Courseiva

AWS Certified Security Specialty SCS-C02 (SCS-C02) — Questions 601–675

1205 questions total · 17pages · All types, answers revealed

Page 8

Page 9 of 17

Page 10
601
MCQeasy

A security engineer needs to ensure that all API calls in an AWS account are logged for incident response. Which AWS service should be enabled?

A.Amazon GuardDuty
B.VPC Flow Logs
C.AWS Config
D.AWS CloudTrail
AnswerD

AWS CloudTrail is the only service that directly records AWS API activity as first-class audit log events. When enabled, it captures the identity of the caller (IAM user or role), the source IP address, the requested action, request parameters, and the response returned by the service, for both management events and (when configured) data events. These logs can be delivered to Amazon S3 and CloudWatch Logs, and the trail can be multi-region and organization-wide, making CloudTrail the authoritative record of every API call for incident response and governance. Unlike anomaly-detection services such as GuardDuty, CloudTrail does not infer or analyze behavior—it simply logs each call exactly as it occurred.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made in an AWS account, including the identity of the caller, the time of the call, the source IP address, and the request parameters. This logging is essential for incident response to reconstruct events and identify unauthorized or malicious activity.

Exam trap

The trap here is that candidates confuse AWS Config with CloudTrail because both deal with 'logging' and 'compliance,' but Config tracks resource state changes over time, not the API calls that caused those changes.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes logs (like CloudTrail, VPC Flow Logs, and DNS logs) for malicious activity, but it does not itself generate or store API call logs. Option B is wrong because VPC Flow Logs capture metadata about network traffic (IP addresses, ports, protocols) at the elastic network interface level, not API calls to AWS services. Option C is wrong because AWS Config records resource configuration changes and evaluates compliance rules, but it does not log API calls; it relies on CloudTrail for API history.

602
MCQhard

Refer to the exhibit. The security team is investigating a security incident in us-west-2 region. They notice that management events from us-west-2 are not appearing in the CloudTrail logs. Based on the exhibit, what is the most likely reason?

A.The S3 bucket is in a different region
B.The trail is not logging data events
C.The trail is not a multi-region trail
D.The trail does not have log file validation enabled
AnswerC

A single-region trail only records management events that occur in the same region where the trail is defined. Events happening in other regions are not captured at all unless the trail is configured as a multi-region trail, which creates equivalent trails in every region. Since the security team is investigating events from another region, the lack of a multi-region configuration directly explains the gap.

Why this answer

The exhibit shows a single-region CloudTrail trail. A single-region trail only logs events in the region where it is created. Since management events from us-west-2 are not appearing, the trail must have been created in a different region.

To capture events from us-west-2, the trail would need to be multi-region. Therefore, the most likely reason is that the trail is not a multi-region trail.

Exam trap

The trap is that candidates might assume a trail in the same region as the incident automatically captures all events, but the exhibit likely shows a trail in a different region. A single-region trail only captures events from its own region, so to capture events from us-west-2, the trail must be multi-region or a separate trail must exist in us-west-2.

How to eliminate wrong answers

Option A is wrong because an S3 bucket in a different region does not prevent CloudTrail from delivering logs; CloudTrail can deliver logs to an S3 bucket in any region, and the logs would still contain management events from us-west-2. Option B is wrong because data events are separate from management events; the trail not logging data events would not affect the delivery of management events, which are logged by default unless explicitly excluded. Option D is wrong because log file validation is a security feature that ensures log integrity but does not affect whether events are captured or delivered; it only validates that log files have not been tampered with after delivery.

603
MCQhard

A company's incident response team is using AWS Systems Manager to run commands on EC2 instances for forensic analysis. The team needs to ensure that the commands are run with minimal latency and that the results are stored securely. Which Systems Manager capability should the team use?

A.AWS Systems Manager Automation
B.AWS Systems Manager Session Manager
C.AWS Systems Manager Patch Manager
D.AWS Systems Manager Run Command
AnswerD

AWS Systems Manager Run Command is the correct choice because it executes an arbitrary command (shell or PowerShell) on one or more managed instances through the SSM Agent and can immediately write the output to Amazon S3. It supports tag-based targeting, returns status and response details, and offers low latency—critical for incident response. Storing the output to S3 provides a persistent and auditable record for later analysis, while the same command can be fanned out to a fleet in parallel.

Why this answer

AWS Systems Manager Run Command is the correct capability because it allows the incident response team to execute commands on EC2 instances with minimal latency by using the SSM Agent to run scripts or commands directly, and it can store command output in Amazon S3 or CloudWatch Logs for secure, durable storage. This meets the requirement for low-latency execution and secure result storage without requiring interactive sessions or complex automation workflows.

Exam trap

The trap here is that candidates often confuse Session Manager (interactive access) with Run Command (non-interactive execution), assuming that 'minimal latency' implies a live session, but Run Command is actually faster for scripted tasks because it avoids session setup overhead and can target multiple instances in parallel.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Automation is designed for multi-step, automated workflows (e.g., patching, AMI creation) and introduces orchestration overhead, not optimized for low-latency ad-hoc command execution. Option B is wrong because AWS Systems Manager Session Manager provides interactive shell or port forwarding access, not a mechanism to run commands with minimal latency and store results securely; it is for live sessions, not scripted execution. Option C is wrong because AWS Systems Manager Patch Manager is specifically for automating OS patching, not for running arbitrary forensic commands or storing results.

604
MCQmedium

A company's security team discovers that an Amazon EC2 instance has been compromised and is sending outbound traffic to a known malicious IP address. The instance is in a VPC with a security group that allows all outbound traffic. What is the FASTEST way to stop the outbound traffic without affecting other instances?

A.Modify the network ACL of the subnet to deny outbound traffic to the malicious IP.
B.Change the route table of the subnet to route traffic to a blackhole.
C.Terminate the compromised EC2 instance immediately.
D.Modify the security group attached to the instance to revoke all outbound rules.
AnswerD

Security groups are stateful, instance-level firewalls, so modifying the security group attached to the instance to revoke all outbound rules will immediately block the compromised instance's egress traffic without affecting other instances in the subnet. Changes apply instantly to the ENI, and because security groups are scoped to the instance, this provides precise, surgical isolation. This is the fastest way to stop malicious outbound communication while preserving the instance for investigation.

Why this answer

Security groups are stateful and act as a virtual firewall at the instance level. By revoking all outbound rules in the security group attached to the compromised EC2 instance, you immediately block all outbound traffic from that specific instance without affecting any other instances in the VPC. This is the fastest and most targeted action because it requires no changes to subnet-level configurations or instance termination.

Exam trap

The trap here is that candidates often confuse security groups with network ACLs, assuming that a NACL change is faster or more precise, when in fact security groups are instance-level and can be modified instantly without affecting other instances, making them the fastest and most targeted solution.

How to eliminate wrong answers

Option A is wrong because modifying a network ACL (NACL) affects all instances in the subnet, not just the compromised one, and NACLs are stateless, requiring explicit rules for both inbound and outbound traffic, which adds complexity and latency. Option B is wrong because changing the route table to a blackhole would affect all traffic from the subnet, not just the compromised instance, and would disrupt other instances. Option C is wrong because terminating the instance stops all traffic but also destroys the instance and any data on it, which is not the fastest nor the least disruptive method; it also does not allow for forensic analysis.

605
MCQmedium

Refer to the exhibit. A security engineer configured this S3 bucket policy to allow CloudTrail to deliver logs. However, logs are not being delivered. What is the MOST likely reason?

A.The Resource should be arn:aws:s3:::my-trail-bucket/*, not with AWSLogs prefix.
B.The Principal is set to a service, but must be an AWS account ID.
C.The Action should be s3:GetObject, not s3:PutObject.
D.The policy is missing s3:GetBucketAcl permission for CloudTrail.
AnswerD

The missing permission is s3:GetBucketAcl, and without it CloudTrail will reject the bucket even though PutObject is allowed. Before writing its first log, CloudTrail calls GetBucketAcl on the destination bucket to confirm the bucket's owner, and the bucket policy must explicitly grant that action to the cloudtrail service principal. If the bucket ACL check fails, CloudTrail returns an error such as 'bucket does not exist or bucket ACL does not allow access' and log delivery halts. This permission is a separate, required statement from the object-write permission.

Why this answer

CloudTrail requires the s3:GetBucketAcl permission on the S3 bucket to verify that the bucket policy grants the necessary access for log delivery. Without this permission, CloudTrail cannot confirm it has write access, and log delivery fails even if s3:PutObject is allowed. Option D correctly identifies this missing permission as the root cause.

Exam trap

The trap here is that candidates focus on the obvious s3:PutObject action and overlook the prerequisite s3:GetBucketAcl permission, which CloudTrail requires for its initial access validation.

How to eliminate wrong answers

Option A is wrong because the Resource ARN with the AWSLogs prefix is correct for CloudTrail log delivery; CloudTrail writes logs to the AWSLogs/<account-id>/CloudTrail/ path, so the policy must restrict access to that prefix to follow security best practices. Option B is wrong because CloudTrail uses a service principal (cloudtrail.amazonaws.com) in the Principal field, not an AWS account ID, which is the standard and correct configuration. Option C is wrong because CloudTrail delivers logs by writing (putting) objects to the bucket, so s3:PutObject is the required action, not s3:GetObject.

606
MCQeasy

A company uses Amazon RDS for MySQL and wants to monitor database activity for security analysis. Which AWS service should be used to capture detailed database activity logs such as login attempts and query execution?

A.AWS CloudTrail
B.Amazon RDS Enhanced Monitoring
C.AWS Config
D.Amazon RDS Database Activity Streams
AnswerD

Amazon RDS Database Activity Streams captures database activity at the engine level, including every SQL statement, authenticated user, client IP, session ID, and execution timestamp, and pushes it as a near-real-time stream to Amazon Kinesis. From Kinesis, the stream can be consumed by external audit, security, or monitoring tools to alert on suspicious queries or maintain an audit trail. This is exactly the capability needed to monitor database queries in real time, making it the correct answer.

Why this answer

Amazon RDS Database Activity Streams is the correct service because it captures a near-real-time stream of database activity, including login attempts, query execution, and other operations at the database engine level. It integrates with AWS CloudWatch and third-party monitoring tools, providing granular audit logs for security analysis that go beyond what CloudTrail or Enhanced Monitoring offer.

Exam trap

The trap here is confusing AWS CloudTrail (which logs control-plane API calls) with database-level activity logging, leading candidates to choose CloudTrail when they need internal database audit trails.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API calls made to the RDS service (e.g., creating or modifying DB instances), not the internal database activity like SQL queries or login attempts. Option B is wrong because Amazon RDS Enhanced Monitoring provides OS-level metrics (CPU, memory, disk I/O) from the hypervisor, not database-level audit logs. Option C is wrong because AWS Config tracks resource configuration changes and compliance, not real-time database activity or query logs.

607
MCQmedium

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting. Which AWS service should they use?

A.AWS Network Firewall
B.AWS WAF
C.AWS Firewall Manager
D.AWS Shield Advanced
AnswerB

AWS WAF is a web application firewall that protects web applications by inspecting HTTP(S) requests and allowing or blocking them based on rules you define. It specifically includes managed rule groups and match conditions for SQL injection and cross-site scripting (XSS), as well as rate-based rules to mitigate abusive traffic. Since the application is running in EC2 behind an Application Load Balancer or Amazon CloudFront, AWS WAF can be attached to those endpoints directly.

Why this answer

AWS WAF is a web application firewall that helps protect web applications from common web exploits like SQL injection and cross-site scripting (XSS). It integrates directly with Application Load Balancers to inspect HTTP/HTTPS requests and block malicious traffic based on customizable rules. This makes it the correct choice for the security team's requirement.

Exam trap

The trap here is that candidates often confuse AWS WAF with AWS Network Firewall, thinking network-layer filtering is sufficient for application-layer threats, but WAF is specifically designed for HTTP/HTTPS inspection at the application layer.

How to eliminate wrong answers

Option A is wrong because AWS Network Firewall is a stateful managed firewall for VPC network traffic, not designed to inspect application-layer payloads like HTTP requests for SQL injection or XSS. Option C is wrong because AWS Firewall Manager is a policy management service that centrally configures and enforces firewall rules across accounts, not a service that directly inspects web traffic for exploits. Option D is wrong because AWS Shield Advanced provides DDoS protection and cost protection against scaling attacks, not application-layer threat detection for SQL injection or XSS.

608
MCQeasy

A security engineer is investigating a potential security incident involving an Amazon RDS database. The engineer needs to determine if someone attempted to access the database with incorrect credentials. Which AWS service should the engineer use to view authentication failures?

A.Amazon CloudWatch Logs
B.VPC Flow Logs
C.Amazon RDS database logs (error logs)
D.AWS CloudTrail
AnswerC

Amazon RDS database logs, specifically the error log, are the authoritative source for database-level authentication failure entries. For example, MySQL error logs record messages like 'Access denied for user 'alice'@'host' (using password: YES)' for each failed login, and PostgreSQL logs similarly capture 'FATAL: password authentication failed for user 'alice''. These logs are generated by the database engine itself and are accessible through the RDS console, the DescribeDBLogFiles API, or by streaming them to Amazon CloudWatch Logs. Because the question is about database authentication attempts, the RDS error log directly contains the required evidence.

Why this answer

Amazon RDS database error logs capture authentication failures, including attempts with incorrect credentials, because the database engine itself logs these events. For example, MySQL's error log records 'Access denied for user' messages, and PostgreSQL's log records 'FATAL: password authentication failed' entries. This makes RDS database logs the direct source for viewing authentication failures at the database level.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which logs API calls) with database-level authentication logging, assuming CloudTrail captures all security events, but it does not log database engine authentication failures because those occur within the database session, not through the AWS API.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs is a service for storing, monitoring, and accessing log files, but it does not generate or capture database authentication failures by itself; it can only ingest logs from other sources like RDS database logs if configured. Option B is wrong because VPC Flow Logs capture metadata about network traffic (IP addresses, ports, protocols) but do not log application-level authentication events such as database credential failures. Option D is wrong because AWS CloudTrail records API calls made to the AWS control plane (e.g., CreateDBInstance, ModifyDBInstance) and does not capture database engine-level authentication events like incorrect password attempts.

609
MCQeasy

A company wants to centralize logs from multiple AWS accounts into a single S3 bucket for analysis. The accounts are part of an AWS Organizations organization. Which set of steps will accomplish this?

A.Create an organization trail in the management account with logging enabled for all accounts.
B.Use AWS Config to aggregate logs from all accounts into a central S3 bucket.
C.Create a CloudTrail trail in each account and configure each to write to the same S3 bucket.
D.Set up Amazon Kinesis Data Firehose in each account to stream logs to a central S3 bucket.
AnswerA

CloudTrail organization trails are created in the management account and automatically apply to every account in AWS Organizations, delivering all account logs to a single S3 bucket without per-account configuration. This is the native mechanism for centralizing management-event logging across an organization, and the management account owns and controls the trail. Because the trail is organization-wide, you get consistent logging coverage and centralized governance.

Why this answer

AWS Organizations allows you to create an organization trail from the management account. When you enable logging for all accounts in the organization, CloudTrail automatically creates a trail that applies to every account in the organization, delivering log files from all accounts to a single S3 bucket without needing per-account configuration.

Exam trap

The trap here is that candidates often assume each account must individually configure CloudTrail to write to a shared bucket, overlooking the organization trail feature that automates multi-account log centralization through AWS Organizations.

How to eliminate wrong answers

Option B is wrong because AWS Config aggregates configuration items and compliance snapshots, not CloudTrail logs; it is designed for resource configuration tracking, not centralized log delivery. Option C is wrong because while each account can write to the same S3 bucket, this approach requires manual setup per account, does not leverage Organizations for automatic multi-account management, and can lead to permission conflicts or log delivery failures without proper bucket policies. Option D is wrong because Amazon Kinesis Data Firehose is a streaming data delivery service, not a native CloudTrail log destination; CloudTrail cannot directly send logs to Firehose without additional configuration, and this approach does not provide the centralized, automatic trail management that an organization trail offers.

