Courseiva
← Back to AWS Certified Security Specialty SCS-C02 questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise AWS Certified Security Specialty SCS-C02 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
SCS-C02
exam code
Amazon Web Services
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related SCS-C02 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummultiple choice
Full question →

Refer to the exhibit. An IAM policy is attached to a group. An IAM user in that group attempts to stop an EC2 instance from IP address 198.51.100.10. What will happen?

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "ec2:DescribeInstances",
        "ec2:StartInstances",
        "ec2:StopInstances"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Deny",
      "Action": "*",
      "Resource": "*",
      "Condition": {
        "StringNotEquals": {
          "aws:SourceIp": "203.0.113.0/24"
        }
      }
    }
  ]
}
Question 2mediummultiple choice
Full question →

Refer to the exhibit. A security engineer runs the above command and sees the security group configuration. Based on the output, which statement is correct?

Network Topology
$ aws ec2 describe-security-groupsgroup-ids sg-12345678Refer to the exhibit."SecurityGroups": ["GroupId": "sg-12345678","GroupName": "web-sg","Description": "Web server security group","VpcId": "vpc-12345678","IpPermissions": ["IpProtocol": "tcp","FromPort": 80,"ToPort": 80,"IpRanges": ["CidrIp": "0.0.0.0/0"},"FromPort": 22,"ToPort": 22,"CidrIp": "203.0.113.0/24"],"IpPermissionsEgress": ["IpProtocol": "-1",
Question 3hardmultiple choice
Full question →

Refer to the exhibit. A security engineer runs the describe-instances command for an EC2 instance. The instance has a public IP address. The security group "allow-ssh-http" has inbound rules that allow SSH from 0.0.0.0/0 and HTTP from 0.0.0.0/0. The engineer wants to block SSH access from the internet while keeping HTTP access. Which change should be made?

Network Topology
$ aws ec2 describe-instancesinstance-ids i-0abcd1234efgh5678Refer to the exhibit.```"Reservations": ["Groups": [],"Instances": ["InstanceId": "i-0abcd1234efgh5678","ImageId": "ami-0abcdef1234567890","State": {"Code": 16,"Name": "running"},"PrivateIpAddress": "172.31.0.10","SecurityGroups": ["GroupName": "allow-ssh-http","GroupId": "sg-12345678"],"NetworkInterfaces": ["Association": {"PublicIp": "54.123.45.67""Attachment": {"DeviceIndex": 0
Question 4mediummultiple choice
Full question →

Refer to the exhibit. A security engineer is investigating a potential unauthorized VPC creation. What does the evidence suggest?

Network Topology
$ aws cloudtrail lookup-eventslookup-attributes AttributeKey=EventNamestart-time 2024-01-01T00:00:00Zend-time 2024-01-02T00:00:00Z$ aws ec2 describe-vpcsvpc-ids vpc-12345678vpc-ids vpc-87654321"Events": ["EventId": "example1","EventName": "CreateVpc","ReadOnly": "false","Username": "admin","EventTime": "2024-01-01T12:00:00Z","Resources": [{"ResourceType": "AWS::EC2::VPC", "ResourceName": "vpc-12345678"}]},"EventId": "example2","EventTime": "2024-01-01T13:00:00Z","Resources": [{"ResourceType": "AWS::EC2::VPC", "ResourceName": "vpc-87654321"}]"Vpcs": ["VpcId": "vpc-12345678","Tags": [{"Key": "Name", "Value": "Production"}]
Question 5hardmultiple choice
Full question →

Refer to the exhibit. An IAM policy is attached to a group. A user in the group accesses the S3 bucket from an IP address 203.0.113.5 using HTTPS. What will be the result?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": ["s3:GetObject"],
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": [
            "192.0.2.0/24",
            "198.51.100.0/24"
          ]
        },
        "Bool": {
          "aws:SecureTransport": "true"
        }
      }
    }
  ]
}
Question 6hardmultiple choice
Full question →

Refer to the exhibit. A security engineer reviews this CloudFormation template. The bucket is intended to be private. What is the security issue in the configuration?

