misconfiguration most likely to enable?

A.Logging bypass via CloudTrail
B.Cross-service confused deputy attack
C.Unauthorized access by an external attacker
D.Privilege escalation by attaching additional policies
AnswerC

This is correct: an overly broad trust policy—for example `"Principal": "*"` without restrictive conditions—allows any AWS principal from any account to call `sts:AssumeRole` and obtain the role's temporary security credentials. Once assumed, the attacker receives all permissions attached to the role, enabling unauthorized actions in the account. In the absence of conditions like `aws:PrincipalArn`, `aws:PrincipalAccount`, or an external ID, there is no mechanism to distinguish legitimate principals from external attackers, so the role effectively exposes its permissions to the entire AWS ecosystem.

Why this answer

An IAM role trust policy that allows any AWS account (i.e., `"Principal": {"AWS": "*"}`) to assume the role means that any user or service in any AWS account can call the STS `AssumeRole` API to obtain temporary credentials for the role. This directly enables unauthorized access by an external attacker who can discover the role ARN and assume it, gaining all permissions attached to the role.

Exam trap

The trap here is that candidates may confuse a trust policy misconfiguration with a permissions policy misconfiguration, thinking that privilege escalation (Option D) is the primary risk, when in fact the trust policy directly controls who can assume the role, making unauthorized access the immediate and most likely attack.

How to eliminate wrong answers

Option A is wrong because CloudTrail logs all AWS API calls, including STS `AssumeRole` actions, and there is no mechanism in this misconfiguration to bypass or disable CloudTrail logging. Option B is wrong because a cross-service confused deputy attack involves a malicious service tricking another service into using its own permissions, not an overly permissive trust policy allowing any AWS account to assume a role. Option D is wrong because the misconfiguration is in the trust policy, not in the permissions policy; privilege escalation by attaching additional policies would require the attacker to already have IAM permissions to modify policies, which is not enabled by the trust policy alone.

400
MCQmedium

A company uses AWS Organizations and wants to enable Amazon GuardDuty across all member accounts. The security team wants to centrally manage findings and automate responses. What is the MOST efficient way to achieve this?

A.Designate a Delegated Administrator account for GuardDuty in AWS Organizations and enable GuardDuty for all accounts from that account.
B.Use AWS CloudFormation StackSets to deploy a GuardDuty detector in each account.
C.Enable AWS Security Hub in the management account and configure it to ingest GuardDuty findings from member accounts.
D.Enable GuardDuty in each member account individually and configure cross-account access to a central S3 bucket.
AnswerA

By designating a delegated administrator for GuardDuty in AWS Organizations, you centralize management and allow GuardDuty to automatically enable itself for all existing and future accounts. This creates a single detector per region in the delegated admin account with all member accounts linked underneath, so findings are aggregated without manual per-account setup. This is the native, supported pattern for scaling GuardDuty across an organization.

Why this answer

AWS Organizations allows you to designate a Delegated Administrator account for GuardDuty, which can then enable GuardDuty and manage findings centrally across all member accounts without manual per-account setup. This approach is the most efficient as it leverages the Organizations integration to automatically enable GuardDuty in new accounts and centralize finding management, reducing operational overhead.

Exam trap

The trap here is that candidates often confuse Security Hub's ability to aggregate findings with the actual enablement of GuardDuty, leading them to choose Option C, which only addresses aggregation, not the initial enablement requirement.

How to eliminate wrong answers

Option B is wrong because AWS CloudFormation StackSets can deploy resources across accounts, but GuardDuty requires a detector to be enabled per account, and StackSets do not natively handle the centralized management of findings or automated responses as efficiently as the Delegated Administrator model. Option C is wrong because AWS Security Hub can ingest GuardDuty findings, but it does not enable GuardDuty itself; it only aggregates findings from already-enabled detectors, so it does not address the initial enablement requirement. Option D is wrong because enabling GuardDuty individually in each account and configuring cross-account access to an S3 bucket is manual, inefficient, and does not provide centralized management or automated response capabilities; it also introduces additional complexity with S3 bucket policies and cross-account roles.

401
MCQhard

A security engineer needs to ensure that all new IAM users are created with a strong password policy enforced. Which action should be taken?

A.Set a custom IAM password policy in the account
B.Use AWS Config to automatically delete users with weak passwords
C.Create a Lambda function that checks password strength on user creation
D.Use AWS Secrets Manager to generate passwords
AnswerA

Setting a custom IAM password policy is the native, account-wide control that enforces minimum length, complexity, rotation, and reuse restrictions for all IAM users. When any IAM user creates a password or resets a forgotten one, IAM evaluates it against this policy and rejects non-compliant choices, so it directly satisfies the requirement. It is the only option that applies automatically to every new user without custom infrastructure or reliance on post-creation events.

Why this answer

AWS IAM account password policies are configured at the account level and apply to all IAM users created in that account. Setting a custom password policy enforces minimum length, complexity, reuse prevention, and rotation requirements automatically for every new and existing user. This is the native, supported mechanism for enforcing strong passwords across an AWS account.

Exam trap

SCS-C02 often tests the difference between preventive controls (IAM password policy) and detective controls (AWS Config, Lambda) — candidates pick Config or Lambda because they sound more 'automated', but the requirement is enforcement at creation, which only the native policy provides.

How to eliminate wrong answers

Option B is wrong because AWS Config is a compliance-monitoring service — it can detect non-compliant resources but cannot delete IAM users or enforce password strength at creation time. Option C is wrong because a Lambda function triggered on user creation is a custom workaround that adds latency and complexity, and it cannot retroactively enforce password policy on existing users. Option D is wrong because Secrets Manager generates and stores secrets for applications, not for IAM user console passwords, and it does not enforce a password policy on IAM users.

402
MCQeasy

A company needs to audit all changes to IAM policies in their AWS account. Which AWS service should they use to record these changes?

A.Amazon S3
B.Amazon CloudWatch Logs
C.AWS Config
D.AWS CloudTrail
AnswerD

CloudTrail records API activity across the account, including every IAM policy creation, modification and deletion, capturing the identity, timestamp and request parameters. This satisfies the audit requirement by providing a tamper-evident log of who changed which policy and when.

Why this answer

AWS CloudTrail records API activity in an AWS account, including all changes to IAM policies (CreatePolicy, PutRolePolicy, AttachRolePolicy, etc.). CloudTrail captures the identity of the caller, the time, the source IP, and the request parameters, making it the authoritative service for auditing IAM policy changes. It is enabled by default for management events and can be configured for multi-region and organization-wide trails.

Exam trap

SCS-C02 often tests the confusion between AWS Config (resource configuration history and compliance) and CloudTrail (API activity auditing) — candidates pick Config because it sounds like it tracks changes, but CloudTrail is the service that records who made the API call.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is object storage and does not record API activity — it can store CloudTrail logs but is not the auditing service itself. Option B is wrong because CloudWatch Logs is a log aggregation and monitoring service; it can receive CloudTrail logs but does not natively record IAM API calls. Option C is wrong because AWS Config records resource configuration changes and evaluates compliance, but CloudTrail is the service that captures the API calls that made those changes — for auditing who changed IAM policies, CloudTrail is the correct source.

403
MCQhard

A company uses AWS Organizations with a management account and several member accounts. The security team wants to restrict the use of specific AWS services (e.g., EC2, Lambda) in certain accounts based on the account's environment (dev, test, prod). Which approach should be used to implement this requirement?

A.Use AWS CloudTrail to monitor API calls and revoke access after the fact.
B.Create IAM roles in each account with policies that deny access to services.
C.Use AWS Organizations to tag accounts (e.g., Environment=Dev) and use SCPs with conditions to deny access to services based on tags.
D.Use AWS Config rules to detect and alert when restricted services are used.
AnswerC

Tag-based SCPs allow fine-grained control across accounts.

Why this answer

By tagging accounts in AWS Organizations (e.g., Environment=Dev) and using Service Control Policies (SCPs) with conditions based on those tags, the security team can restrict usage of specific AWS services per account environment. SCPs are applied at the organization level and affect all users and roles in the account, providing preventive controls. Option A is incorrect because CloudTrail only logs API calls and does not prevent usage; revoking access after the fact is not a preventive measure.

Option B is incorrect because IAM roles are identity-based and do not restrict services at the account level; also, managing roles per account would be cumbersome. Option D is incorrect because AWS Config rules detect non-compliant resource configurations but do not prevent the use of services; they are detective controls.

404
MCQhard

A security engineer is investigating a suspected compromise of an Amazon EC2 instance that is a member of an Auto Scaling group. The instance is still running and the engineer must preserve volatile evidence before the Auto Scaling group replaces it. Which sequence of actions best preserves the evidence while maintaining the ability to analyze it later?

A.Stop the instance, detach the root EBS volume, create a snapshot of the volume, and then reattach the original volume to the instance.
B.Create an AMI of the instance, terminate the instance to prevent further malicious activity, and launch a new instance from the AMI for analysis.
C.Detach the instance from the Auto Scaling group, reboot the instance into single-user mode, and copy the root filesystem to an S3 bucket using the AWS CLI.
D.Capture memory with an approved forensic tool, take EBS snapshots of all attached volumes, record instance metadata and network connections, then isolate the instance by replacing its security group with a quarantine group.
AnswerD

Capturing memory first preserves volatile data such as running processes and credentials that are lost on shutdown. EBS snapshots of all volumes preserve persistent disk state, and recording metadata and network connections captures context. Isolating with a quarantine security group stops further communication without destroying the instance, giving the engineer time to analyze copies.

Why this answer

Preserving volatile evidence requires acting before any shutdown or termination. Capturing memory first retains processes and credentials, EBS snapshots preserve disk state for offline analysis, and recording metadata and network connections provides investigative context. Isolating the instance with a quarantine security group stops exfiltration and command-and-control traffic without destroying the evidence, and it keeps the instance alive so additional artifacts can be collected if needed.

Exam trap

The trap here is treating an AMI or EBS snapshot as complete evidence and terminating the instance, which destroys volatile memory and any live network state.

405
Multi-Selecthard

Which THREE are best practices for securing IAM in an AWS environment? (Choose THREE.)

Select 3 answers
A.Use IAM roles for applications running on EC2.
B.Enable MFA for all IAM users.
C.Use the AWS account root user for daily administrative tasks.
D.Grant broad permissions to simplify management.
E.Rotate IAM user access keys regularly.
AnswersA, B, E

IAM roles allow EC2 instances to obtain temporary security credentials automatically through instance profiles, eliminating the need to embed long-term access keys on the instance. These temporary credentials are vended via the instance metadata service and are rotated by AWS STS, reducing the risk of leaked keys and their blast radius. Roles also let you enforce least privilege cleanly, because you can attach narrowly scoped policies to the role and update them without modifying the instance.

Why this answer

Using IAM roles for EC2 instances eliminates the need to store long-term AWS credentials (access keys) on the instance. Instead, the instance assumes the role via the EC2 metadata service, which automatically rotates temporary security credentials (via AWS STS). This follows the principle of least privilege and reduces the risk of credential leakage.

Exam trap

The SCS-C02 exam often tests the misconception that the root user is acceptable for daily tasks because it has full access, but the trap is that the root user lacks granular audit trails and cannot be restricted by IAM policies, making it a massive security risk for routine operations.

406
Multi-Selecthard

A company wants to implement automated remediation of security findings from Amazon GuardDuty. Which THREE AWS services can be used together to create an automated response workflow? (Select THREE.)