610
MCQeasy

Your company has a serverless application using AWS Lambda, Amazon API Gateway, and Amazon DynamoDB. The security team enabled AWS CloudTrail and Amazon GuardDuty. GuardDuty generates a finding 'Recon:EC2/PortProbeUnprotectedPort' for an EC2 instance that does not exist in the account. Upon investigation, you realize that the finding is triggered by a misconfigured Network Load Balancer (NLB) that is exposing a port to the internet. The NLB is used by the API Gateway. You need to reduce false positives for this specific finding. What should you do?

A.Change the NLB to an Application Load Balancer.
B.Enable AWS Shield Advanced to block the probes.
C.Disable GuardDuty for the account.
D.Create a suppression rule in GuardDuty to filter out findings for the NLB's public IP and port.
AnswerD

Create a GuardDuty suppression rule that filters findings based on the NLB's public IP address and port, which automatically excludes those matching findings from the Active findings view and from CloudWatch Events delivery. Suppression rules evaluate regex-based criteria on finding fields, so you can scope the rule to exactly this endpoint while all other GuardDuty detections remain fully active and visible. This is GuardDuty's intended mechanism for whitelisting known false positives and involves no infrastructure changes, additional cost, or loss of detection coverage.

Why this answer

GuardDuty suppression rules allow you to filter out findings that are known false positives based on specific criteria, such as the public IP and port of the NLB. Since the NLB is intentionally exposing a port for API Gateway, the port probe finding is expected behavior, not a real threat. Suppressing findings for that specific combination reduces noise without disabling GuardDuty for the entire account.

Exam trap

The trap here is that candidates may think changing the load balancer type or adding DDoS protection will stop the probes, but GuardDuty detects the probe activity itself, not the vulnerability—so only suppression rules can prevent the false positive without disabling the service.

How to eliminate wrong answers

Option A is wrong because changing the NLB to an Application Load Balancer does not address the root cause—the exposed port—and ALBs also have public IPs that can be probed, potentially generating similar findings. Option B is wrong because AWS Shield Advanced is a DDoS protection service that does not suppress or filter GuardDuty findings; it mitigates volumetric attacks but does not prevent port probe detections. Option C is wrong because disabling GuardDuty entirely would remove all threat detection capabilities for the account, which is an overreaction to a single false positive and violates security best practices.

611
Multi-Selecthard

Which TWO AWS services can be used to automatically block malicious IP addresses at the network perimeter? (Select TWO.)

Select 2 answers
A.Amazon Route 53
B.Security Groups
C.Network ACLs
D.AWS WAF
E.AWS Shield Advanced
AnswersC, D

Network ACLs (NACLs) are stateless, subnet-level firewalls that evaluate rules in ascending numeric order and support both allow and deny rules. To automatically block a specific IP, you can add a deny rule with a /32 source CIDR at the top of the NACL, but because NACLs are stateless you must also write a corresponding rule for the return traffic. This explicit-denying capability makes NACLs one of the correct answers.

Why this answer

Network ACLs (NACLs) are stateless virtual firewalls that operate at the subnet level in a VPC. They can be configured with inbound and outbound rules to explicitly deny traffic from specific IP addresses, effectively blocking malicious IPs at the network perimeter before they reach the instances.

Exam trap

The trap here is that candidates often confuse Security Groups with Network ACLs, thinking Security Groups can block traffic at the network perimeter, but Security Groups are instance-level and cannot block traffic before it enters the subnet.

612
MCQmedium

A security engineer is implementing automated incident response. The engineer wants to use AWS Lambda to automatically remediate GuardDuty findings. What is the recommended pattern to trigger the Lambda function?

A.Configure an Amazon EventBridge rule to match GuardDuty findings and invoke the Lambda function.
B.Subscribe the Lambda function to an SNS topic that GuardDuty publishes findings to.
C.Use CloudWatch Logs subscription filter to trigger Lambda on GuardDuty log entries.
D.Have the Lambda function poll the EC2 instance metadata for threat indicators.
AnswerA

EventBridge is GuardDuty's native event bus integration. GuardDuty automatically publishes each finding as an event to the default event bus, where a rule can match the detail-type 'GuardDuty Finding' and use Lambda as a target. The rule supports filtering by severity, account, or finding type, and Lambda receives the finding JSON directly, enabling precise, low-latency automated remediation. This is the architecturally supported pattern with built-in retry and optional dead-letter queues.

Why this answer

Amazon EventBridge is the recommended pattern because it natively integrates with AWS GuardDuty to receive all finding events in near real-time. By configuring an EventBridge rule that matches GuardDuty finding types (e.g., 'UnauthorizedAccess:EC2/SSHBruteForce'), you can directly invoke a Lambda function for automated remediation without polling or intermediate services. This pattern is serverless, event-driven, and follows AWS best practices for decoupled incident response.

Exam trap

The trap here is that candidates may assume GuardDuty uses SNS or CloudWatch Logs for output, similar to other AWS services, but GuardDuty exclusively emits findings as EventBridge events, making EventBridge the only native and recommended trigger pattern for Lambda remediation.

How to eliminate wrong answers

Option B is wrong because GuardDuty does not publish findings directly to SNS topics; it sends findings to EventBridge or can be configured to send to SNS via EventBridge, but direct subscription is not supported. Option C is wrong because GuardDuty does not write findings to CloudWatch Logs; findings are sent as events to EventBridge, not as log entries. Option D is wrong because EC2 instance metadata does not contain threat indicators from GuardDuty; it only provides instance-specific metadata like IP address or IAM role, and polling it would be an anti-pattern for event-driven remediation.

613
MCQhard

Refer to the exhibit. An IAM policy is attached to a group. A user in the group accesses the S3 bucket from an IP address 203.0.113.5 using HTTPS. What will be the result?

A.The user will be denied access because the source IP is not in the allowed ranges.
B.The user can access objects because an Allow with conditions grants access by default.
C.The user will be denied access because the policy does not allow the action explicitly.
D.The user can access objects because the condition for SecureTransport is met.
AnswerA

Because the only Allow statement in the attached group policy is conditioned on both a permitted source IP range and HTTPS (SecureTransport=true), a request coming from an IP outside that range does not satisfy the source IP condition. In IAM evaluation, an Allow with unsatisfied conditions contributes no effective permission, and since no other applicable statement grants the action, the default-deny rule applies. The user is therefore denied even though HTTPS might be used.

Why this answer

The IAM policy includes a condition that restricts access to only the IP ranges 192.0.2.0/24 and 198.51.100.0/24. The user's IP address 203.0.113.5 does not fall within these ranges, so access is denied. Option B is incorrect because an Allow with conditions does not grant access by default; all conditions must be satisfied.

Option C is incorrect because the policy does explicitly allow the s3:GetObject action, but only under the specified conditions. Option D is incorrect because while SecureTransport is satisfied, the IP condition is not met, and all conditions must be true for the Allow to take effect.

614
Multi-Selectmedium

A company uses AWS Organizations and wants to restrict the use of specific instance types across all accounts. Which TWO actions should be taken to enforce this restriction?

Select 2 answers
A.Restrict instance types at the VPC level using network ACLs.
B.Use AWS CloudTrail to monitor instance launches and send alerts.
C.Apply a Service Control Policy (SCP) that denies ec2:RunInstances with noncompliant instance types.
D.Create an IAM role that denies launch of noncompliant instances.
E.Use AWS Config rules to detect and automatically stop noncompliant instances.
AnswersC, E

An SCP applied at the root or OU level with a Deny effect for ec2:RunInstances and a StringNotLike/StringNotEquals condition on ec2:InstanceType explicitly blocks noncompliant launches for all principals inside the affected accounts, including IAM users, roles, and the root user. SCPs provide an authoritative guardrail because they are evaluated as a filter on the account's effective permissions and cannot be overridden by a more permissive IAM policy within that account. This gives central governance across the entire AWS Organization, making it the correct preventive control.

Why this answer

Service Control Policies (SCPs) in AWS Organizations allow you to centrally control the maximum available permissions for all accounts in the organization. By applying an SCP that denies ec2:RunInstances when the instance type does not match an allowed list, you can effectively prevent any user or role in any account from launching noncompliant instance types, even if they have full IAM permissions to do so.

Exam trap

The trap here is that candidates often confuse detective controls (like CloudTrail or AWS Config) with preventive controls (like SCPs), or they mistakenly think IAM roles can enforce organization-wide restrictions when they are only scoped to the trust policy of that specific role.

615
MCQeasy

A security analyst needs to detect and alert on suspicious API calls in real time. Which combination of AWS services should be used?

A.AWS CloudTrail, Amazon CloudWatch Logs, and Amazon EventBridge.
B.Amazon Inspector and AWS CloudTrail.
C.Amazon GuardDuty and AWS Lambda.
D.AWS Config and Amazon SNS.
AnswerA

CloudTrail records API activity, CloudWatch Logs stores those events, and EventBridge filters them in near real time to trigger alerts. This satisfies the requirement to detect suspicious API calls as they occur, rather than relying on periodic batch analysis or delayed log review.

Why this answer

AWS CloudTrail captures API calls and delivers log files to Amazon CloudWatch Logs, where you can define metric filters to detect suspicious patterns. Amazon EventBridge then consumes those filtered log events to trigger real-time alerts or automated remediation actions. This combination provides the end-to-end pipeline needed for real-time detection and alerting on API activity.

Exam trap

The trap here is that candidates often assume GuardDuty alone can provide real-time API call alerts, but GuardDuty findings are based on aggregated threat intelligence and behavioral analysis, not real-time per-API-call filtering, whereas CloudTrail plus CloudWatch Logs plus EventBridge gives you precise, real-time control over specific API actions.

How to eliminate wrong answers

Option B is wrong because Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities and network exposure, not a real-time API call detection service. Option C is wrong because while Amazon GuardDuty can detect suspicious API activity using threat intelligence and anomaly detection, it does not natively provide real-time alerting on specific API calls; it generates findings that are typically evaluated asynchronously, and AWS Lambda alone cannot capture or filter API calls without a source like CloudTrail. Option D is wrong because AWS Config is a resource inventory and compliance service that tracks configuration changes, not API calls, and Amazon SNS is a notification service that requires a source of events (like CloudTrail and CloudWatch Logs) to deliver alerts.

616
MCQhard

During an incident response, a security engineer needs to capture a forensic image of an EC2 instance's root volume for analysis. The instance is running and cannot be stopped. What is the recommended approach to capture the volume without stopping the instance?

A.Use the dd command via AWS Systems Manager to create a raw image and store it in S3.
B.Detach the volume from the instance, create a snapshot, and then attach it to a forensic analysis instance.
C.Create a snapshot while the volume is attached to the instance.
D.Use AWS Systems Manager to run a command that copies the volume content to S3.
AnswerC

Creating a snapshot while the volume is attached is the correct approach because Amazon EBS snapshots are designed to be taken of in-use volumes without stopping the instance. The snapshot is crash-consistent (or file-system-consistent if the instance has the AWS backup agent or you freeze the filesystem), and it provides a point-in-time forensic copy that can later be analyzed by creating a new volume from the snapshot. This satisfies the incident response requirement to preserve evidence while keeping the instance running for continued investigation or memory acquisition.

Why this answer

The correct approach is to create a snapshot of the EBS root volume while it is still attached to the running instance (Option C). Snapshots can be taken of in-use volumes without stopping the instance, providing a point-in-time copy for forensic analysis. Option B is incorrect because you cannot detach the root volume of a running instance without first stopping it, which contradicts the requirement not to stop the instance.

Exam trap

Candidates often mistakenly believe that the root volume can be detached while the instance is running (Option B), or that a snapshot requires stopping the instance. In reality, snapshots of attached volumes are allowed and are the recommended method for capturing forensic images without downtime.

How to eliminate wrong answers

Option A is wrong because the dd command via AWS Systems Manager would require the volume to be unmounted or the instance to be stopped to avoid data corruption from concurrent writes, and storing a raw image in S3 is inefficient and not a standard forensic practice. Option C is wrong because creating a snapshot while the volume is attached is actually the correct first step, but the question asks for the full recommended approach to capture the volume for analysis, which includes using the snapshot to create a new volume and attach it to a forensic instance—not just taking the snapshot. Option D is wrong because AWS Systems Manager cannot directly copy volume content to S3 without first creating a snapshot or using a tool like dd, which would require the volume to be unmounted or the instance to be stopped to ensure consistency.

617
Multi-Selecteasy

Which TWO are valid ways to authenticate an IAM user?

Select 2 answers
A.SSL/TLS certificate
B.MFA token
C.Password
D.SSH key pair
E.Access keys (access key ID and secret access key)
AnswersC, E

An IAM user password is the primary authentication factor for the AWS Management Console, entered together with the account ID or alias at the sign-in page. This password is stored as a login profile for the IAM user and can be rotated manually by the user or administratively by an account administrator. It functions as a persistent credential that grants full access to the console session. This is one of the two standard ways to authenticate an IAM user.

Why this answer

Option C (Password) is correct because an IAM user with console access authenticates to the AWS Management Console using a user name and password, which is the standard sign-in credential for interactive console sessions. Option E (Access keys, i.e., access key ID and secret access key) is correct because programmatic requests to AWS APIs, CLI, and SDKs are signed with an access key ID and secret access key pair tied to the IAM user. Option A (SSL/TLS certificate) is not a valid IAM user authentication method; X.509 certificates are used for signing SOAP requests in limited legacy scenarios, not as a general IAM user credential.

Option B (MFA token) is not a standalone authentication method — it is a second factor used in addition to a password or access key, not a primary credential by itself. Option D (SSH key pair) is not an IAM authentication mechanism; SSH keys are used for logging into EC2 instances (e.g., via CodeCommit or instance access), not for authenticating to AWS as an IAM user.

Exam trap

The trap is considering MFA as a primary authentication method. Candidates might select MFA token as a way to authenticate, but it is only a second factor. Another trap is confusing SSH keys with IAM authentication; SSH keys are for EC2 instances, not IAM users.

618
MCQeasy

A company uses AWS CloudTrail to log all API activity. The security team wants to ensure that any changes to CloudTrail configuration (e.g., disabling the trail, deleting the trail, modifying the log delivery) are detected immediately. They have created a CloudWatch Events rule to capture the event 'StopLogging' and send an SNS notification. During testing, the team stops the trail and does not receive the notification. The CloudWatch Events rule is configured with the correct event pattern. What should the team check?

A.Verify that the CloudTrail trail is logging management events.
B.Ensure that the event pattern includes the correct source and detail-type.
C.Confirm that the SNS topic subscription is confirmed.
D.Check the IAM role associated with the CloudWatch Events rule to ensure it has permissions to publish to the SNS topic.
AnswerD

CloudWatch Events rules that target an SNS topic must assume an IAM role that grants sns:Publish on that topic's ARN. Without that permission, the rule fails at execution time with an AccessDenied error, even though the event pattern matched and the rule appears to have fired. The correct fix is to verify the role's trust policy allows events.amazonaws.com to assume it and that the attached policy includes the exact sns:Publish action for the target topic.

Why this answer

CloudWatch Events rules require an IAM role with permissions to invoke the target (e.g., publish to SNS). Even if the event pattern matches and the SNS topic exists, without a properly configured IAM role that grants `sns:Publish` to the CloudWatch Events service, the rule cannot deliver the notification. This is a common misconfiguration that causes silent failures.

Exam trap

The trap here is that candidates assume the event pattern matching is the only requirement for delivery, overlooking the IAM permissions needed for the CloudWatch Events rule to invoke the SNS target.

How to eliminate wrong answers

Option A is wrong because the issue is about receiving a notification for the 'StopLogging' event, not about whether the trail logs management events; CloudTrail must log management events for the event to appear, but the team already captured the event pattern correctly, so this is not the immediate cause of the missing notification. Option B is wrong because the question states the CloudWatch Events rule is configured with the correct event pattern, so the source and detail-type are already correct; checking them again would not resolve the delivery failure. Option C is wrong because the SNS topic subscription confirmation is only relevant for email or HTTP endpoints; if the SNS topic is used as a CloudWatch Events target, the subscription is automatically confirmed by the service, so this is not the likely cause.

619
MCQhard

A company is using AWS CloudTrail to monitor API activity. The security team wants to be alerted when an IAM user creates a new access key. Which CloudTrail event should be used to create a CloudWatch Events rule?

