Courseiva

AWS Certified Security Specialty SCS-C02 (SCS-C02) — Questions 451–525

1205 questions total · 17pages · All types, answers revealed

Page 6

Page 7 of 17

Page 8
451
MCQmedium

Refer to the exhibit. An IAM policy is attached to an IAM user. The user reports that they can upload objects to the S3 bucket but cannot list the contents of the bucket. Which statement explains this behavior?

A.The policy does not include the s3:ListBucket action.
B.The policy includes s3:ListBucket but is missing the bucket ARN.
C.The policy denies the s3:ListBucket action.
D.The policy explicitly denies s3:ListBucket.
AnswerA

The attached IAM policy only grants s3:PutObject and s3:GetObject; it does not contain a statement allowing s3:ListBucket. Listing the objects in an S3 bucket is a bucket-level permission that requires s3:ListBucket on the bucket ARN (e.g., arn:aws:s3:::example-bucket). Because no Allow exists for that action, IAM's default-deny rule causes list requests to fail, even though the user can still upload and download objects.

Why this answer

The IAM policy grants the s3:PutObject action, which allows the user to upload objects, but it does not include the s3:ListBucket action. The s3:ListBucket action is required to list the contents of an S3 bucket (e.g., via the ListObjects API call). Without this permission, the user can upload but cannot see the bucket's object listing.

Exam trap

The trap here is that candidates often confuse an implicit deny (missing allow) with an explicit deny, or assume that the s3:PutObject action implicitly grants listing permissions, which it does not.

How to eliminate wrong answers

Option B is wrong because if the policy included s3:ListBucket but was missing the bucket ARN, the action would not apply to the specific bucket, resulting in a deny by default (implicit deny), not a successful upload with failed listing. Option C is wrong because an implicit deny (lack of allow) is not the same as an explicit deny; the policy does not contain a Deny statement for s3:ListBucket. Option D is wrong because an explicit deny would require a Deny effect statement for s3:ListBucket, which is not present in the policy; the behavior is due to missing allow, not an explicit deny.

452
MCQmedium

A company uses Amazon GuardDuty for threat detection. The security team wants to automatically isolate an EC2 instance that is communicating with a known malicious IP address. Which combination of services should be used?

A.GuardDuty -> AWS Config -> Lambda -> modify security group
B.GuardDuty -> CloudWatch Alarm -> Lambda -> modify security group
C.GuardDuty -> EventBridge -> Lambda -> modify security group
D.GuardDuty -> AWS Shield -> modify security group
E.GuardDuty -> AWS Systems Manager -> modify security group
AnswerC

GuardDuty findings are delivered as events to Amazon EventBridge, which matches the malicious-IP finding type and invokes a Lambda function. Lambda then modifies the instance's security group, removing outbound access and satisfying the automated isolation requirement without terminating the instance or disrupting forensic evidence.

Why this answer

Amazon GuardDuty generates findings that can be sent to Amazon EventBridge as events. EventBridge can then trigger an AWS Lambda function that modifies the security group associated with the EC2 instance to deny traffic to/from the malicious IP address. This architecture provides a serverless, event-driven response mechanism without polling or additional services.

Exam trap

The trap here is that candidates confuse CloudWatch Alarms with EventBridge, not realizing that GuardDuty findings are event-driven and require a rule-based event bus (EventBridge) rather than a metric-based alarm (CloudWatch Alarm) to trigger remediation.

How to eliminate wrong answers

Option A is wrong because AWS Config is a configuration compliance and resource inventory service, not an event-driven trigger for real-time threat response; it cannot directly forward GuardDuty findings to Lambda. Option B is wrong because CloudWatch Alarms are designed for metric-based thresholds (e.g., CPU utilization), not for receiving structured JSON findings from GuardDuty; GuardDuty does not natively publish to CloudWatch Alarms. Option D is wrong because AWS Shield is a DDoS protection service and does not process GuardDuty findings or modify security groups.

Option E is wrong because AWS Systems Manager is an operations management service for patching and automation, not designed to consume GuardDuty findings in real time for security group modifications.

453
Multi-Selectmedium

A company is designing a centralized logging solution for multiple AWS accounts. The solution must meet the following requirements: 1) Logs from all accounts must be stored in a centralized S3 bucket. 2) The logs must be encrypted at rest using AWS KMS. 3) Access to the logs must be logged and monitored. Which TWO services should be used to meet the requirements? (Choose TWO.)

Select 2 answers
A.Amazon GuardDuty
B.AWS CloudTrail
C.Amazon Macie
D.S3 server access logs
E.AWS Config
AnswersB, D

CloudTrail is the correct service for centralized logging because it can be configured in an organization to deliver management (and optionally data) events from all member accounts into a single organization-level S3 bucket, providing a durable, immutable, and centralized audit trail. With CloudTrail organization trails, log files from every account are delivered to a common prefix structure, enabling unified compliance analysis and searchable history. This direct S3 delivery is the standard pattern for building a centralized multi-account logging solution.

Why this answer

AWS CloudTrail is correct because it can be configured to deliver log files from multiple AWS accounts into a single centralized S3 bucket, meeting the requirement for centralized logging. It also integrates with AWS KMS to encrypt the log files at rest using customer-managed keys, satisfying the encryption requirement.

Exam trap

The trap here is that candidates often confuse services that generate logs (like CloudTrail) with services that monitor or analyze logs (like GuardDuty or Macie), or they overlook that S3 server access logs are needed specifically to meet the requirement for logging and monitoring access to the centralized bucket.

454
Multi-Selectmedium

Which TWO actions can be performed using AWS IAM? (Choose two.)

Select 2 answers
A.Change the instance type of an RDS database
B.Create a CloudFront distribution
C.Define a password policy for IAM users
D.Create an IAM role with a trust policy for EC2
E.Configure a VPC peering connection
AnswersC, D

Defining an account password policy is a core IAM feature: IAM provides the UpdateAccountPasswordPolicy API and a dedicated console page to enforce policies such as minimum password length, complexity, expiration, and reuse prevention for all IAM users. This policy is stored and enforced by the IAM service as part of its identity-management responsibilities. Since IAM directly manages user credentials, password policy configuration is one of the two actions correctly performed using AWS IAM.

Why this answer

AWS IAM allows you to define a password policy for IAM users, which enforces complexity requirements, rotation periods, and reuse prevention. This is a core IAM feature that helps secure user credentials without relying on external identity providers.

Exam trap

The trap here is that candidates confuse IAM's authorization capabilities (granting permissions) with the ability to directly perform resource operations, leading them to select options like A, B, or E that are actual AWS actions but are not performed by IAM itself.

455
MCQeasy

A security engineer notices that an IAM role used by an EC2 instance is generating a large number of API calls to an S3 bucket that is not part of the company's account. Which AWS service should be used to detect and alert on this suspicious activity?

A.AWS CloudTrail
B.Amazon Inspector
C.AWS Config
D.Amazon GuardDuty
AnswerD

Amazon GuardDuty continuously analyses CloudTrail management and S3 data events, VPC Flow Logs and DNS logs using threat intelligence and machine learning to surface anomalous behaviour. It specifically detects EC2 instance credential compromise and calls to unrecognised or malicious S3 buckets, satisfying the requirement to detect and alert on this suspicious cross-account activity.

Why this answer

Amazon GuardDuty is the correct service because it uses machine learning and anomaly detection to analyze AWS CloudTrail management and data events, VPC Flow Logs, and DNS logs. It can detect unusual API calls, such as an EC2 instance role making a high volume of requests to an S3 bucket outside the company's account, which is a classic indicator of compromised credentials or data exfiltration. GuardDuty generates findings and can integrate with Amazon CloudWatch Events to trigger alerts or automated remediation.

Exam trap

The trap here is that candidates often confuse CloudTrail (which logs the activity) with GuardDuty (which analyzes and alerts on the activity), leading them to select CloudTrail because they think logging alone is sufficient for detection, but GuardDuty is the service specifically designed for threat detection and alerting.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail is a logging service that records API calls, but it does not perform real-time detection, analysis, or alerting on suspicious activity; it only provides raw logs that require separate monitoring and analysis. Option B is wrong because Amazon Inspector is a vulnerability management service that assesses EC2 instances for software vulnerabilities and unintended network exposure, not for detecting anomalous API call patterns or cross-account data access. Option C is wrong because AWS Config is a resource inventory and compliance service that evaluates resource configurations against rules, but it does not analyze API call patterns or detect anomalous behavior like unusual S3 access from an IAM role.

456
MCQeasy

A security analyst wants to receive a notification whenever a new security group is created in their AWS account. Which AWS service should they use to trigger an SNS notification based on the CloudTrail event?

A.Amazon GuardDuty
B.AWS Config
C.Amazon EventBridge (CloudWatch Events)
D.AWS Lambda
AnswerC

Amazon EventBridge (formerly CloudWatch Events) is a serverless event bus that ingests events from AWS services, including CloudTrail API call events, and uses rules to filter and route them to targets such as SNS topics. You can create an event rule with a pattern that matches specific API events (e.g., eventName, eventSource) and immediately invoke an SNS topic to send a notification. This is the correct service for real-time, event-driven alerts based on API activity, as it directly supports the required notification workflow.

Why this answer

Amazon EventBridge (formerly CloudWatch Events) can monitor CloudTrail API calls in real time and trigger an SNS notification when a specific event, such as CreateSecurityGroup, occurs. By creating a rule that matches the event source and detail type, EventBridge evaluates incoming events and routes matching ones to an SNS topic, enabling the desired notification.

Exam trap

The trap here is that candidates often confuse AWS Config with EventBridge, thinking Config can trigger notifications on API events, but Config only evaluates resource state changes, not real-time API calls, and requires a custom Lambda rule to react to events, whereas EventBridge natively supports CloudTrail event patterns.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail management events for malicious activity, but it does not provide custom event-driven notifications based on specific CloudTrail API calls like CreateSecurityGroup. Option B is wrong because AWS Config is a resource inventory and compliance service that evaluates resource configurations against rules, but it cannot directly trigger SNS notifications from CloudTrail events; it uses its own config rules and remediation actions, not event-driven triggers. Option D is wrong because AWS Lambda is a compute service that can process events, but it is not the service that triggers the SNS notification; Lambda would be a target of an EventBridge rule, not the service that monitors CloudTrail events and initiates the notification.

457
MCQmedium

A security engineer needs to ensure that an Amazon S3 bucket blocks all public access. Which S3 block public access settings should be enabled?

A.Block public access to buckets and objects granted through new public bucket policies
B.Block public access to buckets and objects granted through new access control lists (ACLs)
C.Block public access to buckets and objects granted through any access control lists (ACLs)
D.Block all public access
AnswerD

This option enables all four S3 Block Public Access settings: BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, and RestrictPublicBuckets. BlockPublicAcls stops new public ACLs, IgnorePublicAcls causes existing public ACLs to be disregarded, BlockPublicPolicy prevents adding new public bucket policies, and RestrictPublicBuckets limits how existing public policies are used. Together they close both ACL-based and bucket-policy-based pathways for anonymous or public access, making this the correct choice to ensure the bucket is not publicly accessible.

Why this answer

The 'Block all public access' setting in Amazon S3 is a single toggle that simultaneously enables all four individual block public access settings, ensuring that no public access is allowed through any mechanism—bucket policies, ACLs, or otherwise. This is the only setting that comprehensively blocks all public access to the S3 bucket and its objects, as required by the security engineer's goal.

Exam trap

The trap here is that candidates may think enabling individual settings (like blocking new bucket policies or new ACLs) is sufficient, but they overlook that existing policies or ACLs could still allow public access, and only 'Block all public access' guarantees complete closure of all public access vectors.

How to eliminate wrong answers

Option A is wrong because it only blocks public access granted through new public bucket policies, leaving existing policies and ACLs (both new and existing) as potential vectors for public access. Option B is wrong because it only blocks public access granted through new ACLs, while existing ACLs and bucket policies could still allow public access. Option C is wrong because it blocks public access through any ACLs (both new and existing) but does not block public access granted through bucket policies, which is a separate and common mechanism for granting public access.

458
MCQhard

A company uses AWS Organizations to manage multiple accounts. The security team wants to centralize threat detection across all accounts. They enable Amazon GuardDuty in the management account and intend to use delegated administrator functionality. However, they find that GuardDuty is not detecting threats in member accounts. What is the most likely cause?

A.GuardDuty requires an S3 bucket in each account to store findings.
B.GuardDuty is not enabled in the member accounts. The security team must invite member accounts or use the delegated administrator to enable GuardDuty in all accounts.
C.GuardDuty only monitors the management account's resources, not member accounts.
D.GuardDuty does not support delegated administrator for AWS Organizations.
AnswerB

The correct issue is that GuardDuty has not been enabled for the member accounts. When you set up AWS Organizations, you still need to explicitly enable GuardDuty in the management account and then either send email invitations to each member account or, preferably, designate a delegated administrator who can use the `EnableOrganizationAdminAccount` API to activate GuardDuty for every account in the organization. Without this explicit step, member accounts remain unmonitored and cannot produce GuardDuty findings.

Why this answer

Amazon GuardDuty must be enabled in each member account to detect threats in those accounts. When using the delegated administrator model, the security team can enable GuardDuty across all accounts programmatically via the delegated administrator API, but they must explicitly perform this action. Simply enabling GuardDuty in the management account does not automatically activate it in member accounts, which is why no threats are detected in those accounts.

Exam trap

The trap here is that candidates assume enabling GuardDuty in the management account automatically propagates to all member accounts, but AWS requires an explicit delegated administrator action to enable the service across the organization.

How to eliminate wrong answers

Option A is wrong because GuardDuty does not require an S3 bucket in each account to store findings; findings are stored centrally in the GuardDuty service and can be exported to a single S3 bucket if configured. Option C is wrong because GuardDuty, when properly enabled via delegated administrator, monitors resources across all member accounts, not just the management account. Option D is wrong because GuardDuty fully supports delegated administrator for AWS Organizations, allowing a designated account to manage GuardDuty across the organization.

459
MCQmedium

During a security incident, a forensic investigator needs to capture the memory of a running EC2 instance without shutting it down. Which AWS feature should be used?

A.Amazon CloudWatch agent
B.EC2 Rescue for Linux or Systems Manager Run Command with a memory dump script
C.AWS CloudTrail
D.Amazon EBS snapshot
AnswerB

EC2 Rescue for Linux includes diagnostic modules that can trigger a memory dump, and AWS Systems Manager Run Command can execute a memory-dump script on the target instance; both operate inside the guest OS to copy volatile memory while the instance remains running. By writing the output to an EBS volume or Amazon S3, they preserve process, kernel, and network state for forensic analysis. This is the correct option because no AWS control-plane API can read guest RAM directly.

Why this answer

EC2 Rescue for Linux (via Systems Manager Run Command) includes a built-in script that can capture a full memory dump from a running EC2 instance without requiring a shutdown. This is essential for forensic analysis to preserve volatile data like running processes, network connections, and kernel structures. The script leverages the Linux 'vmcore' or 'LiME' (Linux Memory Extractor) tool to safely extract memory contents while the instance remains operational.

Exam trap

The trap here is that candidates often confuse capturing volatile memory with taking a disk snapshot (Option D), not realizing that memory is stored in RAM and is not preserved by EBS snapshots, which only capture persistent storage.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Agent is designed for collecting metrics, logs, and performance data, not for capturing raw memory dumps; it cannot access or dump physical memory. Option C is wrong because AWS CloudTrail records API activity and management events, not the volatile memory state of an EC2 instance; it provides no mechanism for memory acquisition. Option D is wrong because an Amazon EBS snapshot captures the persistent disk state (block-level storage), not the contents of RAM; memory is volatile and not stored on EBS volumes.

460
MCQmedium

An organization wants to enforce multi-factor authentication (MFA) for all IAM users accessing the AWS Management Console. Which policy should be used?

A.A policy that allows all actions and denies when aws:MultiFactorAuthPresent is true.
B.A policy that allows all actions except ConsoleLogin unless MFA is present.
C.A policy that allows all actions when aws:MultiFactorAuthPresent is true.
D.A policy that denies all actions unless aws:MultiFactorAuthPresent is true.
AnswerD

This is the correct enforcement pattern: a Deny statement with the condition aws:MultiFactorAuthPresent equal to false (or using BoolIfExists to treat a missing key as false) explicitly blocks every action from principals that did not use MFA. Because explicit Deny statements take precedence over any Allow, attaching this policy ensures no other policy can accidentally allow unauthenticated-with-MFA access. This is the standard AWS-recommended way to enforce MFA across all AWS API actions.

