Courseiva

AWS Certified Security Specialty SCS-C02 (SCS-C02) — Questions 526–600

1205 questions total · 17pages · All types, answers revealed

Page 7

Page 8 of 17

Page 9
526
Multi-Selectmedium

A security engineer is reviewing the following IAM policy attached to a role. Which TWO actions are allowed by this policy? (Choose two.) ```json { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "s3:ListBucket", "s3:GetObject" ], "Resource": "*" } ] } ```

Select 2 answers
A.s3:ListBucket
B.ec2:TerminateInstances
C.iam:CreateUser
D.kms:Decrypt
E.s3:GetObject
AnswersA, E

The policy includes an explicit Allow statement for s3:ListBucket on the bucket resource, so this action is permitted. IAM defaults to deny only for actions not covered by any applicable Allow, and because no explicit or resource-based Deny applies to this principal for that bucket, the ListBucket call is authorized. The permission is scoped to the bucket ARN, not individual objects, which matches the resource type required by the ListBucket API.

Why this answer

Option A (s3:ListBucket) is correct because the policy's Action list explicitly includes "s3:ListBucket" with Effect Allow and Resource "*", so listing any S3 bucket is permitted. Option E (s3:GetObject) is correct because "s3:GetObject" is also explicitly listed in the same Allow statement, granting read access to objects across all resources. The unmarked options do not belong because the policy only allows the two S3 actions named; ec2:TerminateInstances, iam:CreateUser, and kms:Decrypt are not present in the Action list, and IAM policies are deny-by-default for any action not explicitly allowed.

Exam trap

SCS-C02 often tests the principle of least privilege and implicit deny — candidates may incorrectly assume that unrelated actions like ec2:TerminateInstances are allowed because the policy uses Resource: "*", confusing resource scope with action scope.

527
MCQmedium

A company has an AWS Lambda function that processes sensitive data. The security team wants to ensure that any errors or suspicious behavior are immediately investigated. Which combination of services should be used to send real-time notifications for anomalous function executions?

A.CloudWatch Logs and SNS
B.CloudTrail and SNS
C.AWS Config and SQS
D.Amazon Detective and SES
AnswerA

Lambda function execution output is written to CloudWatch Logs, so a metric filter can parse log events for patterns such as 'ERROR' or 'AccessDenied' and drive a CloudWatch alarm. The alarm then publishes to an SNS topic, delivering real-time notifications to operators. This is the native, low-latency monitoring path for Lambda function behavior and is ideal for sensitive-data processing failures.

Why this answer

CloudWatch Logs can capture Lambda function execution logs, and a CloudWatch Logs metric filter can be configured to detect patterns indicative of errors or suspicious behavior (e.g., 'ERROR', 'Exception', or custom anomaly patterns). When the metric filter triggers a CloudWatch alarm, it can publish a message directly to an Amazon SNS topic, which then sends real-time notifications (e.g., email, SMS, or HTTP endpoint) to the security team for immediate investigation.

Exam trap

The trap here is that candidates often confuse CloudTrail (which logs API calls) with CloudWatch Logs (which captures application-level execution output), leading them to choose CloudTrail for real-time error monitoring when it is actually designed for auditing and compliance, not for triggering on application errors.

How to eliminate wrong answers

Option B is wrong because AWS CloudTrail records API calls and management events (e.g., who invoked the Lambda function), not the function's execution logs or error output; it cannot trigger real-time notifications based on anomalous function behavior. Option C is wrong because AWS Config is designed for resource configuration compliance and change tracking, not for monitoring real-time execution errors or suspicious behavior; SQS is a message queue that requires a separate consumer to process notifications, adding latency and complexity. Option D is wrong because Amazon Detective is a post-incident investigation service that analyzes historical data to identify root causes of security findings, not a real-time notification service; SES is an email-sending service that requires custom integration and does not natively trigger from Lambda execution anomalies.

528
Multi-Selecteasy

Which TWO of the following are valid options for encrypting data at rest in Amazon EBS? (Choose two.)

Select 2 answers
A.Enable EBS encryption by default using the AWS managed key for EBS.
B.Use a customer managed KMS key.
C.Use an encryption script on the EC2 instance to encrypt the volume.
D.Use AWS CloudHSM to generate and store the encryption key.
E.Use S3 server-side encryption to encrypt the EBS snapshot.
AnswersA, B

Enabling EBS encryption by default causes all newly created EBS volumes and snapshots to be encrypted automatically. When no custom key is specified, AWS uses the AWS managed key with alias 'aws/ebs' to perform encryption, which is transparent and requires no additional configuration. This satisfies encryption-at-rest requirements with minimal operational overhead and is the simplest valid option.

Why this answer

Option A is correct because Amazon EBS supports account-level and Region-level encryption by default, which automatically encrypts new volumes and snapshots using the AWS managed key for EBS (aws/ebs) unless you specify a different key. Option B is correct because EBS encryption can be configured to use a customer managed KMS key, giving you control over key policies, rotation, and grants while still using the native EBS/KMS encryption mechanism. Option C is not a valid EBS at-rest encryption option because running an encryption script inside the EC2 instance is application-level or OS-level encryption, not native EBS volume encryption.

Option D is not correct because CloudHSM is a separate HSM service and is not the mechanism used to generate or store EBS encryption keys; EBS encryption keys are managed through AWS KMS. Option E is not correct because S3 server-side encryption protects objects stored in S3, not EBS volumes or EBS snapshots.

Exam trap

SCS-C02 often tests the difference between native AWS encryption mechanisms and application-level or unrelated service encryption; candidates may pick CloudHSM or S3 encryption thinking they apply to EBS, but only KMS-based options are valid for EBS at rest.

529
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to centralize security logs (CloudTrail, VPC Flow Logs, AWS Config) from all accounts into a single S3 bucket for analysis. What is the MOST secure way to set up this centralized logging?

A.Create a dedicated S3 bucket in the management account, enable S3 default encryption, and configure service delivery for each account.
B.Create a dedicated S3 bucket in the security account with a bucket policy that grants write access to the logging services of all accounts and enforces encryption in transit and at rest.
C.Configure each account to deliver logs to the same S3 bucket used for other data.
D.Create an S3 bucket in each account and use S3 replication to copy logs to a central bucket.
AnswerB

This approach aligns with AWS best practices by placing logs in a dedicated security account that is isolated from production workloads and the management account. The bucket policy grants write access only to the logging services of all accounts, using service principals like logging.s3.amazonaws.com, while condition keys such as aws:SecureTransport force TLS and a deny statement without s3:x-amz-server-side-encryption ensures all objects are encrypted at rest. This centralizes auditability, enforces least privilege, and provides a single source of truth for compliance and incident investigation.

Why this answer

It uses a dedicated S3 bucket in a security account (not the management account) with a bucket policy that explicitly grants write access to the logging services (CloudTrail, VPC Flow Logs, AWS Config) from all accounts, while enforcing encryption in transit (aws:SecureTransport) and at rest (default SSE-S3 or SSE-KMS). This follows the security best practice of isolating logs in a separate account and using resource-based policies to restrict access, preventing accidental deletion or modification by other accounts.

Exam trap

The trap here is that candidates often assume the management account is the safest place for centralized logs, but AWS best practices recommend using a dedicated security account to isolate logs and avoid compromising the management account's administrative boundaries.

How to eliminate wrong answers

Option A is wrong because placing the S3 bucket in the management account violates the principle of least privilege and separation of duties; the management account should not be used for operational workloads, and service delivery configuration alone does not enforce encryption in transit or restrict access to only logging services. Option C is wrong because using the same S3 bucket for other data increases the attack surface and risk of unauthorized access or log tampering, and it does not enforce encryption or proper access controls for logging services. Option D is wrong because S3 replication introduces complexity, potential latency, and does not enforce encryption in transit or at rest at the source; it also requires additional permissions and does not centralize logs directly from the logging services.

530
Multi-Selectmedium

Which TWO actions should a security engineer take to protect an Amazon EC2 instance from unauthorized access? (Choose two.)

Select 2 answers
A.Place the instance in a public subnet and rely solely on security groups.
B.Disable termination protection so the instance can be easily terminated if compromised.
C.Configure security groups to allow only necessary inbound traffic.
D.Place the instance in a private subnet and use a bastion host for administrative access.
E.Enable detailed billing to monitor instance usage.
AnswersC, D

Security groups act as a stateful virtual firewall, evaluating inbound traffic and allowing only the rules you explicitly define. By restricting inbound traffic to only necessary ports and source IP ranges, you minimize the attack surface and block unused services from being probed. This least-privilege approach is a fundamental security control that should be applied in addition to network segmentation, not as a substitute for it.

Why this answer

Security groups act as a virtual firewall for EC2 instances, controlling inbound and outbound traffic at the instance level. By configuring security groups to allow only necessary inbound traffic (Option C), you follow the principle of least privilege, reducing the attack surface. This is a fundamental security best practice for protecting EC2 instances from unauthorized access.

Exam trap

The trap here is that candidates often think placing an instance in a public subnet with security groups is sufficient, but the exam expects you to recognize that a private subnet with a bastion host is a more secure architecture for administrative access.

531
Multi-Selecteasy

A security engineer is designing a monitoring solution for a multi-account AWS environment using AWS Organizations. The solution must provide a centralized view of all API activities and send alerts for suspicious events. Which TWO services together can achieve this? (Choose TWO.)

Select 2 answers
A.Amazon GuardDuty
B.AWS Lambda
C.AWS CloudTrail
D.Amazon CloudWatch Logs
E.AWS Config
AnswersC, D

AWS CloudTrail records management events (and optionally data events) for every API call made in an AWS account, capturing the identity, source IP, time, request parameters, and response elements. When enabled for an AWS Organization, you can create an organization trail that logs events for all accounts and delivers them to a single Amazon S3 bucket, enabling centralized auditing. This makes CloudTrail the definitive source of API activity for security monitoring, compliance, and forensic investigation.

Why this answer

AWS CloudTrail is correct because it records all API activity across an AWS environment, and when integrated with AWS Organizations, it can deliver a centralized view of API calls from all accounts into a single CloudTrail trail. Amazon CloudWatch Logs is correct because it can ingest CloudTrail logs from a centralized logging account, allowing the security engineer to create metric filters and alarms that trigger alerts for suspicious events based on specific API patterns.

Exam trap

The trap here is that candidates often pick GuardDuty (A) because it is a security service, but they overlook that GuardDuty does not provide a centralized view of all API activities or allow custom alerting on specific API events, which requires CloudTrail and CloudWatch Logs.

532
Multi-Selecteasy

Which TWO AWS services can be used to monitor and detect unauthorized changes to Amazon S3 bucket policies? (Choose two.)

Select 2 answers
A.AWS CloudTrail
B.Amazon GuardDuty
C.Amazon CloudWatch Logs
D.AWS Config
E.Amazon VPC Flow Logs
AnswersA, D

AWS CloudTrail records management events in your account, including the PutBucketPolicy API call that modifies an S3 bucket policy. This gives you a complete, auditable history of who made the change, from which IP address, and when, making it a primary service for detecting and investigating policy changes.

Why this answer

AWS CloudTrail is correct because it records all API calls made to Amazon S3, including changes to bucket policies (e.g., PutBucketPolicy, DeleteBucketPolicy). By enabling CloudTrail on the S3 bucket or using a trail that logs data events for S3, you can monitor and detect unauthorized policy modifications in near real-time through the CloudTrail event history or by delivering logs to Amazon CloudWatch Logs for further analysis.

Exam trap

The trap here is that candidates often confuse Amazon GuardDuty's ability to analyze CloudTrail logs for threat detection with direct monitoring of S3 policy changes, but GuardDuty does not have built-in rules to detect unauthorized policy modifications; it focuses on anomalous behavior like unusual API patterns, not specific resource-level changes.

533
Multi-Selectmedium

Which TWO actions are valid ways to send application logs from an EC2 instance to Amazon CloudWatch Logs? (Select TWO.)

Select 2 answers
A.Configure the EC2 instance to stream syslog to AWS CloudTrail.
B.Write logs to an S3 bucket and use S3 event notifications to send to CloudWatch Logs.
C.Install and configure the unified CloudWatch agent on the EC2 instance.
D.Enable VPC Flow Logs to capture application traffic.
E.Install and configure the legacy CloudWatch Logs agent.
AnswersC, E

The unified CloudWatch agent (amazon-cloudwatch-agent) is the recommended method for collecting both custom metrics and log files from EC2 instances. It tails configured log files and forwards each line to a CloudWatch Logs group and stream using the PutLogEvents API, with options for multi-line logs, timestamp formats, and rotation. This directly and reliably satisfies the requirement to send application logs to CloudWatch Logs, making it a correct answer.

Why this answer

The unified CloudWatch agent (option C) is a valid and recommended method for collecting application logs from EC2 instances and sending them to CloudWatch Logs. It supports collecting logs from various sources, including syslog, and can also collect metrics, providing a single agent for both monitoring and logging.

Exam trap

The trap here is that candidates may confuse VPC Flow Logs (which capture network traffic metadata) with application-level logging, or assume that S3 event notifications can directly forward log data to CloudWatch Logs without an intermediary service like Lambda.

534
MCQhard

A company runs a critical web application on Amazon EC2 instances behind an Application Load Balancer (ALB) in a VPC. The security team uses Amazon GuardDuty and has enabled Amazon Detective. Recently, GuardDuty raised a 'Recon:EC2/PortProbeUnprotectedPort' finding for one of the instances. The security engineer verified that the ALB security group only allows inbound HTTP/HTTPS from the internet. However, the finding indicates that the instance is receiving probes on port 22 (SSH). Further investigation with Detective shows that the probes originate from multiple IP addresses and are reaching the instance's private IP address. The engineer suspects that the SSH port is exposed despite the security group configuration. What is the MOST likely cause of this exposure?

A.The EC2 instance's security group allows inbound SSH from 0.0.0.0/0.
B.VPC Flow Logs are misconfigured and are inadvertently forwarding traffic to the instance.
C.AWS Shield Advanced is causing false positives by marking legitimate traffic as probes.
D.The ALB security group has an inbound rule that allows SSH from the internet.
AnswerA

The EC2 instance's security group explicitly permits inbound SSH on port 22 from 0.0.0.0/0. This means the instance is reachable directly from the internet on its own public or elastic IP, completely bypassing the ALB. GuardDuty detects the resulting SSH brute-force attempts from external sources, so this is the root cause despite the ALB fronting web traffic.

Why this answer

The GuardDuty finding 'Recon:EC2/PortProbeUnprotectedPort' indicates that an EC2 instance is receiving unsolicited probes on a port that should not be publicly accessible. Since the ALB security group only allows HTTP/HTTPS from the internet, but the probes are reaching the instance's private IP on port 22 (SSH), the most likely cause is that the instance's own security group has an inbound rule allowing SSH from 0.0.0.0/0. This bypasses the ALB's security group because the instance's security group is evaluated independently for direct traffic to the instance's private IP, and if it permits SSH from anywhere, the probes will reach the instance.

Exam trap

The trap here is that candidates assume the ALB's security group fully protects the backend instances, forgetting that instances have their own security groups that are evaluated independently for direct traffic to their private IPs.

How to eliminate wrong answers

Option B is wrong because VPC Flow Logs are a monitoring feature that captures metadata about IP traffic; they do not forward or route traffic to instances, so misconfiguration cannot cause exposure. Option C is wrong because AWS Shield Advanced is a DDoS protection service that does not generate false positives for port probes; GuardDuty findings are independent of Shield, and Shield does not mark legitimate traffic as probes. Option D is wrong because the ALB security group only allows HTTP/HTTPS from the internet, and even if it allowed SSH, that would only affect traffic to the ALB, not directly to the instance's private IP; the probes are reaching the instance directly, not through the ALB.

535
MCQmedium

A company has a requirement to retain AWS CloudTrail logs for 7 years for compliance. The logs are stored in an S3 bucket. The company wants to reduce storage costs by automatically moving older logs to a cheaper storage class. Which solution should the company implement?

