Courseiva

CCNA Security Governance Questions

75 of 168 questions · Page 1/3 · Security Governance topic · Answers revealed

1
MCQhard

A company's security team discovers that an IAM role has been assumed from an unexpected external AWS account. Which AWS service can be used to analyze the trust policy and identify unintended access?

A.AWS IAM Access Analyzer
B.AWS CloudTrail Insights
C.AWS Config
D.AWS Security Hub
AnswerA

AWS IAM Access Analyzer is correct because it performs automated, semantic analysis of the trust policy attached to the IAM role and identifies whether the role can be assumed by principals outside your AWS account or AWS organization. It generates concrete findings for external access, including the exact external principal and the action that grants access, so your security team can directly review and remediate the role. Other services merely log or aggregate activity; Access Analyzer specifically applies reachability logic to the policy statements.

Why this answer

AWS IAM Access Analyzer analyzes resource-based policies, including IAM role trust policies, to identify resources shared with external entities. It can detect when a role's trust policy allows an unexpected external AWS account to assume it, providing findings that highlight unintended access.

Exam trap

SCS-C02 often tests the specific purpose of IAM Access Analyzer versus CloudTrail Insights or Config — candidates pick CloudTrail Insights because it sounds like it analyzes activity, but Access Analyzer is the service for policy analysis.

How to eliminate wrong answers

Option B is wrong because CloudTrail Insights detects unusual API activity patterns but does not analyze trust policies for external access. Option C is wrong because AWS Config evaluates resource configurations against rules but does not specifically analyze trust policies for external principals. Option D is wrong because Security Hub aggregates findings from various services but does not itself analyze trust policies; it relies on services like Access Analyzer.

2
Multi-Selectmedium

A company uses AWS Organizations and wants to ensure that no member account can disable AWS CloudTrail or delete CloudTrail log files from S3. Which TWO actions should the security team take? (Choose TWO.)

Select 2 answers
A.Create an SCP that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail.
B.Enable MFA delete on the S3 bucket that stores CloudTrail logs.
C.Apply an SCP to the management account to prevent disabling CloudTrail.
D.Add an S3 bucket policy that denies s3:DeleteObject for the CloudTrail log bucket.
E.Create an IAM role for CloudTrail with permissions to write logs only.
AnswersA, D

An SCP that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail is an effective preventive control at the organization level. SCPs are inherited by all member accounts and cannot be bypassed by the account's IAM administrators or even the root user, guaranteeing that the CloudTrail trail remains active and undisputed. This directly addresses the requirement to ensure that no one can stop or remove the audit history, making it a correct answer.

Why this answer

Option A is correct because an AWS Organizations service control policy (SCP) attached to member accounts can explicitly deny the CloudTrail control-plane actions cloudtrail:StopLogging and cloudtrail:DeleteTrail, which are exactly the API calls used to disable a trail, and SCPs are the standard guardrail mechanism for enforcing such restrictions across all accounts in the organization. Option D is correct because a bucket policy on the CloudTrail log bucket that denies s3:DeleteObject (and ideally s3:DeleteObjectVersion) prevents any principal, including account administrators, from deleting the log objects, directly satisfying the requirement to protect the log files. Option B is not correct because MFA Delete only requires additional authentication for deleting object versions; it does not by itself prevent deletion and is not the SCP/bucket-policy guardrail the scenario requires.

Option C is not correct because SCPs do not apply to the management account, so applying one there would not prevent disabling CloudTrail in member accounts. Option E is not correct because an IAM role granting write-only permissions to CloudTrail does not stop member accounts from calling StopLogging/DeleteTrail or deleting S3 log objects.

Exam trap

SCS-C02 often tests the misconception that SCPs can be applied to the management account or that MFA Delete alone protects CloudTrail logs — candidates must remember SCPs never affect the management account and that log immutability requires an S3-layer control.

3
Multi-Selecthard

Which THREE are benefits of using AWS CloudTrail for security governance? (Choose three.)

Select 3 answers
A.Enables real-time log analysis with Amazon CloudWatch Logs
B.Automatically remediates noncompliant resources
C.Supports compliance audits by providing event history
D.Provides a record of API activity in the account
E.Allows security analysis of user activity
AnswersC, D, E

CloudTrail’s event history is designed as a durable, tamper-evident record of account activity, which auditors can use as evidence for compliance controls. It captures management events for 90 days in the console and can deliver to S3 or CloudTrail Lake for long-term retention, enabling organizations to satisfy audit requirements across frameworks like SOC 2, PCI DSS, and HIPAA. This audit trail is a core reason CloudTrail is considered essential for compliance.

Why this answer

Option C is correct because CloudTrail retains a searchable history of management and data events that auditors can use to demonstrate who did what and when, satisfying compliance audit requirements. Option D is correct because CloudTrail's core function is to record AWS API activity (management events, and optionally data and insight events) in the account and deliver them as log files to Amazon S3 and/or CloudWatch Logs. Option E is correct because those API activity records include the identity (IAM user, role, federated user) and source IP, enabling security teams to analyze user behavior and detect anomalous or unauthorized actions.

Option A is not correct as stated because CloudTrail itself does not perform real-time log analysis; it can deliver events to CloudWatch Logs, but the analysis is done by CloudWatch Logs metric filters/alarms, not by CloudTrail. Option B is not correct because CloudTrail is an auditing and logging service and does not automatically remediate noncompliant resources; remediation requires services such as AWS Config rules with remediation actions or Lambda-based automation.

Exam trap

SCS-C02 often tests CloudTrail benefits, and candidates may incorrectly select real-time analysis or automatic remediation, which are not native CloudTrail features.

4
MCQmedium

A company wants to ensure that all S3 buckets in their AWS account have encryption enabled. Which AWS service can continuously evaluate compliance and automatically remediate non-compliant buckets?

A.AWS CloudTrail
B.AWS Config
C.AWS IAM
D.Amazon S3
AnswerB

AWS Config continuously records the configuration of each S3 bucket and evaluates the recorded state against managed rules such as s3-bucket-server-side-encryption-enabled. When a bucket is noncompliant, Config can trigger Auto Remediation via a Systems Manager Automation document to append or modify the bucket's encryption configuration. This works on existing buckets in near-real time, and also on any new bucket created, making it a direct enforcement mechanism.

Why this answer

AWS Config is the service that continuously evaluates resource configurations against desired policies and can automatically remediate non-compliant resources. It can monitor S3 bucket encryption settings and trigger remediation actions (e.g., via SSM Automation) to enable encryption. AWS Config rules can be configured to check for encryption and automatically remediate using remediation actions.

Exam trap

SCS-C02 often tests the difference between detective and preventive controls; candidates may choose CloudTrail for compliance monitoring, but CloudTrail only logs API calls and does not evaluate compliance or remediate.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity and does not evaluate compliance or remediate resources. Option C is wrong because AWS IAM manages identities and permissions, not continuous compliance evaluation of resource configurations. Option D is wrong because Amazon S3 itself does not provide continuous compliance evaluation or automatic remediation; it is the resource being monitored, not the monitoring service.

5
MCQhard

A company runs a multi-account AWS environment using AWS Organizations. The security team uses AWS Config to monitor compliance. Recently, they noticed that a developer in the 'development' account created an S3 bucket that is publicly accessible. The security team wants to prevent this in the future by automatically remediating any public S3 bucket. They have an SCP that denies s3:PutBucketPublicAccessBlock, but developers are still making buckets public by using bucket ACLs. The security team wants to implement a solution that automatically fixes any bucket that becomes public. Which solution should they choose?

A.Use CloudTrail to detect PutBucketAcl events and send to SNS for manual remediation
B.Use AWS Config with the s3-bucket-public-read-prohibited managed rule and an automatic remediation action using AWS Systems Manager Automation
C.Update the SCP to deny s3:PutBucketAcl with a condition for public access
D.Attach an IAM policy to all users that denies s3:PutBucketAcl
AnswerB

AWS Config continuously evaluates bucket configurations against the s3-bucket-public-read-prohibited managed rule, which checks both bucket ACLs and bucket policies for public read access. When a violation is detected, an automatic remediation action invokes an AWS Systems Manager Automation runbook (e.g., AWS-DisableS3BucketPublicRead) to remove the public grant or apply a deny. This is a fully automated lifecycle: detect, remediate, and re-evaluate until compliant, without human intervention, making it the correct solution.

Why this answer

AWS Config's s3-bucket-public-read-prohibited managed rule evaluates S3 bucket ACLs and policies for public read access. When a noncompliant bucket is detected, an automatic remediation action using AWS Systems Manager Automation can invoke a custom SSM document (e.g., AWS-DisableS3BucketPublicReadWrite) to remove public ACLs or apply a bucket policy that denies public access. This provides automated, event-driven remediation without relying on manual intervention or incomplete SCPs.

Exam trap

The trap here is that candidates often assume an SCP or IAM policy that denies the specific API call (s3:PutBucketAcl) is the best solution, but the question requires automatic remediation of already-public buckets, not prevention—and SCPs cannot remediate existing noncompliant resources, only block future actions.

How to eliminate wrong answers

Option A is wrong because using CloudTrail to detect PutBucketAcl events and sending to SNS for manual remediation does not automatically fix the bucket; it requires human action, which is slow and error-prone, and does not meet the requirement for automatic remediation. Option C is wrong because updating the SCP to deny s3:PutBucketAcl with a condition for public access would prevent developers from setting public ACLs in the first place, but the question states that developers are already bypassing the existing SCP (which denies s3:PutBucketPublicAccessBlock) by using ACLs; an SCP that denies s3:PutBucketAcl could be effective, but the question explicitly asks for a solution that automatically fixes any bucket that becomes public, not one that prevents the action—furthermore, SCPs cannot retroactively remediate already-public buckets. Option D is wrong because attaching an IAM policy to all users that denies s3:PutBucketAcl is not scalable in a multi-account environment (IAM policies are account-specific and cannot be applied across all accounts via AWS Organizations), and it also does not provide automatic remediation for buckets that are already public.

6
MCQmedium

Refer to the exhibit. A security engineer attaches this S3 bucket policy to an S3 bucket. What is the effect of this policy?

A.Requests over HTTP are denied, but HTTPS requests are allowed.
B.The policy has no effect because there is no Allow statement.
C.All requests over HTTPS are allowed.
D.All requests to the bucket are denied.
AnswerA

The bucket policy includes a Deny statement with a Bool condition on aws:SecureTransport set to "false". This condition matches only when the request is made over plain HTTP, not TLS/SSL. Consequently, HTTP requests are explicitly denied, while HTTPS requests do not match the condition and therefore are not blocked by this statement. Any valid allow from another policy can therefore permit HTTPS access.

Why this answer

The policy contains a Deny statement conditioned on 'aws:SecureTransport' being false, which blocks all HTTP requests while allowing HTTPS requests to proceed (subject to other permissions). Because Deny only triggers when the condition matches, HTTPS requests are unaffected by this statement and can be allowed by other policies or ACLs.

Exam trap

SCS-C02 often tests the misconception that a policy needs an Allow statement to have any effect, causing candidates to select 'no effect' when a Deny-only policy is actually fully enforceable.

How to eliminate wrong answers

Option B is wrong because a bucket policy with only a Deny statement is fully effective — Deny statements do not require a matching Allow to take effect; they explicitly block matching requests. Option C is wrong because the policy does not grant any Allow; it only denies HTTP, so HTTPS requests are not automatically allowed unless another policy grants permission. Option D is wrong because the Deny is conditional on SecureTransport being false, so HTTPS requests are not denied by this policy.

7
MCQmedium

A company uses AWS KMS to encrypt data in S3 buckets. The security team needs to ensure that KMS keys can only be used by specific IAM roles within the same account. Which key policy should be applied?

A."Principal": {"AWS": "arn:aws:iam::123456789012:*"}
B."Principal": {"AWS": "*"}
C."Principal": {"AWS": "arn:aws:iam::123456789012:root"}
D."Principal": {"AWS": "arn:aws:iam::123456789012:role/AllowedRole"}
AnswerD

This principal ARN explicitly identifies the IAM role 'AllowedRole' in the account. When the role is assumed (by an EC2 instance, Lambda, or an STS AssumeRole call), the role's temporary credentials include the role's ARN as the principal, so the KMS key policy exactly matches it. This is the correct least-privilege configuration because no other IAM user or role can use the key unless the role allows it, and the key policy does not expose the key to the entire account. You could further restrict it by adding a condition like kms:ViaService to limit it to S3, but this is the best answer among the options.

Why this answer

A KMS key policy that names a specific IAM role ARN as the principal grants key usage only to that role, which directly satisfies the requirement to restrict key usage to specific IAM roles within the account. The key policy is the primary access control for a KMS key, and explicit role ARNs enforce least privilege at the key level.

Exam trap

SCS-C02 often tests the misconception that specifying the account root ARN restricts access to the account — candidates must remember that root ARN delegates to IAM and does not limit usage to specific roles.

How to eliminate wrong answers

Option A is wrong because arn:aws:iam::123456789012:* is not a valid principal ARN — the wildcard in the role/user path position does not match all principals and would not grant the intended access; it is syntactically invalid for a principal element. Option B is wrong because "AWS": "*" grants access to every principal in every account, which is the opposite of restricting usage. Option C is wrong because specifying the account root ARN delegates permission to the account, allowing any principal in the account with the right IAM permissions to use the key, which does not restrict usage to specific roles.

8
Multi-Selectmedium

Which TWO actions are best practices for securing an AWS account root user? (Select TWO.)

Select 2 answers
A.Use the root user for everyday administrative tasks.
B.Create access keys for the root user.
C.Delete the root user to prevent unauthorized access.
D.Create an IAM user with administrative privileges and use it instead of the root user.
E.Enable MFA on the root user.
AnswersD, E

Creating an IAM user with administrative privileges and using that user for day-to-day management reduces the exposure of the root user credentials, which is a core AWS account security best practice. This allows you to enforce MFA, assign permissions via IAM policies, rotate credentials, and audit actions through CloudTrail, none of which are possible with the root user in a least-privilege manner. While AWS now recommends using IAM Identity Center with roles for human access, an admin IAM user protected by MFA is still a valid baseline for root-user credential protection.

Why this answer

Option D is correct because AWS best practice is to create an IAM user (or federated identity) with the required administrative permissions and use that identity for day-to-day administration, reserving the root user only for the few tasks that specifically require it, such as changing the account name, closing the account, or changing the support plan. Option E is correct because enabling multi-factor authentication (MFA) on the root user adds a second authentication factor, so a compromised root password alone is insufficient to sign in; AWS strongly recommends a hardware MFA device for the root user. Option A is wrong because using the root user for everyday administrative tasks violates least privilege and greatly increases the blast radius if those credentials are compromised.