A.EnableMFADevice
B.UpdateAccessKey
C.UploadSigningCertificate
D.CreateAccessKey
AnswerD

The CreateAccessKey event is logged by CloudTrail when an IAM user or role calls the CreateAccessKey API to generate a new access key pair. This is precisely the event that indicates creation of a new access key, making it the correct answer. Note that while CloudTrail records the access key ID in the event, the secret access key is not logged; it is displayed only once at creation time. This event is also useful for detecting unauthorized credential creation.

Why this answer

The correct event is CreateAccessKey because this is the specific CloudTrail event that is logged when an IAM user creates a new access key. CloudTrail captures this API call as a management event, and a CloudWatch Events rule can be configured to match this event name to trigger an alert. The security team's requirement is to detect the creation of access keys, which is directly represented by the CreateAccessKey event.

Exam trap

The trap here is that candidates may confuse UpdateAccessKey with CreateAccessKey, thinking that updating a key includes creation, but UpdateAccessKey only modifies the key's status (e.g., Active/Inactive) and does not generate a new key pair.

How to eliminate wrong answers

Option A is wrong because EnableMFADevice is the event for enabling a multi-factor authentication device on an IAM user, not for creating an access key. Option B is wrong because UpdateAccessKey is the event for changing the status of an access key (e.g., Active to Inactive), not for creating a new one. Option C is wrong because UploadSigningCertificate is the event for uploading an X.509 signing certificate, which is unrelated to access key creation.

620
MCQmedium

A company uses AWS KMS to encrypt data at rest in Amazon S3. The security team requires that all encryption keys be automatically rotated every year. Which solution meets this requirement?

A.Use an AWS managed key and enable automatic rotation.
B.Use a customer managed key with imported key material and enable automatic rotation.
C.Use a customer managed key and enable automatic rotation with a yearly rotation period.
D.Use an AWS managed key and manually rotate it every year.
AnswerC

A customer managed key provides the administrative control needed to satisfy the requirement, and KMS supports automatic rotation with a configurable period between 90 and 2560 days for symmetric keys generated in KMS. By creating a customer managed key with KMS-generated key material and setting its automatic rotation period to 365 days, the company achieves seamless annual rotation while decrypting data with previous key versions as needed.

Why this answer

Customer managed keys (CMKs) in AWS KMS support automatic rotation with a customizable rotation period, which can be set to 365 days (one year) to meet the security team's requirement. AWS managed keys, on the other hand, have a fixed automatic rotation period of every three years (1095 days) and cannot be adjusted, making them unsuitable for a yearly rotation mandate. By using a CMK with automatic rotation enabled and specifying a rotation period of one year, the company ensures that the encryption key material is rotated annually without manual intervention.

Exam trap

The trap here is that candidates often assume AWS managed keys can be configured for automatic rotation with a custom period, but in reality, AWS managed keys have a fixed three-year rotation schedule and cannot be adjusted, making customer managed keys the only option for yearly rotation.

How to eliminate wrong answers

Option A is wrong because AWS managed keys have a fixed automatic rotation period of approximately three years (1095 days) and do not allow customization to a yearly rotation period. Option B is wrong because customer managed keys with imported key material do not support automatic rotation; AWS KMS cannot rotate key material that was imported from an external source, so the security team would need to manually rotate the key. Option D is wrong because AWS managed keys cannot be manually rotated; they are managed entirely by AWS and do not provide a manual rotation capability, and even if manual rotation were possible, it would not meet the 'automatically rotated' requirement.

621
Multi-Selectmedium

Which TWO actions should a security engineer take to ensure that Amazon GuardDuty can effectively monitor for suspicious activity in a VPC? (Choose two.)

Select 2 answers
A.Enable DNS query logging and publish to CloudWatch Logs.
B.Enable VPC Flow Logs and publish to CloudWatch Logs.
C.Enable CloudTrail data events for S3.
D.Enable S3 server access logs.
E.Enable AWS Config configuration history.
AnswersA, B

GuardDuty uses DNS logs for domain-based threat detection.

Why this answer

Amazon GuardDuty relies on DNS query logs to detect suspicious domain name resolution patterns, such as DNS tunneling or communication with known malicious domains. By enabling DNS query logging and publishing to CloudWatch Logs, GuardDuty can ingest this data as a source for its threat detection algorithms. Without DNS logs, GuardDuty cannot analyze DNS-based attack vectors within the VPC.

Exam trap

The trap here is that candidates often think enabling CloudTrail or S3 logs is sufficient for VPC monitoring, but GuardDuty specifically requires VPC Flow Logs and DNS query logs as its primary network-based data sources for detecting suspicious VPC activity.

622
MCQeasy

A company stores sensitive data in an Amazon S3 bucket. The security team requires that all data in transit between the company's on-premises data center and S3 be encrypted. Which solution meets this requirement?

A.Set up an IPsec VPN connection between the data center and AWS, and access S3 through the VPN.
B.Enable S3 Transfer Acceleration on the bucket.
C.Use HTTPS (TLS) endpoints when uploading objects to S3.
D.Use AWS PrivateLink to create a VPC endpoint for S3.
AnswerC

Using HTTPS (TLS) endpoints for S3 requests encrypts the entire request payload, the headers, and the response in transit between the client and S3. TLS provides confidentiality, integrity, and authentication, preventing eavesdropping and tampering. This is the correct approach because it ensures each object upload is protected end-to-end at the application layer, regardless of network path.

Why this answer

Using HTTPS (TLS) ensures encryption of data in transit between the client and S3. Option A is incorrect because although an IPsec VPN encrypts traffic between the data center and AWS, the data is then decrypted and sent to S3, so it does not guarantee encryption for the entire path unless S3 is accessed via HTTPS as well. Option B is incorrect because S3 Transfer Acceleration speeds up transfers using edge locations but does not provide encryption; HTTPS is still required.

Option D is incorrect because a VPC endpoint for S3 provides private connectivity but does not encrypt traffic; encryption still relies on HTTPS.

623
Multi-Selecthard

A security engineer is designing a secure VPC architecture for a web application that must be accessible from the internet. The application runs on EC2 instances in private subnets. Which THREE components are required to provide secure internet connectivity?

Select 3 answers
A.Public subnets with routes to the IGW
B.NAT Gateway in a public subnet
C.Virtual Private Gateway (VGW)
D.Transit Gateway
E.Internet Gateway (IGW) attached to the VPC
AnswersA, B, E

A public subnet is defined by having a route table entry with a destination of 0.0.0.0/0 pointing to an Internet Gateway (IGW). This default route enables resources with public IPs to directly send and receive traffic from the internet. While the IGW is the actual gateway, the route in the public subnet is the configuration that makes the subnet public. Therefore, public subnets with routes to the IGW are a critical part of the architecture for internet-facing components.

Why this answer

A is correct because public subnets require routes to the Internet Gateway (IGW) in their route tables to allow traffic from the internet to reach resources in those subnets. For the web application's EC2 instances in private subnets to initiate outbound internet connectivity (e.g., for software updates), a NAT Gateway must be placed in a public subnet with a route to the IGW, and the private subnet's route table must point 0.0.0.0/0 traffic to the NAT Gateway. The IGW attached to the VPC is the foundational component that enables bidirectional internet traffic for the VPC, but it must be explicitly associated with route tables of public subnets.

Exam trap

The trap here is that candidates often confuse the Virtual Private Gateway (VGW) or Transit Gateway as alternatives for internet connectivity, but neither provides NAT or direct internet access; they are designed for hybrid networking and inter-VPC routing, respectively.

624
MCQhard

A company uses AWS Organizations with SCPs. The security team wants to ensure that no IAM user can be created without MFA. Which SCP should be applied at the root OU?

A.Deny iam:CreateUser unconditionally
B.Use an IAM policy to require MFA for API calls
C.Deny iam:CreateUser unless the request includes a condition for MFA
D.Attach an IAM policy to all users requiring MFA
AnswerC

This SCP denies iam:CreateUser when the aws:MultiFactorAuthPresent condition key evaluates to false, effectively allowing the action only for callers who authenticated with MFA. Because SCPs apply to all principals in an AWS organization, this check is enforced regardless of the permissions granted by an individual IAM policy. The Deny statement with a Bool condition is the precise, organizational-level mechanism that prevents creation of users without an MFA requirement.

Why this answer

It uses a Service Control Policy (SCP) to deny the `iam:CreateUser` action unless the request includes a condition that MFA is present. SCPs are account-level permission boundaries in AWS Organizations, and this approach ensures that no IAM user can be created without MFA across all accounts in the organization, as SCPs are evaluated before any IAM policies.

Exam trap

The trap here is that candidates confuse SCPs with IAM policies, thinking an IAM policy can enforce MFA at the root OU level, but SCPs are the only mechanism that can apply organization-wide restrictions on actions like `iam:CreateUser`.

How to eliminate wrong answers

Option A is wrong because unconditionally denying `iam:CreateUser` would prevent all user creation, including those with MFA, which does not meet the requirement of allowing MFA-enabled users. Option B is wrong because an IAM policy requiring MFA for API calls only controls access to existing users and does not prevent the creation of users without MFA; it also cannot be applied at the root OU level as SCPs are needed. Option D is wrong because attaching an IAM policy to all users requiring MFA is an account-level action that does not prevent the creation of new users without MFA, and it cannot be enforced across all accounts via the root OU.

625
MCQeasy

A company wants to detect and alert on unauthorized API calls in their AWS account. Which AWS service can provide real-time notifications when specific API calls are made?

A.AWS Config
B.Amazon CloudWatch Events (EventBridge)
C.Amazon GuardDuty
D.AWS Trusted Advisor
AnswerB

Amazon EventBridge (formerly CloudTrail Events integration within CloudWatch Events) is the appropriate real-time service because it can consume CloudTrail API-call events and pattern-match on fields like eventName, userIdentity, errorCode, and sourceIPAddress. You can create a rule with a custom event pattern—for example, source: 'aws.cloudtrail' and eventName: 'DeleteBucket'—and route matching events to SNS, Lambda, or CloudWatch Logs to trigger alerts. This gives near-instant, event-driven detection of unauthorized API attempts, including filtered access-denied events.

Why this answer

Amazon CloudWatch Events (now part of Amazon EventBridge) can capture real-time API calls made to AWS services by using a rule that matches specific API calls via CloudTrail integration. When a matching API call occurs, EventBridge can trigger a target such as an SNS topic or Lambda function to send a notification, enabling immediate alerting on unauthorized API calls.

Exam trap

The trap here is that candidates often confuse AWS Config's configuration change detection with real-time API call monitoring, but Config evaluates resource state changes at intervals or on configuration changes, not the API calls themselves, whereas EventBridge provides immediate, event-driven notification of specific API actions.

How to eliminate wrong answers

Option A is wrong because AWS Config is a service for evaluating resource configurations against desired policies and tracking configuration changes over time, not for real-time notification of specific API calls. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail management events for malicious activity, but it does not provide direct, customizable real-time notifications for arbitrary API calls; it focuses on anomaly detection rather than event-driven alerting on specific API actions. Option D is wrong because AWS Trusted Advisor provides best-practice recommendations for cost optimization, performance, security, and fault tolerance, but it does not monitor or alert on real-time API calls.

626
Multi-Selecthard

A security team is implementing automated response to AWS GuardDuty findings. Which THREE actions should be taken to ensure proper incident response?

Select 3 answers
A.Create an AWS Lambda function that automatically modifies the security group of the affected instance to block all traffic.
B.Tag the affected instance with a 'quarantine' tag for tracking.
C.Create a snapshot of the EBS volumes attached to the instance for forensic analysis.
D.Terminate the affected instance immediately to neutralize the threat.
E.Disable AWS CloudTrail to prevent further logging of malicious activity.
AnswersA, B, C

Automating a Lambda-based containment action via EventBridge when a GuardDuty finding is detected is the correct initial response because it lets you immediately revoke all inbound and outbound security group rules on the affected instance. This stops lateral movement and malicious traffic while leaving the instance running and its memory and disk state intact for later forensic collection. The Lambda function must have the appropriate IAM policy to describe and modify security groups, and it can also log the rule changes to CloudTrail for audit.

Why this answer

Isolating the affected instance by modifying its security group to block all traffic is a common containment strategy that stops malicious network activity without destroying evidence. This approach allows the security team to perform forensic analysis and remediation while preventing further compromise, aligning with AWS incident response best practices.

Exam trap

The trap here is that candidates may think immediate termination (Option D) is the fastest way to neutralize a threat, but AWS incident response frameworks emphasize containment and evidence preservation over destruction.

627
Multi-Selectmedium

Which TWO are best practices for managing IAM roles for EC2 instances?

Select 2 answers
A.Regularly rotate IAM user access keys.
B.Attach the same role to all instances for simplicity.
C.Apply the principle of least privilege when defining role permissions.
D.Use an IAM role to grant permissions to applications running on EC2.
E.Store AWS access keys directly on the instance.
AnswersC, D

Enforcing least privilege means granting only the specific API actions and resources required for the application's function, and then further constraining them with conditions such as ec2:ResourceTag or aws:SourceIp. This limits the blast radius if the instance is compromised because a breached application can only perform the minimal set of operations. A role's policy is the sole authority for what temporary credentials obtained through the instance profile can do, so its precision directly determines the security posture.

Why this answer

The principle of least privilege ensures that an IAM role attached to an EC2 instance grants only the minimum permissions required for the application to function. This reduces the attack surface and limits potential damage from compromised instances. AWS Identity and Access Management (IAM) roles for EC2 use temporary security credentials obtained via the instance metadata service (IMDS), eliminating the need for long-term access keys.

Exam trap

The trap here is that candidates may confuse IAM user access key rotation (Option A) with role credential management, or think that storing keys directly on the instance (Option E) is acceptable if the instance is in a private subnet, but AWS explicitly recommends using IAM roles for EC2 to avoid hardcoded credentials.

628
MCQhard

A security engineer is reviewing AWS CloudTrail logs and notices a large number of `DescribeInstances` API calls from a single IAM user in a short period. The engineer suspects a credential compromise. What is the most effective way to automatically revoke the compromised credentials and notify the security team?

A.Use AWS CloudTrail to automatically disable the IAM user's access keys.
B.Create an Amazon EventBridge rule that triggers an AWS Lambda function to revoke the keys and send an SNS notification.
C.Create an AWS Config rule that checks for excessive API calls and revokes keys.
D.Enable Amazon GuardDuty to automatically revoke compromised credentials.
AnswerB

Amazon EventBridge can match CloudTrail API events in near real-time using event patterns and then invoke an AWS Lambda function as a target. The Lambda function can call iam:UpdateAccessKey with Status=Inactive to revoke the compromised key(s), and it can also publish a message to an SNS topic to alert security personnel. This serverless pattern is a recommended, native AWS approach for automated incident response to suspicious IAM activity, making it the correct choice here.

Why this answer

It uses Amazon EventBridge to detect the anomalous DescribeInstances API calls (via CloudTrail as an event source), then triggers an AWS Lambda function to programmatically revoke the IAM user's access keys (using the `deactivate_access_key` or `delete_access_key` API), and sends an SNS notification to the security team. This provides an automated, near-real-time response to a suspected credential compromise without manual intervention.

Exam trap

The trap here is that candidates may think CloudTrail or GuardDuty can directly take remediation actions, but they are detection-only services that require integration with compute services like Lambda for automated response.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail is a logging service and does not have the capability to automatically disable IAM access keys; it only records API activity. Option C is wrong because AWS Config rules are designed for compliance and resource configuration auditing, not for real-time threat detection or automated revocation of credentials based on API call frequency. Option D is wrong because Amazon GuardDuty can detect suspicious activity (e.g., unusual API calls) but does not automatically revoke credentials; it generates findings that require a separate response mechanism (e.g., EventBridge + Lambda) to take action.

629
MCQmedium

A company uses AWS CloudTrail to log all API calls. The security team wants to ensure that any attempt to disable CloudTrail logging is detected and alerted within minutes. Which solution should they implement?

A.Create a CloudWatch metric filter on CloudTrail logs for StopLogging or DeleteTrail events and set an alarm.
B.Use Amazon GuardDuty to monitor for disablement events.
C.Create an AWS Config rule to detect when CloudTrail is disabled.
D.Configure S3 event notifications on the CloudTrail bucket.
AnswerA

A CloudWatch metric filter can inspect CloudTrail events as they are streamed to a CloudWatch Logs log group and match the eventName field for StopLogging or DeleteTrail API calls. When the filter's metric value changes, a CloudWatch alarm triggers immediately, enabling a real-time response before the trail is completely stopped or deleted. This approach directly monitors the management events that disable auditing, without relying on secondary indicators like object delivery. It also supports optional SNS notifications and Lambda actions for automated remediation.