Why this answer

It uses an IAM policy with a Deny effect on all actions when `aws:MultiFactorAuthPresent` is false (or not true). This ensures that any IAM user attempting to perform any action, including ConsoleLogin, must have authenticated with MFA; otherwise, the request is denied. This is the standard approach to enforce MFA for all AWS Management Console access.

Exam trap

The trap here is that candidates often confuse the condition key evaluation — thinking a policy that 'allows when MFA is present' is sufficient, but without an explicit Deny for when MFA is absent, other policies could still grant access, making the enforcement incomplete.

How to eliminate wrong answers

Option A is wrong because it denies actions when `aws:MultiFactorAuthPresent` is true, which would block users who have authenticated with MFA, defeating the purpose. Option B is wrong because it allows all actions except ConsoleLogin unless MFA is present, but it does not deny other actions (like API calls) when MFA is absent, leaving a security gap. Option C is wrong because it allows all actions when MFA is present but does not explicitly deny actions when MFA is absent, meaning a user without MFA could still access resources if another policy grants access.

461
MCQhard

A company uses Amazon S3 to store sensitive documents. The security policy requires that all objects be encrypted using server-side encryption with customer-provided keys (SSE-C). An application fails when trying to read an object with the error 'The request includes an invalid header.' What is the MOST likely cause?

A.The application did not specify an encryption context in the request.
B.The KMS key used for encryption has been disabled.
C.The application did not include the x-amz-server-side-encryption-customer-key header in the GET request.
D.The S3 bucket does not have versioning enabled.
AnswerC

For an SSE-C encrypted object, S3 does not store or possess the actual encryption key; it only stores a one-way HMAC-derived verification value. Accordingly, every GET request must include the `x-amz-server-side-encryption-customer-key` header, along with `x-amz-server-side-encryption-customer-algorithm` and optionally the MD5 header, so S3 can verify the key and decrypt the object. Omitting the key header in the GET causes S3 to return a 400 Bad Request because it cannot authenticate the customer-supplied key.

Why this answer

With SSE-C, the customer provides the encryption key on every request, and S3 does not store it. For a GET request, the client must include the same key headers used during PUT: x-amz-server-side-encryption-customer-algorithm, x-amz-server-side-encryption-customer-key, and x-amz-server-side-encryption-customer-key-MD5. If the key header is missing, S3 returns an 'invalid header' error because it cannot decrypt the object.

Exam trap

The trap is mixing up SSE-C with SSE-KMS — candidates pick 'encryption context' or 'KMS key disabled' because they forget SSE-C requires the customer key headers on every request, not KMS.

How to eliminate wrong answers

Option A is wrong because encryption context is a KMS concept (used with SSE-KMS for additional authenticated data), not SSE-C; SSE-C does not use encryption context. Option B is wrong because a disabled KMS key would produce a KMS-related error (e.g., KMS.DisabledException), and SSE-C does not use KMS at all. Option D is wrong because bucket versioning is unrelated to encryption headers; versioning affects object retention, not the ability to decrypt on GET.

462
MCQeasy

A company wants to receive real-time notifications when specific API calls are made in their AWS account, such as IAM user creation or S3 bucket policy changes. Which AWS service should be used to trigger notifications based on these API events?

A.Amazon CloudWatch Events (Amazon EventBridge)
B.Amazon GuardDuty
C.Amazon Simple Notification Service (SNS)
D.AWS Config
AnswerA

Amazon CloudWatch Events (Amazon EventBridge) is the correct choice because it natively ingests AWS CloudTrail API activity as event patterns and can filter for specific API calls (e.g., by eventName, awsRegion, or userIdentity) in real time. Once a rule matches, EventBridge invokes a target such as AWS Lambda, Amazon SNS, or Step Functions to deliver the notification, giving you low-latency, event-driven responses to the exact API activity you care about.

Why this answer

Amazon CloudWatch Events (now part of Amazon EventBridge) is the correct service because it can capture AWS API calls in real time via CloudTrail integration. You can create a rule that matches specific API calls (e.g., CreateUser, PutBucketPolicy) and route those events to a target such as an SNS topic or Lambda function for immediate notification. This provides the real-time, event-driven notification required by the scenario.

Exam trap

The trap here is that candidates often pick Amazon SNS because they think of 'notifications' first, but they overlook that SNS cannot directly consume AWS API events without an intermediary like EventBridge or CloudTrail.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes logs (e.g., CloudTrail, VPC Flow Logs, DNS logs) for malicious activity, but it does not provide a mechanism to trigger custom notifications based on specific API calls. Option C is wrong because Amazon Simple Notification Service (SNS) is a pub/sub messaging service that can deliver notifications, but it cannot directly capture or filter API calls; it requires an event source like EventBridge to send it events. Option D is wrong because AWS Config is a configuration auditing and compliance service that evaluates resource configurations against rules, but it does not provide real-time event-driven notifications for specific API calls; it operates on configuration changes and periodic evaluations.

463
MCQhard

A company has an S3 bucket with versioning enabled. They want to ensure that all deleted objects are retained for 90 days before permanent deletion. Which S3 feature should be used?

A.S3 Lifecycle policy with NoncurrentVersionExpiration
B.S3 Replication
C.S3 Object Lock
D.MFA Delete
AnswerA

S3 Lifecycle policy with NoncurrentVersionExpiration defines how many days a previous version is retained after it becomes noncurrent. When a versioned object is deleted, S3 places a delete marker and the prior version is preserved as a noncurrent version; the lifecycle action permanently removes those noncurrent versions only after the specified number of days. This provides exactly the requested grace period for recovering deleted objects before they are eventually purged.

Why this answer

S3 Lifecycle policies can manage the expiration of noncurrent versions of objects. In this scenario, after an object is deleted, it becomes a noncurrent version. A lifecycle rule with NoncurrentVersionExpiration can be set to permanently delete those noncurrent versions after a specified number of days (e.g., 90).

Option A is correct. S3 Object Lock protects objects from deletion but does not automatically delete them after a period. S3 Replication is for copying objects to another bucket.

MFA Delete adds a multi-factor authentication requirement for deletion but does not set a retention period.

464
Multi-Selectmedium

A company wants to monitor for suspicious IAM activity, such as a user creating access keys without authorization. Which THREE AWS services can be used together to detect and alert on this activity in real-time? (Choose THREE.)

Select 3 answers
A.Amazon CloudWatch Logs
B.Amazon Inspector
C.AWS CloudTrail
D.AWS Trusted Advisor
E.Amazon Simple Notification Service (SNS)
AnswersA, C, E

CloudWatch Logs is the service that turns CloudTrail log data into actionable alarms. By creating a metric filter on a log group for events such as CreateAccessKey or ConsoleLogin failures, you can define a CloudWatch alarm that evaluates the metric and triggers an SNS notification when the count exceeds a threshold. This makes CloudWatch Logs the central monitoring component for detecting suspicious IAM activity in near real time.

Why this answer

Amazon CloudWatch Logs is correct because it can ingest and monitor log data from AWS CloudTrail in real-time. By creating a CloudWatch Logs metric filter on CloudTrail logs for events like CreateAccessKey, you can trigger an alarm that sends notifications via SNS when unauthorized access key creation occurs. This enables real-time detection and alerting for suspicious IAM activity.

Exam trap

The trap here is that candidates often confuse Amazon Inspector or Trusted Advisor as security monitoring services, but they lack the capability to monitor real-time IAM API activity, which requires CloudTrail, CloudWatch Logs, and SNS working together.

465
MCQhard

A company uses AWS Organizations with SCPs. The SCP for the production OU denies all actions on DynamoDB. An IAM policy attached to a user in that OU allows dynamodb:PutItem. What is the effective access?

A.The user can perform PutItem because the IAM policy allows it.
B.The user cannot perform PutItem because the SCP denies all DynamoDB actions and IAM allows are overridden.
C.The user cannot perform PutItem because the SCP applies only to the root account.
D.The user can perform PutItem only if the SCP has an explicit allow.
AnswerB

The SCP explicitly denies all DynamoDB actions for the OU, and service control policies are evaluated before IAM identity policies. Because a deny in an SCP always takes precedence over an allow in an IAM policy, the user's PutItem call will be denied even if the attached IAM policy grants it. This is the correct outcome under AWS's policy evaluation model.

Why this answer

In AWS Organizations, Service Control Policies (SCPs) define the maximum permissions for accounts in an OU. An explicit Deny in an SCP overrides any Allow in IAM policies. Since the SCP denies all DynamoDB actions, the user cannot perform PutItem regardless of the IAM policy allowing it.

Exam trap

The trap is assuming that an IAM Allow can override an SCP Deny—candidates must remember that SCPs are guardrails and explicit denies in SCPs always win over IAM allows.

How to eliminate wrong answers

Option A is wrong because IAM policy allows are not effective if an SCP explicitly denies the action—SCPs take precedence. Option C is wrong because SCPs apply to all accounts in the OU, not just the root account; they affect all IAM users and roles in member accounts. Option D is wrong because SCPs do not require an explicit allow to permit actions; they only filter permissions.

An implicit deny in SCPs does not block actions if IAM allows them, but an explicit deny always blocks.

466
MCQeasy

A company wants to detect and alert on changes to IAM roles and policies in their AWS account. Which combination of AWS services should they use?

A.Amazon GuardDuty and AWS Shield
B.Amazon CloudWatch Logs and AWS Lambda
C.AWS CloudTrail and Amazon EventBridge (CloudWatch Events)
D.AWS Config and Amazon Inspector
AnswerC

AWS CloudTrail is the correct service to record all IAM API activity—such as CreateRole, UpdateAssumeRolePolicy, AttachRolePolicy, and DeleteRole—by generating event logs with details like the requesting principal, source IP, and timestamp. Amazon EventBridge (formerly CloudWatch Events) can be configured with rule patterns that match specific IAM events, then trigger actions like sending notifications to Amazon SNS or invoking a Lambda function. This combination enables near-real-time, event-driven alerting on exactly the IAM role changes that the company cares about, with no need for polling or custom log parsing.

Why this answer

AWS CloudTrail records all API calls, including changes to IAM roles and policies, and delivers log files to an S3 bucket or CloudWatch Logs. Amazon EventBridge (formerly CloudWatch Events) can then be used to create rules that match specific CloudTrail events (e.g., PutRolePolicy, CreateRole) and trigger alerts via SNS, Lambda, or other targets. This combination provides real-time detection and notification of IAM modifications.

Exam trap

The trap here is that candidates often confuse AWS Config (which evaluates resource compliance) with real-time event-driven alerting, or they mistakenly think GuardDuty’s threat detection includes IAM policy change alerts, when in fact CloudTrail + EventBridge is the correct pattern for custom event-based monitoring.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that monitors for malicious activity using VPC Flow Logs, DNS logs, and CloudTrail events, but it does not directly alert on IAM policy changes; AWS Shield is a DDoS protection service and irrelevant here. Option B is wrong because CloudWatch Logs can store log data but cannot independently detect or alert on IAM changes without a rule engine like EventBridge; Lambda alone cannot trigger on CloudTrail events without an event source such as EventBridge or S3 notifications. Option D is wrong because AWS Config evaluates resource compliance against rules and can detect drift in IAM policies, but it does not provide real-time event-driven alerts; Amazon Inspector is a vulnerability assessment service for EC2 instances and container workloads, not for IAM change detection.

467
Multi-Selectmedium

Which TWO of the following are valid ways to grant an IAM user permissions to access an S3 bucket? (Choose 2.)

Select 2 answers
A.Assign an instance profile to the user.
B.Create a VPC endpoint policy.
C.Attach an IAM policy to the user.
D.Add the user to an IAM group with a policy.
E.Use an SCP to allow access.
AnswersC, D

An identity-based IAM policy attached directly to the user grants that user the specified S3 actions on the bucket. This is a standard, valid mechanism for granting an IAM user access, independent of any bucket policy or group membership.

Why this answer

Option C is correct because attaching an IAM identity-based policy directly to the user grants that user the specified S3 permissions, which is the standard way to authorize an IAM principal. Option D is correct because adding the user to an IAM group that has an S3 policy attached means the user inherits those permissions through group membership, another standard identity-based authorization method. Option A is incorrect because an instance profile is a container for an IAM role used by EC2 instances (and similar compute), not a mechanism for granting permissions to an IAM user.

Option B is incorrect because a VPC endpoint policy controls which principals can access the service through that endpoint; it does not grant an IAM user permissions to an S3 bucket. Option E is incorrect because an SCP sets the maximum permissions boundary for accounts in an AWS Organization; it only restricts permissions and never grants access on its own.

Exam trap

The trap here is that candidates often confuse identity-based policies (attached to users/groups/roles) with resource-based policies (like bucket policies) or other access control mechanisms (like SCPs or VPC endpoint policies), leading them to select options that do not directly grant permissions to an IAM user.

468
MCQmedium

A company has a VPC with a CIDR block of 10.0.0.0/16. The company wants to connect this VPC to an on-premises network that uses the CIDR block 10.0.0.0/8. The company has set up an AWS Site-to-Site VPN connection. After configuration, the on-premises network cannot reach resources in the VPC, and the VPC cannot reach on-premises resources. What is the most likely cause of the connectivity issue?

A.The VPC route table does not have a route for the on-premises CIDR block pointing to the virtual private gateway.
B.The security group attached to the VPC resources does not allow traffic from the on-premises CIDR block.
C.The VPN connection is using dynamic routing (BGP) instead of static routing, which is required for overlapping CIDRs.
D.The on-premises network CIDR block overlaps with the VPC CIDR block, causing routing conflicts.
AnswerD

The on-premises network uses 10.0.0.0/8, which includes the VPC CIDR 10.0.0.0/16. This overlap creates conflicting routes: traffic destined for 10.0.0.0/16 could be routed locally within the VPC or to the VPN, causing ambiguity and failure. Overlapping CIDRs are a common cause of hybrid connectivity issues and must be resolved by re-addressing one side.

Why this answer

The on-premises network CIDR 10.0.0.0/8 overlaps with the VPC CIDR 10.0.0.0/16. This overlap causes routing conflicts because the same IP range exists on both sides of the VPN. Traffic cannot be correctly routed, leading to connectivity failure.

The solution is to re-address either the VPC or the on-premises network to eliminate the overlap.

Exam trap

The trap here is assuming that a missing route or security group rule is the cause, when the fundamental issue is overlapping CIDR blocks that make routing impossible.

469
MCQeasy

A company wants to allow a user to assume a role in another AWS account to access resources. Which AWS service should be used to create and manage the trust relationship between the accounts?

A.IAM roles with a trust policy that allows the external account.
B.AWS Security Token Service (STS) to generate tokens.
C.IAM users in the source account with cross-account permissions.
D.AWS Organizations service control policies.
AnswerA

IAM roles are the native AWS mechanism for cross-account access: the role's trust policy explicitly names the external account (or its users/roles) as a principal, and the permission policy grants the specific actions the role can perform. When the external user assumes the role, AWS verifies that the trust policy allows the request and then issues temporary credentials scoped to the role's permissions, making this the correct and secure way to enable the cross-account assumption.

Why this answer

IAM roles with a trust policy that explicitly allows the external AWS account to assume the role is the correct mechanism for establishing a cross-account trust relationship. The trust policy defines which principal (the external account) is allowed to assume the role, and the permissions policy attached to the role controls what actions the assumed role can perform. This is the foundational AWS service for delegating access across accounts.

Exam trap

The trap here is that candidates confuse the mechanism for establishing trust (IAM role trust policy) with the mechanism for obtaining credentials (STS), leading them to select STS as the answer despite it being a downstream step.

How to eliminate wrong answers

Option B is wrong because AWS Security Token Service (STS) is used to generate temporary security credentials (tokens) after a trust relationship is established, not to create or manage the trust relationship itself. Option C is wrong because IAM users are identities within a single account; granting cross-account permissions to an IAM user would require creating a role in the target account and allowing the user to assume it, not directly managing the trust relationship. Option D is wrong because AWS Organizations service control policies (SCPs) are used to centrally manage permissions across accounts in an organization, but they do not create or manage trust relationships for role assumption between accounts.

470
MCQeasy

A company wants to restrict access to an Amazon S3 bucket so that only users from a specific AWS account can upload objects. Which policy mechanism should be used?