Option B is wrong because AWS advises against creating access keys for the root user; if root access keys already exist, they should be deleted, since long-lived root keys are a major security risk. Option C is wrong because the root user cannot be deleted; it is permanently tied to the account and can only be secured by protecting its credentials and limiting its use.

Exam trap

SCS-C02 often tests root user security; candidates may think the root user can be deleted or that access keys are acceptable, but the root user cannot be deleted and access keys should be avoided.

9
MCQhard

A company uses AWS Organizations with many accounts. The security team wants to ensure that no account can disable AWS CloudTrail or stop logging. Which configuration should be used?

A.Enable CloudTrail log file validation.
B.Attach an IAM policy to the root user in each account.
C.Use AWS Config rules to detect and alert when CloudTrail is modified.
D.Apply an SCP that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail.
AnswerD

A service control policy (SCP) that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail is the correct preventive control because SCPs are account permission boundaries applied at the organization, organizational unit, or account level, and they apply to every IAM principal, including the root user. Once attached to all member accounts, it blocks these API calls before they execute, ensuring that no user or role—even with administrator privileges—can disable or delete CloudTrail. This centralizes protection and is the only option that directly prevents the malicious actions.

Why this answer

Service Control Policies (SCPs) in AWS Organizations are the only mechanism that can enforce a hard deny across all accounts in an organization, preventing even account root users from performing specified actions. By applying an SCP that denies cloudtrail:StopLogging and cloudtrail:DeleteTrail, the security team ensures no account can disable or delete CloudTrail trails, regardless of IAM permissions within the account. SCPs define the maximum available permissions for accounts in the organization.

Exam trap

SCS-C02 often tests the distinction between preventive controls (SCPs) and detective controls (Config, CloudTrail validation), so candidates who pick alerting mechanisms instead of enforcement mechanisms fall into the trap.

How to eliminate wrong answers

Option A is wrong because CloudTrail log file validation only detects whether log files have been tampered with after delivery — it does not prevent anyone from stopping or deleting the trail in the first place. Option B is wrong because IAM policies attached to root users in each account are still modifiable by those root users and do not provide organization-wide enforcement; a root user could simply remove the policy. Option C is wrong because AWS Config rules are detective controls that alert after a change occurs — they do not prevent the action, and a malicious actor could disable CloudTrail before the rule fires or the alert is acted upon.

10
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team wants to centrally manage IAM policies across all accounts. Which AWS feature should the team use to enforce permissions across member accounts?

A.IAM roles with cross-account access
B.Service Control Policies (SCPs)
C.AWS Config rules
D.AWS CloudTrail trails
AnswerB

Service Control Policies (SCPs) are AWS Organizations policies that centrally manage the maximum available permissions for identities and resources in member accounts. They act as guardrails that restrict what IAM users, roles, and even the root user can do in an account, without granting any permissions themselves. By attaching SCPs to accounts or organizational units, you can enforce consistent permission boundaries across the entire organization, which directly matches the requirement for central permission control.

Why this answer

Service Control Policies (SCPs) allow central control over permissions for all accounts in an organization. Option A is wrong because IAM roles with cross-account access provide temporary access but do not enforce policies centrally. Option C is wrong because AWS Config rules are for compliance monitoring, not permission enforcement.

Option D is wrong because AWS CloudTrail is for auditing, not enforcement.

11
Multi-Selecthard

A company is implementing AWS Organizations with multiple accounts. Which THREE are benefits of using service control policies (SCPs)? (Choose three.)

Select 3 answers
A.Grant cross-account access
B.Prevent users from disabling CloudTrail
C.Enforce compliance requirements
D.Manage consolidated billing
E.Centrally restrict permissions across accounts
AnswersB, C, E

Specifically, SCPs can deny the CloudTrail management actions such as cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail, preventing even the root user in a member account from disabling audit logging. Because SCPs act as an overlay on all IAM identities within the affected accounts, they are an effective detective and preventive control for maintaining an immutable trail record. This is a common pattern for meeting audit and security requirements.

Why this answer

Option B is correct because an SCP can deny the cloudtrail:StopLogging and cloudtrail:DeleteTrail actions at the OU or account level, ensuring member accounts cannot disable or delete CloudTrail trails even if their IAM policies allow it. Option C is correct because SCPs let you codify and enforce organizational compliance guardrails—such as blocking use of unapproved regions or services—uniformly across all accounts in an OU. Option E is correct because SCPs are the AWS Organizations mechanism for centrally setting the maximum available permissions for principals in member accounts, restricting what IAM policies can grant.

Option A is not a benefit of SCPs because SCPs only filter/limit permissions; they never grant access, so cross-account access must be established with IAM roles, resource policies, or identity federation. Option D is not a benefit of SCPs because consolidated billing is a separate AWS Organizations feature handled by the management account's payment method, not by service control policies.

Exam trap

SCS-C02 often tests the misconception that SCPs grant permissions or handle billing, when they only restrict permissions and consolidated billing is a separate Organizations feature.

12
MCQmedium

A security engineer needs to ensure that all EC2 instances launched in a development account are tagged with a cost center. What is the most effective way to enforce this?

A.Use AWS Config to detect untagged instances and send alerts
B.Use AWS Systems Manager to tag instances after launch
C.Create a tag policy in AWS Organizations requiring the cost center tag
D.Use an IAM policy that denies ec2:RunInstances unless the request includes the cost center tag
AnswerD

An IAM policy can explicitly deny ec2:RunInstances when a condition key such as ec2:RequestTag/cost-center is absent from the API request—for example, by using a Null condition set to true. Because IAM policies are evaluated before the API call is executed, any launch attempt that omits the cost-center tag is immediately rejected, before any instance is created. This is a true preventive control and is the only listed option that stops the launch itself.

Why this answer

Using an IAM policy with a condition key (e.g., `aws:RequestTag`) that denies `ec2:RunInstances` unless the `cost center` tag is specified in the API call enforces tagging at launch time. This prevents any untagged instance from being created, providing proactive enforcement rather than reactive detection or remediation.

Exam trap

The trap here is that candidates often choose AWS Config (Option A) because it is a common governance tool, but they miss that Config only detects non-compliance after the fact, whereas IAM policies provide preventive enforcement at the API level.

How to eliminate wrong answers

Option A is wrong because AWS Config can only detect and alert on untagged instances after they are launched, not prevent their creation, leaving a window of non-compliance. Option B is wrong because AWS Systems Manager can tag instances after launch, but this is a reactive measure that does not enforce tagging at creation time and may miss instances that are not managed by Systems Manager. Option C is wrong because tag policies in AWS Organizations are used to enforce consistent tagging across accounts but do not prevent the launch of untagged resources; they only provide a compliance check and can mark non-compliant resources, not block the action.

13
MCQeasy

A company uses AWS Secrets Manager to store database credentials. The security team needs to ensure that secrets are automatically rotated every 30 days. Which configuration should be used?

A.Manually update the secret in Secrets Manager every 30 days.
B.Use Amazon Macie to detect when secrets are stale.
C.Set an expiration date on the secret and recreate it.
D.Enable automatic rotation using an AWS Lambda function.
AnswerD

Secrets Manager natively supports automatic rotation by invoking an AWS Lambda function that updates the secret and the database credential in a coordinated fashion. The Lambda function follows the rotation schedule you configure (for example, every 30 days) and uses staged steps to ensure the secret is valid before promoting it, while also updating the target database. This fully automates the credential lifecycle, eliminates manual intervention, and is the correct way to enforce periodic rotation for database credentials stored in Secrets Manager.

Why this answer

AWS Secrets Manager provides a built-in mechanism to automatically rotate secrets using an AWS Lambda function. By configuring a rotation schedule (e.g., every 30 days), Secrets Manager invokes the Lambda function to create a new version of the secret and update the database credentials, ensuring compliance without manual intervention.

Exam trap

The trap here is that candidates may confuse setting an expiration date (Option C) with automatic rotation, but expiration only triggers deletion or recreation, not the seamless, scheduled credential update that a Lambda-based rotation provides.

How to eliminate wrong answers

Option A is wrong because manually updating the secret every 30 days is not automated and violates the requirement for automatic rotation; it also introduces human error risk and operational overhead. Option B is wrong because Amazon Macie is a data discovery and classification service that identifies sensitive data in S3, not a tool for detecting stale secrets or managing rotation schedules in Secrets Manager. Option C is wrong because setting an expiration date on a secret only marks it for deletion or forces recreation, but does not automatically rotate the secret; the secret must be manually recreated, and the rotation process is not triggered by expiration alone.

14
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team needs to enforce that all S3 buckets in the organization block public access. Which policy should be attached to the root organizational unit to achieve this?

A.Enable AWS CloudTrail to log public access attempts and alert the security team.
B.Use AWS Config rules to remediate non-compliant buckets automatically.
C.Attach a service control policy (SCP) that denies s3:PutBucketPublicAccessBlock.
D.Create an IAM role with a bucket policy that blocks public access.
AnswerC

SCPs can be attached to OUs to centrally restrict permissions.

Why this answer

Attach a service control policy (SCP) that denies s3:PutBucketPublicAccessBlock. SCPs can be applied at the root organizational unit to centrally restrict permissions across all accounts, preventing any account from allowing public access to S3 buckets. Option A (CloudTrail) only logs events, not block access.

Option B (AWS Config) can detect non-compliance but requires additional automation to enforce; the question asks for enforcement directly. Option D (IAM role) is account-specific and cannot enforce globally.

15
MCQeasy

A company is using AWS Organizations with multiple accounts. The security team wants to ensure that all IAM users in the organization have multi-factor authentication (MFA) enabled. Which combination of actions should be taken to enforce this requirement?

A.Create an SCP that denies IAM actions without MFA and attach it to the IAM group that contains all users.
B.Create an SCP that denies IAM actions without MFA and attach it to the root organizational unit (OU).
C.Create an SCP that denies IAM actions without MFA and attach it to each IAM user.
D.Create an SCP that denies IAM actions without MFA and attach it to the management account.
AnswerB

Attaching the SCP to the root organizational unit places it in the hierarchy of every OU and member account in the organization, so the deny rule with aws:MultiFactorAuthPresent applies to every IAM user in those accounts. Because a root-level SCP is evaluated as an organizational permission boundary before IAM authorization, an IAM action without MFA is blocked throughout the member accounts.

Why this answer

Service Control Policies (SCPs) in AWS Organizations can be attached to the root organizational unit (OU) to apply a blanket denial of IAM actions when MFA is not present, affecting all accounts and users within the organization. This leverages the `aws:MultiFactorAuthPresent` condition key in an SCP to enforce MFA at the organization level, ensuring that even if IAM users are created in member accounts, they cannot perform IAM actions without MFA. Attaching the SCP to the root OU ensures the policy cascades down to all child OUs and accounts, providing centralized enforcement.

Exam trap

The trap here is that candidates mistakenly think SCPs can be attached to IAM users or groups, but SCPs are organization-level policies that only apply to OUs, accounts, or the root, not to individual IAM entities.

How to eliminate wrong answers

Option A is wrong because SCPs cannot be attached to IAM groups; SCPs are applied to OUs, accounts, or the root of the organization, not to IAM entities like groups, users, or roles. Option C is wrong because SCPs cannot be attached directly to IAM users; they are only applicable to AWS Organizations entities (OUs, accounts, or the root). Option D is wrong because attaching the SCP to the management account would only affect that single account, not the member accounts; SCPs must be attached to the root OU or relevant OUs to enforce policies across the entire organization.

16
MCQeasy

A company wants to centrally manage access keys for IAM users. Which AWS service can generate and rotate access keys automatically?

A.AWS CloudHSM
B.AWS KMS
C.AWS Systems Manager Parameter Store
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager automatically rotates secrets, including IAM user access keys, using a Lambda function built-in or custom. It can store the secret as AWSCURRENT and manage rotations with defined schedules, and also provides access policy and audit capabilities. This makes Secrets Manager the correct service for centrally managing and rotating IAM access keys.

Why this answer

AWS Secrets Manager is the correct service because it natively supports automatic rotation of secrets, including IAM user access keys. You can configure a rotation schedule (e.g., every 30 days) and Secrets Manager will generate a new access key pair, update the IAM user, and optionally disable or delete the old key. This provides a fully managed, centralized solution for rotating access keys without custom scripting.

Exam trap

The trap here is that candidates often confuse AWS KMS (which handles encryption keys) with Secrets Manager (which handles secrets like passwords and access keys), or they assume Parameter Store can rotate secrets automatically, but only Secrets Manager provides built-in, configurable rotation for IAM access keys.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides hardware security modules for cryptographic key storage and operations, but it does not generate or rotate IAM access keys. Option B is wrong because AWS KMS manages encryption keys (symmetric and asymmetric) and performs cryptographic operations, but it cannot create or rotate IAM user access keys. Option C is wrong because AWS Systems Manager Parameter Store can store secrets as parameters, but it lacks built-in rotation capabilities; you would need to implement custom rotation logic using Lambda, whereas Secrets Manager provides native rotation.

17
MCQeasy

A company wants to automate the enforcement of security best practices across all AWS accounts in an organization. The solution should automatically remediate noncompliant resources. Which AWS service should be used to achieve this?

A.AWS Organizations service control policies (SCPs)
B.AWS IAM Access Analyzer
C.Amazon GuardDuty
D.AWS Config rules with auto-remediation
AnswerD

AWS Config rules evaluate resource configurations against desired policies and, when a rule is noncompliant, can trigger an associated AWS Systems Manager Automation runbook to automatically perform the necessary corrective action. This combination of continuous evaluation and auto-remediation directly addresses the need to automate enforcement of security best practices. For example, a Config rule can detect an S3 bucket without encryption and invoke an Automation document to enable default encryption, all without manual intervention.

Why this answer

AWS Config rules evaluate resource configurations against desired states and can trigger automatic remediation via SSM Automation documents when a resource is noncompliant. With AWS Organizations integration, Config can aggregate compliance across all accounts and apply remediation centrally, making it the correct choice for automated enforcement with remediation.

Exam trap

The trap is confusing preventive controls (SCPs) with detective-and-remediative controls (Config rules); the question's keyword 'automatically remediate' rules out SCPs, which only block actions.

How to eliminate wrong answers

Option A is wrong because SCPs restrict what actions principals can perform but do not evaluate resource compliance or perform remediation; they are preventive, not detective/remediative. Option B is wrong because IAM Access Analyzer identifies overly permissive resource policies and unused access, but it does not remediate noncompliant resources automatically. Option C is wrong because GuardDuty is a threat detection service that identifies malicious activity; it does not enforce configuration best practices or remediate resources.