Why this answer

CloudTrail logs API calls like `StopLogging` and `DeleteTrail` to CloudWatch Logs. By creating a metric filter on these specific event names and setting a CloudWatch alarm, the security team can receive near-real-time alerts within minutes of any attempt to disable CloudTrail logging, meeting the detection requirement.

Exam trap

The trap here is that candidates often confuse AWS Config's periodic evaluation with real-time CloudWatch alarm capabilities, or mistakenly think GuardDuty's threat detection includes specific API-level alerts for CloudTrail disablement, when in fact GuardDuty does not generate findings for these specific management events by default.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes DNS, VPC flow logs, and CloudTrail management events for malicious activity, but it does not provide a native, configurable alarm for specific CloudTrail disablement events like StopLogging or DeleteTrail; it focuses on broader threats rather than this specific compliance alert. Option C is wrong because AWS Config rules are designed for continuous compliance evaluation of resource configurations (e.g., whether CloudTrail is enabled) and typically run on a periodic basis (e.g., every hour or on configuration changes), not for real-time alerting within minutes of an API call. Option D is wrong because S3 event notifications on the CloudTrail bucket can trigger on object creation (e.g., new log files), but they cannot directly detect the CloudTrail API calls that disable logging; they only react to log file delivery, not the disabling action itself.

630
MCQhard

A security engineer is investigating a potential security incident. They suspect that an IAM user's credentials were compromised and used to launch EC2 instances in a region where the user normally does not operate. Which AWS service can help the engineer identify the source IP address and user agent of the API calls that launched the instances?

A.AWS CloudHSM
B.AWS CloudTrail
C.Amazon Inspector
D.AWS Artifact
AnswerB

CloudTrail is the correct answer because it records API activity across AWS accounts, capturing details like source IP address, user agent, request parameters, and response elements. This enables security engineers to investigate potential security incidents by correlating who made the call, from what IP, and with what tool. CloudTrail events provide the forensic evidence needed to trace actions.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to the AWS environment, including the source IP address, user agent, and the identity of the caller. By examining CloudTrail logs for the `RunInstances` event, the engineer can identify the exact source IP address and user agent used to launch the EC2 instances, even if the region is unusual for the user.

Exam trap

The trap here is that candidates may confuse CloudTrail with CloudWatch or other monitoring services, but CloudTrail is the only service that records the source IP and user agent of API calls, while CloudWatch focuses on metrics and logs from resources, not API call metadata.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM is a hardware security module service for managing encryption keys, not a logging or monitoring service; it cannot capture API call metadata like source IP or user agent. Option C is wrong because Amazon Inspector is a vulnerability assessment service that scans EC2 instances and workloads for software vulnerabilities and unintended network exposure, but it does not record API call history or source IP addresses. Option D is wrong because AWS Artifact is a self-service portal for downloading AWS compliance reports and agreements, such as SOC and PCI reports; it provides no operational logging or API call tracking capabilities.

631
MCQeasy

A security engineer needs to ensure that all traffic to an EC2 instance in a VPC is inspected by a network firewall appliance. The firewall is deployed in a separate subnet. What is the MOST secure and scalable way to route traffic through the firewall?

A.Configure a NAT gateway in the firewall subnet and route all traffic through it.
B.Use a Gateway Load Balancer with a Gateway Load Balancer endpoint in each subnet.
C.Use an Application Load Balancer in front of the firewall.
D.Create a transit gateway and route traffic through the firewall subnet.
AnswerB

Gateway Load Balancer sits inline at Layers 3 and 4 by encapsulating traffic in GENEVE tunnels, forwarding packets to a fleet of firewall appliances while preserving flow symmetry. A Gateway Load Balancer endpoint is created in each subnet and becomes the next-hop target in VPC route tables, so all traffic entering or leaving those subnets is transparently steered through the firewall fleet. This design also provides health checks and autoscaling for the security appliances.

Why this answer

A Gateway Load Balancer (GWLB) with a Gateway Load Balancer endpoint in each subnet provides transparent, scalable, and highly available traffic inspection. GWLB operates at Layer 3 (IP packets) and uses GENEVE encapsulation to forward traffic to the firewall appliance without modifying the source/destination IP addresses, ensuring all traffic to the EC2 instance is inspected. This architecture scales horizontally by adding more firewall instances behind the GWLB and avoids single points of failure.

Exam trap

The trap here is that candidates often confuse Gateway Load Balancer with a traditional load balancer (ALB/NLB) or assume a NAT gateway can inspect inbound traffic, but GWLB is the only AWS service designed specifically for transparent, scalable, and highly available traffic inspection at the network layer.

How to eliminate wrong answers

Option A is wrong because a NAT gateway is designed for outbound internet traffic from private subnets, not for bidirectional traffic inspection; it cannot route inbound traffic to an EC2 instance through a firewall appliance. Option C is wrong because an Application Load Balancer operates at Layer 7 (HTTP/HTTPS) and cannot inspect non-HTTP traffic or forward raw IP packets, making it unsuitable for network-layer firewall inspection. Option D is wrong because a transit gateway provides connectivity between VPCs and on-premises networks but does not inherently support transparent traffic inspection; routing traffic through a firewall subnet via a transit gateway requires complex manual route table configurations and lacks the built-in health checks and auto-scaling of a GWLB.

632
Multi-Selectmedium

Which TWO of the following are valid methods to centrally manage security policies and enforce compliance across multiple AWS accounts? (Choose two.)

Select 2 answers
A.Deploy AWS Config conformance packs using AWS CloudFormation StackSets across accounts.
B.Attach IAM policies to all IAM users in each account.
C.Use AWS Security Hub to automatically enforce compliance rules.
D.Use AWS Organizations service control policies (SCPs) to restrict allowed actions.
E.Enable VPC Flow Logs in each account and send them to a central S3 bucket.
AnswersA, D

AWS Config conformance packs are collections of AWS Config rules and remediation actions that can be deployed across multiple accounts and Regions using CloudFormation StackSets. This provides a centralized, repeatable way to enforce and monitor compliance baselines without needing to log into each account individually. The StackSet orchestrates the deployment, while the conformance pack defines the rules that evaluate resource compliance.

Why this answer

AWS Config conformance packs provide a way to deploy a collection of AWS Config rules and remediation actions across multiple accounts and Regions. When combined with AWS CloudFormation StackSets, you can centrally deploy these conformance packs to all accounts in an AWS Organization, ensuring consistent compliance enforcement. This approach allows you to define and manage security policies as code, automatically evaluating resources against desired configurations.

Exam trap

The trap here is that candidates often confuse AWS Security Hub's detection and aggregation capabilities with actual enforcement, but Security Hub does not automatically enforce compliance—it only reports findings, while conformance packs and SCPs provide the enforcement mechanism.

633
MCQhard

A company uses AWS Lambda functions that access an Amazon RDS for MySQL database. The Lambda functions are configured with environment variables containing the database credentials. A security audit reveals that the credentials are stored in plaintext in the Lambda configuration. The security team wants to remediate this by using AWS Secrets Manager to store and automatically rotate the credentials. The Lambda functions are invoked frequently, and the team wants to minimize the impact of rotation on running functions. Which solution meets these requirements with the LEAST operational overhead?

A.Use AWS KMS to encrypt the environment variables in the Lambda configuration. Enable automatic rotation of the KMS key.
B.Store the credentials in Secrets Manager with automatic rotation enabled. Modify the Lambda functions to retrieve the secret at runtime using the Secrets Manager API and cache the secret using the AWS SDK.
C.Store the credentials in Secrets Manager and pass the secret ARN as an environment variable. Configure the Lambda function to retrieve the secret on each invocation without caching.
D.Store the credentials in AWS Systems Manager Parameter Store as a SecureString parameter with automatic rotation. Modify the Lambda function to read the parameter at runtime.
AnswerB

This approach centralizes secret storage, enables automatic rotation, and uses caching to reduce API calls and latency. The Lambda function retrieves the secret at runtime; caching ensures that frequent invocations do not overwhelm Secrets Manager and that rotated credentials are picked up after cache expiry. This minimizes operational overhead and improves security.

Why this answer

AWS Secrets Manager is designed to store and rotate database credentials automatically. By modifying the Lambda function to retrieve the secret at runtime and caching it, you reduce the number of API calls while ensuring that rotated credentials are eventually used. This approach provides security with minimal operational overhead because Secrets Manager handles rotation without custom code.

Exam trap

The trap here is assuming that encrypting environment variables with KMS is sufficient, but it does not remove the plaintext credentials from the Lambda configuration nor does it rotate them.

634
MCQeasy

A security engineer wants to receive real-time notifications when an AWS API call is made to delete an S3 bucket. Which service should be used to capture and forward these events to an Amazon SNS topic?

A.AWS CloudTrail with CloudWatch Events
B.AWS Trusted Advisor
C.Amazon GuardDuty
D.AWS Config
AnswerA

AWS CloudTrail with CloudWatch Events is the correct choice because CloudTrail records all AWS API calls as events, and CloudWatch Events (now Amazon EventBridge) can evaluate those events in near real time using an event pattern that matches specific actions like S3 DeleteBucket. When the pattern matches, it immediately triggers an SNS topic to send notifications. This architecture gives you direct, low-latency alerting on API activity, which is exactly what the security engineer needs. Unlike the other options, it is purpose-built for reacting to individual API calls as they happen.

Why this answer

AWS CloudTrail captures all API calls made to S3, including DeleteBucket. By sending these CloudTrail events to Amazon CloudWatch Events (now part of Amazon EventBridge), you can create a rule that matches the specific API call and forwards it to an SNS topic for real-time notification. This combination provides the exact event-driven pipeline needed for immediate alerting on S3 bucket deletions.

Exam trap

The trap here is that candidates often confuse AWS Config's ability to detect configuration changes with the need for real-time API call capture, leading them to choose AWS Config instead of CloudTrail with CloudWatch Events.

How to eliminate wrong answers

Option B is wrong because AWS Trusted Advisor provides best-practice recommendations and cost optimization checks, but it does not capture or forward real-time API events. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events for malicious activity, but it does not directly forward specific API calls to SNS topics. Option D is wrong because AWS Config evaluates resource configurations and compliance rules, but it does not capture real-time API calls or forward them to SNS; it focuses on configuration changes and drift detection.

635
MCQhard

A security engineer notices that a developer's IAM user has full administrator access. The engineer wants to implement the principle of least privilege for the developer. What is the best way to proceed?

A.Create a new IAM group with the AdministratorAccess policy and add the developer to the group.
B.Use IAM Access Advisor to review the developer's historical usage and create a custom policy that only includes the services and actions used.
C.Replace the AdministratorAccess policy with a managed job function policy such as PowerUserAccess.
D.Remove the administrative access and ask the developer to request permissions as needed.
AnswerB

IAM Access Advisor reports the last-accessed timestamp for each service the developer actually used. Building a custom policy from that historical usage removes unused permissions, achieving least privilege without breaking required workflows, unlike blanket administrator access.

Why this answer

The best way to implement least privilege is to use IAM Access Advisor to review the developer's historical usage and then create a custom policy that only includes the services and actions actually used. This approach is data-driven and ensures that the developer retains necessary permissions while removing unnecessary ones. It aligns with the principle of least privilege by tailoring permissions to actual needs.

Exam trap

SCS-C02 often tests the misconception that using a managed policy like PowerUserAccess is sufficient for least privilege, but it is still too broad; the correct approach is to create a custom policy based on actual usage.

How to eliminate wrong answers

Option A is wrong because creating a new group with AdministratorAccess and adding the developer would still grant full admin access, violating least privilege. Option C is wrong because replacing with PowerUserAccess is still broad and may include more permissions than needed; it is not tailored to the developer's actual usage. Option D is wrong because removing all administrative access and requiring the developer to request permissions as needed is disruptive and does not proactively define a least-privilege policy; it could lead to delays and is not the best practice for implementing least privilege.

636
MCQhard

A company runs a web application on Amazon EC2 behind an Application Load Balancer (ALB). The security team wants to allow only traffic from the ALB to reach the EC2 instances. Which security group configuration should be used?

A.Allow inbound traffic from the ALB's private IP addresses on the EC2 security group.
B.Allow inbound traffic from the VPC CIDR block on the EC2 security group.
C.Allow inbound traffic from the ALB's security group ID on the EC2 security group.
D.Allow inbound HTTP traffic from 0.0.0.0/0 on the EC2 security group.
AnswerC

Referencing the ALB's security group ID as the source makes the EC2 rule follow the load balancer automatically, so only traffic from that ALB is permitted. This is more precise than CIDR ranges, which would also admit any host in the ALB's subnets.

Why this answer

Security groups can reference other security groups by ID. By setting an inbound rule on the EC2 security group that references the ALB's security group ID, only traffic originating from the ALB is allowed. This is the recommended approach as ALB private IP addresses are dynamic and can change, making IP-based rules (Option A) unreliable.

Exam trap

The trap here is that candidates often assume ALBs have fixed private IP addresses and choose Option A, not realizing that ALB IPs are dynamic and that security group referencing is the AWS-recommended method for this pattern.

How to eliminate wrong answers

Option A is wrong because ALBs do not have static private IP addresses; they use elastic network interfaces that can change, making IP-based rules unreliable and requiring constant updates. Option B is wrong because allowing traffic from the entire VPC CIDR block would permit any resource in the VPC (including compromised instances or unauthorized services) to reach the EC2 instances, bypassing the ALB. Option D is wrong because allowing HTTP traffic from 0.0.0.0/0 would expose the EC2 instances directly to the internet, defeating the purpose of using an ALB for traffic control and security.

637
MCQmedium

A company uses a hybrid architecture with on-premises servers and AWS. The company uses AWS Site-to-Site VPN to connect to a VPC. The security team suspects that a VPN tunnel has been compromised and an attacker is intercepting traffic. The team needs to verify the integrity of the VPN connection. What is the MOST effective way to detect if traffic is being intercepted?

A.Monitor Amazon CloudWatch metrics for the VPN tunnel, such as tunnel state and data throughput.
B.Use AWS Config to check VPN configuration compliance.
C.Use a third-party network monitoring tool to perform deep packet inspection.
D.Enable VPC Flow Logs and analyze traffic patterns for unusual destinations.
AnswerA

Amazon CloudWatch publishes VPN tunnel metrics natively, including TunnelState (UP/DOWN) and DataTransferred. A sudden, unexplained tunnel flap, prolonged DOWN state, or throughput spike during an idle period can signal a renegotiation attack, a man-in-the-middle redirecting traffic to an unauthorized peer, or a compromised customer gateway. Because these metrics are captured from the AWS side of the IPsec tunnel and are continuously recorded, they can be compared against historical baselines to detect abnormal behavior that would indicate interception or tampering.

Why this answer

Monitoring Amazon CloudWatch metrics for the VPN tunnel, specifically the 'TunnelState' metric, directly indicates whether the tunnel is up or down. A compromised tunnel that is intercepting traffic would likely cause the tunnel to flap or drop unexpectedly, which CloudWatch can alert on. Additionally, abnormal data throughput patterns (e.g., sudden spikes or drops) can signal interception or rerouting of traffic, making this the most effective way to detect integrity issues without relying on traffic content.

Exam trap

The trap here is that candidates confuse configuration compliance (AWS Config) or traffic analysis (VPC Flow Logs) with active tunnel integrity verification, overlooking that CloudWatch metrics directly monitor the VPN tunnel's operational state and performance, which is the most reliable indicator of compromise without requiring decryption.

How to eliminate wrong answers

Option B is wrong because AWS Config checks configuration compliance (e.g., encryption settings, routing rules) but cannot detect active interception or compromise of a live VPN tunnel; it only validates static configuration. Option C is wrong because deep packet inspection (DPI) requires decrypting the VPN traffic, which is not possible without the VPN encryption keys; the attacker would also be encrypted, so DPI cannot distinguish legitimate from intercepted traffic. Option D is wrong because VPC Flow Logs capture metadata (IPs, ports, protocols) but not the content or integrity of the VPN tunnel; unusual destinations might indicate exfiltration but do not directly confirm tunnel interception, and flow logs cannot detect if traffic is being modified or replayed within the encrypted tunnel.