Exhibit

Refer to the exhibit.

Resources:
  MyBucket:
    Type: AWS::S3::Bucket
    Properties:
      BucketName: my-secure-bucket
      PublicAccessBlockConfiguration:
        BlockPublicAcls: true
        BlockPublicPolicy: true
        IgnorePublicAcls: true
        RestrictPublicBuckets: true
      BucketPolicy:
        Version: 2012-10-17
        Statement:
          - Effect: Allow
            Principal: "*"
            Action: s3:GetObject
            Resource: !Sub "${MyBucket.Arn}/*"
Question 7easymultiple choice
Full question →

A security engineer is reviewing a CloudTrail log entry (exhibit). What is the most immediate security concern indicated by this event?

Exhibit

Refer to the exhibit.

```
{
  "Records": [
    {
      "eventVersion": "1.08",
      "userIdentity": {
        "type": "IAMUser",
        "arn": "arn:aws:iam::123456789012:user/JohnDoe",
        "accountId": "123456789012",
        "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
      },
      "eventTime": "2024-08-01T12:34:56Z",
      "eventSource": "ec2.amazonaws.com",
      "eventName": "AuthorizeSecurityGroupIngress",
      "awsRegion": "us-east-1",
      "sourceIPAddress": "203.0.113.5",
      "userAgent": "console.amazonaws.com",
      "requestParameters": {
        "groupId": "sg-0123456789abcdef0",
        "ipPermissions": {
          "items": [
            {
              "ipProtocol": "tcp",
              "fromPort": 22,
              "toPort": 22,
              "ipRanges": [
                {
                  "cidrIp": "0.0.0.0/0"
                }
              ]
            }
          ]
        }
      }
    }
  ]
}
```
Question 8mediummultiple choice
Full question →

Refer to the exhibit. A security engineer runs this AWS CLI command to investigate root user logins. The output shows a successful ConsoleLogin event. What should the engineer do next to improve security?

Network Topology
$ aws cloudtrail lookup-eventslookup-attributes AttributeKey=EventNamestart-time 2023-01-01T00:00:00Zend-time 2023-01-02T00:00:00Zquery 'Events[?UserIdentity.Type=="Root"]'Refer to the exhibit."EventId": "example1","EventName": "ConsoleLogin","ReadOnly": "False","Username": "root","EventTime": "2023-01-01T12:00:00Z","CloudTrailEvent": "{\"userIdentity\":{\"type\":\"Root\",\"arn\":\"arn:aws:iam::123456789012:root\"},\"responseElements\":{\"ConsoleLogin\":\"Success\"}}"
Question 9hardmultiple choice
Review the full subnetting walkthrough →

Refer to the exhibit. A security engineer is unable to SSH into an EC2 instance in subnet-12345678. The instance's security group allows inbound SSH from 10.0.0.0/8, and the instance has a public IP. What is the most likely reason for the failure?

Network Topology
$ aws ec2 describe-security-groupsgroup-ids sg-12345678$ aws ec2 describe-network-aclsfilters Name=association.subnet-id"SecurityGroups": ["GroupId": "sg-12345678","IpPermissions": ["IpProtocol": "tcp","FromPort": 22,"ToPort": 22,"IpRanges": [{"CidrIp": "10.0.0.0/8"}]],"IpPermissionsEgress": ["IpProtocol": "-1","IpRanges": [{"CidrIp": "0.0.0.0/0"}]"NetworkAcls": ["NetworkAclId": "acl-12345678","Entries": ["RuleNumber": 100,"Protocol": "6","RuleAction": "allow","Egress": false,"CidrBlock": "0.0.0.0/0","PortRange": {"From": 22, "To": 22}},"RuleNumber": 32767,"Protocol": "-1","RuleAction": "deny","CidrBlock": "0.0.0.0/0"
Question 10mediummultiple choice
Review the full subnetting walkthrough →

Refer to the exhibit. A security engineer runs the CLI command and receives the output shown. The engineer expects to see flow logs for a specific subnet, but the output shows the resource ID as a VPC. What is the most likely reason?

