Courseiva

CCNA Management and Security Governance Questions

75 of 168 questions · Page 2/3 · Management and Security Governance · Answers revealed

76
MCQhard

A security engineer is designing a system to detect and respond to IAM policy changes that could grant excessive permissions. The solution must alert within minutes of the change and automatically revert the change if it violates a predefined baseline. Which combination of services should the engineer use?

A.AWS CloudTrail and Amazon S3
B.AWS CloudTrail, Amazon CloudWatch Events, and AWS Lambda
C.AWS Config and AWS Systems Manager
D.IAM Access Analyzer and AWS Lambda
AnswerB

CloudTrail continuously streams API activity from the account, and a CloudWatch Events rule can match specific IAM actions (e.g., PutUserPolicy, AttachUserPolicy) in real time. The rule triggers a Lambda function, which can immediately respond by removing the policy, restoring a backup, or alerting security personnel. This is a native, serverless, event-driven architecture that satisfies both detection and automated remediation.

Why this answer

AWS CloudTrail logs IAM policy changes. Amazon CloudWatch Events (now EventBridge) can match specific API calls (e.g., PutRolePolicy) and trigger an AWS Lambda function within minutes. The Lambda function can evaluate the change against a baseline and automatically revert it if it violates the policy, providing both detection and remediation.

Exam trap

SCS-C02 often tests the misconception that AWS Config can automatically remediate without additional services, or that CloudTrail alone can trigger actions, ignoring the need for EventBridge and Lambda.

How to eliminate wrong answers

Option A is wrong because CloudTrail and S3 only store logs; they do not provide real-time alerting or automated remediation. Option C is wrong because AWS Config can detect changes but does not automatically revert them; Systems Manager can automate but requires additional setup and is not event-driven in the same way. Option D is wrong because IAM Access Analyzer identifies overly permissive policies but does not automatically revert changes; Lambda alone lacks the event trigger from CloudTrail.

77
MCQeasy

A startup is deploying a web application on AWS. The application runs on EC2 instances behind an Application Load Balancer (ALB). The security team wants to ensure that all traffic to the EC2 instances is encrypted. They configure the ALB to listen on HTTPS (port 443) and forward traffic to the EC2 instances on HTTP (port 80). Additionally, they create a security group for the EC2 instances that only allows inbound traffic from the ALB's security group on port 80. However, a security audit reveals that the traffic between the ALB and EC2 instances is not encrypted. Which step should the security team take to encrypt the traffic between the ALB and EC2 instances?

A.Update the EC2 security group to allow traffic on port 443 from the ALB.
B.Enable encryption at rest on the EC2 instances.
C.Configure the target group to use HTTPS protocol and install a certificate on the EC2 instances.
D.Change the ALB listener to use TCP instead of HTTPS.
AnswerC

Changing the target group protocol to HTTPS instructs the ALB to establish TLS connections to the EC2 instances. To complete a TLS handshake, each instance must present a valid certificate (for the domain or IP) trusted by the client, so you must install and configure a certificate on the instances. This ensures that traffic between the ALB and instances is encrypted, closing the gap where plaintext HTTP might otherwise travel inside the VPC.

Why this answer

To encrypt traffic between the ALB and EC2 instances, configure the target group to use HTTPS protocol and install a certificate on the EC2 instances. This ensures the ALB sends HTTPS requests to the instances, encrypting the traffic. Option A is wrong because opening port 443 on the EC2 security group alone does not enable encryption; the listener must also use HTTPS for target traffic.

Option B is wrong because encryption at rest protects data stored on disk, not data in transit. Option D is wrong because changing the ALB listener to TCP would terminate TLS at the ALB and forward unencrypted traffic to the targets, which defeats the purpose.

78
MCQhard

A security engineer notices that an IAM role in the production account is being assumed by a user from another AWS account, which violates the principle of least privilege. The role's trust policy allows the root user of the external account. What is the MOST secure way to restrict access to only a specific user in the external account?

A.Apply an SCP to the external account to deny the sts:AssumeRole action.
B.Create an IAM policy in the external account that denies sts:AssumeRole for the role.
C.Modify the trust policy to specify the exact user ARN instead of the root ARN.
D.Add a condition to the role's permissions policy requiring a specific source IP.
AnswerC

Change the Principal element in the role's trust policy from arn:aws:iam::123456789012:root to arn:aws:iam::123456789012:user/specific-user. The root ARN represents every principal in the external account, whereas the user ARN scopes the sts:AssumeRole permission to exactly one IAM user, eliminating the ability of roles or other users in that account to assume the production role.

Why this answer

Modifying the trust policy to include the specific user ARN is the most direct and secure approach. Option A is incorrect because SCPs do not affect cross-account access. Option B is incorrect because IAM policies on the role do not restrict who can assume it.

Option D is incorrect because the external account's IAM policies do not control trust.

79
MCQeasy

Which AWS service allows you to create and manage encryption keys for your AWS resources?

A.AWS CloudHSM
B.AWS Key Management Service (KMS)
C.AWS Certificate Manager
D.AWS Secrets Manager
AnswerB

AWS Key Management Service (KMS) is the managed service purpose-built for creating and managing encryption keys, called customer master keys (CMKs), and data keys. It supports key policies, IAM-based access control, automatic annual rotation, key disabling and deletion, and direct cryptographic operations like encrypt, decrypt, and re-encrypt. KMS also integrates with dozens of AWS services for envelope encryption and records every key usage event in CloudTrail, making it the correct answer.

Why this answer

AWS Key Management Service (KMS) is the managed service designed specifically for creating, storing, and managing encryption keys used to encrypt data across AWS services. It integrates with AWS CloudTrail for auditing key usage and supports symmetric and asymmetric keys, with automatic key rotation and fine-grained access control via IAM and key policies.

Exam trap

The trap here is that candidates confuse AWS CloudHSM (a dedicated hardware security module) with KMS, not realizing that CloudHSM requires manual management and does not natively integrate with AWS services for automatic encryption, whereas KMS is the fully managed key creation and management service.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides dedicated hardware security modules (HSMs) for generating and storing keys, but it does not offer a managed key creation and management service with integrated AWS service encryption; instead, it requires you to manage the HSM appliance and client software yourself. Option C is wrong because AWS Certificate Manager (ACM) handles SSL/TLS certificate provisioning, renewal, and deployment, not the creation or management of encryption keys for data at rest or in transit. Option D is wrong because AWS Secrets Manager is designed to rotate, manage, and retrieve secrets (e.g., database credentials, API keys), not to create or manage encryption keys; it can use KMS to encrypt secrets, but it is not a key management service itself.

80
MCQhard

A company uses AWS Organizations with multiple accounts. The security team needs to ensure that no account can disable a specific security service, such as AWS Config, across all accounts. Which approach should be used?

A.Create an IAM role with a deny policy for the action and attach it to all users
B.Create an AWS Config rule to check for the action and automatically remediate
C.Attach a service control policy (SCP) that denies the action at the root organization level
D.Enable AWS CloudTrail and create a metric filter to alert on the action
AnswerC

A service control policy attached to the root organizational unit acts as a maximum permission boundary for every account under it, cascading through all child OUs and accounts. Because SCPs affect the effective permissions of all principals, including the account root users, an explicit deny statement overrides any allow from IAM-based or resource-based policies. This makes it the only option here that centrally prevents an action across the entire organization before the request can be executed.

Why this answer

A service control policy (SCP) in AWS Organizations can be attached to the root, OU, or account level to set permission guardrails. An SCP that denies the action (e.g., config:StopConfigurationRecorder or config:DeleteConfigurationRecorder) at the root organization level applies to all accounts and cannot be overridden by account administrators, ensuring the security service cannot be disabled.

Exam trap

The trap is choosing detective or reactive controls (Config rules, CloudTrail alerts) instead of preventive controls (SCPs) — the question asks to 'ensure no account can disable,' which requires prevention, not detection.

How to eliminate wrong answers

Option A is wrong because an IAM role with a deny policy attached to all users is not scalable and can be bypassed by users with other roles or by root users; it does not enforce at the organization level. Option B is wrong because an AWS Config rule detects noncompliance but does not prevent the action — it can only remediate after the fact, and if the service is disabled, the rule may not function. Option C is correct.

Option D is wrong because CloudTrail and metric filters only provide alerting and auditing, not prevention — the action would still succeed.

81
MCQhard

A company uses AWS Organizations with SCPs. The security team wants to ensure that no IAM user can be created without MFA. Which SCP should be applied at the root OU?

A.Deny iam:CreateUser unconditionally
B.Use an IAM policy to require MFA for API calls
C.Deny iam:CreateUser unless the request includes a condition for MFA
D.Attach an IAM policy to all users requiring MFA
AnswerC

This SCP denies iam:CreateUser when the aws:MultiFactorAuthPresent condition key evaluates to false, effectively allowing the action only for callers who authenticated with MFA. Because SCPs apply to all principals in an AWS organization, this check is enforced regardless of the permissions granted by an individual IAM policy. The Deny statement with a Bool condition is the precise, organizational-level mechanism that prevents creation of users without an MFA requirement.

Why this answer

It uses a Service Control Policy (SCP) to deny the `iam:CreateUser` action unless the request includes a condition that MFA is present. SCPs are account-level permission boundaries in AWS Organizations, and this approach ensures that no IAM user can be created without MFA across all accounts in the organization, as SCPs are evaluated before any IAM policies.

Exam trap

The trap here is that candidates confuse SCPs with IAM policies, thinking an IAM policy can enforce MFA at the root OU level, but SCPs are the only mechanism that can apply organization-wide restrictions on actions like `iam:CreateUser`.

How to eliminate wrong answers

Option A is wrong because unconditionally denying `iam:CreateUser` would prevent all user creation, including those with MFA, which does not meet the requirement of allowing MFA-enabled users. Option B is wrong because an IAM policy requiring MFA for API calls only controls access to existing users and does not prevent the creation of users without MFA; it also cannot be applied at the root OU level as SCPs are needed. Option D is wrong because attaching an IAM policy to all users requiring MFA is an account-level action that does not prevent the creation of new users without MFA, and it cannot be enforced across all accounts via the root OU.

82
Multi-Selectmedium

Which TWO of the following are valid methods to centrally manage security policies and enforce compliance across multiple AWS accounts? (Choose two.)

Select 2 answers
A.Deploy AWS Config conformance packs using AWS CloudFormation StackSets across accounts.
B.Attach IAM policies to all IAM users in each account.
C.Use AWS Security Hub to automatically enforce compliance rules.
D.Use AWS Organizations service control policies (SCPs) to restrict allowed actions.
E.Enable VPC Flow Logs in each account and send them to a central S3 bucket.
AnswersA, D

AWS Config conformance packs are collections of AWS Config rules and remediation actions that can be deployed across multiple accounts and Regions using CloudFormation StackSets. This provides a centralized, repeatable way to enforce and monitor compliance baselines without needing to log into each account individually. The StackSet orchestrates the deployment, while the conformance pack defines the rules that evaluate resource compliance.

Why this answer

AWS Config conformance packs provide a way to deploy a collection of AWS Config rules and remediation actions across multiple accounts and Regions. When combined with AWS CloudFormation StackSets, you can centrally deploy these conformance packs to all accounts in an AWS Organization, ensuring consistent compliance enforcement. This approach allows you to define and manage security policies as code, automatically evaluating resources against desired configurations.

Exam trap

The trap here is that candidates often confuse AWS Security Hub's detection and aggregation capabilities with actual enforcement, but Security Hub does not automatically enforce compliance—it only reports findings, while conformance packs and SCPs provide the enforcement mechanism.

83
MCQhard

A company is using AWS Organizations and wants to delegate the administration of certain accounts to different teams. For example, the finance team should be able to manage billing-related accounts, but not development accounts. Which AWS feature allows this type of delegation?

A.AWS Organizations delegated administrator
B.AWS IAM Identity Center (AWS SSO)
C.Service control policies (SCPs)
D.IAM roles in each account
AnswerA

AWS Organizations delegated administrator is a native feature that lets you designate a member account as the administrative owner for a specified AWS service across the entire organization. For example, a finance account can be registered to manage Cost Explorer and billing reports for all accounts, so finance staff can perform service-specific administrative tasks without needing the management account's root user. This provides centralized, org-wide service administration while preserving the principle of least privilege.

Why this answer

AWS Organizations delegated administrator allows a member account to be designated as the administrator for a specific AWS service (e.g., AWS Billing, AWS CloudFormation StackSets, AWS Config) across the organization. This enables the finance team's account to manage billing-related accounts without granting them full management over development accounts. It is the only feature that provides service-specific administrative delegation within Organizations.

Exam trap

SCS-C02 often tests the distinction between SCPs (permission guardrails) and delegated administrator (service-specific administrative delegation), causing candidates to pick SCPs when the question asks for delegation of administration.

How to eliminate wrong answers

Option B is wrong because IAM Identity Center (AWS SSO) is for centralized user access and permission management, not for delegating administrative control of specific accounts or services. Option C is wrong because SCPs are used to set permission guardrails across accounts, not to delegate administration to a specific team. Option D is wrong because IAM roles in each account provide cross-account access but do not implement the delegated administrator model that scopes service administration to a specific account.

84
MCQmedium

A security engineer is responsible for ensuring that all API calls made in an AWS account are logged and that the logs are immutable for at least one year. The engineer must also ensure that any attempt to delete or modify the logs triggers an alert. Which solution meets these requirements?

A.Enable AWS CloudTrail with log file validation, store logs in an S3 bucket with versioning and MFA delete enabled, and create an Amazon EventBridge rule to alert on DeleteObject or PutObject events for the bucket.
B.Enable AWS CloudTrail with log file validation, store logs in an S3 bucket with Object Lock in compliance mode for one year, and create an Amazon EventBridge rule to alert on DeleteObject or PutObject events for the bucket.
C.Enable AWS CloudTrail with log file validation, store logs in an S3 bucket with versioning and MFA delete enabled, and create an Amazon CloudWatch alarm on the CloudTrail metric for log file delivery failures.
D.Enable AWS CloudTrail with log file validation, store logs in an S3 bucket with Object Lock in compliance mode for one year, and create an Amazon CloudWatch alarm on the CloudTrail metric for log file delivery failures.
AnswerB

CloudTrail with log file validation ensures log integrity. S3 Object Lock in compliance mode prevents deletion or modification for the retention period, providing immutability for one year. An EventBridge rule that triggers on DeleteObject or PutObject events for the bucket will alert on any attempt to delete or modify the logs, meeting all requirements.