Select 3 answers
A.Amazon CloudWatch Events (EventBridge)
B.AWS Lambda
C.AWS Step Functions
D.Amazon SQS
E.AWS Config
AnswersA, B, C

Amazon CloudWatch Events (EventBridge) is the correct primary service because GuardDuty natively publishes findings to the EventBridge default event bus as structured events. An EventBridge rule can filter on finding fields (e.g., severity, type, account ID) and route matched findings to targets such as Lambda functions or Step Functions state machines, enabling near-real-time automated remediation without custom polling. This is the standard, serverless integration point for GuardDuty-driven responses.

Why this answer

Amazon GuardDuty sends findings to Amazon CloudWatch Events (EventBridge) as events. You can configure an EventBridge rule to match specific GuardDuty findings and trigger an AWS Lambda function for automated remediation. AWS Step Functions can orchestrate complex remediation workflows involving multiple Lambda functions or other AWS services, providing retry logic and error handling.

Exam trap

The trap here is that candidates often select Amazon SQS or AWS Config because they are associated with event-driven architectures or compliance, but they are not the core services used in the standard GuardDuty automated remediation pattern, which relies on EventBridge, Lambda, and Step Functions.

407
Multi-Selecthard

A security engineer needs to restrict access to an S3 bucket so that only requests from a specific VPC endpoint are allowed. Which condition must be configured?

Select 1 answer
A.aws:SourceIp
B.aws:UserAgent
C.aws:SourceVpce
D.aws:SourceVpc
E.aws:Referer
AnswersC

aws:SourceVpce is the correct condition key because it restricts access to requests that arrive through a specific VPC endpoint, identified by its endpoint ID (e.g., vpce-1234567890abcdef0). This condition is evaluated based on the endpoint's identity, which cannot be spoofed or altered through IP address translation, providing a reliable network-level control. It ensures that only traffic coming from that exact VPC endpoint is allowed to access the S3 bucket.

Why this answer

To restrict S3 bucket access to a specific VPC endpoint, the bucket policy must include a condition that checks the VPC endpoint ID. The condition key `aws:SourceVpce` evaluates the endpoint ID of the VPC endpoint through which the request arrives. This ensures that only requests originating from that specific endpoint are allowed, effectively blocking access from the public internet or other endpoints.

Exam trap

SCS-C02 often tests the difference between `aws:SourceVpce` and `aws:SourceVpc`; candidates may confuse VPC ID with VPC endpoint ID, leading to selection of the wrong condition key.

408
MCQeasy

A company wants to grant cross-account access to an S3 bucket owned by Account A to a user in Account B. The bucket policy in Account A allows access from Account B. What additional configuration is required?

A.The IAM user in Account B must have a policy that allows access to the S3 bucket.
B.Nothing; the bucket policy is sufficient.
C.The bucket must be configured with ACLs.
D.An SCP must allow the s3:GetObject action.
AnswerA

The bucket policy in Account A grants the IAM user (or Account B) the ability to access the S3 bucket, but cross-account access requires an explicit allow from the requester's own account as well. The IAM user in Account B must have an identity-based policy that permits the specific S3 action (e.g., s3:GetObject) on the target bucket or object ARN. AWS evaluates both the resource-based bucket policy and the identity-based policy, and if either does not explicitly allow the action, the request is denied. Without this IAM policy, the user may have no effective permission to perform the S3 operation despite the bucket policy granting access.

Why this answer

Cross-account access to an S3 bucket requires both a resource-based policy (the bucket policy in Account A) and an identity-based policy (an IAM policy attached to the user or role in Account B). The bucket policy grants access to the external account, but the IAM user in Account B must also have an explicit policy that allows the desired actions (e.g., s3:GetObject). Therefore, Option A is correct.

Option B is incorrect because the bucket policy alone is not sufficient. Option C is incorrect because ACLs are not required and are generally not recommended for cross-account access. Option D is incorrect because SCPs (Service Control Policies) are used for organization-wide guardrails and are not required for this specific cross-account access.

409
MCQeasy

A security engineer needs to monitor for unauthorized changes to security group rules in an AWS account. Which AWS service can evaluate security group rules against a desired configuration and alert on changes?

A.AWS Security Hub
B.AWS Config
C.Amazon GuardDuty
D.AWS CloudTrail
AnswerB

AWS Config is the correct choice because it continuously records configuration changes to your security groups, including additions or deletions of ingress and egress rules. By using managed or custom Config rules, you can define a desired security group configuration (for example, disallowing SSH access from 0.0.0.0/0) and AWS Config will evaluate each change against that baseline, generating compliance alerts and invoking remediation via EventBridge or Lambda when a noncompliant change occurs.

Why this answer

AWS Config is correct because it provides a managed rule called 'restricted-ssh' or custom rules using AWS Config managed rules or Lambda functions to evaluate security group rules against a desired configuration. When a security group rule is added, removed, or modified, AWS Config detects the configuration change, evaluates it against the defined rules, and can trigger an Amazon SNS notification to alert the security engineer. This makes AWS Config the appropriate service for continuous monitoring and alerting on unauthorized changes to security group rules.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which logs API calls) with AWS Config (which evaluates the resulting configuration state), leading them to choose CloudTrail because they think logging API calls is sufficient for monitoring unauthorized changes, but CloudTrail does not evaluate the configuration against a desired state or provide alerting on noncompliant rules.

How to eliminate wrong answers

Option A is wrong because AWS Security Hub aggregates security findings from multiple services (like AWS Config, GuardDuty, and Inspector) and provides a comprehensive security posture view, but it does not directly evaluate security group rules against a desired configuration or generate alerts for unauthorized changes on its own. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events for malicious activity, not for monitoring configuration changes to security group rules. Option D is wrong because AWS CloudTrail records API calls (including those that modify security groups) for auditing and forensic analysis, but it does not evaluate the resulting configuration against a desired state or provide alerting on unauthorized changes—it only logs the actions taken.

410
MCQeasy

A developer needs to grant an IAM user access to a specific S3 bucket only. Which IAM policy element should be used to restrict access to that bucket?

A.Principal
B.Condition
C.Resource
D.Action
AnswerC

The Resource element is the only policy element that specifies which service resources the action applies to, using Amazon Resource Names (ARNs). To grant an IAM user access to a specific S3 bucket, you must include that bucket's ARN in the Resource field, optionally with a wildcard for objects. Without the correct Resource entry, the policy cannot define the scope of access needed.

Why this answer

The Resource element in an IAM policy specifies the AWS resource(s) to which the policy statement applies. For an S3 bucket, you use the bucket's ARN (e.g., arn:aws:s3:::bucket-name) or its objects (arn:aws:s3:::bucket-name/*) in the Resource field to restrict access to that specific bucket. This directly scopes the permissions to the intended bucket, ensuring the IAM user can only perform allowed actions on that resource.

Exam trap

SCS-C02 often tests the confusion between identity-based and resource-based policy elements, leading candidates to incorrectly choose Principal or Condition when asked how to restrict access to a specific resource in an identity-based policy.

How to eliminate wrong answers

Option A is wrong because Principal is used in resource-based policies (like S3 bucket policies) to specify who (user, role, account) is allowed or denied access, not in identity-based policies to restrict resources. Option B is wrong because Condition adds constraints (e.g., IP range, MFA, time) but does not by itself limit access to a specific bucket; it only refines when a policy applies. Option D is wrong because Action defines the operations (e.g., s3:GetObject) but does not specify which bucket those actions can be performed on.

411
MCQmedium

A company has multiple AWS accounts and wants to centrally aggregate VPC Flow Logs from all accounts into a single S3 bucket in the logging account. What is the MOST secure way to configure cross-account delivery?

A.Use AWS CloudTrail to log flow logs and deliver to the central bucket.
B.Create VPC Flow Logs in each account, specifying the central S3 bucket ARN as the destination, and configure the bucket policy to allow the flow logs service principal to write.
C.Share the central bucket's access key with each account to write directly.
D.Use Amazon Kinesis Data Firehose to stream flow logs from each account to the central S3 bucket.
AnswerB

For each member account, you enable VPC Flow Logs and set the destination to the central S3 bucket's ARN (e.g., arn:aws:s3:::central-bucket/flowlogs). The central account must attach a bucket policy that grants s3:PutObject to the VPC Flow Logs service principal, typically vpc-flow-logs.amazonaws.com, with a resource condition that limits writes to the source account's AWSLogs prefix. Once configured, flow records are published directly and continuously from each account to the central bucket without any additional credentials or infrastructure, making this the native and correct cross-account delivery mechanism.

Why this answer

VPC Flow Logs can be published directly to an S3 bucket in another account by specifying the bucket ARN as the destination. The logging account's bucket policy must grant the `s3:PutObject` permission to the VPC Flow Logs service principal (`delivery.logs.amazonaws.com`) for the cross-account write to succeed. This approach avoids sharing credentials or introducing additional services, maintaining a secure and direct delivery path.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing a streaming service like Kinesis Firehose or misapply CloudTrail, not realizing that VPC Flow Logs have a native cross-account S3 delivery capability that is both secure and simple.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail logs API activity, not VPC Flow Logs; CloudTrail cannot capture or deliver network traffic logs. Option C is wrong because sharing an S3 bucket's access key (long-term credentials) violates the principle of least privilege and introduces a significant security risk of credential exposure or misuse. Option D is wrong because Amazon Kinesis Data Firehose is an unnecessary intermediary that adds complexity and cost; VPC Flow Logs can natively deliver to a cross-account S3 bucket without requiring Firehose.

412
Multi-Selecthard

A security engineer needs to enable VPC Flow Logs to capture traffic metadata. Which THREE components are required to create a VPC Flow Log?

Select 3 answers
A.A CloudWatch Logs log group to publish the flow logs.
B.A VPC, subnet, or network interface to monitor.
C.An S3 bucket to store the flow logs.
D.An Amazon Kinesis Data Firehose delivery stream.
E.An IAM role that grants permissions to publish logs.
AnswersA, B, E

When the delivery target for VPC Flow Logs is CloudWatch Logs, the log group is the container that receives and stores the published flow log records. It must exist in the same Region as the monitored VPC, and VPC Flow Logs automatically creates a log stream for each elastic network interface. Without this log group (or permission to create it), you cannot complete CloudWatch Logs delivery.

Why this answer

A CloudWatch Logs log group is required because VPC Flow Logs publish traffic metadata to CloudWatch Logs as the default destination. The flow logs are stored as log streams within the specified log group, enabling querying and monitoring via CloudWatch Logs Insights. Without a log group, there is no destination for the flow log records to be sent to.

Exam trap

The trap here is that candidates often assume S3 is mandatory because it is a common storage service, but VPC Flow Logs require either CloudWatch Logs or S3 as a destination, and the question specifies the three required components, making S3 optional and thus incorrect.

413
MCQmedium

Refer to the exhibit. A security engineer runs the AWS CLI command to look up console login events. The output shows two successful login events for user1 within 5 minutes. What should the engineer suspect?

A.The user created a new access key.
B.The user's credentials may be compromised.
C.The user's account is being used by multiple users.
D.The user has disabled multi-factor authentication (MFA).
AnswerB

Multiple successful console sign-ins from the same IAM user in a short window, particularly from different source IP addresses or geographies, is a well-recognized indicator of credential theft. An attacker who has obtained the user's password (and possibly bypassed MFA) will often log in repeatedly to establish persistence, exfiltrate data, or escalate privileges. The correct incident-response action is to treat these events as evidence of compromise, invalidate the credentials immediately, and review CloudTrail for unauthorized actions.