638
MCQeasy

A security engineer needs to detect when an IAM access key is created for a user and then used from an unusual location. The engineer wants to receive an alert when such activity occurs. Which AWS service should be used to meet this requirement?

A.Amazon Inspector
B.AWS Config
C.Amazon GuardDuty
D.AWS CloudTrail
AnswerC

GuardDuty continuously monitors CloudTrail management events, VPC Flow Logs, and DNS logs to detect threats. It can identify anomalous behavior such as an IAM access key being used from an unusual geographic location. GuardDuty generates findings that can trigger alerts via CloudWatch Events or SNS, meeting the requirement.

Why this answer

Amazon GuardDuty is a threat detection service that analyzes CloudTrail management events, VPC Flow Logs, and DNS logs to identify malicious or anomalous activity. It can detect unusual access key usage from unexpected locations and generate findings that can be routed to alerting systems. CloudTrail, AWS Config, and Amazon Inspector do not provide this threat detection and alerting capability.

Exam trap

The trap here is assuming that CloudTrail, which records the API calls, also performs the analysis and alerting; in fact, GuardDuty is the service that analyzes those logs and generates findings.

639
MCQeasy

A security engineer is configuring Amazon GuardDuty in a multi-account environment using AWS Organizations. What is the MOST efficient way to enable GuardDuty for all accounts?

A.Create a Lambda function that uses AWS Organizations API to enable GuardDuty in each account
B.Use AWS Service Catalog to provision GuardDuty across accounts
C.Manually enable GuardDuty in each member account
D.Enable GuardDuty in the management account and designate a delegated administrator to manage GuardDuty
AnswerD

GuardDuty is natively integrated with AWS Organizations, and the recommended practice is to enable it in the management account, then designate a delegated administrator account to centrally manage GuardDuty for all member accounts. The delegated administrator can configure detectors, manage findings, and send automated responses, while the management account retains full governance control. This approach automatically covers all existing and future accounts in the organization without requiring per-account manual steps, and it also enables centralized aggregation of findings.

Why this answer

AWS Organizations allows you to enable GuardDuty at the management account level and then designate a delegated administrator to manage GuardDuty across all member accounts. This approach is the most efficient as it eliminates the need for per-account manual or scripted enablement, leveraging the Organizations API to automatically enroll all existing and future accounts.

Exam trap

The trap here is that candidates may think a custom Lambda function or manual per-account setup is required, overlooking the built-in delegated administrator feature that streamlines multi-account GuardDuty management via AWS Organizations.

How to eliminate wrong answers

Option A is wrong because creating a Lambda function to call the Organizations API for each account is unnecessary and less efficient; the delegated administrator feature in GuardDuty already automates multi-account enablement without custom code. Option B is wrong because AWS Service Catalog is designed for provisioning and governing IT service catalogs, not for enabling security services like GuardDuty across accounts; it adds complexity without benefit. Option C is wrong because manually enabling GuardDuty in each member account is inefficient, error-prone, and does not scale, especially in environments with many accounts or frequent account creation.

640
MCQhard

A company is using AWS Organizations and wants to delegate the administration of certain accounts to different teams. For example, the finance team should be able to manage billing-related accounts, but not development accounts. Which AWS feature allows this type of delegation?

A.AWS Organizations delegated administrator
B.AWS IAM Identity Center (AWS SSO)
C.Service control policies (SCPs)
D.IAM roles in each account
AnswerA

AWS Organizations delegated administrator is a native feature that lets you designate a member account as the administrative owner for a specified AWS service across the entire organization. For example, a finance account can be registered to manage Cost Explorer and billing reports for all accounts, so finance staff can perform service-specific administrative tasks without needing the management account's root user. This provides centralized, org-wide service administration while preserving the principle of least privilege.

Why this answer

AWS Organizations delegated administrator allows a member account to be designated as the administrator for a specific AWS service (e.g., AWS Billing, AWS CloudFormation StackSets, AWS Config) across the organization. This enables the finance team's account to manage billing-related accounts without granting them full management over development accounts. It is the only feature that provides service-specific administrative delegation within Organizations.

Exam trap

SCS-C02 often tests the distinction between SCPs (permission guardrails) and delegated administrator (service-specific administrative delegation), causing candidates to pick SCPs when the question asks for delegation of administration.

How to eliminate wrong answers

Option B is wrong because IAM Identity Center (AWS SSO) is for centralized user access and permission management, not for delegating administrative control of specific accounts or services. Option C is wrong because SCPs are used to set permission guardrails across accounts, not to delegate administration to a specific team. Option D is wrong because IAM roles in each account provide cross-account access but do not implement the delegated administrator model that scopes service administration to a specific account.

641
MCQhard

A security engineer suspects that an EC2 instance is communicating with a known malicious IP address. The engineer needs to capture the full network packets for analysis. Which approach should be taken?

A.Enable AWS Security Hub to detect and capture malicious traffic.
B.Install the Amazon CloudWatch agent on the instance to capture network logs.
C.Enable VPC Flow Logs on the subnet and analyze the logs.
D.Use VPC Traffic Mirroring to mirror the instance's ENI to a monitoring appliance.
AnswerD

VPC Traffic Mirroring copies live traffic from a source ENI and sends it to a designated monitoring appliance or security tool, enabling full packet capture and deep packet inspection. Because it operates at the hypervisor level, it can see every packet, including payloads, without installing agents on the instance. This allows the security engineer to analyze the exact malicious traffic and is the correct method for capturing full network data from the EC2 instance.

Why this answer

VPC Traffic Mirroring captures and copies all network traffic from an EC2 instance's Elastic Network Interface (ENI) and forwards it to a monitoring appliance (e.g., a security appliance or packet analyzer) for full packet-level analysis. This is the only option that provides raw, full network packets (including headers and payloads) without impacting the instance's performance or requiring software installation on the instance itself.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (which provide metadata only) with full packet capture, leading them to choose Option C, but VPC Flow Logs cannot capture packet payloads required for deep forensic analysis.

How to eliminate wrong answers

Option A is wrong because AWS Security Hub is a security posture management service that aggregates findings from other services (e.g., GuardDuty, Inspector) and does not capture raw network packets. Option B is wrong because the Amazon CloudWatch agent collects metrics and logs (e.g., CPU, memory, application logs) but cannot capture full network packets at the OSI Layer 2/3 level; it lacks packet capture capabilities. Option C is wrong because VPC Flow Logs capture metadata (e.g., source/destination IP, port, protocol, packet count) but do not capture the actual packet payloads or full network packets required for deep analysis.

642
Multi-Selectmedium

A security engineer is designing a system to manage access to an S3 bucket containing confidential data. Which TWO actions should the engineer take to implement least privilege?

Select 2 answers
A.Use a condition in the IAM policy to restrict access to requests from a specific IP range.
B.Grant only the specific S3 actions needed (e.g., s3:GetObject) rather than s3:*
C.Use a policy that allows s3:* for all users in the organization.
D.Make the bucket public and rely on object ACLs to restrict access.
E.Use pre-signed URLs for all access to the bucket.
AnswersA, B

An IAM condition using aws:SourceIp restricts valid S3 requests to a specified CIDR range, ensuring credentials are only usable from your corporate or trusted network and shrinking the attack surface. This complements least-privilege actions by adding a network-layer control, but remember that if the request goes through a VPC endpoint, aws:SourceIp is not evaluated and you must use aws:sourceVpce instead. It is a valid, cost-free way to reduce exposure.

Why this answer

Option A is correct because adding an IAM policy condition such as aws:SourceIp to restrict requests to a specific IP range narrows the circumstances under which the allowed S3 actions can be performed, which is a core least-privilege technique. Option B is correct because granting only the specific actions required (for example s3:GetObject instead of s3:*) limits permissions to exactly what the workload needs, directly implementing least privilege. Option C is wrong because allowing s3:* for all users in the organization grants far broader permissions than necessary and violates least privilege.

Option D is wrong because making the bucket public exposes the confidential data and object ACLs alone are not a least-privilege access control mechanism. Option E is wrong because pre-signed URLs are a temporary delegation mechanism, not a substitute for scoping IAM permissions to the minimum required actions and conditions.

Exam trap

SCS-C02 often tests the misconception that using pre-signed URLs or object ACLs alone achieves least privilege, when in fact least privilege requires explicit, minimal IAM actions and conditions.

643
Multi-Selecthard

A security engineer is investigating a potential data breach. The engineer wants to analyze historical API calls made by a specific IAM user. Which TWO AWS services can be used together to achieve this? (Select TWO.)

Select 2 answers
A.S3 Server Access Logs
B.VPC Flow Logs
C.AWS CloudTrail
D.Amazon CloudWatch Logs Insights
E.Amazon CloudWatch Logs
AnswersC, E

AWS CloudTrail is the authoritative audit service because it logs every supported AWS API call (management events, and optionally data events) with the caller's IAM identity, source IP address, user agent, request parameters, and response elements. A CloudTrail event history can be delivered to an S3 bucket and subsequently ingested into CloudWatch Logs or Amazon Security Lake, making it the primary evidence source for reconstructing who did what during a breach. It is the correct service to use when investigating suspicious API activity.

Why this answer

AWS CloudTrail is the service that records API activity across AWS accounts, including who made the call, the source IP address, and the time of the call. By enabling CloudTrail for the specific IAM user, the security engineer can retrieve a history of all API calls made by that user. CloudWatch Logs can then be used to store and query those CloudTrail logs for analysis, such as filtering by user ARN or event name.

Exam trap

The trap here is that candidates often confuse CloudWatch Logs Insights (a query tool) with CloudWatch Logs (the storage service), or mistakenly think S3 Server Access Logs or VPC Flow Logs can capture IAM user API activity, when in fact only CloudTrail records management-plane API calls.

644
MCQmedium

A security engineer is designing a network ACL for a public subnet containing an Application Load Balancer. The subnet must allow inbound HTTPS traffic from the internet and outbound traffic to the internet for patches. Which inbound rule should be added?

A.Allow TCP port 1024-65535 from 0.0.0.0/0
B.Allow UDP port 443 from 0.0.0.0/0
C.Allow all traffic from 0.0.0.0/0
D.Allow TCP port 443 from 0.0.0.0/0
AnswerD

This is the correct and most restrictive inbound rule for a public HTTPS endpoint because HTTPS is implemented with TLS over TCP and defaults to destination port 443. Allowing TCP 443 from 0.0.0.0/0 enables any internet client to initiate a TCP connection and perform a TLS handshake with the web server. Because NACLs are stateless, you must also configure a separate outbound rule allowing the ephemeral port range (1024–65535) so the server's return traffic can reach that client. Restricting the inbound rule to TCP 443 avoids exposing other ports while still meeting the functional requirement.

Why this answer

HTTPS traffic uses TCP port 443, and the network ACL must explicitly allow inbound TCP traffic on port 443 from the internet (0.0.0.0/0) to reach the Application Load Balancer. Network ACLs are stateless, so each direction requires a separate rule; this inbound rule permits the initial HTTPS connection requests.

Exam trap

The trap here is that candidates may confuse stateless network ACLs with stateful security groups, leading them to think an ephemeral port rule (like option A) is needed for inbound traffic, when in fact the inbound rule must specify the destination port 443 for the initial connection.

How to eliminate wrong answers

Option A is wrong because it allows ephemeral ports (1024-65535) as the destination port, which is used for return traffic, not for inbound HTTPS requests; this rule would not permit the initial connection on port 443. Option B is wrong because HTTPS uses TCP, not UDP; a UDP port 443 rule would not match HTTPS traffic and would be ineffective. Option C is wrong because allowing all traffic is overly permissive and violates the principle of least privilege; it would permit unnecessary protocols and ports, increasing the attack surface.

645
MCQmedium

A security engineer is responsible for ensuring that all API calls made in an AWS account are logged and that the logs are immutable for at least one year. The engineer must also ensure that any attempt to delete or modify the logs triggers an alert. Which solution meets these requirements?

A.Enable AWS CloudTrail with log file validation, store logs in an S3 bucket with versioning and MFA delete enabled, and create an Amazon EventBridge rule to alert on DeleteObject or PutObject events for the bucket.
B.Enable AWS CloudTrail with log file validation, store logs in an S3 bucket with Object Lock in compliance mode for one year, and create an Amazon EventBridge rule to alert on DeleteObject or PutObject events for the bucket.
C.Enable AWS CloudTrail with log file validation, store logs in an S3 bucket with versioning and MFA delete enabled, and create an Amazon CloudWatch alarm on the CloudTrail metric for log file delivery failures.
D.Enable AWS CloudTrail with log file validation, store logs in an S3 bucket with Object Lock in compliance mode for one year, and create an Amazon CloudWatch alarm on the CloudTrail metric for log file delivery failures.
AnswerB

CloudTrail with log file validation ensures log integrity. S3 Object Lock in compliance mode prevents deletion or modification for the retention period, providing immutability for one year. An EventBridge rule that triggers on DeleteObject or PutObject events for the bucket will alert on any attempt to delete or modify the logs, meeting all requirements.

Why this answer

To achieve immutable logs for one year and alert on tampering, use CloudTrail with log file validation, S3 Object Lock in compliance mode to prevent deletion or modification, and EventBridge to detect and alert on DeleteObject or PutObject events for the bucket. This combination ensures logs cannot be altered and any attempt triggers an alert.

Exam trap

The trap here is assuming that S3 versioning with MFA delete provides immutability, when it only allows recovery and requires MFA for permanent deletion, not preventing modification attempts.

646
MCQeasy

A company uses AWS CloudTrail to log all API calls in their AWS account. They need to ensure that log files are not tampered with after they are delivered to the S3 bucket. Which feature should be enabled to provide integrity validation?

A.Enable S3 Versioning on the CloudTrail bucket.
B.Enable S3 server-side encryption with SSE-S3.
C.Enable CloudTrail log file integrity validation.
D.Enable S3 Object Lock on the CloudTrail bucket.
AnswerC

CloudTrail log file integrity validation is the correct choice because it provides cryptographic verification of the log files: every log file's SHA-256 hash is included in a separate, frequently issued digest file that is signed with a private key. This hash chain lets you detect whether a log file was modified, deleted, or replaced after CloudTrail delivered it, and you can verify digests using the public key that CloudTrail publishes. Because an attacker would need the private key to forge a valid digest, this feature directly satisfies the requirement to determine whether CloudTrail logs have been tampered with.

Why this answer

CloudTrail log file integrity validation uses a SHA-256 hash chain to detect if log files have been modified, deleted, or tampered with after delivery to S3. When enabled, CloudTrail delivers a digest file that contains hashes of the log files, allowing you to verify that no unauthorized changes have occurred. This is the only feature specifically designed for integrity validation of CloudTrail logs.

Exam trap

The trap here is that candidates often confuse data protection features like encryption or versioning with integrity validation, but only CloudTrail's built-in integrity validation provides cryptographic proof that log files have not been tampered with after delivery.

How to eliminate wrong answers

Option A is wrong because S3 Versioning preserves multiple versions of an object but does not validate the integrity or detect tampering of the log file content itself. Option B is wrong because S3 server-side encryption (SSE-S3) protects data at rest from unauthorized access but does not provide any mechanism to verify that the log files have not been altered after delivery. Option D is wrong because S3 Object Lock prevents objects from being deleted or overwritten for a fixed retention period, but it does not validate the integrity or detect modifications to the content of the log files.

647
Multi-Selecteasy

A company is designing an incident response plan for AWS. The plan must include the ability to collect forensic data from EC2 instances without requiring SSH key pairs. Which TWO AWS services can be used to acquire forensic data from EC2 instances without remote access? (Choose 2.)

Select 2 answers
A.AWS Systems Manager Run Command
B.AWS Config
C.Amazon Inspector
D.AWS CloudTrail
E.Amazon EBS snapshots
AnswersA, E

AWS Systems Manager Run Command lets authorized responders execute scripts or commands on EC2 instances through the SSM Agent, eliminating the need for SSH bastion hosts or key management during an incident. This supports live response actions such as collecting volatile data, stopping services, or isolating a compromised instance, all while recording the execution in CloudTrail and allowing IAM-based permission controls.