A.Create a bucket policy with a condition that checks the aws:SourceAccount condition key.
B.Attach an IAM policy to the bucket that denies access to all users except those from the allowed account.
C.Generate a pre-signed URL for each upload request.
D.Configure the bucket ACL to grant access only to the allowed account's canonical user ID.
AnswerA

A bucket policy with an aws:SourceAccount condition key evaluates the account ID of the IAM principal that signs the request and is enforced by S3 when the bucket is accessed. This condition is evaluated against the requester's account number, allowing you to allow or deny access based on that account without specifying individual user ARNs. It is the recommended approach because it uses a resource-based policy that directly supports condition keys, and it ensures all requests from unintended accounts are rejected.

Why this answer

A bucket policy with the `aws:SourceAccount` condition key allows you to restrict access to a specific AWS account. When users from the allowed account upload objects, the condition evaluates the source account ID, ensuring only requests originating from that account are permitted. This is the recommended approach for cross-account access control in S3, as it directly enforces the account-level restriction at the bucket policy level.

Exam trap

The trap here is that candidates confuse IAM policies with resource-based policies, thinking an IAM policy can be attached to an S3 bucket, or they mistakenly believe bucket ACLs or pre-signed URLs can enforce account-level restrictions.

How to eliminate wrong answers

Option B is wrong because IAM policies are attached to IAM users, groups, or roles, not directly to S3 buckets; you cannot attach an IAM policy to a bucket. Option C is wrong because pre-signed URLs grant temporary access to specific objects for any user with the URL, regardless of AWS account, and do not restrict uploads to a specific account. Option D is wrong because bucket ACLs are legacy and do not support account-level restrictions based on AWS account IDs; they use canonical user IDs, which are not the same as AWS account IDs and are less flexible for cross-account control.

471
MCQmedium

A security engineer needs to protect data in transit between an EC2 instance and an RDS database. The RDS database uses SSL/TLS certificates. What is the MOST secure way to ensure that the connection is encrypted?

A.Configure the EC2 instance to use a self-signed certificate for SSL connections.
B.Enable encryption at rest on the RDS instance to automatically encrypt in-transit traffic.
C.Download the RDS CA certificate to the EC2 instance and configure the database client to use SSL and verify the certificate.
D.Create an IAM policy that requires SSL connections to the RDS endpoint.
AnswerC

Configuring the client with SSL and the downloaded RDS CA certificate enables full certificate verification, authenticating the database endpoint and preventing man-in-the-middle interception. Encryption alone without verification would leave the connection vulnerable, so this satisfies the requirement for the most secure encrypted connection.

Why this answer

Option C is correct because it ensures both encryption and server authentication. Downloading the RDS CA certificate (the trusted root for the RDS instance's server certificate) and configuring the client to verify it prevents man-in-the-middle attacks by confirming the RDS endpoint's identity. Simply enabling SSL without verification (as in other options) leaves the connection vulnerable to spoofing, so this is the most secure approach.

Exam trap

SCS-C02 often tests the misconception that enabling encryption at rest or using an IAM policy alone secures data in transit, when in fact client-side certificate verification is required for true security.

How to eliminate wrong answers

Option A is wrong because using a self-signed certificate on the EC2 instance does not validate the RDS server's certificate; it would either fail the handshake or require disabling verification, defeating the purpose. Option B is wrong because encryption at rest (e.g., RDS storage encryption) has no effect on data in transit; it only protects data on disk. Option D is wrong because an IAM policy can enforce that SSL be used (e.g., via rds:RequireSSL), but it does not configure the client to verify the server certificate, so it does not provide authentication and is not the most secure method.

472
MCQmedium

A security engineer sees the above security group configuration for an EC2 instance. The instance hosts a web application that should only be accessible from the internal network (10.0.0.0/8) over HTTPS, and SSH should not be open to the internet. What is the security issue with this configuration?

A.The outbound rule allows all traffic to all destinations.
B.The inbound HTTPS rule is too permissive.
C.The inbound SSH rule is too permissive.
D.There is no security issue; the configuration is correct.
AnswerA

The outbound rule is defined as allowing all traffic to 0.0.0.0/0, meaning any instance associated with this security group can initiate connections to any IP address on any port. This violates the principle of least privilege because if an attacker compromises the instance, they could use it as a pivot to exfiltrate sensitive data or launch outbound attacks. Even though inbound HTTPS may also be overly broad, the outbound any-any rule is a critical misconfiguration because it provides no egress filtering or restrictions to required services.

Why this answer

The outbound rule allowing all traffic to all destinations (0.0.0.0/0) violates the principle of least privilege. While the inbound rules restrict HTTPS to the internal network (10.0.0.0/8) and SSH is not open to the internet, the outbound rule permits any instance in the security group to initiate connections to any IP address and port, including malicious external hosts. This could allow data exfiltration or outbound attacks, which is a security issue even if inbound access is properly restricted.

Exam trap

The trap here is that candidates focus solely on inbound rules (HTTPS and SSH) and overlook the outbound rule, assuming that stateful security groups automatically handle outbound traffic safely, but AWS explicitly tests that outbound rules must also be restricted to follow least privilege.

How to eliminate wrong answers

Option B is wrong because the inbound HTTPS rule is correctly scoped to the internal network (10.0.0.0/8), which aligns with the requirement that the web application should only be accessible from the internal network. Option C is wrong because the inbound SSH rule is not open to the internet (0.0.0.0/0) in the provided configuration; it is restricted to the internal network (10.0.0.0/8), so it is not too permissive. Option D is wrong because the outbound rule is overly permissive, creating a security risk that makes the configuration incorrect.

473
MCQmedium

A security engineer discovers that an IAM user has a policy that allows them to delete any S3 bucket in the account. The engineer wants to audit all delete actions performed by this user. Which AWS service should be used?

A.Amazon GuardDuty
B.AWS Config
C.AWS CloudTrail
D.Amazon CloudWatch Logs
AnswerC

AWS CloudTrail records every S3 API call, including DeleteBucket, capturing the IAM user's identity, timestamp, source IP and request parameters. This satisfies the audit requirement by providing an immutable event history of all delete actions performed by that user across the account.

Why this answer

AWS CloudTrail records API activity in an AWS account, including S3 DeleteBucket and DeleteObject calls, capturing the identity of the caller, source IP, timestamp, and request parameters. To audit all delete actions performed by a specific IAM user, the engineer enables CloudTrail (ideally an organization trail or a trail with S3 log delivery) and filters events by the user's ARN and event names. CloudTrail is the authoritative audit log for AWS API actions.

Exam trap

SCS-C02 often tests the difference between detection (GuardDuty), configuration compliance (Config), and audit logging (CloudTrail) — candidates pick GuardDuty because it is security-focused, but it does not provide the raw audit trail.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes CloudTrail, VPC Flow Logs, and DNS logs for malicious or anomalous behavior — it does not provide a searchable audit trail of specific API calls. Option B is wrong because AWS Config records resource configuration changes and evaluates compliance rules; while it can show that an S3 bucket was deleted, it does not capture the full API-level audit detail (caller identity, request parameters) that CloudTrail does. Option D is wrong because Amazon CloudWatch Logs is a log storage and monitoring service; CloudTrail can deliver logs to CloudWatch Logs, but CloudWatch Logs itself is not the audit source for API activity.

474
Multi-Selecthard

Which TWO steps should a security engineer take when responding to a confirmed security incident involving a compromised EC2 instance? (Choose 2.)

Select 2 answers
A.Reimage the instance from a clean AMI immediately
B.Delete all CloudTrail logs related to the instance
C.Isolate the instance by changing its security group to deny all traffic
D.Take a snapshot of the instance's EBS volumes for forensic analysis
E.Immediately terminate the instance to stop the attack
AnswersC, D

Replacing the instance's security group with one that denies all inbound and outbound traffic severs command-and-control and exfiltration channels while preserving the instance's memory and disk state for investigation, satisfying containment without terminating evidence needed for the incident response.

Why this answer

Option C is correct because isolating the compromised EC2 instance by replacing its security group with one that denies all inbound and outbound traffic is the standard containment step that stops lateral movement and command-and-control communication while preserving the instance's volatile state for investigation. Option D is correct because taking EBS snapshots of the instance's volumes captures a point-in-time, read-only copy of the disk that can be mounted on a separate forensic workstation for evidence preservation and analysis without altering the original data. Option A is not appropriate as a first response because reimaging destroys volatile evidence and should only occur after containment and forensic capture are complete.

Option B is wrong because deleting CloudTrail logs is log tampering that destroys the audit trail needed for the investigation. Option E is wrong because terminating the instance shuts it down and can destroy volatile memory and instance-store data before evidence is collected.

Exam trap

The trap here is that candidates often confuse 'immediate termination' (Option E) with containment, but AWS incident response frameworks emphasize preserving evidence and isolating rather than destroying the instance, as termination eliminates the ability to perform memory forensics and root cause analysis.

475
Multi-Selecteasy

Which TWO AWS services are designed to provide DDoS protection? (Choose 2.)

Select 2 answers
A.VPC Flow Logs
B.AWS CloudTrail
C.AWS Config
D.AWS WAF
E.AWS Shield Standard
AnswersD, E

AWS WAF is a web application firewall that protects at Layer 7 by inspecting HTTP(S) requests and filtering malicious traffic before it reaches your application. You can use rate-based rules to limit the number of requests from a given IP address, block known attacker IP sets, and mitigate HTTP floods, SQL injection, or cross-site scripting attempts. This directly addresses application-layer DDoS attacks, which consume application resources by sending large volumes of web requests, and it is a core component for ongoing protection of web-facing workloads.

Why this answer

AWS WAF (Option D) is a web application firewall that helps protect web applications from common web exploits that could affect application availability, compromise security, or consume excessive resources. It integrates with Amazon CloudFront, Application Load Balancer, and API Gateway to filter and monitor HTTP(S) requests, providing protection against layer 7 DDoS attacks such as SQL injection and cross-site scripting.

Exam trap

The trap here is that candidates may confuse monitoring or auditing services (VPC Flow Logs, CloudTrail, Config) with active security controls, but only AWS Shield and AWS WAF provide direct DDoS mitigation capabilities.

476
Multi-Selectmedium

A security engineer is designing a VPC with public and private subnets. The private subnets will host databases that should not have direct internet access. Which three components are required to provide outbound internet access for these databases? (Choose THREE.)

Select 3 answers
A.AWS WAF attached to the NAT gateway.
B.An internet gateway attached to the VPC.
C.Route tables in the private subnets with a default route (0.0.0.0/0) pointing to the NAT gateway.
D.A VPC gateway endpoint for S3.
E.A NAT gateway in a public subnet.
AnswersB, C, E

The internet gateway provides the VPC's path to the internet and is required for the NAT gateway to reach external destinations. Without it attached to the VPC, the NAT gateway cannot forward private-subnet traffic outbound, so the stem's outbound access fails.

Why this answer

Option B is correct because an internet gateway (IGW) attached to the VPC is the fundamental component that enables any communication between the VPC and the internet; the NAT gateway itself requires an IGW to forward traffic outbound. Option E is correct because a NAT gateway must be deployed in a public subnet (one whose route table points to the IGW) so it can translate private subnet traffic to the internet while preventing inbound connections to the databases. Option C is correct because the private subnet route tables must contain a default route (0.0.0.0/0) targeting the NAT gateway, which is how the databases' outbound packets are directed to the NAT for translation.

Option A is not required because AWS WAF is a layer 7 web application firewall that protects web applications and does not enable or provide outbound internet access. Option D is not required because a VPC gateway endpoint for S3 only provides private connectivity to Amazon S3 and does not provide general outbound internet access.

Exam trap

The trap here is that candidates often think a NAT gateway alone provides internet access, forgetting that the NAT gateway must be placed in a public subnet with a route to an internet gateway, and that the private subnet’s default route must point to the NAT gateway, not the IGW.

477
MCQeasy

A company wants to ensure that data at rest in Amazon EBS volumes is encrypted. What is the simplest way to achieve this?

A.Enable EBS encryption by default in the AWS account.
B.Use AWS KMS to create a custom key and attach it to each volume.
C.Encrypt each volume manually using the AWS Management Console.
D.Use an operating system-level encryption tool like LUKS.
AnswerA

Enabling EBS encryption by default at the account or Region level is the simplest, AWS-native way to enforce encryption for all new EBS volumes. No per-volume configuration is required: every newly created volume and any snapshot copied from it is automatically encrypted with the account's default KMS key (AWS-managed or customer-managed). This setting does not retroactively encrypt existing unencrypted volumes, but it ensures all future data-at-rest is protected across the account.

Why this answer

The simplest way to ensure that data at rest in Amazon EBS volumes is encrypted is to enable EBS encryption by default in the AWS account. This setting automatically encrypts all new EBS volumes created in the account, using the default KMS key for EBS encryption. It eliminates the need to manually encrypt each volume or attach custom KMS keys.

Other methods are more manual and do not provide the same level of automation.

Exam trap

SCS-C02 often tests the simplest way to enforce EBS encryption, and candidates may choose manual encryption or custom KMS keys, overlooking the account-level default encryption setting.

How to eliminate wrong answers

Option B is wrong because using a custom KMS key for each volume is manual and does not ensure all volumes are encrypted by default. Option C is wrong because encrypting each volume manually is error-prone and not scalable. Option D is wrong because OS-level encryption like LUKS does not encrypt the EBS volume itself; it encrypts data within the instance, but the volume remains unencrypted at the EBS layer, and snapshots would not be encrypted.

478
MCQeasy

A company uses Amazon GuardDuty and receives a finding of type 'Backdoor:EC2/C&CActivity.B!DNS' for an EC2 instance. What does this finding indicate?

A.The instance is being targeted by an SSH brute force attack.
B.The instance is communicating with a known command and control server.
C.The instance is exfiltrating data to an S3 bucket.
D.The instance is being used in a DDoS attack.
AnswerB

The `C&CActivity` threat purpose denotes confirmed command-and-control traffic, and the `!DNS` suffix specifies the DNS protocol as the detection vector. This satisfies the stem's requirement to interpret the finding type: GuardDuty has observed the instance resolving a domain attributed to a known C&C server.

Why this answer

The finding 'Backdoor:EC2/C&CActivity.B!DNS' indicates that GuardDuty has detected DNS queries from the EC2 instance to a domain associated with known command and control (C&C) infrastructure. This is based on GuardDuty's threat intelligence feeds that map DNS request patterns to known malicious domains, signaling that the instance may be compromised and communicating with an attacker's server.

Exam trap

The trap here is that candidates may confuse 'Backdoor:EC2/C&CActivity.B!DNS' with generic network anomalies or other attack types, but the key differentiator is the DNS-specific indicator that pinpoints communication with a known command and control server, not the attack vector or data exfiltration method.

How to eliminate wrong answers

Option A is wrong because SSH brute force attacks are detected by GuardDuty findings such as 'UnauthorizedAccess:EC2/SSHBruteForce', not by DNS-based C&C activity. Option C is wrong because data exfiltration to an S3 bucket would typically be detected by findings like 'Policy:IAMUser/RootCredentialUsage' or S3-specific findings, not by DNS query analysis for C&C domains. Option D is wrong because DDoS attack participation is indicated by findings such as 'Backdoor:EC2/DenialOfService' or 'Behavior:EC2/NetworkOutboundDenialOfService', which analyze traffic volume and patterns, not DNS queries to C&C servers.

479
MCQhard

Refer to the exhibit. A security engineer runs the AWS CLI command shown and receives an AccessDenied error. The IAM user Alice has a policy that grants kms:Decrypt on all resources. What is the most likely cause of the error?

A.The KMS key policy does not grant kms:Decrypt to the IAM user Alice.
B.The IAM user policy does not allow kms:Decrypt.
C.The command uses the wrong key ID.
D.The ciphertext blob is corrupted.
AnswerA

KMS authorises access through both the key policy and IAM policies. If the key policy does not grant kms:Decrypt to Alice, the request is denied regardless of her identity-based policy, making the key policy the most likely cause.

Why this answer

AWS KMS enforces a two-part authorization model: the caller must be allowed by both the identity-based IAM policy and the KMS key policy. Even though Alice's IAM policy grants kms:Decrypt on all resources, the key policy must also grant her (or her account with delegation) access to that key. If the key policy does not permit Alice, the request is denied, which is the most likely cause of the AccessDenied error.

Exam trap

SCS-C02 often tests the KMS dual-authorization requirement; candidates assume an IAM allow is sufficient and forget that the key policy must also grant access, which is the classic cause of AccessDenied on kms:Decrypt.