A.Use S3 Intelligent-Tiering to automatically move logs to the most cost-effective access tier.
B.Configure an S3 Lifecycle policy to transition objects from S3 Standard to S3 Glacier after a specified number of days.
C.Move logs to S3 Standard-IA after 30 days.
D.Use S3 Batch Operations to manually copy logs to S3 Glacier.
AnswerB

Configure an S3 Lifecycle policy with a transition rule that moves CloudTrail logs from S3 Standard to S3 Glacier after a defined number of days, such as 30 or 90. This automated, deterministic approach aligns perfectly with typical log access patterns—logs are actively analyzed immediately after delivery, then only rarely needed for compliance or audit investigations. Glacier provides extremely low-cost, durable archival storage, which is cost-optimal for a 7-year retention requirement, and the lifecycle rule requires no ongoing operational effort once set.

Why this answer

An S3 Lifecycle policy can automatically transition CloudTrail logs from S3 Standard to S3 Glacier after a specified number of days, meeting the 7-year retention requirement while reducing storage costs. S3 Glacier is designed for long-term archival at low cost, and lifecycle rules can be configured to transition objects directly or through intermediate classes like S3 Standard-IA. S3 Intelligent-Tiering (Option A) also automatically optimizes costs and supports archival tiers, but it works based on access patterns, not fixed age-based rules, and incurs per-object monitoring fees.

For compliance-driven, age-based retention, a Lifecycle policy is the more direct and cost-effective solution.

Exam trap

The trap is that candidates may choose S3 Intelligent-Tiering (Option A) thinking it automatically optimizes costs for all scenarios, but Intelligent-Tiering monitors access patterns, not ages, and while it does support Glacier tiers, it is not designed for fixed retention periods. For age-based archival to Glacier, an S3 Lifecycle policy is the appropriate control.

How to eliminate wrong answers

Option A is wrong because S3 Intelligent-Tiering is designed for unpredictable access patterns and does not guarantee cost savings for long-term archival; it also does not transition to Glacier, which is needed for 7-year retention. Option C is wrong because moving logs to S3 Standard-IA after 30 days reduces cost for infrequent access but does not address the 7-year retention requirement; Standard-IA is not a long-term archival class and would still incur higher costs over 7 years compared to Glacier. Option D is wrong because S3 Batch Operations is a manual, one-time process that does not automate ongoing transitions, and manually copying logs to Glacier is inefficient and error-prone for a continuous compliance requirement.

536
MCQeasy

Which IAM feature allows you to grant temporary, limited-privilege credentials for a specific role?

A.Resource-based policies
B.IAM roles
C.AWS STS
D.Service control policies
AnswerC

AWS STS is the service that issues temporary, limited-privilege credentials through APIs like GetSessionToken, AssumeRole, and GetFederationToken. These credentials consist of an access key ID, a secret access key, and a session token, and they automatically expire after a configurable duration, ranging from 15 minutes to 36 hours depending on the API used. This reduces the risk of long-term credential exposure and is the correct IAM feature that directly grants temporary credentials.

Why this answer

AWS STS (Security Token Service) is the service that provides temporary, limited-privilege credentials for IAM roles or federated users. When you assume a role, STS issues temporary security credentials that can be used to access AWS resources. This is the core mechanism for granting temporary access.

Exam trap

SCS-C02 often tests the distinction between IAM roles and STS, where candidates might think that IAM roles themselves provide credentials, but actually STS is the service that issues the temporary credentials.

How to eliminate wrong answers

Option A is wrong because resource-based policies are attached to resources (like S3 buckets) and define who can access them, but they do not grant temporary credentials. Option B is wrong because IAM roles are an identity that can be assumed, but the actual temporary credentials are issued by STS. Option D is wrong because Service Control Policies are used in AWS Organizations to set permission boundaries, not to grant temporary credentials.

537
MCQhard

A company is designing a network architecture for a multi-tier web application. The application consists of a public-facing ALB, web servers in private subnets, and an RDS database in isolated subnets. The security team requires that the web servers have no direct internet access. Which VPC configuration meets this requirement?

A.Public subnets with an Internet Gateway.
B.Isolated subnets with no route to the internet.
C.Private subnets with a NAT Gateway in a public subnet.
D.Private subnets with a VPN connection to the corporate network.
AnswerC

Private subnets with a NAT Gateway in a public subnet provide a controlled outbound-only internet path. The private subnets' route table sends 0.0.0.0/0 to the NAT Gateway, which holds an Elastic IP and translates traffic, while inbound connections from the internet are still impossible. This allows instances to fetch updates and call external services without being directly exposed, making it the recommended multi-tier architecture pattern.

Why this answer

Placing web servers in private subnets with a NAT Gateway in a public subnet allows them to initiate outbound connections to the internet (e.g., for software updates) while preventing any inbound internet traffic from reaching them directly. The NAT Gateway translates private IPs to the public IP of the gateway, and the private subnets' route table points 0.0.0.0/0 to the NAT Gateway, not an Internet Gateway, ensuring no direct internet access.

Exam trap

The trap here is that candidates often confuse 'no direct internet access' with 'no internet access at all,' leading them to choose isolated subnets (Option B) instead of recognizing that private subnets with a NAT Gateway allow outbound-only internet access, which satisfies the requirement.

How to eliminate wrong answers

Option A is wrong because public subnets with an Internet Gateway would give the web servers direct internet access via their public IPs, violating the requirement for no direct internet access. Option B is wrong because isolated subnets with no route to the internet would prevent the web servers from initiating any outbound internet traffic (e.g., for patches or updates), which is often needed for operational tasks, and the requirement only prohibits direct internet access, not all internet access. Option D is wrong because a VPN connection to the corporate network provides private connectivity to an on-premises network, not internet access, and does not address the requirement to prevent direct internet access—it is irrelevant to the internet access control.

538
MCQeasy

A security team needs to centrally manage permissions for multiple AWS accounts. Which AWS service should they use?

A.AWS IAM
B.AWS Config
C.AWS Organizations with service control policies (SCPs)
D.AWS CloudTrail
AnswerC

AWS Organizations gives you a central management structure for all your AWS accounts, and service control policies (SCPs) let you apply permission guardrails at the root, organizational unit (OU), or account level. SCPs restrict the maximum allowed actions for IAM principals in member accounts, but they do not grant permissions—they work alongside IAM policies to enforce central restrictions across the entire organization. This is the correct service because it provides centralized, cross-account permission governance that IAM alone cannot achieve.

Why this answer

AWS Organizations with service control policies (SCPs) is the correct choice because SCPs allow you to centrally manage permissions across multiple AWS accounts by defining maximum permissions for member accounts. Unlike IAM policies that are attached to users or roles within a single account, SCPs act as a guardrail at the organization or organizational unit (OU) level, restricting what actions accounts and their IAM principals can perform, even if the account's own IAM policies allow more.

Exam trap

The trap here is that candidates often confuse AWS IAM (which manages permissions within a single account) with the need for cross-account permission management, leading them to select IAM instead of recognizing that AWS Organizations with SCPs is the correct service for central governance across multiple accounts.

How to eliminate wrong answers

Option A is wrong because AWS IAM manages permissions for users, groups, and roles within a single AWS account, not across multiple accounts centrally. Option B is wrong because AWS Config is a service for evaluating resource configurations against rules and tracking compliance, not for managing permissions. Option D is wrong because AWS CloudTrail records API activity for auditing and governance, but it does not enforce or manage permissions.

539
MCQhard

A financial services company is designing a data protection strategy for its DynamoDB table containing sensitive customer data. The table has a global secondary index (GSI). The company needs to encrypt the data at rest using a customer managed key (CMK) that is rotated annually. Which solution meets these requirements?

A.Create the table with default encryption, then update the table to use a CMK and enable automatic rotation
B.Create the table without encryption, then enable encryption on the table and GSI separately using a CMK
C.Create the table with an AWS managed key and use AWS KMS automatic rotation
D.Create the table with a customer managed key (CMK) and enable automatic key rotation
AnswerD

A customer managed CMK is the correct choice because the customer controls the key, including its rotation schedule, access policies, and auditability, which meets financial services compliance demands. When you create a DynamoDB table with a customer managed CMK and enable automatic key rotation, DynamoDB uses that key to encrypt the base table and all GSIs automatically, as GSIs inherit the table's encryption settings. This provides unified, customer-controlled encryption with rotation, fully satisfying the requirement.

Why this answer

DynamoDB supports encryption at rest using AWS KMS. When a table is created, you must specify whether to use a default AWS managed key or a customer managed key (CMK). The global secondary index (GSI) inherits the encryption settings from the base table and cannot have separate encryption settings.

Option D is correct because you can create the table with a CMK and enable automatic key rotation on that CMK. Option A is incorrect because you cannot change the encryption key of an existing DynamoDB table; encryption settings must be specified at creation. Option B is incorrect because DynamoDB tables always have encryption enabled by default (you cannot create a table without encryption), and you cannot enable encryption separately on the GSI.

Option C is incorrect because the requirement specifies a customer managed key (CMK), not an AWS managed key; while AWS managed keys have automatic rotation by default, they do not provide customer control over the key.

540
MCQmedium

A company wants to protect data in transit between its on-premises network and Amazon VPC using IPsec VPN. Which AWS service should be used to establish this VPN connection?

A.AWS Client VPN
B.AWS Site-to-Site VPN
C.AWS Transit Gateway
D.AWS Direct Connect
AnswerB

AWS Site-to-Site VPN creates encrypted IPsec tunnels between an on-premises customer gateway device and an AWS virtual private gateway or transit gateway attachment. It automatically provisions two tunnels for high availability, encrypts traffic as it traverses the public internet, and supports dynamic BGP or static routing. This directly satisfies the requirement to protect data in transit between the on-premises network and the VPC.

Why this answer

AWS Site-to-Site VPN is the service used to establish an IPsec VPN connection between an on-premises network and an Amazon VPC. It creates a secure tunnel over the internet using IPsec, terminating on a Virtual Private Gateway (VGW) or Transit Gateway on the AWS side and a Customer Gateway on the on-premises side.

Exam trap

SCS-C02 often tests the distinction between Site-to-Site VPN (network-to-network IPsec) and Client VPN (user-to-network) — the trap is selecting Client VPN or Transit Gateway when the requirement is specifically an IPsec VPN between an on-premises network and a VPC.

How to eliminate wrong answers

Option A is wrong because AWS Client VPN is a managed client-based VPN service for individual remote users to connect to AWS or on-premises networks, not for site-to-site connectivity between networks. Option C is wrong because AWS Transit Gateway is a network transit hub that can attach VPCs and VPNs, but it is not the service that establishes the IPsec VPN connection itself — it can be the termination point, but the VPN service is Site-to-Site VPN. Option D is wrong because AWS Direct Connect provides a dedicated private network connection, not an IPsec VPN over the internet.

541
MCQhard

A company wants to allow cross-account access to an S3 bucket. The bucket owner (Account A) wants to grant read-only access to users in Account B. Which combination of policies is required?

A.A bucket ACL in Account A granting READ access to Account B
B.A bucket policy in Account A granting s3:GetObject to Account B and an IAM policy in Account B allowing s3:GetObject
C.An IAM policy in Account A that allows s3:GetObject
D.An IAM role in Account B that grants s3:GetObject to Account A
AnswerB

Cross-account access is an AND operation: the bucket policy in Account A must explicitly allow the principal (the root user or a specific IAM principal in Account B) to call s3:GetObject, and the IAM identity in Account B must have an attached identity-based policy that also permits s3:GetObject. If either policy denies or lacks the permission, the request fails, because both the resource-based policy (in the owning account) and the identity-based policy (in the accessing account) must grant the action. This pattern is the standard way to grant direct cross-account access to an S3 object while keeping the resource owner in control.

Why this answer

Cross-account S3 access requires two-sided permission: the bucket owner (Account A) must grant access via a bucket policy that allows Account B's principal to perform s3:GetObject, and the IAM user or role in Account B must also have an IAM policy allowing s3:GetObject. Both are evaluated, and the request is allowed only if both sides permit it.

Exam trap

SCS-C02 often tests the misconception that a bucket policy alone is sufficient for cross-account access, ignoring the requirement for an identity-based policy in the caller's account.

How to eliminate wrong answers

Option A is wrong because S3 bucket ACLs are legacy and cannot grant cross-account access to IAM principals in another account in the way a bucket policy can; ACLs also do not support condition keys or fine-grained actions like s3:GetObject. Option C is wrong because an IAM policy in Account A applies only to principals within Account A, not to users in Account B, so it cannot grant cross-account access. Option D is wrong because an IAM role in Account B granting access to Account A reverses the direction — it would let Account A assume a role in Account B, not let Account B read Account A's bucket.

542
MCQeasy

A company wants to log all API calls made in their AWS account for auditing. Which AWS service should be enabled to capture these logs?

A.VPC Flow Logs
B.Amazon CloudWatch Logs
C.Amazon S3 server access logs
D.AWS CloudTrail
AnswerD

AWS CloudTrail is the purpose-built service that records API activity across your AWS account, capturing management events for the control plane and optionally data events for services like S3. Each event includes the identity of the caller, source IP address, request parameters, response elements, and a timestamp, whether the call came from the console, SDK, or CLI. CloudTrail's event history provides 90 days of visibility by default, and you can create trails to deliver logs to S3 or CloudWatch Logs for long-term auditing and compliance.

Why this answer

AWS CloudTrail records API calls made in an AWS account, including the identity, time, source IP, and request details, which is exactly what is needed for auditing. Enabling CloudTrail captures management and, optionally, data events across services. This makes it the correct service for logging all API calls.

Exam trap

SCS-C02 often tests the difference between CloudTrail (API call auditing) and VPC Flow Logs (network traffic) or S3 access logs (bucket-level requests), so candidates pick a logging service that does not capture account-wide API activity.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture IP traffic metadata for network interfaces, not API calls. Option B is wrong because CloudWatch Logs is a log storage and analysis service; it can receive CloudTrail logs but does not itself capture API calls. Option C is wrong because S3 server access logs record requests to S3 buckets only, not account-wide API calls.

543
Multi-Selecteasy

A security engineer is investigating a possible data exfiltration from an S3 bucket. Which THREE AWS services can be used to detect and alert on suspicious activity? (Choose THREE.)

Select 3 answers
A.Amazon CloudWatch Logs
B.Amazon GuardDuty
C.AWS CloudTrail
D.AWS Config
E.Amazon Macie
AnswersB, C, E

Amazon GuardDuty is a managed threat detection service that continuously analyzes AWS account activity, including CloudTrail management and S3 data events, VPC Flow Logs, and DNS query logs, using integrated threat intelligence and anomaly-detection machine learning. It can generate findings such as an S3 bucket compromised finding or unusual data-access patterns that strongly indicate data exfiltration, and it alerts security engineers without requiring manually defined thresholds. This makes it the most direct, purpose-built service for spotting suspicious S3 activity in near real time.

Why this answer

Amazon GuardDuty (B) is correct because it continuously monitors CloudTrail management and S3 data events, VPC Flow Logs, and DNS logs using threat intelligence and machine learning to generate findings such as Exfiltration:S3/ObjectRead.Unusual or Discovery:S3, which directly detect suspicious S3 access patterns. AWS CloudTrail (C) is correct because it records S3 data events (GetObject, PutObject, DeleteObject) and management events, providing the audit trail needed to identify anomalous API calls and feed GuardDuty and CloudWatch analysis. Amazon Macie (E) is correct because it uses machine learning and pattern matching to discover sensitive data in S3, and its findings (e.g., Policy:IAMUser/S3BucketPublic, SensitiveData:S3Object/Multiple) plus CloudWatch Events integration can alert on potential exfiltration of sensitive objects.

Amazon CloudWatch Logs (A) is not a detection service for S3 activity by itself; it stores and monitors log streams but requires CloudTrail or other sources to capture S3 API calls. AWS Config (D) tracks resource configuration changes and compliance but does not analyze S3 object access behavior or sensitive data movement, so it cannot detect exfiltration activity.

Exam trap

The trap here is that candidates often confuse AWS Config with a security detection service, but Config only tracks configuration changes and compliance, not the actual data access or network activity needed to detect exfiltration.

544
MCQhard

Refer to the exhibit. A user from IP 10.1.2.3 attempts to download an object from my-secret-bucket using HTTP (not HTTPS). What will be the outcome?

A.Success, because the Allow statement is evaluated first.
B.Failure, because the user's IP is not in the allowed range.
C.Success, because the user's IP is within the allowed range.
D.Failure, because the Deny statement blocks HTTP requests.
AnswerD

This is the correct outcome because AWS IAM uses an explicit deny override model: if any applicable policy contains a Deny statement that matches the request, access is denied even if an Allow statement also matches. Here, the request is sent over HTTP, so the Deny condition on aws:SecureTransport (e.g., "aws:SecureTransport": "false") is triggered, blocking the request. The user's IP being within the allowed range is irrelevant because the Deny statement takes unconditional precedence.