18
MCQhard

A security engineer notices that an IAM user has been inactive for 90 days. What is the best way to identify and disable such users?

A.Use CloudTrail to identify users with no recent events
B.Use AWS Config rule to detect inactive users
C.Use IAM Credential Report and disable users with no activity in 90 days
D.Use AWS Organizations to disable users
AnswerC

The IAM Credential Report lists every user's password and access key usage with timestamps, letting the engineer identify accounts with no activity for 90 days and then disable them. It provides the credential-age and last-used data the scenario requires.

Why this answer

The IAM Credential Report provides a comprehensive CSV export of all IAM users in the account, including the `password_last_used` and `access_key_last_used_date` columns. This allows a security engineer to directly identify users who have had no activity for 90 days and then disable them by applying an IAM policy with a `Deny` effect or removing their credentials. It is the most straightforward, native, and accurate method for this specific task.

Exam trap

The trap here is that candidates confuse CloudTrail (which logs events) with the IAM Credential Report (which directly reports user activity), or they assume AWS Config can evaluate user inactivity when it is designed for resource configuration compliance, not behavioral monitoring.

How to eliminate wrong answers

Option A is wrong because CloudTrail records API activity but does not natively aggregate or report on user inactivity over a 90-day period; you would need to write custom queries and there is no built-in 'inactive user' view. Option B is wrong because AWS Config rules evaluate resource configurations (e.g., whether an IAM user has a policy attached) but cannot directly detect user login or API activity inactivity; there is no managed Config rule for 'inactive IAM user'. Option D is wrong because AWS Organizations is a service for managing multiple AWS accounts centrally, not for disabling individual IAM users within a single account.

19
MCQmedium

Refer to the exhibit. An IAM policy is attached to a user. The user attempts to upload an object to my-bucket using server-side encryption with AWS KMS (SSE-KMS). What is the outcome?

A.The upload fails because the Deny statement denies any PutObject that does not use AES256 encryption.
B.The upload fails because the Allow statement requires AES256 encryption.
C.The upload succeeds because the policy does not explicitly deny SSE-KMS.
D.The upload succeeds because the Allow statement matches the s3:PutObject action.
AnswerA

The upload fails because the Deny statement is explicit and takes precedence over any Allow. Since the request either omits the encryption header or uses a different value (e.g., aws:kms), the Deny's StringNotEquals condition matches, and IAM denies s3:PutObject before the Allow can be evaluated. This is the only correct outcome.

Why this answer

The policy contains an explicit Deny for s3:PutObject when the request does not use AES256 server-side encryption. In IAM, an explicit Deny always overrides any Allow, so a PutObject using SSE-KMS (aws:kms) fails even though the Allow statement matches the action and resource. The Deny condition effectively whitelists only AES256, making any other encryption mode—including SSE-KMS—blocked.

Exam trap

SCS-C02 often tests the misconception that a matching Allow statement can override an explicit Deny, when in fact explicit Deny always takes precedence in IAM evaluation.

How to eliminate wrong answers

Option B is wrong because the Allow statement does not require AES256; it merely permits the action, and Allow statements cannot enforce encryption requirements on their own—only Deny with conditions can. Option C is wrong because IAM evaluation is deny-first: an explicit Deny does not need to name SSE-KMS specifically; it denies everything not matching the AES256 condition, which includes SSE-KMS. Option D is wrong because a matching Allow is irrelevant when an explicit Deny applies to the same action; explicit Deny always wins in IAM policy evaluation.

20
MCQmedium

A security engineer is designing a solution to automatically remediate non-compliant resources in an AWS account. The engineer needs to trigger an AWS Lambda function when an EC2 instance is launched without the required tags. Which AWS service should be used to detect the non-compliant resource and invoke the Lambda function?

A.AWS CloudTrail
B.AWS Config
C.Amazon GuardDuty
D.AWS Systems Manager
AnswerB

AWS Config continuously records resource configurations and evaluates them against managed or custom rules, such as the required-tags rule that checks for specific tag keys. When a resource becomes noncompliant, Config can invoke remediation actions via Systems Manager Automation documents or Lambda functions, such as adding the missing tag automatically. This makes it the correct service for both detecting missing tags and automating their correction.

Why this answer

AWS Config is the correct service because it continuously evaluates resource configurations against desired rules. You can create a Config rule that checks for required tags on EC2 instances; when a non-compliant instance is detected, Config can automatically invoke a Lambda function via an remediation action. This native integration enables automatic, event-driven remediation without custom polling or additional services.

Exam trap

SCS-C02 often tests the difference between detection services (GuardDuty, CloudTrail) and compliance evaluation services (AWS Config), and candidates may confuse CloudTrail's logging with Config's compliance monitoring.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail only records API activity and does not evaluate resource compliance or trigger automated remediation. Option C is wrong because Amazon GuardDuty is a threat detection service that identifies malicious activity, not tag compliance. Option D is wrong because AWS Systems Manager is used for operational management (e.g., patching, automation) but does not natively detect non-compliant resource configurations based on tag policies.

21
MCQmedium

A company uses AWS Organizations with all features enabled. The security team wants to ensure that no IAM users are created in any account. Which approach should be used?

A.Use AWS Config rules to detect IAM users and notify via SNS.
B.Enable AWS CloudTrail Insights to detect anomalous IAM activity.
C.Attach a service control policy (SCP) that denies iam:CreateUser.
D.Apply an IAM policy to the root user to deny iam:CreateUser.
AnswerC

A service control policy (SCP) is an organizational policy that specifies the maximum allowed permissions for all principals, including the root user, in every account governed by an AWS Organizations hierarchy. Attaching an SCP that explicitly denies iam:CreateUser to the organization root or a specific OU prevents any principal in those accounts from creating IAM users, regardless of the permissions granted by IAM policies. Because all features are enabled, the SCP is enforced globally across member accounts, making it a true preventive control.

Why this answer

Service Control Policies (SCPs) in AWS Organizations allow you to centrally restrict permissions across all accounts in the organization. By attaching an SCP that denies the `iam:CreateUser` action, you prevent the creation of IAM users in any member account, regardless of any IAM policies attached to users or roles within those accounts. This provides a guardrail that cannot be overridden by account administrators, ensuring compliance with the security team's requirement.

Exam trap

The trap here is that candidates often confuse IAM policies with SCPs, thinking that an IAM policy attached to the root user can block actions across the account, but SCPs are the only mechanism that can enforce such restrictions across all principals in an organization.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can only detect and notify about IAM users after they are created; they do not prevent the creation of IAM users, so they fail to meet the requirement of ensuring no IAM users are created. Option B is wrong because AWS CloudTrail Insights is designed to detect anomalous API activity and generate insights, but it does not block or prevent IAM user creation; it only provides post-event analysis. Option D is wrong because applying an IAM policy to the root user does not prevent IAM user creation in other accounts or even in the same account, as the root user is not subject to IAM policies; additionally, IAM policies cannot be attached to the root user, and even if they could, they would not affect other users or roles in the account.

22
Drag & Dropmedium

Drag and drop the steps to set up a secure S3 bucket with encryption and access control in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Secure S3 bucket requires encryption, public access block, bucket policy, versioning, and access logging.

23
MCQmedium

A company uses AWS Key Management Service (KMS) to encrypt sensitive data in Amazon S3. The security team needs to ensure that the KMS key can only be used from within the company's VPC and not from the public internet. How can this be achieved?

A.Use an SCP to deny kms:Encrypt unless the request comes from the VPC.
B.Use AWS CloudTrail to monitor KMS calls and alert if they come from outside the VPC.
C.Create a VPC endpoint for KMS and modify the KMS key policy to allow usage only from the specified VPC endpoint.
D.Create a VPC endpoint for KMS and attach a bucket policy that requires the endpoint.
AnswerC

Creating an interface VPC endpoint for AWS KMS allows KMS API calls from your VPC to reach the service without traversing the public internet. The definitive control is to modify the KMS key policy to include a condition such as "aws:sourceVpce": "vpce-1234567890abcdef0" in the Allow statement, so that only requests that arrive through that specific VPC endpoint can use the key. This works because KMS evaluates the key policy with the sourceVpce context key, and requests that do not originate from the designated endpoint are implicitly denied, while requests from an EC2 instance or private subnet using the endpoint are allowed. The key policy must include the principal (e.g., the IAM role/account root) and the restriction to the VPC endpoint, because the VPC endpoint itself is the enforcement point that KMS trusts.

Why this answer

To restrict KMS key usage to a VPC, you create a VPC endpoint for KMS (an interface endpoint powered by AWS PrivateLink) and then modify the KMS key policy to allow usage only from that VPC endpoint. This ensures that requests to KMS must come through the VPC endpoint, not the public internet.

Exam trap

The trap is confusing S3 bucket policies with KMS key policies; candidates may think a bucket policy can restrict KMS usage, but KMS access is controlled by key policies and IAM policies, and VPC endpoint conditions must be in the key policy.

How to eliminate wrong answers

Option A is wrong because SCPs apply to AWS accounts and cannot condition on VPC endpoint; they cannot enforce that a request comes from a specific VPC. Option B is wrong because CloudTrail monitoring is detective, not preventive; it alerts but does not block public internet access. Option D is wrong because a bucket policy controls access to S3, not to KMS; while you can require a VPC endpoint for S3, it does not restrict KMS key usage.

24
MCQhard

A security engineer is investigating a potential data exfiltration incident. The engineer notices that an EC2 instance in a private subnet is making outbound connections to an external IP address on port 443. The VPC has a NAT gateway in a public subnet, and the route table for the private subnet directs 0.0.0.0/0 to the NAT gateway. The security group for the instance allows all outbound traffic. Which AWS service can the engineer use to determine which IAM role or user is responsible for launching the instance?

A.AWS Config
B.VPC Flow Logs
C.IAM Access Analyzer
D.AWS CloudTrail
AnswerD

AWS CloudTrail is the authoritative audit service for API activity in AWS, and it records RunInstances as a management event. Each CloudTrail event includes the userIdentity object with the IAM principal, role, or assumed-role session, along with sourceIPAddress, eventTime, userAgent, requestParameters, and responseElements containing the new instance IDs. By searching CloudTrail logs for RunInstances events, the security engineer can directly identify which IAM user or role launched the instance, enabling attribution and further investigation of the alleged data exfiltration.

Why this answer

AWS CloudTrail records API activity, including the RunInstances call that launched the EC2 instance, along with the identity (IAM user or role) that made the request. By querying CloudTrail events for the instance ID, the engineer can determine which principal launched it. This directly answers the attribution question.

Exam trap

SCS-C02 often tests the difference between network-level logs (VPC Flow Logs) and API-level audit logs (CloudTrail), so candidates pick Flow Logs when the question asks about identity attribution.

How to eliminate wrong answers

Option A is wrong because AWS Config tracks resource configuration changes and compliance, not the identity that performed API calls. Option B is wrong because VPC Flow Logs capture IP traffic metadata (source/dest, ports, accept/reject) but not IAM identity or API caller information. Option C is wrong because IAM Access Analyzer identifies resource policies that grant external access; it does not log who launched an instance.

25
MCQmedium

A security engineer is designing a system to centrally manage security rules across multiple AWS accounts. The engineer wants to ensure that any resources that are non-compliant with security policies are automatically remediated. Which combination of services should the engineer use?

A.AWS CloudTrail with Amazon SNS
B.Amazon GuardDuty with AWS Step Functions
C.AWS Security Hub with Amazon EventBridge
D.AWS Config with AWS Lambda for automatic remediation
AnswerD

AWS Config continuously records resource configuration changes and evaluates them against managed or custom rules to determine compliance. When a resource drifts from the required policy, AWS Config can invoke an AWS Lambda function as a remediation action, which can automatically apply corrective changes such as updating security groups, enabling encryption, or deleting orphaned resources. This combination provides both the compliance evaluation and the automatic remediation needed for a central management system, making it the correct choice.

Why this answer

AWS Config continuously evaluates resource configurations against desired policies (Config Rules), and its remediation action feature can invoke an AWS Lambda function automatically when a resource is found non-compliant. This combination provides both centralized, multi-account compliance evaluation (via a Config aggregator) and automated remediation, which is exactly what the question requires. Lambda gives the custom logic needed to fix the non-compliant resource, making this the only option that delivers automatic remediation based on compliance state.

Exam trap

SCS-C02 often tests the distinction between detection/aggregation services (Security Hub, GuardDuty, CloudTrail) and the only service that natively evaluates configuration compliance and can trigger automatic remediation (AWS Config with Lambda/SSM Automation) — candidates frequently pick Security Hub with EventBridge because it sounds like centralized compliance management, but it lacks built-in remediation.

How to eliminate wrong answers

Option A is wrong because CloudTrail only records API activity for auditing and SNS merely delivers notifications — neither evaluates resource compliance nor performs remediation. Option B is wrong because GuardDuty is a threat-detection service that identifies malicious activity or compromised credentials; it does not assess resource configuration compliance, and Step Functions alone cannot remediate without a compliance signal. Option C is wrong because Security Hub aggregates and prioritizes findings from services like GuardDuty, Inspector, and Config, and EventBridge can route those findings, but this pairing only detects and routes events — it does not automatically remediate non-compliant resources without an additional remediation target such as Lambda or SSM Automation.

26
MCQhard

Refer to the exhibit. A security engineer applies this bucket policy to an S3 bucket. A user without HTTPS tries to download an object. What is the outcome?

A.The request is denied because the condition matches
B.The request fails because the condition does not match
C.The request succeeds because the policy has a Deny effect
D.The request succeeds because the resource is not specific enough
AnswerA

The request is denied because the condition matches — i.e., the request was made over plain HTTP, so the aws:SecureTransport boolean value is false, causing the condition "Bool": {"aws:SecureTransport": "false"} to evaluate true. When the Deny statement's condition is satisfied, the explicit deny overrides any Allow, so S3 returns 403 AccessDenied. The resource ARN covering the object bucket is also broad, but that is not the operative issue.

Why this answer

The bucket policy includes a condition that denies requests when `aws:SecureTransport` is `false`. Since the user attempts to download an object without HTTPS, the condition matches, and the explicit Deny effect overrides any Allow. Therefore, the request is denied.

Exam trap

The trap here is that candidates may think a Deny effect always denies, but they must check whether the condition evaluates to true; if the condition does not match, the Deny is not applied, and the request could succeed based on other policies.