How to eliminate wrong answers

Option B is wrong because the scenario explicitly states the IAM user policy grants kms:Decrypt on all resources, so the identity policy is not the blocker. Option C is wrong because using the wrong key ID would typically produce a NotFoundException or a different error, and the scenario implies the correct key is referenced. Option D is wrong because a corrupted ciphertext blob would produce an InvalidCiphertextException or decryption failure, not an AccessDenied authorization error.

480
MCQmedium

A company uses AWS CloudFormation to deploy infrastructure. A security requirement states that no security group should allow inbound SSH access from 0.0.0.0/0. What is the best way to enforce this policy?

A.Create an IAM policy that denies the ec2:AuthorizeSecurityGroupIngress action if the CIDR is 0.0.0.0/0.
B.Use AWS Config with a managed rule to detect and automatically remediate non-compliant security groups.
C.Add an AWS::IAM::Policy resource in the CloudFormation template to deny the rule.
D.Use a service control policy (SCP) that denies the CreateStack action if the template contains SSH from 0.0.0.0/0.
AnswerB

AWS Config can continuously monitor security group configurations using the managed rule 'vpc-sg-open-only-to-authorized-ports', which flags security groups that allow unrestricted inbound access. When the rule detects a non-compliant security group, you can attach an automatic remediation action using an AWS Systems Manager Automation document such as AWS-RevokeSecurityGroupIngress. This removes the offending SSH 0.0.0.0/0 rule without requiring manual intervention, and AWS Config tracks compliance status in the dashboard.

Why this answer

AWS Config with a managed rule (e.g., 'restricted-ssh') can continuously evaluate security group configurations against the policy and automatically remediate non-compliant rules using AWS Systems Manager Automation. This provides detective and corrective enforcement without blocking legitimate administrative actions, unlike IAM or SCP approaches that would prevent necessary changes or fail to detect existing non-compliant resources.

Exam trap

The trap here is that candidates often choose an IAM-based deny policy (Option A) thinking it prevents the action entirely, but they overlook that AWS Config with remediation is the only option that both detects and automatically fixes existing non-compliant security groups, which is the core requirement of 'enforcing' the policy.

How to eliminate wrong answers

Option A is wrong because denying ec2:AuthorizeSecurityGroupIngress only prevents new inbound SSH rules from being added but does not detect or remediate existing non-compliant security groups that were created before the policy was applied. Option C is wrong because adding an AWS::IAM::Policy resource inside a CloudFormation template only affects the stack's execution role and cannot retroactively enforce rules on security groups already deployed or created outside that template. Option D is wrong because an SCP denying CreateStack based on template content cannot inspect the actual security group rules after stack creation, and it would block all stack creation attempts even if the SSH rule is later removed or modified.

481
Multi-Selectmedium

Which TWO AWS services can be used to centrally collect and analyze logs from multiple AWS accounts? (Choose two.)

Select 2 answers
A.Amazon CloudWatch Logs
B.AWS CloudTrail
C.Amazon Kinesis Data Firehose
D.Amazon Athena
E.Amazon S3
AnswersA, E

Amazon CloudWatch Logs is a central service that can aggregate logs from multiple AWS accounts and on-premises sources via cross-account subscriptions and log destinations. It provides a unified view for monitoring, querying, and setting metric filters on log data, making it a true central collection point for operational logs.

Why this answer

Amazon CloudWatch Logs can centrally collect logs from multiple AWS accounts by using cross-account subscription filters or by aggregating logs into a central account via CloudWatch Logs destination. This enables centralized monitoring and analysis of log data from various sources, meeting the requirement for a multi-account log collection and analysis solution.

Exam trap

The trap here is that candidates often confuse log collection services (CloudWatch Logs, S3) with analysis-only services (Athena) or event-recording services (CloudTrail), failing to recognize that CloudTrail generates logs but does not centrally collect them from multiple accounts without additional configuration.

482
MCQeasy

A security team wants to automatically revoke public access to an S3 bucket when Amazon GuardDuty detects a suspicious API call from a known malicious IP address. Which AWS service should be used to orchestrate this automated response?

A.AWS Config
B.AWS Lambda
C.AWS Systems Manager Automation
D.AWS CloudTrail
AnswerC

AWS Systems Manager Automation is a managed workflow service that can execute runbooks against AWS resources; the AWS-DisableS3BucketPublicRead runbook removes public-read ACLs or otherwise strips public access from S3 buckets. The runbook runs under an IAM execution role and can be invoked automatically by AWS Config rules or Amazon EventBridge, giving a fully automated, auditable remediation path. Unlike a custom Lambda function, this service is purpose-built for remediation and requires no custom code.

Why this answer

AWS Systems Manager Automation is the correct service because it provides a runbook-based orchestration framework that can be triggered by Amazon EventBridge events from GuardDuty findings. It can execute predefined automation documents (e.g., AWS-DisableS3BucketPublicReadWrite) to modify S3 bucket policies and revoke public access without requiring custom code, making it ideal for automated incident response workflows.

Exam trap

The trap here is that candidates often choose AWS Lambda as the default for any automation task, overlooking that AWS Systems Manager Automation is the purpose-built service for orchestrated, runbook-based incident response with built-in approval and rollback capabilities.

How to eliminate wrong answers

Option A is wrong because AWS Config is a compliance and resource auditing service that evaluates resource configurations against rules, but it cannot directly execute remediation actions like revoking S3 bucket public access; it can only trigger Lambda functions or Systems Manager Automation for remediation. Option B is wrong because while AWS Lambda can be used to revoke public access, it is not a dedicated orchestration service; it requires custom code and manual integration with EventBridge and GuardDuty, whereas Systems Manager Automation provides a managed, runbook-based approach with built-in error handling and approval workflows. Option D is wrong because AWS CloudTrail is a logging service that records API calls, but it cannot execute any automated response actions; it only provides the audit trail that GuardDuty uses for detection.

483
MCQhard

A company uses AWS Organizations to manage multiple accounts. The security team must enforce that all Amazon S3 buckets across all accounts are encrypted with AWS KMS. The team has enabled S3 default encryption for new buckets, but existing buckets may not be encrypted. They need to automatically remediate any non-compliant buckets. The team has AWS Config and AWS Lambda available. What is the MOST operationally efficient solution?

A.Manually review all buckets using the S3 console and enable encryption for those that are not encrypted.
B.Write a script that runs daily on an EC2 instance to list all buckets and enable encryption on any that are not encrypted.
C.Use AWS Config with the s3-bucket-server-side-encryption-enabled rule and configure an AWS Systems Manager Automation document to remediate non-compliant buckets.
D.Use AWS Trusted Advisor to check for unencrypted buckets and send an SNS notification to the security team to manually remediate.
AnswerC

AWS Config continuously evaluates each S3 bucket against the s3-bucket-server-side-encryption-enabled managed rule and, upon detecting non-compliance, can immediately trigger an AWS Systems Manager Automation document to apply default encryption automatically. This creates a closed-loop, serverless remediation pipeline that is real-time, fully audited (via Config compliance history and SSM Automation execution logs), and scalable across accounts through Organization-level conformance packs. It is the only option that provides both continuous detection and automatic remediation without manual effort or infrastructure management.

Why this answer

Use AWS Config with the s3-bucket-server-side-encryption-enabled rule to detect non-compliant S3 buckets. Then configure an automatic remediation action using an AWS Systems Manager Automation document to enable encryption on those buckets. This approach is serverless, automated, and operationally efficient as it does not require manual intervention or separate compute resources.

484
MCQhard

A company uses AWS CloudTrail to log all management events and data events for S3. The security team wants to detect any PutObject API calls that upload objects with server-side encryption disabled. Which solution is MOST efficient?

A.Use Amazon GuardDuty to detect unencrypted uploads.
B.Use Amazon Macie to scan S3 objects for missing encryption.
C.Enable S3 server access logs and parse them with Amazon Athena.
D.Enable CloudTrail data events for S3 and create a CloudWatch metric filter to alert on PutObject calls without the x-amz-server-side-encryption header.
AnswerD

The correct approach is to enable CloudTrail data events for the S3 bucket, because S3 data events record each PutObject API call, including request parameters such as the x-amz-server-side-encryption header when the caller supplies it. You can send those events to CloudWatch Logs and create a metric filter that matches PutObject events where that header is absent, then attach a CloudWatch alarm to notify the security team. This directly captures the encryption intent of the caller at upload time, which is exactly what the requirement asks for.

Why this answer

CloudTrail data events for S3 capture PutObject API calls, including request parameters. A CloudWatch metric filter can be configured to match PutObject events that lack the 'x-amz-server-side-encryption' header, indicating the object was uploaded without server-side encryption. This approach is efficient as it uses existing logging infrastructure without additional scanning or parsing overhead.

Exam trap

The trap here is that candidates may confuse GuardDuty or Macie as encryption compliance tools, but they are designed for threat detection and data classification, respectively, not for verifying encryption headers on API calls.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty does not inspect S3 object-level encryption headers; it focuses on threat detection (e.g., unusual API activity, credential compromise) rather than compliance checks for encryption. Option B is wrong because Amazon Macie is designed to discover sensitive data (e.g., PII) in S3 objects, not to detect missing server-side encryption on uploads; it operates on stored objects, not API calls. Option C is wrong because S3 server access logs are object-level logs that record requests but require parsing with Athena, which is less efficient than real-time CloudWatch metric filtering and does not natively filter on encryption headers without custom queries.

485
Multi-Selectmedium

A company is designing a data protection strategy for its Amazon S3 buckets. Which TWO actions can help protect data from accidental deletion or overwrite?

Select 2 answers
A.Enable MFA Delete on the bucket.
B.Enable Cross-Region Replication.
C.Enable default encryption.
D.Enable versioning on the bucket.
E.Set a lifecycle policy to expire objects.
AnswersA, D

MFA Delete is a bucket-level feature that, when enabled alongside versioning, requires a valid multi-factor authentication code before S3 will permanently delete an object version or change the versioning state. Even if an IAM policy grants s3:DeleteObject or s3:DeleteObjectVersion, the API call fails unless the x-amz-mfa header contains a valid code, adding an independent security layer. This specifically prevents accidental or malicious deletion by requiring physical possession of an MFA device, making it a direct and powerful control for data protection.

Why this answer

Option A (Enable MFA Delete on the bucket) is correct because MFA Delete requires multi-factor authentication to permanently delete an object version or to suspend or re-enable versioning, adding a strong safeguard against accidental or malicious deletion. Option D (Enable versioning on the bucket) is correct because versioning keeps multiple variants of an object in the same bucket, so an overwrite creates a new version and a delete only adds a delete marker, allowing the prior version to be restored. Together, versioning preserves prior object states and MFA Delete protects those versions from being permanently removed.

Option B (Cross-Region Replication) is not correct here because it copies objects to another bucket for durability and compliance, but it does not by itself prevent deletion or overwrite in the source bucket. Option C (default encryption) protects data confidentiality at rest but does not stop deletion or overwrite. Option E (a lifecycle policy to expire objects) actually deletes objects, which is the opposite of protecting against accidental deletion.

Exam trap

SCS-C02 often tests whether candidates confuse durability/replication features with deletion-protection features — Cross-Region Replication and encryption are distractors because they do not prevent deletion or overwrite.

486
MCQeasy

A company needs to monitor for unauthorized S3 bucket deletions. Which CloudWatch Logs metric filter should be used on CloudTrail logs?

A.eventName = GetBucketAcl
B.eventName = DeleteBucket
C.eventName = PutBucketPolicy
D.eventName = ListBuckets
AnswerB

DeleteBucket is the exact S3 management API invoked when a bucket is removed, and CloudTrail records it as eventName = DeleteBucket for each deletion attempt. An EventBridge rule or CloudWatch Logs metric filter targeting this event name catches both successful and failed deletion attempts, depending on the response elements. This is the only option that corresponds to the actual bucket deletion operation, making it the correct value to monitor.

Why this answer

The CloudTrail event `DeleteBucket` is logged when an S3 bucket is deleted. By creating a CloudWatch Logs metric filter that matches `eventName = DeleteBucket` on the CloudTrail log group, you can trigger an alarm or automated response to detect unauthorized bucket deletions. This directly addresses the monitoring requirement.

Exam trap

The trap here is that candidates may confuse read-only or policy-modifying events (like `GetBucketAcl`, `PutBucketPolicy`, or `ListBuckets`) with the actual deletion event, failing to recognize that only `DeleteBucket` directly corresponds to bucket removal.

How to eliminate wrong answers

Option A is wrong because `GetBucketAcl` retrieves the bucket's access control list, not a deletion event, so it would not detect bucket deletions. Option C is wrong because `PutBucketPolicy` modifies the bucket policy, which could lead to unauthorized access but is not a deletion action. Option D is wrong because `ListBuckets` enumerates all buckets in the account and is a read-only operation, not a deletion.

487
Multi-Selectmedium

A company uses AWS Config to record resources. Which TWO actions can be taken to automatically remediate non-compliant resources detected by AWS Config rules?

Select 2 answers
A.Configure AWS Config rules to invoke an AWS Lambda function for remediation
B.Configure AWS Config rules to send notifications to an SNS topic
C.Use AWS Systems Manager Automation documents as remediation actions
D.Use AWS CloudTrail to log non-compliant events
E.Use Amazon CloudWatch Events to trigger an AWS Step Functions state machine
AnswersA, C

AWS Config rules can be directly associated with remediation actions, and invoking a Lambda function is a fully supported native option. Lambda enables custom code to evaluate and automatically fix non-compliant resources, such as updating security group rules or stopping an instance, based on the rule's evaluation result. This makes it one of the two built-in remediation targets available without needing external services.

Why this answer

AWS Config rules can be configured with remediation actions that invoke an AWS Lambda function. When a resource is evaluated as non-compliant, the rule triggers the Lambda function, which can execute custom logic to modify or fix the resource, such as adjusting security group rules or enabling encryption. This provides automated, programmable remediation directly integrated with AWS Config's evaluation lifecycle.

Exam trap

The trap here is that candidates often confuse notification-based responses (like SNS or CloudWatch Events) with actual automated remediation, forgetting that AWS Config's native remediation actions are limited to Lambda functions and Systems Manager Automation documents, not generic event-driven workflows.

488
MCQhard

A security engineer is reviewing the following IAM policy attached to an S3 bucket: { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": "*", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::example-bucket/*", "Condition": { "IpAddress": { "aws:SourceIp": "10.0.0.0/8" } } } ] } The bucket contains sensitive data and should only be accessible from the corporate network (CIDR 10.0.0.0/8). However, the engineer is concerned that this policy might not be effective. What is the primary security concern with this policy?

A.The bucket policy does not include a Deny statement for requests outside the IP range, so the default allow might still permit access from other IPs.
B.The policy grants public access to the bucket because the Principal is "*", allowing anyone from the specified IP range to access objects.
C.The condition key aws:SourceIp only evaluates the IP address of the client, but if the request comes through a proxy, the IP might not match.
D.The policy uses s3:GetObject but does not include s3:ListBucket, so users cannot see the object list, but they can guess object keys.
AnswerB

The policy sets Principal to '*' in a bucket policy, which means every principal—including unauthenticated anonymous users—is included in the scope of the statement. The condition on aws:SourceIp narrows the network source to a specific IP CIDR, but it does not require any AWS credentials, identity, or account relationship. As a result, any person or service whose traffic originates from that IP range can read objects in the bucket, making the bucket effectively public to that entire network.

Why this answer

The bucket policy uses `"Principal": "*"` combined with `"Effect": "Allow"`, which explicitly grants public access to anyone who meets the condition. While the condition restricts access to the `10.0.0.0/8` IP range, the policy itself is still a public bucket policy — it allows any authenticated or unauthenticated user from that IP range to read objects. This violates the principle of least privilege and exposes sensitive data to any user on the corporate network, not just authorized IAM roles or users.

Exam trap

The trap here is that candidates focus on the IP restriction condition and assume it makes the policy secure, overlooking the fact that `"Principal": "*"` still makes the bucket publicly accessible to any user within that IP range, which is a direct violation of AWS shared responsibility and least privilege principles.

How to eliminate wrong answers

Option A is wrong because the default behavior of IAM and S3 bucket policies is to deny all access unless explicitly allowed; there is no 'default allow' that would permit requests outside the IP range — the policy simply does not grant access to IPs outside `10.0.0.0/8`, so they are implicitly denied. Option C is wrong because the `aws:SourceIp` condition key correctly evaluates the source IP of the request, and while proxies can alter the perceived IP, the condition still works as intended for direct requests; the concern about proxy IPs is a valid operational consideration but not the primary security flaw of this policy. Option D is wrong because the lack of `s3:ListBucket` does not create a security vulnerability — it only prevents listing objects, which is a separate access control concern, and the policy's primary issue is granting public access to sensitive data.