Why this answer

Two successful console login events for the same user within 5 minutes, especially from different source IP addresses or user agents, is a strong indicator of credential compromise. An attacker who has obtained the user's password can log in while the legitimate user is also active, creating overlapping sessions. AWS CloudTrail records the `ConsoleLogin` event with details like `sourceIPAddress` and `userAgent`, which the engineer should examine to confirm whether the logins originated from different locations or devices.

Exam trap

The trap here is that candidates may assume multiple logins are due to shared credentials or MFA misconfiguration, but the key indicator of compromise is the temporal proximity of two successful logins, which strongly suggests an attacker is using the same credentials concurrently.

How to eliminate wrong answers

Option A is wrong because creating a new access key does not generate console login events; access key creation is recorded as `CreateAccessKey` in CloudTrail, not as a `ConsoleLogin` event. Option C is wrong because while multiple users could theoretically share an account, AWS Identity and Access Management (IAM) best practices prohibit sharing credentials, and the overlapping logins more likely indicate an attacker using stolen credentials rather than legitimate sharing. Option D is wrong because disabling MFA does not cause multiple login events within a short timeframe; MFA status changes are recorded as `DeactivateMFADevice` events, and the absence of MFA would not explain two rapid successive logins.

414
MCQmedium

A security engineer is designing a network architecture for a web application that must be highly available and secure. The application uses an Application Load Balancer (ALB) in front of EC2 instances. Which architecture meets these requirements?

A.Place both the ALB and EC2 instances in private subnets across two Availability Zones.
B.Place the ALB in private subnets and EC2 instances in public subnets across two Availability Zones.
C.Place the ALB in public subnets and EC2 instances in private subnets across two Availability Zones.
D.Place both the ALB and EC2 instances in public subnets across two Availability Zones.
AnswerC

This is the correct architecture: the internet-facing ALB resides in public subnets, where it has public IP addresses and a route through the internet gateway to accept client traffic, while the EC2 instances are placed in private subnets with no public IPs or direct internet ingress. The ALB terminates HTTP/HTTPS traffic and forwards requests to instances over private IP addresses using target groups; security groups on the instances should only allow traffic from the ALB security group. This design keeps instances isolated from direct internet access while still providing high availability across two Availability Zones.

Why this answer

The correct architecture places the ALB in public subnets so it can receive internet traffic, while EC2 instances reside in private subnets for enhanced security. The ALB acts as a reverse proxy, terminating client connections and forwarding requests to the instances over private IPs, which prevents direct internet access to the instances. Deploying across two Availability Zones ensures high availability by surviving an AZ failure.

Exam trap

The trap here is that candidates often assume both components must be in the same subnet type for simplicity, but the correct design intentionally separates public-facing and private resources to enforce security boundaries.

How to eliminate wrong answers

Option A is wrong because placing both the ALB and EC2 instances in private subnets would block internet traffic from reaching the ALB, making the web application inaccessible from the internet. Option B is wrong because placing EC2 instances in public subnets exposes them directly to the internet, bypassing the security benefits of the ALB and increasing the attack surface. Option D is wrong because placing both the ALB and EC2 instances in public subnets exposes the instances to inbound internet traffic, defeating the purpose of using an ALB for security and potentially violating compliance requirements.

415
MCQmedium

A security engineer is investigating a potential data exfiltration incident. The engineer notices that an EC2 instance with an attached IAM role has been making API calls to an S3 bucket in another AWS account. The engineer wants to identify the source of the API calls and determine if the calls are malicious. Which AWS service should the engineer use to view the API calls made by the IAM role?

A.VPC Flow Logs
B.Amazon GuardDuty
C.AWS Config
D.AWS CloudTrail
AnswerD

CloudTrail records every API call, capturing the IAM role's identity, source IP, timestamp and requested S3 action. This lets the engineer trace the cross-account calls back to the specific EC2 instance and assess whether the pattern indicates malicious exfiltration.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made by IAM roles, including the source IP address, user agent, and the specific actions performed. In this scenario, CloudTrail logs will show the exact API calls made by the EC2 instance's IAM role to the S3 bucket in another account, enabling the security engineer to identify the source and determine if the calls are malicious.

Exam trap

The trap here is that candidates confuse VPC Flow Logs (which show network traffic) with CloudTrail (which shows API calls), or they assume GuardDuty provides raw logs instead of just alerts, leading them to pick a service that cannot directly answer the question of viewing the specific API calls made by the IAM role.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) but do not log AWS API calls or IAM role activity. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes CloudTrail, VPC Flow Logs, and DNS logs for anomalies, but it does not directly provide the raw API call logs needed to view the specific actions taken by the IAM role. Option C is wrong because AWS Config records resource configuration changes and compliance, not the API calls made by IAM roles.

416
MCQhard

A company has a requirement that all IAM users must use strong passwords. The security engineer needs to enforce a password policy that requires minimum 12 characters, at least one uppercase letter, and at least one number. The engineer sets the password policy in IAM. However, existing users with weak passwords are not forced to change them. What should the engineer do to enforce the policy for existing users?

A.Manually reset each user's password to a strong password.
B.Enable 'Allow users to change their own password' in the policy.
C.Re-apply the password policy to each user.
D.Set the password expiration period to 0 to force immediate password change.
AnswerD

Setting the 'password expiration period' to 0 in the IAM account password policy causes every existing password to expire immediately, forcing each IAM user to choose a new password at the next sign-in. Because the account-level policy has already defined the required strength, the newly chosen passwords must satisfy those strong-complexity rules. This is the only listed option that enforces the strong-password requirement collectively on all users without requiring manual intervention per user.

Why this answer

Setting the password policy to expire existing passwords will force users to change them on next login. Option A is wrong because the policy is already set; users are not forced to change. Option B is wrong because allowing users to change passwords does not enforce the policy.

Option C is wrong because resetting passwords manually is not scalable and not required.

417
MCQeasy

A company wants to allow its development team to have full access to Amazon S3 buckets that are tagged with 'Environment: Dev'. Which IAM policy element should be used to restrict access based on tags?

A.Use 'aws:PrincipalTag' in the Condition element
B.Use 'aws:SourceTag' in the Condition element
C.Use 'aws:RequestTag' in the Condition element
D.Use 'aws:ResourceTag' in the Condition element
AnswerD

aws:ResourceTag allows you to write a condition such as StringEquals: aws:ResourceTag/Project: Dev, which is evaluated against tags attached to the resource that the request targets. This AWS global condition key supports attribute-based access control and works in both identity-based and resource-based policies. It directly enforces that a developer can only perform an action when the specific resource has the required tag key-value pair, making it the correct choice for this requirement.

Why this answer

To restrict access based on tags attached to the S3 bucket (the resource), the IAM policy must use the aws:ResourceTag condition key. This key evaluates the tags on the target resource, allowing or denying actions only when the resource carries the specified tag, such as Environment: Dev.

Exam trap

SCS-C02 often tests the distinction between aws:ResourceTag (tags on the target resource) and aws:PrincipalTag (tags on the caller); candidates frequently confuse the two and select PrincipalTag when the question asks about resource tags.

How to eliminate wrong answers

Option A is wrong because aws:PrincipalTag evaluates tags on the IAM principal making the request, not on the target resource. Option B is wrong because aws:SourceTag is not a valid IAM condition key; it does not exist in AWS policy language. Option C is wrong because aws:RequestTag is used to control which tags can be applied during resource creation or modification, not to restrict access to already-tagged resources.

418
MCQhard

A company has a multi-account strategy and wants to ensure that all API calls from member accounts are logged to a centralized S3 bucket in the security account. Which configuration is required?

A.Use Amazon Kinesis Data Streams to stream CloudTrail events from all accounts to the central S3 bucket
B.Create an organization trail in the management account that logs all accounts
C.Create a CloudTrail trail in each member account and specify the same S3 bucket
D.Enable AWS Security Hub in the security account and configure it to collect CloudTrail logs
AnswerB

Creating an organization trail in the management account of an AWS Organization automatically logs events from every member account, including future accounts as they are added. This trail delivers all cloud trail event history to a single S3 bucket you designate, eliminating the need to configure trails individually per account. It gives central administrators full visibility and control over governance, and it supports a single set of lifecycle policies and permissions applied across the entire organization.

Why this answer

AWS Organizations allows you to create an organization trail in the management account that automatically applies to all member accounts. This ensures that CloudTrail logs from every account in the organization are delivered to a single, centralized S3 bucket in the security account without needing per-account configuration. The organization trail uses the management account’s CloudTrail configuration to enable logging across the entire organization, and the S3 bucket policy must grant the necessary permissions for CloudTrail to write logs from all accounts.

Exam trap

The trap here is that candidates often assume creating separate trails per account (Option C) is simpler or more reliable, but they overlook the AWS Organizations integration that allows a single organization trail to automatically cover all accounts, reducing administrative overhead and ensuring consistent log delivery.

How to eliminate wrong answers

Option A is wrong because Amazon Kinesis Data Streams is a real-time data streaming service, not a logging destination for CloudTrail; CloudTrail can deliver logs to S3 or CloudWatch Logs, but Kinesis Data Streams is not a native CloudTrail destination for centralized logging. Option C is wrong because creating a separate trail in each member account and specifying the same S3 bucket requires manual configuration per account, does not scale, and does not leverage AWS Organizations for automatic management; additionally, each member account would need its own bucket policy to allow writes, which is error-prone. Option D is wrong because AWS Security Hub is a security posture management service that aggregates findings from various AWS services, but it does not collect or store CloudTrail logs; it can ingest CloudTrail events as a data source for findings, but it does not replace the need for a centralized S3 bucket for log storage.

419
MCQhard

A company has an Amazon S3 bucket with versioning enabled. They want to ensure that all objects in the bucket are encrypted at rest using server-side encryption with AWS KMS (SSE-KMS). They also want to prevent any future uploads that are not encrypted with SSE-KMS. Which combination of actions should they take?

A.Add a bucket policy that denies s3:PutObject if s3:x-amz-server-side-encryption is not aws:kms. Use S3 Inventory to report encryption status of existing objects.
B.Use AWS Config rule s3-bucket-server-side-encryption-enabled to check compliance.
C.Use S3 Object Lock with governance mode.
D.Enable default encryption with SSE-KMS on the bucket. Use S3 Inventory to report encryption status.
AnswerA

This solution combines an explicit bucket policy deny with the s3:x-amz-server-side-encryption condition key to reject any PutObject that does not specify aws:kms as the encryption value, making enforcement happen before the write is committed. Because this is a request-level condition, it cannot be bypassed by client-side SDK settings or explicit SSE headers that differ from KMS. S3 Inventory then provides a periodic CSV or Parquet report of existing objects, including their encryption status, enabling the team to locate and remediate any legacy objects that predate the policy.

Why this answer

A bucket policy denying PutObject without SSE-KMS prevents non-compliant uploads, and S3 Inventory reports encryption status. Option B only checks compliance, does not enforce. Option C does not enforce encryption.

Option D does not enforce.

420
MCQeasy

A company is storing sensitive data in Amazon S3 buckets. They want to ensure that all uploaded objects are encrypted at rest using server-side encryption with AWS KMS (SSE-KMS). Which bucket policy statement will enforce this?