Why this answer

AWS Systems Manager Run Command allows you to run scripts or commands on EC2 instances via the SSM Agent, without requiring SSH keys or direct network access. This enables forensic data collection (e.g., memory dumps, log files) by executing commands remotely through the AWS Systems Manager service, using IAM roles for authentication.

Exam trap

The trap here is that candidates often confuse AWS Config or CloudTrail as tools for collecting instance-level forensic data, when in fact they are governance and logging services that do not provide direct access to instance memory or disk contents.

648
MCQhard

A company is using AWS KMS to encrypt data in Amazon Redshift. They need to rotate the KMS key annually. Which approach meets the requirement with minimal operational impact?

A.Create a new KMS key each year and update the Redshift cluster to use the new key
B.Use an AWS Lambda function to rotate the key every year
C.Enable automatic key rotation on the KMS key
D.Rotate the key by re-importing key material into an existing KMS key
AnswerC

Enable automatic rotation on the KMS key. AWS KMS automatically rotates the backing key material one year after the key is created and then every year thereafter, while keeping the same key ID and metadata, so Redshift continues to use the key without any reconfiguration. The old key material is retained to decrypt existing ciphertext, ensuring that all data encrypted under prior versions remains accessible. This meets the requirement of key rotation with minimal effort and no application changes.

Why this answer

AWS KMS supports automatic annual key rotation for customer-managed KMS keys. Enabling this feature automatically rotates the key material once per year with no manual intervention, minimal operational overhead, and no impact on the Redshift cluster, which continues to use the same key ID.

Exam trap

The trap here is that candidates may think automatic rotation is not available for KMS keys or that they must manually rotate keys using Lambda or by creating new keys, when in fact KMS provides a simple toggle for annual automatic rotation that requires no additional resources.

How to eliminate wrong answers

Option A is wrong because creating a new KMS key each year and updating the Redshift cluster requires manual re-encryption of all data and reconfiguration of the cluster, causing significant operational impact and potential downtime. Option B is wrong because AWS Lambda is unnecessary and adds complexity; KMS already provides built-in automatic rotation that does not require custom code or scheduling. Option D is wrong because re-importing key material into an existing KMS key is only applicable to imported key material (not AWS-generated keys) and does not meet the requirement for annual rotation of an AWS KMS key; it also requires manual steps and does not automate the rotation schedule.

649
Multi-Selectmedium

A company is considering using AWS Shield Advanced to protect against DDoS attacks. Which three features are included with AWS Shield Advanced? (Choose THREE.)

Select 3 answers
A.Cost protection against DDoS-related scaling charges
B.Dedicated IP addresses for EC2 instances
C.AWS Site-to-Site VPN
D.Integration with AWS WAF for web ACLs
E.24/7 access to the AWS DDoS Response Team (DRT)
AnswersA, D, E

AWS Shield Advanced provides cost protection to help offset charges incurred when protected resources automatically scale in response to a DDoS attack. For example, if a DDoS attack causes an Application Load Balancer to scale out or CloudFront to serve more requests, AWS can issue billing credits for those additional resource usage charges, as long as the resources are protected by Shield Advanced and the attack is detected. This ensures customers are not financially penalized for the very elasticity that keeps their applications resilient during an attack.

Why this answer

AWS Shield Advanced provides cost protection against DDoS-related scaling charges, meaning if your EC2 or ELB instances scale up due to a DDoS attack, AWS will provide credits for the additional resources incurred. This is a key financial safeguard included in the Shield Advanced subscription.

Exam trap

The trap here is that candidates may confuse AWS Shield Advanced with AWS Shield Standard, or assume features like dedicated IPs or VPN are part of the DDoS protection package, when in fact they are separate services with different purposes.

650
MCQeasy

A company wants to encrypt data at rest in an Amazon S3 bucket. Which AWS service can centrally manage the encryption keys?

A.AWS CloudHSM
B.AWS Certificate Manager (ACM)
C.AWS Key Management Service (AWS KMS)
D.AWS Secrets Manager
AnswerC

AWS Key Management Service (AWS KMS) is a fully managed service that centralizes the creation, storage, rotation, and deletion of customer master keys (CMKs). S3 integrates with KMS through server-side encryption (SSE-KMS), where S3 uses a KMS key to encrypt each object's data key automatically and enforces IAM policies on key usage. This gives you centralized control, auditability through CloudTrail, and seamless S3 encryption, making KMS the correct and standard service for encrypting data at rest in S3.

Why this answer

AWS Key Management Service (AWS KMS) is the correct service because it is a fully managed, centralized service that allows you to create, manage, and control the encryption keys used to encrypt data at rest in Amazon S3. S3 integrates directly with KMS via Server-Side Encryption with AWS KMS (SSE-KMS), enabling you to use customer managed keys (CMKs) or AWS managed keys to enforce granular access control and audit key usage through AWS CloudTrail.

Exam trap

The trap here is that candidates often confuse AWS CloudHSM with KMS because both involve encryption keys, but CloudHSM is a hardware-based key storage service that lacks native integration with S3 for centralized key management, whereas KMS is the intended service for SSE-KMS.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides dedicated hardware security modules (HSMs) for generating and storing keys, but it does not centrally manage encryption keys for S3; it requires manual integration and does not offer native S3 encryption key management. Option B is wrong because AWS Certificate Manager (ACM) is designed to provision, manage, and deploy public and private SSL/TLS certificates for network encryption, not for managing encryption keys for data at rest in S3. Option D is wrong because AWS Secrets Manager is used to securely store and rotate secrets such as database credentials and API keys, not to centrally manage encryption keys for S3 server-side encryption.

651
MCQeasy

A security engineer is designing a system to centrally manage IAM users and roles across multiple AWS accounts. The company uses AWS Organizations. Which AWS service should be used to manage permissions across accounts?

A.AWS Config
B.AWS Artifact
C.AWS CloudTrail
D.AWS IAM Identity Center (AWS SSO)
AnswerD

AWS IAM Identity Center (formerly AWS SSO) is the service designed to centrally manage workforce identities and fine-grained access to multiple AWS accounts and business applications. It connects to your existing identity provider via SAML 2.0 or SCIM, and its permission sets define which IAM roles users or groups assume in each account. This unified access model is exactly what a central management solution requires, so this is the correct choice.

Why this answer

AWS IAM Identity Center (formerly AWS SSO) is the service for centrally managing user access to multiple accounts. Option A is wrong because AWS Config is for resource compliance. Option B is wrong because AWS Artifact is for compliance reports.

Option C is wrong because AWS CloudTrail is for auditing API activity.

652
MCQeasy

A security engineer is reviewing AWS CloudTrail and notices `AssumeRole` API calls to a role that should not be assumed by the source identity. What is the FIRST step in the incident response process?

A.Enable AWS GuardDuty to detect future anomalies.
B.Delete the IAM role immediately.
C.Investigate the source IP address and user agent of the `AssumeRole` calls.
D.Disable the AWS account and contact support.
AnswerC

Investigating the source IP address and user agent of the AssumeRole calls is the correct first step because those fields are directly logged in the CloudTrail management event and let the engineer determine whether the role was assumed from an expected corporate network and application versus an unknown external host. This information can be cross-referenced with VPC Flow Logs, AWS WAF logs, or threat intelligence to establish a baseline of legitimate usage and scope the incident. It preserves all evidence while enabling a quick threat verdict.

Why this answer

The first step in any incident response process is to investigate and gather evidence to understand the scope and impact of the potential security event. Option C is correct because analyzing the source IP address and user agent of the `AssumeRole` API calls provides critical forensic data to determine if the activity is malicious or a false positive, without disrupting operations or destroying evidence. AWS CloudTrail logs these details, enabling the security engineer to trace the origin of the unauthorized assumption before taking any containment or remediation actions.

Exam trap

The trap here is that candidates often jump to containment actions like deleting the role or disabling the account, forgetting that the first step in incident response is always to investigate and gather evidence to confirm the threat and preserve forensic data.

How to eliminate wrong answers

Option A is wrong because enabling AWS GuardDuty is a proactive detection measure, not an immediate first step during an active incident; it would not help investigate the existing suspicious `AssumeRole` calls already logged. Option B is wrong because immediately deleting the IAM role could destroy forensic evidence, disrupt legitimate workloads that depend on the role, and is a hasty containment action that should only follow a thorough investigation. Option D is wrong because disabling the entire AWS account is an extreme, disproportionate response that would cause a complete denial of service for all users and applications, and contacting support is not a technical first step for investigation.

653
Multi-Selectmedium

A security engineer is implementing a data classification policy for an S3 bucket that contains sensitive customer data. The policy requires that all objects be encrypted at rest using AWS KMS and that any attempt to upload an unencrypted object be denied. Which THREE steps should the engineer take to enforce this policy? (Choose THREE.)

Select 3 answers
A.Enable S3 bucket keys to reduce KMS API calls.
B.Create a customer managed KMS key.
C.Enable bucket policy to enforce SSL (aws:SecureTransport).
D.Add a bucket policy that denies PutObject if s3:x-amz-server-side-encryption is not aws:kms.
E.Enable S3 default encryption with the KMS key.
AnswersB, D, E

A customer managed KMS key provides the key material and granular key policy control required for SSE-KMS encryption of the sensitive objects. Without it, the bucket policy condition on aws:kms cannot be satisfied, since no suitable key exists to reference.

Why this answer

Option B is correct because the policy requires AWS KMS encryption, and a customer managed KMS key gives the engineer control over the key policy, rotation, and permissions needed to encrypt the sensitive objects. Option D is correct because a bucket policy with a Deny on s3:PutObject when the s3:x-amz-server-side-encryption condition is not aws:kms actively blocks any upload that does not request SSE-KMS, which is exactly the enforcement mechanism the policy demands. Option E is correct because enabling S3 default encryption with the KMS key ensures that objects are encrypted at rest with SSE-KMS even when a request does not explicitly specify encryption headers, satisfying the baseline encryption requirement.

Option A is not correct because S3 Bucket Keys only reduce KMS API call costs and request throttling; they do not enforce encryption or deny unencrypted uploads. Option C is not correct because enforcing aws:SecureTransport only requires TLS in transit and does nothing to guarantee encryption at rest with KMS or to reject unencrypted object uploads.

Exam trap

SCS-C02 often tests the difference between enabling default encryption (which is passive) and enforcing encryption via bucket policy (which is active). Candidates frequently select only default encryption and miss the need for an explicit deny policy to block unencrypted uploads.

654
Multi-Selecthard

A company wants to use AWS CloudTrail to monitor data events for all S3 buckets. Which THREE steps are necessary? (Choose THREE.)

Select 3 answers
A.Specify an S3 bucket to store the log files
B.Create a new CloudTrail trail
C.Create a CloudWatch Events rule to forward data events
D.Enable CloudTrail Insights to detect unusual data access
E.Enable data events for all S3 buckets in the trail configuration
AnswersA, B, E

CloudTrail delivers all log records, including the enabled S3 data events, to the S3 bucket you specify when creating the trail. This bucket is the required durable destination for log file storage, and without it, event history is limited to 90 days and cannot be exported or integrated with other analytics tools.

Why this answer

CloudTrail requires a destination S3 bucket to store the log files it generates. Without specifying a bucket, the trail cannot persist logs, and this bucket must have appropriate bucket policies to allow CloudTrail to write logs. This is a mandatory step when creating any trail, whether for management or data events.

Exam trap

The trap here is that candidates often confuse CloudTrail Insights (which analyzes management events for anomalies) with the ability to log data events, or mistakenly think a CloudWatch Events rule is needed to forward data events, when in fact data events are configured directly in the trail's event selector.

655
MCQhard

A company is using Amazon CloudWatch Logs to store application logs. The security team needs to retain logs for 7 years to comply with regulatory requirements. The logs are accessed infrequently after the first 90 days. What is the MOST cost-effective way to meet these retention and access requirements?

A.Export logs from CloudWatch Logs to an S3 bucket, then use S3 Lifecycle policies to transition logs to S3 Glacier Deep Archive after 90 days.
B.Stream logs to an S3 bucket using Kinesis, then use S3 Lifecycle policies to transition logs to S3 Standard-IA after 90 days.
C.Set a retention policy on the CloudWatch Logs log group to 7 years and use CloudWatch Logs Insights for queries.
D.Set a retention policy on the CloudWatch Logs log group to 7 years and use CloudWatch Logs lifecycle policies to transition to Amazon S3 Glacier.
AnswerA

Exporting log data from CloudWatch Logs to S3 via the CreateExportTask API is the native, recommended path for long-term archival. Once in S3, a lifecycle rule can transition objects from S3 Standard to S3 Glacier Deep Archive after 90 days, minimizing storage costs for data that is rarely, if ever, accessed while meeting the 7-year compliance requirement. This approach also lets you set a short retention on the original log group to avoid ongoing CloudWatch Logs storage fees after export completes.

Why this answer

Exporting logs from CloudWatch Logs to Amazon S3 and using S3 Lifecycle policies to transition them to S3 Glacier Deep Archive after 90 days is the most cost-effective solution. CloudWatch Logs storage costs are higher than S3, and Glacier Deep Archive offers the lowest storage cost for infrequently accessed data that must be retained for 7 years. This approach meets the retention requirement while minimizing costs for logs that are rarely accessed after the initial 90-day period.

Exam trap

The trap here is that candidates may incorrectly assume CloudWatch Logs can directly transition logs to Glacier via lifecycle policies, but CloudWatch Logs does not support lifecycle transitions to S3 storage classes; logs must first be exported to S3.

How to eliminate wrong answers

Option B is wrong because S3 Standard-IA is more expensive than Glacier Deep Archive for long-term archival storage, and streaming logs via Kinesis adds unnecessary cost and complexity when a direct export from CloudWatch Logs to S3 is available. Option C is wrong because retaining logs in CloudWatch Logs for 7 years is significantly more expensive than storing them in S3 Glacier Deep Archive, and CloudWatch Logs Insights queries incur additional costs for data scanning. Option D is wrong because CloudWatch Logs does not have lifecycle policies to transition logs directly to Amazon S3 Glacier; the correct mechanism is to export logs to S3 first and then use S3 Lifecycle policies to transition to Glacier storage classes.

656
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to prevent all users in the production account from disabling AWS CloudTrail or modifying its configuration. What is the MOST effective way to achieve this?

A.Use IAM policies to deny only cloudtrail:DeleteTrail for all users.
B.Enable CloudTrail log file validation and use AWS Config to detect changes.
C.Create an SCP in AWS Organizations that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, cloudtrail:UpdateTrail, and similar actions.
D.Attach an IAM permissions boundary to all IAM roles in the production account that denies CloudTrail modifications.
AnswerC

SCPs in AWS Organizations set the maximum available permissions for every principal in a member account, including the root user, so a deny for cloudtrail:StopLogging, DeleteTrail and UpdateTrail blocks all users in the production account regardless of their IAM policies.

Why this answer

Service Control Policies (SCPs) in AWS Organizations provide centralized, preventive control over the maximum permissions for all accounts in an organization or OU. By creating an SCP that denies CloudTrail actions such as StopLogging, DeleteTrail, and UpdateTrail, the security team can ensure that no user or role in the production account can disable or modify CloudTrail, even if they have IAM permissions. This is the most effective and scalable way to enforce this restriction across the account.

Exam trap

SCS-C02 often tests the difference between preventive and detective controls, and candidates frequently choose IAM policies or AWS Config when the requirement is to prevent actions across an entire account or organization.

How to eliminate wrong answers

Option A is wrong because an IAM policy denying only DeleteTrail is incomplete and can be bypassed by users with permissions to StopLogging or UpdateTrail, and it must be attached to every user or role. Option B is wrong because log file validation and AWS Config are detective controls, not preventive; they detect changes but do not prevent them. Option D is wrong because permissions boundaries apply to individual IAM entities and are not centrally managed across the account, making them less effective and harder to maintain than SCPs.

657
MCQeasy

A security engineer is investigating a potential compromise of an EC2 instance. The engineer needs to capture network traffic to and from the instance for forensic analysis. Which AWS service should be used to capture this traffic?

A.AWS Config
B.AWS Network Firewall
C.VPC Traffic Mirroring
D.Amazon Inspector
AnswerC

VPC Traffic Mirroring copies the full packet content from one or more elastic network interfaces (ENIs) of an EC2 instance and forwards it to a target such as a security appliance, an NLB, or an ENI that hosts a packet capture tool. This gives investigators the raw traffic needed to detect and analyze anomalies, lateral movement, or exfiltration without affecting the workload's primary network path. It is the correct choice when the goal is to capture and inspect actual network packets for a suspected compromise.