489
MCQeasy

A security engineer is configuring CloudTrail to log all management events across all regions. The engineer wants to ensure that log files are delivered to an S3 bucket owned by a separate AWS account for centralized auditing. Which additional configuration is required to allow the S3 bucket in the other account to receive these logs?

A.Create an S3 bucket policy on the source account's bucket to allow cross-account access.
B.Enable S3 server-side encryption with KMS on the destination bucket.
C.Create an IAM role in the source account and attach a trust policy for CloudTrail.
D.Add a bucket policy to the destination S3 bucket that allows CloudTrail to write objects.
AnswerD

The destination bucket must have a resource-based policy that explicitly allows CloudTrail's service principal (`cloudtrail.amazonaws.com`) to write objects into that bucket, typically with `s3:PutObject` permission and a condition restricting access to the source account's trail. This bucket policy is the only mechanism that authorizes the cross-account write path because CloudTrail in the source account presents no IAM role or source-account user credentials to S3. For a complete setup, the trail in the source account references the destination bucket ARN, and the bucket policy also includes `s3:GetBucketAcl` or `s3:GetBucketLocation` as needed for CloudTrail to verify bucket ownership. Without this policy, CloudTrail will fail with an access denied error during delivery.

Why this answer

CloudTrail delivers log files to an S3 bucket in a separate account by writing objects across accounts. The destination bucket must have a bucket policy that explicitly grants CloudTrail (the service principal `cloudtrail.amazonaws.com`) permission to write objects (e.g., `s3:PutObject`). Without this policy, CloudTrail cannot deliver logs to the cross-account bucket, even if the source account has proper CloudTrail configuration.

Exam trap

The trap here is that candidates confuse cross-account S3 access with IAM roles, assuming CloudTrail needs an IAM role in the source account to assume permissions, when in fact CloudTrail uses a service principal and a resource-based bucket policy on the destination bucket.

How to eliminate wrong answers

Option A is wrong because the source account does not own the destination bucket; the bucket policy must be on the destination bucket (owned by the separate account), not on a source account bucket. Option B is wrong because enabling S3 server-side encryption with KMS on the destination bucket is optional and not required for cross-account log delivery; it addresses encryption, not access control. Option C is wrong because CloudTrail does not use an IAM role in the source account to write to a cross-account S3 bucket; it relies on a resource-based policy (bucket policy) on the destination bucket, not a trust policy for CloudTrail.

490
Multi-Selecthard

A company is migrating a legacy application to AWS. The application requires two-way communication between the web servers and the database servers using TCP port 3306. The security team wants to follow the principle of least privilege. Which TWO actions should be taken to secure the traffic?

Select 2 answers
A.Create a security group for the web servers that allows outbound traffic on port 3306 to the database security group.
B.Create a security group for the database servers that allows inbound traffic on port 3306 from the web subnet CIDR.
C.Place the database servers in a public subnet for easier connectivity.
D.Configure the network ACL for the database subnet to allow inbound traffic on port 3306 from the web subnet CIDR.
E.Create a security group for the database servers that allows inbound traffic on port 3306 from the web security group ID.
AnswersA, E

This is correct because security groups are stateful: when the web server initiates a TCP connection to the database on port 3306, the corresponding return traffic is automatically allowed back into the web server without an explicit inbound rule. By setting the destination to the database security group ID rather than an IP range, the rule dynamically applies to every instance currently associated with that security group, which simplifies management if the database fleet scales or changes. This outbound rule scopes traffic to the specific database tier and avoids opening port 3306 to the whole VPC.

Why this answer

Security groups are stateful, so allowing outbound traffic on port 3306 from the web servers to the database security group automatically permits the corresponding return traffic. This adheres to the principle of least privilege by specifying the destination as the database security group ID rather than a broad CIDR range, ensuring only the intended web servers can initiate the connection.

Exam trap

The trap here is that candidates often confuse security groups (stateful, instance-level) with network ACLs (stateless, subnet-level) and incorrectly assume that a subnet CIDR-based rule in a security group is equivalent to using a security group ID, when in fact the latter provides stricter least-privilege control by limiting access to only the specific instances in the web security group.

491
MCQeasy

An IAM policy attached to a user contains the above statements. The user attempts to download an object from 'example-bucket/confidential/report.pdf'. What is the result?

A.The download fails because the user is not an administrator.
B.The download succeeds because the user can access other objects.
C.The download succeeds because the first statement allows GetObject.
D.The download fails because the deny statement applies to the object.
AnswerD

The Deny statement's resource element is scoped to the exact ARN of the requested object, so it matches this specific GetObject call. In IAM's evaluation logic, an explicit Deny that matches the action and resource is an absolute veto: it overrides all Allow statements and default-deny is not even reached. Consequently, the download fails with AccessDenied because the request is explicitly denied, not because of any other condition or lack of permission.

Why this answer

The explicit Deny statement in the IAM policy takes precedence over any Allow statement, so even though the first statement allows s3:GetObject, the deny on the confidential prefix blocks the download. AWS evaluates all applicable policies and any explicit Deny wins. Therefore the download fails because the deny statement applies to the object.

Exam trap

SCS-C02 often tests the misconception that an Allow statement guarantees access, when the correct rule is that any explicit Deny in any applicable policy overrides all Allows.

How to eliminate wrong answers

Option A is wrong because the failure is not due to lack of administrator privileges; IAM evaluation is based on the specific actions and resources in the policy, not on admin status. Option B is wrong because access to other objects is irrelevant — IAM evaluates each request against the specific resource ARN, and the deny targets the confidential prefix. Option C is wrong because it ignores the explicit Deny, which overrides the Allow in AWS IAM policy evaluation logic.

492
MCQhard

A company has a VPC with public and private subnets. The private sub host Amazon RDS instances. To allow the RDS instances to access the internet for software updates without exposing them to inbound internet traffic, what should be configured?

A.Use a VPN connection to an on-premises network that has internet access.
B.Set up a VPC peering connection to a VPC with internet access.
C.Create a NAT gateway in a public subnet and add a route to the NAT gateway in the private subnet route table.
D.Attach an internet gateway to the private subnet route table.
AnswerC

A NAT gateway deployed in a public subnet with an associated elastic IP provides outbound internet connectivity for instances in private subnets. You must add a default route (0.0.0.0/0) in the private subnet's route table pointing to the NAT gateway's interface or ID, ensuring instances can initiate outbound connections while remaining inaccessible from the internet.

Why this answer

A NAT gateway in a public subnet allows instances in private subnets to initiate outbound traffic to the internet (e.g., for software updates) while preventing any unsolicited inbound connections from the internet. Adding a route in the private subnet's route table that points 0.0.0.0/0 to the NAT gateway enables this outbound-only internet access for the RDS instances.

Exam trap

The trap here is that candidates often confuse a NAT gateway with an internet gateway, mistakenly thinking an internet gateway can be attached to a private subnet, or they overlook that a NAT gateway must be placed in a public subnet with an internet gateway attached to that subnet's route table to function correctly.

How to eliminate wrong answers

Option A is wrong because a VPN connection to an on-premises network with internet access would route traffic through the on-premises network, adding latency and complexity, and is not the standard AWS solution for outbound-only internet access from private subnets. Option B is wrong because VPC peering does not provide internet access; it only enables private connectivity between VPCs, and the peered VPC would need its own internet gateway and NAT gateway to provide internet access, making this an indirect and unnecessarily complex solution. Option D is wrong because attaching an internet gateway to a private subnet route table would expose the RDS instances to inbound internet traffic, violating the requirement to prevent inbound exposure, and internet gateways are designed for public subnets, not private ones.

493
MCQeasy

A company wants to restrict access to an S3 bucket so that only traffic from a specific VPC can read objects. Which security mechanism should be used?

A.Use an S3 bucket policy with a condition that restricts access to the VPC endpoint ID.
B.Assign an IAM role to the S3 bucket.
C.Attach a security group to the S3 bucket.
D.Configure a network ACL on the VPC subnet to allow traffic to S3.
AnswerA

A bucket policy can use the aws:SourceVpce condition key to restrict access to a specific VPC endpoint. This allows only traffic that arrives through the corresponding gateway or interface endpoint to reach the bucket, while all other sources, including the public internet, are denied. This resource-based control is the correct way to enforce VPC-only access to an S3 bucket.

Why this answer

An S3 bucket policy can include a condition that restricts access to traffic originating from a specific VPC endpoint. By using the `aws:SourceVpce` condition key, the policy ensures that only requests coming through the specified VPC endpoint (interface or gateway) are allowed to read objects, effectively locking down access to the VPC.

Exam trap

The trap here is that candidates often confuse network-level controls (security groups, NACLs) with resource-based policies, mistakenly thinking they can apply security groups or NACLs to S3 buckets, when in fact S3 only supports bucket policies and IAM policies for access control.

How to eliminate wrong answers

Option B is wrong because IAM roles are assigned to principals (users, services) to grant permissions, not to S3 buckets; buckets themselves cannot assume roles. Option C is wrong because security groups are network-level firewalls for EC2 instances and other AWS resources, but S3 buckets are not network interfaces and cannot have security groups attached. Option D is wrong because network ACLs control traffic at the subnet level and cannot restrict access to a specific S3 bucket; they also cannot enforce bucket-level conditions like VPC endpoint IDs.

494
MCQeasy

A security engineer needs to ensure that all data stored in an Amazon S3 bucket is encrypted at rest. The bucket must use server-side encryption with a key managed by the customer (SSE-C). What must the engineer include in the PUT request to enforce this?

A.x-amz-server-side-encryption-customer-algorithm and x-amz-server-side-encryption-customer-key
B.x-amz-server-side-encryption: AES256
C.x-amz-server-side-encryption: aws:kms
D.x-amz-server-side-encryption-bucket-key-enabled: true
AnswerA

These two headers are mandatory for SSE-C, where the customer supplies the raw 256-bit AES key in each request rather than letting AWS hold key material. x-amz-server-side-encryption-customer-algorithm must be set to AES256, and x-amz-server-side-encryption-customer-key must contain the base64-encoded key, typically accompanied by x-amz-server-side-encryption-customer-key-MD5 to verify integrity. AWS discards the key after encrypting the object and stores only a salted HMAC for later validation, so you must re-supply these headers on every PUT, GET, HEAD, or range read.

Why this answer

SSE-C requires the client to provide both the encryption algorithm and the encryption key in the PUT request headers. The `x-amz-server-side-encryption-customer-algorithm` header must be set to `AES256`, and the `x-amz-server-side-encryption-customer-key` header must contain the base64-encoded 256-bit key. Without these headers, S3 will not apply customer-provided encryption keys, and the object will not be encrypted with SSE-C.

Exam trap

The trap here is that candidates confuse the `x-amz-server-side-encryption` header (used for SSE-S3 and SSE-KMS) with the SSE-C-specific headers, leading them to pick Option B or C, which do not allow customer-provided keys.

How to eliminate wrong answers

Option B is wrong because `x-amz-server-side-encryption: AES256` specifies SSE-S3, where AWS manages the key, not the customer. Option C is wrong because `x-amz-server-side-encryption: aws:kms` specifies SSE-KMS, which uses AWS KMS keys, not customer-provided keys. Option D is wrong because `x-amz-server-side-encryption-bucket-key-enabled: true` enables S3 Bucket Keys for SSE-KMS, reducing KMS API calls, but does not enforce SSE-C or provide customer-managed keys.

495
Multi-Selecteasy

A company wants to receive notifications when AWS CloudTrail logs are delivered to an S3 bucket. Which TWO AWS services can be used together to achieve this? (Choose TWO.)

Select 2 answers
A.Amazon S3 Event Notifications
B.AWS CloudTrail
C.AWS Lambda
D.Amazon Simple Queue Service (SQS)
E.Amazon Simple Notification Service (SNS)
AnswersA, E

S3 Event Notifications are generated by the S3 service when an object is created (s3:ObjectCreated:*) and can be delivered to SNS, SQS, or Lambda. Placing this configuration on the CloudTrail log bucket triggers a notification each time CloudTrail writes a new log file, enabling downstream alerting without polling.

Why this answer

Amazon S3 Event Notifications can be configured to publish events (like `s3:ObjectCreated:*`) when CloudTrail logs are delivered to the S3 bucket. These notifications can be sent directly to Amazon SNS, which then delivers the notification to subscribers (e.g., email, SMS, or HTTP endpoints). Together, S3 Event Notifications and SNS provide a serverless, real-time notification pipeline without needing custom polling or compute resources.

Exam trap

The trap here is that candidates often think Lambda is mandatory to process S3 events and send notifications, but S3 Event Notifications can directly target SNS without any compute layer, making Lambda an unnecessary third service for this specific requirement.

496
MCQmedium

A company has multiple AWS accounts managed through AWS Organizations. The security team needs to ensure that no EC2 instances are launched without an approved Amazon Machine Image (AMI). Which governance control should be implemented?

A.Use a service control policy (SCP) that denies ec2:RunInstances unless the AMI ID is in an approved list.
B.Deploy an AWS Config rule that triggers a Lambda function to terminate non-compliant instances.
C.Use AWS CloudTrail to monitor instance launches and alert the security team.
D.Use an IAM policy that restricts ec2:RunInstances to approved AMIs.
AnswerA

A service control policy (SCP) is the correct preventive control because it applies at the AWS Organizations level and acts as a permission boundary that no IAM principal in a member account can bypass, including account administrators. By adding a Deny statement for ec2:RunInstances with a condition such as ec2:ImageId not being in the approved AMI list (using StringNotEquals or ForAnyValue:StringNotEquals), the restriction is enforced before any EC2 instance is launched. SCPs do not grant permissions, but they effectively block non-compliant launches across all accounts and future accounts.

Why this answer

A service control policy (SCP) is the correct governance control because it operates at the AWS Organizations level, allowing the security team to enforce a deny on ec2:RunInstances across all member accounts unless the AMI ID matches an approved list. SCPs are account permission boundaries that cannot be overridden by IAM policies within the account, ensuring that no user or role can launch an EC2 instance with an unapproved AMI, even if they have full administrative privileges. This provides a preventive control that blocks non-compliant actions before they occur, which is more robust than detective or reactive measures.

Exam trap

The trap here is that candidates often confuse IAM policies with SCPs, assuming that an IAM policy can enforce organization-wide controls, but SCPs are the only mechanism that applies as a permission boundary across all accounts in an AWS Organization and cannot be overridden by account administrators.

How to eliminate wrong answers

Option B is wrong because an AWS Config rule with a Lambda function to terminate non-compliant instances is a detective and reactive control, not a preventive governance control; it only acts after the instance is launched, incurring potential cost and security exposure. Option C is wrong because AWS CloudTrail is a logging and monitoring service that records API calls but does not prevent the launch; it only alerts the security team after the fact, leaving a window for non-compliant instances to run. Option D is wrong because an IAM policy that restricts ec2:RunInstances to approved AMIs can be bypassed by users with higher privileges (e.g., an administrator) or by modifying the policy within the account, whereas an SCP applies as a boundary that cannot be overridden by account-level IAM policies.

497
MCQeasy

A developer is trying to use the AWS CLI to list objects in an S3 bucket but receives an AccessDenied error. The developer has an IAM user with a policy that allows s3:ListBucket on the bucket. What could be causing the error?

A.The developer has not enabled MFA on their IAM user.
B.The S3 bucket has a bucket policy that denies access to the developer's IAM user.
C.The S3 bucket does not exist in the same AWS region as the CLI is configured.
D.The IAM policy is attached to a group, not directly to the user.
AnswerB

An explicit deny statement in a bucket policy always overrides any allow granted by an IAM policy, regardless of how specific or broad that allow is. Here, even if the developer's IAM user is explicitly allowed `s3:ListBucket` by an identity-based policy, a bucket policy that contains a matching `Effect: "Deny"` for that principal (or a deny condition that matches the user) will make the request fail with AccessDenied. This is the only option that explains a denied request despite valid credentials and an otherwise permissive IAM setup.

Why this answer

S3 access decisions are evaluated by combining IAM identity-based policies with bucket policies, and an explicit Deny in either location always wins. Even though the developer's IAM policy grants s3:ListBucket, a bucket policy that explicitly denies the user's principal overrides that Allow. This is the classic 'explicit deny beats allow' rule in AWS's policy evaluation logic.