A.{"Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"StringNotEquals": {"s3:x-amz-server-side-encryption": "aws:kms"}}}
B.{"Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"StringNotEquals": {"s3:x-amz-server-side-encryption": "AES256"}}}
C.{"Effect": "Allow", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"StringEquals": {"s3:x-amz-server-side-encryption": "aws:kms"}}}
D.{"Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"StringEquals": {"s3:x-amz-server-side-encryption": "aws:kms"}}}
AnswerA

This bucket policy is correct because it uses an explicit Deny with a StringNotEquals condition to require that every s3:PutObject request includes the x-amz-server-side-encryption header set to aws:kms. Since explicit Deny statements override any Allow, any upload that lacks the header or uses a different encryption method is blocked, while requests that properly specify SSE-KMS are allowed. The absence of the header also makes StringNotEquals evaluate true, so the Deny also catches requests that omit encryption entirely, ensuring sensitive data is always encrypted with KMS-managed keys.

Why this answer

It uses a Deny effect with a StringNotEquals condition on the s3:x-amz-server-side-encryption header set to 'aws:kms'. This ensures that any PutObject request that does not include the header specifying SSE-KMS is denied, effectively enforcing that all uploaded objects must be encrypted with AWS KMS. The Deny effect overrides any Allow, making this policy robust against accidental or malicious uploads without the required encryption.

Exam trap

The trap here is that candidates often choose an Allow policy (Option C) thinking it enforces encryption, but without a Deny, requests that omit the encryption header are still allowed by default, making the policy ineffective.

How to eliminate wrong answers

Option B is wrong because it enforces SSE-S3 (AES256) instead of SSE-KMS, which does not meet the requirement for server-side encryption with AWS KMS. Option C is wrong because an Allow effect with a StringEquals condition is insufficient; it does not block uploads that lack the encryption header, as the default behavior (no explicit Deny) would allow them. Option D is wrong because it enforces SSE-S3 (AES256) via a Deny, which again is not SSE-KMS and would incorrectly block valid SSE-KMS uploads while allowing non-compliant ones.

421
MCQmedium

A company is using IAM roles to grant EC2 instances access to an S3 bucket. The security team wants to ensure that the instances can only access their own bucket. Which policy should be attached to the IAM role to enforce this?

A.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:*","Resource":"*"}]}
B.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:GetObject","Resource":"*"}]}
C.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:GetObject","Resource":"*","Condition":{"IpAddress":{"aws:SourceIp":"10.0.0.0/16"}}}]}
D.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:GetObject","Resource":"arn:aws:s3:::my-bucket/*"}]}
AnswerD

This is the correct least-privilege policy: it restricts the s3:GetObject action to a specific Resource ARN, arn:aws:s3:::my-bucket/*, which matches only objects inside the my-bucket bucket. The lack of s3:ListBucket permission is fine for direct object retrieval—the caller must know the object key, but that matches the requirement of granting access to the bucket's objects. The policy contains no wildcards beyond the object-name segment (*), so it does not grant access to other buckets or to bucket-level operations like listing. This scoping aligns with AWS's recommended practice of using resource-level permissions for S3 actions and is the only option that satisfies the principle of least privilege.

Why this answer

Option D is the only policy that scopes the Allow to a specific bucket ARN (arn:aws:s3:::my-bucket/*), which enforces least privilege by ensuring the role can only access objects in that one bucket. The other options either grant wildcard access or use conditions that do not restrict the resource to the instance's own bucket.

Exam trap

The trap is picking a policy that 'looks' scoped (e.g., with an IP condition) but still uses Resource:* — the exam tests whether you verify the Resource element, not just the presence of a Condition.

How to eliminate wrong answers

Option A is wrong because it grants s3:* on Resource:* — full S3 access to every bucket in the account, the opposite of least privilege. Option B is wrong because it allows s3:GetObject on Resource:* — read access to objects in any bucket, not just the instance's own bucket. Option C is wrong because while it adds an IP condition, the Resource is still '*' and the SourceIp condition is unreliable for EC2 (the instance's private IP is not what S3 sees for gateway endpoint traffic; S3 sees the VPC endpoint or NAT IP), so it does not correctly scope access to the instance's bucket.

422
MCQhard

A company runs a web application on an Auto Scaling group of EC2 instances behind an Application Load Balancer. The application stores user session data in an ElastiCache Redis cluster. The security team receives an alert from GuardDuty that one of the EC2 instances is communicating with a known command-and-control (C2) IP address. The instance ID is i-0a1b2c3d4e5f. The security engineer needs to contain the threat immediately while preserving the instance for forensic analysis. Which course of action should the security engineer take?

A.Apply a new security group that denies all inbound and outbound traffic to the instance.
B.Remove the security group from the Auto Scaling group to isolate the instance.
C.Terminate the EC2 instance immediately to stop the communication.
D.Create an AMI of the instance for forensic analysis and then terminate the instance.
AnswerA

Applying a new security group that denies all inbound and outbound traffic immediately severs the instance's network path at the hypervisor, cutting off the C2 server connection without killing the process or losing memory artifacts. Because security group changes are applied instantly across the VPC, this containment step is faster than OS-level firewall rules and avoids tipping off the attacker. The instance remains powered on, allowing you to capture a memory dump and disk image for forensic analysis before any restoration or termination.

Why this answer

Applying a new security group that denies all inbound and outbound traffic immediately stops the C2 communication at the network layer without destroying the instance. This preserves the instance for forensic analysis (e.g., memory dump, disk imaging) while containing the threat. The security group acts as a virtual firewall, and changing it is a non-destructive, reversible action that can be applied directly to the instance even if it is part of an Auto Scaling group.

Exam trap

The trap here is that candidates often choose to terminate the instance (Option C) thinking it is the fastest containment, but they overlook the critical requirement to preserve the instance for forensic analysis, which termination destroys.

How to eliminate wrong answers

Option B is wrong because removing the security group from the Auto Scaling group does not isolate the instance; the instance retains its existing security group(s) and continues to communicate. Option C is wrong because terminating the instance destroys the forensic evidence (e.g., volatile memory, running processes, disk state) and prevents further analysis. Option D is wrong because creating an AMI takes time and does not immediately stop the C2 communication; the instance remains active and can continue exfiltrating data or receiving commands during the AMI creation process.

423
MCQhard

A security engineer is configuring AWS CloudWatch Logs to monitor for suspicious activity. They want to create a metric filter that detects when an IAM user calls the `iam:CreateAccessKey` API. The engineer writes the following filter pattern: `{ ($.eventName = "CreateAccessKey") }`. After testing, the filter does not trigger. What is the most likely reason?

A.The filter pattern syntax is incorrect; it should use square brackets.
B.The metric filter is not associated with the correct log group.
C.CloudWatch Logs does not support metric filters for CloudTrail logs.
D.The filter pattern does not include the eventSource field, so it might match events from other services.
AnswerB

The most likely cause is that the metric filter is attached to a different log group than the one receiving the CloudTrail CreateAccessKey events. Metric filters evaluate only log data that arrives in the specific log group they are configured on; if the CloudTrail trail streams to another log group in another account or region, or the filter is created under the wrong log group name, the pattern never sees the relevant events. Verify the trail's destination log group and that the filter is assigned there.

Why this answer

The filter pattern `{ ($.eventName = "CreateAccessKey") }` is syntactically correct and will match any CloudTrail event with eventName CreateAccessKey, regardless of service. The most likely reason the filter does not trigger is that the metric filter is not associated with the correct log group, or the log group does not contain CloudTrail events from IAM. A missing eventSource field does not prevent the filter from working; it would simply match events from any service, which could cause false positives, but not a failure to trigger.

Exam trap

Candidates often focus on filter pattern syntax or missing fields when the filter doesn't trigger, but the most common cause is misconfiguration of the metric filter's association to the log group. Always verify the log group contains the expected CloudTrail events and that the metric filter is correctly linked.

How to eliminate wrong answers

Option A is wrong because the filter pattern syntax `{ ($.eventName = "CreateAccessKey") }` is correct for CloudWatch Logs metric filters; square brackets are not used in metric filter patterns (they are used in CloudWatch Logs Insights queries). Option B is wrong because the question states the filter does not trigger after testing, implying it was associated with a log group, and the issue is with the pattern itself, not the association. Option C is wrong because CloudWatch Logs fully supports metric filters for CloudTrail logs, which is a common use case for monitoring API activity.

424
MCQhard

A security engineer needs to allow an application running on an Amazon EC2 instance to access an Amazon S3 bucket. The application must not use long-term credentials. The engineer has created an IAM role with the necessary permissions and attached it to the instance profile. However, the application is still receiving access denied errors. Upon investigation, the engineer finds that the application is using the AWS SDK for Java and is explicitly setting credentials via environment variables. What is the MOST likely cause of the access denied errors?

A.The IAM role's trust policy does not allow the EC2 service to assume the role.
B.The environment variables contain credentials that are expired or lack the necessary permissions.
C.The S3 bucket policy denies access to the IAM role associated with the instance profile.
D.The EC2 instance metadata service is disabled, preventing the SDK from retrieving temporary credentials.
AnswerB

When environment variables are set, the AWS SDK prioritizes them over the instance profile credentials. If those credentials are expired or have insufficient permissions, the application will receive access denied errors even though the instance profile role has the correct permissions. The SDK does not fall back to the instance profile when explicit credentials are provided.

Why this answer

The AWS SDK credential provider chain checks environment variables before instance profile credentials. If the application sets AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY, those credentials are used exclusively. If they are expired or lack permissions, access is denied.

The solution is to remove the environment variables so the SDK uses the instance profile's temporary credentials.

Exam trap

The trap here is assuming that attaching an IAM role to an EC2 instance automatically overrides any manually configured credentials, when in fact explicit environment variables take precedence in the SDK's credential provider chain.

425
Multi-Selectmedium

A company wants to ensure that all Amazon S3 bucket policies comply with a security baseline that prohibits public read access. Which TWO methods can be used to detect non-compliant buckets? (Choose TWO.)

Select 2 answers
A.Enable AWS CloudTrail to monitor GetPublicAccessBlock calls.
B.Use IAM Access Analyzer to review bucket policies for public access.
C.Use Amazon Inspector to scan bucket policies.
D.Use AWS Config with the s3-bucket-public-read-prohibited managed rule.
E.Use AWS Trusted Advisor to check S3 bucket permissions.
AnswersB, D

IAM Access Analyzer is the correct tool here because it uses automated reasoning to analyze resource-based policies, including S3 bucket policies, and generates findings for any policy that grants access to principals outside your AWS account or organization. It specifically flags 'public' access when a bucket policy allows anonymous access (Principal: "*"), and it also surfaces cross-account access with detailed context about the external principal, actions, and resource. This allows you to review every bucket policy systematically and remediate unintended public exposure, making it a comprehensive policy-review solution.

Why this answer

IAM Access Analyzer reviews resource policies to identify resources shared with an external entity. For S3 buckets, it can analyze bucket policies and detect if they grant public read access (i.e., access to 'Principal': '*'). This directly identifies non-compliant buckets against the security baseline that prohibits public read access.

Exam trap

The trap here is that candidates may confuse AWS Trusted Advisor's 'S3 Bucket Permissions' check (which only flags buckets with open ACLs or bucket policies that allow 'Everyone' access) with a comprehensive detection of all public read access, but it does not catch all bucket policy configurations that grant public read access (e.g., via a principal like 'CanonicalUser' or a specific AWS account).