Why this answer

To achieve immutable logs for one year and alert on tampering, use CloudTrail with log file validation, S3 Object Lock in compliance mode to prevent deletion or modification, and EventBridge to detect and alert on DeleteObject or PutObject events for the bucket. This combination ensures logs cannot be altered and any attempt triggers an alert.

Exam trap

The trap here is assuming that S3 versioning with MFA delete provides immutability, when it only allows recovery and requires MFA for permanent deletion, not preventing modification attempts.

85
MCQeasy

A security engineer is designing a system to centrally manage IAM users and roles across multiple AWS accounts. The company uses AWS Organizations. Which AWS service should be used to manage permissions across accounts?

A.AWS Config
B.AWS Artifact
C.AWS CloudTrail
D.AWS IAM Identity Center (AWS SSO)
AnswerD

AWS IAM Identity Center (formerly AWS SSO) is the service designed to centrally manage workforce identities and fine-grained access to multiple AWS accounts and business applications. It connects to your existing identity provider via SAML 2.0 or SCIM, and its permission sets define which IAM roles users or groups assume in each account. This unified access model is exactly what a central management solution requires, so this is the correct choice.

Why this answer

AWS IAM Identity Center (formerly AWS SSO) is the service for centrally managing user access to multiple accounts. Option A is wrong because AWS Config is for resource compliance. Option B is wrong because AWS Artifact is for compliance reports.

Option C is wrong because AWS CloudTrail is for auditing API activity.

86
Multi-Selectmedium

A security engineer is implementing a data classification policy for an S3 bucket that contains sensitive customer data. The policy requires that all objects be encrypted at rest using AWS KMS and that any attempt to upload an unencrypted object be denied. Which THREE steps should the engineer take to enforce this policy? (Choose THREE.)

Select 3 answers
A.Enable S3 bucket keys to reduce KMS API calls.
B.Create a customer managed KMS key.
C.Enable bucket policy to enforce SSL (aws:SecureTransport).
D.Add a bucket policy that denies PutObject if s3:x-amz-server-side-encryption is not aws:kms.
E.Enable S3 default encryption with the KMS key.
AnswersB, D, E

A customer managed KMS key provides the key material and granular key policy control required for SSE-KMS encryption of the sensitive objects. Without it, the bucket policy condition on aws:kms cannot be satisfied, since no suitable key exists to reference.

Why this answer

Option B is correct because the policy requires AWS KMS encryption, and a customer managed KMS key gives the engineer control over the key policy, rotation, and permissions needed to encrypt the sensitive objects. Option D is correct because a bucket policy with a Deny on s3:PutObject when the s3:x-amz-server-side-encryption condition is not aws:kms actively blocks any upload that does not request SSE-KMS, which is exactly the enforcement mechanism the policy demands. Option E is correct because enabling S3 default encryption with the KMS key ensures that objects are encrypted at rest with SSE-KMS even when a request does not explicitly specify encryption headers, satisfying the baseline encryption requirement.

Option A is not correct because S3 Bucket Keys only reduce KMS API call costs and request throttling; they do not enforce encryption or deny unencrypted uploads. Option C is not correct because enforcing aws:SecureTransport only requires TLS in transit and does nothing to guarantee encryption at rest with KMS or to reject unencrypted object uploads.

Exam trap

SCS-C02 often tests the difference between enabling default encryption (which is passive) and enforcing encryption via bucket policy (which is active). Candidates frequently select only default encryption and miss the need for an explicit deny policy to block unencrypted uploads.

87
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to prevent all users in the production account from disabling AWS CloudTrail or modifying its configuration. What is the MOST effective way to achieve this?

A.Use IAM policies to deny only cloudtrail:DeleteTrail for all users.
B.Enable CloudTrail log file validation and use AWS Config to detect changes.
C.Create an SCP in AWS Organizations that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, cloudtrail:UpdateTrail, and similar actions.
D.Attach an IAM permissions boundary to all IAM roles in the production account that denies CloudTrail modifications.
AnswerC

SCPs in AWS Organizations set the maximum available permissions for every principal in a member account, including the root user, so a deny for cloudtrail:StopLogging, DeleteTrail and UpdateTrail blocks all users in the production account regardless of their IAM policies.

Why this answer

Service Control Policies (SCPs) in AWS Organizations provide centralized, preventive control over the maximum permissions for all accounts in an organization or OU. By creating an SCP that denies CloudTrail actions such as StopLogging, DeleteTrail, and UpdateTrail, the security team can ensure that no user or role in the production account can disable or modify CloudTrail, even if they have IAM permissions. This is the most effective and scalable way to enforce this restriction across the account.

Exam trap

SCS-C02 often tests the difference between preventive and detective controls, and candidates frequently choose IAM policies or AWS Config when the requirement is to prevent actions across an entire account or organization.

How to eliminate wrong answers

Option A is wrong because an IAM policy denying only DeleteTrail is incomplete and can be bypassed by users with permissions to StopLogging or UpdateTrail, and it must be attached to every user or role. Option B is wrong because log file validation and AWS Config are detective controls, not preventive; they detect changes but do not prevent them. Option D is wrong because permissions boundaries apply to individual IAM entities and are not centrally managed across the account, making them less effective and harder to maintain than SCPs.

88
Multi-Selecthard

A security team needs to ensure that all IAM users in a production account use multi-factor authentication (MFA) before accessing the AWS Management Console. Which TWO steps should be taken? (Choose TWO.)

Select 2 answers
A.Use AWS Config rules to detect users without MFA.
B.Enable MFA for each IAM user.
C.Attach an IAM policy that denies console access if MFA is not present.
D.Apply an SCP that requires MFA for console access.
E.Configure an IAM password policy to require MFA.
AnswersB, C

Enabling MFA for each IAM user is the foundational prerequisite because AWS IAM does not automatically assign MFA devices. An administrator must manually activate a virtual or hardware MFA device for every user, and without this step no conditional policy can ever evaluate successfully because the MFA condition would always be false. This direct action ensures the compliance goal is met at the source, not just enforced at login.

Why this answer

To enforce MFA for console access, you need to enable MFA for each user (B) and attach an IAM policy that denies console access if MFA is not present (C). Option E is incorrect because the IAM password policy cannot require MFA; it only requires MFA for password changes, not console login. Option A is incorrect because AWS Config rules can detect users without MFA but cannot enforce it.

Option D is incorrect because SCPs apply to accounts, not individual user console access; they cannot directly require MFA for console login.

Exam trap

This question asks to select two steps, but some candidates may incorrectly think there is a third correct step, such as configuring an IAM password policy or using AWS Config, but these do not enforce MFA for console access.

89
MCQhard

A security engineer is designing a centralized logging solution for a multi-account AWS environment using AWS Organizations. The solution must ensure that all CloudTrail logs from all accounts are delivered to a single S3 bucket in the security account. Additionally, the logs must be encrypted with a KMS key that is managed by the security account. Which combination of steps is required?

A.Create a trail in each account, each delivering to the same S3 bucket. Use a bucket policy to allow cross-account writes. Use a single KMS key with appropriate key policy.
B.Use AWS Config to deliver logs to a central bucket. Enable CloudWatch Logs in each account and stream to the security account.
C.Create a trail in the management account with organization trail enabled, delivering to a bucket in the management account. Use KMS default encryption.
D.Create a trail in the security account with organization trail enabled, delivering to a bucket in the security account. Configure bucket policy and KMS key policy to allow CloudTrail and S3 from all accounts.
AnswerA

Correct. Each account's trail sends logs to the central S3 bucket in the security account. The bucket policy allows cross-account writes, and the KMS key policy grants necessary permissions for CloudTrail and S3 from all accounts.

Why this answer

It uses individual trails in each account, all configured to deliver to the same centralized S3 bucket in the security account. A bucket policy can grant CloudTrail write permissions from all accounts, and a single KMS key (managed by the security account) with appropriate key policy ensures encryption. This approach meets the centralized logging and encryption requirements without violating organization trail constraints.

Option B is incorrect because AWS Config does not deliver CloudTrail logs, and CloudWatch Logs streaming is not the required solution. Option C is incorrect because the trail is created in the management account but delivers to a bucket in the management account, not the security account, and it uses default encryption instead of a customer-managed KMS key from the security account. Option D is incorrect because organization trails can only be created in the management account; creating one in the security account is not allowed.

90
Multi-Selectmedium

A security engineer is designing a governance framework for a multi-account AWS environment. The framework must enforce the principle of least privilege for cross-account access. Which TWO strategies should be implemented?

Select 2 answers
A.Enable AWS CloudTrail in all accounts and aggregate logs.
B.Grant full administrative access to a central security group.
C.Use a single IAM user across all accounts for administrative tasks.
D.Use IAM roles with specific permissions and trust policies for cross-account access.
E.Define service control policies (SCPs) that restrict the maximum permissions per account.
AnswersD, E

IAM roles with specific permission policies and trust policies enable cross-account access by allowing principals from a trusted account to assume the role and receive temporary, scoped AWS credentials through the AWS STS AssumeRole API. The role's trust policy specifies which accounts or principals may assume it, while the permission policy limits what those principals can do after assuming it, providing a true least-privilege mechanism. This is the correct approach because it avoids long-lived credentials, enforces the principle of least privilege, and supports conditions such as MFA, source IP, or session tags for further restriction.

Why this answer

IAM roles with specific permissions and trust policies enable cross-account access without sharing long-term credentials. The trust policy defines which accounts can assume the role, and the permissions policy grants only the necessary actions, enforcing the principle of least privilege.

Exam trap

The trap here is that candidates may confuse detective controls (like CloudTrail logging) with preventive controls (like IAM roles and SCPs), or mistakenly think that sharing a single IAM user or granting broad permissions is acceptable for administrative convenience.

91
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to ensure that all newly created accounts automatically have AWS CloudTrail enabled, with logs delivered to a centralized S3 bucket. Which solution meets these requirements with the least operational overhead?

A.Create an SCP that enables CloudTrail and enforces log delivery to the centralized S3 bucket.
B.Use AWS Trusted Advisor to check CloudTrail status and send alerts to the security team.
C.Create an SCP that denies actions to disable CloudTrail and modify the S3 bucket policy. Use AWS CloudFormation StackSets to deploy a CloudTrail trail in each account.
D.Use AWS Config rules with auto-remediation to enable CloudTrail in each account.
AnswerC

StackSets with service-managed permissions automatically deploy the CloudTrail trail to every account, including newly created ones, satisfying the automatic-enablement constraint with minimal overhead. The SCP complements this by preventing trail deletion or bucket-policy tampering, enforcing immutability across the organisation without per-account scripting.

Why this answer

The correct answer. SCPs cannot enable CloudTrail, but they can prevent disabling it and modifying the S3 bucket policy. To actually enable CloudTrail across all accounts with minimal overhead, AWS CloudFormation StackSets can deploy a CloudTrail trail in each account automatically.

Option A is incorrect because SCPs cannot enable services—they only deny or allow actions. Option B is incorrect because AWS Trusted Advisor only checks and alerts; it does not enforce configurations. Option D is incorrect because AWS Config rules with auto-remediation can work but involve more setup and overhead compared to using StackSets, which is purpose-built for deploying resources across multiple accounts.

Therefore, C provides the least operational overhead.

92
MCQeasy

A company wants to ensure that all IAM users have multi-factor authentication (MFA) enabled. Which AWS service can be used to detect users without MFA and automatically send a notification?

A.AWS Trusted Advisor
B.AWS CloudTrail
C.AWS Config
D.AWS IAM
AnswerC

AWS Config continuously records configuration items for IAM users and supports the managed rule iam-user-mfa-enabled, which evaluates whether each IAM user has MFA enabled and marks noncompliant users in the Config dashboard. When a user becomes noncompliant, Config can publish evaluation results to Amazon SNS, triggering notifications or automated remediation via Systems Manager Automation. It also provides configuration history and snapshots so you can audit MFA status over time, making it the correct service for continuously verifying that all IAM users have multi-factor authentication.

Why this answer

AWS Config is the correct answer because it provides a managed rule 'iam-user-mfa-enabled' that can evaluate whether IAM users have MFA enabled. When a non-compliant user is detected, AWS Config can trigger an SNS notification to alert administrators. AWS Trusted Advisor (option A) only checks MFA on the root account, not all IAM users.

AWS CloudTrail (option B) records API activity but does not evaluate configuration rules. AWS IAM (option D) itself does not have automatic detection and notification capabilities for MFA status.

93
MCQeasy

A company wants to centrally manage backups for Amazon RDS instances across multiple AWS accounts. Which AWS service should be used to automate the creation and enforcement of backup policies?

A.S3 Lifecycle policies
B.AWS Backup
C.AWS CloudTrail
D.AWS Systems Manager
AnswerB

AWS Backup is the correct service because it provides a centralized, fully managed backup layer that can govern Amazon RDS databases across accounts and Regions. You define backup plans with schedules, lifecycle rules, and a retention period, then assign resources by tags or ID. It also supports cross-account backup copying and integration with AWS Organizations, enabling consistent backup compliance and centralized recovery point management for RDS workloads.

Why this answer

AWS Backup allows centralized backup policies across accounts and regions. Option A is wrong because S3 Lifecycle policies are for object lifecycle, not RDS backups. Option C is wrong because CloudTrail is for auditing API calls.

Option D is wrong because Systems Manager is for operational management, not backup policies.

94
Multi-Selecteasy

A company is using AWS Organizations and wants to restrict the use of specific AWS services in member accounts. Which TWO approaches can be used to enforce these restrictions? (Choose TWO.)

Select 2 answers
A.Use Service Quotas to limit the number of resources per service.
B.Enable AWS CloudTrail to log service usage.
C.Apply a service control policy (SCP) to the organizational unit (OU).
D.Create IAM policies in each member account to deny access to the services.
E.Use AWS Config rules to automatically terminate resources.
AnswersC, D

Applying an SCP to the OU is the correct preventive control at the AWS Organizations level. An SCP can explicitly deny actions for all AWS services or specific services (e.g., ec2:*) across every member account under that OU, and it applies to all IAM principals including the root user. SCPs operate at the account boundary as an allowlist or denylist, and effective permissions are the intersection of the SCP and the IAM identity/resource policies, ensuring that a centrally defined deny cannot be bypassed by per-account IAM policies.