Why this answer

VPC Traffic Mirroring captures and inspects network traffic at the Elastic Network Interface (ENI) level by copying packets from a source ENI to a target, such as a Network Load Balancer or another ENI. This allows the security engineer to perform deep packet inspection and forensic analysis without impacting the production traffic flow. It supports both IPv4 and IPv6 traffic and can filter by protocol, port, or packet direction, making it ideal for incident response scenarios.

Exam trap

The trap here is that candidates confuse VPC Traffic Mirroring with AWS Network Firewall, assuming that a firewall inherently captures traffic, but Network Firewall only inspects and filters traffic in-line without providing a separate packet capture stream for forensic analysis.

How to eliminate wrong answers

Option A is wrong because AWS Config is a resource inventory and compliance auditing service that records configuration changes, not network traffic. Option B is wrong because AWS Network Firewall is a managed firewall service that filters traffic at the VPC level but does not capture or mirror traffic for forensic analysis; it blocks or allows traffic based on rules. Option D is wrong because Amazon Inspector is a vulnerability assessment service that scans for software vulnerabilities and unintended network exposure, not a packet capture tool.

658
Multi-Selectmedium

A security engineer is designing a threat detection solution for a multi-account AWS environment. The engineer needs to detect and respond to suspicious API activity across all accounts. Which TWO services should be used together to achieve this? (Choose two.)

Select 2 answers
A.Amazon CloudWatch
B.Amazon GuardDuty
C.AWS Security Hub
D.Amazon Inspector
E.AWS Config
AnswersB, C

Amazon GuardDuty is a machine-learning and anomaly-detection security service that continuously analyzes AWS CloudTrail management and data events, VPC Flow Logs, and DNS query logs to identify unauthorized behavior, crypto-mining, credential compromise, and API abuse. It generates severity-ranked findings using threat intelligence and behavioral modeling, making it the core service for a threat detection solution.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious or unauthorized behavior across AWS accounts, including suspicious API activity. By enabling GuardDuty in all accounts and aggregating findings to a central administrator account, it provides the necessary detection layer for multi-account environments.

Exam trap

The trap here is that candidates often confuse AWS Security Hub (a findings aggregation and compliance service) with a primary detection tool, but Security Hub itself does not generate threat detections—it ingests findings from GuardDuty and other services, so both are needed together.

659
MCQeasy

A company wants to monitor failed SSH login attempts to its EC2 instances. Which AWS service should be used to collect and analyze these logs?

A.VPC Flow Logs
B.Amazon CloudWatch Logs with the unified CloudWatch agent
C.AWS CloudTrail
D.AWS Config
AnswerB

The unified CloudWatch agent collects operating-system logs such as /var/log/secure or auth.log from EC2 instances and ships them to CloudWatch Logs, where metric filters and alarms can detect and alert on failed SSH login attempts.

Why this answer

Amazon CloudWatch Logs with the unified CloudWatch agent is the correct choice because the agent can be configured to collect and forward system log files, such as /var/log/secure (Amazon Linux) or /var/log/auth.log (Ubuntu), which record SSH authentication attempts including failures. This allows centralized monitoring and analysis of failed SSH logins via CloudWatch Logs Insights or metric filters.

Exam trap

The trap here is that candidates confuse VPC Flow Logs (network-level) with OS-level logs, or assume CloudTrail captures all activity including guest OS events, when in fact CloudTrail only records AWS API calls, not in-OS authentication logs.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture metadata about network traffic (IP addresses, ports, protocols) but do not log application-level events like SSH authentication failures. Option C is wrong because AWS CloudTrail records API calls made to the AWS control plane (e.g., EC2 RunInstances) but does not capture guest OS-level logs such as SSH login attempts. Option D is wrong because AWS Config tracks resource configuration changes and compliance, not operating system log events.

660
MCQmedium

Refer to the exhibit. A security engineer runs this AWS CLI command to investigate root user logins. The output shows a successful ConsoleLogin event. What should the engineer do next to improve security?

A.Delete the root user account.
B.Disable the root user password and require all logins via IAM users.
C.Enable IAM Access Analyzer to detect and alert on root user activity.
D.Enable multi-factor authentication (MFA) for the root user.
AnswerD

A successful root ConsoleLogin without MFA leaves the account's most privileged identity protected by a password alone. Enabling MFA for the root user adds a second authentication factor, satisfying the requirement to strengthen security after confirming root console access.

Why this answer

Enabling multi-factor authentication (MFA) for the root user adds an extra layer of security, making it much harder for an attacker to compromise the root account even if the password is known. While AWS recommends avoiding routine use of the root user, the root account cannot be deleted; instead, securing it with MFA is a best practice. Options A and B are incorrect because root user cannot be deleted, and disabling the password alone does not prevent root user login via password recovery or other methods.

Option C is incorrect because IAM Access Analyzer analyzes resource-based policies for unintended access, not root user activity; it does not generate findings for ConsoleLogin events.

Exam trap

The trap is that candidates may confuse IAM Access Analyzer (which analyzes resource policies) with AWS CloudTrail or Amazon GuardDuty (which can monitor root user activity). The question asks for the next step after detecting a root user login, which is to secure the root user with MFA, not to enable a service that does not monitor such events.

How to eliminate wrong answers

Option A is wrong because the root user account cannot be deleted; it is a permanent AWS account owner with immutable privileges. Option B is wrong because disabling the root user password does not prevent root user access via other methods (e.g., access keys) and does not address the need for monitoring; AWS requires root user credentials for certain account management tasks. Option D is wrong because while enabling MFA for the root user is a best practice, the question specifically asks what to do next after observing a successful ConsoleLogin event—MFA does not provide detection or alerting for root user activity, which is the immediate security concern.

661
MCQeasy

A security team detects that an IAM user's access keys are being used from an unusual geographic location. Which AWS service provides this type of anomaly detection?

A.Amazon Inspector
B.AWS CloudTrail
C.Amazon GuardDuty
D.AWS Config
AnswerC

Amazon GuardDuty is a continuous threat detection service that uses machine learning and threat intelligence to analyze AWS API activity from CloudTrail, VPC Flow Logs, and DNS logs. It specifically identifies anomalous IAM user behavior, such as a user's access key being used from a geographically distant location or at impossible travel speeds, which strongly suggests the key has been stolen. GuardDuty then generates a security finding that can be routed to a response playbook, making it the correct service for detecting this type of credential misuse.

Why this answer

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior, including anomalous API calls from unusual geographic locations. It uses machine learning models and integrated threat intelligence to analyze AWS CloudTrail management events, VPC Flow Logs, and DNS logs, making it the correct service for detecting IAM user access key usage from an unexpected region.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail's logging capability with active threat detection, but CloudTrail only records events and does not analyze them for anomalies—GuardDuty is the service that performs the analysis and generates findings.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, not for monitoring IAM user activity or geographic anomalies. Option B is wrong because AWS CloudTrail is a governance, compliance, and auditing service that records API activity but does not perform real-time anomaly detection or flag unusual geographic patterns on its own. Option D is wrong because AWS Config is a resource inventory and compliance service that evaluates resource configurations against rules, not a threat detection service for anomalous user behavior.

662
MCQmedium

A company uses Amazon GuardDuty and AWS Security Hub. The security team wants to automatically remediate high-severity GuardDuty findings that indicate an EC2 instance is communicating with a known command and control (C&C) server. The remediation should isolate the instance by modifying the security group to deny all inbound and outbound traffic. Which solution is the most efficient?

A.Use Amazon CloudWatch Events to directly modify the security group when a GuardDuty finding is published.
B.Send Security Hub findings to Amazon EventBridge, which triggers a Lambda function to modify the security group.
C.Configure GuardDuty to automatically update the security group when a finding is generated.
D.Create an AWS Config rule that triggers a Lambda function when a security group change is detected.
AnswerB

This is the correct architecture because Security Hub ingests GuardDuty findings as security findings and can forward them to an EventBridge bus. An EventBridge rule can filter for specific finding types or severities and trigger a Lambda function, which then uses the AWS SDK to modify the security group. This decouples detection from remediation and is a standard, supported pattern for automated response to security findings.

Why this answer

It leverages Security Hub as a central aggregation point for GuardDuty findings, then uses EventBridge to trigger a Lambda function that modifies the security group. This is the most efficient architecture as Security Hub normalizes findings from multiple sources, and EventBridge provides reliable, low-latency event routing to Lambda for custom remediation logic without requiring direct GuardDuty-to-security-group integration.

Exam trap

The trap here is that candidates assume GuardDuty can directly modify security groups (Option C) or that CloudWatch Events can directly perform API actions (Option A), when in reality both require a Lambda function as an intermediary to execute the remediation logic.

How to eliminate wrong answers

Option A is wrong because CloudWatch Events (now part of EventBridge) can trigger on GuardDuty findings, but directly modifying a security group from a CloudWatch Events rule is not possible — CloudWatch Events cannot execute API calls to modify security groups; it only routes events to targets like Lambda. Option C is wrong because GuardDuty does not have native capability to automatically modify security groups; it only generates findings and can send them to EventBridge or Security Hub, but cannot directly perform remediation actions. Option D is wrong because an AWS Config rule that triggers on security group changes is reactive and does not address the requirement to automatically remediate the GuardDuty finding; it would only detect changes after they occur, not initiate the isolation based on the finding.

663
Multi-Selecthard

A security team needs to ensure that all IAM users in a production account use multi-factor authentication (MFA) before accessing the AWS Management Console. Which TWO steps should be taken? (Choose TWO.)

Select 2 answers
A.Use AWS Config rules to detect users without MFA.
B.Enable MFA for each IAM user.
C.Attach an IAM policy that denies console access if MFA is not present.
D.Apply an SCP that requires MFA for console access.
E.Configure an IAM password policy to require MFA.
AnswersB, C

Enabling MFA for each IAM user is the foundational prerequisite because AWS IAM does not automatically assign MFA devices. An administrator must manually activate a virtual or hardware MFA device for every user, and without this step no conditional policy can ever evaluate successfully because the MFA condition would always be false. This direct action ensures the compliance goal is met at the source, not just enforced at login.

Why this answer

To enforce MFA for console access, you need to enable MFA for each user (B) and attach an IAM policy that denies console access if MFA is not present (C). Option E is incorrect because the IAM password policy cannot require MFA; it only requires MFA for password changes, not console login. Option A is incorrect because AWS Config rules can detect users without MFA but cannot enforce it.

Option D is incorrect because SCPs apply to accounts, not individual user console access; they cannot directly require MFA for console login.

Exam trap

This question asks to select two steps, but some candidates may incorrectly think there is a third correct step, such as configuring an IAM password policy or using AWS Config, but these do not enforce MFA for console access.

664
MCQhard

Refer to the exhibit. A security engineer is reviewing this IAM policy attached to a user. The user reports that they are able to stop and start instances, but they cannot terminate instances. However, the engineer notices that there is no explicit deny for termination. Why is the user unable to terminate instances?

A.The policy does not include an explicit Allow for ec2:TerminateInstances.
B.The second statement's Resource is set to '*' but the Action list does not include termination.
C.The first statement's Resource element is too restrictive and does not include the termination API call.
D.The policy has a syntax error that prevents termination from being evaluated.
AnswerA

The policy contains separate Action and Resource elements, and IAM permits an action only when an explicit Allow statement matches that action. Because ec2:TerminateInstances appears nowhere in the first statement's Action list (which grants Start and Stop) or in the second statement's Describe-only list, the action is implicitly denied by IAM's default-deny evaluation. Without an explicit Allow, no other statement or wildcard can rescue it; the request fails with an UnauthorizedOperation error.

Why this answer

IAM policies operate on an explicit allow model. Even though there is no explicit deny for ec2:TerminateInstances, the user is unable to terminate instances because the policy does not include an explicit Allow action for ec2:TerminateInstances. Without an explicit Allow, the default behavior is to deny the action, regardless of whether a deny statement is present.

Exam trap

The trap here is that candidates often assume the absence of an explicit deny means the action is allowed, but AWS IAM defaults to implicit deny for any action not explicitly allowed.

How to eliminate wrong answers

Option B is wrong because the second statement's Resource being set to '*' and the Action list not including termination is irrelevant; the issue is the lack of an explicit Allow for termination, not the resource specification. Option C is wrong because the first statement's Resource element being too restrictive does not prevent termination; the problem is that termination is not allowed at all in the policy. Option D is wrong because there is no syntax error; the policy is syntactically valid but simply does not grant the required permission.

665
MCQhard

A security engineer is designing a centralized logging solution for a multi-account AWS environment using AWS Organizations. The solution must ensure that all CloudTrail logs from all accounts are delivered to a single S3 bucket in the security account. Additionally, the logs must be encrypted with a KMS key that is managed by the security account. Which combination of steps is required?

A.Create a trail in each account, each delivering to the same S3 bucket. Use a bucket policy to allow cross-account writes. Use a single KMS key with appropriate key policy.
B.Use AWS Config to deliver logs to a central bucket. Enable CloudWatch Logs in each account and stream to the security account.
C.Create a trail in the management account with organization trail enabled, delivering to a bucket in the management account. Use KMS default encryption.
D.Create a trail in the security account with organization trail enabled, delivering to a bucket in the security account. Configure bucket policy and KMS key policy to allow CloudTrail and S3 from all accounts.
AnswerA

Correct. Each account's trail sends logs to the central S3 bucket in the security account. The bucket policy allows cross-account writes, and the KMS key policy grants necessary permissions for CloudTrail and S3 from all accounts.

Why this answer

It uses individual trails in each account, all configured to deliver to the same centralized S3 bucket in the security account. A bucket policy can grant CloudTrail write permissions from all accounts, and a single KMS key (managed by the security account) with appropriate key policy ensures encryption. This approach meets the centralized logging and encryption requirements without violating organization trail constraints.

Option B is incorrect because AWS Config does not deliver CloudTrail logs, and CloudWatch Logs streaming is not the required solution. Option C is incorrect because the trail is created in the management account but delivers to a bucket in the management account, not the security account, and it uses default encryption instead of a customer-managed KMS key from the security account. Option D is incorrect because organization trails can only be created in the management account; creating one in the security account is not allowed.

666
Multi-Selectmedium

A company wants to protect sensitive data stored in Amazon S3. Which TWO actions should the company take to meet this goal? (Choose TWO.)

Select 2 answers
A.Enable S3 Transfer Acceleration.
B.Configure S3 event notifications to send events to Amazon SNS.
C.Enable S3 Block Public Access.
D.Enable S3 Object Lock.
E.Enable default encryption on the bucket.
AnswersC, E

Enabling S3 Block Public Access adds a strong, explicit layer of protection that can block public reading or writing through bucket policies, ACLs, or object ACLs, even if those public grants are unintentionally set. This control operates at both bucket and account levels and is a primary safeguard against data exposure caused by misconfigurations, making it essential for sensitive data.

Why this answer

Option C (Enable S3 Block Public Access) is correct because it applies account- and bucket-level settings that reject any ACL or bucket policy granting public access, preventing accidental exposure of sensitive objects to the internet. Option E (Enable default encryption on the bucket) is correct because it ensures every object is encrypted at rest with SSE-S3 or SSE-KMS automatically, protecting data confidentiality even if storage media is compromised. Option A (S3 Transfer Acceleration) only speeds up uploads/downloads via edge locations and does not protect data.

Option B (S3 event notifications to Amazon SNS) merely reports object events and provides no security control. Option D (S3 Object Lock) enforces WORM retention to prevent deletion or modification, which addresses integrity/retention rather than protecting sensitive data from unauthorized access or disclosure.

Exam trap

SCS-C02 often tests whether candidates confuse availability/performance features (Transfer Acceleration) or event-driven features (SNS notifications) with actual data protection controls, and whether they recognize that Object Lock addresses integrity/retention rather than confidentiality.

667
Multi-Selectmedium

A company wants to detect and respond to potential security threats in near real-time. Which THREE AWS services should the company use together? (Select THREE.)