426
MCQmedium

A company has an S3 bucket that contains sensitive data. The security team wants to ensure that all access to the bucket is encrypted in transit. What is the most effective way to enforce this?

A.Enable default encryption on the S3 bucket using SSE-S3.
B.Enable AWS CloudTrail to log all S3 access and alert on non-HTTPS requests.
C.Add a bucket policy that denies access if the request does not use HTTPS (aws:SecureTransport condition).
D.Create an IAM policy that denies S3 actions without the condition aws:SecureTransport.
AnswerC

Adding a bucket policy with a Deny effect and the condition `aws:SecureTransport: false` will reject any request that is not sent over SSL/TLS. This is the most direct and comprehensive way to enforce HTTPS on S3 because the bucket policy is evaluated for every request to the bucket, regardless of which IAM principal, account, or anonymous user makes it. Using a resource-based policy at the bucket level also aligns with AWS best practices for S3 security and is the recommended mechanism to mandate encrypted connections.

Why this answer

A bucket policy with the aws:SecureTransport condition denies any request that does not use HTTPS, enforcing encryption in transit. Option A is incorrect because SSE-S3 only encrypts data at rest, not during transmission. Option B is incorrect because CloudTrail logs access but does not enforce encryption.

Option D is incorrect because an IAM policy can deny non-HTTPS requests, but enforcing this at the bucket policy level is more direct and applies to all principals accessing the bucket.

427
MCQmedium

During an incident response, a security engineer needs to preserve the state of an EC2 instance's root volume for forensic analysis. The instance is still running. Which action should be taken to ensure the data is preserved without altering it?

A.Stop the instance and then create an AMI.
B.Create a snapshot of the root volume.
C.Use dd if=/dev/xvda over SSH to copy the volume.
D.Detach the root volume and attach it to a forensics instance.
AnswerB

A snapshot is a point-in-time, crash-consistent copy of the EBS root volume that preserves the current on-disk state without stopping or detaching the instance. Taking a snapshot is the standard forensic first step because it is non-intrusive, does not trigger shutdown scripts, and keeps the original volume intact for later analysis while the snapshot can be inspected on a separate examination instance.

Why this answer

Creating a snapshot of the root volume is the correct action because it captures a point-in-time, crash-consistent copy of the volume's data without requiring the instance to be stopped or the volume to be detached. This preserves the current state of the running instance for forensic analysis while ensuring the data is not altered by the snapshot process itself, as AWS snapshots are read-only and do not modify the source volume.

Exam trap

The trap here is that candidates may think stopping the instance (Option A) is necessary to ensure data consistency, but they overlook that stopping alters the system state and that a snapshot of a running instance is still a valid, unaltered point-in-time copy for forensic purposes.

How to eliminate wrong answers

Option A is wrong because stopping the instance changes its state (e.g., flushes memory, stops processes) and may alter or lose volatile data that is critical for forensic analysis; creating an AMI from a stopped instance also introduces additional metadata and is not a direct, unaltered copy of the root volume. Option C is wrong because using dd over SSH to copy the root device (/dev/xvda) while the instance is running will result in an inconsistent copy due to ongoing writes, and it modifies the source volume by reading it, potentially triggering forensic concerns about data integrity and chain of custody. Option D is wrong because detaching the root volume from a running instance forces an immediate stop of the instance (since the root volume is required for operation), which alters the system state and may cause data loss or corruption; attaching it to a forensics instance then introduces the risk of write operations to the volume.

428
MCQhard

A company has a multi-account AWS environment with 50 accounts. The security team uses AWS CloudTrail to log management events in each account and delivers logs to a centralized S3 bucket in the security account. Recently, the team noticed that some CloudTrail logs are missing from the central bucket for a few accounts. The logs appear to be delivered intermittently. The security engineer checks the CloudTrail configuration in one of the affected accounts and sees that the trail is configured to deliver to the central bucket. The bucket policy in the security account allows CloudTrail to write from all accounts. The engineer also checks the CloudTrail console and sees that the trail status is 'Logging'. What is the MOST likely cause of the intermittent log delivery?

A.The S3 bucket has default encryption enabled, which interferes with CloudTrail writes.
B.The S3 bucket has a Lifecycle policy that deletes objects prematurely.
C.The CloudTrail trail is using Kinesis Data Firehose for delivery, which has a throughput limit.
D.The CloudTrail trail in each account is not associated with an SQS queue, causing delivery failures.
AnswerC

When a CloudTrail trail is configured to deliver to Kinesis Data Firehose, the logs are sent to a delivered stream that has a default throughput limit of 5,000 records per second and 5 MB per second. If the trail produces records faster than the stream can accept, Firehose throttles the producer, and CloudTrail can drop logs or mark delivery as failed for that interval. This perfectly explains intermittent missing logs, unlike the other options that would cause all-or-nothing or delayed effects.

Why this answer

The most likely cause is that the CloudTrail trail is configured to deliver logs via Kinesis Data Firehose, which has a throughput limit. If the volume of log data exceeds the Firehose stream's capacity, some logs may fail to be delivered, resulting in intermittent missing logs. Option A is incorrect because S3 default encryption (SSE-S3) does not interfere with CloudTrail writes; CloudTrail can write to encrypted buckets.

Option B is incorrect because a lifecycle policy deletes objects after they are stored, not during delivery, so it would not cause intermittent missing logs. Option D is incorrect because CloudTrail does not use SQS for log delivery; it delivers directly to S3 or via Firehose.

429
MCQhard

A company has a multi-account AWS environment using AWS Organizations. The security team has enabled AWS CloudTrail with an organization trail that delivers logs to a centralized S3 bucket in the management account. They have also enabled Amazon GuardDuty in all accounts. Recently, they noticed that some EC2 instances in a member account are exhibiting unusual network behavior, such as outbound traffic to known malicious IP addresses. The security engineer needs to quickly determine the source of the traffic and identify which EC2 instances are affected. The engineer has access to the management account and the member account. Which course of action should the engineer take to most efficiently investigate this incident?

A.Use AWS Config to review the configuration changes of the EC2 instances and identify any anomalies.
B.Use Amazon Detective to investigate the GuardDuty findings and analyze VPC Flow Logs to identify the affected instances.
C.Use Amazon Inspector to scan the EC2 instances for vulnerabilities and correlate with network traffic.
D.Query the VPC Flow Logs stored in the centralized S3 bucket using Amazon Athena to find the source IP and affected instances.
AnswerB

Amazon Detective is purpose-built for security investigations and natively integrates with GuardDuty findings. It automatically aggregates and correlates data from VPC Flow Logs, CloudTrail, and other sources, presenting a visual graph of resources, IP addresses, and behaviors. By launching an investigation from a GuardDuty finding, you can quickly scope the affected EC2 instances and analyze the associated flow log data without manual querying. This gives the most efficient and complete investigation pathway.

Why this answer

Amazon Detective is purpose-built to investigate and analyze GuardDuty findings, automatically ingesting VPC Flow Logs, CloudTrail, and GuardDuty data to build a behavior graph that pinpoints affected EC2 instances and traffic sources. It correlates the malicious-IP finding with the specific instance and network path in a few clicks, which is exactly the 'quickly determine source and affected instances' requirement. This is the most efficient investigative path because Detective already has the data pre-processed and linked to the finding.

Exam trap

SCS-C02 often tests whether candidates confuse vulnerability scanning (Inspector), configuration tracking (Config), and manual log querying (Athena) with the purpose-built threat investigation service (Detective) that automatically correlates GuardDuty findings with network and API activity.

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configuration changes and compliance, not network traffic or threat findings, so it cannot identify which instances are communicating with malicious IPs. Option C is wrong because Amazon Inspector performs vulnerability scanning of instances and does not analyze outbound network traffic or correlate with GuardDuty threat findings. Option D is wrong because querying VPC Flow Logs in S3 via Athena is a manual, slower approach that requires writing SQL, locating the right log partitions, and manually correlating IPs to instances — it lacks the automated finding-to-resource linkage that Detective provides.

430
MCQeasy

A company is required to audit all changes to IAM policies. Which AWS service should be used to record these changes?

A.AWS Config
B.Amazon CloudWatch Logs
C.Amazon S3
D.AWS CloudTrail
E.IAM Access Analyzer
AnswerD

AWS CloudTrail is the correct service because it captures management events as API activity, including all IAM policy changes such as PutRolePolicy, AttachUserPolicy, and CreatePolicyVersion. Each CloudTrail event records the requesting IAM principal, source IP address, event time, and request parameters, providing a complete, tamper-evident audit trail. You can query these events via the CloudTrail console, the LookupEvents API, or deliver them to S3 or CloudWatch Logs for long-term retention and automated alerting.

Why this answer

AWS CloudTrail is the correct service because it records API activity in your AWS account, including all IAM policy changes made via the AWS Management Console, SDKs, CLI, or AWS services. Each event is captured as a CloudTrail event with details such as the identity making the request, the time of the request, and the request parameters, enabling a complete audit trail of IAM policy modifications.

Exam trap

The trap here is that candidates often confuse AWS Config's ability to track configuration changes with CloudTrail's ability to record API-level audit trails, but Config only shows the state of resources over time without the identity and context of who made the change.

How to eliminate wrong answers

Option A is wrong because AWS Config is a configuration management service that evaluates resource configurations against desired policies and records configuration changes, but it does not capture the API-level audit trail of who made the change and when. Option B is wrong because Amazon CloudWatch Logs is used for monitoring, storing, and accessing log files from various sources, but it does not natively record IAM policy changes unless CloudTrail logs are sent to it. Option C is wrong because Amazon S3 is an object storage service that can store CloudTrail log files, but it does not itself record or generate audit logs of IAM policy changes.

Option E is wrong because IAM Access Analyzer helps identify resources shared with external entities by analyzing resource-based policies, but it does not record a history of policy changes.

431
MCQmedium

A security engineer needs to ensure that all traffic between two EC2 instances in different subnets is encrypted in transit. What is the most secure and efficient solution?

A.Configure network ACLs to allow traffic
B.Use VPC Peering
C.Set up an IPsec VPN between the instances
D.Configure security groups to allow traffic
AnswerC

An IPsec VPN creates an encrypted tunnel between the configured endpoints (here, the instances), typically using ESP in tunnel or transport mode to encrypt IP payloads and, when needed, the original IP header. It also provides mutual authentication, integrity checking, and anti-replay protection, ensuring all traffic between the instances is confidential and tamper-evident. This is the only option that actively encrypts the traffic itself.

Why this answer

An IPsec VPN between the two EC2 instances provides end-to-end encryption of all traffic at the network layer, regardless of the application protocol. This ensures that data in transit between the instances is encrypted using IPsec (ESP/AH), which is the most secure and efficient solution for encrypting traffic between two specific instances in different subnets without relying on the underlying network infrastructure.

Exam trap

The trap here is that candidates often confuse network-layer connectivity solutions (like VPC Peering or security groups) with encryption mechanisms, assuming that routing traffic through AWS's private network or allowing traffic via security groups inherently encrypts the data, when in fact neither provides encryption in transit.

How to eliminate wrong answers

Option A is wrong because network ACLs are stateless firewall rules that filter traffic based on IP addresses, ports, and protocols, but they do not provide any encryption of traffic in transit. Option B is wrong because VPC Peering connects two VPCs at the network layer using the AWS global network, but it does not encrypt traffic between instances; traffic is routed over the AWS backbone but remains unencrypted unless additional encryption (e.g., IPsec) is applied. Option D is wrong because security groups act as stateful virtual firewalls that control inbound and outbound traffic at the instance level, but they do not encrypt any data; they only permit or deny traffic based on rules.