Why this answer

Option C is correct because service control policies (SCPs) in AWS Organizations define the maximum available permissions for accounts in an OU, and an SCP that denies access to specific AWS services will block those services for all principals in the affected member accounts (except the management account). Option D is correct because IAM policies attached to users, groups, or roles in each member account can include explicit Deny statements for the actions of the services to be restricted, thereby enforcing the restriction at the identity level within that account. Option A is not correct because Service Quotas only cap the quantity of resources or API rates per service; they do not block the use of a service.

Option B is not correct because AWS CloudTrail only records API activity for auditing and does not enforce any restriction. Option E is not correct because AWS Config rules evaluate and report on resource compliance; they detect and can trigger remediation, but they do not themselves prevent or terminate service usage as an enforcement mechanism.

Exam trap

SCS-C02 often tests service restriction methods, and candidates may select Service Quotas or CloudTrail, which do not enforce restrictions.

95
MCQeasy

A security engineer needs to ensure that all IAM policies in an AWS account are evaluated for overly permissive access, such as wildcard actions or resources, before they are attached to IAM roles. The engineer wants to automate this check and receive alerts when noncompliant policies are detected. Which AWS service should the engineer use?

A.Amazon GuardDuty
B.AWS Identity and Access Management Access Analyzer
C.AWS Security Hub
D.AWS Trusted Advisor
AnswerB

IAM Access Analyzer analyzes resource policies and IAM policies to identify overly permissive access, including wildcard actions and resources. It can generate findings and provide alerts, helping automate the detection of noncompliant policies. This directly addresses the requirement to evaluate policies before attachment.

Why this answer

IAM Access Analyzer is designed to analyze IAM policies and resource policies to identify overly permissive access, including wildcard actions and resources. It provides findings and can be integrated with other services for alerts, making it the correct choice for automating policy evaluation.

Exam trap

The trap here is confusing IAM Access Analyzer with AWS Security Hub, which aggregates findings but does not perform the policy analysis itself.

96
MCQmedium

A company has a requirement to automatically rotate secrets for an RDS database every 90 days. The secrets are stored in AWS Secrets Manager. Which resource should be configured to perform the rotation?

A.CloudWatch Logs subscription filter
B.Amazon EventBridge scheduled rule
C.AWS Config rule
D.AWS Lambda function
AnswerD

AWS Secrets Manager uses a Lambda function as the compute engine for its native rotation feature. When rotation is triggered, Secrets Manager invokes the Lambda function with different stages (createSecret, setSecret, testSecret, finishSecret) to generate and store a new secret value and update the associated service or database. You must provide the Lambda function with an IAM role that has permissions to access the secret and the target resource, and for private resources, it must be attached to a VPC. This is why the correct answer is the Lambda function, not a scheduling or compliance service.

Why this answer

AWS Secrets Manager uses a Lambda function to perform the actual rotation of secrets. When you configure rotation for a secret, you specify a Lambda function that implements the rotation logic, including creating a new secret version, updating the database credentials, and testing the new credentials. The Lambda function is invoked by Secrets Manager on the schedule you define (e.g., every 90 days).

Thus, the resource that performs the rotation is the Lambda function.

Exam trap

SCS-C02 often tests the misconception that EventBridge or other services directly rotate secrets, when in fact Secrets Manager relies on a Lambda function to perform the rotation logic.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs subscription filters are used to route log events to other services like Lambda or Kinesis, not to perform secret rotation. Option B is wrong because an EventBridge scheduled rule can trigger actions on a schedule, but it does not itself rotate secrets; it could be used to invoke a Lambda function, but the rotation logic still resides in the Lambda function. Option C is wrong because AWS Config rules evaluate resource configurations for compliance, they do not perform active rotation of secrets.

97
MCQmedium

A security engineer is configuring an S3 bucket policy to restrict access to only requests that originate from a specific VPC endpoint. Which condition key should be used?

A.aws:VpcSourceIp
B.aws:SourceVpc
C.aws:SourceIp
D.aws:SourceVpce
AnswerD

aws:SourceVpce is the correct condition key because it directly evaluates the VPC endpoint ID (for example, vpce-0123abc) from which the S3 request originated. Combining a bucket policy that allows a principal like "*" with the condition "aws:SourceVpce": "vpce-0123abc" ensures the bucket is accessible only via that specific gateway or interface endpoint. Requests from the internet, other endpoints, or on-premises networks do not have the matching SourceVpce value and are denied, giving you precise, endpoint-level access control.

Why this answer

The aws:SourceVpce condition key is the correct choice because it evaluates the VPC endpoint ID (e.g., vpce-12345678) through which the request reached S3. When you attach a bucket policy that includes a condition like "aws:SourceVpce": "vpce-abc123", S3 only allows requests that traverse that specific endpoint, effectively locking the bucket to your private VPC endpoint and blocking all public internet access. This is the standard pattern for enforcing private-only access to S3 from a VPC.

Exam trap

SCS-C02 often tests the confusion between aws:SourceVpc (the VPC ID) and aws:SourceVpce (the endpoint ID), tricking candidates into choosing the broader VPC-level condition when the question specifically asks to restrict to a VPC endpoint.

How to eliminate wrong answers

Option A is wrong because aws:VpcSourceIp is not a valid AWS global condition key — the correct key for the source IP of a request coming through a VPC endpoint is aws:SourceIp, and even that does not identify the endpoint itself. Option B is wrong because aws:SourceVpc identifies the VPC ID (e.g., vpc-abc123) that owns the endpoint, not the endpoint itself; it is broader and would allow any endpoint in that VPC, which is less restrictive than pinning to a specific endpoint. Option C is wrong because aws:SourceIp matches the public or private IP address of the requester, not the VPC endpoint; it cannot distinguish traffic that arrived via a specific endpoint and is easily spoofed or misapplied in NAT/proxy scenarios.

98
MCQeasy

A company wants to centrally manage and enforce backup policies for all EC2 instances across multiple AWS accounts. Which AWS service should be used?

A.AWS Config
B.AWS CloudFormation StackSets
C.AWS Backup
D.AWS Systems Manager
AnswerC

AWS Backup is the fully managed, policy-based backup service that centralizes and automates backup scheduling, retention, and cross-region/cross-account copying across AWS services. You define backup plans with rules for frequency and retention, assign resources via tags or resource IDs, and AWS Backup enforces those policies continuously—including creating backups on schedule and enforcing lifecycle transitions to cold storage or expiration. This meets the requirement to centrally manage and enforce backup policies.

Why this answer

AWS Backup is the correct service because it provides a centralized, policy-based solution to define and enforce backup policies across multiple AWS accounts and regions. It integrates with AWS Organizations to manage backups for EC2 instances and other supported resources, ensuring compliance with governance requirements without needing custom scripts or manual processes.

Exam trap

The trap here is that candidates often confuse AWS Config's compliance evaluation (which can detect missing backups) with actual backup enforcement, or they mistakenly think CloudFormation StackSets can schedule backups, but neither service provides the centralized backup lifecycle management that AWS Backup offers.

How to eliminate wrong answers

Option A is wrong because AWS Config is a service for evaluating resource configurations against desired policies (e.g., compliance rules), not for creating or enforcing backup schedules. Option B is wrong because AWS CloudFormation StackSets deploy and manage infrastructure as code across accounts, but they do not natively provide backup lifecycle management or automated backup policies. Option D is wrong because AWS Systems Manager is an operations hub for patch management, automation, and inventory, but it lacks native backup policy enforcement for EC2 instances across multiple accounts.

99
MCQeasy

A security engineer needs to grant a third-party auditor read-only access to all resources in an AWS account for a limited time. The auditor should not be able to make any changes. Which AWS service should the engineer use to provide temporary credentials?

A.AWS IAM Identity Center (successor to AWS Single Sign-On)
B.AWS Identity and Access Management (IAM) with long-term access keys
C.Amazon Cognito identity pools
D.AWS Security Token Service (AWS STS) with AssumeRole
AnswerD

AWS STS AssumeRole provides temporary security credentials with a specified duration. The engineer can create an IAM role with read-only permissions and allow the auditor to assume it, granting time-limited access without long-term credentials. This meets the requirement for temporary, read-only access.

Why this answer

AWS STS AssumeRole is the correct choice because it allows the creation of temporary credentials with a defined expiration and specific permissions. The engineer can create a role with read-only policies and allow the auditor to assume it. This provides secure, time-limited access without distributing long-term credentials.

Other options either provide long-term credentials or are not designed for this use case.

Exam trap

The trap here is thinking that IAM Identity Center is the default for temporary access, but it is intended for workforce SSO and not for external third-party auditors who need direct AWS API access.

100
MCQeasy

A company wants to automatically detect and remediate S3 buckets that are publicly accessible. Which AWS service can be used to evaluate bucket policies against a defined rule and trigger an automated response?

A.Amazon GuardDuty
B.AWS CloudTrail
C.Amazon Inspector
D.AWS Config
AnswerD

AWS Config is the correct service because it continuously records configuration changes for resources like AWS::S3::Bucket and evaluates each bucket policy against managed rules (e.g., s3-bucket-public-read-prohibited) or custom rules written in AWS Lambda. On detecting a noncompliant policy, Config can invoke an automatic remediation action, such as running an SSM Automation document or a custom Lambda function to revert or fix the policy. This gives you native detect-and-remediate capabilities rather than just an audit trail or a threat alert.

Why this answer

AWS Config evaluates resource configurations against rules and can trigger automatic remediation via SSM Automation documents. For S3 public access, the managed rule s3-bucket-public-read-prohibited or s3-bucket-public-write-prohibited can detect noncompliant buckets and invoke a remediation action to block public access.

Exam trap

The trap is confusing GuardDuty (threat detection) with AWS Config (configuration compliance and remediation) — only Config evaluates policies against rules and triggers automated responses.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that identifies malicious activity, not a configuration compliance service that evaluates bucket policies against rules. Option B is wrong because AWS CloudTrail logs API activity for auditing, but does not evaluate configurations or trigger remediation. Option C is wrong because Amazon Inspector assesses vulnerabilities in EC2 instances and container images, not S3 bucket policies.

101
Multi-Selecteasy

Which TWO AWS services can be used to detect and alert on suspicious API activity in real-time? (Choose two.)

Select 2 answers
A.AWS CloudTrail with CloudWatch Events
B.VPC Flow Logs
C.Amazon S3
D.AWS Config
E.Amazon GuardDuty
AnswersA, E

AWS CloudTrail records all API activity across your account, including the identity making the call, source IP, timestamp, and the exact action performed. By creating a CloudWatch Events rule that filters for specific CloudTrail events—such as unauthorized PutBucketPolicy attempts, failed console logins, or IAM privilege escalation patterns—you can trigger near-real-time alerts through Amazon SNS, Lambda, or AWS Chatbot. This combination provides a native, low-latency pipeline to both detect and alert on suspicious management-plane activity.

Why this answer

AWS CloudTrail with CloudWatch Events (A) is correct because CloudTrail records every API call as a management or data event, and CloudWatch Events (now EventBridge) can match those events in near real-time using rules and trigger alerts via SNS, Lambda, or other targets, enabling detection of suspicious API activity as it happens. Amazon GuardDuty (E) is correct because it continuously analyzes CloudTrail management events, VPC Flow Logs, and DNS logs with threat intelligence and machine learning to detect anomalous or malicious API activity and generate findings in real time. VPC Flow Logs (B) only capture IP traffic metadata at the network interface level, not API-level activity, so they cannot directly detect suspicious API calls.

Amazon S3 (C) is an object storage service and provides no native detection or alerting for API activity. AWS Config (D) evaluates resource configuration compliance and records configuration changes, but it is not designed for real-time detection and alerting on suspicious API behavior.

Exam trap

SCS-C02 often tests the distinction between network-level monitoring (VPC Flow Logs) and API-level monitoring (CloudTrail/GuardDuty), causing candidates to select VPC Flow Logs for API activity detection.

102
Multi-Selecthard

A company wants to centrally manage and enforce security policies across multiple AWS accounts using AWS Organizations. Which THREE actions should be taken? (Choose three.)

Select 3 answers
A.Use the root user of each member account for administrative tasks.
B.Enable all features in AWS Organizations and create service control policies (SCPs) to restrict actions.
C.Use AWS CloudTrail to log API calls in all accounts and deliver logs to a centralized S3 bucket.
D.Create IAM roles in member accounts that grant cross-account access from the management account.
E.Disable CloudTrail in member accounts to reduce costs.
AnswersB, C, D

Enabling all features in AWS Organizations and creating service control policies (SCPs) is the foundational step for central governance because SCPs apply boundary limits across every principal in member accounts, including the root user, without needing to log in to each account. SCPs can deny high-risk actions such as disabling CloudTrail, deleting IAM roles, or leaving the organization, and they work alongside IAM policies to enforce a global guardrail.

Why this answer

Option B is correct because enabling all features in AWS Organizations unlocks advanced governance capabilities, including service control policies (SCPs), which are the mechanism for centrally restricting the maximum available permissions across member accounts. Option C is correct because AWS CloudTrail provides centralized audit logging of API activity; creating a trail that applies to all accounts and delivers logs to a single S3 bucket in a central account gives the company visibility and evidence of policy enforcement across the organization. Option D is correct because IAM roles in member accounts with trust policies allowing the management account to assume them enable secure cross-account administration without sharing long-term credentials, which is the recommended pattern for centralized management.

Option A is not appropriate because the root user of each member account should not be used for routine administrative tasks; it has unrestricted permissions, cannot be constrained by SCPs, and should be protected with MFA and reserved for break-glass scenarios. Option E is incorrect because disabling CloudTrail in member accounts would eliminate the audit trail needed to verify and enforce security policies, undermining the centralized governance goal.

Exam trap

SCS-C02 often tests the misconception that root users are needed for cross-account administration — candidates forget that IAM roles with trust policies are the secure, auditable alternative.

103
MCQmedium

A security engineer is auditing an S3 bucket policy that allows cross-account access. The engineer wants to ensure that only encrypted connections are permitted. Which condition should be added to the policy?

A.aws:SourceIp
B.aws:Referer
C.aws:SecureTransport
D.s3:x-amz-server-side-encryption
AnswerC

The aws:SecureTransport condition key evaluates whether the request arrived over TLS, returning false for plain HTTP. Adding it with a Boolean false value denies unencrypted access, satisfying the stem's requirement that only encrypted connections reach the cross-account bucket.

Why this answer

The aws:SecureTransport condition key evaluates to true when the request is made over HTTPS/TLS and false over HTTP. Adding a Deny statement with 'aws:SecureTransport: false' ensures that any non-TLS request to the bucket is rejected, enforcing encrypted connections.