How to eliminate wrong answers

Option B is wrong because the condition does match (the request lacks HTTPS, so `aws:SecureTransport` is false), so the Deny applies. Option C is wrong because the policy has a Deny effect, which denies the request, not allows it to succeed. Option D is wrong because the resource is specific enough (the bucket ARN is explicit), and the Deny effect is triggered by the condition, not by resource specificity.

27
Multi-Selecteasy

Which TWO of the following are valid AWS IAM security best practices?

Select 2 answers
A.Implement a strong password policy for IAM users.
B.Share IAM user access keys among team members for convenience.
C.Delete IAM users instead of disabling them when not needed.
D.Enable multi-factor authentication (MFA) for privileged users.
E.Use the AWS account root user for everyday administrative tasks.
AnswersA, D

A strong password policy enforces length, complexity and rotation, reducing credential-guessing and brute-force success against IAM users. It satisfies the stem's best-practise criterion by hardening the primary authentication secret before other controls are layered on.

Why this answer

Option A is correct because implementing a strong IAM account password policy enforces complexity requirements such as minimum length, uppercase/lowercase, numbers, symbols, and rotation, which reduces the risk of brute-force and credential-guessing attacks against IAM user sign-ins. Option D is correct because enabling MFA for privileged users adds a second authentication factor, so a compromised password alone is insufficient to perform sensitive actions, which is a core AWS IAM best practice. Option B is not a best practice because IAM access keys are long-term credentials tied to a specific identity and must never be shared; sharing them breaks accountability and complicates rotation and revocation.

Option C is not correct as stated because AWS recommends disabling (deactivating) credentials and removing permissions before deleting users, and deletion should be done only when the identity is truly no longer needed. Option E is not a best practice because the root user has unrestricted access and should be used only for the few tasks that require it, with MFA enabled and access keys removed.

Exam trap

SCS-C02 often tests the root-user and credential-sharing misconceptions; candidates who think deleting users is cleaner than disabling, or that root is fine for admin work, pick the wrong options.

28
MCQeasy

A security engineer needs to ensure that an Amazon S3 bucket is not publicly accessible. Which AWS service can be used to continuously monitor and alert if the bucket becomes public?

A.AWS CloudTrail
B.AWS Config
C.AWS Trusted Advisor
D.Amazon GuardDuty
AnswerB

AWS Config continuously records the configuration state of your S3 bucket and evaluates it against managed rules such as s3-bucket-public-read-prohibited, s3-bucket-encryption-enabled, and s3-bucket-versioning-enabled. When a bucket configuration drifts from the expected baseline, AWS Config marks the resource noncompliant and can trigger remediation via Systems Manager Automation or alert you through Amazon SNS. This native configuration governance is precisely what is needed to ensure the bucket remains compliant, not merely observed or protected.

Why this answer

(AWS Config) is correct because AWS Config has managed rules such as 's3-bucket-public-read-prohibited' and 's3-bucket-public-write-prohibited' that can evaluate S3 bucket policies and ACLs, continuously monitor configurations, and trigger alerts via Amazon SNS when a bucket becomes public. Option A (AWS CloudTrail) is wrong because CloudTrail records API calls but does not evaluate resource configurations. Option C (AWS Trusted Advisor) provides best-practice checks but does not offer continuous monitoring and alerting for configuration changes.

Option D (Amazon GuardDuty) focuses on threat detection, not configuration compliance.

29
MCQhard

A security engineer attaches the above SCP to an OU containing development accounts. The engineer expects that only t3.micro instances can be launched, but developers report that they cannot launch any EC2 instances. What is the MOST likely reason?

A.The SCP syntax is invalid because it uses Deny without an explicit Allow.
B.The condition StringNotEquals is evaluated incorrectly for EC2 instance types.
C.The SCP is applied at the organization root and overrides the OU-level policy.
D.The SCP denies all ec2 actions because there is no explicit allow statement.
AnswerD

SCPs act as permission boundaries and never grant permissions; they only filter the actions that IAM policies allow. If an SCP contains only Deny statements and no Allow statement permitting EC2 actions, the implicit default deny applies to every EC2 API call, regardless of what IAM identity-based policies grant. This is why the policy denies all EC2 actions.

Why this answer

SCPs operate on a default-deny model: all actions are implicitly denied unless explicitly allowed. The policy only denies non-t3.micro instance types but does not include an explicit Allow statement for ec2:RunInstances or any other EC2 action. Without an explicit Allow, the implicit deny blocks all EC2 actions, including launching t3.micro instances.

Exam trap

The trap here is that candidates assume a Deny statement with a condition implicitly allows all other actions, forgetting that SCPs follow a default-deny model where any action not explicitly allowed is denied.

How to eliminate wrong answers

Option A is wrong because SCPs do not require an explicit Allow alongside a Deny; they can use Deny alone to restrict actions, but the issue here is the lack of any Allow statement. Option B is wrong because the StringNotEquals condition is evaluated correctly—it denies instance types that are not t3.micro, but the problem is the missing Allow for the action itself. Option C is wrong because the SCP is attached to the OU, not the root, and even if a root-level SCP existed, it would not override the OU-level policy unless explicitly set to deny; SCPs are additive and the most restrictive applies.

30
MCQmedium

A company has a multi-account AWS environment managed with AWS Organizations. The security team wants to ensure that no EC2 instance in any account can be launched without a specific tag 'CostCenter'. The team has created a Service Control Policy (SCP) that denies the ec2:RunInstances action if the request does not include the tag 'CostCenter'. However, they find that instances are still being launched without the tag in some accounts. What is the most likely reason?

A.The SCP uses the wrong condition key; it should use 'aws:ResourceTag' instead.
B.The accounts launching instances without tags are the management account.
C.The SCP does not include an explicit allow for the action.
D.The SCP is not attached to the organizational units containing the accounts.
AnswerB

In AWS Organizations, the management account is explicitly exempt from all SCPs; SCPs can only restrict access for member accounts. If the SCP is attached at the root or to the relevant OUs and untagged instances still appear, the launches must be originating from the management account, whose principals are not evaluated against any SCP and therefore retain full permissions.

Why this answer

The most likely reason is that the accounts launching instances without the tag are the management account. Service Control Policies (SCPs) do not affect the management account in AWS Organizations; they only apply to member accounts. Therefore, if the security team is testing from the management account, the SCP denying ec2:RunInstances without the 'CostCenter' tag will not be enforced.

Option A is incorrect because 'aws:RequestTag' is the correct condition key for tagging requests, not 'aws:ResourceTag'. Option C is incorrect because SCPs work by denying actions, not by requiring explicit allows. Option D is incorrect because the SCP would still prevent unauthorized launches even without an explicit allow.

The issue is specifically that SCPs do not apply to the management account.

31
Multi-Selecteasy

Which TWO AWS services can be used to detect and alert on unauthorized API calls in real time?

Select 2 answers
A.Amazon CloudWatch Alarms
B.AWS KMS
C.Amazon EventBridge
D.AWS IAM
E.AWS Config
AnswersA, C

CloudWatch Alarms work with CloudTrail by using metric filters that are applied to log groups containing CloudTrail events. When the metric filter detects a pattern such as a specific unauthorized API action or a spike in failed calls, the alarm shifts to ALARM and publishes to an SNS topic to alert operators. This threshold-based approach is one of the standard ways to turn historical CloudTrail logs into actionable alerts.

Why this answer

Amazon CloudWatch Alarms (A) is correct because you can create metric filters on CloudTrail log groups that match unauthorized API calls (e.g., AccessDenied or specific error codes), and the alarm triggers an SNS notification in near real time. Amazon EventBridge (C) is correct because it can receive CloudTrail management events, match patterns for unauthorized API activity (such as errorCode values), and route them to targets like SNS, Lambda, or SQS for immediate alerting. AWS KMS (B) is a key management service, not an API-call detection or alerting service.

AWS IAM (D) controls authentication and authorization but does not itself detect or alert on unauthorized calls. AWS Config (E) evaluates resource configuration compliance and records configuration changes, not real-time API-call alerting.

Exam trap

SCS-C02 often tests the distinction between detection services (GuardDuty, CloudWatch, EventBridge) and configuration/identity services (Config, IAM, KMS) — candidates may pick AWS Config thinking it alerts on API calls, but Config is for compliance evaluation, not real-time API monitoring.

32
MCQmedium

A company wants to centrally manage IAM users and allow them to access multiple AWS accounts using a single set of credentials. Which AWS service should be used?

A.AWS IAM Identity Center (AWS SSO)
B.IAM roles with cross-account trust
C.AWS Organizations consolidated billing
D.Amazon Cognito user pools
AnswerA

AWS IAM Identity Center (AWS SSO) is the correct service for centrally managing IAM users across multiple AWS accounts because it provides a single identity source and allows users to sign in once with temporary credentials issued through AWS STS. It supports creating users directly, connecting an external identity provider for federation, and assigning permission sets that control access across all accounts in an AWS Organization, eliminating the need for long-lived IAM user access keys and enabling a single sign-on experience.

Why this answer

AWS IAM Identity Center (formerly AWS SSO) is the correct service because it provides a centralized identity source that allows users to sign in once with a single set of credentials and then access multiple AWS accounts and business applications. It integrates with AWS Organizations to automatically manage permissions across accounts, eliminating the need for separate IAM users in each account.

Exam trap

The trap here is that candidates often confuse IAM roles with cross-account trust as a centralized solution, but they require manual role setup and do not provide a single sign-on portal or unified credential management across accounts.

How to eliminate wrong answers

Option B is wrong because IAM roles with cross-account trust allow users in one account to assume roles in another account, but they still require separate IAM users in the originating account and do not provide a single sign-on experience with a unified credential set. Option C is wrong because AWS Organizations consolidated billing only aggregates billing and payment across accounts; it does not manage user identities or provide authentication. Option D is wrong because Amazon Cognito user pools are designed for customer-facing identity and access management for web and mobile applications, not for centrally managing IAM users accessing multiple AWS accounts.

33
MCQmedium

A security team needs to ensure that all API calls made in the AWS account are logged and the logs are stored in a central S3 bucket that is encrypted with a KMS key. Which combination of steps should the team take to achieve this?

A.Enable AWS Config and have it deliver configuration history to an encrypted S3 bucket.
B.Enable CloudWatch Logs and stream logs to an encrypted S3 bucket.
C.Enable VPC Flow Logs and publish to an encrypted S3 bucket.
D.Enable CloudTrail and configure it to deliver logs to an encrypted S3 bucket.
AnswerD

AWS CloudTrail is the service explicitly designed to log every API call made in your AWS account, recording details like caller identity, source IP, request parameters, and response data. You can configure a trail to deliver these JSON log files to an S3 bucket, and enabling encryption on that bucket (e.g., with SSE-KMS or SSE-S3) protects the logs at rest. This satisfies the requirement to ensure all API calls are logged and stored securely.

Why this answer

AWS CloudTrail records all API calls made in an AWS account, including management events and optionally data events, and can be configured to deliver log files to a central S3 bucket. By enabling CloudTrail with an S3 bucket destination and configuring the bucket with SSE-KMS encryption using a KMS key, the team meets both requirements: logging all API calls and storing logs encrypted with KMS. This is the standard AWS approach for API activity auditing.

Exam trap

The trap is confusing services that log activity (CloudTrail for API calls, Config for resource changes, VPC Flow Logs for network traffic) and selecting one that does not capture API calls.

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configuration changes and compliance, not API calls; it does not provide a complete API call audit trail. Option B is wrong because CloudWatch Logs captures log data from services and applications but does not natively log all AWS API calls; it is not the API auditing service. Option C is wrong because VPC Flow Logs capture IP traffic metadata to and from network interfaces, not API calls, and cannot log AWS API activity.

34
MCQeasy

A company wants to use AWS CloudFormation to manage infrastructure. The security team requires that all templates are scanned for security vulnerabilities before deployment. Which service should be integrated into the pipeline?

A.Amazon Inspector
B.AWS CloudFormation Guard
C.AWS Config
D.AWS Shield Advanced
AnswerB

AWS CloudFormation Guard is the correct choice because it is a policy-as-code engine designed to validate CloudFormation templates (and JSON/YAML in general) against custom rules before deployment. You define guards, such as 'every S3 bucket must have encryption enabled' or 'no IAM user with administrator access', and the Guard CLI or CI/CD integration checks the template's structure and properties. Any noncompliant resource is flagged in the pre-deployment phase, letting you fail the pipeline before infrastructure is created.

Why this answer

AWS CloudFormation Guard (cfn-guard) is a policy-as-code tool that allows you to define rules to validate CloudFormation templates against security best practices before deployment. It integrates into CI/CD pipelines to enforce compliance with organizational policies, such as ensuring encryption is enabled or public access is restricted, directly addressing the requirement to scan templates for security vulnerabilities.

Exam trap

The trap here is confusing runtime vulnerability scanning (Amazon Inspector) with pre-deployment template validation (CloudFormation Guard), leading candidates to choose Inspector because they associate 'security vulnerabilities' with runtime scanning rather than infrastructure-as-code compliance.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability management service that scans running EC2 instances, container images, and Lambda functions for software vulnerabilities and network exposure, not CloudFormation templates. Option C is wrong because AWS Config is a service for evaluating and auditing the configuration of deployed AWS resources against desired policies, not for scanning infrastructure-as-code templates before deployment. Option D is wrong because AWS Shield Advanced is a managed Distributed Denial of Service (DDoS) protection service for applications running on AWS, not a tool for scanning CloudFormation templates.

35
MCQmedium

A security engineer is designing a cross-account access policy. The engineer has an S3 bucket in Account A and wants to grant read access to a user in Account B. Which combination of policies is required?

A.A bucket policy in Account A that allows access to the user in Account B.
B.A bucket ACL in Account A granting access to the user in Account B.
C.An IAM policy in Account B that grants s3:GetObject to the bucket.
D.A bucket policy in Account A allowing the user, and an IAM policy in Account B granting s3:GetObject.
AnswerD

This is correct. The bucket policy in Account A acts as a resource-based policy that grants the external user access to the object, while the IAM policy in Account B gives that user the identity-based permission to make the request. Both policies are evaluated, and the union of permissions allows the cross-account S3 GetObject. This follows the standard S3 cross-account access model where both the resource-based and identity-based policies must allow the action.

Why this answer

Cross-account access to an S3 bucket requires both a resource-based policy (bucket policy) in Account A that grants permissions to the user in Account B, and an identity-based policy (IAM policy) in Account B that allows the user to perform the s3:GetObject action. Without both, access is denied. Option A is wrong because a bucket policy alone is insufficient; the user still needs an IAM policy in their own account to allow the action.