Why this answer

The Deny statement with condition aws:SecureTransport=false will block HTTP requests. Even though the IP matches the allow rule, the explicit Deny overrides the Allow.

545
MCQhard

A security engineer is troubleshooting an issue where CloudTrail logs for a single AWS account are not being delivered to the centralized S3 bucket in the logging account. The engineer has verified that the CloudTrail trail is enabled, the S3 bucket policy allows CloudTrail to write, and the bucket exists. However, no log files have been delivered for the past 6 hours. The engineer checks the CloudTrail console and sees that the trail status shows 'Logging' but the latest log file time is from 8 hours ago. The engineer suspects a permission issue but cannot find any explicit deny in the bucket policy. What is the MOST likely cause of this issue?

A.The CloudTrail trail is not configured to deliver to a cross-account bucket.
B.The CloudTrail trail is configured with a role that does not have S3 full access.
C.The S3 bucket is in a different region than the CloudTrail trail.
D.The KMS key policy used by the S3 bucket does not grant CloudTrail permission to use the key.
AnswerD

When the destination S3 bucket is encrypted with SSE-KMS, CloudTrail must be explicitly allowed to use that customer-managed KMS key before it can write delivery files. The key policy must grant the CloudTrail service principal (or the trail's assumed role) kms:GenerateDataKey and kms:Decrypt actions; without these, CloudTrail will fail at the encryption step even though the trail is otherwise correctly configured. This is the most likely cause because the error is specific to SSE-KMS buckets — CloudTrail cannot silently assume IAM permissions across services for KMS operations and requires explicit key policy authorization. Therefore, a KMS key policy lacking CloudTrail permissions is exactly the kind of misconfiguration that would block log delivery.

Why this answer

If the S3 bucket is encrypted with SSE-KMS, CloudTrail must have permission to use the KMS key to encrypt the logs. If the KMS key policy does not grant CloudTrail the necessary permissions (kms:GenerateDataKey and kms:Decrypt), CloudTrail cannot write logs, even if the S3 bucket policy allows it. The trail status may still show 'Logging' because the trail is enabled, but delivery fails silently.

This is the most likely cause given the symptoms.

Exam trap

SCS-C02 often tests the hidden dependency on KMS key policies for encrypted S3 buckets; candidates focus on the S3 bucket policy and overlook the KMS key policy, leading to prolonged troubleshooting.

How to eliminate wrong answers

Option A is wrong because CloudTrail can deliver to a cross-account bucket if the bucket policy and KMS key policy allow it; the question states the bucket policy allows CloudTrail to write, so cross-account is not the issue. Option B is wrong because CloudTrail does not use an IAM role to write to S3; it uses the S3 bucket policy and, if encrypted, the KMS key policy. Option C is wrong because CloudTrail can deliver to an S3 bucket in a different region; there is no regional restriction.

546
MCQeasy

A developer needs to run an application on an EC2 instance that accesses an S3 bucket. What is the best practice for granting permissions?

A.Use an SCP to allow S3 access for the instance.
B.Create a bucket policy that grants access to the instance ID.
C.Store AWS access keys on the instance and use them in the application.
D.Create an IAM role with S3 access and attach it to the EC2 instance profile.
AnswerD

This is the correct approach because an IAM role attached to an EC2 instance profile securely provides the instance with temporary credentials through the instance metadata service. The role enforces least-privilege permissions for S3, automatically rotates credentials, and eliminates the need to embed long-term keys, aligning with AWS security best practices and following the principle of granting only the required access.

Why this answer

The correct answer is D because attaching an IAM role to an EC2 instance profile provides temporary, automatically rotated credentials to the instance, eliminating the need to hardcode or manage long-term access keys. This follows the AWS best practice of using IAM roles for EC2 to grant least-privilege permissions to AWS services like S3. The instance profile acts as a container for the role and allows the EC2 instance to assume it, with credentials delivered via the Instance Metadata Service (IMDS).

Exam trap

SCS-C02 often tests the misconception that SCPs or bucket policies can directly grant permissions to EC2 instances, or that long-term access keys are acceptable for instance-based access, when the best practice is always to use IAM roles for EC2.

How to eliminate wrong answers

Option A is wrong because SCPs (Service Control Policies) are used at the AWS Organizations level to set permission guardrails, not to grant permissions to EC2 instances; they only limit what IAM principals can do and cannot grant access. Option B is wrong because a bucket policy grants access to IAM principals (users, roles, accounts) or services, not to an EC2 instance ID; instance IDs are not valid principals in IAM policies. Option C is wrong because storing AWS access keys on an instance is a security anti-pattern that risks key leakage and does not follow best practices for credential management; keys should be rotated and never embedded in code or instances.

547
MCQeasy

A security engineer is reviewing an IAM policy that grants permissions to an IAM user. The policy includes the following statement: { "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::example-bucket/*" }. The engineer wants to ensure that the user can only access objects in the bucket when the request originates from a specific VPC endpoint. Which additional element should the engineer add to the policy?

A.A condition that checks aws:RequestedRegion against the region of the VPC endpoint.
B.A condition that checks aws:PrincipalOrgID against the organization ID.
C.A condition that checks aws:SourceIp against the VPC CIDR range.
D.A condition that checks aws:SourceVpce against the VPC endpoint ID.
AnswerD

The aws:SourceVpce condition key can be used to restrict access to requests that come through a specific VPC endpoint. Adding this condition ensures that the user can only access objects when the request originates from that endpoint, meeting the requirement to limit access to a specific VPC endpoint.

Why this answer

The aws:SourceVpce condition key is used to allow or deny access based on the VPC endpoint through which the request is made. By including this condition in the IAM policy, the engineer ensures that only requests routed through the specified VPC endpoint can access the S3 objects. This is a common pattern for restricting access to private network paths.

Exam trap

The trap here is confusing network-based conditions like aws:SourceIp with endpoint-specific conditions, when only aws:SourceVpce can precisely limit access to a particular VPC endpoint.

548
Multi-Selecthard

A company has enabled Amazon GuardDuty in multiple AWS accounts. The security team wants to centralize GuardDuty findings into a single account for analysis. Which THREE steps are required to achieve this? (Choose THREE.)

Select 3 answers
A.Configure CloudWatch Logs cross-account subscription to aggregate findings.
B.Create an EventBridge rule to forward findings to the master account.
C.Invite member accounts to join the GuardDuty master account.
D.Accept the invitation in each member account.
E.Designate one account as the GuardDuty master account.
AnswersC, D, E

After designating a GuardDuty administrator (master) account, the administrator must send an invitation to each member account it wants to onboard. This invitation is the formal step that creates the GuardDuty account relationship, allowing the master account to access member findings, manage GuardDuty configurations, and generate usage reports. In an AWS Organizations environment, this step can be automated through delegated administration, but the manual invitation process is the correct and required approach when not using Organizations.

Why this answer

In Amazon GuardDuty, to centralize findings from multiple accounts, you must designate a master account and then invite member accounts to join. The invitation process establishes a trusted relationship where the master account can aggregate and analyze findings from all member accounts. Without this step, the master account cannot receive findings from other accounts.

Exam trap

The trap here is that candidates often confuse the GuardDuty multi-account setup with other cross-account aggregation methods (like CloudWatch Logs subscription filters or EventBridge cross-account rules), but GuardDuty has its own built-in master-member mechanism that does not require those services.

549
MCQeasy

A company wants to monitor for unauthorized changes to its Amazon S3 bucket policies. Which AWS service should be used to detect such changes?

A.AWS Config
B.AWS CloudTrail
C.Amazon GuardDuty
D.Amazon CloudWatch Logs Insights
AnswerA

AWS Config records configuration changes for supported resources and continuously evaluates those configurations against managed or custom rules. For S3 bucket policies, rules such as s3-bucket-policy-grant-check can detect unauthorized or noncompliant policy changes, flag the resource as noncompliant, and trigger remediation. It maintains a configuration history and timeline, making it the appropriate service for monitoring unauthorized changes to resource configuration.

Why this answer

AWS Config continuously records resource configurations and evaluates them against rules, so it can detect and alert on changes to S3 bucket policies via the s3-bucket-policy-not-more-permissive or custom Config rules. It provides a configuration timeline and compliance state, which is exactly what's needed to detect unauthorized policy modifications.

Exam trap

SCS-C02 often tests the difference between detecting configuration drift (AWS Config) and detecting API activity (CloudTrail) — candidates pick CloudTrail because it 'logs changes' but miss the compliance-evaluation requirement.

How to eliminate wrong answers

Option B is wrong because CloudTrail only records API calls — it logs that PutBucketPolicy was invoked but does not evaluate whether the resulting configuration is compliant or alert on drift. Option C is wrong because GuardDuty is a threat-detection service analyzing VPC flow logs, DNS logs, and CloudTrail for malicious activity; it does not monitor configuration compliance. Option D is wrong because CloudWatch Logs Insights is a query tool for log data — it can search CloudTrail logs but provides no configuration-state tracking or compliance evaluation.

550
Multi-Selectmedium

A company is designing a data protection strategy for Amazon EBS volumes. Which TWO practices should be implemented? (Choose TWO.)

Select 2 answers
A.Enable encryption by default for new EBS volumes
B.Use S3 Object Lock to prevent deletion of snapshots
C.Enable automated backups for Amazon RDS
D.Take regular snapshots of EBS volumes and store them in a different region
E.Use EBS multi-attach for high availability
AnswersA, D

Enabling encryption by default for new EBS volumes is a foundational data-at-rest protection control because it automatically encrypts the underlying volume and its snapshots with an AWS KMS key, without requiring per-volume configuration. This prevents raw storage from being accessed if an unauthorized party gains access to the physical media, and it also ensures that any future snapshots derived from these volumes inherit the same encryption, which is mandatory for many compliance frameworks.

Why this answer

Option A is correct because enabling EBS encryption by default ensures that all newly created EBS volumes in the account/Region are automatically encrypted at rest using AWS KMS keys, protecting data without relying on manual per-volume configuration. Option D is correct because EBS snapshots are incremental, point-in-time backups stored in Amazon S3, and copying them to a different Region provides cross-Region durability and disaster recovery against Regional failures or accidental deletion. Option B is incorrect because S3 Object Lock applies to objects in S3 buckets, not to EBS snapshots, which are managed through EBS snapshot APIs and lifecycle policies.

Option C is incorrect because automated backups for Amazon RDS protect RDS databases, not EBS volumes, so it does not address the EBS data protection requirement. Option E is incorrect because EBS Multi-Attach only allows a single io1/io2 volume to be attached to multiple Nitro-based EC2 instances in the same AZ for concurrent access, and it does not provide backup or data protection.

Exam trap

SCS-C02 often tests the misconception that S3 Object Lock can be used to protect EBS snapshots, confusing S3 features with EBS capabilities, or that EBS multi-attach provides high availability, when it is actually for concurrent access in clustered applications.

551
Multi-Selectmedium

A security engineer is investigating a potential security incident. Which TWO AWS services can be used to analyze historical network traffic patterns? (Choose TWO.)

Select 2 answers
A.Amazon GuardDuty
B.VPC Flow Logs
C.Amazon CloudWatch Logs
D.AWS CloudTrail
E.Amazon Athena
AnswersB, E

VPC Flow Logs capture IP traffic metadata—source and destination addresses, ports, protocol, packet and byte counts, and allow/deny actions—for traffic reaching network interfaces in your VPC. When published to Amazon S3, these logs become a durable, queryable history that can be analyzed with Athena using standard SQL to reconstruct past network behavior, such as whether an instance communicated with a suspicious host. This makes VPC Flow Logs the correct and most direct source for retrospective network traffic analysis.

Why this answer

VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol, packet/byte counts) for network interfaces in a VPC. They are stored in Amazon CloudWatch Logs or Amazon S3, enabling historical analysis of network traffic patterns. Athena can query VPC Flow Logs stored in S3 using SQL, making it a powerful tool for analyzing historical traffic patterns at scale.

Exam trap

The trap here is that candidates often confuse CloudWatch Logs (a storage/monitoring service) with Athena (a query service), or mistakenly think CloudTrail captures network traffic data instead of API activity, leading them to select CloudWatch Logs or CloudTrail instead of Athena.

552
Multi-Selecthard

A company is using AWS Direct Connect with a private virtual interface (VIF) to connect its on-premises network to a VPC. The security team wants to encrypt traffic over the Direct Connect connection. Which TWO options can be used? (Choose TWO.)

Select 2 answers
A.Use AWS KMS to encrypt the traffic.
B.Use AWS Certificate Manager to issue certificates for the connection.
C.Enable MACsec on the Direct Connect connection.
D.Use SSL/TLS to encrypt the traffic between on-premises and AWS.
E.Establish an IPsec VPN tunnel over the Direct Connect connection.
AnswersC, E

MACsec operates at layer 2, providing hop-by-hop encryption on the dedicated Direct Connect link between the customer router and the AWS device. It encrypts traffic traversing the connection itself, satisfying the requirement without overlaying an IPsec tunnel.

Why this answer

Option C is correct because AWS Direct Connect supports MACsec (IEEE 802.1AE) on dedicated connections at 10 Gbps and 100 Gbps, providing point-to-point Layer 2 encryption between the on-premises router and the AWS Direct Connect location. Option E is correct because you can run an IPsec VPN over the private VIF (or a transit VIF) on top of Direct Connect, which encrypts traffic end-to-end at Layer 3 between the on-premises VPN device and the AWS VPN endpoint. Option A is incorrect because AWS KMS is a key management service for encrypting data at rest, not for encrypting network traffic in transit over Direct Connect.

Option B is incorrect because ACM issues and manages TLS certificates for AWS-integrated services, not for encrypting a Direct Connect link. Option D is incorrect because generic SSL/TLS is not a supported mechanism for encrypting the Direct Connect private VIF transport itself; encryption must come from MACsec or an IPsec VPN.

Exam trap

The trap here is that candidates often assume encryption must happen at higher layers (like SSL/TLS) or through a separate service (like KMS), but the exam tests knowledge of Layer 2 encryption (MACsec) and Layer 3 encryption (IPsec over Direct Connect) as the two valid methods to encrypt traffic over a Direct Connect connection.

553
MCQhard

A company is using Amazon GuardDuty to detect threats. The security team notices that GuardDuty findings are not triggering the intended automated response via a CloudWatch Events rule. What is the most likely reason?

A.The CloudWatch Events rule's event pattern does not match the GuardDuty finding event structure.
B.The GuardDuty detector is in a different region than the CloudWatch Events rule.
C.The Lambda function invoked by CloudWatch Events does not have an IAM role assigned.
D.VPC Flow Logs are not enabled.
AnswerA

GuardDuty emits findings to CloudWatch Events as structured events, and the rule's pattern must exactly match their JSON schema. Specifically, the pattern must use "source": ["aws.guardduty"] and "detail-type": ["GuardDuty Finding"]; otherwise the rule is never triggered. If the pattern mismatches, the Lambda function will not be invoked, even though the finding is visible in the GuardDuty console. This is the most common cause of a silent rule failure.

Why this answer

GuardDuty findings are sent to CloudWatch Events as events with a specific structure, including fields like 'detail-type' set to 'GuardDuty Finding' and 'source' set to 'aws.guardduty'. If the CloudWatch Events rule's event pattern does not match this exact structure—for example, if it filters on the wrong 'source' or 'detail-type'—the rule will not trigger the intended automated response. This is the most common reason for the described failure.

Exam trap

The trap here is that candidates often assume the issue is with permissions (Lambda role) or prerequisites (VPC Flow Logs), but the core problem is almost always a mismatch in the event pattern structure, which is a fundamental CloudWatch Events concept.

How to eliminate wrong answers

Option B is wrong because CloudWatch Events rules can be configured to receive events from any region by using a cross-region event bus or by setting up the rule in the same region as the GuardDuty detector; the detector and rule do not need to be in the same region for the rule to match events, but the default behavior is that events are regional unless explicitly configured otherwise. Option C is wrong because the Lambda function's IAM role is only relevant for execution permissions after the rule triggers; if the rule does not match the event, the Lambda function is never invoked, so its role is irrelevant to the triggering issue. Option D is wrong because VPC Flow Logs are not required for GuardDuty to generate findings or for CloudWatch Events to receive them; GuardDuty uses multiple data sources (DNS logs, VPC Flow Logs, CloudTrail logs) but the absence of VPC Flow Logs does not prevent findings from being sent to CloudWatch Events.