Exam trap

The trap is confusing in-transit encryption (aws:SecureTransport) with at-rest encryption (s3:x-amz-server-side-encryption); candidates who pick the latter misunderstand which layer the condition controls.

How to eliminate wrong answers

Option A is wrong because aws:SourceIp restricts access by source IP address, not by transport encryption; it does not prevent HTTP requests from an allowed IP. Option B is wrong because aws:Referer checks the HTTP Referer header, which is trivially spoofable and unrelated to encryption enforcement. Option D is wrong because s3:x-amz-server-side-encryption checks the encryption algorithm requested for the object at rest, not whether the connection itself is encrypted in transit.

104
MCQeasy

A security engineer needs to grant cross-account read access to an S3 bucket in Account A to a user in Account B. What is the correct combination of actions?

A.Attach an IAM policy to the user in Account B allowing the action; no bucket policy needed
B.Apply a bucket policy in Account A granting access to the user in Account B; no user policy needed
C.Use S3 bucket ACLs to grant READ access to the Account B user
D.Apply a bucket policy in Account A granting access to the principal in Account B, and attach an IAM policy to the user in Account B allowing the action
AnswerD

This is the correct and complete solution. For cross-account S3 access, AWS requires that both the resource-based policy (bucket policy) in Account A and the identity-based policy (IAM policy) attached to the user in Account B explicitly allow the s3:GetObject action. The bucket policy grants the Account B principal access to the bucket, while the IAM policy provisions that principal with the necessary action permissions in its own account. Without either side, the request is denied. This dual-policy requirement ensures both the resource owner and the caller's account are aligned.

Why this answer

Cross-account S3 access requires both a bucket policy in the resource account (Account A) that explicitly grants the cross-account principal (the user in Account B) the s3:GetObject action, and an IAM policy attached to the user in Account B that allows the same action. This two-way authorization is necessary because the bucket policy controls access to the S3 resource, while the IAM policy controls the user's permissions to initiate the request. Without both, the request will be denied by either the resource-based policy or the identity-based policy.

Exam trap

The trap here is that candidates often assume either a bucket policy alone or an IAM policy alone is sufficient for cross-account access, failing to recognize that AWS requires both the resource-based policy to grant access to the external principal and the identity-based policy to authorize the user to make the request.

How to eliminate wrong answers

Option A is wrong because an IAM policy alone in Account B cannot grant access to a resource in Account A; the resource owner must also allow access via a bucket policy or ACL. Option B is wrong because a bucket policy alone in Account A is insufficient; the user in Account B must also have an IAM policy that permits the s3:GetObject action, otherwise the request is denied by the user's own account. Option C is wrong because S3 bucket ACLs are legacy and do not support granting access to individual IAM users in another account; they only support AWS accounts or predefined groups, and are generally superseded by bucket policies for cross-account access.

105
MCQhard

A company wants to enforce that all S3 buckets are encrypted with SSE-KMS. Which AWS service can be used to automatically remediate non-compliant buckets?

A.AWS CloudTrail with CloudWatch Events
B.AWS Service Catalog
C.AWS Config with auto-remediation
D.AWS Organizations
AnswerC

AWS Config with auto-remediation is the correct choice because it continuously evaluates bucket configuration against a managed rule such as s3-bucket-server-side-encryption-enabled. When a bucket is non-compliant, Config automatically triggers a Systems Manager Automation document, often AWS-EnableS3BucketEncryption, to enable SSE-S3 or SSE-KMS on that bucket. This provides a closed-loop detective-and-remediative workflow that handles both newly created and already-existing unencrypted buckets.

Why this answer

AWS Config with auto-remediation can enforce that all S3 buckets are encrypted with SSE-KMS. You create an AWS Config rule (e.g., s3-bucket-server-side-encryption-enabled) that evaluates bucket encryption settings, and attach an AWS Systems Manager Automation document (e.g., AWS-EnableS3BucketEncryption) as a remediation action. When a non-compliant bucket is detected, AWS Config automatically triggers the remediation action to enable SSE-KMS encryption on that bucket.

Exam trap

The trap here is that candidates may confuse AWS Config's evaluation and remediation capabilities with AWS CloudTrail's logging and event-driven actions, assuming CloudTrail with CloudWatch Events can automatically fix non-compliance without custom code, but AWS Config is the only service that provides native, automated remediation via managed rules and automation documents.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail with CloudWatch Events can detect API calls (like creating an unencrypted bucket) and trigger a notification or a Lambda function, but it does not provide native auto-remediation; you would need custom code to enforce encryption, making it less direct and not an automatic remediation service. Option B is wrong because AWS Service Catalog is used to create and manage a catalog of approved IT services (e.g., pre-configured S3 buckets with SSE-KMS), but it does not monitor or remediate existing non-compliant buckets; it only governs new resources provisioned through the catalog. Option D is wrong because AWS Organizations provides centralized policy management (e.g., Service Control Policies) to restrict actions like creating unencrypted buckets, but it cannot automatically remediate already non-compliant buckets; it only prevents future violations.

106
MCQmedium

A company needs to audit all changes to IAM policies in its AWS account. Which AWS service should be used to record the change history of IAM policies?

A.Amazon CloudWatch Logs
B.Amazon GuardDuty
C.AWS CloudTrail
D.AWS Config
AnswerC

AWS CloudTrail is the correct choice because it records every management event API call made in your AWS account, including all IAM policy changes such as PutRolePolicy, AttachUserPolicy, DeletePolicy, and CreatePolicy. Each event includes the identity of the caller (user, role, or service), the timestamp, source IP address, request parameters, and response elements, giving you a complete and verifiable audit trail. CloudTrail trails can deliver event logs to an Amazon S3 bucket for long-term retention and optionally to CloudWatch Logs for monitoring. This makes CloudTrail the authoritative service for auditing who changed an IAM policy, when, and what exactly was changed.

Why this answer

AWS CloudTrail is the service that records API activity in an AWS account, including all changes to IAM policies. When an IAM policy is created, modified, or deleted, CloudTrail logs the event with details such as the identity of the caller, the time of the API call, the source IP address, and the request parameters. This makes CloudTrail the authoritative source for auditing IAM policy changes.

Exam trap

SCS-C02 often tests the distinction between AWS Config and CloudTrail: candidates may choose AWS Config because it tracks resource changes, but CloudTrail is specifically for API activity auditing, which includes the 'who, what, when, and where' of IAM policy modifications.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs is a log storage and analysis service; it does not natively record AWS API calls unless CloudTrail or other services deliver logs to it. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes logs (like CloudTrail events) for malicious activity, but it does not provide a raw audit trail of IAM policy changes. Option D is wrong because AWS Config records resource configurations and changes, but it is designed for compliance and configuration history, not for capturing the full API-level audit trail of who made the change and how; CloudTrail is the primary service for API auditing.

107
MCQhard

An organization uses AWS Organizations and wants to restrict the use of specific EC2 instance types across all member accounts. Which policy type should be used to enforce this restriction?

A.Resource-based policy
B.IAM policy
C.Service control policy (SCP)
D.AWS CloudFormation policy
AnswerC

A service control policy (SCP) is a feature of AWS Organizations that you attach to the organization root, an organizational unit (OU), or an individual account to centrally set the maximum permissions available to all principals within those accounts. SCPs do not grant permissions; instead, they act as a permission boundary, and their effects are inherited by all child accounts, making them the only option among these that can consistently restrict services across many accounts at once. For example, you can use an SCP to deny the use of a specific AWS service or the ability to leave the organization, which cannot be accomplished with IAM or resource-based policies alone. This makes the SCP the correct choice for organization-wide service restriction.

Why this answer

Service control policies (SCPs) are the only AWS Organizations policy type that can centrally restrict the maximum available permissions for all accounts in an organization or organizational unit. By attaching an SCP that denies the ec2:RunInstances action for specific instance types (using condition keys like ec2:InstanceType), the organization can enforce the restriction across all member accounts, regardless of their local IAM policies. SCPs do not grant permissions; they only filter them, so they are ideal for guardrails.

Exam trap

The trap is assuming that IAM policies can be used organization-wide or that SCPs grant permissions; candidates must remember that SCPs are guardrails that limit permissions and are the only centralized policy type for multi-account restrictions.

How to eliminate wrong answers

Option A is wrong because resource-based policies are attached to individual resources (e.g., S3 buckets, KMS keys) and cannot enforce organization-wide restrictions on EC2 instance types. Option B is wrong because IAM policies are account-specific and cannot be centrally applied to all accounts in an organization; they also grant permissions rather than restrict them at the organizational level. Option D is wrong because AWS CloudFormation policies do not exist as a policy type; CloudFormation is a service for provisioning resources, not for enforcing permission boundaries.

108
MCQeasy

A company needs to centrally manage access to AWS resources across multiple accounts. Which AWS service should be used to define and enforce a set of common permissions for all accounts in the organization?

A.AWS Directory Service
B.AWS IAM
C.AWS Single Sign-On (SSO)
D.AWS Organizations with SCPs
AnswerD

AWS Organizations with Service Control Policies (SCPs) is the correct mechanism for centrally managing access because SCPs act as organization-wide authorization filters that cap the maximum permissions for every IAM principal—including the root user—in every member account. You can attach SCPs at the root, organizational unit (OU), or account level, and they apply transitively to all child accounts. SCPs do not grant permissions; instead, they explicitly allow or deny API actions, effectively enforcing common compliance guardrails and permission boundaries consistently across the whole organization.

Why this answer

AWS Organizations with Service Control Policies (SCPs) allows you to centrally manage and enforce permissions across all accounts in an organization. SCPs define the maximum permissions for accounts and can be applied to the root, OUs, or individual accounts. Option A (AWS Directory Service) is for managed directory services, not for permissions management.

Option B (IAM) is per-account and does not centrally manage multiple accounts. Option C (AWS SSO) is for federated access, not for enforcing permissions boundaries.

109
MCQhard

A company has an AWS account with a single VPC and multiple subnets. The security team wants to ensure that no network ACL (NACL) allows inbound SSH (port 22) from 0.0.0.0/0. Which AWS service can be used to detect and alert on such non-compliant NACLs?

A.Amazon Inspector
B.Amazon GuardDuty
C.AWS Config
D.AWS CloudTrail
AnswerC

AWS Config continuously records the configuration of supported resources, including Network ACLs and their inbound/outbound rules, as configuration items in a timeline. It then evaluates those config items against managed rules—such as the managed rule 'incoming-ssh-disabled'—or custom Lambda rules that can inspect each NACL entry and mark any ingress rule allowing 0.0.0.0/0 on port 22 as non-compliant. When non-compliance is detected, AWS Config can trigger an Amazon SNS notification for immediate alerting, and it retains a compliance history for auditing, which is exactly what the company needs.

Why this answer

AWS Config continuously records resource configurations and evaluates them against rules, making it the correct service to detect non-compliant NACLs. You can use the managed rule 'nacl-no-unrestricted-ssh-rdp' (or a custom rule) to flag any NACL that allows inbound SSH from 0.0.0.0/0 and trigger alerts via Amazon EventBridge or SNS. This directly addresses the requirement to detect and alert on non-compliant NACLs.

Exam trap

SCS-C02 often tests the distinction between detection services (GuardDuty for threats, Inspector for vulnerabilities) and compliance evaluation services (Config for configuration rules), tempting candidates to pick GuardDuty for configuration issues.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances, container images, and Lambda functions for software vulnerabilities and unintended network exposure — it does not evaluate NACL configuration rules. Option B is wrong because GuardDuty is a threat detection service that analyzes logs (CloudTrail, VPC Flow Logs, DNS) for malicious activity; it does not assess NACL compliance. Option D is wrong because CloudTrail records API activity and changes but does not evaluate whether configurations comply with a policy — it provides the audit trail, not the compliance check.

110
MCQhard

A company uses AWS Organizations and wants to restrict the use of specific AWS services in member accounts. For example, they want to block the use of Amazon Redshift. Which policy type should be used?

A.Service control policies (SCPs)
B.IAM permissions boundaries
C.IAM identity-based policies
D.S3 bucket policies
AnswerA

Service control policies (SCPs) are the correct mechanism because AWS Organizations lets you attach them to the root, OUs, or individual accounts, where they act as an account-wide permission guardrail. An SCP defines the maximum allowed actions for every IAM principal in the account, including the root user, so it can deny entire AWS services across all enrolled accounts. This central, inherited control does not require touching each IAM role or user individually.

Why this answer

Service control policies (SCPs) are used in AWS Organizations to centrally manage permissions across multiple accounts. They can restrict which AWS services and actions are available to member accounts. To block the use of Amazon Redshift in member accounts, an SCP can be applied to the organizational units or accounts that denies the redshift:* actions.

Exam trap

The trap is confusing SCPs with IAM policies; SCPs are specifically for Organizations and apply across accounts, while IAM policies are within a single account.

How to eliminate wrong answers

Option B is wrong because IAM permissions boundaries are used to set the maximum permissions for an IAM entity, but they do not apply across accounts and are not used for service-level restrictions in Organizations. Option C is wrong because IAM identity-based policies are attached to IAM users, groups, or roles and grant permissions within a single account; they cannot be used to restrict services across multiple accounts in an organization. Option D is wrong because S3 bucket policies are resource-based policies that apply only to S3 buckets and cannot block the use of Amazon Redshift.

111
Multi-Selecteasy

A company needs to ensure that its S3 buckets are not publicly accessible. Which TWO AWS services can be used to detect and report on public S3 buckets? (Choose two.)

Select 2 answers
A.Amazon GuardDuty
B.AWS Trusted Advisor
C.AWS Config
D.AWS CloudTrail
E.Amazon Inspector
AnswersB, C

AWS Trusted Advisor includes the 'S3 Bucket Permissions' check, which specifically reviews S3 bucket policies and ACLs for configurations that allow public read or write access, and flags those buckets in the Security category of the dashboard. This is a prescriptive, AWS-managed check that immediately identifies public buckets across your account. The check also differentiates between public access granted by ACLs versus bucket policies, providing focused remediation guidance and making it a first-line tool for this requirement.

Why this answer

AWS Trusted Advisor (option B) checks S3 bucket permissions and reports any bucket that has open access policies, including public read or write access. AWS Config (option C) can evaluate S3 bucket policies against custom or managed rules (e.g., s3-bucket-public-read-prohibited, s3-bucket-public-write-prohibited) to detect noncompliant buckets and trigger remediation. Both services provide detection and reporting capabilities for public S3 buckets.

Exam trap

The trap here is that candidates often confuse Amazon GuardDuty's threat detection capabilities with S3 bucket policy auditing, but GuardDuty does not evaluate bucket permissions for public access; it only detects suspicious API activity after the fact.