Network Topology
aws ec2 describe-flow-logsfilter "Name=log-group-nameRefer to the exhibit.Output:"FlowLogs": ["CreationTime": "2023-08-01T12:00:00Z","FlowLogId": "fl-12345678","FlowLogStatus": "ACTIVE","ResourceId": "vpc-12345678","TrafficType": "ALL","LogGroupName": "my-flow-log-group","DeliverLogsPermissionArn": "arn:aws:iam::123456789012:role/FlowLogRole","LogDestinationType": "cloud-watch-logs"
Question 11hardmultiple choice
Full question →

A security engineer runs the get-account-authorization-details command and sees the exhibit output. The engineer wants to ensure that the 'admin' user does not have administrative access. Which steps should be taken?

Exhibit

Refer to the exhibit.

$ aws iam get-account-authorization-details
{
    "UserDetailList": [
        {
            "UserName": "admin",
            "AttachedManagedPolicies": [
                {
                    "PolicyName": "AdministratorAccess",
                    "PolicyArn": "arn:aws:iam::aws:policy/AdministratorAccess"
                }
            ]
        },
        {
            "UserName": "svc-account",
            "AttachedManagedPolicies": [
                {
                    "PolicyName": "ReadOnlyAccess",
                    "PolicyArn": "arn:aws:iam::aws:policy/ReadOnlyAccess"
                }
            ]
        }
    ],
    "GroupDetailList": [],
    "Policies": [
        {
            "PolicyName": "CustomReadOnly",
            "PolicyId": "ANPA...",
            "AttachmentCount": 1,
            "PolicyVersionList": [
                {
                    "Document": {
                        "Version": "2012-10-17",
                        "Statement": [
                            {
                                "Effect": "Allow",
                                "Action": ["ec2:Describe*", "s3:Get*"],
                                "Resource": "*"
                            }
                        ]
                    }
                }
            ]
        }
    ]
}
Question 12mediummultiple choice
Full question →

Refer to the exhibit. A security engineer runs the 'simulate-custom-policy' command to test a policy. The output shows 'explicitDeny' for ec2:RunInstances. What is the most likely reason?

Network Topology
$ aws iam simulate-custom-policypolicy-input-list '{"Version":"2012-10-17"action-names ec2:DescribeInstances ec2:RunInstancesRefer to the exhibit."EvaluationResults": ["EvalActionName": "ec2:DescribeInstances","EvalDecision": "allowed"},"EvalActionName": "ec2:RunInstances","EvalDecision": "explicitDeny"
Question 13hardmultiple choice
Full question →

Refer to the exhibit. A security engineer runs the command above and sees that the flow log status is ACTIVE. However, the engineer notices that no logs are appearing in the CloudWatch log group. What is the most likely cause?

Network Topology
$ aws ec2 describe-flow-logsfilter "Name=log-group-nameRefer to the exhibit.Exhibit: (AWS CLI command output)"FlowLogs": ["CreationTime": "2023-01-01T00:00:00Z","FlowLogId": "fl-12345678","FlowLogStatus": "ACTIVE","ResourceId": "eni-12345678","TrafficType": "ALL","LogGroupName": "my-flow-log","DeliverLogsPermissionArn": "arn:aws:iam::123456789012:role/flow-logs-role","LogDestinationType": "cloud-watch-logs"
Question 14hardmultiple choice
Full question →

Refer to the exhibit. A security engineer attaches this bucket policy to an S3 bucket. A user from IP address 203.0.113.10 tries to download an object using HTTP (not HTTPS). What will happen?

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Deny",
      "Principal": "*",
      "Action": "s3:*",
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "Bool": {
          "aws:SecureTransport": "false"
        }
      }
    },
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "203.0.113.0/24"
        }
      }
    }
  ]
}
Question 15mediummultiple choice
Full question →

Refer to the exhibit. A security engineer attaches this S3 bucket policy to an S3 bucket. What is the effect of this policy?

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Deny",
      "Action": "s3:*",
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "BoolIfExists": {
          "aws:SecureTransport": "false"
        }
      }
    }
  ]
}

These SCS-C02 practice questions are part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style SCS-C02 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.