Option B is wrong because bucket ACLs are a legacy mechanism and do not effectively support cross-account access for specific IAM users; they would still require an IAM policy in Account B. Option C is wrong because an IAM policy in Account B alone is insufficient; the bucket policy in Account A must explicitly grant access to the user, as the bucket's default policy denies access from other accounts.

36
MCQhard

A company has a multi-account AWS Organization with hundreds of accounts. The security team wants to prevent any IAM user from creating access keys in any account. What is the most scalable and secure approach?

A.Use IAM Access Analyzer to generate findings when access keys are created.
B.Configure IAM password policies in each account to disallow access keys.
C.Apply an SCP that denies the IAM:CreateAccessKey action to all accounts in the organization.
D.Create an AWS Config rule in each account to automatically delete access keys.
AnswerC

A service control policy attached to the organization root, an OU, or individual accounts can explicitly deny the IAM:CreateAccessKey action, and because SCP deny statements override all identity-based and resource-based allows in the affected accounts, no principal in those accounts can create a new access key. This provides a centralized, preventive guardrail that scales across all accounts without requiring per-account configuration or custom automation. It is important to note that an SCP only prevents future creation and does not remove or invalidate access keys that already exist.

Why this answer

Service Control Policies (SCPs) applied at the organization or OU level deny the IAM:CreateAccessKey action across every account in one place, which is the most scalable and preventive control. Because SCPs are inherited, a single policy blocks access key creation in all current and future accounts without per-account configuration.

Exam trap

SCS-C02 often tests the difference between preventive controls (SCPs) and detective controls (Config, Access Analyzer) — candidates pick Config or Access Analyzer because they sound like governance tools, missing that only SCPs block the action before it happens.

How to eliminate wrong answers

Option A is wrong because IAM Access Analyzer generates findings about externally accessible resources; it does not detect or block access key creation. Option B is wrong because IAM password policies govern password complexity and rotation for console users — they have no effect on access keys, which are a separate credential type. Option D is wrong because an AWS Config rule is detective and per-account; it would require deployment in every account and only deletes keys after they are created, which is neither preventive nor scalable.

37
MCQhard

A company uses AWS Organizations and has a requirement to enforce that all EC2 instances launched in any account must have a specific tag "Environment" with value "Production". The security team wants to prevent any instance without this tag from being launched. They implement a service control policy (SCP) that denies the ec2:RunInstances action if the request does not include the required tag. However, they find that users are still able to launch instances without the tag. The SCP is attached to the root OU. The team also has an IAM policy that allows ec2:RunInstances with no conditions. What is the most likely reason the SCP is not preventing the launches?

A.The SCP does not apply to the root user in member accounts.
B.The IAM policy allows the action, which overrides the SCP deny.
C.The SCP is applied to the management account, not the member accounts.
D.The SCP uses ec2:ResourceTag instead of aws:RequestTag for the condition.
AnswerD

For ec2:RunInstances, tags supplied in the request are evaluated through the aws:RequestTag condition key; ec2:ResourceTag evaluates tags on existing resources, which do not yet exist at launch. The SCP therefore never matches the request, so untagged instances launch despite the deny statement.

Why this answer

The SCP uses the condition key ec2:ResourceTag, which evaluates tags on the EC2 instance resource, but at the time of RunInstances, the instance does not yet exist, so the tag is not present. To enforce tagging at launch, the SCP must use the aws:RequestTag condition key, which checks tags included in the request. Therefore, the SCP fails to deny launches without the required tag.

Exam trap

The trap is confusing ec2:ResourceTag with aws:RequestTag; candidates often think that tagging an instance after launch can satisfy a ResourceTag condition, but the condition is evaluated at the time of the API call, and for RunInstances, the resource tag does not exist yet.

How to eliminate wrong answers

Option A is wrong because SCPs do apply to IAM users and roles in member accounts, including the root user of member accounts (though not the management account). Option B is wrong because SCPs take precedence over IAM policies; an explicit deny in an SCP overrides any allow in IAM. Option C is wrong because SCPs attached to the root OU apply to all member accounts, not the management account, but the issue is not about the management account.

38
MCQeasy

A company has a requirement to audit all API calls made to AWS services in their account. Which AWS service should be used to meet this requirement?

A.AWS Config
B.Amazon Inspector
C.Amazon GuardDuty
D.AWS CloudTrail
AnswerD

AWS CloudTrail is the correct service because it logs every API call made to AWS services as an event, capturing the identity of the caller, the time of the call, source IP address, request parameters, and the response returned. These events can be delivered to Amazon S3 and CloudWatch Logs, and queried via Athena, enabling a complete, tamper-evident audit trail. CloudTrail trails can record management events, data events, and insights events, making it the authoritative source for API auditing across the account or organization.

Why this answer

AWS CloudTrail records all API calls made to AWS services in an account, capturing the identity of the caller, the time, the source IP, the request parameters, and the response. It is the authoritative service for auditing API activity across the AWS account, and it can deliver logs to S3, CloudWatch Logs, or EventBridge for analysis and alerting. Enabling CloudTrail in all regions with log file validation is a standard compliance requirement.

Exam trap

The trap is confusing CloudTrail (API audit logging) with AWS Config (resource configuration history) or GuardDuty (threat detection) — candidates often pick Config because it also provides a history, but only CloudTrail logs every API call.

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configuration changes and evaluates compliance against rules, but it does not log every API call — it tracks resource state, not the full API audit trail. Option B is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances, container images, and Lambda functions for software vulnerabilities and network exposure, not API activity. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes CloudTrail, VPC Flow Logs, and DNS logs for malicious activity, but it does not itself provide the raw audit log of all API calls — that is CloudTrail's role.

39
MCQmedium

A company wants to ensure that IAM users with console access have strong passwords. Which IAM password policy setting should the company configure to enforce the use of at least one uppercase letter?

A.MinimumPasswordLength
B.RequireUppercaseCharacters
C.RequireNumbers
D.RequireSymbols
AnswerB

RequireUppercaseCharacters is the password policy parameter that forces every IAM user password to contain at least one uppercase letter, directly satisfying the stated requirement for console users. Setting it to true makes IAM reject any password lacking an uppercase character at creation or change time.

Why this answer

The IAM password policy setting `RequireUppercaseCharacters` specifically enforces that IAM user passwords contain at least one uppercase letter (A-Z). When enabled, any password created or changed must include an uppercase character, otherwise IAM rejects it. This directly satisfies the requirement to enforce uppercase letters for console users.

Exam trap

SCS-C02 often tests the specific IAM password policy settings and their exact enforcement, so candidates must distinguish between length, uppercase, lowercase, numbers, and symbols requirements rather than assuming any complexity setting enforces uppercase.

How to eliminate wrong answers

Option A is wrong because `MinimumPasswordLength` only sets the minimum number of characters (e.g., 8 to 128) and does not enforce character composition like uppercase letters. Option C is wrong because `RequireNumbers` enforces at least one numeric digit (0-9), not an uppercase letter. Option D is wrong because `RequireSymbols` enforces at least one non-alphanumeric symbol (e.g., ! @ # $ % ^ & * ( ) _ + - = [ ] { } | '), not an uppercase letter.

40
MCQmedium

A company has a multi-account AWS Organization with 50 accounts. The security team uses AWS CloudTrail to log all API calls and sends the logs to a central S3 bucket in the security account. The team wants to ensure that any attempt to disable CloudTrail logging or delete the trail is detected and automatically remediated within 5 minutes. They have configured an AWS Config rule that triggers an AWS Lambda function when the CloudTrail configuration changes. However, the Lambda function is not being invoked when they test by stopping the trail. The Lambda function's IAM role has permissions to start and update CloudTrail. CloudTrail logs show that the Config rule is evaluating the resource, but the Lambda function is not triggered. What is the most likely cause?

A.The S3 bucket policy does not allow CloudTrail to write logs.
B.The Lambda function's IAM role does not have permission to modify CloudTrail.
C.The CloudTrail trail does not have permission to send logs to the S3 bucket.
D.The AWS Config service does not have permission to invoke the Lambda function.
AnswerD

For a custom AWS Config rule backed by Lambda, AWS Config must be explicitly allowed to invoke the Lambda function. This is done by adding a resource-based policy to the Lambda function that grants the `config.amazonaws.com` service principal permission to call `lambda:InvokeFunction`. Without that policy, AWS Config returns an access denied error when it attempts to trigger the Lambda for each configuration snapshot. The Lambda execution role is irrelevant to this authorization step, which is why the invocation fails despite the role having CloudTrail permissions.

Why this answer

AWS Config uses a service-linked role or a configured IAM role to invoke the Lambda function as the remediation action. If the Config service does not have permission to invoke the Lambda function — typically because the Lambda function's resource-based policy does not grant config.amazonaws.com the lambda:InvokeFunction permission, or the Config service role lacks the necessary trust — the rule will evaluate the resource but the remediation action will silently fail to trigger the Lambda. The question states the Lambda role already has CloudTrail permissions, so the missing link is Config's ability to invoke Lambda.

Exam trap

The trap here is that candidates focus on the Lambda execution role's permissions (which are already correct) and overlook the separate requirement that the AWS Config service itself must be granted permission to invoke the Lambda function via the function's resource-based policy.

How to eliminate wrong answers

Option A is wrong because the S3 bucket policy controlling CloudTrail log delivery is unrelated to whether the Config rule can invoke a Lambda function; CloudTrail logs are already being delivered since the team can see Config rule evaluations. Option B is wrong because the question explicitly states the Lambda function's IAM role already has permissions to start and update CloudTrail, so this is not the missing permission. Option C is wrong because the CloudTrail trail's permission to send logs to S3 is also unrelated to the Config-to-Lambda invocation path, and CloudTrail logging is clearly working since the team can observe Config rule evaluations and CloudTrail logs.

41
MCQhard

A company's security team discovers that an EC2 instance in the production account has been compromised. The instance has an IAM role attached that allows it to read from an S3 bucket containing sensitive data. The team needs to immediately stop the data exfiltration while preserving the evidence. What should the team do first?

A.Detach the S3 bucket from the VPC endpoint.
B.Apply an inline policy to the IAM role that denies all S3 actions.
C.Remove the IAM role from the EC2 instance.
D.Terminate the compromised EC2 instance immediately.
AnswerB

Attaching an inline policy with an explicit deny for all S3 actions to the EC2 instance's IAM role immediately blocks all S3 API calls because explicit denies override any allow statements, and IAM policies are evaluated at request time. This containment works for any temporary credentials already issued, since every request is re-authorized against the role's current policies, and it does not destroy the instance or remove evidence needed for investigation. This is the fastest, least invasive way to stop S3 exfiltration.

Why this answer

The correct first step because applying an inline policy that denies all S3 actions to the IAM role immediately stops the compromised instance from accessing the S3 bucket, preventing data exfiltration while preserving the instance's state for forensic investigation. Option A is incorrect because detaching the S3 bucket from the VPC endpoint does not affect the instance's ability to access S3 through the internet or other endpoints. Option C is incorrect because removing the IAM role from the instance may not take effect immediately if the role's credentials are cached, and it could disrupt evidence collection.

Option D is incorrect because terminating the instance would destroy volatile evidence and might not stop exfiltration in time if the instance is already sending data.

42
Multi-Selectmedium

Which TWO are best practices for managing IAM policies? (Select TWO.)

Select 2 answers
A.Use wildcards (*) to simplify policy management
B.Use inline policies instead of managed policies
C.Use SCPs to enforce permissions
D.Grant least privilege by using specific actions and resources
E.Use AWS managed policies when possible
AnswersD, E

Granting least privilege means constructing IAM policies so that every Action and Resource element is scoped to the specific operations and ARNs the principal actually needs, and where applicable adding condition keys such as 'aws:PrincipalTag' or 'aws:RequestedRegion' to further constrain access. For example, instead of allowing 's3:ListBucket' on all buckets, the policy should list the exact bucket name in the Resource and restrict the action to relevant key prefixes, while also avoiding overly broad Principal elements in resource policies. This practice reduces the attack surface, limits the impact of compromised credentials, and is a foundational requirement of the AWS Well-Architected Framework's security pillar.

Why this answer

The principle of least privilege is a foundational security best practice in AWS IAM. By specifying exact actions (e.g., s3:GetObject) and resources (e.g., arn:aws:s3:::example-bucket/*) instead of using wildcards, you minimize the blast radius of a compromised credential or misconfigured policy. This aligns with the AWS Well-Architected Framework's security pillar, which mandates granting only the permissions required to perform a task.

Exam trap

The trap here is that candidates often confuse SCPs as a method to grant permissions, when in fact SCPs only define a maximum permission boundary and cannot grant any access—permissions must still be explicitly allowed by IAM policies within the account.

43
MCQhard

A security engineer needs to monitor for unauthorized API calls in real-time. Which combination of services should be used?

A.Amazon S3 event notifications and AWS Lambda
B.AWS CloudTrail and Amazon CloudWatch Logs with metric filters
C.AWS Config and Amazon SNS
D.Amazon GuardDuty and AWS CloudTrail
AnswerB

CloudTrail records every management and data API call as a JSON log entry containing the requesting IAM principal, the action, and the service, including access-denied errors such as UnauthorizedOperation or AccessDenied. When the trail is configured to deliver to CloudWatch Logs, you can create a metric filter with a pattern that matches specific error codes, and then attach a CloudWatch Alarm to that metric to notify on unauthorized API calls. This creates a deterministic, near-real-time alerting pipeline across the entire AWS account, which is exactly what the security engineer needs.

Why this answer

AWS CloudTrail records all API calls in an AWS account, and CloudWatch Logs can ingest those logs. By creating metric filters on CloudWatch Logs, you can define patterns that match unauthorized API calls (e.g., AccessDenied errors) and trigger alarms in real time. This combination provides the necessary logging and real-time monitoring capability.

Exam trap

The SCS-C02 exam often tests the distinction between services that log events (CloudTrail) versus services that detect threats (GuardDuty) versus services that monitor configuration (Config), leading candidates to choose GuardDuty because it sounds security-focused, but it does not provide real-time metric-based alerting on raw API calls.

How to eliminate wrong answers

Option A is wrong because Amazon S3 event notifications are designed to notify on S3 object-level events (e.g., PUT, DELETE), not on API calls across all AWS services; they lack the ability to monitor unauthorized API calls broadly. Option C is wrong because AWS Config is a service for resource inventory, configuration history, and compliance rules, not for real-time monitoring of API call logs; Amazon SNS alone cannot parse or filter API call data. Option D is wrong because Amazon GuardDuty is a threat detection service that analyzes findings from multiple sources (including CloudTrail) but does not provide real-time monitoring of raw API calls itself; it relies on CloudTrail for data but adds latency for threat analysis rather than immediate metric-based alerting.