112
MCQmedium

A company is implementing a multi-account strategy using AWS Organizations. The security team wants to enforce that all newly created member accounts automatically have an IAM role that allows read-only access to the management account. Which configuration should be used?

A.Create an AWS Lambda function that listens for AWS CloudTrail CreateAccount events and creates the role in the new account.
B.Use AWS CloudFormation StackSets to deploy the role to all existing and future accounts.
C.Use an AWS Config managed rule to evaluate new accounts and trigger a remediation action to create the role.
D.Configure an SCP with the 'iam_role' setting to specify a role name and path to be automatically created in new accounts.
AnswerB

AWS CloudFormation StackSets with service-managed permissions allows you to deploy a stack template that defines the IAM role to every account in your AWS Organization. When you enable automatic deployment and specify the organization-wide or OU-wide target, StackSets automatically deploys the stack to new accounts as they are created. This ensures the role exists in all existing and future accounts without requiring custom orchestration or event-driven logic.

Why this answer

AWS CloudFormation StackSets is the correct service for deploying a common IAM role across multiple accounts, including automatically to new accounts as they are added to the organization. When you create a StackSet with service-managed permissions, you can enable automatic deployments so that the stack instance is created in every new account that joins the target organizational unit (OU). This directly satisfies the requirement to enforce the role's presence in all newly created member accounts without custom automation.

Exam trap

SCS-C02 often tests the misconception that SCPs can create or manage resources, when they are only permission boundaries; candidates may also overlook StackSets' automatic deployment feature for new accounts.

How to eliminate wrong answers

Option A is wrong because building a custom Lambda function to react to CloudTrail CreateAccount events is unnecessarily complex, introduces latency, and requires maintaining event patterns and cross-account permissions; it is not the native, recommended mechanism. Option C is wrong because AWS Config rules evaluate resource compliance and can trigger remediation, but they do not proactively create resources in new accounts; they are reactive and would require a custom remediation action, plus Config must be enabled in each account. Option D is wrong because SCPs are permission guardrails that restrict what principals can do; they do not have an 'iam_role' setting and cannot create IAM roles or any resources.

113
MCQeasy

A company is using AWS Organizations to manage multiple accounts. The security team wants to prevent any IAM user from creating access keys. Which type of policy should be used to enforce this control across all accounts?

A.Service Control Policy (SCP)
B.AWS CloudTrail trail
C.AWS Config managed rule
D.IAM permissions boundary
AnswerA

SCPs are the AWS Organizations feature that centrally controls the maximum allowed permissions for all IAM principals in member accounts. You attach an SCP to the organization root, OUs, or individual accounts, and it applies to every user and role in that account, including the account root user, without requiring per-resource configuration. Because SCPs act as a boundary that IAM policies cannot exceed, they are the effective preventive control to block actions across all accounts in the organization.

Why this answer

Service Control Policies (SCPs) are the only AWS Organizations policy type that can centrally restrict what IAM principals in member accounts are allowed to do, including denying iam:CreateAccessKey across every account in the OU. Because SCPs set the maximum permissions boundary for all identities in the account, an explicit Deny in an SCP overrides any IAM policy that would otherwise grant the action. This makes SCPs the correct mechanism for enforcing a blanket, organization-wide control.

Exam trap

SCS-C02 often tests the misconception that IAM permissions boundaries or AWS Config rules can enforce organization-wide preventive controls, when only SCPs provide centralized, preventive permission filtering across all accounts in an OU.

How to eliminate wrong answers

Option B is wrong because CloudTrail is a logging and auditing service that records API activity; it can detect that an access key was created but cannot prevent the action. Option C is wrong because AWS Config managed rules evaluate resource configuration compliance after the fact and can trigger remediation, but they do not block the iam:CreateAccessKey API call in real time. Option D is wrong because an IAM permissions boundary only limits the maximum permissions of a single IAM user or role to which it is attached; it must be applied per-identity and cannot be enforced organization-wide from a central point.

114
MCQeasy

A security auditor needs to view a list of all IAM users, including their last activity timestamps, for a compliance review. Which AWS service provides this information natively?

A.AWS CloudTrail
B.IAM Access Analyzer
C.AWS IAM credential report
D.AWS Config
AnswerC

The IAM credential report is a CSV exported through the console or via GenerateCredentialReport/GetCredentialReport APIs that lists every IAM user in the account. It includes password last used and rotation status, access key IDs and their last-used/rotation dates, MFA device presence, and whether the user has a password. This report directly answers the auditor's need for a complete, current list of IAM users plus their credential hygiene.

Why this answer

The AWS IAM credential report is a native feature that generates a CSV containing all IAM users, their access keys, password status, MFA status, and key rotation dates including last activity timestamps. It is specifically designed for auditing user credentials and activity, making it the correct choice for a compliance review of last activity.

Exam trap

The trap is confusing activity logging (CloudTrail) with credential inventory (credential report) — candidates pick CloudTrail because it 'shows activity', but it does not natively produce a per-user last-activity list.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity events, not a consolidated list of IAM users with last-activity timestamps — you would have to parse logs manually. Option B is wrong because IAM Access Analyzer identifies resources shared with external entities and validates policies; it does not report user last-activity. Option D is wrong because AWS Config tracks resource configuration changes and compliance, not per-user credential activity timestamps.

115
Multi-Selecthard

Which THREE are best practices for managing security in a multi-account AWS environment? (Choose three.)

Select 3 answers
A.Use SCPs to restrict permissions across accounts.
B.Disable AWS CloudTrail in production accounts to reduce costs.
C.Use a dedicated security account for security tools and audits.
D.Centralize logging in a dedicated security account.
E.Use the root user of each account for administrative tasks.
AnswersA, C, D

SCPs provide central control over every account's permissions by acting as a permission filter on all IAM principals in AWS Organizations' organizational units. They can deny services or actions even if the account's own IAM policies allow them, but they do not grant access themselves; instead, SCPs set a boundary that effects only the accounts they are attached to, ensuring that even root users of member accounts cannot perform unauthorized operations.

Why this answer

Option A is correct because AWS Organizations Service Control Policies (SCPs) are applied at the OU or account level and set the maximum available permissions for all IAM principals in member accounts, providing a centralized guardrail to restrict permissions across accounts. Option C is correct because a dedicated security account isolates security tooling (such as GuardDuty, Security Hub, and IAM Access Analyzer) and audit activities from production workloads, following AWS's recommended multi-account security structure. Option D is correct because centralizing logs in a dedicated security account (often via AWS Organizations CloudTrail organization trails and cross-account log destinations) protects audit data from tampering by account owners and enables unified monitoring and retention.

Option B is incorrect because disabling CloudTrail removes the audit trail needed for incident response, compliance, and forensics; CloudTrail is a foundational detective control, not an optional cost to cut. Option E is incorrect because the root user has unrestricted access that cannot be limited by SCPs or IAM policies, so it should be locked away with MFA and never used for routine administrative tasks; least-privilege IAM roles or federated identities should be used instead.

Exam trap

SCS-C02 often tests the misconception that cost optimization justifies disabling CloudTrail or that root user access is acceptable for admin tasks — both are anti-patterns that violate core security best practices.

116
MCQeasy

A company wants to centrally manage access keys for all IAM users across multiple accounts. Which AWS service should be used to rotate access keys automatically?

A.AWS STS
B.AWS IAM
C.AWS Secrets Manager
D.AWS CloudHSM
AnswerB

AWS IAM is the only service that owns the lifecycle of IAM user access keys through CreateAccessKey, UpdateAccessKey, and DeleteAccessKey APIs. Because IAM does not provide built-in scheduling for rotation, central management must be implemented as custom automation (for example, a Lambda function invoked by Amazon EventBridge) that rotates keys across accounts using IAM APIs. IAM also tracks access key status and last-used metadata, which supports a central auditing and rotation process.

Why this answer

AWS IAM is the service that manages IAM users and access keys. While there is no built-in automatic rotation feature in IAM, you can automate access key rotation using IAM APIs or the AWS CLI. Among the given options, AWS IAM is the correct choice because it directly handles access keys.

AWS STS provides temporary credentials, not access key management. AWS Secrets Manager can store secrets but cannot automatically rotate IAM access keys. AWS CloudHSM is for hardware-based cryptographic key storage.

117
Multi-Selecthard

A company wants to implement least privilege access for a data analytics team that uses Amazon Athena to query data in S3. Which THREE steps should be taken?

Select 3 answers
A.Grant full S3 access to all buckets
B.Grant write access to an S3 bucket for query results
C.Grant access to Amazon Redshift
D.Grant permissions to use Athena workgroups and queries
E.Grant read access to the specific S3 buckets containing the data
AnswersB, D, E

When Athena executes a query, it writes the query results, metadata, and any converted data to a designated S3 location, typically the workgroup's result bucket. Granting write access (for example s3:PutObject and s3:GetObject) to that bucket is a required part of the permission set. Without this, Athena fails with an access denied error after the query runs even if the data was read successfully.

Why this answer

Athena requires a dedicated S3 bucket to store query results, and granting write access to that specific bucket ensures the service can write output without exposing other data. This aligns with least privilege by limiting write permissions to only the necessary location.

Exam trap

The trap here is that candidates often assume Athena requires broad S3 permissions or confuse it with Redshift Spectrum, leading them to select full S3 access or irrelevant Redshift permissions instead of focusing on the specific read and write buckets needed for least privilege.

118
Multi-Selecteasy

Which TWO are valid methods to centrally manage multiple AWS accounts? (Choose two.)

Select 2 answers
A.AWS IAM
B.AWS Service Catalog
C.Amazon Cognito
D.AWS Control Tower
E.AWS Organizations
AnswersD, E

AWS Control Tower is the correct answer because it provides a centralized governance solution specifically for multi-account environments. It automatically sets up a landing zone, provisions accounts through an account factory, and applies preventive and detective guardrails using AWS Organizations and IAM under the hood. Control Tower gives you a single pane of glass for managing account structure and compliance.

Why this answer

AWS Control Tower (D) is correct because it provides a centralized landing zone that automates the setup of a multi-account AWS environment using AWS Organizations, IAM Identity Center, and guardrails (preventive and detective controls) to govern accounts at scale. AWS Organizations (E) is correct because it is the foundational service for centrally managing multiple AWS accounts, allowing consolidated billing, organizational units (OUs), service control policies (SCPs), and centralized policy-based governance across accounts. AWS IAM (A) is not correct because it manages users, groups, roles, and permissions within a single AWS account (or via roles across accounts), not centralized multi-account governance.

AWS Service Catalog (B) is not correct because it lets administrators create and manage approved IT service portfolios for end users, but it does not itself centrally manage multiple AWS accounts. Amazon Cognito (C) is not correct because it provides identity, authentication, and authorization for web and mobile applications, not multi-account AWS management.

Exam trap

SCS-C02 often tests the confusion between IAM (single-account identity) and Organizations/Control Tower (multi-account governance), tempting candidates to pick IAM for central management.

119
MCQeasy

A security engineer is tasked with ensuring that all S3 buckets in an AWS account have versioning enabled. The engineer needs to identify buckets that do not have versioning enabled. Which AWS service is BEST suited for this task?

A.AWS Trusted Advisor
B.AWS CloudTrail
C.IAM Access Analyzer
D.AWS Config
AnswerD

AWS Config provides the managed rule 's3-bucket-versioning-enabled' and continuously records S3 bucket configuration items. When a bucket is created or changed, AWS Config evaluates it against the rule and marks it compliant or noncompliant, allowing you to track versioning status over time. This is the correct service because it performs continuous, account-wide configuration compliance evaluation rather than a one-time or policy-focused check.

Why this answer

AWS Config is the best-suited service because it continuously evaluates resource configurations against desired rules. You can use the managed rule 's3-bucket-versioning-enabled' to identify buckets that do not have versioning enabled, and AWS Config will flag them as non-compliant. This provides an automated, scalable way to audit all buckets in an account.

Exam trap

SCS-C02 often tests the distinction between services that record activity (CloudTrail) and services that evaluate configuration state (AWS Config) — candidates may pick CloudTrail because it logs S3 API calls, but it cannot report on current versioning status.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor provides best-practice checks, including an S3 bucket versioning check, but it is not as granular or customizable as AWS Config for enforcing and remediating specific configurations across all buckets. Option B is wrong because AWS CloudTrail records API activity and management events, not the current configuration state of S3 buckets — it cannot directly tell you which buckets lack versioning. Option C is wrong because IAM Access Analyzer identifies resources shared with external entities, not S3 bucket versioning status.

120
MCQhard

Refer to the exhibit. A security engineer runs the get-trail-status command for a CloudTrail trail. The engineer notices that LatestCloudWatchLogsDeliveryTime is null. What does this indicate?

A.The trail has stopped logging.
B.The trail is not delivering logs to S3.
C.The digest delivery has failed.
D.The trail is not configured to deliver logs to CloudWatch Logs.
AnswerD

The absence of a CloudWatch Logs delivery timestamp (such as LatestCloudWatchLogsDeliveryTime) and the lack of a CloudWatch Logs log group ARN indicate the trail does not have the CloudWatch Logs integration enabled. Trail status returns these fields only when the trail is configured to send events to CloudWatch Logs, which requires an IAM role and explicit log-group setup. Therefore, the trail is not delivering to CloudWatch Logs.

Why this answer

LatestCloudWatchLogsDeliveryTime being null indicates the trail has never delivered logs to a CloudWatch Logs log group — in other words, CloudWatch Logs delivery is not configured for this trail. If delivery were configured and functioning, this field would contain the timestamp of the most recent delivery. A null value specifically means no delivery has occurred, not that delivery failed.

Exam trap

SCS-C02 often tests the distinction between S3 delivery fields and CloudWatch Logs delivery fields in get-trail-status, and candidates assume a null timestamp means logging is broken rather than that the specific integration is unconfigured.

How to eliminate wrong answers

Option A is wrong because a stopped trail would still show a historical LatestCloudWatchLogsDeliveryTime if it had ever delivered; null means it never delivered, and logging status is reflected in other fields like IsLogging. Option B is wrong because S3 delivery status is tracked by separate fields (LatestDeliveryTime, LatestDeliveryAttemptTime), not by the CloudWatch-specific field. Option C is wrong because digest delivery failure would populate error fields like LastDeliveryError rather than leaving the timestamp null.

121
MCQmedium

A company uses AWS Organizations and wants to restrict the AWS Regions in which resources can be created across all member accounts. Which mechanism should be used?