554
MCQhard

A Security Engineer is troubleshooting why AWS CloudTrail is not delivering logs to an S3 bucket. The bucket policy allows CloudTrail access. What is a likely cause of the issue?

A.The S3 bucket uses SSE-KMS and the key policy does not grant CloudTrail permission
B.The S3 bucket has a lifecycle policy that deletes objects too quickly
C.CloudTrail is not enabled in the region
D.The S3 bucket is in a different region than the trail
AnswerA

CloudTrail requires explicit kms:GenerateDataKey and kms:Decrypt permissions on the customer managed KMS key used for SSE-KMS encryption of the S3 bucket. If the key policy grants these actions only to the bucket owner or other principals, CloudTrail's delivery role is denied and PutObject calls fail with an access denied error. This is a common cause of CloudTrail logs not appearing while the trail itself remains active.

Why this answer

When an S3 bucket uses SSE-KMS (Server-Side Encryption with AWS KMS), CloudTrail must have explicit permissions in the KMS key policy to decrypt the key and encrypt log files. Even if the S3 bucket policy grants CloudTrail access, the KMS key policy is a separate authorization layer; without a statement allowing CloudTrail to use the kms:GenerateDataKey and kms:Decrypt actions, log delivery will fail silently or with access denied errors.

Exam trap

The trap here is that candidates assume the S3 bucket policy is the only authorization layer, overlooking that KMS key policies act as an independent permission boundary when SSE-KMS is used, leading them to choose incorrect options like cross-region or lifecycle issues.

How to eliminate wrong answers

Option B is wrong because a lifecycle policy that deletes objects too quickly would cause logs to be removed after delivery, not prevent delivery itself; CloudTrail would still successfully deliver logs initially. Option C is wrong because CloudTrail must be enabled in the region where the trail is created, but the question states the trail exists and is not delivering logs, implying it is enabled; the issue is not about enabling the service. Option D is wrong because CloudTrail can deliver logs to an S3 bucket in a different region; cross-region delivery is supported and not a cause of delivery failure.

555
MCQmedium

A company has enabled CloudTrail in all regions and is logging to a single S3 bucket. The security team needs to ensure that any attempted deletion of CloudTrail logs generates an immediate alert. Which solution meets this requirement?

A.Configure an S3 event notification on the bucket for s3:ObjectRemoved:* events, invoke a Lambda function to publish to an SNS topic.
B.Use AWS Config to create a rule that checks for deleted objects and sends an SNS notification.
C.Enable CloudTrail Insights to detect unusual deletion activity and send alerts.
D.Create a CloudWatch Logs metric filter on the CloudTrail log group for DeleteObject events and trigger an alarm.
AnswerA

S3 event notifications are delivered in near-real-time directly from the bucket for object-level actions. By subscribing to s3:ObjectRemoved:* events, the Lambda function is invoked immediately upon a delete or delete-marker creation, then publishes to SNS for alerting. This bypasses the multi-minute delivery latency of CloudTrail logs and does not require any additional monitoring infrastructure.

Why this answer

S3 event notifications can be configured to trigger a Lambda function on `s3:ObjectRemoved:*` events, which captures all object deletion actions (including DeleteObject and DeleteObjects API calls). The Lambda function can then publish a message to an SNS topic, enabling immediate alerting. This approach provides real-time, event-driven monitoring directly from S3, without relying on CloudTrail log ingestion delays.

Exam trap

The trap here is that candidates may assume CloudTrail Insights or CloudWatch Logs metric filters are the correct real-time alerting mechanisms, but they overlook the inherent latency in CloudTrail log delivery and the fact that S3 event notifications provide immediate, event-driven triggers for object deletions.

How to eliminate wrong answers

Option B is wrong because AWS Config rules evaluate resource configurations against desired policies, but they do not monitor real-time object deletion events; Config checks configuration changes periodically (e.g., every 10 minutes) and cannot provide immediate alerts for individual object deletions. Option C is wrong because CloudTrail Insights detects unusual API activity patterns (e.g., anomalous volume of calls) but does not generate alerts for every single deletion event; it is designed for anomaly detection, not real-time per-event alerting. Option D is wrong because CloudTrail logs are delivered to S3, not to a CloudWatch Logs log group by default; you would need to set up a separate CloudWatch Logs subscription to stream CloudTrail logs, and even then, metric filters on CloudWatch Logs introduce latency (up to several minutes) and do not provide immediate alerting for each deletion.

556
MCQhard

Refer to the exhibit. A security engineer attaches this bucket policy to an S3 bucket. A user from IP address 203.0.113.10 tries to download an object using HTTP (not HTTPS). What will happen?

A.The request is allowed because the IP address matches the allow statement.
B.The request is denied because the IP is not in the allowed range.
C.The request is denied because HTTP is used.
D.The request is allowed because the user is using a valid IP.
AnswerC

The bucket policy includes an explicit deny statement that blocks any request where the transport protocol is HTTP, typically via a condition such as `aws:SecureTransport: false`. Since the request in question uses HTTP, that deny condition is met, and an explicit deny always overrides any allow statement in the policy. As a result, even a request from an otherwise permitted IP address is denied because of the insecure protocol.

Why this answer

The bucket policy includes a condition that denies access when the request uses HTTP (aws:SecureTransport equals false). Even though the IP address 203.0.113.10 matches the allowed IP range in the policy, the explicit deny for HTTP requests overrides the allow. Since the user is using HTTP, the request is denied.

Exam trap

The trap here is that candidates see the IP address matches the allow statement and assume the request is allowed, overlooking the explicit deny for HTTP that overrides the allow due to AWS IAM policy evaluation logic.

How to eliminate wrong answers

Option A is wrong because the policy contains an explicit deny condition for HTTP requests that overrides the IP-based allow statement, so matching the IP does not guarantee access. Option B is wrong because the IP address 203.0.113.10 is within the allowed IP range specified in the policy (203.0.113.0/24), so the denial is not due to IP mismatch. Option D is wrong because the request is denied due to the use of HTTP, not because the IP is invalid; the IP is valid but the protocol condition triggers the deny.

557
Multi-Selecthard

A security engineer is investigating a security incident where an EC2 instance was used to launch an outbound denial-of-service (DoS) attack. The engineer needs to collect forensic evidence. Which THREE actions should the engineer take? (Choose three.)

Select 3 answers
A.Reboot the instance to clear any malicious processes.
B.Delete the CloudTrail logs that show the instance's API calls.
C.Create an Amazon EBS snapshot of the instance's root volume.
D.Capture the instance's memory using a tool like LiME or Amazon EC2 instance memory capture.
E.Terminate the instance to stop the attack immediately.
AnswersC, D, E

Creating an EBS snapshot of the root volume captures the disk state at a single point in time, including compromised binaries, log files, user artifacts, and any persistence mechanisms the attacker installed. Unlike live acquisition, a snapshot allows offline analysis on a separate instance without altering the original evidence. It also provides a recoverable copy in case the instance is later terminated for containment.

Why this answer

Creating an Amazon EBS snapshot preserves persistent data for offline analysis. Option D is correct because capturing memory preserves volatile evidence. Option E is correct because after collecting forensic evidence, terminating the instance stops the attack immediately and prevents further damage.

Options A and B are incorrect because they destroy evidence (reboot clears memory, deletion removes logs).

Exam trap

A common pitfall is selecting options like rebooting (A) or deleting logs (B) which destroy evidence. While terminating (E) is a valid containment step, it must be done after evidence is collected via snapshot (C) and memory capture (D). The three correct actions are C, D, and E.

558
MCQeasy

A company wants to allow users to assume a role in another AWS account to access a specific S3 bucket. What must be configured?

A.A trust policy on the IAM role that allows the user's account to assume the role.
B.An S3 bucket policy that allows the user to access the bucket.
C.An IAM role with a trust policy allowing the user's account and a bucket policy granting the role access to the bucket.
D.A resource-based policy on the S3 bucket that allows the user's account.
AnswerC

This is the complete cross-account access solution: the role's trust policy allows the user's account to assume the role, and the bucket policy grants the role's ARN explicit permission to perform S3 actions. The user calls sts:AssumeRole and receives temporary credentials scoped to the role, then uses those credentials to access the bucket; the bucket policy recognizes the assumed-role principal. Both policies are necessary because the trust policy does not confer resource permissions, and the bucket policy does not grant the ability to assume the role.

Why this answer

Cross-account role assumption requires two coordinated policies: a trust policy on the IAM role in the target account that names the user's account (or principal) as a trusted entity, and a resource-based policy (bucket policy) in the target account granting the role access to the S3 bucket. Both are necessary because the trust policy authorizes the AssumeRole call, while the bucket policy authorizes the S3 actions once the role is assumed.

Exam trap

SCS-C02 often tests the misconception that a trust policy or a bucket policy alone is sufficient, when cross-account role assumption actually requires both the trust relationship and the resource permission to be in place.

How to eliminate wrong answers

Option A is wrong because a trust policy alone only allows the AssumeRole call; without a bucket policy granting the role S3 permissions, the assumed role cannot actually read the bucket. Option B is wrong because a bucket policy alone does not establish the trust relationship needed for the user to assume a role in the other account. Option D is wrong because a resource-based policy on the bucket that grants the user's account directly does not involve role assumption and does not satisfy the requirement to 'assume a role in another AWS account.'

559
MCQmedium

A security team needs to centralize audit logs from multiple AWS accounts into a single S3 bucket. The solution must be scalable and support future account additions. Which approach meets these requirements?

A.Use Amazon CloudWatch Logs to stream logs from each account to a central account.
B.Use AWS Trusted Advisor to collect logs from all accounts.
C.Configure CloudTrail in each account to deliver logs to the same S3 bucket.
D.Use AWS Organizations to create a CloudTrail trail that applies to all accounts in the organization.
AnswerD

An AWS Organizations trail is the native solution: CloudTrail is enabled in the management account and automatically applies to every member account, including accounts added later. The management account creates a service-linked role that allows CloudTrail to deliver log files from all member accounts to a designated S3 bucket in the management account. This centralizes all API activity across the organization into a single auditable store without per-account manual setup.

Why this answer

AWS Organizations allows you to create an organization-wide CloudTrail trail that automatically applies to all existing and future accounts in the organization. This is the most scalable approach because new accounts added to the organization are automatically covered without manual configuration per account. The trail delivers logs to a central S3 bucket, meeting the requirement to centralize audit logs.

Exam trap

The trap is choosing per-account CloudTrail configuration (Option C) because it seems straightforward, but the question emphasizes scalability and future account additions — only the organization trail automatically covers new accounts without manual intervention.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs streaming from each account to a central account requires per-account configuration and does not automatically cover new accounts — it is not scalable for future account additions without automation. Option B is wrong because AWS Trusted Advisor is a service that provides recommendations on cost, security, performance, and fault tolerance; it does not collect or centralize audit logs. Option C is wrong because configuring CloudTrail in each account to deliver to the same S3 bucket requires manual setup in every account and does not automatically apply to new accounts, making it less scalable than an organization trail.

560
MCQhard

A security engineer is investigating a potential compromise. They notice that an IAM user 'svc-backup' has been making unusual API calls from an IP address outside the company's VPC. The engineer wants to ensure all future API calls from this user are logged with full event details. However, the current CloudTrail trail is set to log only management events. What should the engineer do to capture the required details?

A.Enable VPC Flow Logs and correlate with CloudTrail logs.
B.Update the existing trail to log data events for IAM.
C.Create a new trail that logs data events for S3 and configure it to deliver to a separate S3 bucket.
D.Enable CloudTrail Insights to detect unusual activity for the user.
AnswerB

Updating the existing trail to log data events for IAM captures the exact API calls needed for the investigation, including GetUser, ListAccessKeys, GetLoginProfile, and other IAM data-plane operations. By default, a trail only records management events, so these data events are absent unless you explicitly add an event selector for the IAM resource type. Doing this on the existing trail preserves the current delivery configuration and eliminates the need for a separate, redundant trail, giving investigators a direct, complete audit of the user's activity.

Why this answer

CloudTrail trails configured to log only management events do not capture IAM user activity such as API calls made by the user. By updating the existing trail to log data events for IAM, the engineer ensures that all future API calls from 'svc-backup' are logged with full event details, including the source IP address and request parameters. This directly addresses the requirement without creating unnecessary additional trails or services.

Exam trap

The trap here is that candidates often confuse 'data events' with only S3 object-level operations, forgetting that IAM also has data events that must be explicitly enabled to capture user-level API calls.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) but do not log IAM API call details or user identity information, so they cannot provide the required event details. Option C is wrong because the unusual API calls are from an IAM user, not from S3; logging data events for S3 would capture S3 object-level operations but not IAM API calls made by the user. Option D is wrong because CloudTrail Insights detects unusual activity patterns based on existing logged events, but it does not enable logging of data events; it only analyzes management events already being logged, so it would not capture the missing data event details.

561
MCQeasy

A DevOps engineer needs to monitor failed SSH login attempts to Amazon EC2 instances. Which AWS service should the engineer use to collect and analyze the login events?

A.AWS Config
B.Amazon CloudWatch Logs
C.AWS CloudTrail
D.VPC Flow Logs
AnswerB

Amazon CloudWatch Logs is the correct choice because the CloudWatch agent (or the legacy Logs agent) can be installed on an EC2 instance to tail local system logs, including /var/log/auth.log on Amazon Linux or /var/log/secure on RHEL/CentOS. Once collected, you can define a metric filter to match patterns such as 'Failed password' or 'Connection refused' that sshd emits on failed attempts, and then trigger alarms based on those metrics. This directly captures the OS-level authentication events needed to monitor failed SSH logins.

Why this answer

Amazon CloudWatch Logs is the correct service because it can ingest, monitor, and analyze log data from EC2 instances, including SSH authentication logs (e.g., /var/log/secure or /var/log/auth.log). By installing the CloudWatch Logs agent on the EC2 instance, the engineer can stream these log events to CloudWatch Logs, where they can be searched, visualized, and used to trigger alarms on failed SSH attempts. AWS Config tracks resource configuration changes, not OS-level login events; CloudTrail records AWS API calls, not guest OS logs; and VPC Flow Logs capture network traffic metadata, not application or authentication logs.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which logs AWS API calls) with OS-level auditing, mistakenly thinking CloudTrail captures guest OS login events, when in fact CloudTrail only records control-plane actions and never sees inside the instance's operating system.

How to eliminate wrong answers

Option A is wrong because AWS Config is a service for evaluating and recording changes to AWS resource configurations (e.g., security group rules, instance types), not for collecting or analyzing OS-level login events like SSH attempts. Option C is wrong because AWS CloudTrail logs API calls made to the AWS control plane (e.g., RunInstances, DescribeInstances), not guest OS activities such as SSH logins, which occur within the instance's operating system. Option D is wrong because VPC Flow Logs capture metadata about IP traffic flowing to and from network interfaces (e.g., source/destination IP, ports, protocol), but they do not log application-layer events like SSH authentication successes or failures.

562
Multi-Selectmedium

Which TWO AWS services can be used to monitor and audit data access patterns to Amazon S3 buckets? (Choose 2.)

Select 2 answers
A.AWS Config
B.AWS CloudWatch
C.AWS CloudTrail
D.Amazon S3 Server Access Logs
E.AWS Trusted Advisor
AnswersC, D

AWS CloudTrail records S3 data events such as GetObject and PutObject, capturing the identity, source IP, timestamp and request details for each object-level API call. This satisfies the requirement to audit who accessed which objects, provided data events are explicitly enabled on the trail.

Why this answer

AWS CloudTrail (C) is correct because it records S3 data-plane API calls such as GetObject and PutObject when data events are enabled, providing an audit trail of who accessed which objects and when. Amazon S3 Server Access Logs (D) is correct because S3 can deliver detailed, per-request access records (requester, bucket, operation, HTTP status, bytes) directly to a target bucket for auditing access patterns. AWS Config (A) tracks resource configuration changes and compliance, not object-level data access patterns.