44
MCQhard

Refer to the exhibit. A security engineer applied the bucket policy shown. What is the effect of this policy?

A.All PutObject requests are denied.
B.Only GetObject requests that use HTTP are denied.
C.Only GetObject requests from specific IP ranges are denied.
D.All GetObject requests to the bucket are denied.
AnswerB

Correct. The policy denies GetObject requests when aws:SecureTransport is false (HTTP).

Why this answer

The bucket policy includes a Deny statement for s3:GetObject requests that are not using HTTPS. The condition `aws:SecureTransport` is set to false, meaning the request is over HTTP. Therefore, any GetObject request made over HTTP is denied.

PutObject requests are not affected, and GetObject requests over HTTPS are allowed regardless of IP address.

Exam trap

The trap here is that candidates overlook the `Null` condition on `aws:SecureTransport` and assume the `NotIpAddress` condition alone denies all requests from outside the IP range, missing that the policy only triggers when the request is over HTTP.

How to eliminate wrong answers

Option A is wrong because the policy only denies `s3:GetObject`, not `s3:PutObject`, so PutObject requests are not denied. Option C is wrong because the policy denies requests from IPs outside the specified range only when the request uses HTTP; it does not deny requests from specific IP ranges—it denies requests not from that range, but only under the HTTP condition. Option D is wrong because the policy does not deny all GetObject requests; it only denies those made over HTTP, leaving HTTPS GetObject requests unaffected.

45
MCQeasy

A security engineer needs to audit all API calls made in an AWS account for the past 90 days. Which AWS service should the engineer use?

A.Amazon S3 access logs
B.AWS CloudTrail
C.AWS Config
D.Amazon CloudWatch Logs
AnswerB

AWS CloudTrail is the authoritative audit service that records every API call made in the account, including the identity of the principal, the source IP address, the time, and the request parameters. By default, it captures management events across all AWS services, and it can be configured to log data events for services like S3 and Lambda. These event logs are delivered to an S3 bucket and can be integrated with CloudWatch Logs for alerting and analysis, making it the correct choice for comprehensive API auditing.

Why this answer

AWS CloudTrail (Option B) is the correct service for auditing all API calls made in an AWS account over the past 90 days. It records API activity and can be configured to store logs for 90 days in the management event history. Option A (Amazon S3 access logs) logs access to S3 objects, not API calls.

Option C (AWS Config) tracks resource configuration changes, not API calls. Option D (Amazon CloudWatch Logs) is for monitoring, storing, and accessing log files from various sources, but it is not specifically designed for auditing API calls; CloudTrail is the primary service for that purpose.

46
MCQeasy

A security team needs to audit all changes to IAM policies in their AWS account. Which AWS service should they use to record policy changes?

A.Amazon Inspector
B.AWS CloudTrail
C.Amazon GuardDuty
D.AWS Config
AnswerB

AWS CloudTrail is the correct service because it provides a continuous, immutable audit log of every API call made in your AWS account, including the IAM actions that modify policies such as PutRolePolicy, AttachUserPolicy, and DeletePolicy. Each event captures the identity of the caller, the source IP, the time, and the request parameters, making it the definitive source for security audits of IAM changes. CloudTrail's event history is viewable for 90 days, and you can extend retention with a trail that delivers events to an S3 bucket or CloudWatch Logs for long-term compliance.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made in the AWS account, including IAM policy changes (e.g., CreatePolicy, PutRolePolicy, AttachUserPolicy). These events are captured as CloudTrail log entries, providing a complete audit trail of who made the change, when, and from which source IP. This directly meets the requirement to audit all changes to IAM policies.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks resource configuration state) with CloudTrail (which tracks API call history), leading them to choose AWS Config because it can detect drift, but it does not provide the detailed audit trail of who made the change and when.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability assessment service that scans for software vulnerabilities and unintended network exposure, not a service that records API activity or policy changes. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes DNS logs, VPC flow logs, and CloudTrail events for malicious activity, but it does not itself record or store the raw API call history for IAM policy changes. Option D is wrong because AWS Config evaluates and records resource configuration changes (e.g., whether an IAM policy is attached to a user) and can trigger rules, but it does not capture the API call details (who, when, source IP) that are required for a complete audit trail of policy changes; that is CloudTrail's role.

47
MCQhard

A security engineer notices that an S3 bucket policy allows access to a principal from another AWS account. Which AWS feature can be used to check if this external access is intended?

A.AWS Trusted Advisor bucket permissions check
B.AWS Config rule s3-bucket-public-read-prohibited
C.AWS CloudTrail event history
D.AWS IAM Access Analyzer
AnswerD

IAM Access Analyzer continuously analyzes resource-based policies and creates findings whenever access to a resource like an S3 bucket is granted to an external principal — an AWS account outside your zone of trust or an anonymous principal. Each finding details the external account/principal, the exact actions allowed, and the policy statement causing the access, so you can determine whether that access is intended. In the console you can then mark the finding as 'Archive' for intended access or take remediation action for unintended access, which is the only option here that directly answers the security engineer's question.

Why this answer

IAM Access Analyzer generates findings for external access to S3 buckets. You can review and archive findings if intended.

48
MCQmedium

Refer to the exhibit. A company uses this CloudFormation template. What security best practice is being violated?

A.The instance type is too small for production workloads.
B.The security group allows SSH access from all IP addresses.
C.The AMI ID is not specified as a parameter.
D.The EBS volume is not encrypted.
AnswerB

Allowing SSH (port 22) from 0.0.0.0/0 in the security group exposes the instance's administration interface to the entire internet, enabling brute-force attacks, credential stuffing, and potential unauthorized access. This directly violates the principle of least privilege and is a well-known high-severity misconfiguration, making it the most immediate security risk in the template.

Why this answer

The security group allows SSH access from all IP addresses (0.0.0.0/0), which is a significant security risk that exposes the instance to unauthorized access. Option A is wrong because the instance type is a performance consideration, not a security best practice. Option C is wrong because specifying the AMI ID as a parameter is not a security requirement; it is a parameterization best practice but not security-related.

Option D is wrong because while encryption is a security best practice, the most critical violation here is the open SSH access, as it directly exposes the instance to potential attacks.

49
Multi-Selecthard

Which TWO AWS services can be used to enforce that specific resource types (e.g., EC2 instances) are tagged with a 'CostCenter' tag? (Choose two.)

Select 2 answers
A.AWS Organizations tag policies
B.AWS Service Catalog
C.AWS Config
D.AWS CloudFormation
E.AWS IAM
AnswersA, C

AWS Organizations tag policies are a centralized policy type that define which tag keys and values are allowed on resources across all accounts in the organization. Attached to the root, an OU, or an account, they act as a preventive guardrail during resource creation and modification, so a resource that is tagged outside the allowed rules can be denied. This makes them the native service for enforcing specific tags organization-wide.

Why this answer

AWS Config can evaluate resource tagging and AWS Organizations can use tag policies. IAM is for permissions, not enforcement; CloudFormation can be used but not for existing resources; Service Catalog is for provisioning, not enforcement.

50
MCQeasy

What is the purpose of an AWS Service Control Policy (SCP) in AWS Organizations?

A.To grant specific permissions to users in member accounts.
B.To restrict only the root user of each member account.
C.To monitor and log API activity across the organization.
D.To set permission guardrails that restrict what actions accounts in the organization can perform.
AnswerD

SCPs set permission guardrails by defining the maximum actions that principals in an account or organizational unit can perform. When attached at the organization, OU, or account level, an SCP constrains all IAM users and roles in that account—including the account root user—by filtering what identity-based and resource-based policies are allowed to grant. They act as a boundary that limits, but never grants, permissions, making them the correct mechanism for organization-wide controls such as denying the deletion of CloudTrail logs or restricting access to certain AWS services.

Why this answer

SCPs are used to centrally control the maximum available permissions for all accounts in an organization. Option A is wrong because SCPs do not grant permissions; they restrict them. Option B is wrong because SCPs apply to all users and roles, not just root.

Option C is wrong because SCPs are not for monitoring; they are permission guardrails.

51
MCQeasy

A company wants to automate the enforcement of security best practices across all AWS accounts. Which AWS service provides pre-built rules for security compliance?

A.Amazon GuardDuty
B.Amazon Inspector
C.AWS Security Hub
D.AWS Config
AnswerC

AWS Security Hub aggregates security findings from across AWS accounts and services and runs automated, continuous compliance checks against standards such as CIS AWS Foundations, AWS Foundational Best Practices, and PCI DSS. It provides a consolidated security score and actionable insights, enabling automated enforcement of security best practices. This integration and standard-based evaluation make it the correct service for the stated requirement.

Why this answer

AWS Security Hub is the correct answer because it provides a comprehensive view of security alerts and compliance status across AWS accounts, and it includes pre-built security standards and automated compliance checks based on frameworks such as the AWS Foundational Security Best Practices (FSBP), CIS AWS Foundations Benchmark, and PCI DSS. These pre-built rules allow you to automate the enforcement of security best practices without manual configuration.

Exam trap

The trap here is that candidates often confuse AWS Config's managed rules (which evaluate resource configurations) with Security Hub's pre-built security compliance standards, but Security Hub is specifically designed for aggregating and automating security best practices across accounts, while Config is a configuration auditing tool without built-in security compliance frameworks.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior using machine learning and threat intelligence, but it does not provide pre-built rules for security compliance or automated compliance checks. Option B is wrong because Amazon Inspector is an automated vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, but it does not offer pre-built compliance rules or enforce security best practices across accounts. Option D is wrong because AWS Config is a service that evaluates your resource configurations against desired configurations using custom or managed rules, but it does not provide pre-built security compliance standards or a consolidated dashboard for security best practices across accounts; it focuses on resource configuration auditing rather than security compliance enforcement.

52
MCQhard

A security engineer is designing a solution to centrally manage security findings from multiple AWS services across an organization. The engineer needs to aggregate findings from Amazon GuardDuty, Amazon Inspector, and IAM Access Analyzer into a single view and take automated remediation actions based on severity. Which combination of AWS services should the engineer use?

A.AWS Trusted Advisor with Amazon EventBridge rules to trigger AWS Lambda for remediation.
B.AWS Security Hub with custom actions and Amazon EventBridge rules to trigger AWS Lambda for remediation.
C.Amazon CloudWatch Logs with metric filters and alarms to trigger AWS Lambda for remediation.
D.AWS Config with remediation actions and AWS Systems Manager Automation documents.
AnswerB

Security Hub aggregates findings from GuardDuty, Inspector, and IAM Access Analyzer into a single view. Custom actions allow you to define remediation steps, and EventBridge rules can trigger Lambda functions to automate remediation based on severity. This meets the requirement for centralized management and automated response.

Why this answer

AWS Security Hub is the central service that aggregates findings from GuardDuty, Inspector, IAM Access Analyzer, and other AWS services. By using Security Hub custom actions and EventBridge rules, you can automate remediation with Lambda based on severity, providing a single view and automated response.

Exam trap

The trap here is assuming that AWS Config or CloudWatch Logs can aggregate findings from multiple security services, when only Security Hub provides that centralized aggregation.

53
MCQhard

A company has a requirement that all access keys for IAM users must be rotated every 90 days. A security engineer needs to implement an automated solution to identify and disable keys that are older than 90 days. Which approach meets the requirement with the least operational overhead?

A.Use AWS Trusted Advisor to check key age and send notifications.
B.Use AWS CloudTrail to monitor CreateAccessKey events and trigger a Lambda function to check key age.
C.Use IAM Access Analyzer to generate findings for unused keys and manually disable them.
D.Use an AWS Config rule with auto-remediation to disable keys older than 90 days.
AnswerD

AWS Config continuously evaluates keys against a custom rule and auto-remediation invokes a remediation action to disable non-compliant keys, removing manual checks. This satisfies the 90-day rotation requirement with least operational overhead, since detection and disabling happen automatically without custom scheduling infrastructure.

Why this answer

AWS Config can evaluate IAM access key age against a desired rule (e.g., 'iam-access-key-rotated') and trigger automatic remediation using SSM Automation documents to disable keys older than 90 days. This provides a fully automated, low-overhead solution that continuously enforces the requirement without manual intervention.

Exam trap

The trap is selecting a monitoring or notification service (Trusted Advisor, CloudTrail, Access Analyzer) instead of an enforcement service (Config with auto-remediation) when the requirement explicitly asks for automated disabling with least operational overhead.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor only provides notifications and does not automatically disable keys, requiring manual action and thus higher operational overhead. Option B is wrong because CloudTrail logs CreateAccessKey events but does not natively evaluate key age; building a custom Lambda solution adds development and maintenance overhead. Option C is wrong because IAM Access Analyzer identifies unused permissions and generates findings, but it does not automatically disable keys and still requires manual remediation.

54
MCQeasy

A company wants to enforce that all IAM users use multi-factor authentication (MFA) to access the AWS Management Console. Which AWS service can be used to enforce this requirement?

A.AWS Organizations
B.AWS Config
C.AWS Identity and Access Management (IAM)
D.Amazon Cognito
AnswerC

AWS Identity and Access Management (IAM) is correct because MFA enforcement is implemented with an identity-based policy that uses the global condition key aws:MultiFactorAuthPresent. You attach a Deny statement with "BoolIfExists": {"aws:MultiFactorAuthPresent": "false"} to a user or group, which blocks every API action unless the principal signed in with a valid MFA token. This makes MFA a native part of IAM's authentication and authorization flow, directly satisfying the company's requirement for all IAM users.

Why this answer

AWS IAM allows you to create a policy with a condition that requires MFA for console access. Option A is wrong because AWS Organizations is used to manage multiple accounts, not to enforce MFA on individual users. Option B is wrong because AWS Config can check compliance but cannot enforce the requirement; it only evaluates resource configurations.

Option D is wrong because Amazon Cognito is used for external identity federation, not for enforcing MFA on IAM users.

55
Matchingmedium

Match each AWS security control to its category.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Stateful firewall at instance level

Stateless firewall at subnet level

Centralized management of firewall rules

Managed firewall for VPCs

Why these pairings

Security Groups are stateful instance-level firewalls, Network ACLs are stateless subnet-level firewalls. Common confusions involve mixing statefulness and level of operation.

56
MCQhard

A security engineer needs to ensure that all new IAM users are created with a strong password policy enforced. Which action should be taken?

A.Set a custom IAM password policy in the account
B.Use AWS Config to automatically delete users with weak passwords
C.Create a Lambda function that checks password strength on user creation
D.Use AWS Secrets Manager to generate passwords
AnswerA

Setting a custom IAM password policy is the native, account-wide control that enforces minimum length, complexity, rotation, and reuse restrictions for all IAM users. When any IAM user creates a password or resets a forgotten one, IAM evaluates it against this policy and rejects non-compliant choices, so it directly satisfies the requirement. It is the only option that applies automatically to every new user without custom infrastructure or reliance on post-creation events.