A.Apply a service control policy (SCP) that denies operations in unauthorized regions.
B.Use VPC endpoints to restrict API calls to specific regions.
C.Configure AWS Config rules to detect and delete resources in unauthorized regions.
D.Attach an IAM policy to each user that denies operations in unauthorized regions.
AnswerA

A service control policy (SCP) attached at the organization root or an organizational unit acts as an upper boundary on all IAM principals in every member account, including the account root user. Because member account administrators cannot modify or remove an SCP, adding a Deny statement with a condition such as aws:RequestedRegion not in an allowed list prevents any operation in unauthorized Regions before the API call executes. This is the recommended preventive, centralized control for enforcing regional boundaries across AWS Organizations.

Why this answer

A service control policy (SCP) in AWS Organizations can be used to restrict the AWS Regions in which resources can be created across all member accounts. SCPs define the maximum permissions for accounts and can deny actions in unauthorized regions.

Exam trap

SCS-C02 often tests the use of SCPs for centralized governance. Candidates might choose IAM policies or Config rules, but SCPs are the only mechanism that can enforce restrictions across all accounts in an organization.

How to eliminate wrong answers

Option B is wrong because VPC endpoints are used to privately connect to AWS services, not to restrict regions. Option C is wrong because AWS Config rules can detect non-compliant resources but do not prevent their creation; they are reactive. Option D is wrong because attaching an IAM policy to each user is not scalable and does not enforce restrictions across all accounts centrally.

122
Multi-Selectmedium

A security engineer is designing a solution to protect sensitive data in S3. Which THREE mechanisms can be used to enforce encryption at rest?

Select 3 answers
A.Use an SCP to deny s3:PutObject without encryption
B.Enable default encryption on the S3 bucket
C.Enable cross-region replication
D.Apply a bucket policy that denies PutObject without the x-amz-server-side-encryption header
E.Enable MFA Delete on the S3 bucket
AnswersA, B, D

An SCP is an organization-level policy that can restrict IAM actions across all accounts in an OU. By adding a deny condition that requires the s3:x-amz-server-side-encryption key to be present for s3:PutObject, the SCP effectively blocks any unencrypted upload to S3 in the selected accounts, regardless of IAM permissions. This is a preventive control that cannot be overridden by individual bucket policies or IAM users, providing centralized enforcement for sensitive data.

Why this answer

An SCP (Service Control Policy) can be applied at the organizational level to deny any s3:PutObject action that does not include encryption parameters. This enforces encryption at rest across all accounts in the organization, preventing users from uploading unencrypted objects regardless of individual bucket policies or default encryption settings.

Exam trap

The trap here is that candidates confuse cross-region replication (which copies encrypted objects but does not enforce encryption) with an encryption enforcement mechanism, or they think MFA Delete relates to encryption at rest when it only protects against deletion.

123
MCQeasy

A security engineer applies the above bucket policy to an S3 bucket. What is the effect of this policy?

A.All requests to the bucket are denied regardless of protocol.
B.All requests to the bucket must be made over HTTPS.
C.The policy has no effect because it uses a condition.
D.All requests to the bucket must be made over HTTP.
AnswerB

This policy uses an explicit Deny with a Bool condition that matches when aws:SecureTransport is false, meaning "if the request did not arrive over TLS/HTTPS, deny it." Since S3 evaluates this explicit Deny before any Allow, even a statement allowing s3:GetObject cannot override it for HTTP requests. The net effect is that every successful request to the bucket must be made over HTTPS.

Why this answer

The bucket policy includes a statement that denies all actions (s3:*) when the request does not use HTTPS (aws:SecureTransport is false). This effectively requires all requests to the bucket to be made over HTTPS. Therefore, option B is correct.

Option A is incorrect because the policy does not deny all requests; it only denies non-HTTPS requests. Option C is incorrect because the condition does have an effect. Option D is incorrect because HTTP requests are denied.

124
MCQmedium

A security engineer reviews the above CloudTrail event. Which action should the engineer take FIRST to mitigate a potential security issue?

A.Revert the bucket policy to remove the public access.
B.Delete the bucket to prevent data exposure.
C.Contact the root user to confirm the action.
D.Disable the root user's access keys.
AnswerA

Reverting the bucket policy is the correct immediate action because the CloudTrail event shows a PutBucketPolicy call that assigned public read access (e.g., Principal * and s3:GetObject). The bucket is now publicly readable, so you must restore the previous policy version or edit the policy to remove the public grant. While you should also check S3 Block Public Access settings and audit IAM permissions, undoing the policy change is the direct way to stop the exposure.

Why this answer

The CloudTrail event shows that the root user executed `s3:PutBucketPolicy` to apply a bucket policy that grants public access (e.g., `Principal: "*"` or `Effect: "Allow"` with `Action: "s3:GetObject"`). Reverting the bucket policy to remove public access is the immediate corrective action to stop unauthorized data exposure. This directly addresses the security issue by revoking the public read permissions that were just granted.

Exam trap

The trap here is that candidates may focus on disabling the root user's access keys (Option D) because they associate root user actions with compromised credentials, but the real issue is the bucket policy itself—the root user intentionally or unintentionally made the bucket public, and the immediate fix is to revert that policy.

How to eliminate wrong answers

Option B is wrong because deleting the bucket is an overly destructive action that would cause data loss and disrupt any legitimate workloads; the correct first step is to fix the policy, not destroy the resource. Option C is wrong because the root user is the one who performed the action, so contacting them to 'confirm' wastes time and does not mitigate the ongoing public exposure; the engineer should act immediately to revoke access. Option D is wrong because the root user's access keys are not relevant here—the root user performed the action via the AWS Management Console or the root user's own credentials, and disabling access keys does not revoke the bucket policy that is already in effect.

125
Multi-Selectmedium

A company wants to implement a least-privilege access model for their AWS resources. Which TWO of the following are best practices for achieving this?

Select 2 answers
A.Use a single IAM role for all users in the account.
B.Grant permissions only for the specific actions required.
C.Attach IAM policies to groups rather than individual users.
D.Use conditions in IAM policies to restrict access based on attributes like source IP or time.
E.Always use AWS managed policies instead of customer managed policies.
AnswersB, D

Least privilege means constructing IAM policies that explicitly allow only the exact API actions and resources a principal needs for its job function, denying everything else by default. Each Allow statement should enumerate concrete actions such as s3:GetObject on specific resource ARNs rather than using wildcards like s3:* or Action: "*". This minimizes the blast radius if credentials are compromised and ensures that even legitimate users can only perform the minimum operations required to do their work.

Why this answer

Granting only the necessary permissions is the core of least-privilege. Option D is correct because using conditions to restrict access based on attributes like source IP or time further enforces least-privilege. Option A is wrong because using a single IAM role for all users violates the least-privilege principle by granting excessive permissions.

Option C is wrong because attaching policies to groups is a best practice for manageability, but it does not directly address least-privilege. Option E is wrong because using only AWS managed policies may grant more permissions than needed; customer managed policies can be tailored to specific requirements.

126
MCQeasy

A security engineer needs to automate the response to an AWS CloudTrail log event that indicates a potential security threat. Which AWS service would be most appropriate to orchestrate the automated response?

A.AWS Lambda
B.Amazon Simple Queue Service (SQS)
C.AWS Step Functions
D.Amazon EventBridge
AnswerC

AWS Step Functions is a serverless workflow orchestration service that models security response runbooks as state machines with explicit states for Lambda invocations, AWS API calls, and human approvals. Its built-in retry, timeout, branching, and parallel-execution semantics let the engineer encode conditional decision points and error handling without custom code. This makes it the appropriate service for automating a coordinated, auditable response to CloudTrail events.

Why this answer

AWS Step Functions is a serverless orchestration service that models workflows as state machines, making it ideal for coordinating multi-step, multi-service incident response (e.g., isolate instance → snapshot → notify → create ticket) with retries, branching, and human-approval steps. While Lambda executes individual functions, Step Functions provides the durable orchestration, state tracking, and error handling needed for a reliable automated response. It integrates natively with EventBridge, Lambda, SNS, and security services.

Exam trap

SCS-C02 often tests the distinction between 'trigger' and 'orchestrate'—candidates pick EventBridge or Lambda because they initiate the response, but the question asks for the service that coordinates the multi-step workflow, which is Step Functions.

How to eliminate wrong answers

Option A is wrong because AWS Lambda is a compute service for running individual functions; it can perform a single action but lacks built-in state management, sequencing, and long-running workflow orchestration. Option B is wrong because SQS is a message queue for decoupling producers and consumers, not an orchestration engine—it buffers messages but does not coordinate multi-step response logic. Option D is wrong because EventBridge is an event bus that routes events to targets; it can trigger a workflow but does not itself orchestrate the sequence of remediation actions.

127
Multi-Selecthard

Which THREE AWS services can be used to centrally manage and audit permissions across multiple accounts in AWS Organizations?

Select 3 answers
A.Amazon Inspector
B.AWS Shield
C.AWS IAM Access Analyzer
D.AWS CloudTrail
E.AWS Config
AnswersC, D, E

AWS IAM Access Analyzer provides centralized visibility into resource-based policies across your account or entire AWS organization by continuously generating findings when a resource is shared with external principals. It examines policies attached to S3 buckets, IAM roles, KMS keys, and Secrets Manager secrets, flagging access from outside your organization's trusted boundary. This makes it a core service for monitoring and managing external permission exposure at scale.

Why this answer

AWS IAM Access Analyzer (C) is correct because it continuously analyzes resource policies across accounts in AWS Organizations to identify resources shared with external entities, helping centrally manage and audit permissions. AWS CloudTrail (D) is correct because it records API activity across all accounts in an organization into a centralized trail, enabling auditing of who did what and when for permission-related changes. AWS Config (E) is correct because it continuously assesses and records resource configurations and policy compliance across accounts, allowing centralized auditing of permission-related configuration drift.

Amazon Inspector (A) is not correct because it is a vulnerability management service for EC2, Lambda, and container images, not a permissions auditing tool. AWS Shield (B) is not correct because it is a managed DDoS protection service, unrelated to centrally managing or auditing permissions.

Exam trap

The trap is selecting security services by name association — candidates see 'Inspector' or 'Shield' and assume they relate to permissions, when only Access Analyzer, CloudTrail, and Config actually provide centralized permission auditing.

128
MCQmedium

A security engineer needs to ensure that all API calls made to AWS services are logged for auditing. Which AWS service should be used?

A.AWS Config
B.Amazon VPC Flow Logs
C.AWS CloudTrail
D.Amazon CloudWatch Logs
AnswerC

AWS CloudTrail is the appropriate service for capturing API activity across AWS. It records management events by default, including actions performed through the AWS Management Console, SDKs, CLI, and other services, and can be configured to log data events for services like Amazon S3 and Lambda. Each CloudTrail event provides the identity, timestamp, source IP, request parameters, and response elements, making it the definitive source for API call auditing.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to AWS services, capturing details such as the identity of the caller, the time of the call, the source IP address, request parameters, and response elements. This provides a complete audit trail of user activity and API usage, which is essential for security auditing and compliance.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks configuration changes) with CloudTrail (which logs API calls), or they mistakenly think VPC Flow Logs or CloudWatch Logs are the primary services for API auditing, when in fact CloudTrail is the dedicated service for recording all AWS API activity.

How to eliminate wrong answers

Option A is wrong because AWS Config is designed for resource inventory, configuration history, and compliance rules, not for logging API calls; it tracks changes to resource configurations, not the API actions themselves. Option B is wrong because Amazon VPC Flow Logs capture information about IP traffic going to and from network interfaces in a VPC, such as source/destination IPs and ports, but they do not log AWS API calls. Option D is wrong because Amazon CloudWatch Logs is a service for storing, monitoring, and accessing log files from various sources, but it does not natively capture API calls; it can be used to store CloudTrail logs, but the service that actually generates the API call logs is CloudTrail.

129
MCQmedium

A security team wants to centrally manage and automatically remediate findings across 40 AWS accounts in an organization. They need a solution that aggregates security findings from GuardDuty, Inspector, and Macie into one place and can trigger automated remediation runbooks. Which combination of services BEST meets these requirements?

A.Enable Amazon Detective in all accounts and forward findings to a central S3 bucket, then use AWS Lambda functions triggered by S3 event notifications for remediation.
B.Enable AWS CloudTrail Lake in all accounts and create queries that detect GuardDuty, Inspector, and Macie findings, then use EventBridge Scheduler to run remediation scripts.
C.Enable AWS Security Hub in all accounts with the organization integration, then use Amazon EventBridge rules and AWS Systems Manager Automation runbooks for remediation.
D.Enable AWS Trusted Advisor in all accounts and use AWS Config rules with automatic remediation for findings from GuardDuty, Inspector, and Macie.
AnswerC

Security Hub aggregates findings from GuardDuty, Inspector, and Macie across organization accounts when centralized configuration is enabled. EventBridge can match Security Hub findings and invoke Systems Manager Automation runbooks to remediate automatically. This combination provides both centralized aggregation and automated response, directly satisfying the stated requirements for 40 accounts.

Why this answer

Security Hub with organization integration ingests and normalizes findings from GuardDuty, Inspector, and Macie across all accounts, providing a single aggregation point. EventBridge rules can match Security Hub findings and invoke Systems Manager Automation runbooks for automated remediation. Trusted Advisor, Detective, and CloudTrail Lake do not aggregate these detection findings, and scheduled or S3-triggered remediation lacks native integration.

Exam trap

The trap here is assuming AWS Config automatic remediation can act on GuardDuty, Inspector, or Macie findings, when Config remediation is scoped to Config rules.

130
MCQeasy

A security engineer needs to centrally manage and enforce security policies across multiple AWS accounts in an organization. Which AWS service should they use?

A.AWS CloudFormation StackSets
B.AWS IAM
C.AWS Firewall Manager
D.AWS Organizations with SCPs
AnswerD

AWS Organizations with Service Control Policies (SCPs) is the correct choice because SCPs are centralized policy documents that attach to the organization root, organizational units, or individual accounts and define the maximum allowed permissions for all IAM principals in those accounts. SCPs act as guardrails that restrict what services and actions can be performed, and they are enforced by a central governance layer independent of the account's local IAM administrators. Because SCPs are managed from the management account of the organization, they provide a single point to centrally administer and enforce security policies across every member account.

Why this answer

AWS Organizations with Service Control Policies (SCPs) allows central policy management across accounts. Firewall Manager focuses on VPC security, not general policies.