AWS CloudWatch (B) provides metrics, logs, and alarms but does not natively audit S3 object access requests. AWS Trusted Advisor (E) offers best-practice checks and recommendations, not access auditing.

Exam trap

The trap here is that candidates often confuse AWS Config (which checks configuration compliance) with CloudTrail (which records API activity), or they overlook that S3 Server Access Logs are a separate, native logging feature distinct from CloudTrail.

563
Multi-Selectmedium

Which THREE actions should be taken when preparing an incident response plan for AWS?

Select 3 answers
A.Enable AWS CloudTrail in all regions.
B.Share the AWS account root user password with the incident response team.
C.Automate incident response using AWS Systems Manager Automation runbooks.
D.Disable VPC Flow Logs to reduce log volume.
E.Create IAM roles with limited permissions for incident responders.
AnswersA, C, E

Enabling CloudTrail in all regions ensures a complete, auditable record of all AWS API activity, including management events, across every region, which is essential for reconstructing the timeline of an incident, identifying compromised credentials or unusual actions, and meeting forensic and compliance requirements. Without multi-region trails, actions in unmonitored regions can go undetected, leaving gaps in the investigation. CloudTrail is a foundational security service that should be enabled by default as part of incident response preparation.

Why this answer

AWS CloudTrail must be enabled in all regions to ensure that all API calls across the entire AWS infrastructure are logged. This provides a comprehensive audit trail essential for forensic investigation and identifying the scope of a security incident. Without multi-region CloudTrail, an attacker could operate in an unmonitored region, leaving no trace for incident responders.

Exam trap

The trap here is that candidates may think sharing the root password is acceptable for emergency access, but AWS explicitly prohibits this and recommends using IAM roles with break-glass procedures instead.

564
MCQeasy

A security engineer needs to monitor for suspicious API calls in near real-time and trigger an automated response. Which AWS service should be used to capture and analyze these API calls?

A.AWS CloudHSM
B.Amazon GuardDuty
C.AWS CloudTrail
D.AWS Config
AnswerC

CloudTrail records API activity across the account, capturing who called which AWS API, from where, and when. Its event history and trail delivery to CloudWatch Logs or EventBridge enable near-real-time detection and automated response to suspicious calls.

Why this answer

AWS CloudTrail is the correct service because it captures all API calls made to the AWS environment, including those from the AWS Management Console, SDKs, CLI, and AWS services. By enabling CloudTrail Insights or using CloudWatch Events with CloudTrail logs, you can monitor for suspicious API calls in near real-time and trigger automated responses via Lambda functions or SNS notifications.

Exam trap

The trap here is that candidates confuse GuardDuty's threat detection capabilities with the actual capture of API calls, forgetting that GuardDuty consumes CloudTrail logs rather than generating them, so the service that captures the calls is CloudTrail, not GuardDuty.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides hardware security modules for cryptographic key storage and operations, not for monitoring or analyzing API calls. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events for malicious activity, but it does not natively capture API calls itself—it relies on CloudTrail as a data source, and the question asks for the service that captures and analyzes the calls, not just analyzes them. Option D is wrong because AWS Config evaluates resource configurations against desired policies and tracks configuration changes, but it does not capture or analyze API calls; it focuses on resource state, not the API actions that led to that state.

565
MCQmedium

An administrator wants to audit all IAM actions in the account. Which AWS service should be used?

A.AWS Config
B.Amazon GuardDuty
C.AWS CloudTrail
D.Amazon CloudWatch
AnswerC

AWS CloudTrail records API activity across the account, capturing every IAM action as a management event with caller identity, timestamp and source IP. This satisfies the requirement to audit all IAM actions, since CloudTrail logs control-plane operations by default. CloudWatch, Config and Trusted Advisor do not provide this comprehensive API audit trail.

Why this answer

AWS CloudTrail records API activity, including all IAM actions. AWS Config tracks resource configuration changes, not API actions. Amazon GuardDuty is a threat detection service.

Amazon CloudWatch monitors metrics and logs, but does not record API calls.

566
MCQeasy

A security engineer needs to monitor for failed SSH login attempts to EC2 instances and send alerts. Which combination of AWS services should be used?

A.VPC Flow Logs and Amazon Athena.
B.AWS CloudTrail and Amazon SNS.
C.Amazon S3 event notifications and AWS Lambda.
D.CloudWatch Logs agent on EC2, CloudWatch Logs metric filter, and CloudWatch Alarm.
AnswerD

The CloudWatch Logs agent installed on the EC2 instance can tail OS-level log files such as /var/log/secure or /var/log/auth.log and continuously stream those events to CloudWatch Logs. A CloudWatch Logs metric filter can then be configured with a pattern like 'Failed password for' or 'authentication failure' to count each failed SSH login attempt into a custom metric. A CloudWatch Alarm associated with that metric can trigger when the count breaches a threshold—for instance, 5 failures in 5 minutes—and then invoke an SNS topic or other action. This captures exactly the OS-level authentication signal needed to detect brute-force or failed SSH login events.

Why this answer

The CloudWatch Logs agent on EC2 can stream SSH auth logs (e.g., /var/log/secure or /var/log/auth.log) to CloudWatch Logs. A metric filter can then parse these logs for failed SSH login patterns (e.g., 'Failed password'), and a CloudWatch Alarm can trigger an SNS notification or other action when the metric exceeds a threshold. This combination directly monitors OS-level authentication events, which is required for detecting failed SSH attempts.

Exam trap

The trap here is that candidates confuse AWS-managed logging services (CloudTrail, VPC Flow Logs) with OS-level logging, assuming CloudTrail captures all security events, when in fact it only records AWS API calls, not guest OS authentication attempts.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network-level metadata (IP addresses, ports, protocols) but do not log application-layer authentication events like SSH login success or failure; Athena can query flow logs but cannot extract SSH auth outcomes. Option B is wrong because AWS CloudTrail records API calls to the AWS control plane (e.g., EC2 RunInstances) but does not log guest OS-level SSH login attempts within an EC2 instance. Option C is wrong because S3 event notifications trigger on object-level events in S3 buckets, not on EC2 instance logs; while Lambda could process logs, there is no mechanism to capture SSH auth logs from EC2 instances without an agent or direct log delivery.

567
MCQmedium

A security engineer notices suspicious API calls from an EC2 instance that has an IAM role attached. The engineer wants to quickly determine if the instance's credentials have been compromised and are being used from an external IP address. What is the most efficient way to detect this?

A.Check VPC Flow Logs for traffic from the instance to unusual destinations.
B.Review AWS CloudTrail logs for the instance's IAM role and look for source IP addresses outside the VPC.
C.Enable Amazon GuardDuty and look for the finding type 'UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration'.
D.Use IAM Access Analyzer to review the trust policy of the instance's IAM role.
AnswerC

Amazon GuardDuty is the correct choice because it automatically monitors CloudTrail events, VPC Flow Logs, and DNS logs using threat intelligence and machine learning to detect anomalies. The specific finding type 'UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration' is designed to identify when EC2 instance role credentials are being used from an external source or in an unusual pattern, indicating exfiltration. This automated detection provides real-time alerts, which is far more effective than manual analysis for this type of security incident.

Why this answer

Amazon GuardDuty's finding type 'UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration' is specifically designed to detect when EC2 instance credentials (from an IAM role) are being used from an external IP address. GuardDuty analyzes CloudTrail management events, VPC Flow Logs, and DNS logs to identify anomalous API calls where the source IP is outside the VPC, indicating credential exfiltration. This is the most efficient method as it provides a pre-built, automated detection without manual log analysis.

Exam trap

The trap here is that candidates assume manual log analysis (CloudTrail or VPC Flow Logs) is the fastest approach, but GuardDuty provides automated, real-time detection specifically for this exfiltration pattern, making it the most efficient choice.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs only show network traffic (IP addresses, ports, protocols) but do not include IAM role or API call details, so they cannot directly confirm credential misuse from an external IP. Option B is wrong because while CloudTrail logs can show source IP addresses, manually reviewing them for the IAM role's API calls is not the most efficient method; it requires filtering and correlation, whereas GuardDuty automates this detection. Option D is wrong because IAM Access Analyzer reviews resource-based policies for unintended access (e.g., trust policies), not for detecting active credential compromise or external usage of instance credentials.

568
Multi-Selecthard

A security engineer is designing a permissions boundary for an IAM role used by an EC2 instance. The role must be able to read from an S3 bucket (my-bucket) and write to CloudWatch Logs. Which THREE conditions must be met for the role to have effective permissions? (Choose THREE.)

Select 3 answers
A.The EC2 instance must have an instance profile attached.
B.The effective permissions are the intersection of the boundary and identity-based policies.
C.The identity-based policy attached to the role must allow the required actions.
D.The permissions boundary policy must allow the required actions.
E.The S3 bucket policy must explicitly allow the role.
AnswersB, C, D

Effective permissions for any principal are always the intersection of all applicable policies: the permissions boundary acts as a ceiling, and the identity-based policy (e.g., attached to the role) acts as the grant. The IAM engine evaluates both, and an action is permitted only if it is allowed by the identity-based policy, not denied by the boundary, and not denied by any other policy (like a service control policy or resource policy). This intersection model is the fundamental logic of IAM permissions boundaries: the boundary limits the maximum permissions, but the identity policy must still explicitly grant the action within that limit.

Why this answer

Option B is correct because AWS evaluates a permissions boundary as a filter: the role's effective permissions are the intersection of what the identity-based policy grants and what the boundary allows, so an action must be permitted by both. Option C is correct because the identity-based policy attached to the role is the primary grant of permissions; without it allowing s3:GetObject on my-bucket and logs:CreateLogStream/logs:PutLogEvents, the role has no permissions regardless of the boundary. Option D is correct because the permissions boundary must also allow those same required actions, since any action not permitted by the boundary is denied even if the identity-based policy allows it.

Option A is not required for effective permissions because an instance profile is merely the container that delivers a role's temporary credentials to EC2, not a condition that grants or restricts the role's permissions. Option E is not required because a bucket policy is only needed when cross-account access or explicit resource-based grants are involved; for same-account access, the identity-based policy plus boundary is sufficient.

Exam trap

SCS-C02 often tests the misconception that a permissions boundary grants permissions, when in fact it only limits them — candidates incorrectly select the boundary as sufficient on its own.

569
MCQhard

A security engineer is configuring a VPC for a highly sensitive application. The VPC must not have a route to the internet, but the application needs to periodically download security patches from a specific domain (patches.example.com). Which solution meets these requirements with minimal operational overhead?

A.Launch a proxy server in a public subnet and configure the application to use the proxy.
B.Use a VPC endpoint for Amazon S3 and DynamoDB to download patches.
C.Create a VPC interface endpoint for AWS Systems Manager and use Systems Manager Patch Manager to apply patches.
D.Deploy a NAT gateway in a public subnet and add a route to the NAT gateway for the private subnet.
AnswerB

A VPC endpoint for Amazon S3 (a gateway endpoint) allows resources in private subnets to access S3 using private IP addresses with traffic staying entirely within the AWS network, without any internet gateway, NAT device, or VPN connection. Since patches are stored in S3 buckets, the application can retrieve patch files directly over the endpoint, and an endpoint for DynamoDB can handle patch metadata or state tables. This satisfies the no-internet-route requirement while enabling secure patch downloads.

Why this answer

It uses VPC endpoints for Amazon S3 (and optionally DynamoDB) to provide private connectivity to AWS services without requiring an internet gateway. By storing the security patches in an S3 bucket with a custom domain alias (e.g., patches.example.com), the application can download patches through the VPC endpoint, meeting the requirement of no internet route and minimizing operational overhead. Options A and D require an internet gateway, which creates a route to the internet.

Option C does not provide access to an external domain like patches.example.com.

Exam trap

Candidates may assume that AWS Systems Manager Patch Manager can download patches from any external domain via VPC endpoints, but SSM endpoints only provide private access to AWS services, not arbitrary external domains. The correct approach is to store patches in an AWS service like S3 and use a VPC endpoint.

How to eliminate wrong answers

Option A is wrong because launching a proxy server in a public subnet requires the VPC to have an internet gateway and a route to the internet, which violates the requirement that the VPC must not have a route to the internet. Option B is wrong because VPC endpoints for Amazon S3 and DynamoDB are designed for accessing those specific AWS services, not for downloading patches from an external domain like patches.example.com; they cannot route traffic to arbitrary internet destinations. Option D is wrong because deploying a NAT gateway in a public subnet requires the VPC to have an internet gateway attached to the public subnet, which again creates a route to the internet, directly contradicting the requirement.

570
MCQhard

A company uses Amazon Detective to investigate security findings. The security team is analyzing a GuardDuty finding of type 'Backdoor:EC2/C&CActivity.B!DNS' for an EC2 instance. The team wants to use Detective to understand the full scope of the incident, including which other resources the instance communicated with and any IAM roles used. However, when the team opens the finding in Detective, they see no network activity data for the instance. The instance is in a VPC with VPC Flow Logs enabled, and Flow Logs are being published to CloudWatch Logs. What should the team do to enable Detective to display the network activity?

A.Re-enable the GuardDuty finding in Amazon Detective.
B.Enable GuardDuty EKS Audit Logs monitoring.
C.Ensure that VPC Flow Logs are enabled for the VPC and are being published to Amazon CloudWatch Logs in the same account and Region as Detective.
D.Install the Amazon Detective agent on the EC2 instance.
AnswerC

Amazon Detective relies on VPC Flow Logs to populate the network activity details on a finding, such as source/destination IPs, ports, and protocol. For those flow logs to be ingested, they must be enabled for the relevant VPC and published to Amazon CloudWatch Logs in the same AWS account and Region as the Detective graph. Without this configuration, Detective can still show the GuardDuty finding and some API activity, but the network path section will be empty—so enabling VPC Flow Logs is the correct fix.

Why this answer

Amazon Detective ingests VPC Flow Logs from CloudWatch Logs to generate network activity visualizations for EC2 instances. Even though VPC Flow Logs are enabled and published to CloudWatch Logs, Detective requires that the logs are in the same AWS account and Region as the Detective behavior graph. If the logs are in a different account or Region, Detective cannot access them, resulting in no network activity data being displayed for the instance.

Exam trap

The trap here is that candidates assume simply enabling VPC Flow Logs and publishing to CloudWatch Logs is sufficient, but they overlook the requirement that the logs must be in the same AWS account and Region as the Detective behavior graph for ingestion to occur.

How to eliminate wrong answers

Option A is wrong because re-enabling the GuardDuty finding in Detective does not affect the ingestion of VPC Flow Logs; Detective automatically ingests findings from GuardDuty when the integration is enabled, and the issue is with missing network data, not the finding itself. Option B is wrong because GuardDuty EKS Audit Logs monitoring is specific to Amazon EKS clusters and has no relevance to EC2 instance network activity or VPC Flow Logs. Option D is wrong because Amazon Detective does not require or use an agent on EC2 instances; it relies on existing data sources like VPC Flow Logs, GuardDuty findings, and CloudTrail logs, and installing an agent would not enable network activity visualization.

571
Multi-Selectmedium

A company wants to use AWS services to detect and respond to a potential DDoS attack on their web application hosted on EC2 instances behind an Application Load Balancer (ALB). Which TWO AWS services should the company use for detection and mitigation?

Select 2 answers
A.AWS WAF
B.AWS Shield Advanced
C.Amazon Route 53
D.Amazon CloudFront
E.Amazon GuardDuty
AnswersA, B

AWS WAF is a web application firewall that can detect and respond to application-layer DDoS attacks by creating rate-based rules that automatically block or rate-limit requests from a single IP address once a configured threshold is exceeded. It also supports custom rules for HTTP inspection, making it a direct, policy-driven tool for DDoS mitigation. WAF integrates with CloudFront, Application Load Balancer, and API Gateway to enforce these rules in real time at the edge or ingestion point.

Why this answer

AWS WAF is correct because it allows you to create web access control lists (web ACLs) to filter and monitor HTTP/HTTPS requests to your Application Load Balancer. By defining rate-based rules, you can automatically block IP addresses that exceed a threshold of requests per 5-minute window, mitigating layer 7 DDoS attacks such as HTTP floods or SQL injection attempts.

Exam trap

The trap here is that candidates often confuse AWS Shield Advanced (which provides network-layer DDoS detection and mitigation) with AWS WAF (which provides application-layer filtering), but the question requires both detection and mitigation, and Shield Advanced alone does not offer the granular application-layer rule customization that WAF provides for an ALB-based web application.