432
MCQeasy

A security team wants to audit all changes to IAM policies in the AWS account. Which AWS service should be used to track these changes?

A.AWS Config
B.AWS Trusted Advisor
C.AWS CloudTrail
D.AWS CloudWatch Logs
AnswerC

AWS CloudTrail records every management API call made through the IAM service, including PutUserPolicy, PutRolePolicy, AttachUserPolicy, and DeleteUserPolicy, as management events. Each event contains the identity of the caller, the source IP address, the request parameters, and a timestamp, giving you a full, tamper-evident audit trail of IAM policy changes. By default, the event history is available for 90 days, and you can configure a trail to deliver events to S3 and CloudWatch Logs for long-term retention and analysis.

Why this answer

AWS CloudTrail records API activity in the account, including all IAM policy changes (CreatePolicy, PutRolePolicy, AttachPolicy, etc.), and delivers these events to an S3 bucket and optionally CloudWatch Logs. It is the authoritative service for auditing who changed what and when across AWS APIs. For IAM policy change auditing, CloudTrail is the correct and standard answer.

Exam trap

SCS-C02 often tests whether candidates confuse AWS Config (resource configuration history) with CloudTrail (API activity audit), causing them to pick Config when the question asks about tracking changes to IAM policies.

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configuration state and changes over time, but it is not the primary API-level audit trail for IAM policy modifications — CloudTrail captures the API calls themselves. Option B is wrong because Trusted Advisor provides best-practice checks and recommendations, not an audit log of changes. Option D is wrong because CloudWatch Logs is a log storage and analysis service; it can receive CloudTrail events but is not itself the audit source.

433
MCQhard

A security engineer is configuring Amazon Inspector to assess EC2 instances for software vulnerabilities. The engineer has installed the SSM Agent on all instances and ensured that the instances have internet access. However, Amazon Inspector shows the instances as 'Unmanaged'. What is the MOST likely cause?

A.The IAM role attached to the EC2 instance does not have permissions to publish metrics to CloudWatch.
B.The security group attached to the instance blocks outbound traffic to the Amazon Inspector service.
C.The instance does not have the EC2 instance metadata service enabled.
D.The SSM Agent is not running or is not registered with AWS Systems Manager.
AnswerD

Amazon Inspector is integrated with AWS Systems Manager Agent, which is responsible for collecting inventory and system configuration data from EC2 instances for assessment. For an instance to appear as 'Managed,' the SSM Agent must be running and registered with the Systems Manager service. If the agent is not running or not registered, Inspector cannot obtain the necessary telemetry and therefore reports the instance as 'Unmanaged.' This is the correct condition that explains the issue.

Why this answer

Amazon Inspector requires EC2 instances to be managed by AWS Systems Manager (SSM) to install the SSM Agent and register it with the Systems Manager service. If the SSM Agent is not running or not registered, the instance cannot communicate with Systems Manager, and Inspector will report it as 'Unmanaged'. Even with internet access and the agent installed, the agent must be actively running and registered for the instance to be properly managed.

Exam trap

The trap here is that candidates may assume internet access alone is sufficient for Inspector to work, overlooking the critical requirement that the SSM Agent must be actively running and registered with Systems Manager for the instance to be considered managed.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector does not require CloudWatch metrics publishing; it relies on Systems Manager for agent communication and assessment data. Option B is wrong because while outbound traffic to the Inspector service endpoints is necessary, the primary cause of 'Unmanaged' status is the SSM Agent registration failure, not security group rules blocking Inspector traffic specifically. Option C is wrong because the EC2 instance metadata service is used for instance identity and credentials, but its absence does not directly cause an 'Unmanaged' status in Inspector; the SSM Agent registration is the critical factor.

434
MCQmedium

A security engineer is setting up automated incident response for a compromised EC2 instance. The engineer wants to isolate the instance immediately upon detection of a GuardDuty finding. Which AWS service can be used to automatically trigger a Lambda function that modifies the instance's security group?

A.AWS Step Functions
B.Amazon Inspector
C.Amazon CloudWatch Events
D.AWS Config
AnswerC

Amazon CloudWatch Events (also known as Amazon EventBridge) is the native service that GuardDuty uses to emit findings as events. You create an event rule with a pattern that matches fields like the finding type or severity, and set a Lambda function as the target. This rule can invoke Lambda in near real time whenever a qualifying GuardDuty finding is generated, making it the correct foundational service for automated incident response.

Why this answer

Amazon CloudWatch Events (now part of Amazon EventBridge) can be configured with a rule that matches specific GuardDuty finding events. When a finding is detected, the rule triggers a Lambda function that can modify the EC2 instance's security group to isolate it, for example by removing all inbound rules or replacing the group with a restrictive one. This provides the automated, event-driven response required.

Exam trap

The trap here is that candidates may confuse Amazon Inspector (a vulnerability scanner) with GuardDuty (a threat detection service), or assume AWS Config's compliance rules can react to security findings, when in fact only CloudWatch Events/EventBridge provides the direct event-driven trigger for GuardDuty findings.

How to eliminate wrong answers

Option A is wrong because AWS Step Functions is a workflow orchestration service that coordinates multiple AWS services, but it is not directly triggered by GuardDuty findings; it would require an intermediary like CloudWatch Events to start the workflow. Option B is wrong because Amazon Inspector is a vulnerability assessment service that scans for software vulnerabilities and network exposure, not a real-time event trigger for incident response actions. Option D is wrong because AWS Config is a service for evaluating resource configurations against desired policies and tracking changes, but it cannot directly trigger a Lambda function in response to a GuardDuty finding; it uses rules that evaluate configuration changes, not security findings.

435
MCQhard

A company uses AWS CloudTrail to log all API calls. During an incident investigation, the security team needs to identify who deleted an S3 bucket. CloudTrail logs are stored in a centralized S3 bucket with server-side encryption using AWS KMS. Which additional step is required to ensure the CloudTrail logs can be queried quickly for this investigation?

A.Enable CloudTrail Lake
B.Stream logs to CloudWatch Logs and use CloudWatch Logs Insights
C.Use Amazon Athena with a table defined over the S3 bucket
D.Enable Amazon GuardDuty
AnswerC

Amazon Athena can query CloudTrail logs stored in S3 by defining a table over the bucket using the CloudTrail SerDe, with columns matching the JSON event structure and partitions for date/hour. The table is either created manually via a DDL statement or automatically by the 'Create Athena table' option in the CloudTrail console. Athena then runs standard SQL directly on the compressed log objects without moving or transforming the data, making it the simplest serverless way to search all API calls.

Why this answer

Amazon Athena allows you to query CloudTrail logs directly in S3 using standard SQL without needing to move or transform the data. Since the logs are already in a centralized S3 bucket, defining a table over that location enables fast, ad-hoc queries to identify the specific DeleteBucket event, including who performed it and when. This approach is cost-effective and avoids additional streaming or storage costs.

Exam trap

The trap here is that candidates often assume CloudTrail logs must be streamed to CloudWatch Logs for querying, but Athena provides a more direct and cost-effective solution for querying historical logs stored in S3 without additional streaming overhead.

How to eliminate wrong answers

Option A is wrong because CloudTrail Lake is a managed data lake for CloudTrail logs that requires ingesting logs into a separate event data store, which adds cost and complexity; it is not necessary for querying existing logs in S3. Option B is wrong because streaming logs to CloudWatch Logs incurs additional costs and latency, and CloudWatch Logs Insights is designed for real-time monitoring of operational metrics, not for deep forensic analysis of historical S3 bucket deletions. Option D is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail management events for anomalies, but it does not provide a direct query interface to search for specific historical events like who deleted an S3 bucket.

436
MCQeasy

A developer needs to grant an EC2 instance read-only access to an S3 bucket. Which of the following is the most secure way to provide these permissions?

A.Use an IAM role and store the credentials in AWS Systems Manager Parameter Store, then retrieve them at instance launch.
B.Create an IAM role with read-only access and attach it to the EC2 instance profile.
C.Create a bucket policy that grants read-only access to the instance's public IP address.
D.Create an IAM user with read-only access and store the access keys in the instance's user data.
AnswerB

An IAM role attached to the instance profile supplies temporary, automatically rotated credentials to the EC2 instance, avoiding long-term access keys on the instance. This satisfies the requirement for read-only S3 access using the most secure mechanism.

Why this answer

Using an IAM role attached to an instance profile grants temporary credentials and eliminates long-term access keys. Option A is incorrect because storing credentials in Parameter Store (or any static storage) is less secure than using an instance profile, and IAM roles do not have static credentials to store. Option C is incorrect because a bucket policy cannot grant access based on an instance's public IP in a secure or reliable way, and it would grant access to anyone with that IP, not just the instance.

Option D is incorrect because storing IAM user access keys in user data exposes long-term credentials, which is less secure than using an instance profile.

437
MCQhard

Refer to the exhibit. An organization applies this SCP to an OU containing a developer account. A developer in that account tries to launch an m5.large instance using the AWS Management Console. What is the outcome?

A.The instance launches successfully because the SCP only applies to StartInstances, not RunInstances.
B.The launch fails because the SCP denies RunInstances for instance types other than t2.micro and t2.small.
C.The instance launches successfully because the SCP does not explicitly allow any actions.
D.The launch fails only if the developer's IAM policy also denies the action.
AnswerB

The SCP uses a condition such as ec2:InstanceType StringNotEquals t2.micro,t2.small. For an m5.large launch, the condition evaluates to true because m5.large is not in the allowed list, so the Deny statement applies and the RunInstances call is explicitly denied. The launch fails because the requested instance type does not match the only two approved types, regardless of any IAM policy that might allow it.

Why this answer

The SCP explicitly denies the ec2:RunInstances action when the condition key ec2:InstanceType does not match t2.micro or t2.small. Since m5.large is not in the allowed list, the deny effect applies, and the launch fails regardless of any IAM policy that might allow it. SCPs act as a guardrail that overrides IAM permissions, so even if the developer has full IAM access, the SCP blocks the operation.

Exam trap

The trap here is that candidates confuse SCPs with IAM policies, thinking an explicit allow in IAM can override an SCP deny, but SCPs act as a boundary that cannot be bypassed by any IAM permission.

How to eliminate wrong answers

Option A is wrong because the SCP explicitly denies ec2:RunInstances, not just ec2:StartInstances; the exhibit shows 'Deny' for RunInstances with a condition on instance type. Option C is wrong because SCPs do not need to explicitly allow actions; they default to allowing all actions unless a deny is applied, and here a deny is applied for non-compliant instance types. Option D is wrong because SCPs are evaluated before IAM policies; a deny in an SCP cannot be overridden by an IAM allow, so the launch fails regardless of the developer's IAM policy.

438
MCQeasy

A company needs to share an encrypted Amazon S3 object with another AWS account. The object is encrypted with an AWS KMS customer managed key. Which steps are required?