Exam trap

SCS-C02 often tests the misconception that an IAM Allow is sufficient for S3 access, when in fact an explicit Deny in a bucket policy, SCP, or permission boundary silently overrides it.

How to eliminate wrong answers

Option A is wrong because MFA is not required for s3:ListBucket by default; MFA is only enforced if a policy explicitly includes the aws:MultiFactorAuthPresent condition, and nothing in the scenario indicates that. Option C is wrong because S3 bucket names are globally unique and the CLI automatically resolves the correct regional endpoint; a region mismatch produces a redirect or NoSuchBucket error, not AccessDenied. Option D is wrong because IAM policies attached to a group are inherited by group members, so attaching the policy to a group instead of directly to the user still grants the permission.

498
MCQeasy

A company needs to securely store database credentials for a legacy application running on Amazon EC2. The credentials are currently hardcoded in the application code. Which service should be used to rotate and retrieve secrets automatically?

A.AWS Systems Manager Parameter Store with a SecureString parameter.
B.AWS Key Management Service (KMS).
C.AWS Secrets Manager.
D.AWS CloudHSM.
AnswerC

AWS Secrets Manager is purpose-built for this scenario, offering secure storage, fine-grained access policies, and automatic credential rotation via built-in integrations with services like Amazon RDS and Redshift. It also natively supports secret versioning and schedule-based rotation using Lambda, so database credentials can be refreshed without application downtime or manual intervention.

Why this answer

AWS Secrets Manager is purpose-built for storing, rotating, and retrieving secrets such as database credentials. It natively supports automatic rotation via Lambda functions and provides fine-grained access control using IAM and KMS. The legacy application can retrieve credentials programmatically using the Secrets Manager API or SDK, eliminating hardcoded credentials.

Exam trap

SCS-C02 often tests the distinction between Secrets Manager and Parameter Store, where candidates incorrectly assume Parameter Store's SecureString provides automatic rotation, but only Secrets Manager offers native rotation for database credentials.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store with SecureString can store encrypted parameters but does not provide built-in automatic rotation for database credentials; rotation must be implemented manually. Option B is wrong because AWS KMS is a key management service for encryption keys, not a secrets store; it cannot store or rotate database credentials. Option D is wrong because AWS CloudHSM is a hardware security module for dedicated key storage and cryptographic operations, not a secrets management service with rotation capabilities.

499
MCQmedium

A security engineer is tasked with implementing network segmentation for a multi-tier application. The web tier must be accessible from the internet, but the application tier must only be accessible from the web tier. The database tier must only be accessible from the application tier. All tiers are in the same VPC. Which design meets these requirements?

A.Create a security group for each tier. Configure inbound rules to allow traffic only from the preceding tier's security group.
B.Use a single security group for all instances and use IAM policies to restrict access.
C.Place each tier in separate subnets and use network ACLs with CIDR blocks to allow traffic between tiers.
D.Place all instances in public subnets and restrict access using security groups.
AnswerA

Security group chaining gives tier-specific, stateful filtering without hard-coding IP addresses. Define a separate security group for the web, app, and database tiers, then set inbound rules on the app SG that allow traffic from the web SG (on the app port) and on the database SG that allow traffic from the app SG. Because the source is an SG ID, any instance associated with the preceding tier automatically has access, and newly launched instances in that tier are included without updating CIDR rules. This enforces least-privilege east-west traffic isolation.

Why this answer

Security groups can reference other security groups as sources in inbound rules, allowing granular traffic control between tiers without CIDR blocks. This approach allows the web tier security group to allow inbound from the internet, the app tier security group to allow inbound only from the web tier security group, and the database tier security group to allow inbound only from the app tier security group. Option B is incorrect because IAM policies control user permissions, not network traffic.

Option C is incorrect because network ACLs with CIDR blocks are less specific and do not scale well, and placing tiers in separate subnets is not necessary. Option D is incorrect because placing all instances in public subnets unnecessarily exposes them to the internet, increasing security risk.

500
MCQhard

A company has an IAM policy that allows s3:GetObject on all buckets. However, a specific S3 bucket policy explicitly denies s3:GetObject to all principals. An IAM user with the IAM policy tries to read an object from that bucket. What is the result?

A.The request is allowed because the IAM policy is more specific.
B.The request is allowed because the IAM policy allows the action.
C.The request is denied because the bucket policy applies only to IAM users.
D.The request is denied because the explicit deny in the bucket policy overrides the allow in the IAM policy.
AnswerD

This is correct because AWS IAM policy evaluation uses a single decision tree in which any explicit deny overrides all allow statements, regardless of where those allows originate. The IAM policy allows s3:GetObject, but the bucket policy contains an explicit deny for the same action and principal. That explicit deny takes precedence, causing the request to be denied. This fundamental rule ensures that explicit deny statements are always authoritative over allows.

Why this answer

D is correct because AWS IAM policy evaluation logic follows an explicit deny override: any explicit deny in any applicable policy (resource-based or identity-based) overrides any allow. The S3 bucket policy explicitly denies s3:GetObject to all principals, so even though the IAM policy allows the action, the explicit deny takes precedence, resulting in a denied request.

Exam trap

The trap here is that candidates often assume an identity-based allow (IAM policy) can override a resource-based deny (bucket policy), but AWS explicitly prioritizes denies over allows across all policy types.

How to eliminate wrong answers

Option A is wrong because AWS does not use a 'more specific' rule between policies; explicit deny always overrides allow regardless of specificity. Option B is wrong because the IAM policy allow is overridden by the explicit deny in the bucket policy; an allow alone does not guarantee access when a deny exists. Option C is wrong because bucket policies apply to all principals, not just IAM users; the explicit deny in the bucket policy applies to the IAM user as a principal.

501
MCQhard

A company wants to deploy a web application that must be accessible over HTTPS only. The application runs behind an Application Load Balancer (ALB). The security team wants to enforce HTTP Strict Transport Security (HSTS) to prevent downgrade attacks. Which configuration achieves this?

A.Use AWS CloudFront with a custom header that enforces HSTS
B.Configure the ALB to redirect HTTP traffic to HTTPS and have the application set the Strict-Transport-Security header in the response
C.Configure the ALB listener to use HTTPS only and set a custom header via a listener rule
D.Enable HSTS on the ALB via the AWS Management Console
AnswerB

This is the correct architecture because it separates transport security into two complementary layers: the ALB listener uses a redirect action to convert any plain HTTP request to HTTPS, forcing TLS for every attempt, and the application returns the Strict-Transport-Security header in its response, which instructs browsers to automatically use HTTPS for the domain for the specified duration. ALB does not natively generate HSTS headers, so the application must supply it after a successful TLS connection. This satisfies both the immediate encryption requirement and the long-term HSTS enforcement.

Why this answer

HSTS is enforced by the web application sending the `Strict-Transport-Security` header in HTTPS responses. By configuring the ALB to redirect HTTP to HTTPS, all traffic is forced over TLS, and the application can then set the HSTS header to instruct browsers to always use HTTPS for future requests. The ALB itself does not natively set HSTS headers; this must be done at the application layer.

Exam trap

The trap here is that candidates assume HSTS can be configured directly on the ALB (like a security policy or listener rule), when in fact it must be implemented at the application layer by setting the response header, and the ALB only handles traffic redirection.

How to eliminate wrong answers

Option A is wrong because AWS CloudFront can forward or add custom headers, but it does not natively enforce HSTS; the `Strict-Transport-Security` header must still be set by the origin (the application) or via a CloudFront Function/Lambda@Edge, and simply using a custom header does not implement HSTS correctly. Option C is wrong because ALB listener rules can only modify or insert headers for requests, not for responses; HSTS requires the header to be present in the HTTP response from the target, not in the request. Option D is wrong because the ALB does not have a built-in HSTS feature or setting in the AWS Management Console; HSTS is an application-layer header and cannot be enabled directly on the load balancer.

502
MCQmedium

An organization has a production AWS account and a development AWS account. Developers need to access the production account from the development account using IAM roles. What is the MOST secure way to set this up?

A.Create an IAM role in the production account with a trust policy allowing the development account to assume it.
B.Create IAM users in the production account and share access keys with developers.
C.Establish a VPN connection between the accounts and use directory credentials.
D.Create the same IAM users in both accounts with identical permissions.
AnswerA

This is the correct approach because it uses an IAM role with a trust policy that explicitly delegates the ability to assume the role to the development account. When the development account calls sts:AssumeRole, it receives temporary, automatically rotating credentials scoped to the permissions policy attached to the role, so no long-term access keys are stored or shared. The trust policy should also include a condition such as aws:SourceAccount to protect against the confused deputy problem and ensure only the intended development account can request the role.

Why this answer

It uses cross-account IAM roles, allowing developers in the development account to assume a role in the production account using AWS Security Token Service (STS). This provides temporary, least-privilege credentials without sharing long-term access keys. Option B is insecure because sharing access keys creates long-term credentials that are hard to rotate and manage.

Option C is incorrect: a VPN provides network connectivity but does not grant IAM access. Option D is incorrect because IAM users are account-specific; duplicating users across accounts does not enable cross-account access.

503
MCQmedium

Refer to the exhibit. A role has two policies attached. The custom policy includes an Allow for s3:PutObject. An IAM user assumes this role and tries to upload a file to S3. What happens?

A.The upload succeeds because the custom policy allows s3:PutObject
B.The upload fails because the managed policy only allows read
C.The upload is denied by default because no explicit allow
D.The upload fails because the managed policy overrides the custom policy
AnswerA

The upload succeeds because IAM policies are evaluated as a combined set, and the custom policy explicitly grants the s3:PutObject permission required for uploading an object. An explicit allow in any attached identity-based policy is sufficient to permit the action, overriding the default implicit deny. The read-only managed policy does not block this; it simply grants no write access, but the custom policy fills that gap.

Why this answer

The upload succeeds because IAM evaluates policies in a default-deny environment, and the custom policy attached to the role explicitly allows s3:PutObject. When a user assumes the role, the effective permissions are the union of all attached policies; the managed policy's read-only restriction does not block the explicit allow for s3:PutObject. Since there is no explicit deny for s3:PutObject, the allow from the custom policy grants the action.

Exam trap

The trap here is that candidates mistakenly believe a more restrictive policy (managed read-only) overrides a less restrictive one (custom allow), but IAM never overrides policies; it only denies if an explicit deny exists, and allows if any explicit allow exists.

How to eliminate wrong answers

Option B is wrong because the managed policy's read-only restriction does not override an explicit allow; IAM uses an allow-list model where any explicit allow permits the action unless there is an explicit deny. Option C is wrong because the custom policy provides an explicit allow for s3:PutObject, so the action is not denied by default. Option D is wrong because no policy overrides another in IAM; the effective permissions are the union of all allows minus any explicit denies, and the managed policy does not contain a deny for s3:PutObject.

504
MCQeasy

A security analyst wants to monitor unsuccessful login attempts to the AWS Management Console. Which AWS service and log combination should be used?

A.Amazon S3 server access logs.
B.VPC Flow Logs.
C.Amazon CloudWatch Logs.
D.AWS CloudTrail.
AnswerD

AWS CloudTrail records the ConsoleLogin management event for every AWS Management Console sign-in attempt, including both successful and failed authentications. A failed login appears as an event with the eventName ConsoleLogin and responseElements.ConsoleLogin.LoginResult set to Failure, along with details like the IAM user or root principal, source IP address, user agent, and MFA usage. Security analysts can query these events with the AWS CLI lookup-events command, the CloudTrail console, or by analyzing the JSON log files delivered to S3 or CloudWatch Logs.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to the AWS Management Console, including failed login attempts (ConsoleLogin events with an 'errorMessage' field). CloudTrail logs these events as management events, which can be delivered to Amazon CloudWatch Logs or an S3 bucket for monitoring and alerting. This makes it the only option that captures authentication failures at the console level.

Exam trap

The trap here is that candidates confuse CloudWatch Logs (a log destination) with a log source, forgetting that CloudWatch Logs cannot capture console login events without CloudTrail delivering them first.

How to eliminate wrong answers

Option A is wrong because Amazon S3 server access logs record requests made to an S3 bucket (e.g., GET, PUT, DELETE), not AWS Management Console login attempts. Option B is wrong because VPC Flow Logs capture metadata about IP traffic flowing through a VPC (e.g., source/destination IPs, ports, protocols), not authentication events. Option C is wrong because Amazon CloudWatch Logs is a log storage and monitoring service, not a log source; it cannot generate logs of console login attempts on its own—it requires a service like CloudTrail to deliver those logs.

505
MCQhard

A company uses AWS Organizations to manage multiple accounts. The security team needs to implement a centralized logging solution where all VPC Flow Logs from all accounts are sent to a central S3 bucket in the security account. The flow logs must be encrypted with a customer-managed KMS key (CMK) that is owned by the security account. The security engineer has enabled VPC Flow Logs in each account and configured the destination to be the central S3 bucket. However, the flow logs are not being delivered. The engineer checks the S3 bucket policy and confirms that it grants the required permissions to the Flow Logs service principal. What is the MOST likely cause of the failure?

A.The VPC Flow Logs service does not support cross-account delivery.
B.The KMS key policy does not grant the Flow Logs service principal permission to use the key.
C.CloudTrail must be enabled in the source account for Flow Logs to work.
D.The S3 bucket policy is missing a condition for source account.
AnswerB

VPC Flow Logs encrypts delivered records using the destination CMK, so the Flow Logs service principal needs kms:GenerateDataKey and kms:Decrypt in the key policy. The S3 bucket policy alone cannot grant that KMS access, blocking delivery.

Why this answer

When VPC Flow Logs are delivered to an S3 bucket encrypted with a customer-managed KMS key, the Flow Logs service principal must have permission to use that key. Even if the S3 bucket policy grants access, the KMS key policy must also allow the Flow Logs service to encrypt data. Without this, the delivery fails.

This is the most likely cause given the scenario.

Exam trap

SCS-C02 often tests the misconception that S3 bucket policy alone is sufficient for encrypted delivery — candidates forget that KMS key policies are separate and must explicitly grant the service principal access.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs do support cross-account delivery to an S3 bucket in another account, provided the bucket policy and KMS key policy allow it. Option C is wrong because CloudTrail is not required for VPC Flow Logs to function; they are independent services. Option D is wrong because while a condition for source account might be needed in some cases, the scenario already states the bucket policy grants required permissions, and the more specific issue with KMS key policy is the likely cause.

506
Drag & Dropmedium

Drag and drop the steps to respond to a suspected AWS IAM credential compromise in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Credential compromise response starts with rotation, log review, disabling user, revoking temp creds, and notification.

507
MCQeasy

A company is using AWS WAF to protect its Application Load Balancer (ALB). The security team wants to block requests that do not contain a valid API key in the HTTP header 'X-API-Key'. Which WAF rule type should be used?

A.String match condition
B.Regex pattern set
C.Rate-based rule
D.IP set
AnswerB

A regex pattern set lets you define a regular expression that describes the structural format of valid API keys, such as a required prefix followed by a specific number of alphanumeric characters. In a WAF rule, you can use the 'not' operator to inspect the API key header and block any request whose key does not match this pattern, providing centralized pattern-based validation at the edge. This directly addresses the requirement to reject invalid API keys.

Why this answer

A regex pattern set rule is the correct choice because it allows you to define a regular expression pattern that matches the expected format of valid API keys in the 'X-API-Key' header. AWS WAF regex pattern sets can be used in a rule to inspect the header value and block requests that do not match the pattern, providing flexible and precise validation beyond simple string matching.

Exam trap

The trap here is that candidates often confuse string match conditions with regex pattern sets, assuming that a simple 'contains' or 'starts with' string match is sufficient for validating structured data like API keys, when in fact regex provides the necessary pattern flexibility.

How to eliminate wrong answers

Option A is wrong because a string match condition can only check for exact or substring matches, not complex patterns like varying alphanumeric formats or specific character sequences typical of API keys. Option C is wrong because a rate-based rule is designed to block IPs based on request rate thresholds, not to inspect header content for a valid API key. Option D is wrong because an IP set rule blocks or allows traffic based on source IP addresses, not on the presence or validity of an API key in a header.

508
MCQeasy

A company uses AWS Organizations and wants to centrally manage CloudTrail trails across all accounts. Which feature should be enabled?

A.CloudTrail organization trail
B.Cross-account CloudTrail
C.Service Control Policy for CloudTrail
D.AWS Config aggregator
AnswerA

An organization trail is a dedicated CloudTrail feature created in the AWS Organizations management account that automatically logs API activity for every account in the organization and delivers those logs to a single S3 bucket. It is configured once and applies across all AWS Regions, providing a central, management-account-owned audit record that member accounts cannot modify or delete. This is the native, scalable mechanism for centrally managing CloudTrail logs across the entire organization.