572
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team needs to enforce that all Amazon S3 buckets across the organization are configured to block public access. Which solution should be used to centrally enforce this requirement?

A.Enable AWS Trusted Advisor to automatically remediate public buckets.
B.Use a service control policy (SCP) to deny the s3:PutBucketPublicAccessBlock action at the organization root.
C.Create an IAM role in each account that denies the s3:PutBucketPublicAccessBlock action.
D.Apply a bucket policy to each bucket that blocks public access.
AnswerB

An SCP applied at the organization root in AWS Organizations is an identity-policy boundary that affects every principal, including the root user, in every member account. By explicitly denying the s3:PutBucketPublicAccessBlock action, users cannot create, change, or delete S3 Block Public Access settings, effectively preventing all accounts from removing public-access protections. This is the only option that gives a centrally manageable, organization-wide preventive control.

Why this answer

Service control policies (SCPs) in AWS Organizations allow you to centrally control the maximum available permissions for all accounts within the organization. By denying the s3:PutBucketPublicAccessBlock action at the organization root, you prevent any account from disabling or modifying the public access block settings on any S3 bucket, thereby enforcing the security team's requirement across all accounts. This approach works because SCPs are applied at the organization level and override any IAM or bucket-level permissions that would otherwise allow the action.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies or bucket policies, thinking that a bucket policy or an IAM role can centrally enforce a deny across all accounts, but only SCPs operate at the organization level and apply to all principals in the member accounts.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor can only detect public buckets and provide recommendations, but it cannot automatically remediate them without additional custom automation (e.g., using AWS Config rules with auto-remediation), and it is not a central enforcement mechanism. Option C is wrong because creating an IAM role in each account that denies the action does not prevent users or services from using other IAM roles or direct IAM user permissions to call s3:PutBucketPublicAccessBlock; SCPs are the only way to enforce a deny across all principals in an account. Option D is wrong because applying a bucket policy to each bucket that blocks public access is a per-bucket manual or scripted approach that does not prevent future buckets from being created without the policy, nor does it centrally enforce the requirement across all existing and new buckets.

573
Multi-Selecteasy

Which TWO AWS services can be used to centrally collect and analyze logs from multiple AWS accounts? (Select TWO.)

Select 2 answers
A.AWS Config
B.Amazon Athena (to query logs in S3)
C.Amazon S3 (as a central log repository)
D.Amazon Inspector
E.AWS Shield
AnswersB, C

Amazon Athena is an interactive serverless query service that runs standard SQL directly against data stored in Amazon S3. After logs from multiple accounts are centrally delivered to an S3 bucket, Athena can query those logs (e.g., CloudTrail, VPC Flow Logs, ALB logs) without loading them into a database or managing infrastructure. It complements S3 as the storage layer by providing the analysis capability needed to search and correlate log data, making it a correct answer for centrally collecting and analyzing logs.

Why this answer

Amazon S3 can serve as a centralized log repository by aggregating logs from multiple AWS accounts using cross-account S3 bucket policies. Amazon Athena can then query those logs directly in S3 using standard SQL, enabling centralized analysis without moving data. Together, they provide a scalable, serverless solution for multi-account log collection and analysis.

Exam trap

The trap here is that candidates often mistake AWS Config for a log collection service because it records configuration changes, but it does not aggregate or analyze logs from multiple accounts; it only provides per-account configuration history and compliance rules.

574
MCQeasy

A company wants to ensure that data stored in Amazon S3 is encrypted at rest using keys managed by AWS. Which encryption option should they choose?

A.Client-side encryption.
B.Server-side encryption with AWS KMS (SSE-KMS).
C.Server-side encryption with customer-provided keys (SSE-C).
D.Server-side encryption with S3 managed keys (SSE-S3).
AnswerD

SSE-S3 uses a multi-layer envelope encryption scheme in which Amazon S3 creates a unique data key for each object and encrypts that data key with a S3-owned master key that AWS automatically rotates. The customer needs no key material, no KMS configuration, and no key lifecycle management, making this the straightforward option for delegating key management entirely to AWS. It is the only option listed that relies purely on AWS-managed keys with no customer-controlled key configuration.

Why this answer

SSE-S3 uses AES-256 encryption keys managed entirely by AWS, fulfilling the requirement for encryption at rest with AWS-managed keys. When you upload an object, S3 encrypts it before writing to disk and decrypts it when you access it, all without any customer action or key management overhead.

Exam trap

The trap here is that candidates often confuse SSE-KMS as 'AWS-managed' because KMS can use AWS managed keys, but the question specifically requires keys managed solely by AWS without any customer involvement, which only SSE-S3 provides.

How to eliminate wrong answers

Option A is wrong because client-side encryption requires the customer to manage keys and encrypt data before uploading, which does not meet the requirement for AWS-managed keys. Option B is wrong because SSE-KMS uses AWS KMS keys that are customer-managed (or AWS-managed but with customer control over key policies and rotation), not purely AWS-managed keys as specified. Option C is wrong because SSE-C requires the customer to provide and manage their own encryption keys, which contradicts the requirement for keys managed by AWS.

575
MCQhard

A security engineer is designing a system to detect and respond to IAM policy changes that could grant excessive permissions. The solution must alert within minutes of the change and automatically revert the change if it violates a predefined baseline. Which combination of services should the engineer use?

A.AWS CloudTrail and Amazon S3
B.AWS CloudTrail, Amazon CloudWatch Events, and AWS Lambda
C.AWS Config and AWS Systems Manager
D.IAM Access Analyzer and AWS Lambda
AnswerB

CloudTrail continuously streams API activity from the account, and a CloudWatch Events rule can match specific IAM actions (e.g., PutUserPolicy, AttachUserPolicy) in real time. The rule triggers a Lambda function, which can immediately respond by removing the policy, restoring a backup, or alerting security personnel. This is a native, serverless, event-driven architecture that satisfies both detection and automated remediation.

Why this answer

AWS CloudTrail logs IAM policy changes. Amazon CloudWatch Events (now EventBridge) can match specific API calls (e.g., PutRolePolicy) and trigger an AWS Lambda function within minutes. The Lambda function can evaluate the change against a baseline and automatically revert it if it violates the policy, providing both detection and remediation.

Exam trap

SCS-C02 often tests the misconception that AWS Config can automatically remediate without additional services, or that CloudTrail alone can trigger actions, ignoring the need for EventBridge and Lambda.

How to eliminate wrong answers

Option A is wrong because CloudTrail and S3 only store logs; they do not provide real-time alerting or automated remediation. Option C is wrong because AWS Config can detect changes but does not automatically revert them; Systems Manager can automate but requires additional setup and is not event-driven in the same way. Option D is wrong because IAM Access Analyzer identifies overly permissive policies but does not automatically revert changes; Lambda alone lacks the event trigger from CloudTrail.

576
MCQeasy

A company wants to automatically trigger a Lambda function when a new security finding is generated in AWS Security Hub. Which service should be used to invoke the Lambda function?

A.Amazon Simple Notification Service (SNS)
B.AWS Security Hub itself
C.Amazon EventBridge
D.AWS CloudTrail
AnswerC

Amazon EventBridge is the correct answer because Security Hub natively publishes all findings and finding updates to the default event bus as events such as 'Security Hub Findings - Imported'. A rule can use an event pattern to filter on compliance status, severity, or finding type and target a Lambda function, which EventBridge then invokes asynchronously. This is the standard event-driven integration designed for automating responses to Security Hub findings.

Why this answer

Amazon EventBridge is the correct service because AWS Security Hub automatically sends all findings to the default EventBridge bus as events. You can create an EventBridge rule that matches the 'Security Hub Findings - Imported' event pattern and targets a Lambda function for invocation. This is the native, recommended integration for event-driven responses to Security Hub findings.

Exam trap

The trap here is that candidates may think Security Hub can directly invoke Lambda or that SNS is the primary integration, but AWS explicitly designed EventBridge as the central event bus for all Security Hub findings to enable flexible, rule-based routing.

How to eliminate wrong answers

Option A is wrong because Amazon SNS is a pub/sub notification service that can be used as a target for EventBridge rules, but it is not the service that directly invokes Lambda in response to Security Hub findings; SNS would require a separate subscription and does not natively parse Security Hub event patterns. Option B is wrong because AWS Security Hub itself does not invoke Lambda functions directly; it only generates findings and sends them to EventBridge, CloudWatch, or S3 via integrations. Option D is wrong because AWS CloudTrail records API calls for auditing and does not provide real-time event-driven invocation of Lambda functions based on Security Hub findings.

577
MCQeasy

A security engineer is configuring a VPC with public and private subnets. The engineer needs to allow instances in the private subnet to download software updates from the internet. Which component should be added to the VPC?

A.VPN connection to on-premises.
B.VPC endpoint for Amazon S3.
C.Bastion host in a public subnet.
D.NAT gateway in a public subnet.
AnswerD

A NAT gateway in a public subnet is correct because it enables instances in private subnets to initiate outbound IPv4 traffic to the internet, such as software updates or API calls, while preventing unsolicited inbound connections from reaching them. The NAT gateway resides in a public subnet with an Elastic IP and uses the internet gateway to reach external networks, while private subnet route tables direct 0.0.0.0/0 traffic to the NAT gateway. It is fully managed, scales automatically, and does not require patch management—unlike a NAT instance.

Why this answer

A NAT gateway placed in a public subnet allows instances in a private subnet to initiate outbound connections to the internet (e.g., to download software updates) while remaining unreachable from the internet. The NAT gateway performs source NAT, translating the private IPs to its own Elastic IP, and returns responses to the originating instances. This is the standard AWS pattern for giving private subnets outbound-only internet access.

Exam trap

SCS-C02 often tests the misconception that a VPC endpoint or bastion host can provide general outbound internet access; candidates must recognize that only a NAT device (gateway or instance) in a public subnet enables private-subnet instances to reach the internet.

How to eliminate wrong answers

Option A is wrong because a VPN connection to on-premises provides connectivity to a corporate network, not to the public internet, and does not enable general internet downloads. Option B is wrong because a VPC endpoint for Amazon S3 only provides private access to S3 (and S3-compatible services), not to arbitrary internet hosts serving software updates. Option C is wrong because a bastion host in a public subnet is used for inbound SSH/RDP administrative access to private instances, not for outbound internet access from private instances.

578
Multi-Selecteasy

A security engineer needs to detect and respond to suspicious activity on an Amazon RDS database. Which TWO services can be used together to monitor database activity and trigger automated remediation?

Select 2 answers
A.Amazon Detective
B.Amazon RDS Enhanced Monitoring
C.AWS Lambda
D.Amazon RDS Performance Insights
E.Amazon GuardDuty
AnswersC, E

AWS Lambda is the correct answer because it is a serverless compute service that can be triggered by security events via Amazon EventBridge (e.g., a GuardDuty finding) and execute automated response actions. A Lambda function can revoke IAM credentials, modify security groups, terminate instances, or quarantine an RDS instance, turning detection signals into immediate remediation without manual intervention.

Why this answer

AWS Lambda is correct because it can be triggered by Amazon RDS database activity streams (e.g., via Amazon RDS for MySQL or PostgreSQL) or by Amazon CloudWatch Events/EventBridge rules that detect suspicious database events (such as failed login attempts or unusual query patterns). Lambda functions can then execute automated remediation actions, such as revoking database access, rotating credentials, or isolating the database instance. This enables a serverless, event-driven response to threats without manual intervention.

Exam trap

The trap here is that candidates often confuse monitoring services (Enhanced Monitoring, Performance Insights) with security detection and response services, or they overlook that GuardDuty alone cannot perform automated remediation—it requires a compute service like Lambda to execute the response actions.

579
MCQeasy

An IAM policy allows the iam:PassRole action for a specific role only when the role is passed to EC2. A developer tries to launch an EC2 instance with this role, but fails. What is the most likely missing permission?

A.The developer does not have ec2:RunInstances permission.
B.The developer needs to create the role first.
C.The developer does not have iam:PassRole permission for the role.
D.The condition in the policy is incorrect; it should use 'ec2.amazonaws.com' as the service.
AnswerA

Launching an EC2 instance is an ec2:RunInstances API call, and IAM requires a separate, explicit authorization for that action. A policy that grants iam:PassRole only authorizes the developer to attach a pre-existing role to a resource; it does not authorize creating or starting the instance itself. Without ec2:RunInstances permission, AWS denies the request even though the PassRole policy is valid, so this is the correct reason for the failure.

Why this answer

iam:PassRole only authorizes the principal to hand a role to a service; it does not authorize the service action itself. To launch an EC2 instance, the developer must also have ec2:RunInstances in their identity-based policy. The scenario states the PassRole condition is correctly scoped to EC2, so the failure is most likely the absence of the EC2 launch permission.

Without ec2:RunInstances, the API call is denied before PassRole is even evaluated.

Exam trap

SCS-C02 often tests the misconception that iam:PassRole alone is sufficient to use a role with a service — candidates forget that the service action (e.g., ec2:RunInstances) must also be allowed.

How to eliminate wrong answers

Option B is wrong because the role already exists (the policy references a specific role), and creating a role is not required to launch an instance with it. Option C is wrong because the question states the policy allows iam:PassRole for the role when passed to EC2 — so the permission is present and correctly conditioned. Option D is wrong because the condition for passing a role to EC2 uses the service principal 'ec2.amazonaws.com' in the iam:PassedToService condition key, which is exactly what the scenario describes; the condition is not the problem.

580
MCQeasy

A startup is deploying a web application on AWS. The application runs on EC2 instances behind an Application Load Balancer (ALB). The security team wants to ensure that all traffic to the EC2 instances is encrypted. They configure the ALB to listen on HTTPS (port 443) and forward traffic to the EC2 instances on HTTP (port 80). Additionally, they create a security group for the EC2 instances that only allows inbound traffic from the ALB's security group on port 80. However, a security audit reveals that the traffic between the ALB and EC2 instances is not encrypted. Which step should the security team take to encrypt the traffic between the ALB and EC2 instances?

A.Update the EC2 security group to allow traffic on port 443 from the ALB.
B.Enable encryption at rest on the EC2 instances.
C.Configure the target group to use HTTPS protocol and install a certificate on the EC2 instances.
D.Change the ALB listener to use TCP instead of HTTPS.
AnswerC

Changing the target group protocol to HTTPS instructs the ALB to establish TLS connections to the EC2 instances. To complete a TLS handshake, each instance must present a valid certificate (for the domain or IP) trusted by the client, so you must install and configure a certificate on the instances. This ensures that traffic between the ALB and instances is encrypted, closing the gap where plaintext HTTP might otherwise travel inside the VPC.

Why this answer

To encrypt traffic between the ALB and EC2 instances, configure the target group to use HTTPS protocol and install a certificate on the EC2 instances. This ensures the ALB sends HTTPS requests to the instances, encrypting the traffic. Option A is wrong because opening port 443 on the EC2 security group alone does not enable encryption; the listener must also use HTTPS for target traffic.

Option B is wrong because encryption at rest protects data stored on disk, not data in transit. Option D is wrong because changing the ALB listener to TCP would terminate TLS at the ALB and forward unencrypted traffic to the targets, which defeats the purpose.

581
Multi-Selectmedium

A security engineer is designing a VPC with public and private subnets. The VPC will host web servers in public subnets and database servers in private subnets. The web servers need to send traffic to the database servers, and the database servers must not have direct internet access. Which TWO configurations should the engineer implement?

Select 2 answers
A.Use network ACLs to block all inbound traffic to the private subnets.
B.Configure security group rules to allow inbound traffic from the web server security group to the database security group.
C.Do not add a route to an internet gateway in the route table for the private subnets.
D.Attach an internet gateway to the VPC and route the private subnets to it.
E.Add a NAT gateway in the public subnet and route the private subnets to it.
AnswersB, C

The database security group should have an inbound rule that references the web server security group as its source rather than a CIDR block. This allows the web tier to reach the database service on the required port, such as 3306 or 5432, while keeping the database isolated from all other sources. Because security group references are stateful and evaluated dynamically, this rule continues to work as web instances scale or are replaced, and it does not require the database to have a public IP or an internet gateway route.