A.Use an object ACL to grant the other account read access.
B.Update both the bucket policy and the KMS key policy to grant cross-account access.
C.Update the bucket policy to allow the other account to access the object.
D.Update the KMS key policy to allow the other account to decrypt.
AnswerB

The correct cross-account configuration requires two resource-based policies that address separate authorization layers: the bucket policy must explicitly allow the external account's principal to call s3:GetObject on the object, and the KMS key policy must explicitly allow that same external principal to call kms:Decrypt. The bucket policy authorizes the S3 data-plane operation, while the KMS key policy authorizes the cryptographic operation that S3 performs on the requester's behalf. Without either policy, the request fails because the external account is not part of the key owner's account and cross-account access is denied by default.

Why this answer

Cross-account access to a KMS-encrypted S3 object requires permissions on both sides: the S3 bucket policy must grant the external account s3:GetObject, and the KMS key policy must grant that account kms:Decrypt. Without the KMS key policy update, the external account's request fails with AccessDenied even if the bucket policy allows it, because S3 delegates decryption authorization to KMS.

Exam trap

SCS-C02 often tests the misconception that a bucket policy alone is sufficient for cross-account access to KMS-encrypted objects, ignoring the separate KMS key policy authorization boundary.

How to eliminate wrong answers

Option A is wrong because S3 object ACLs do not grant KMS decrypt permissions — ACLs only control S3-level access, and KMS-encrypted objects still require kms:Decrypt on the key. Option C is wrong because updating only the bucket policy is insufficient; the KMS key policy must also authorize the external account, otherwise decryption fails. Option D is wrong because updating only the KMS key policy without the bucket policy leaves the S3 GetObject call unauthorized.

439
Multi-Selectmedium

A security engineer is designing a governance framework for a multi-account AWS environment. The engineer needs to ensure that all accounts comply with the principle of least privilege for IAM roles and that any non-compliant resources are automatically reported. Which two AWS services should the engineer use together to achieve this? (Choose TWO.)

Select 2 answers
A.AWS Security Hub
B.AWS Service Catalog
C.Amazon GuardDuty
D.AWS Config
E.AWS CloudTrail
AnswersA, D

AWS Security Hub is the correct choice because it provides a centralized view of security and compliance posture across AWS accounts. It ingests and aggregates findings from AWS Config, including IAM role compliance checks, and continuously runs controls from frameworks like CIS AWS Foundations Benchmark and AWS Foundational Security Best Practices. This allows a security engineer to create a governance framework that monitors IAM roles against least-privilege policies, with automated compliance reporting and a unified dashboard. Security Hub also integrates with AWS Organizations to aggregate findings from multiple accounts, making it the appropriate service for enterprise-wide IAM governance.

Why this answer

AWS Security Hub is correct because it provides a comprehensive view of security alerts and compliance status across multiple AWS accounts, aggregating findings from various AWS services and third-party tools. AWS Config is correct because it continuously monitors and records AWS resource configurations, enabling you to define rules (e.g., IAM least privilege policies) and automatically evaluate resource compliance, triggering notifications or remediation actions for non-compliant resources. Together, Security Hub can ingest AWS Config rule compliance results as findings, allowing centralized reporting and automated response to IAM role violations.

Exam trap

The trap here is that candidates often confuse AWS Config (resource compliance evaluation) with AWS CloudTrail (API activity logging) or Amazon GuardDuty (threat detection), failing to recognize that only AWS Config can directly assess IAM role configurations against least privilege rules and automatically report non-compliance.

440
MCQmedium

A security engineer is investigating a potential data exfiltration incident. The engineer needs to determine whether an IAM user in account A accessed an S3 bucket in account B. The engineer has access to both accounts. Which combination of steps should the engineer take to identify the cross-account access?

A.Enable S3 server access logging on the bucket in account B and check the logs.
B.Enable CloudTrail in account B and check the S3 event history for the bucket.
C.Enable CloudTrail in account A and check the S3 event history.
D.Enable CloudWatch Logs in account A and check the S3 access logs.
AnswerB

CloudTrail in account B, the bucket owner account, is the authoritative audit trail for S3 API calls made against the bucket. When you enable CloudTrail with S3 data events for the bucket, every cross-account request from account A generates an event that includes the full userIdentity ARN of the calling IAM user or role. The event record also contains the source IP address, the event name (e.g., GetObject), and the bucket ARN, allowing you to trace exactly which IAM identity performed the suspected exfiltration. This is the only option that gives you the complete identity-level detail required for the investigation.

Why this answer

To identify cross-account access to an S3 bucket, enable CloudTrail in the account that owns the bucket (account B) and configure a trail with data events for S3 object-level operations. This captures the IAM user ARN from account A in the CloudTrail event. S3 server access logging (Option A) can also provide similar details, but CloudTrail is the recommended approach for auditing API calls.

Ensure data events are enabled for the bucket.

Exam trap

Candidates often think enabling CloudTrail in the source account (account A) will capture cross-account S3 access, but CloudTrail logs are per-account and per-region, so the data event must be logged in the account that owns the resource (account B). Additionally, remember to enable S3 data events in CloudTrail; otherwise, object-level operations will not be logged.

How to eliminate wrong answers

Option A is wrong because enabling S3 server access logging on the bucket in account B would capture the access, but it requires configuring a target bucket and waiting for logs to be delivered, which is not the immediate step described; the question asks for a combination of steps, and CloudTrail is the more direct and commonly used method for cross-account access identification. Option C is wrong because CloudTrail in account A logs API calls made by users in account A, but it does not capture the S3 data plane events on the bucket in account B; those events are logged in account B's CloudTrail. Option D is wrong because CloudWatch Logs in account A does not natively capture S3 access logs; S3 access logs are delivered to a target S3 bucket, not directly to CloudWatch Logs, and even if they were, they would be in account B's logs, not account A's.

441
MCQmedium

A company has a web application running on EC2 instances behind an Application Load Balancer (ALB). The application uses a custom header X-Auth-Token to authenticate requests. The security team wants to use AWS WAF to block requests that do not contain this header or contain an invalid token. The WAF is associated with the ALB. The team creates a rule with a match condition that checks for the presence of the X-Auth-Token header and a regex pattern for the token value. However, the rule is not blocking any requests. What is the most likely cause?

A.AWS WAF is not supported for Application Load Balancers; it only supports CloudFront.
B.AWS WAF cannot inspect custom headers; it can only inspect standard HTTP headers.
C.The regex pattern for the token is too complex for AWS WAF to process.
D.There is an allow rule with a higher priority that allows all requests before the block rule is evaluated.
AnswerD

AWS WAF evaluates rules in ascending priority order, where lower numeric priority values are evaluated first. If a higher-priority allow rule (e.g., priority 0) matches all requests and is set to 'Allow', the web ACL immediately stops evaluating remaining rules, so a lower-priority block rule (e.g., priority 1) is never reached. The presence of such a broad allow rule fully explains why requests are not blocked, even when the block rule itself is properly configured.

Why this answer

AWS WAF evaluates rules in priority order, and the first rule that matches determines the action. If an allow rule with a lower number (higher priority) matches all requests, the block rule is never evaluated. Therefore, the most likely cause is that an allow rule with higher priority is permitting all traffic before the block rule can inspect the header.

Exam trap

SCS-C02 often tests the misconception that AWS WAF cannot inspect custom headers or that rule order doesn't matter; candidates must remember that rule priority and action determine whether a block rule is ever reached.

How to eliminate wrong answers

Option A is wrong because AWS WAF is supported on Application Load Balancers, not just CloudFront. Option B is wrong because AWS WAF can inspect custom headers; it supports all HTTP headers including custom ones. Option C is wrong because AWS WAF regex patterns have limits but complexity is rarely the cause of no blocking; the service would return an error if the pattern were invalid.

442
MCQhard

Refer to the exhibit. An IAM policy allows running EC2 instances. A developer tries to launch a t2.micro instance but receives an 'AccessDenied' error. What is the most likely reason?

A.The policy does not grant permissions for other required resources such as images or security groups.
B.The developer is trying to launch a different instance type.
C.The region in the policy does not match the developer's region.
D.The policy has an explicit deny elsewhere.
AnswerA

Launching an EC2 instance requires more than the `ec2:RunInstances` action; the policy must also allow dependent resources. The `RunInstances` call authorises each referenced AMI, security group, subnet and key pair, so a policy granting only the run action fails with `AccessDenied` when those resource-level permissions are absent.

Why this answer

Even though the policy allows the ec2:RunInstances action on the instance resource, the RunInstances API call requires permissions for other resources such as Amazon Machine Images (AMI), security groups, and key pairs. Without explicit permissions for these resources, the API call fails with an AccessDenied error. Option B is incorrect because the condition specifies t2.micro, matching the developer's request.

Option C is incorrect because the policy does not restrict by region. Option D is incorrect because there is no explicit deny; the denial is due to missing resource permissions.

443
MCQhard

A company uses AWS CloudHSM to store encryption keys for a custom database encryption application. The application runs on Amazon EC2 instances and uses the PKCS#11 library to communicate with the HSM. Recently, the application started failing with 'CKR_SESSION_HANDLE_INVALID' errors. Which of the following is the most likely cause?

A.The client certificate used for mutual TLS authentication has expired
B.The security group for the HSM does not allow inbound traffic from the EC2 instance
C.The application is not closing sessions properly, causing the HSM to reach the maximum number of open sessions
D.The HSM's firmware version is incompatible with the PKCS#11 library
AnswerC

PKCS#11 sessions on a CloudHSM are finite, and each session handle is valid only until C_CloseSession or C_Finalize is called. An application that fails to close sessions leaks them, and once the HSM client's session limit is reached, any handle retained from an evicted or expired session returns CKR_SESSION_HANDLE_INVALID on subsequent operations. This is the correct explanation: the root cause is session lifecycle mismanagement, not network or identity configuration, and the fix is to use try-with-resources or a session pool that guarantees C_CloseSession in all code paths.

Why this answer

CKR_SESSION_HANDLE_INVALID is a PKCS#11 error indicating that the session handle used by the application is no longer valid. This typically occurs when the application opens sessions but fails to close them, eventually exhausting the HSM's maximum session limit. Once the limit is reached, new session requests fail or existing handles become invalid.

Proper session management (closing sessions after use) is required to avoid this error.

Exam trap

The trap is confusing network or authentication errors with PKCS#11 session errors — candidates may pick security group or certificate issues, but the specific error code CKR_SESSION_HANDLE_INVALID points directly to session management on the HSM.

How to eliminate wrong answers

Option A is wrong because an expired client certificate would cause TLS handshake failures or authentication errors, not a PKCS#11 session handle error — the application would not even establish a connection to the HSM. Option B is wrong because a security group blocking inbound traffic would prevent the EC2 instance from connecting to the HSM at all, resulting in connection timeouts or network errors, not CKR_SESSION_HANDLE_INVALID. Option D is wrong because firmware incompatibility would typically cause different errors (e.g., CKR_DEVICE_ERROR or CKR_FUNCTION_NOT_SUPPORTED) and would affect all operations consistently, not manifest as invalid session handles.

444
MCQhard

A security engineer runs the get-account-authorization-details command and sees the exhibit output. The engineer wants to ensure that the 'admin' user does not have administrative access. Which steps should be taken?

A.Delete the 'admin' user and create a new user with limited permissions.
B.Modify the AdministratorAccess policy to deny all actions.
C.Detach the AdministratorAccess policy from the 'admin' user and attach a custom policy with read-only permissions.
D.Attach a permissions boundary that denies all actions.
AnswerC

Detaching the AdministratorAccess policy from the 'admin' user directly removes the administrative privilege, while attaching a custom read-only policy grants only the permissions needed for the user's job — a least-privilege approach. The user keeps its IAM identity, credentials, MFA, and other configuration, making this the minimal, reversible change. This should be combined with a review of the custom policy's actions and resources to ensure it truly limits access to read-only APIs.