Why this answer

A CloudTrail organization trail is a trail created in the management account of an AWS Organization that automatically applies to all member accounts. It logs events from every account in the organization to a single S3 bucket, enabling centralized management and compliance. This is the native feature designed for multi-account CloudTrail governance, requiring no per-account configuration.

Exam trap

SCS-C02 often tests the misconception that SCPs can enforce CloudTrail logging or that AWS Config aggregator can centralize CloudTrail logs, when in fact only an organization trail provides automatic, multi-account CloudTrail management.

How to eliminate wrong answers

Option B is wrong because 'cross-account CloudTrail' is not a specific AWS feature; while you can share trails across accounts manually, it lacks the automatic, organization-wide scope of an organization trail. Option C is wrong because Service Control Policies (SCPs) are used to restrict permissions, not to enable or manage CloudTrail trails; they cannot create or centralize trails. Option D is wrong because AWS Config aggregator collects configuration and compliance data across accounts, not CloudTrail event logs, and does not manage trails.

509
MCQeasy

A company uses AWS Secrets Manager to store database credentials. They need to rotate the secrets automatically every 30 days. Which rotation strategy should they use?

A.Use AWS Systems Manager Parameter Store to rotate the secret.
B.Manually update the secret every 30 days.
C.Enable automatic rotation in Secrets Manager and specify a Lambda rotation function.
D.Use an AWS Config rule to trigger rotation.
AnswerC

Enabling automatic rotation in AWS Secrets Manager and specifying a Lambda rotation function is the correct approach. Secrets Manager invokes the Lambda function on a configurable schedule (e.g., every 30 days), and the function follows the rotation protocol—creating a new credential, updating the database user/password, and storing the new value as a version of the secret. This allows applications to automatically retrieve the new credential via the secret ARN while keeping the database credential synchronized, and it supports multi-user or single-user rotation strategies.

Why this answer

AWS Secrets Manager natively supports automatic rotation of secrets, and you must specify an AWS Lambda function to perform the rotation logic (e.g., updating the database password and storing the new secret). This ensures the secret is rotated on a schedule (every 30 days) without manual intervention, meeting the requirement for automated rotation.

Exam trap

The trap here is that candidates may confuse AWS Systems Manager Parameter Store with Secrets Manager, thinking Parameter Store can also rotate secrets automatically, or they may incorrectly assume AWS Config rules can schedule rotations, when in fact only Secrets Manager with a Lambda function provides native automatic rotation.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store does not have built-in automatic rotation capabilities; it is a parameter store, not a secrets rotation service, and would require custom automation to rotate secrets. Option B is wrong because manually updating the secret every 30 days is not automated and defeats the purpose of using Secrets Manager for rotation; it introduces human error and operational overhead. Option D is wrong because AWS Config rules are used for compliance evaluation and remediation, not for scheduling or executing secret rotation; they can trigger a Lambda function for remediation but are not designed as a rotation scheduler.

510
MCQeasy

An organization wants to use AWS Organizations to centrally manage permissions for multiple accounts. Which IAM feature is used to grant cross-account access within the organization?

A.IAM roles
B.Service control policies (SCPs)
C.Resource-based policies
D.IAM groups
AnswerA

IAM roles are the correct mechanism because they support cross-account trust relationships: the organization can configure a role in a target account with a trust policy allowing principals from a central account to assume it. When a user or service in the central account calls sts:AssumeRole, AWS STS returns temporary credentials scoped to the role's permissions policy, enabling centrally governed access across accounts. This is the standard way to grant access to AWS accounts, and it can be combined with AWS Organizations' central management for auditing and policy enforcement.

Why this answer

IAM roles are the standard mechanism for granting cross-account access within AWS Organizations. A role in the target (trusting) account defines a trust policy that names principals in other accounts as trusted entities, and those principals call sts:AssumeRole to obtain temporary credentials scoped to the role's permissions policy. This avoids creating duplicate IAM users in every account and is the recommended pattern for centralized, auditable cross-account access.

Exam trap

SCS-C02 often tests the misconception that SCPs grant permissions — candidates confuse SCPs (which only limit maximum permissions) with IAM roles (which actually grant cross-account access).

How to eliminate wrong answers

Option B is wrong because SCPs only define the maximum permissions boundary for accounts in an organization — they restrict what identities can do but do not themselves grant any permissions or establish cross-account trust. Option C is wrong because resource-based policies (e.g., S3 bucket policies) can grant cross-account access to specific resources, but they are resource-specific and not the general IAM feature used to grant cross-account access across an organization. Option D is wrong because IAM groups are containers for IAM users within a single account and cannot span accounts or be referenced in a trust policy.

511
MCQhard

A financial services company runs a critical application on Amazon EC2 instances in a VPC. The application processes sensitive financial data and must meet strict compliance requirements. The security team recently discovered that an EC2 instance was compromised due to an unpatched vulnerability. The attacker used the instance's IAM role to access an S3 bucket containing customer data and exfiltrated the data. The security team needs to prevent such incidents in the future. They have implemented the following controls: - All EC2 instances are launched in private subnets. - The IAM roles used by EC2 instances follow the principle of least privilege. - Security groups restrict inbound and outbound traffic. - AWS Systems Manager Patch Manager is used to patch instances. - AWS CloudTrail is enabled and logs are sent to a centralized S3 bucket. - Amazon GuardDuty is enabled. Despite these controls, the team is concerned about the blast radius if an instance is compromised again. Which additional measure would MOST effectively limit the blast radius of a compromised EC2 instance?

A.Enable VPC Flow Logs to monitor traffic to S3.
B.Use S3 VPC Endpoints with a bucket policy that only allows access from the VPC endpoint, and use Systems Manager Session Manager instead of SSH.
C.Deploy AWS WAF in front of the S3 bucket.
D.Create an AWS Config rule to detect S3 access from EC2 instances.
AnswerB

Creating an S3 VPC endpoint and attaching a bucket policy that denies all access unless the request originates from that endpoint confines S3 traffic to the AWS internal network, removing exposure to the public internet. This, combined with replacing SSH with AWS Systems Manager Session Manager, eliminates inbound SSH ports and relies on IAM-based, auditable session access instead of static keys. Together, these controls shrink the attack surface and provide preventive, policy-enforced protection against both network-level exfiltration and credential compromise.

Why this answer

Using an S3 VPC endpoint with a bucket policy that restricts access exclusively to that endpoint ensures that compromised EC2 instances can only reach S3 through the VPC endpoint, preventing data exfiltration over the internet. Additionally, replacing SSH with Systems Manager Session Manager eliminates the need for open inbound SSH ports and provides fine-grained access control through IAM, reducing the attack surface and blast radius.

Exam trap

The trap here is that candidates may choose VPC Flow Logs (Option A) thinking it provides active protection, but it is only a monitoring tool that does not reduce the blast radius; the key is to implement network-level and access-level restrictions that prevent data exfiltration even if an instance is compromised.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs only provide visibility into traffic patterns and do not actively limit the blast radius or prevent data exfiltration. Option C is wrong because AWS WAF is a web application firewall designed to protect web-facing resources like ALB or CloudFront, not S3 buckets directly; it cannot restrict access from EC2 instances to S3. Option D is wrong because an AWS Config rule is a detective control that can detect non-compliant access after it occurs, but it does not proactively limit the blast radius or prevent exfiltration in real time.

512
MCQeasy

A security engineer needs to centralize logs from multiple AWS accounts into a single S3 bucket. Which solution is most secure?

A.Deliver logs to separate buckets per account and use S3 replication to copy them to a central bucket.
B.Use a single S3 bucket in the management account and have each account write logs directly without additional permissions.
C.Configure each account's CloudTrail to deliver to a centralized S3 bucket in a logging account, with a bucket policy allowing CloudTrail from source accounts.
D.Stream logs to Amazon Kinesis Data Firehose in each account and consolidate into a single S3 bucket via cross-account delivery.
AnswerC

This is correct because CloudTrail can be configured as a single trail (or one per source account) to deliver to a centralized S3 bucket in a dedicated logging account. The logging account's S3 bucket policy must explicitly authorize cloudtrail.amazonaws.com for each source account, usually with a source account and source ARN condition, so CloudTrail can write objects to a per-source prefix. This creates an immutable, central log store that source-account administrators cannot modify or delete, and it is a standard, well-supported pattern for centralized logging.

Why this answer

It uses a centralized S3 bucket in a dedicated logging account with a bucket policy that explicitly grants CloudTrail from source accounts the s3:PutObject permission. This ensures logs are written directly to a single location without intermediate replication or cross-account delivery that could introduce latency or complexity. The bucket policy can restrict access to only CloudTrail service principals and specific source account ARNs, maintaining a secure, auditable log trail.

Exam trap

The trap here is that candidates assume S3 replication (Option A) is the simplest centralized solution, but they overlook that CloudTrail can deliver directly to a cross-account bucket with a properly scoped bucket policy, which is more secure and avoids the overhead of replication or streaming services.

How to eliminate wrong answers

Option A is wrong because S3 replication introduces a time delay and requires the source bucket to have versioning enabled, which adds complexity and potential for log loss if replication fails; it also duplicates storage costs and does not prevent the source account from modifying logs before replication. Option B is wrong because having each account write logs directly to a bucket in the management account without additional permissions is insecure—CloudTrail requires explicit cross-account permissions via a bucket policy, and without them, the write will fail; this option also violates the principle of least privilege by allowing all accounts to write to a single bucket without restriction. Option D is wrong because streaming logs through Kinesis Data Firehose introduces an additional service that can fail or throttle, adds latency, and requires managing cross-account delivery policies for Firehose, which is more complex and less secure than direct CloudTrail delivery to S3 with a bucket policy.

513
MCQmedium

A company has a security group that allows inbound SSH from 0.0.0.0/0. The security team wants to restrict access to only the company's public IP range 203.0.113.0/24. What change should be made?

A.Add a network ACL rule to deny SSH from 0.0.0.0/0.
B.Modify the inbound SSH rule in the security group to source 203.0.113.0/24.
C.Add a network ACL rule to allow SSH from 203.0.113.0/24.
D.Remove the inbound SSH rule from the security group.
AnswerB

Modifying the inbound SSH rule's source from 0.0.0.0/0 to 203.0.113.0/24 is the precise fix because security groups are stateful and support only allow rules. Every IP outside that CIDR will be implicitly denied by the security group's default-deny behavior, while the company's addresses remain permitted. This change directly aligns the security group with the requirement and requires no extra outbound rule because stateful filtering automatically allows the return traffic.

Why this answer

Security groups are stateful and act as a virtual firewall for instances. To restrict inbound SSH access from 0.0.0.0/0 to only the company's public IP range, you must modify the existing inbound rule's source CIDR from 0.0.0.0/0 to 203.0.113.0/24. This change directly updates the allowed source IP range, and since security groups evaluate all rules before making a decision, the more specific allowed range will take effect without needing additional rules.

Exam trap

The trap here is that candidates often confuse the stateless behavior of network ACLs with the stateful behavior of security groups, leading them to incorrectly believe that adding a deny rule in a network ACL can override a security group's allow rule for the same traffic.

How to eliminate wrong answers

Option A is wrong because network ACLs are stateless and operate at the subnet level, not at the instance level; adding a deny rule in a network ACL would not override the security group's allow rule for SSH, and it would also require an explicit allow rule for return traffic due to statelessness. Option C is wrong because adding a network ACL rule to allow SSH from 203.0.113.0/24 does not change the security group's existing inbound SSH rule that allows 0.0.0.0/0, so SSH from any IP would still be permitted by the security group. Option D is wrong because removing the inbound SSH rule entirely would block all SSH access, including from the company's intended IP range, which is not the desired outcome.

514
MCQhard

A security engineer runs the above CloudTrail lookup command to investigate a change to the S3 bucket policy. The command only returns one event, but the engineer knows that the bucket policy was changed multiple times. What is the most likely reason?

A.The bucket policy changes were made through the AWS Management Console, which is not logged.
B.The event is not logged because PutBucketPolicy is not supported by CloudTrail.
C.The command is filtering by the wrong attribute.
D.The command is limiting results to one event.
AnswerD

This is correct. The aws cloudtrail lookup-events --max-results 1 option instructs CloudTrail to return only one event from the matching results, even if many PutBucketPolicy events exist. The LookupEvents API returns up to 50 events per page, and --max-results limits that page size; additional matches require pagination with NextToken or a higher value. Thus the command does not prove that no other bucket policy changes occurred.

Why this answer

The command uses --max-results 1, limiting output to one event. Option A is wrong because changes through the AWS Management Console are logged by CloudTrail. Option B is wrong because PutBucketPolicy is supported by CloudTrail and the event shown confirms it.

Option C is wrong because filtering by ResourceName is not the issue; the --max-results parameter is the cause.

515
Multi-Selectmedium

A security engineer is designing a secure VPC architecture. Which THREE components should be used to implement defense in depth? (Choose three.)

Select 3 answers
A.VPN connection
B.Internet gateway
C.Security groups
D.Network ACLs
E.VPC Flow Logs
AnswersC, D, E

Instance-level firewall.

Why this answer

Security groups (C) are stateful virtual firewalls that control inbound and outbound traffic at the instance level. They operate at the network interface (ENI) level, allowing only explicitly permitted traffic and automatically allowing return traffic for permitted sessions. This provides a critical layer of host-level defense within the VPC.

Exam trap

The trap here is that candidates often confuse connectivity components (VPN, Internet gateway) with security controls, or they overlook that VPC Flow Logs are a detective control (not preventive) but still a valid part of defense in depth, leading them to select A or B instead of the correct trio of security groups, network ACLs, and VPC Flow Logs.

516
MCQmedium

A company has an AWS Direct Connect connection to its on-premises data center. The security team wants to ensure that traffic between the VPC and the data center is encrypted. Which solution should they use?

A.Set up an IPsec VPN connection over the Direct Connect virtual interface.
B.Enable encryption on the Direct Connect virtual interface.
C.Use AWS Site-to-Site VPN over the internet.
D.Use VPC Peering to connect the VPC to the data center.
AnswerA

A Direct Connect virtual interface provides a dedicated, low-latency network path, but it does not encrypt traffic on its own. By configuring an IPsec VPN session over that virtual interface, you can encapsulate all packets in an encrypted tunnel between the on-premises edge and the AWS VPN endpoint, meeting compliance requirements while retaining Direct Connect's performance and reliability benefits.

Why this answer

AWS Direct Connect does not encrypt traffic by default. To encrypt, you can use an IPsec VPN over the Direct Connect virtual interface (option A). Option B is incorrect because Direct Connect does not support native encryption on the virtual interface; encryption must be added via IPsec or application-level encryption.

Option C is not optimal because the requirement specifies using the existing Direct Connect connection, not internet-based VPN. Option D is incorrect because VPC Peering connects VPCs within AWS, not an on-premises data center, and does not provide encryption.

517
Multi-Selectmedium

A company is designing a network architecture for a critical application that must be highly available and secure. Which TWO actions should be taken to ensure high availability of the network infrastructure?

Select 2 answers
A.Deploy resources across multiple Availability Zones.
B.Use Elastic IP addresses for failover between instances.
C.Use a single internet gateway for the VPC.
D.Use a single Availability Zone for all resources to reduce complexity.
E.Place all instances in a public subnet for easy access.
AnswersA, B

Distributing workloads across multiple Availability Zones within a Region makes an entire data-center failure survivable because each AZ runs on independent power, cooling, and physical networking. If one AZ degrades or goes offline, healthy copies of the workload in other AZs continue to serve traffic, giving the design a failure domain with no single point of failure. This is the foundational pattern for mission-critical architecture on AWS and is more effective than any single-instance or IP-level technique.

Why this answer

Deploying resources across multiple Availability Zones (AZs) ensures that if one AZ experiences a failure (e.g., power outage, network disruption), the application can continue serving traffic from another AZ. This is the foundational principle of high availability in AWS, as each AZ is isolated but connected via low-latency links, allowing for fault tolerance without single points of failure.

Exam trap

The trap here is that candidates often confuse high availability with disaster recovery or assume that using a single internet gateway or Elastic IP addresses alone provides sufficient fault tolerance, when in fact the core requirement is geographic redundancy across Availability Zones.

518
MCQeasy

A security engineer needs to be alerted when an IAM user attempts to modify an S3 bucket policy. Which method is the MOST efficient?