131
MCQhard

A security engineer notices that an IAM user has been performing suspicious actions in an AWS account. The engineer needs to generate a credential report to identify the age of the user's access keys. Which AWS CLI command should the engineer run?

A.aws iam get-account-authorization-details
B.aws iam generate-credential-report && aws iam get-credential-report
C.aws iam generate-service-last-accessed-details
D.aws iam list-access-keys --user-name suspectUser
AnswerB

The generate-credential-report command starts an asynchronous job in IAM, and then get-credential-report downloads the completed CSV file. The report contains columns such as access_key_1_last_rotated, access_key_2_last_rotated, and password_last_rotated, which directly provide the age of every key and password in the account. This is the standard, account-wide method for determining stale access keys and exactly satisfies the need to identify the age of a user's access key.

Why this answer

The AWS CLI command to generate and retrieve an IAM credential report is a two-step process: first run 'aws iam generate-credential-report' to trigger report generation, then run 'aws iam get-credential-report' to retrieve it. The report includes access key age, password age, MFA status, and other credential metadata for all IAM users, which is exactly what the engineer needs.

Exam trap

SCS-C02 often tests the confusion between 'list-access-keys' (which shows key IDs and status but not age) and the credential report (which includes creation/rotation dates), causing candidates to pick the simpler but insufficient command.

How to eliminate wrong answers

Option A is wrong because 'aws iam get-account-authorization-details' returns IAM policies, roles, groups, and users but does not include credential age or access key rotation information. Option C is wrong because 'aws iam generate-service-last-accessed-details' generates a report on which services and actions were last accessed by an IAM entity, not credential age. Option D is wrong because 'aws iam list-access-keys' lists access key IDs and status (Active/Inactive) for a user but does not provide the creation date or age of the keys — the credential report is required for age data.

132
MCQeasy

A company's security team wants to receive alerts when an IAM user creates a new access key. Which AWS service can be used to monitor and notify on this specific API call?

A.AWS Trusted Advisor
B.Amazon GuardDuty
C.AWS CloudTrail with Amazon CloudWatch Events
D.AWS Config
AnswerC

AWS CloudTrail records every API call made by an IAM user or role, and delivering those trail events to Amazon CloudWatch Events (now EventBridge) enables custom rules that match exact API actions and principals. A rule can filter on eventName, userIdentity, and request parameters, then invoke an SNS topic to notify the security team in near real time. This is the only option that directly reacts to specific API activities rather than aggregate state or threats.

Why this answer

CloudTrail logs IAM CreateAccessKey events, and CloudWatch Events can trigger a notification. Option A is wrong because Trusted Advisor is for best practices. Option B is wrong because GuardDuty is for threat detection.

Option D is wrong because AWS Config is for resource compliance.

133
MCQmedium

A security engineer is designing a solution to enforce that all S3 buckets in an AWS account have server-side encryption enabled. The engineer needs to automatically remediate any non-compliant buckets. Which AWS service should be used to implement this requirement?

A.AWS Lambda with S3 events
B.AWS Config with managed rules and auto-remediation
C.AWS IAM policy to deny PutBucketEncryption without encryption
D.AWS CloudTrail
AnswerB

The correct solution is AWS Config with a managed rule such as s3-bucket-server-side-encryption-enabled, which continuously evaluates whether each bucket has default encryption enabled. When a bucket is noncompliant, AWS Config can invoke auto-remediation using an SSM Automation document like AWS-EnableS3BucketEncryption to apply SSE-S3 or SSE-KMS. This provides both detection and automated correction, unlike event-driven or logging-only approaches.

Why this answer

AWS Config continuously evaluates resource configurations against rules, and managed rules such as s3-bucket-server-side-encryption-enabled detect non-compliant buckets; Config remediation actions can then invoke SSM Automation documents or Lambda to automatically re-enable encryption. This provides both detection and automatic remediation in a single managed service, which is exactly what the requirement asks for.

Exam trap

SCS-C02 often tests the misconception that CloudTrail or IAM policies can enforce encryption compliance — candidates must distinguish detective/remediative services (Config) from logging (CloudTrail) and preventive but limited controls (IAM).

How to eliminate wrong answers

Option A is wrong because Lambda with S3 events reacts to object-level events, not to configuration state changes like encryption being disabled; it would require custom logic and does not provide continuous compliance evaluation. Option C is wrong because an IAM policy denying PutBucketEncryption without encryption is not a valid condition — IAM cannot inspect the encryption parameters of the request in that way, and it does not remediate existing non-compliant buckets. Option D is wrong because CloudTrail only records API activity; it does not evaluate compliance or remediate resources.

134
MCQeasy

A developer needs to grant an IAM user read-only access to an S3 bucket containing sensitive data. The bucket is encrypted with an AWS KMS customer managed key. Which set of permissions must be included in the IAM policy?

A.s3:GetObject, kms:Encrypt
B.s3:GetObject, kms:Decrypt
C.kms:Decrypt
D.s3:ListBucket, kms:Decrypt
AnswerB

This pair is correct because reading a KMS-encrypted S3 object is a two-step operation: S3 GetObject retrieves the ciphertext from the bucket, and KMS Decrypt decrypts the envelope-encrypted data key so the object's contents are revealed. The s3:GetObject permission allows the actual read of the object, while kms:Decrypt grants the ability to unwrap the key that protects that object. Together they provide exactly the read-only access required.

Why this answer

To read objects from an encrypted S3 bucket, the user needs both s3:GetObject to retrieve the object and kms:Decrypt to decrypt the object using the KMS key. Option A is wrong because it includes kms:Encrypt instead of kms:Decrypt; decryption is required, not encryption. Option C is wrong because it lacks s3:GetObject permission, which is necessary to retrieve the object.

Option D is wrong because it includes s3:ListBucket, which is not required for reading a specific object, and it lacks s3:GetObject.

135
MCQeasy

A company wants to receive real-time notifications when an IAM user in their AWS account performs a console login. Which AWS service should be used to monitor and alert on this activity?

A.AWS IAM
B.AWS Config
C.AWS Trusted Advisor
D.AWS CloudTrail and Amazon EventBridge
AnswerD

AWS CloudTrail captures all API activity as events, including who made the call, which service, and the result. These events are delivered to Amazon EventBridge in near real time, where a rule can filter for a specific action (for example, `iam:CreateUser` or `sts:AssumeRole`) and route the matched event to an SNS topic or Lambda function to send a notification. Together they provide an event-driven pipeline for real-time alerting on API calls.

Why this answer

AWS CloudTrail logs console login events, and Amazon EventBridge can be used to create rules that trigger notifications (e.g., via SNS) in real-time when such events occur. Option A is incorrect because IAM does not provide monitoring capabilities. Option B is incorrect because AWS Config is designed for tracking resource configuration changes, not API call activity.

Option C is incorrect because Trusted Advisor offers best-practice recommendations and does not provide real-time monitoring of login events.

136
MCQmedium

A security engineer needs to provide a detailed report of all IAM users, their access keys, and the last time each key was used, to identify unused credentials. Which AWS service or feature should the engineer use to generate this report?

A.Amazon GuardDuty
B.IAM credential report
C.AWS CloudTrail logs
D.AWS Trusted Advisor
AnswerB

The IAM credential report provides a CSV file listing all IAM users and the status of their credentials, including passwords, access keys, MFA devices, and the last used date for each. It is the most direct way to obtain the required information for identifying unused credentials.

Why this answer

The IAM credential report is specifically designed to provide a comprehensive list of IAM users and their credential details, including last used information for access keys. It is generated on demand and can be downloaded as a CSV. Other services like CloudTrail, Trusted Advisor, and GuardDuty do not offer this consolidated view, making the credential report the correct choice.

Exam trap

The trap here is thinking that CloudTrail logs can easily provide last used dates for access keys, but CloudTrail logs record API calls, not a summary of credential usage, and would require significant effort to aggregate.

137
Multi-Selectmedium

Which TWO actions should a security engineer take to ensure that an S3 bucket is not publicly accessible? (Choose two.)

Select 2 answers
A.Enable S3 Block Public Access at the account level
B.Enable AWS CloudTrail for the bucket
C.Remove all bucket ACLs
D.Set a bucket policy that denies all public access
E.Enable S3 Block Public Access at the bucket level
AnswersA, E

Enabling S3 Block Public Access at the account level is the definitive control because it applies a centralized, organization-wide guardrail that overrides any per-bucket settings. It blocks public access through all four mechanisms—ACLs, bucket policies, access point policies, and multi-object access point policies—and, once set, cannot be overridden by a bucket policy unless the account-level setting itself is changed. This creates a hard boundary that ensures no bucket in the account can be made publicly accessible, even if a future misconfiguration or a bucket policy explicitly permits public access. The question asks for actions to 'ensure' protection, making this the strongest and most reliable answer as it covers all existing and future buckets.

Why this answer

Block Public Access settings at bucket and account level prevent all public access. The other options are not correct because: ACLs can allow public access; CloudTrail does not block; Bucket policies are overridden by Block Public Access.

138
MCQhard

This SCP is attached to an organizational unit (OU). A developer in an account within the OU tries to launch a t2.small instance. What is the outcome?

A.The launch fails because the SCP denies all RunInstances actions.
B.The launch succeeds because the SCP allows t2.micro only.
C.The launch fails because the SCP denies non-t2.micro instances.
D.The launch succeeds because SCPs do not apply to developers.
AnswerC

The SCP's Deny effect triggers when the ec2:InstanceType condition does not equal t2.micro, typically using StringNotEquals. A t2.small instance does not match t2.micro, so the condition evaluates to true and the Deny takes effect, blocking the RunInstances call. Since SCPs are implicit deny guardrails applied at the OU level, not even the developer's IAM permissions can override this denial, so the launch fails with an unauthorized operation error.

Why this answer

The SCP denies ec2:RunInstances if the instance type is not t2.micro. Since t2.small is not t2.micro, the condition matches, and the action is denied. Option A is wrong because the SCP does not deny all RunInstances actions; it only denies those that do not match the condition.

Option B is wrong because the launch fails, not succeeds. Option D is wrong because SCPs apply to all principals in the account, including developers.

139
Multi-Selectmedium

A company wants to ensure that all Amazon S3 buckets are encrypted at rest. Which THREE services can be used together to automatically remediate unencrypted S3 buckets?

Select 3 answers
A.Amazon S3 default encryption
B.AWS CloudTrail
C.Amazon EventBridge
D.AWS Config
E.AWS Lambda
AnswersC, D, E

Amazon EventBridge is the event-routing backbone of the remediation workflow: it receives compliance state-change events published by AWS Config, such as a bucket transitioning to NON_COMPLIANT for the s3-bucket-server-side-encryption-enabled rule. Using an EventBridge rule, you filter for these S3 compliance events and target an AWS Lambda function for automatic response. Without EventBridge, AWS Config would only generate history or console notifications and would not have a native, low-latency path to invoke custom remediation code.

Why this answer

AWS Config (D) is correct because it continuously evaluates S3 bucket configuration against a managed rule such as s3-bucket-server-side-encryption-enabled and flags buckets that are not encrypted at rest. Amazon EventBridge (C) is correct because it can receive the AWS Config compliance-change event (or a Config rule evaluation result) and route it to a target for automated remediation. AWS Lambda (E) is correct because it serves as the remediation target, running code that calls PutBucketEncryption to enable default encryption on the noncompliant bucket.

Amazon S3 default encryption (A) is not a remediation mechanism by itself; it only defines encryption applied to objects when the bucket setting is enabled, so it cannot detect or fix an unencrypted bucket. AWS CloudTrail (B) records API activity for auditing but does not evaluate resource compliance or trigger automatic remediation.

Exam trap

SCS-C02 often tests the misconception that CloudTrail or S3 default encryption alone can remediate — the trap is forgetting that Config detects, EventBridge routes, and Lambda acts, forming a three-service chain.

140
MCQmedium

A company wants to enforce that all IAM users in an AWS account must have multi-factor authentication (MFA) enabled. Which AWS service can be used to automatically detect and remediate non-compliant users?

A.AWS Trusted Advisor
B.AWS IAM Access Analyzer
C.AWS CloudTrail
D.AWS Config
AnswerD

AWS Config continuously evaluates resources such as AWS::IAM::User against managed rules, and the iam-user-mfa-enabled rule specifically designates IAM users without a registered MFA device as noncompliant. Config can then invoke an AWS Systems Manager Automation document or a custom remediation action to remediate noncompliant IAM users, making it the only listed service that can both detect and act on missing MFA across all IAM users.

Why this answer

AWS Config continuously records resource configurations and evaluates them against rules. A managed rule such as 'iam-user-mfa-enabled' detects IAM users without MFA, and Config remediation actions (via SSM Automation documents) can automatically enforce MFA or disable non-compliant users. This gives both detection and automated remediation in a single service, matching the requirement.

Exam trap

SCS-C02 often tests the difference between services that only detect (Trusted Advisor, Access Analyzer, CloudTrail) and services that both detect and remediate (AWS Config with remediation actions) — candidates pick Trusted Advisor because it sounds like a security advisor.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor only provides advisory checks (including a security category for MFA on the root account) and cannot detect per-user MFA status or perform remediation. Option B is wrong because IAM Access Analyzer identifies resources shared with external entities (S3 buckets, roles, KMS keys) — it does not evaluate MFA compliance. Option C is wrong because CloudTrail only logs API activity; it records events but has no rule-evaluation or remediation capability.

141
MCQhard

A company's security team needs to enforce encryption at rest for all RDS instances in the production account. They have enabled mandatory encryption using a service control policy. What else must be done to ensure existing unencrypted RDS instances are encrypted?

A.Attach a new KMS key policy to the RDS instance.
B.Create a snapshot of the unencrypted instance, copy the snapshot with encryption enabled, and restore the encrypted snapshot to a new DB instance.
C.Enable encryption on the DB subnet group and reboot the instance.
D.Modify the RDS instance to enable encryption using the AWS Console.
AnswerB

This is the standard, supported migration path. First, create a manual snapshot of the unencrypted RDS instance. Then copy that snapshot and select 'Enable encryption' (or specify a KMS key ID), because the copy operation re-encrypts the data at rest. Finally, restore the encrypted snapshot to a new DB instance, redirect application traffic to the new instance, and retire the old unencrypted instance once validation is complete.

Why this answer

RDS does not support directly enabling encryption on an existing unencrypted instance. The only way to encrypt an existing unencrypted RDS instance is to take a snapshot of it, copy the snapshot with encryption enabled, and restore the encrypted snapshot to a new DB instance. Options A, C, and D are incorrect: A: Attaching a new KMS key policy to the RDS instance does not encrypt the instance; encryption is applied at snapshot creation.