Why this answer

Security group rules are stateful and can reference other security groups as a source, allowing the web server security group to be specified as the source for inbound traffic to the database security group. This ensures that only traffic originating from the web servers is permitted to reach the database servers, providing a logical, application-layer firewall without exposing the databases to the internet. Option C is correct because omitting a route to an internet gateway from the private subnet's route table ensures that the database servers have no direct path to the internet, satisfying the requirement that they must not have direct internet access.

Exam trap

The trap here is that candidates often confuse the purpose of NAT gateways (outbound-only internet access) with the requirement to block all internet access, leading them to incorrectly select Option E, or they mistakenly think network ACLs are the primary control for traffic between subnets, overlooking the stateful, group-based nature of security groups.

582
MCQhard

A security engineer notices that an IAM role in the production account is being assumed by a user from another AWS account, which violates the principle of least privilege. The role's trust policy allows the root user of the external account. What is the MOST secure way to restrict access to only a specific user in the external account?

A.Apply an SCP to the external account to deny the sts:AssumeRole action.
B.Create an IAM policy in the external account that denies sts:AssumeRole for the role.
C.Modify the trust policy to specify the exact user ARN instead of the root ARN.
D.Add a condition to the role's permissions policy requiring a specific source IP.
AnswerC

Change the Principal element in the role's trust policy from arn:aws:iam::123456789012:root to arn:aws:iam::123456789012:user/specific-user. The root ARN represents every principal in the external account, whereas the user ARN scopes the sts:AssumeRole permission to exactly one IAM user, eliminating the ability of roles or other users in that account to assume the production role.

Why this answer

Modifying the trust policy to include the specific user ARN is the most direct and secure approach. Option A is incorrect because SCPs do not affect cross-account access. Option B is incorrect because IAM policies on the role do not restrict who can assume it.

Option D is incorrect because the external account's IAM policies do not control trust.

583
MCQeasy

A developer needs to allow a Lambda function to write logs to CloudWatch Logs. What is the MINIMUM IAM policy that should be attached to the Lambda execution role?

A.{"Effect":"Allow","Action":["logs:CreateLogGroup","logs:CreateLogStream","logs:PutLogEvents"],"Resource":"*"}
B.{"Effect":"Allow","Action":"logs:PutLogEvents","Resource":"arn:aws:logs:us-east-1:123456789012:log-group:my-log-group:*"}
C.{"Effect":"Allow","Action":"logs:*","Resource":"*"}
D.{"Effect":"Allow","Action":["logs:DescribeLogGroups","logs:DescribeLogStreams"],"Resource":"*"}
AnswerA

CloudWatch Logs requires exactly these three log actions for a Lambda function to create its log group, stream and write events. Omitting any action causes logging to fail, so this is the minimum viable set.

Why this answer

The minimum policy for a Lambda function to write logs to CloudWatch Logs must include logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents. Lambda creates the log group and stream on first invocation, so all three actions are required. Resource '*' is acceptable because the log group name is not known in advance and Lambda needs to create it dynamically.

Exam trap

SCS-C02 often tests whether candidates know that Lambda requires CreateLogGroup and CreateLogStream in addition to PutLogEvents — many pick only PutLogEvents and miss the creation actions.

How to eliminate wrong answers

Option B is wrong because it only allows logs:PutLogEvents on a specific pre-existing log group — Lambda cannot create the log group or stream, so the first invocation fails. Option C is wrong because logs:* grants far more than the minimum, violating least privilege. Option D is wrong because DescribeLogGroups and DescribeLogStreams are read-only actions that do not allow writing log events.

584
MCQhard

An organization has a multi-account AWS environment using AWS Organizations. The security team needs to ensure that no Amazon EC2 instances are launched without an IAM instance profile that includes a specific role. Which preventive control should be implemented?

A.Create an SCP that denies ec2:RunInstances when the condition iam:InstanceProfile is not set to the required profile ARN.
B.Attach an IAM policy to all users that denies ec2:RunInstances unless an instance profile is specified.
C.Create an SCP that denies ec2:RunInstances when the condition ec2:InstanceProfile is not set.
D.Use AWS Config rule ec2-instance-profile-attached to detect non-compliant instances and automatically terminate them.
AnswerA

This SCP is correct because it applies at the organization level to all member accounts and uses the global IAM condition key iam:InstanceProfile to require a specific instance profile ARN. The deny rule blocks any ec2:RunInstances call from any principal—user, role, or service—that does not include the required profile in its parameters. The condition key is evaluated exactly and provides a preventive guardrail that cannot be bypassed by user-specific policy exceptions.

Why this answer

AWS Organizations Service Control Policies (SCPs) can be applied to all accounts in the organization to prevent actions across all principals. By using the `iam:InstanceProfile` condition key with the `ec2:RunInstances` action, the SCP denies the launch of any EC2 instance that does not have the required IAM instance profile attached. This is a preventive control that blocks the action before it occurs, ensuring compliance across the entire multi-account environment.

Exam trap

The trap here is confusing the condition key `iam:InstanceProfile` (which is correct for IAM instance profiles) with `ec2:InstanceProfile` (which does not exist), leading candidates to choose Option C, and also mistaking detective controls like AWS Config for preventive controls, as in Option D.

How to eliminate wrong answers

Option B is wrong because IAM policies attached to users only apply to those specific users and do not prevent actions performed by roles or services (e.g., EC2 Auto Scaling, AWS CloudFormation) that launch instances without an instance profile, making it an incomplete control. Option C is wrong because `ec2:InstanceProfile` is not a valid condition key for the `ec2:RunInstances` action; the correct condition key is `iam:InstanceProfile`, which references the IAM instance profile ARN. Option D is wrong because AWS Config rules are detective controls that only identify non-compliant resources after they are created, not preventive controls that block the action; automatic termination is a reactive measure, not a preventive one.

585
MCQmedium

A security team needs to audit all changes to IAM resources in their AWS account. Which AWS service should they use?

A.VPC Flow Logs
B.AWS CloudTrail
C.AWS Config
D.Amazon CloudWatch Logs
AnswerB

AWS CloudTrail records API activity across the account, including every IAM create, update, and delete operation, with the identity, timestamp, and source IP. This provides the complete audit trail the security team needs to track all IAM resource changes.

Why this answer

AWS CloudTrail records API activity across the AWS account, including all IAM resource changes such as CreateUser, AttachPolicy, DeleteRole, and UpdateAssumeRolePolicy. It captures the identity of the caller, the time, the source IP, and the request parameters, making it the authoritative audit trail for IAM modifications. CloudTrail event history provides 90 days of management events by default, and trails can deliver logs to S3 for long-term retention.

Exam trap

SCS-C02 often tests the distinction between CloudTrail (API activity audit), AWS Config (resource configuration history and compliance), and VPC Flow Logs (network traffic metadata), so candidates must match the service to the specific audit requirement — IAM changes require CloudTrail.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol, accept/reject) at the ENI, subnet, or VPC level — they do not record IAM API calls or resource changes. Option C is wrong because AWS Config records resource configuration changes and evaluates compliance against rules, but it does not provide the full API-level audit trail of who made each IAM change; it shows the resulting configuration state, not the API call details. Option D is wrong because Amazon CloudWatch Logs stores application and service logs, but IAM API activity is not automatically published there — CloudTrail is the service that captures IAM API calls, and CloudWatch Logs can receive CloudTrail logs only if explicitly configured.

586
MCQhard

A company is using AWS CloudTrail to log all management events and has enabled log file validation. What additional security benefit does log file validation provide?

A.It ensures the integrity of the log files by detecting tampering.
B.It prevents anyone from deleting the log files.
C.It encrypts the log files at rest.
D.It provides real-time monitoring for API calls.
AnswerA

CloudTrail log file integrity validation uses a SHA-256 hash chain, where each delivered log file references the hash of the previous file. This cryptographic digest is computed on the log file and stored in a separate digest file (optionally encrypted with the customer's KMS key), allowing you to detect any tampering or modification of log files after delivery. It confirms authenticity and integrity, not prevention of actions.

Why this answer

Log file validation uses a digital signature (SHA-256 hash) created for each log file, which is stored in a separate digest file. When validation is enabled, CloudTrail automatically creates a hash for each log file and signs it with a private key, allowing you to verify that the log files have not been modified, deleted, or tampered with after they were delivered. This ensures the integrity of the log files by detecting any unauthorized changes.

Exam trap

The trap here is that candidates often confuse log file validation with other security features like encryption, deletion prevention, or real-time monitoring, but the exam specifically tests whether you understand that validation is solely about integrity (detecting tampering) and not about confidentiality, availability, or alerting.

How to eliminate wrong answers

Option B is wrong because log file validation does not prevent deletion of log files; deletion prevention is achieved through S3 bucket policies, MFA delete, or S3 Object Lock, not through CloudTrail's validation feature. Option C is wrong because encryption at rest is provided by S3 server-side encryption (SSE-S3, SSE-KMS, or SSE-C) or CloudTrail's optional SSE-KMS integration, not by log file validation. Option D is wrong because real-time monitoring for API calls is provided by CloudTrail Lake, CloudWatch Events, or EventBridge, not by log file validation, which is an integrity check performed after log delivery.

587
MCQhard

A company is using AWS Transit Gateway to connect multiple VPCs and on-premises networks via VPN. The security team wants to inspect all traffic between VPCs before it reaches its destination. Which architecture should be used?

A.Use a VPN CloudHub to connect VPCs and inspect traffic at the VPN endpoint.
B.Use AWS Direct Connect to connect VPCs and inspect traffic on-premises.
C.Use a Transit Gateway with a central inspection VPC that hosts security appliances and route all inter-VPC traffic through it.
D.Use VPC Peering and configure security groups on each VPC to allow only necessary traffic.
AnswerC

AWS Transit Gateway acts as a hub to connect multiple VPCs and on-premises networks, enabling you to implement a hub-and-spoke routing architecture without VPC peering complexities. By attaching a dedicated inspection VPC to the Transit Gateway and configuring route tables so that all inter-VPC traffic is sent to that inspection VPC as a next hop, security appliances (e.g., Palo Alto, Fortinet) can inspect and filter all traffic. This provides centralized visibility and control over east-west traffic while avoiding the scaling limits and meshed connections of VPC peering.

Why this answer

AWS Transit Gateway can route inter-VPC traffic through a central inspection VPC that hosts security appliances (e.g., firewalls, IDS/IPS). By attaching the Transit Gateway to the inspection VPC and configuring route tables to force all traffic between VPCs to pass through the inspection VPC, the security team can inspect all traffic before it reaches its destination. This architecture provides centralized, scalable traffic inspection without requiring traffic to leave the AWS network.

Exam trap

The trap here is that candidates may confuse VPC Peering (Option D) as a valid inspection method, but it lacks a central inspection point and cannot enforce traffic inspection between VPCs without complex, non-scalable configurations.

How to eliminate wrong answers

Option A is wrong because VPN CloudHub is designed for connecting multiple on-premises sites via VPN, not for inter-VPC traffic inspection; it does not provide a mechanism to route VPC-to-VPC traffic through a central inspection point. Option B is wrong because AWS Direct Connect extends the on-premises network to AWS but does not inherently inspect inter-VPC traffic; routing traffic on-premises for inspection would add latency and egress costs, and it is not a recommended pattern for VPC-to-VPC inspection. Option D is wrong because VPC Peering creates direct, one-to-one connections between VPCs without a central inspection point; security groups can only filter traffic at the instance level, not inspect or redirect traffic between VPCs.

588
MCQeasy

Which AWS service allows you to create and manage encryption keys for your AWS resources?

A.AWS CloudHSM
B.AWS Key Management Service (KMS)
C.AWS Certificate Manager
D.AWS Secrets Manager
AnswerB

AWS Key Management Service (KMS) is the managed service purpose-built for creating and managing encryption keys, called customer master keys (CMKs), and data keys. It supports key policies, IAM-based access control, automatic annual rotation, key disabling and deletion, and direct cryptographic operations like encrypt, decrypt, and re-encrypt. KMS also integrates with dozens of AWS services for envelope encryption and records every key usage event in CloudTrail, making it the correct answer.

Why this answer

AWS Key Management Service (KMS) is the managed service designed specifically for creating, storing, and managing encryption keys used to encrypt data across AWS services. It integrates with AWS CloudTrail for auditing key usage and supports symmetric and asymmetric keys, with automatic key rotation and fine-grained access control via IAM and key policies.

Exam trap

The trap here is that candidates confuse AWS CloudHSM (a dedicated hardware security module) with KMS, not realizing that CloudHSM requires manual management and does not natively integrate with AWS services for automatic encryption, whereas KMS is the fully managed key creation and management service.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides dedicated hardware security modules (HSMs) for generating and storing keys, but it does not offer a managed key creation and management service with integrated AWS service encryption; instead, it requires you to manage the HSM appliance and client software yourself. Option C is wrong because AWS Certificate Manager (ACM) handles SSL/TLS certificate provisioning, renewal, and deployment, not the creation or management of encryption keys for data at rest or in transit. Option D is wrong because AWS Secrets Manager is designed to rotate, manage, and retrieve secrets (e.g., database credentials, API keys), not to create or manage encryption keys; it can use KMS to encrypt secrets, but it is not a key management service itself.

589
MCQeasy

A security analyst is reviewing AWS CloudTrail logs and notices a series of API calls from an unfamiliar IAM user. The calls include CreateUser, AttachUserPolicy, and CreateAccessKey. The analyst wants to quickly determine if this activity is anomalous and receive real-time alerts. Which AWS service should the analyst use to achieve this with minimal configuration?

A.Amazon GuardDuty
B.AWS Config
C.Amazon Detective
D.AWS Security Hub
AnswerA

GuardDuty continuously monitors CloudTrail management events and uses machine learning and threat intelligence to detect anomalous IAM behavior, such as unusual user creation or policy attachment. It generates findings in near real-time with minimal setup, requiring only that GuardDuty be enabled. This directly addresses the analyst's need for quick anomaly detection and alerts.

Why this answer

Amazon GuardDuty is the correct service because it automatically analyzes CloudTrail management events, VPC Flow Logs, and DNS logs to detect anomalous behavior, including suspicious IAM activity. It requires no additional infrastructure and generates findings in near real-time. Security Hub and Detective are for aggregation and investigation, while AWS Config focuses on configuration compliance.

Exam trap

The trap here is confusing services that aggregate or investigate findings with the service that actually performs the initial anomaly detection.

590
MCQmedium

A company runs a web application on Amazon EC2 behind an Application Load Balancer (ALB). The application handles payment card information (PCI) and must comply with PCI DSS. The security team wants to ensure that all data in transit between the client and the ALB is encrypted using TLS 1.2 or higher. The ALB currently uses a default certificate from AWS Certificate Manager (ACM) that was issued by Amazon. The compliance team has flagged that the certificate must be issued by a public Certificate Authority (CA) that is trusted by major browsers. The company wants to minimize operational overhead. What should the security team do?

A.Use AWS CloudHSM to generate a certificate and import it into ACM
B.Configure CloudFront in front of the ALB and use a CloudFront default certificate
C.Generate a self-signed certificate on the EC2 instance and upload it to ACM, then associate it with the ALB
D.Request a public certificate from ACM and associate it with the ALB
AnswerD

Requesting a public certificate from AWS Certificate Manager is the correct, fully managed way to implement HTTPS on an Application Load Balancer. ACM's public certificates are issued by trusted CAs (such as Amazon Trust Services), are free of charge, and are automatically renewed as long as you maintain the required DNS validation or email validation records. After ACM validates your domain, you simply attach the certificate to the ALB's HTTPS listener, and the ALB handles TLS termination. This avoids any self-managed CA infrastructure and is aligned with AWS best practices for securing a web application.

Why this answer

AWS Certificate Manager (ACM) can issue public certificates that are signed by Amazon's public CA, which is trusted by all major browsers and operating systems. Requesting a public certificate in ACM and associating it with the ALB listener satisfies the PCI DSS requirement for TLS 1.2+ encryption with a publicly trusted CA, while ACM handles renewal automatically — minimising operational overhead. This is the canonical AWS-recommended approach for ALB TLS termination.

Exam trap

The trap is overcomplicating the solution with CloudHSM or self-signed certs — candidates forget that ACM-issued public certificates are already signed by a browser-trusted public CA, making them the lowest-overhead compliant choice.