Why this answer

AWS IAM account password policies are configured at the account level and apply to all IAM users created in that account. Setting a custom password policy enforces minimum length, complexity, reuse prevention, and rotation requirements automatically for every new and existing user. This is the native, supported mechanism for enforcing strong passwords across an AWS account.

Exam trap

SCS-C02 often tests the difference between preventive controls (IAM password policy) and detective controls (AWS Config, Lambda) — candidates pick Config or Lambda because they sound more 'automated', but the requirement is enforcement at creation, which only the native policy provides.

How to eliminate wrong answers

Option B is wrong because AWS Config is a compliance-monitoring service — it can detect non-compliant resources but cannot delete IAM users or enforce password strength at creation time. Option C is wrong because a Lambda function triggered on user creation is a custom workaround that adds latency and complexity, and it cannot retroactively enforce password policy on existing users. Option D is wrong because Secrets Manager generates and stores secrets for applications, not for IAM user console passwords, and it does not enforce a password policy on IAM users.

57
MCQeasy

A company needs to audit all changes to IAM policies in their AWS account. Which AWS service should they use to record these changes?

A.Amazon S3
B.Amazon CloudWatch Logs
C.AWS Config
D.AWS CloudTrail
AnswerD

CloudTrail records API activity across the account, including every IAM policy creation, modification and deletion, capturing the identity, timestamp and request parameters. This satisfies the audit requirement by providing a tamper-evident log of who changed which policy and when.

Why this answer

AWS CloudTrail records API activity in an AWS account, including all changes to IAM policies (CreatePolicy, PutRolePolicy, AttachRolePolicy, etc.). CloudTrail captures the identity of the caller, the time, the source IP, and the request parameters, making it the authoritative service for auditing IAM policy changes. It is enabled by default for management events and can be configured for multi-region and organization-wide trails.

Exam trap

SCS-C02 often tests the confusion between AWS Config (resource configuration history and compliance) and CloudTrail (API activity auditing) — candidates pick Config because it sounds like it tracks changes, but CloudTrail is the service that records who made the API call.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is object storage and does not record API activity — it can store CloudTrail logs but is not the auditing service itself. Option B is wrong because CloudWatch Logs is a log aggregation and monitoring service; it can receive CloudTrail logs but does not natively record IAM API calls. Option C is wrong because AWS Config records resource configuration changes and evaluates compliance, but CloudTrail is the service that captures the API calls that made those changes — for auditing who changed IAM policies, CloudTrail is the correct source.

58
MCQhard

A company uses AWS Organizations with a management account and several member accounts. The security team wants to restrict the use of specific AWS services (e.g., EC2, Lambda) in certain accounts based on the account's environment (dev, test, prod). Which approach should be used to implement this requirement?

A.Use AWS CloudTrail to monitor API calls and revoke access after the fact.
B.Create IAM roles in each account with policies that deny access to services.
C.Use AWS Organizations to tag accounts (e.g., Environment=Dev) and use SCPs with conditions to deny access to services based on tags.
D.Use AWS Config rules to detect and alert when restricted services are used.
AnswerC

Tag-based SCPs allow fine-grained control across accounts.

Why this answer

By tagging accounts in AWS Organizations (e.g., Environment=Dev) and using Service Control Policies (SCPs) with conditions based on those tags, the security team can restrict usage of specific AWS services per account environment. SCPs are applied at the organization level and affect all users and roles in the account, providing preventive controls. Option A is incorrect because CloudTrail only logs API calls and does not prevent usage; revoking access after the fact is not a preventive measure.

Option B is incorrect because IAM roles are identity-based and do not restrict services at the account level; also, managing roles per account would be cumbersome. Option D is incorrect because AWS Config rules detect non-compliant resource configurations but do not prevent the use of services; they are detective controls.

59
MCQeasy

A company wants to grant cross-account access to an S3 bucket owned by Account A to a user in Account B. The bucket policy in Account A allows access from Account B. What additional configuration is required?

A.The IAM user in Account B must have a policy that allows access to the S3 bucket.
B.Nothing; the bucket policy is sufficient.
C.The bucket must be configured with ACLs.
D.An SCP must allow the s3:GetObject action.
AnswerA

The bucket policy in Account A grants the IAM user (or Account B) the ability to access the S3 bucket, but cross-account access requires an explicit allow from the requester's own account as well. The IAM user in Account B must have an identity-based policy that permits the specific S3 action (e.g., s3:GetObject) on the target bucket or object ARN. AWS evaluates both the resource-based bucket policy and the identity-based policy, and if either does not explicitly allow the action, the request is denied. Without this IAM policy, the user may have no effective permission to perform the S3 operation despite the bucket policy granting access.

Why this answer

Cross-account access to an S3 bucket requires both a resource-based policy (the bucket policy in Account A) and an identity-based policy (an IAM policy attached to the user or role in Account B). The bucket policy grants access to the external account, but the IAM user in Account B must also have an explicit policy that allows the desired actions (e.g., s3:GetObject). Therefore, Option A is correct.

Option B is incorrect because the bucket policy alone is not sufficient. Option C is incorrect because ACLs are not required and are generally not recommended for cross-account access. Option D is incorrect because SCPs (Service Control Policies) are used for organization-wide guardrails and are not required for this specific cross-account access.

60
MCQhard

A company has a requirement that all IAM users must use strong passwords. The security engineer needs to enforce a password policy that requires minimum 12 characters, at least one uppercase letter, and at least one number. The engineer sets the password policy in IAM. However, existing users with weak passwords are not forced to change them. What should the engineer do to enforce the policy for existing users?

A.Manually reset each user's password to a strong password.
B.Enable 'Allow users to change their own password' in the policy.
C.Re-apply the password policy to each user.
D.Set the password expiration period to 0 to force immediate password change.
AnswerD

Setting the 'password expiration period' to 0 in the IAM account password policy causes every existing password to expire immediately, forcing each IAM user to choose a new password at the next sign-in. Because the account-level policy has already defined the required strength, the newly chosen passwords must satisfy those strong-complexity rules. This is the only listed option that enforces the strong-password requirement collectively on all users without requiring manual intervention per user.

Why this answer

Setting the password policy to expire existing passwords will force users to change them on next login. Option A is wrong because the policy is already set; users are not forced to change. Option B is wrong because allowing users to change passwords does not enforce the policy.

Option C is wrong because resetting passwords manually is not scalable and not required.

61
MCQeasy

A security team wants to audit all changes to IAM policies in the AWS account. Which AWS service should be used to track these changes?

A.AWS Config
B.AWS Trusted Advisor
C.AWS CloudTrail
D.AWS CloudWatch Logs
AnswerC

AWS CloudTrail records every management API call made through the IAM service, including PutUserPolicy, PutRolePolicy, AttachUserPolicy, and DeleteUserPolicy, as management events. Each event contains the identity of the caller, the source IP address, the request parameters, and a timestamp, giving you a full, tamper-evident audit trail of IAM policy changes. By default, the event history is available for 90 days, and you can configure a trail to deliver events to S3 and CloudWatch Logs for long-term retention and analysis.

Why this answer

AWS CloudTrail records API activity in the account, including all IAM policy changes (CreatePolicy, PutRolePolicy, AttachPolicy, etc.), and delivers these events to an S3 bucket and optionally CloudWatch Logs. It is the authoritative service for auditing who changed what and when across AWS APIs. For IAM policy change auditing, CloudTrail is the correct and standard answer.

Exam trap

SCS-C02 often tests whether candidates confuse AWS Config (resource configuration history) with CloudTrail (API activity audit), causing them to pick Config when the question asks about tracking changes to IAM policies.

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configuration state and changes over time, but it is not the primary API-level audit trail for IAM policy modifications — CloudTrail captures the API calls themselves. Option B is wrong because Trusted Advisor provides best-practice checks and recommendations, not an audit log of changes. Option D is wrong because CloudWatch Logs is a log storage and analysis service; it can receive CloudTrail events but is not itself the audit source.

62
MCQhard

Refer to the exhibit. An organization applies this SCP to an OU containing a developer account. A developer in that account tries to launch an m5.large instance using the AWS Management Console. What is the outcome?

A.The instance launches successfully because the SCP only applies to StartInstances, not RunInstances.
B.The launch fails because the SCP denies RunInstances for instance types other than t2.micro and t2.small.
C.The instance launches successfully because the SCP does not explicitly allow any actions.
D.The launch fails only if the developer's IAM policy also denies the action.
AnswerB

The SCP uses a condition such as ec2:InstanceType StringNotEquals t2.micro,t2.small. For an m5.large launch, the condition evaluates to true because m5.large is not in the allowed list, so the Deny statement applies and the RunInstances call is explicitly denied. The launch fails because the requested instance type does not match the only two approved types, regardless of any IAM policy that might allow it.

Why this answer

The SCP explicitly denies the ec2:RunInstances action when the condition key ec2:InstanceType does not match t2.micro or t2.small. Since m5.large is not in the allowed list, the deny effect applies, and the launch fails regardless of any IAM policy that might allow it. SCPs act as a guardrail that overrides IAM permissions, so even if the developer has full IAM access, the SCP blocks the operation.

Exam trap

The trap here is that candidates confuse SCPs with IAM policies, thinking an explicit allow in IAM can override an SCP deny, but SCPs act as a boundary that cannot be bypassed by any IAM permission.

How to eliminate wrong answers

Option A is wrong because the SCP explicitly denies ec2:RunInstances, not just ec2:StartInstances; the exhibit shows 'Deny' for RunInstances with a condition on instance type. Option C is wrong because SCPs do not need to explicitly allow actions; they default to allowing all actions unless a deny is applied, and here a deny is applied for non-compliant instance types. Option D is wrong because SCPs are evaluated before IAM policies; a deny in an SCP cannot be overridden by an IAM allow, so the launch fails regardless of the developer's IAM policy.

63
Multi-Selectmedium

A security engineer is designing a governance framework for a multi-account AWS environment. The engineer needs to ensure that all accounts comply with the principle of least privilege for IAM roles and that any non-compliant resources are automatically reported. Which two AWS services should the engineer use together to achieve this? (Choose TWO.)

Select 2 answers
A.AWS Security Hub
B.AWS Service Catalog
C.Amazon GuardDuty
D.AWS Config
E.AWS CloudTrail
AnswersA, D

AWS Security Hub is the correct choice because it provides a centralized view of security and compliance posture across AWS accounts. It ingests and aggregates findings from AWS Config, including IAM role compliance checks, and continuously runs controls from frameworks like CIS AWS Foundations Benchmark and AWS Foundational Security Best Practices. This allows a security engineer to create a governance framework that monitors IAM roles against least-privilege policies, with automated compliance reporting and a unified dashboard. Security Hub also integrates with AWS Organizations to aggregate findings from multiple accounts, making it the appropriate service for enterprise-wide IAM governance.

Why this answer

AWS Security Hub is correct because it provides a comprehensive view of security alerts and compliance status across multiple AWS accounts, aggregating findings from various AWS services and third-party tools. AWS Config is correct because it continuously monitors and records AWS resource configurations, enabling you to define rules (e.g., IAM least privilege policies) and automatically evaluate resource compliance, triggering notifications or remediation actions for non-compliant resources. Together, Security Hub can ingest AWS Config rule compliance results as findings, allowing centralized reporting and automated response to IAM role violations.

Exam trap

The trap here is that candidates often confuse AWS Config (resource compliance evaluation) with AWS CloudTrail (API activity logging) or Amazon GuardDuty (threat detection), failing to recognize that only AWS Config can directly assess IAM role configurations against least privilege rules and automatically report non-compliance.

64
MCQhard

A security engineer runs the get-account-authorization-details command and sees the exhibit output. The engineer wants to ensure that the 'admin' user does not have administrative access. Which steps should be taken?

A.Delete the 'admin' user and create a new user with limited permissions.
B.Modify the AdministratorAccess policy to deny all actions.
C.Detach the AdministratorAccess policy from the 'admin' user and attach a custom policy with read-only permissions.
D.Attach a permissions boundary that denies all actions.
AnswerC

Detaching the AdministratorAccess policy from the 'admin' user directly removes the administrative privilege, while attaching a custom read-only policy grants only the permissions needed for the user's job — a least-privilege approach. The user keeps its IAM identity, credentials, MFA, and other configuration, making this the minimal, reversible change. This should be combined with a review of the custom policy's actions and resources to ensure it truly limits access to read-only APIs.

Why this answer

The 'admin' user has the AdministratorAccess policy attached, granting full administrative rights. To remove administrative access, the engineer should detach this policy and attach a custom policy with read-only permissions (Option C). Option A is unnecessary because deleting the user is not required; detaching the policy is sufficient.

Option B is incorrect because modifying the AdministratorAccess policy to deny all actions would still leave the policy attached, potentially causing confusion or unintended effects; better to detach it. Option D is wrong because attaching a permissions boundary does not remove the existing AdministratorAccess policy; the user would still have administrative access via that policy.

65
MCQhard

A security engineer needs to grant a third-party auditor read-only access to specific AWS Config compliance data in a production account for 30 days. The auditor uses their own AWS account and must not be able to modify any resources or view unrelated data. The security engineer wants to avoid creating IAM users in the production account. Which approach BEST satisfies these requirements?

A.Create an IAM role in the production account with a trust policy allowing the auditor's account and attach a policy granting config:Describe* and config:Get* actions, then provide the role ARN to the auditor.
B.Attach a resource-based policy to the production account's AWS Config service-linked role permitting the auditor's account principal to call config:GetComplianceDetailsByConfigRule.
C.Create an IAM user in the production account for the auditor with a read-only managed policy and enable MFA, sharing credentials securely for the 30-day period.
D.Share the production account's AWS Config data by enabling an AWS Config aggregator in the auditor's account and authorizing the production account as a source account.
AnswerA

Cross-account IAM roles allow the auditor to assume a role in the production account without creating local IAM users. Attaching only Config read actions enforces least privilege, and the trust policy scopes access to the auditor's account. This meets the no-local-users requirement while limiting permissions to compliance data retrieval only, which is exactly what the scenario asks for.

Why this answer

A cross-account IAM role with a trust policy scoped to the auditor's account and permissions limited to AWS Config read actions provides temporary, least-privilege access without creating local IAM users. The auditor assumes the role using their own credentials. Aggregators, service-linked role modifications, and local IAM users either fail to grant the needed access, broaden exposure, or violate the no-local-user constraint.