Select 3 answers
A.AWS Security Hub
B.Amazon Inspector
C.Amazon Detective
D.AWS CloudTrail
E.Amazon GuardDuty
AnswersA, C, E

AWS Security Hub is the correct answer because it functions as a centralized cloud security posture management service that aggregates findings from multiple AWS detective and vulnerability services, including GuardDuty, Inspector, and Macie, into a single console. It enables detection by collecting these findings and facilitates response through event-driven automation using Amazon EventBridge, custom actions, and integration with SIEM or ticketing tools. While it does not generate its own raw detections, it provides the unified visibility and orchestration needed to both detect and respond to security issues across an entire AWS environment.

Why this answer

AWS Security Hub (A) aggregates security findings from multiple AWS services, including Amazon GuardDuty (E) and Amazon Detective (C), into a single dashboard. GuardDuty provides near real-time threat detection by analyzing VPC Flow Logs, DNS logs, and CloudTrail events using machine learning. Detective automates the investigation of those findings by correlating historical data to identify root causes.

Together, these three services enable near real-time detection and response to security threats.

Exam trap

The trap here is that candidates often select Amazon Inspector (B) thinking it provides real-time threat detection, but it is a vulnerability assessment tool that runs on a schedule, not a continuous threat detection service like GuardDuty.

668
MCQeasy

A company has a VPC with multiple subnets. The security team wants to control traffic between subnets using a stateful firewall that can automatically allow return traffic. Which AWS service should be used?

A.Network ACLs
B.AWS Firewall Manager
C.AWS WAF
D.Security groups
AnswerD

Security groups are stateful and are attached to elastic network interfaces (ENIs), automatically permitting return traffic without requiring separate outbound rules for responses. They can be applied consistently across all instances within a subnet to provide effective subnet-wide filtering with connection tracking, which aligns with the security team's need for granular, connection-aware traffic control. Because they operate per-interface and maintain state, they are the correct choice in this scenario.

Why this answer

Security groups act as a stateful virtual firewall for EC2 instances and other resources at the subnet or instance level. They automatically allow return traffic regardless of inbound or outbound rules, which satisfies the requirement for a stateful firewall that controls traffic between subnets.

Exam trap

The trap here is that candidates often confuse Network ACLs with security groups, assuming both are stateful, but Network ACLs are stateless and require explicit bidirectional rules, while security groups automatically handle return traffic.

How to eliminate wrong answers

Option A is wrong because Network ACLs are stateless, meaning they require explicit rules for both inbound and outbound traffic to allow return traffic, which does not meet the stateful requirement. Option B is wrong because AWS Firewall Manager is a centralized policy management service for firewall rules across accounts and resources, not a stateful firewall itself that controls traffic between subnets. Option C is wrong because AWS WAF is a web application firewall that protects against web exploits at the application layer (HTTP/HTTPS), not a stateful network firewall for controlling traffic between subnets.

669
Multi-Selectmedium

A security engineer is designing a governance framework for a multi-account AWS environment. The framework must enforce the principle of least privilege for cross-account access. Which TWO strategies should be implemented?

Select 2 answers
A.Enable AWS CloudTrail in all accounts and aggregate logs.
B.Grant full administrative access to a central security group.
C.Use a single IAM user across all accounts for administrative tasks.
D.Use IAM roles with specific permissions and trust policies for cross-account access.
E.Define service control policies (SCPs) that restrict the maximum permissions per account.
AnswersD, E

IAM roles with specific permission policies and trust policies enable cross-account access by allowing principals from a trusted account to assume the role and receive temporary, scoped AWS credentials through the AWS STS AssumeRole API. The role's trust policy specifies which accounts or principals may assume it, while the permission policy limits what those principals can do after assuming it, providing a true least-privilege mechanism. This is the correct approach because it avoids long-lived credentials, enforces the principle of least privilege, and supports conditions such as MFA, source IP, or session tags for further restriction.

Why this answer

IAM roles with specific permissions and trust policies enable cross-account access without sharing long-term credentials. The trust policy defines which accounts can assume the role, and the permissions policy grants only the necessary actions, enforcing the principle of least privilege.

Exam trap

The trap here is that candidates may confuse detective controls (like CloudTrail logging) with preventive controls (like IAM roles and SCPs), or mistakenly think that sharing a single IAM user or granting broad permissions is acceptable for administrative convenience.

670
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to ensure that all newly created accounts automatically have AWS CloudTrail enabled, with logs delivered to a centralized S3 bucket. Which solution meets these requirements with the least operational overhead?

A.Create an SCP that enables CloudTrail and enforces log delivery to the centralized S3 bucket.
B.Use AWS Trusted Advisor to check CloudTrail status and send alerts to the security team.
C.Create an SCP that denies actions to disable CloudTrail and modify the S3 bucket policy. Use AWS CloudFormation StackSets to deploy a CloudTrail trail in each account.
D.Use AWS Config rules with auto-remediation to enable CloudTrail in each account.
AnswerC

StackSets with service-managed permissions automatically deploy the CloudTrail trail to every account, including newly created ones, satisfying the automatic-enablement constraint with minimal overhead. The SCP complements this by preventing trail deletion or bucket-policy tampering, enforcing immutability across the organisation without per-account scripting.

Why this answer

The correct answer. SCPs cannot enable CloudTrail, but they can prevent disabling it and modifying the S3 bucket policy. To actually enable CloudTrail across all accounts with minimal overhead, AWS CloudFormation StackSets can deploy a CloudTrail trail in each account automatically.

Option A is incorrect because SCPs cannot enable services—they only deny or allow actions. Option B is incorrect because AWS Trusted Advisor only checks and alerts; it does not enforce configurations. Option D is incorrect because AWS Config rules with auto-remediation can work but involve more setup and overhead compared to using StackSets, which is purpose-built for deploying resources across multiple accounts.

Therefore, C provides the least operational overhead.

671
MCQeasy

A security engineer needs to centrally collect and analyze AWS CloudTrail logs from multiple accounts. Which service is designed for this purpose?

A.Configure each account to send logs to a central S3 bucket
B.Enable Amazon GuardDuty in each account and aggregate findings
C.Use Amazon CloudWatch Logs to stream logs from each account to a central account
D.Use AWS Organizations to create a CloudTrail trail that applies to all accounts
AnswerD

Using AWS Organizations, you can create an organization trail from the management account that automatically logs CloudTrail management events for every account in the organization, including future accounts, with no per-account configuration. The trail delivers log files to a single designated S3 bucket in the management account, enabling centralized collection and analysis through Athena, QuickSight, or other tools. This is the native, designed method for centralizing CloudTrail logs across multiple accounts.

Why this answer

AWS Organizations allows you to create a single CloudTrail trail that applies to all accounts in the organization, centrally collecting management and data events into a single S3 bucket (and optionally CloudWatch Logs). This eliminates the need to manually configure trails in each account and ensures consistent logging across the entire organization, meeting the requirement for central collection and analysis.

Exam trap

The trap here is that candidates often confuse 'centralized logging' with simply sending logs to a central S3 bucket (Option A), missing the key requirement that AWS Organizations provides a single, managed trail that applies to all accounts automatically, rather than requiring per-account configuration.

How to eliminate wrong answers

Option A is wrong because simply configuring each account to send logs to a central S3 bucket requires manual setup per account, does not enforce consistent trail configuration, and lacks native aggregation of logs from multiple accounts into a single trail for analysis. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes DNS, VPC flow logs, and CloudTrail logs for malicious activity, but it does not centrally collect or store raw CloudTrail logs for analysis; it only provides findings. Option C is wrong because Amazon CloudWatch Logs can stream logs from multiple accounts, but it requires each account to have its own CloudTrail trail configured and then stream to a central account, which adds complexity and does not provide a single, unified trail across all accounts.

672
MCQeasy

A company wants to centrally collect CloudTrail logs from multiple AWS accounts and enable real-time analysis. Which combination of services should be used?

A.CloudTrail, Amazon Kinesis Data Firehose, and Amazon Athena.
B.CloudTrail, Amazon S3, S3 Event Notifications, and AWS Lambda.
C.CloudTrail, Amazon CloudWatch Logs, and cross-account log subscription.
D.CloudTrail, Amazon S3, and Amazon Simple Queue Service (SQS).
AnswerB

This design works because CloudTrail delivers compressed log files as S3 objects, and S3 Event Notifications invoke Lambda for each new object. Lambda then unpacks the gzipped CloudTrail JSON, filters for key API activity, and writes normalized events to CloudWatch Logs or fires alerts, giving near-real-time analysis without managing servers or a streaming buffer. It is serverless, cost-effective, and tightly integrated with S3, making it the natural choice for a central log collection and analysis pipeline.

Why this answer

It enables centralized collection of CloudTrail logs from multiple accounts by delivering logs to a central S3 bucket, then using S3 Event Notifications to trigger a Lambda function for real-time analysis. This pattern allows near-instant processing of log events as they arrive, meeting the requirement for real-time analysis without polling or batching delays.

Exam trap

The trap here is that candidates often assume Kinesis Data Firehose or CloudWatch Logs are required for real-time analysis, but S3 Event Notifications with Lambda provide a simpler, cost-effective, and fully serverless solution for near-real-time processing of CloudTrail logs.

How to eliminate wrong answers

Option A is wrong because Amazon Kinesis Data Firehose is designed for streaming data ingestion into destinations like S3 or Redshift, but it does not natively support cross-account CloudTrail log delivery or real-time analysis via Athena (which queries data at rest, not in real-time). Option C is wrong because cross-account log subscription to CloudWatch Logs requires CloudTrail to deliver logs to CloudWatch Logs, which incurs additional costs and does not inherently provide real-time analysis; it also lacks the event-driven trigger for immediate processing. Option D is wrong because Amazon SQS is a message queue service that would require additional components to process logs in real-time, and CloudTrail cannot directly deliver logs to SQS; this setup adds latency and complexity without a built-in processing trigger.

673
MCQhard

A company wants to share an encrypted Amazon Machine Image (AMI) with another AWS account. The AMI uses an EBS snapshot encrypted with a customer managed key in KMS. What is the correct procedure to allow the other account to launch an EC2 instance from this AMI?

A.Export the snapshot as an unencrypted snapshot and share it.
B.Share the AMI and have the target account create a new KMS key to encrypt the snapshot.
C.Share only the AMI; the snapshot permissions are inherited from the AMI.
D.Share the AMI, share the snapshot, and grant the target account decrypt permissions on the KMS key.
AnswerD

This is correct because launching a cross-account encrypted AMI requires three separate sharing actions: the AMI itself via ModifyImageAttribute, each backing snapshot via ModifySnapshotAttribute, and the KMS key via a key policy update that grants the target account decrypt permissions. The target account's IAM roles or users must be able to call kms:Decrypt (and kms:CreateGrant for the launch to create a grant) on the source CMK. After these steps, the target can launch the instance and optionally re-encrypt the resulting volumes with its own KMS key. This layered authorization is the standard, supported pattern for sharing encrypted AMIs across accounts.

Why this answer

An encrypted EBS snapshot backed by a customer managed KMS key requires three separate permissions to be shared: the AMI must be shared with the target account, the underlying snapshot must be shared (modify-snapshot-attribute), and the KMS key policy must grant the target account kms:Decrypt and kms:CreateGrant (and typically kms:DescribeKey). Without all three, the target account cannot launch an instance because it cannot decrypt the snapshot volumes.

Exam trap

SCS-C02 often tests the layered nature of encrypted AMI sharing — candidates assume sharing the AMI is sufficient, forgetting that snapshot permissions and KMS key policy grants are separate, mandatory steps.

How to eliminate wrong answers

Option A is wrong because exporting an unencrypted snapshot defeats the purpose of encryption and is also blocked by AWS for snapshots encrypted with a customer managed key unless you first decrypt them — and it violates the security requirement. Option B is wrong because the target account cannot re-encrypt a snapshot it cannot decrypt; creating a new KMS key does not grant access to the source key's ciphertext. Option C is wrong because AMI sharing does not propagate snapshot permissions — snapshot sharing is a separate API call, and KMS key permissions are a third, independent layer.

674
MCQeasy

A company is using Amazon CloudWatch Logs to store application logs. The security team needs to ensure that logs are encrypted at rest using a customer-managed KMS key (CMK). What configuration is required?

A.Add a KMS key policy that allows CloudWatch Logs to use the key.
B.Associate the CMK with the CloudWatch Logs log group by specifying the key ARN in the log group's encryption configuration.
C.Enable default encryption on the S3 bucket used for log export with a CMK.
D.Configure the S3 bucket policy to require SSE-KMS for log delivery.
AnswerB

To encrypt a CloudWatch Logs log group with a customer-managed CMK, you must use the AssociateKmsKey operation (or the console's encryption settings) and pass the key ARN for the log group. Once associated, CloudWatch Logs uses that CMK to encrypt all log data written to the log group. This is the action that actually fulfills the requirement; no other configuration changes the encryption of the log group's stored data.

Why this answer

CloudWatch Logs supports server-side encryption with a customer-managed KMS key (CMK) by associating the key ARN with the log group. This is done via the CloudWatch Logs console, AWS CLI, or SDK using the `associate-kms-key` operation, which encrypts all log data at rest within that log group. The KMS key policy must also grant the CloudWatch Logs service principal (`logs.region.amazonaws.com`) permission to use the key, but the core configuration step is associating the key with the log group.

Exam trap

The trap here is that candidates confuse the necessary KMS key policy (Option A) with the actual configuration step of associating the key with the log group, or they mistakenly think that encrypting the S3 export destination (Options C or D) encrypts the logs within CloudWatch Logs itself.

How to eliminate wrong answers

Option A is wrong because while a KMS key policy that allows CloudWatch Logs to use the key is necessary, it is not sufficient on its own; the key must also be explicitly associated with the log group via encryption configuration. Option C is wrong because enabling default encryption on an S3 bucket with a CMK only affects objects stored in that bucket, not the CloudWatch Logs log group itself; log export to S3 is a separate feature and does not encrypt logs at rest within CloudWatch. Option D is wrong because configuring an S3 bucket policy to require SSE-KMS for log delivery only applies to logs exported to S3, not to the encryption of logs stored natively in CloudWatch Logs.

675
MCQmedium

A security engineer needs to ensure that all S3 object-level API calls (e.g., GetObject, PutObject) on the bucket 'my-bucket' are logged. The current CloudTrail configuration is as shown in the exhibit. What change should the engineer make?

A.Remove the DataResources section and add an AdvancedEventSelector for S3.
B.Change the bucket ARN to 'arn:aws:s3:::my-bucket' without a trailing slash.
C.Enable management events by setting IncludeManagementEvents to true.
D.Change the data resource value to 'arn:aws:s3:::my-bucket/' to cover all objects.
AnswerD

Changing the data resource value to 'arn:aws:s3:::my-bucket/' correctly covers all objects within the bucket. In CloudTrail's DataResource configuration for S3, the ARN must specify a prefix; a trailing slash after the bucket name represents the root prefix, meaning all objects inside that bucket. Without the slash, CloudTrail does not match object-level operations. This is the standard pattern for logging all S3 data events for a single bucket.

Why this answer

To log all S3 object-level API calls (GetObject, PutObject, etc.) on the bucket 'my-bucket', the DataResources value must specify the bucket's ARN with a trailing slash (arn:aws:s3:::my-bucket/) to indicate all objects within the bucket. Without the trailing slash, CloudTrail interprets the ARN as referring to the bucket itself, not its objects, and thus object-level events are not captured. The trailing slash ensures the selector applies to all object keys under that bucket.

Exam trap

The trap here is that candidates often think the bucket ARN without a trailing slash is sufficient for object-level logging, not realizing that the trailing slash is required to match all objects within the bucket, a nuance that CloudTrail documentation explicitly states.

How to eliminate wrong answers

Option A is wrong because removing the DataResources section and adding an AdvancedEventSelector for S3 is unnecessary; the existing DataResources configuration can be corrected simply by appending a trailing slash, and AdvancedEventSelectors are not required for this basic S3 data event logging. Option B is wrong because changing the bucket ARN to 'arn:aws:s3:::my-bucket' without a trailing slash would still not cover object-level events; it would only match the bucket resource itself, not the objects. Option C is wrong because enabling management events (IncludeManagementEvents) controls logging of bucket-level management operations (e.g., CreateBucket, DeleteBucket), not object-level API calls like GetObject or PutObject, which are data events.

Page 8

Page 9 of 17

Page 10