A.Enable VPC Flow Logs and analyze for S3 API traffic
B.Configure an AWS Config rule to detect changes and invoke a Lambda function
C.Create an Amazon CloudWatch Events rule that matches the PutBucketPolicy API call and triggers an SNS notification
D.Enable S3 server access logs and parse them for PutBucketPolicy entries
AnswerC

Create an Amazon CloudWatch Events (now Amazon EventBridge) rule with an event pattern matching the `detail-type` of `AWS API Call via CloudTrail`, the `eventSource` as `s3.amazonaws.com`, and `eventName` as `PutBucketPolicy`. When CloudTrail logs that IAM API call, the rule triggers an SNS topic to notify the security engineer in near real time. This is the native AWS approach for reacting to control-plane actions.

Why this answer

Amazon CloudWatch Events (now Amazon EventBridge) can directly capture the PutBucketPolicy API call as a real-time event and trigger an SNS notification without any additional compute or polling. This is the most efficient method as it requires no log parsing, no custom code, and no additional infrastructure, providing immediate alerting with minimal overhead.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing log-based methods (A or D) or evaluation-based methods (B), missing that CloudWatch Events provides the simplest and most direct real-time alerting for specific API calls without additional overhead.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) but do not log API-level operations like PutBucketPolicy; they cannot identify the specific S3 API call being made. Option B is wrong because an AWS Config rule detects configuration changes after they occur via periodic evaluations or configuration item changes, which introduces latency and requires a Lambda function for notification, making it less efficient than a direct event-driven approach. Option D is wrong because S3 server access logs are delivered on a best-effort basis with delays (often hours), require parsing to extract PutBucketPolicy entries, and are not designed for real-time alerting.

519
MCQhard

A company uses AWS Config to track resource changes. They notice that a weekly compliance report shows an S3 bucket as non-compliant with a rule that checks for server-side encryption. However, the bucket has default encryption enabled. What is the MOST likely reason for this discrepancy?

A.The Config rule checks for SSE on objects, not default bucket encryption.
B.The Config rule was deleted and recreated without re-evaluating existing resources.
C.The Config rule is only evaluating resources in a single AWS Region.
D.The S3 bucket is not tagged with a required tag for the Config rule.
AnswerA

The managed AWS Config rule s3-bucket-server-side-encryption-enabled is deliberately designed to verify that an S3 bucket policy requires the x-amz-server-side-encryption header on uploads — it does not inspect the bucket's default encryption configuration. Setting 'Amazon S3 default encryption' only applies SSE to objects uploaded without explicit encryption headers; those headers can be omitted or overridden by the client, so the bucket remains NON_COMPLIANT unless a bucket policy explicitly denies requests lacking the required encryption header. Therefore, seeing a bucket with default encryption flagged as NON_COMPLIANT is the rule's expected behavior, not a misconfiguration of Config.

Why this answer

The AWS Config managed rule `s3-bucket-server-side-encryption-enabled` specifically checks whether the bucket policy enforces server-side encryption on objects uploaded to the bucket, not whether the bucket has default encryption configured. Default encryption only applies to objects that do not have an encryption setting at the time of upload, but the rule evaluates the bucket's policy for a condition that requires SSE for all PUT requests. Therefore, a bucket with default encryption enabled but without a policy enforcing SSE will be reported as non-compliant.

Exam trap

The trap here is that candidates confuse default bucket encryption with server-side encryption enforcement, assuming that enabling default encryption automatically satisfies the Config rule, when in fact the rule requires a bucket policy to deny unencrypted uploads.

How to eliminate wrong answers

Option B is wrong because deleting and recreating a Config rule without re-evaluating existing resources would cause the rule to evaluate only new resources, but the bucket would still be evaluated if it existed before the recreation; the discrepancy is not due to a missing re-evaluation. Option C is wrong because S3 is a global service, and AWS Config rules for S3 buckets evaluate resources across all regions by default; the rule is not limited to a single region unless explicitly scoped. Option D is wrong because the `s3-bucket-server-side-encryption-enabled` rule does not require any specific tags; it checks for encryption enforcement, not tagging.

520
MCQmedium

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The security team receives an alert from Amazon GuardDuty that one of the EC2 instances is generating outbound traffic to a known command-and-control (C2) IP address. The instance is part of an Auto Scaling group (ASG) with a minimum of 2 and maximum of 10 instances. The security incident response playbook instructs the team to isolate the compromised instance without affecting the application's availability. The team needs to preserve the instance for forensic analysis. Which action should the team take first?

A.Terminate the compromised EC2 instance and allow the ASG to launch a replacement.
B.Detach the EBS root volume from the instance and attach it to a forensic instance.
C.Shut down the instance from within the OS using AWS Systems Manager Run Command.
D.Remove the instance from the ALB target group and attach a security group that denies all traffic.
AnswerD

Deregistering the instance from the ALB target group immediately stops new application traffic from reaching it, while replacing its security group membership with a quarantine security group that contains no allow rules imposes an implicit deny-all at the network interface. This blocks lateral movement, outbound command-and-control traffic, and further exfiltration while the instance continues to run, preserving volatile memory and EBS volumes for forensic capture. It is the correct first step because it is rapid, reversible, and evidence-preserving.

Why this answer

Removing the instance from the ALB target group immediately stops new traffic from reaching the application, while attaching a security group that denies all traffic (e.g., a custom security group with no inbound/outbound rules) effectively isolates the instance at the network layer. This preserves the instance for forensic analysis and does not affect application availability, as the ASG will not automatically terminate the instance (since it is still running and healthy from the ASG's perspective). The ALB will continue to route traffic to the remaining healthy instances in the target group, maintaining service continuity.

Exam trap

The trap here is that candidates may think terminating the instance (Option A) is the fastest way to stop the threat, but they overlook the requirement to preserve the instance for forensic analysis and the need to maintain application availability by not triggering an ASG replacement prematurely.

How to eliminate wrong answers

Option A is wrong because terminating the instance would destroy the forensic evidence (e.g., memory, disk, logs) and the ASG would launch a replacement, but the immediate isolation step should be network-level, not termination. Option B is wrong because detaching the EBS root volume requires the instance to be stopped first, which would take the instance out of service and potentially trigger an ASG replacement, and it does not address the immediate need to stop outbound C2 traffic. Option C is wrong because shutting down the instance from within the OS using Systems Manager Run Command would stop the instance, causing the ASG to launch a replacement (since the instance count drops below the minimum), and it does not preserve the instance for forensic analysis (the instance is stopped, not isolated).

521
MCQhard

Refer to the exhibit. A security engineer is troubleshooting a decryption failure. The command uses the AWS CLI to decrypt a file. The decryption fails with an 'AccessDeniedException' error. The IAM user has the following policy attached: { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "kms:Decrypt", "Resource": "*" } ] } What is the most likely cause of the failure?

A.The KMS key policy does not grant the IAM user decrypt permission
B.The IAM user does not have permission to call kms:Decrypt on the specific key
C.The ciphertext blob is not valid
D.The IAM user is not authorized to use the AWS CLI
AnswerA

The KMS key policy is the resource policy attached to a KMS key and is the authoritative control for access. In AWS KMS, an IAM policy alone does not grant permission; the key policy must explicitly allow the IAM user (or allow the account's IAM policies to take effect) for kms:Decrypt. Because the key policy here lacks such an allowance, the request is denied with AccessDenied even if the IAM identity policy appears permissive. Therefore, the missing key-policy grant for this user is the direct cause of the failure.

Why this answer

KMS decryption requires permission from BOTH the IAM identity-based policy AND the KMS key policy. Even though the IAM policy grants kms:Decrypt on '*', the key policy must also explicitly allow the IAM user (or their account with the right conditions) to use the key. If the key policy does not grant access, the request fails with AccessDeniedException regardless of the IAM policy.

Exam trap

SCS-C02 often tests the KMS dual-authorization model, tricking candidates into assuming that a wildcard IAM policy alone is sufficient — the key policy is the missing piece that causes AccessDeniedException.

How to eliminate wrong answers

Option B is wrong because the IAM policy already grants kms:Decrypt on Resource '*', so the IAM side is not the blocker — the missing piece is the key policy. Option C is wrong because an invalid ciphertext blob would produce an InvalidCiphertextException, not AccessDeniedException. Option D is wrong because AWS CLI authorization is governed by IAM permissions, not a separate CLI-level authorization — if the CLI can authenticate, it can call any API the IAM principal is permitted to call.

522
MCQeasy

An application running on an EC2 instance needs to read from an S3 bucket. What is the BEST practice for granting permissions to the EC2 instance?

A.Store AWS access keys in the application code.
B.Create an IAM user and give access keys to the developer.
C.Use an IAM role and attach it to the EC2 instance profile.
D.Use the root account credentials.
AnswerC

Attaching an IAM role to the EC2 instance profile allows the instance to retrieve temporary security credentials from the instance metadata service (IMDSv2). The SDK automatically calls the Amazon EC2 metadata endpoint (http://169.254.169.254) to obtain an access key, secret key, and session token, which are then used for API requests. These credentials are temporary, automatically rotated, and carry only the permissions defined by the role's policy, avoiding any embedded secrets.

Why this answer

The best practice is to use an IAM role attached to the EC2 instance via an instance profile. This provides temporary, automatically rotated credentials to the instance, eliminating the need to hardcode or distribute long-term access keys. The instance profile allows the EC2 instance to assume the role and obtain credentials from the Instance Metadata Service (IMDS), which the AWS SDK and CLI use automatically.

This approach follows the principle of least privilege and is the most secure and manageable method for granting AWS permissions to EC2 instances.

Exam trap

SCS-C02 often tests the misconception that IAM user access keys are acceptable for EC2 instances, but the exam expects you to recognize that IAM roles with instance profiles are the only secure, best-practice solution for granting permissions to EC2.

How to eliminate wrong answers

Option A is wrong because storing AWS access keys in application code is a severe security risk—keys can be exposed in source control, logs, or reverse engineering, and they are long-term credentials that are difficult to rotate. Option B is wrong because creating an IAM user and giving access keys to a developer violates best practices: it uses long-term credentials, lacks automatic rotation, and ties permissions to a human user rather than the instance, increasing the risk of credential leakage and making auditing harder. Option D is wrong because using root account credentials is extremely dangerous—the root account has unrestricted access to all resources and billing, and AWS strongly recommends never using root for programmatic access; it also cannot be restricted by IAM policies.

523
MCQhard

A security engineer applies the bucket policy shown in the exhibit to an S3 bucket. What is the effect of this policy?

A.Allows uploads only if they use SSE-S3.
B.Allows uploads without encryption.
C.Allows uploads with any server-side encryption.
D.Allows uploads only if they use SSE-KMS.
AnswerD

The policy's `s3:PutObject` statement carries a `StringNotEquals` condition on `s3:x-amz-server-side-encryption` with value `aws:kms`, so any upload lacking the SSE-KMS header is explicitly denied. This satisfies the stem's constraint by permitting only requests specifying SSE-KMS encryption, blocking SSE-S3 and unencrypted writes.

Why this answer

The bucket policy shown in the exhibit uses a Deny effect with a condition that checks whether the s3:x-amz-server-side-encryption header does not equal aws:kms, which means any upload request that does not specify SSE-KMS encryption is denied. Therefore, the policy effectively allows uploads only if they use SSE-KMS. This is a common pattern to enforce encryption at rest with a specific KMS key type.

Exam trap

SCS-C02 often tests the difference between SSE-S3 (AES-256, AWS-managed keys) and SSE-KMS (AWS KMS keys) in bucket policy conditions — candidates see 'server-side encryption' and incorrectly assume any encryption type satisfies the policy, missing the specific aws:kms value in the condition.

How to eliminate wrong answers

Option A is wrong because the policy condition specifically checks for aws:kms, not aws:s3 (which is SSE-S3), so SSE-S3 uploads would be denied. Option B is wrong because the policy explicitly denies uploads without the required encryption header, so unencrypted uploads are blocked. Option C is wrong because the condition uses StringNotEquals with aws:kms, meaning only SSE-KMS satisfies the condition — other encryption types like SSE-S3 or SSE-C would fail the condition and be denied.

524
MCQmedium

An application running on EC2 instances needs to access an S3 bucket. The Security Engineer wants to ensure that the EC2 instances do not have access keys and that the access is restricted to only the required bucket. What is the most secure way to provide this access?

A.Generate an access key for an IAM user with permissions to the S3 bucket and store it in the EC2 instance.
B.Create an S3 bucket policy that allows the EC2 instance's public IP address to access the bucket.
C.Create an IAM role with a policy that allows access to the specific S3 bucket, and attach the role to the EC2 instance profile.
D.Use the root user's access keys to configure the application.
AnswerC

Creating an IAM role with a narrowly scoped policy and attaching it as the instance profile lets the EC2 instance securely obtain temporary credentials from AWS STS through the instance metadata service, with no keys embedded in the AMI or stored on disk. These credentials are rotated automatically and are valid only for a short duration, reducing the blast radius of any credentials leak. The policy can restrict actions to the specific S3 bucket (for example, s3:GetObject and s3:ListBucket), and the role's trust policy allows the EC2 service to assume it, ensuring the instance operates with least privilege and a clear audit trail in CloudTrail.

Why this answer

It uses an IAM role attached to an EC2 instance profile, which allows the instance to obtain temporary security credentials from AWS STS (Security Token Service) without storing any long-term access keys. The role's policy can be scoped to grant access only to the specific S3 bucket, ensuring least privilege. This approach eliminates the risk of key exposure and is the AWS-recommended best practice for granting EC2 instances access to AWS services.

Exam trap

The trap here is that candidates may think storing access keys on the instance (Option A) is acceptable if the keys are scoped, but the exam emphasizes that any long-term credential on an instance is a security risk, and the IAM role mechanism is the only secure, AWS-native way to avoid hardcoded keys.

How to eliminate wrong answers

Option A is wrong because storing an access key on the EC2 instance introduces a long-term credential that can be compromised if the instance is breached, violating the principle of not embedding keys in code or instances. Option B is wrong because restricting access by public IP address is insecure (IPs can change, be spoofed, or shared) and does not authenticate the instance; S3 bucket policies based on IPs are not a secure identity-based access control method. Option D is wrong because using the root user's access keys violates AWS security best practices (root keys should never be used for programmatic access) and grants unrestricted, overly permissive access to all AWS resources, not just the required bucket.

525
MCQmedium

A company wants to restrict access to an S3 bucket so that only requests from a specific VPC endpoint are allowed. Which policy element should be used in the S3 bucket policy?

A.aws:Referer
B.aws:SourceVpce
C.aws:SourceVpc
D.aws:SourceIp
AnswerB

aws:SourceVpce is the correct condition key because it restricts access to requests that originate from a specific VPC endpoint, identified by its endpoint ID (e.g., vpce-1a2b3c4d). In an S3 bucket policy, you can use this condition key with an explicit Allow statement and the endpoint ID as the value to ensure that only traffic flowing through that particular endpoint can access the bucket. This works for both gateway-gateway and interface VPC endpoints for S3, making it the precise mechanism to limit access to exactly one endpoint.

Why this answer

To restrict access to an S3 bucket so that only requests originating from a specific VPC endpoint are allowed, the `aws:SourceVpce` condition key must be used in the S3 bucket policy. This key checks the VPC endpoint ID (e.g., `vpce-1a2b3c4d`) from which the request originated, ensuring that only traffic through that specific endpoint is permitted. Using `aws:SourceVpc` would allow any endpoint within the VPC, not a specific one, and `aws:SourceIp` or `aws:Referer` are irrelevant for VPC endpoint-based access control.

Exam trap

The trap here is that candidates often confuse `aws:SourceVpc` with `aws:SourceVpce`, mistakenly thinking that restricting to a VPC is sufficient, but the question explicitly requires restricting to a specific VPC endpoint, not just any endpoint in the VPC.

How to eliminate wrong answers

Option A is wrong because `aws:Referer` is used to restrict access based on the HTTP Referer header, typically for preventing hotlinking from unauthorized websites, not for VPC endpoint-based access. Option C is wrong because `aws:SourceVpc` restricts access to requests coming from any VPC endpoint within a specified VPC, not a single specific endpoint, which does not meet the requirement of restricting to a specific VPC endpoint. Option D is wrong because `aws:SourceIp` restricts access based on the source IP address of the request, which is not applicable when traffic comes through a VPC endpoint (the source IP is the endpoint's private IP, not the original client IP).

Page 6

Page 7 of 17

Page 8