C: Enabling encryption on the DB subnet group does not affect existing instances; it only applies to new instances. D: Modifying the RDS instance via the console does not allow enabling encryption on an existing instance; encryption can only be enabled at creation or via snapshot copy.

142
Multi-Selectmedium

A security engineer is auditing IAM policies. The engineer wants to identify if any policy grants 'Effect: Allow' with 'Action: *' and 'Resource: *'. Which TWO AWS services can be used to detect such overly permissive policies?

Select 2 answers
A.AWS CloudTrail
B.AWS Trusted Advisor
C.AWS Config
D.IAM Access Analyzer
E.Amazon GuardDuty
AnswersC, D

AWS Config continuously records resource configurations and evaluates them against managed or custom rules, so a rule can flag IAM policies whose statements contain Action: * with Resource: *. This satisfies the requirement to detect overly permissive policies across accounts.

Why this answer

AWS Config [CORRECT] is right because it continuously evaluates IAM policies against managed or custom rules (e.g., iam-policy-no-statements-with-admin-access) and can flag policies containing Effect: Allow with Action: * and Resource: *, which is exactly the overly permissive pattern being audited. IAM Access Analyzer [CORRECT] is also correct because its policy validation and findings (including checks for overly permissive policies such as those granting full administrative access) can identify policies with Action: * and Resource: * on Allow statements. AWS CloudTrail is not correct because it records API activity and events, not policy permission analysis.

AWS Trusted Advisor is not correct because its security checks focus on broad best-practice items like open ports or MFA, not parsing IAM policy statements for wildcard Action/Resource. Amazon GuardDuty is not correct because it detects suspicious activity and threats from logs, not static IAM policy permissiveness.

Exam trap

The trap is selecting CloudTrail or GuardDuty because they are 'security' services — candidates must distinguish between activity logging/threat detection and policy content analysis, which is the domain of Config and IAM Access Analyzer.

143
MCQhard

A company uses AWS Config to evaluate resource compliance. The security team notices that the AWS::IAM::Group resource type is not supported by AWS Config managed rules. What is the best way to detect IAM groups that have an inline policy allowing 'iam:CreateUser'?

A.Create a custom AWS Config rule using a Lambda function that evaluates IAM groups
B.Use IAM Access Analyzer to identify policies that grant broad access
C.Use AWS CloudTrail Insights to detect CreateUser events
D.Enable AWS Config advanced query and run a query on IAM groups
AnswerA

AWS Config does not natively record IAM groups, so a Lambda-backed custom rule is required. The Lambda function can call the IAM API to retrieve a group's policies and evaluate them against your compliance logic, then report compliance via PutEvaluations. This approach gives you full flexibility to assess inline and attached managed policies for groups, which no managed Config rule can do.

Why this answer

AWS Config managed rules do not support the AWS::IAM::Group resource type, so you cannot use a managed rule to evaluate inline policies on IAM groups. The best approach is to create a custom AWS Config rule backed by a Lambda function that can evaluate the IAM group's inline policies and trigger a compliance check when the group configuration changes. This allows you to detect any inline policy that contains the 'iam:CreateUser' action.

Exam trap

The trap here is that candidates assume AWS Config advanced queries can evaluate any resource type, but AWS Config only supports querying resource types that it records, and IAM groups are not recorded, making Option D ineffective.

How to eliminate wrong answers

Option B is wrong because IAM Access Analyzer is designed to identify resources shared with external entities, not to evaluate inline policies on IAM groups for specific actions like 'iam:CreateUser'. Option C is wrong because AWS CloudTrail Insights detects unusual API activity patterns, not the static configuration of IAM group policies; it would only alert after a CreateUser event occurs, not proactively detect the policy. Option D is wrong because AWS Config advanced queries can query resource configuration data, but they cannot evaluate inline policies on IAM groups since AWS Config does not support the AWS::IAM::Group resource type for configuration recording or querying.

144
MCQhard

A company's Security team is using AWS Organizations with a consolidated billing account. The security team wants to ensure that all member accounts have AWS CloudTrail enabled and that logs are delivered to a central S3 bucket in the management account. Which combination of actions should the security team take? (Choose the best answer.)

A.Use AWS Config rules to detect when CloudTrail is disabled.
B.Create a new IAM policy that requires each account owner to enable CloudTrail.
C.Enable CloudTrail in the management account only and use cross-account logging.
D.Use an SCP to deny disabling CloudTrail and use CloudFormation StackSets to deploy CloudTrail in all accounts.
AnswerD

An SCP such as 'DenyCloudTrailDisable' can be attached to the root or OU to explicitly deny cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail (along with PutEventSelectors actions that could stop recording), preventing any principal—including the root user—from disabling the trail. CloudFormation StackSets then deploys a consistent multi-region trail template to every account in the organization, automatically creating the required trail, S3 bucket, and bucket policy. Because SCPs are evaluated in addition to IAM policies and cannot be overridden by account admins, this combination provides both automated enablement and a hard preventive boundary.

Why this answer

Using an SCP to deny disabling CloudTrail and a CloudFormation StackSet to deploy CloudTrail in each account ensures enforcement and deployment across all member accounts. Option A is wrong because AWS Config rules can detect but not prevent disabling of CloudTrail. Option B is wrong because an IAM policy requiring account owners to enable CloudTrail is not enforceable and relies on individual action.

Option C is wrong because enabling CloudTrail only in the management account does not enable it in member accounts; cross-account logging requires member accounts to have CloudTrail configured.

145
MCQeasy

A company has an AWS account with multiple S3 buckets that contain sensitive data. The security team wants to ensure that no public access is granted to any bucket. The team has enabled AWS Config and set up a rule to detect public buckets. The rule reports that all buckets are compliant. However, during a security review, a team member finds that one bucket has a bucket policy that grants 's3:GetObject' to 'Principal': '*'. Why did the AWS Config rule not detect this?

A.AWS CloudTrail must be enabled for Config to evaluate policies.
B.The AWS Config rule only checks ACLs, not bucket policies.
C.The bucket is in a different AWS account.
D.IAM Access Analyzer must be enabled first.
AnswerB

The managed rule s3-bucket-public-read-prohibited inspects the bucket's access control list (ACL) for grants to AllUsers or AuthenticatedUsers and reports NON_COMPLIANT only if those ACL grants are present. It does not parse or evaluate bucket policies, even though bucket policy statements with Principal '*' can also enable public read access. Therefore a bucket with a private ACL and a public bucket policy will show COMPLIANT even though it is actually publicly readable.

Why this answer

The AWS Config managed rule 's3-bucket-public-read-prohibited' only checks for public read access via ACLs, not bucket policies. Therefore, a bucket policy granting 's3:GetObject' to 'Principal': '*' would not be flagged as non-compliant by this rule. To detect public access via bucket policies, a custom AWS Config rule or other mechanisms like IAM Access Analyzer are needed.

Option A is incorrect because CloudTrail logs API calls but does not evaluate compliance. Option C is incorrect because the bucket is in the same account as per the scenario. Option D is incorrect because IAM Access Analyzer can analyze policies but does not enforce compliance rules.

146
Multi-Selecthard

Which THREE AWS services can be used to centrally manage security across multiple accounts? (Select THREE.)

Select 3 answers
A.AWS Config
B.AWS Shield
C.AWS CloudTrail
D.Amazon GuardDuty
E.AWS Organizations
AnswersA, C, E

Config can aggregate rules and compliance across accounts.

Why this answer

AWS Config is correct because it provides a centralized view of resource configurations and compliance across multiple accounts when integrated with AWS Organizations. By enabling Config in the management account and using aggregation authorizations, you can aggregate configuration and compliance data from all member accounts into a single administrator account, enabling centralized security governance.

Exam trap

The trap here is that candidates confuse services that aggregate findings (like GuardDuty with Organizations) with services that centrally manage security policies and configurations, leading them to select GuardDuty instead of recognizing that only AWS Config, AWS CloudTrail (for centralized logging), and AWS Organizations (for policy-based governance) provide true centralized management.

147
Multi-Selectmedium

Which TWO actions should a security engineer take to protect root user credentials? (Select TWO.)

Select 2 answers
A.Use the root user only for billing
B.Share the root user credentials with the security team
C.Do not create access keys for the root user
D.Enable MFA on the root user account
E.Delete the root user account
AnswersC, D

Access keys for the root user are long-term static credentials that bypass the password and MFA protections on the AWS console, enabling direct API calls with full account authority. AWS explicitly warns that root access keys cannot be rotated like IAM user keys and can only be deleted, making any leak a catastrophic risk. Avoiding root access keys entirely -- and using temporary credentials from IAM roles or federation -- is the recommended safeguard.

Why this answer

AWS strongly recommends that you do not create access keys for the root user. Access keys provide programmatic access to the AWS API, and if compromised, an attacker would have unrestricted access to all AWS resources and billing information. By not creating access keys, you eliminate this high-risk attack vector.

Exam trap

The trap here is that candidates often think the root user can be deleted or that using it only for billing is acceptable, but AWS explicitly prohibits deleting the root user and recommends using IAM users with billing permissions instead.

148
MCQmedium

A company wants to automatically detect and notify about any S3 buckets that have public read access. Which combination of services should be used?

A.AWS CloudTrail and AWS Lambda
B.AWS Config and Amazon EventBridge
C.AWS IAM Access Analyzer and Amazon CloudWatch
D.AWS Trusted Advisor and Amazon SES
AnswerB

AWS Config rules continuously evaluate bucket policies and ACLs, flagging any bucket granting public read access as noncompliant. EventBridge then routes those compliance-change events to a notification target, delivering the automatic detection and alerting the stem requires without polling.

Why this answer

AWS Config continuously records S3 bucket configurations and can evaluate them against managed rules such as 's3-bucket-public-read-prohibited', flagging any bucket with public read access as non-compliant. Amazon EventBridge can then route Config's compliance change events to targets like SNS or Lambda for notification. This combination provides both detection and automated notification without custom code.

Exam trap

SCS-C02 often tests the distinction between services that log activity (CloudTrail) versus services that evaluate configuration state (Config) — candidates frequently pick CloudTrail for detection questions when Config is the correct answer.

How to eliminate wrong answers

Option A is wrong because CloudTrail only logs API activity (who did what and when) — it does not evaluate resource configuration state, so it cannot detect that a bucket currently has public read access. Option C is wrong because IAM Access Analyzer identifies resources shared with external entities (including public S3 buckets) but does not natively emit EventBridge events for notification workflows in the same compliance-driven way, and CloudWatch alone does not evaluate S3 bucket policies. Option D is wrong because Trusted Advisor offers a limited set of checks (including S3 bucket permissions) but is not designed for continuous, event-driven detection and notification, and SES is an email service, not a notification router for compliance events.

149
MCQhard

A company uses AWS Organizations with all features enabled. The security team needs to ensure that no member account can disable AWS CloudTrail logging or delete CloudTrail logs stored in S3. Which combination of preventive controls should be implemented?

A.Set up CloudWatch alarms to notify when CloudTrail is modified or logs are deleted.
B.Apply a service control policy (SCP) at the root OU to deny CloudTrail and S3 delete actions, and enable CloudTrail organizational trail.
C.Use IAM policies in each member account to deny CloudTrail and S3 delete actions.
D.Apply an S3 bucket policy denying delete actions, and enable CloudTrail organizational trail.
AnswerB

An SCP placed on the root organizational unit applies as a permission boundary to every account and principal in the organization, including each account's root user, so a deny of cloudtrail:StopLogging, cloudtrail:DeleteTrail, s3:DeleteBucket, and s3:DeleteObject makes tampering impossible even for administrators. The organizational trail, enabled from the management account, automatically collects events from all member accounts and cannot be stopped or disabled by any individual account. Together these controls enforce both protection of the audit trail and preservation of the log files, satisfying the requirement for a preventive solution.

Why this answer

The most effective preventive controls are applying a Service Control Policy (SCP) at the root OU to deny CloudTrail stop/delete and S3 delete actions, combined with enabling an organizational trail in CloudTrail. SCPs enforce guardrails across all member accounts, preventing even account administrators from disabling logging or deleting logs, while the organizational trail ensures centralized logging to a protected S3 bucket.

Exam trap

SCS-C02 often tests whether candidates confuse detective controls (CloudWatch alarms) or per-account IAM policies with organization-wide preventive controls (SCPs), leading them to choose weaker or reactive options.

How to eliminate wrong answers

Option A is wrong because CloudWatch alarms are detective, not preventive; they notify after the fact but do not stop the actions. Option C is wrong because IAM policies in each member account can be modified or bypassed by account administrators and do not provide centralized enforcement like SCPs. Option D is wrong because an S3 bucket policy alone does not prevent disabling CloudTrail logging in member accounts; it only protects the bucket, and it lacks the organization-wide preventive control of an SCP.

150
Multi-Selecthard

A company's security team is implementing controls to meet PCI DSS compliance. The environment includes Amazon EC2, RDS, and S3. Which THREE controls should be implemented to address logging and monitoring requirements?

Select 3 answers
A.Enable AWS Config to track resource configuration changes.
B.Enable VPC Flow Logs for all VPCs.
C.Enable AWS CloudTrail across all AWS regions.
D.Deploy Amazon CloudWatch Application Insights.
E.Enable detailed billing reports.
AnswersA, B, C

AWS Config records resource configuration changes as configuration items, generating a complete history that can be compared against baseline rules. For PCI DSS, it demonstrates compliance with configuration standards (e.g., Requirement 2) by detecting drift from approved settings, such as security group changes or unencrypted storage. This detective control is essential for proving that system configurations are maintained and reviewed.

Why this answer

AWS Config is correct because it tracks resource configuration changes and records them as configuration items, which is essential for PCI DSS Requirement 10.5.2 that mandates logging of all actions taken by any individual with root or administrative privileges. By monitoring changes to EC2, RDS, and S3 configurations, AWS Config provides an audit trail of who made changes, what changed, and when, directly supporting logging and monitoring compliance.

Exam trap

The trap here is that candidates may confuse operational monitoring tools (like CloudWatch Application Insights) or billing tools with the specific logging and monitoring controls required by PCI DSS, which focus on audit trails of configuration changes, network traffic, and API activity.

← PreviousPage 2 of 3 · 168 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Management and Security Governance questions.

CCNA Management and Security Governance Questions — Page 2 of 3 | Courseiva