Why this answer

The 'admin' user has the AdministratorAccess policy attached, granting full administrative rights. To remove administrative access, the engineer should detach this policy and attach a custom policy with read-only permissions (Option C). Option A is unnecessary because deleting the user is not required; detaching the policy is sufficient.

Option B is incorrect because modifying the AdministratorAccess policy to deny all actions would still leave the policy attached, potentially causing confusion or unintended effects; better to detach it. Option D is wrong because attaching a permissions boundary does not remove the existing AdministratorAccess policy; the user would still have administrative access via that policy.

445
MCQmedium

A security engineer is investigating a potential security incident involving an EC2 instance. The engineer needs to capture network traffic to and from the instance for analysis. Which method should be used to capture this traffic without installing any software on the instance?

A.Enable VPC Flow Logs for the subnet.
B.Configure AWS Network Firewall in the VPC.
C.Install the Amazon CloudWatch agent on the instance.
D.Use VPC Traffic Mirroring.
AnswerD

VPC Traffic Mirroring copies live traffic from Elastic Network Interfaces and forwards it to a chosen monitoring appliance or security tool, such as a customer-managed NGFW or packet analyzer, using VXLAN-encapsulated tunnels. It captures full packet content, including headers and payload, without requiring any software installation on the source instance and without impacting the production traffic path. This makes it the correct choice for deep packet inspection and forensic analysis of network traffic.

Why this answer

VPC Traffic Mirroring captures and inspects network traffic at the Elastic Network Interface (ENI) level without requiring any software installation on the EC2 instance. It copies traffic from a source ENI to a target, such as a Network Load Balancer or another ENI, for analysis by security appliances. This meets the requirement of capturing traffic without installing software on the instance.

Exam trap

The trap here is confusing VPC Flow Logs (metadata only) with full packet capture; candidates often pick VPC Flow Logs because they are a familiar logging feature, but they lack the payload data needed for deep packet analysis.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture metadata (source/destination IP, ports, protocol, packet count) but not the actual packet payload, so they cannot provide full network traffic for analysis. Option B is wrong because AWS Network Firewall inspects traffic passing through the firewall but does not capture or mirror traffic to/from a specific EC2 instance for out-of-band analysis. Option C is wrong because the Amazon CloudWatch agent collects OS-level metrics and logs, not network packet captures, and installing it would violate the 'without installing any software' constraint.

446
MCQmedium

A company has enabled AWS Config to record resource changes. The security team needs to be notified when a security group is modified to allow inbound SSH from 0.0.0.0/0. Which AWS service should be used to evaluate the Config rules and trigger notifications?

A.AWS Lambda
B.AWS Security Hub
C.Amazon GuardDuty
D.AWS CloudTrail
E.AWS Config with a custom rule that triggers an SNS notification
AnswerE

AWS Config records resource configuration changes and can evaluate those changes against rules that define desired configurations. A custom rule implemented as a Lambda function returns a compliance status based on a configuration item, and AWS Config can publish the result to an SNS topic when a resource becomes noncompliant. This combination enables real-time notification and corrective workflow each time a configuration change occurs, which is exactly what the requirement needs.

Why this answer

AWS Config with a custom rule is the correct choice because it allows you to define a custom Lambda-backed rule that evaluates security group configurations against the condition of allowing inbound SSH (port 22) from 0.0.0.0/0. When the rule detects non-compliance, it can directly trigger an Amazon SNS notification to alert the security team. This is the native AWS Config mechanism for custom evaluations and notifications, without requiring additional services.

Exam trap

The trap here is that candidates often confuse AWS Config's built-in managed rules (which do not support custom SNS triggers) with the need for a separate service like Lambda or Security Hub, but the correct answer is AWS Config with a custom rule that directly integrates SNS notifications.

How to eliminate wrong answers

Option A is wrong because AWS Lambda is a compute service that can run code but does not itself evaluate Config rules or trigger notifications; it would need to be integrated as part of a custom Config rule or invoked separately. Option B is wrong because AWS Security Hub aggregates security findings from multiple services but does not evaluate AWS Config rules or directly trigger notifications for specific resource changes. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes network traffic and logs for malicious activity, not for evaluating security group configuration changes.

Option D is wrong because AWS CloudTrail records API activity for auditing but does not evaluate resource configurations or trigger notifications based on compliance rules.

447
MCQeasy

A company wants to allow a Lambda function to read objects from an S3 bucket in the same account. What should be done?

A.Store IAM user access keys in the Lambda function's environment variables.
B.Create an IAM role with an S3 read policy and attach it to the Lambda function.
C.Add a bucket policy allowing s3:GetObject for the Lambda service principal.
D.Configure the S3 bucket to be public.
AnswerB

Create an IAM role with a policy allowing s3:GetObject on the specific bucket and object ARNs, then set that role as the Lambda function's execution role. The role's trust policy must allow lambda.amazonaws.com to assume it, after which Lambda calls STS to receive temporary credentials scoped to that role. These credentials are automatically rotated and passed to the AWS SDK, making this the least-privilege, auditable way to grant the function read access to S3.

Why this answer

Lambda functions require an IAM role (execution role) to obtain temporary AWS credentials via the AWS Security Token Service (STS). Attaching a policy with s3:GetObject permissions to this role grants the Lambda function the necessary access to read objects from the S3 bucket without hardcoding long-term credentials.

Exam trap

The trap here is that candidates confuse the Lambda service principal (lambda.amazonaws.com) with the Lambda execution role, incorrectly assuming that a bucket policy can grant access directly to the Lambda service rather than to the IAM role that the Lambda function assumes.

How to eliminate wrong answers

Option A is wrong because storing IAM user access keys in environment variables violates security best practices (long-term credentials are exposed and must be rotated manually), and Lambda natively supports temporary credentials via an execution role. Option C is wrong because a bucket policy that grants s3:GetObject to the Lambda service principal (lambda.amazonaws.com) does not work—the service principal cannot be used as a grantee in a resource-based policy; instead, you must specify the IAM role ARN or the AWS account root user. Option D is wrong because making the S3 bucket public exposes all objects to the internet, which is a severe security risk and unnecessary when a properly scoped IAM role can grant access only to the Lambda function.

448
MCQhard

A security engineer needs to grant a third-party auditor read-only access to specific AWS Config compliance data in a production account for 30 days. The auditor uses their own AWS account and must not be able to modify any resources or view unrelated data. The security engineer wants to avoid creating IAM users in the production account. Which approach BEST satisfies these requirements?

A.Create an IAM role in the production account with a trust policy allowing the auditor's account and attach a policy granting config:Describe* and config:Get* actions, then provide the role ARN to the auditor.
B.Attach a resource-based policy to the production account's AWS Config service-linked role permitting the auditor's account principal to call config:GetComplianceDetailsByConfigRule.
C.Create an IAM user in the production account for the auditor with a read-only managed policy and enable MFA, sharing credentials securely for the 30-day period.
D.Share the production account's AWS Config data by enabling an AWS Config aggregator in the auditor's account and authorizing the production account as a source account.
AnswerA

Cross-account IAM roles allow the auditor to assume a role in the production account without creating local IAM users. Attaching only Config read actions enforces least privilege, and the trust policy scopes access to the auditor's account. This meets the no-local-users requirement while limiting permissions to compliance data retrieval only, which is exactly what the scenario asks for.

Why this answer

A cross-account IAM role with a trust policy scoped to the auditor's account and permissions limited to AWS Config read actions provides temporary, least-privilege access without creating local IAM users. The auditor assumes the role using their own credentials. Aggregators, service-linked role modifications, and local IAM users either fail to grant the needed access, broaden exposure, or violate the no-local-user constraint.

Exam trap

The trap here is assuming AWS Config aggregators grant external parties direct read access, when they only consolidate data for the aggregator owner.

449
MCQmedium

An organization wants to enforce multi-factor authentication (MFA) for all IAM users who perform sensitive actions. Which condition key should be used in an IAM policy to require MFA?

A.aws:SourceIp
B.aws:MultiFactorAuthPresent
C.aws:UserAgent
D.aws:CurrentTime
AnswerB

aws:MultiFactorAuthPresent is the correct global condition key because it is a Boolean request context key that indicates whether the principal authenticated with an MFA device. By adding a condition such as "Bool": {"aws:MultiFactorAuthPresent": "true"} to an IAM policy, administrators can require every matching request to come from a session that has completed MFA. This directly enforces the organization's MFA requirement and cannot be substituted by IP, client, or time-based checks.

Why this answer

The condition key 'aws:MultiFactorAuthPresent' is used in IAM policies to check whether the principal authenticated with MFA. When set to 'true' in a policy condition, it requires that the user has presented a valid MFA token for the request to be allowed, making it the correct choice for enforcing MFA on sensitive actions.

Exam trap

The trap is confusing 'aws:MultiFactorAuthPresent' with other condition keys like 'aws:SourceIp' or 'aws:CurrentTime', or not realizing that it only works with temporary credentials, leading to ineffective MFA enforcement.

How to eliminate wrong answers

Option A is wrong because 'aws:SourceIp' restricts access based on the source IP address, not MFA status. Option C is wrong because 'aws:UserAgent' checks the user agent string of the client, which is not related to MFA. Option D is wrong because 'aws:CurrentTime' restricts access based on the current date and time, not MFA.

450
MCQeasy

A security engineer is investigating a potential data breach. The engineer needs to identify which IAM user accessed a specific S3 object and when. Which AWS service should the engineer use?

A.AWS Config
B.Amazon S3 server access logs
C.AWS CloudTrail
D.Amazon CloudWatch Logs
AnswerC

AWS CloudTrail is the correct answer because it is the only service that records API activity as data events for S3, and by default (when data events are enabled) it captures the exact IAM user principal, source IP address, user agent, request parameters, and timestamp for actions like GetObject and PutObject. This enables the security engineer to create a complete audit trail of who accessed a specific S3 object and when, which is precisely what is needed in a breach investigation. CloudTrail also integrates with CloudWatch Logs for alerting and can deliver to a separate S3 bucket or a security data lake, but its core value here is the user-level accountability it provides for object-level operations.

Why this answer

AWS CloudTrail is the correct service because it records API activity for all AWS services, including S3 object-level operations such as GetObject, PutObject, and DeleteObject. By enabling data events on the specific S3 bucket, CloudTrail logs the IAM user, source IP, timestamp, and the exact object key accessed, providing the precise identity and time needed for breach investigation.

Exam trap

The trap here is that candidates confuse S3 server access logs (which show HTTP-level requests but lack IAM user identity) with CloudTrail (which captures the full IAM user context via the AWS API), leading them to incorrectly select Amazon S3 server access logs.

How to eliminate wrong answers

Option A is wrong because AWS Config evaluates resource configurations and compliance rules, not API-level access logs; it cannot show which user accessed a specific S3 object or when. Option B is wrong because Amazon S3 server access logs record HTTP requests to the bucket at the object level, but they log the requester's AWS account ID or anonymous identifier, not the IAM user ARN, making it impossible to tie the access to a specific IAM user. Option D is wrong because Amazon CloudWatch Logs is a centralized log storage and monitoring service, not a source of API activity logs; it can ingest CloudTrail logs but does not generate the access records itself.

Page 5

Page 6 of 17

Page 7