How to eliminate wrong answers

Option A is wrong because CloudHSM is for generating and storing private keys in a dedicated hardware security module; using it to create a certificate and import it into ACM adds significant operational overhead and is unnecessary when ACM can issue a trusted public cert directly. Option B is wrong because CloudFront default certificates only work for CloudFront distributions on the `*.cloudfront.net` domain and cannot be used for a custom domain or to secure the ALB's own endpoint — it also adds an unnecessary layer. Option C is wrong because a self-signed certificate is not trusted by browsers or public CAs, directly violating the compliance requirement, and ACM does not allow importing self-signed certs for public trust purposes.

591
MCQhard

A company uses AWS Organizations with multiple accounts. The security team needs to ensure that no account can disable a specific security service, such as AWS Config, across all accounts. Which approach should be used?

A.Create an IAM role with a deny policy for the action and attach it to all users
B.Create an AWS Config rule to check for the action and automatically remediate
C.Attach a service control policy (SCP) that denies the action at the root organization level
D.Enable AWS CloudTrail and create a metric filter to alert on the action
AnswerC

A service control policy attached to the root organizational unit acts as a maximum permission boundary for every account under it, cascading through all child OUs and accounts. Because SCPs affect the effective permissions of all principals, including the account root users, an explicit deny statement overrides any allow from IAM-based or resource-based policies. This makes it the only option here that centrally prevents an action across the entire organization before the request can be executed.

Why this answer

A service control policy (SCP) in AWS Organizations can be attached to the root, OU, or account level to set permission guardrails. An SCP that denies the action (e.g., config:StopConfigurationRecorder or config:DeleteConfigurationRecorder) at the root organization level applies to all accounts and cannot be overridden by account administrators, ensuring the security service cannot be disabled.

Exam trap

The trap is choosing detective or reactive controls (Config rules, CloudTrail alerts) instead of preventive controls (SCPs) — the question asks to 'ensure no account can disable,' which requires prevention, not detection.

How to eliminate wrong answers

Option A is wrong because an IAM role with a deny policy attached to all users is not scalable and can be bypassed by users with other roles or by root users; it does not enforce at the organization level. Option B is wrong because an AWS Config rule detects noncompliance but does not prevent the action — it can only remediate after the fact, and if the service is disabled, the rule may not function. Option C is correct.

Option D is wrong because CloudTrail and metric filters only provide alerting and auditing, not prevention — the action would still succeed.

592
Multi-Selecteasy

A company needs to monitor its AWS environment for compliance with the CIS AWS Foundations Benchmark. The security team wants to automatically check for non-compliant resources and receive reports. Which THREE services should be used together to meet these requirements? (Choose THREE.)

Select 2 answers
A.Amazon Detective
B.AWS Security Hub
C.AWS Config
D.Amazon GuardDuty
E.Amazon Macie
AnswersB, C

Correct. Security Hub is the central hub for compliance status, aggregating findings from AWS Config and GuardDuty, and providing reports on CIS benchmark compliance.

Why this answer

AWS Security Hub (B) is correct because it natively supports the CIS AWS Foundations Benchmark as a security standard, aggregates findings from integrated services, and generates compliance scores and reports against that benchmark. AWS Config (C) is correct because it provides configuration recording and managed/custom rules that evaluate resource compliance, and Security Hub's CIS standard relies on AWS Config rules to assess many controls. Amazon GuardDuty (D) is not required for CIS AWS Foundations Benchmark compliance checking or reporting; it is a threat-detection service whose findings can be viewed in Security Hub but does not evaluate CIS controls.

Amazon Detective (A) is used for investigating and visualizing security findings after they occur, and Amazon Macie (E) discovers and classifies sensitive data in S3; neither is part of the CIS compliance-checking and reporting workflow.

Exam trap

The trap is that candidates often confuse threat-detection services (GuardDuty, Detective, Macie) with compliance monitoring services. Security Hub is the central place for aggregating and reporting on compliance standards like CIS, and AWS Config provides the underlying rule evaluation engine. GuardDuty findings do not check CIS controls or produce CIS compliance reports.

593
MCQmedium

A security engineer needs to audit all access to a KMS customer managed key. Which AWS service should be used?

A.AWS Config
B.VPC Flow Logs
C.Amazon CloudWatch Logs
D.AWS CloudTrail
AnswerD

AWS CloudTrail records all KMS API requests as audit events, including both management-plane actions (such as CreateKey, EnableKeyRotation, and DescribeCustomKeyStores) and data-plane operations like Encrypt, Decrypt, and GenerateDataKey. Each CloudTrail event captures the caller's IAM identity, source IP address, key ID, request parameters, and timestamp, and can be delivered to Amazon S3 or CloudWatch Logs for long-term retention and analysis. CloudTrail is therefore the authoritative service for auditing all access to a KMS custom key store or the keys associated with it.

Why this answer

AWS CloudTrail records every API call made to KMS, including Encrypt, Decrypt, GenerateDataKey, CreateKey, and key policy changes, capturing the caller identity, source IP, timestamp, and request parameters. This makes CloudTrail the authoritative service for auditing KMS key usage and access.

Exam trap

The trap is confusing configuration auditing (AWS Config) with access auditing (CloudTrail); Config tells you what a resource looks like, CloudTrail tells you who did what to it.

How to eliminate wrong answers

Option A is wrong because AWS Config tracks resource configuration changes and compliance, not individual API-level access events to KMS keys. Option B is wrong because VPC Flow Logs capture IP-level network traffic metadata (source/dest IP, port, protocol), not KMS API calls, which are HTTPS to the KMS endpoint. Option C is wrong because CloudWatch Logs stores log data but does not natively capture KMS API activity unless CloudTrail is configured to deliver to it; CloudWatch alone is not the audit source.

594
MCQeasy

A company wants to automate the detection of sensitive data in an S3 bucket. Which AWS service should be used?

A.Amazon Macie
B.AWS Artifact
C.Amazon Inspector
D.Amazon GuardDuty
AnswerA

Amazon Macie is a fully managed data security service that uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data stored in S3. It identifies data types such as personally identifiable information (PII), financial data, and credentials, then surfaces findings in dashboards and EventBridge events. For this use case, Macie is correct because it continuously scans and reports on sensitive data without requiring custom tooling or manual inspection.

Why this answer

Amazon Macie uses machine learning to discover and classify sensitive data, making it the correct choice for automated detection of sensitive data in S3. AWS Artifact provides compliance reports, Amazon Inspector assesses vulnerabilities, and Amazon GuardDuty detects threats—none specifically focus on sensitive data detection.

595
MCQeasy

A company is designing a disaster recovery plan for its Amazon RDS for MySQL database. The database must be encrypted at rest. Which approach ensures that the database is encrypted and can be restored in another AWS Region?

A.Enable encryption on the existing DB instance
B.Export the database to Amazon S3 and use S3 cross-Region replication
C.Create a manual snapshot and copy it to another Region with encryption
D.Create a cross-Region read replica with encryption enabled
AnswerD

Creating a cross-Region read replica with encryption enabled gives you a continuously updated, readable copy of the primary database in another AWS Region. RDS automatically replicates changes from the primary using its asynchronous replication engine, and in a disaster you simply promote the replica to a standalone master with a few clicks, minimizing RTO. For encryption, the primary must be encrypted and you specify an AWS KMS key in the destination Region when creating the replica, so the DR copy is encrypted in transit and at rest.

Why this answer

(Create a cross-Region read replica with encryption enabled) is correct because it continuously replicates data to another AWS Region and encryption at rest can be enabled, ensuring both disaster recovery and encryption. Option A is wrong because encryption cannot be enabled on an existing unencrypted DB instance; a new encrypted instance must be created. Option B is wrong because exporting to S3 and using cross-Region replication does not provide a real-time database replica and complicates recovery.

Option C is wrong because while a manual snapshot can be copied to another Region with encryption, it does not provide continuous replication; it is a point-in-time backup, not a disaster recovery solution that minimizes data loss.

596
MCQeasy

A security engineer is investigating a potential data exfiltration from an S3 bucket. Which AWS service should be used to analyze the VPC Flow Logs for the S3 bucket's endpoint?

A.Amazon Macie
B.Amazon Inspector
C.Amazon GuardDuty
D.Amazon Detective
AnswerD

Amazon Detective is purpose-built for security investigation: it ingests VPC Flow Logs, AWS CloudTrail, and EKS audit logs and automatically builds an interactive graph of network traffic, resource interactions, and IAM identities. You can expand a suspected instance to view all of its inbound/outbound connections, the aggregate bytes transferred per peer, and the API actions performed around each flow, which directly answers whether and how data exfiltration occurred. This interactive, multi-source correlation is exactly what the other options lack.

Why this answer

Amazon Detective is the correct service because it can ingest and analyze VPC Flow Logs, including those for a VPC endpoint used to access an S3 bucket. Detective uses machine learning, statistical analysis, and graph theory to identify the root cause of suspicious network traffic patterns, such as unusual data volumes or connections to external IPs, which are indicative of data exfiltration.

Exam trap

The trap here is that candidates confuse Amazon GuardDuty's alerting capability with Amazon Detective's investigative analysis, forgetting that GuardDuty generates findings but Detective is needed for deep forensic analysis of VPC Flow Logs to understand the full scope of an incident.

How to eliminate wrong answers

Option A is wrong because Amazon Macie is a data security service that uses machine learning to discover, classify, and protect sensitive data stored in S3 buckets, but it does not analyze VPC Flow Logs or network traffic. Option B is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances and container workloads for software vulnerabilities and unintended network exposure, not for analyzing VPC Flow Logs. Option C is wrong because Amazon GuardDuty is a threat detection service that can monitor VPC Flow Logs for malicious activity, but it is a continuous monitoring and alerting service, not an investigative tool for deep analysis of historical flow log data; Detective is designed for post-breach root-cause analysis.

597
MCQmedium

A security engineer is configuring a new Amazon RDS for MySQL database. The compliance team requires that all database connections be encrypted in transit. Which configuration ensures this requirement is met?

A.Enable encryption at rest using KMS
B.Enable IAM database authentication
C.Set the 'ssl' parameter to '1' in the DB parameter group
D.Enable the 'require_secure_transport' parameter in the DB parameter group
AnswerD

Setting require_secure_transport to 1 in the custom DB parameter group instructs the MySQL server to reject any connection that does not use a secure transport protocol such as TLS/SSL. This enforces encryption in transit at the server level, meaning clients that request plaintext are refused immediately. It directly addresses the requirement to prevent all unencrypted traffic, regardless of client-side settings.

Why this answer

Setting the 'require_secure_transport' parameter to '1' in the DB parameter group forces all connections to the RDS for MySQL instance to use TLS/SSL encryption. This ensures that data in transit is encrypted, meeting the compliance requirement. The parameter enforces that only encrypted connections are accepted, rejecting any unencrypted attempts.

Exam trap

The trap here is that candidates often confuse enabling SSL support (the 'ssl' parameter) with requiring SSL (the 'require_secure_transport' parameter), thinking that simply enabling SSL on the server forces all clients to use it, but in reality, the server will accept both encrypted and unencrypted connections unless the requirement is explicitly enforced.

How to eliminate wrong answers

Option A is wrong because encryption at rest using KMS protects data stored on disk, not data transmitted over the network, so it does not address encryption in transit. Option B is wrong because IAM database authentication provides authentication using IAM credentials, but it does not enforce or provide encryption of the connection itself; it can be used with or without SSL. Option C is wrong because setting the 'ssl' parameter to '1' enables SSL support on the server, but it does not require clients to use SSL; clients can still connect without encryption, so it does not guarantee all connections are encrypted.

598
MCQmedium

Refer to the exhibit. A security engineer configured this S3 bucket policy for CloudTrail, but CloudTrail logs are not being delivered. What is the MOST likely missing permission?

A.Missing s3:GetBucketAcl permission.
B.The condition StringEquals should be StringLike.
C.Missing s3:PutObject permission for the bucket.
D.The bucket ARN is incorrect.
AnswerC

CloudTrail delivers log files by writing objects into the bucket, so the bucket policy must grant the CloudTrail service principal s3:PutObject on the target prefix. Without that write action, delivery fails regardless of ACLs or ownership controls, which only govern access to objects already written.

Why this answer

For CloudTrail to deliver logs to an S3 bucket, the bucket policy must grant CloudTrail the s3:PutObject permission on the bucket's objects (the /* ARN), in addition to s3:GetBucketAcl on the bucket itself. The exhibit's policy is missing the s3:PutObject statement, so CloudTrail cannot write log files even though it can check the bucket ACL. This is the most likely missing permission.

Exam trap

SCS-C02 often tests the misconception that s3:GetBucketAcl alone is sufficient for CloudTrail delivery, when the critical missing permission is s3:PutObject on the bucket objects ARN.

How to eliminate wrong answers

Option A is wrong because s3:GetBucketAcl is typically already present in a correct CloudTrail bucket policy and is not the missing piece — the exhibit shows the ACL check is not the blocker. Option B is wrong because the StringEquals vs StringLike condition is not the cause of delivery failure; the condition operator affects matching of the source ARN but the fundamental missing permission is PutObject. Option D is wrong because an incorrect bucket ARN would cause a different error and is not the most likely missing permission given the scenario focuses on permissions.

599
MCQhard

A company has an S3 bucket with versioning and MFA Delete enabled. A user attempts to delete an object version using the AWS CLI without MFA. What will happen?

A.The object version is marked for deletion and will be deleted after 30 days.
B.The request fails with an AccessDenied error.
C.The object version is deleted and a delete marker is created.
D.The object version is deleted but not permanently.
AnswerB

The correct behavior is that the request fails with AccessDenied. S3 MFA Delete requires an MFA-authenticated request to permanently delete an object version. Since the request does not include the x-amz-mfa header with a valid MFA code, S3 denies the DeleteObject call. This prevents any deletion, including creation of delete markers.

Why this answer

When MFA Delete is enabled on an S3 bucket, any request to permanently delete an object version or to change the versioning state of the bucket must include a valid MFA token. If a user attempts to delete an object version without MFA, the request fails with an AccessDenied error. This is the expected behavior to protect against accidental or malicious deletions.

Exam trap

SCS-C02 often tests the misconception that MFA Delete applies to all delete operations, but it only applies to deleting specific object versions or changing versioning state; deleting an object without a version ID (creating a delete marker) does not require MFA.

How to eliminate wrong answers

Option A is wrong because there is no automatic deletion after 30 days; MFA Delete does not mark objects for deletion. Option C is wrong because deleting an object version without MFA is not allowed; a delete marker is created only when deleting an object without specifying a version ID, but that is a different operation and still requires MFA if MFA Delete is enabled for version deletion. Option D is wrong because the object version is not deleted at all; the request is denied.

600
MCQmedium

A company uses AWS Organizations with SCPs to restrict services. An administrator creates an SCP that denies access to EC2. A developer in a member account tries to launch an EC2 instance but fails. What is the most likely reason?

A.The SCP from the organization denies EC2
B.The root user of the account has denied EC2
C.The developer's IAM permissions boundary blocks EC2
D.The EC2 instance has a resource-based policy denying access
AnswerA

SCPs apply to all principals in the account.

Why this answer

Service Control Policies (SCPs) in AWS Organizations act as a centralized governance mechanism that applies a deny effect across all IAM principals in member accounts. When an SCP explicitly denies access to EC2, it overrides any allow permissions at the account level, including those granted by IAM policies. The developer's launch attempt fails because the SCP's deny is evaluated before any account-level permissions, effectively blocking the action regardless of the developer's IAM role or user permissions.

Exam trap

The trap here is that candidates often assume IAM permissions or permissions boundaries are the primary cause of access failures, overlooking that SCPs apply a blanket deny that overrides all account-level permissions, including those of the root user.

How to eliminate wrong answers

Option B is wrong because the root user of a member account is also subject to SCPs from the organization; while the root user has full permissions by default, an SCP that denies EC2 applies to the root user as well, so the root user cannot bypass the SCP to allow EC2. Option C is wrong because an IAM permissions boundary limits the maximum permissions a principal can have, but it does not deny actions by itself; if the developer's IAM policy allowed EC2 and the boundary did not explicitly deny EC2, the boundary would not cause the failure—the SCP's deny is the overriding factor. Option D is wrong because EC2 instances do not have resource-based policies that control who can launch them; resource-based policies are used for services like S3 buckets or Lambda functions, not for controlling the ability to create EC2 instances.

Page 7

Page 8 of 17

Page 9