Exam trap

The trap here is assuming AWS Config aggregators grant external parties direct read access, when they only consolidate data for the aggregator owner.

66
MCQmedium

A security engineer discovers that an IAM user has a policy that allows them to delete any S3 bucket in the account. The engineer wants to audit all delete actions performed by this user. Which AWS service should be used?

A.Amazon GuardDuty
B.AWS Config
C.AWS CloudTrail
D.Amazon CloudWatch Logs
AnswerC

AWS CloudTrail records every S3 API call, including DeleteBucket, capturing the IAM user's identity, timestamp, source IP and request parameters. This satisfies the audit requirement by providing an immutable event history of all delete actions performed by that user across the account.

Why this answer

AWS CloudTrail records API activity in an AWS account, including S3 DeleteBucket and DeleteObject calls, capturing the identity of the caller, source IP, timestamp, and request parameters. To audit all delete actions performed by a specific IAM user, the engineer enables CloudTrail (ideally an organization trail or a trail with S3 log delivery) and filters events by the user's ARN and event names. CloudTrail is the authoritative audit log for AWS API actions.

Exam trap

SCS-C02 often tests the difference between detection (GuardDuty), configuration compliance (Config), and audit logging (CloudTrail) — candidates pick GuardDuty because it is security-focused, but it does not provide the raw audit trail.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes CloudTrail, VPC Flow Logs, and DNS logs for malicious or anomalous behavior — it does not provide a searchable audit trail of specific API calls. Option B is wrong because AWS Config records resource configuration changes and evaluates compliance rules; while it can show that an S3 bucket was deleted, it does not capture the full API-level audit detail (caller identity, request parameters) that CloudTrail does. Option D is wrong because Amazon CloudWatch Logs is a log storage and monitoring service; CloudTrail can deliver logs to CloudWatch Logs, but CloudWatch Logs itself is not the audit source for API activity.

67
Multi-Selectmedium

A company uses AWS Config to record resources. Which TWO actions can be taken to automatically remediate non-compliant resources detected by AWS Config rules?

Select 2 answers
A.Configure AWS Config rules to invoke an AWS Lambda function for remediation
B.Configure AWS Config rules to send notifications to an SNS topic
C.Use AWS Systems Manager Automation documents as remediation actions
D.Use AWS CloudTrail to log non-compliant events
E.Use Amazon CloudWatch Events to trigger an AWS Step Functions state machine
AnswersA, C

AWS Config rules can be directly associated with remediation actions, and invoking a Lambda function is a fully supported native option. Lambda enables custom code to evaluate and automatically fix non-compliant resources, such as updating security group rules or stopping an instance, based on the rule's evaluation result. This makes it one of the two built-in remediation targets available without needing external services.

Why this answer

AWS Config rules can be configured with remediation actions that invoke an AWS Lambda function. When a resource is evaluated as non-compliant, the rule triggers the Lambda function, which can execute custom logic to modify or fix the resource, such as adjusting security group rules or enabling encryption. This provides automated, programmable remediation directly integrated with AWS Config's evaluation lifecycle.

Exam trap

The trap here is that candidates often confuse notification-based responses (like SNS or CloudWatch Events) with actual automated remediation, forgetting that AWS Config's native remediation actions are limited to Lambda functions and Systems Manager Automation documents, not generic event-driven workflows.

68
MCQmedium

A company has multiple AWS accounts managed through AWS Organizations. The security team needs to ensure that no EC2 instances are launched without an approved Amazon Machine Image (AMI). Which governance control should be implemented?

A.Use a service control policy (SCP) that denies ec2:RunInstances unless the AMI ID is in an approved list.
B.Deploy an AWS Config rule that triggers a Lambda function to terminate non-compliant instances.
C.Use AWS CloudTrail to monitor instance launches and alert the security team.
D.Use an IAM policy that restricts ec2:RunInstances to approved AMIs.
AnswerA

A service control policy (SCP) is the correct preventive control because it applies at the AWS Organizations level and acts as a permission boundary that no IAM principal in a member account can bypass, including account administrators. By adding a Deny statement for ec2:RunInstances with a condition such as ec2:ImageId not being in the approved AMI list (using StringNotEquals or ForAnyValue:StringNotEquals), the restriction is enforced before any EC2 instance is launched. SCPs do not grant permissions, but they effectively block non-compliant launches across all accounts and future accounts.

Why this answer

A service control policy (SCP) is the correct governance control because it operates at the AWS Organizations level, allowing the security team to enforce a deny on ec2:RunInstances across all member accounts unless the AMI ID matches an approved list. SCPs are account permission boundaries that cannot be overridden by IAM policies within the account, ensuring that no user or role can launch an EC2 instance with an unapproved AMI, even if they have full administrative privileges. This provides a preventive control that blocks non-compliant actions before they occur, which is more robust than detective or reactive measures.

Exam trap

The trap here is that candidates often confuse IAM policies with SCPs, assuming that an IAM policy can enforce organization-wide controls, but SCPs are the only mechanism that applies as a permission boundary across all accounts in an AWS Organization and cannot be overridden by account administrators.

How to eliminate wrong answers

Option B is wrong because an AWS Config rule with a Lambda function to terminate non-compliant instances is a detective and reactive control, not a preventive governance control; it only acts after the instance is launched, incurring potential cost and security exposure. Option C is wrong because AWS CloudTrail is a logging and monitoring service that records API calls but does not prevent the launch; it only alerts the security team after the fact, leaving a window for non-compliant instances to run. Option D is wrong because an IAM policy that restricts ec2:RunInstances to approved AMIs can be bypassed by users with higher privileges (e.g., an administrator) or by modifying the policy within the account, whereas an SCP applies as a boundary that cannot be overridden by account-level IAM policies.

69
MCQmedium

Refer to the exhibit. A role has two policies attached. The custom policy includes an Allow for s3:PutObject. An IAM user assumes this role and tries to upload a file to S3. What happens?

A.The upload succeeds because the custom policy allows s3:PutObject
B.The upload fails because the managed policy only allows read
C.The upload is denied by default because no explicit allow
D.The upload fails because the managed policy overrides the custom policy
AnswerA

The upload succeeds because IAM policies are evaluated as a combined set, and the custom policy explicitly grants the s3:PutObject permission required for uploading an object. An explicit allow in any attached identity-based policy is sufficient to permit the action, overriding the default implicit deny. The read-only managed policy does not block this; it simply grants no write access, but the custom policy fills that gap.

Why this answer

The upload succeeds because IAM evaluates policies in a default-deny environment, and the custom policy attached to the role explicitly allows s3:PutObject. When a user assumes the role, the effective permissions are the union of all attached policies; the managed policy's read-only restriction does not block the explicit allow for s3:PutObject. Since there is no explicit deny for s3:PutObject, the allow from the custom policy grants the action.

Exam trap

The trap here is that candidates mistakenly believe a more restrictive policy (managed read-only) overrides a less restrictive one (custom allow), but IAM never overrides policies; it only denies if an explicit deny exists, and allows if any explicit allow exists.

How to eliminate wrong answers

Option B is wrong because the managed policy's read-only restriction does not override an explicit allow; IAM uses an allow-list model where any explicit allow permits the action unless there is an explicit deny. Option C is wrong because the custom policy provides an explicit allow for s3:PutObject, so the action is not denied by default. Option D is wrong because no policy overrides another in IAM; the effective permissions are the union of all allows minus any explicit denies, and the managed policy does not contain a deny for s3:PutObject.

70
MCQeasy

A company uses AWS Organizations and wants to centrally manage CloudTrail trails across all accounts. Which feature should be enabled?

A.CloudTrail organization trail
B.Cross-account CloudTrail
C.Service Control Policy for CloudTrail
D.AWS Config aggregator
AnswerA

An organization trail is a dedicated CloudTrail feature created in the AWS Organizations management account that automatically logs API activity for every account in the organization and delivers those logs to a single S3 bucket. It is configured once and applies across all AWS Regions, providing a central, management-account-owned audit record that member accounts cannot modify or delete. This is the native, scalable mechanism for centrally managing CloudTrail logs across the entire organization.

Why this answer

A CloudTrail organization trail is a trail created in the management account of an AWS Organization that automatically applies to all member accounts. It logs events from every account in the organization to a single S3 bucket, enabling centralized management and compliance. This is the native feature designed for multi-account CloudTrail governance, requiring no per-account configuration.

Exam trap

SCS-C02 often tests the misconception that SCPs can enforce CloudTrail logging or that AWS Config aggregator can centralize CloudTrail logs, when in fact only an organization trail provides automatic, multi-account CloudTrail management.

How to eliminate wrong answers

Option B is wrong because 'cross-account CloudTrail' is not a specific AWS feature; while you can share trails across accounts manually, it lacks the automatic, organization-wide scope of an organization trail. Option C is wrong because Service Control Policies (SCPs) are used to restrict permissions, not to enable or manage CloudTrail trails; they cannot create or centralize trails. Option D is wrong because AWS Config aggregator collects configuration and compliance data across accounts, not CloudTrail event logs, and does not manage trails.

71
MCQhard

A security engineer runs the above CloudTrail lookup command to investigate a change to the S3 bucket policy. The command only returns one event, but the engineer knows that the bucket policy was changed multiple times. What is the most likely reason?

A.The bucket policy changes were made through the AWS Management Console, which is not logged.
B.The event is not logged because PutBucketPolicy is not supported by CloudTrail.
C.The command is filtering by the wrong attribute.
D.The command is limiting results to one event.
AnswerD

This is correct. The aws cloudtrail lookup-events --max-results 1 option instructs CloudTrail to return only one event from the matching results, even if many PutBucketPolicy events exist. The LookupEvents API returns up to 50 events per page, and --max-results limits that page size; additional matches require pagination with NextToken or a higher value. Thus the command does not prove that no other bucket policy changes occurred.

Why this answer

The command uses --max-results 1, limiting output to one event. Option A is wrong because changes through the AWS Management Console are logged by CloudTrail. Option B is wrong because PutBucketPolicy is supported by CloudTrail and the event shown confirms it.

Option C is wrong because filtering by ResourceName is not the issue; the --max-results parameter is the cause.

72
Multi-Selectmedium

A security engineer is reviewing the following IAM policy attached to a role. Which TWO actions are allowed by this policy? (Choose two.) ```json { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "s3:ListBucket", "s3:GetObject" ], "Resource": "*" } ] } ```

Select 2 answers
A.s3:ListBucket
B.ec2:TerminateInstances
C.iam:CreateUser
D.kms:Decrypt
E.s3:GetObject
AnswersA, E

The policy includes an explicit Allow statement for s3:ListBucket on the bucket resource, so this action is permitted. IAM defaults to deny only for actions not covered by any applicable Allow, and because no explicit or resource-based Deny applies to this principal for that bucket, the ListBucket call is authorized. The permission is scoped to the bucket ARN, not individual objects, which matches the resource type required by the ListBucket API.

Why this answer

Option A (s3:ListBucket) is correct because the policy's Action list explicitly includes "s3:ListBucket" with Effect Allow and Resource "*", so listing any S3 bucket is permitted. Option E (s3:GetObject) is correct because "s3:GetObject" is also explicitly listed in the same Allow statement, granting read access to objects across all resources. The unmarked options do not belong because the policy only allows the two S3 actions named; ec2:TerminateInstances, iam:CreateUser, and kms:Decrypt are not present in the Action list, and IAM policies are deny-by-default for any action not explicitly allowed.

Exam trap

SCS-C02 often tests the principle of least privilege and implicit deny — candidates may incorrectly assume that unrelated actions like ec2:TerminateInstances are allowed because the policy uses Resource: "*", confusing resource scope with action scope.

73
MCQeasy

A security team needs to centrally manage permissions for multiple AWS accounts. Which AWS service should they use?

A.AWS IAM
B.AWS Config
C.AWS Organizations with service control policies (SCPs)
D.AWS CloudTrail
AnswerC

AWS Organizations gives you a central management structure for all your AWS accounts, and service control policies (SCPs) let you apply permission guardrails at the root, organizational unit (OU), or account level. SCPs restrict the maximum allowed actions for IAM principals in member accounts, but they do not grant permissions—they work alongside IAM policies to enforce central restrictions across the entire organization. This is the correct service because it provides centralized, cross-account permission governance that IAM alone cannot achieve.

Why this answer

AWS Organizations with service control policies (SCPs) is the correct choice because SCPs allow you to centrally manage permissions across multiple AWS accounts by defining maximum permissions for member accounts. Unlike IAM policies that are attached to users or roles within a single account, SCPs act as a guardrail at the organization or organizational unit (OU) level, restricting what actions accounts and their IAM principals can perform, even if the account's own IAM policies allow more.

Exam trap

The trap here is that candidates often confuse AWS IAM (which manages permissions within a single account) with the need for cross-account permission management, leading them to select IAM instead of recognizing that AWS Organizations with SCPs is the correct service for central governance across multiple accounts.

How to eliminate wrong answers

Option A is wrong because AWS IAM manages permissions for users, groups, and roles within a single AWS account, not across multiple accounts centrally. Option B is wrong because AWS Config is a service for evaluating resource configurations against rules and tracking compliance, not for managing permissions. Option D is wrong because AWS CloudTrail records API activity for auditing and governance, but it does not enforce or manage permissions.

74
MCQeasy

A company wants to log all API calls made in their AWS account for auditing. Which AWS service should be enabled to capture these logs?

A.VPC Flow Logs
B.Amazon CloudWatch Logs
C.Amazon S3 server access logs
D.AWS CloudTrail
AnswerD

AWS CloudTrail is the purpose-built service that records API activity across your AWS account, capturing management events for the control plane and optionally data events for services like S3. Each event includes the identity of the caller, source IP address, request parameters, response elements, and a timestamp, whether the call came from the console, SDK, or CLI. CloudTrail's event history provides 90 days of visibility by default, and you can create trails to deliver logs to S3 or CloudWatch Logs for long-term auditing and compliance.

Why this answer

AWS CloudTrail records API calls made in an AWS account, including the identity, time, source IP, and request details, which is exactly what is needed for auditing. Enabling CloudTrail captures management and, optionally, data events across services. This makes it the correct service for logging all API calls.

Exam trap

SCS-C02 often tests the difference between CloudTrail (API call auditing) and VPC Flow Logs (network traffic) or S3 access logs (bucket-level requests), so candidates pick a logging service that does not capture account-wide API activity.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture IP traffic metadata for network interfaces, not API calls. Option B is wrong because CloudWatch Logs is a log storage and analysis service; it can receive CloudTrail logs but does not itself capture API calls. Option C is wrong because S3 server access logs record requests to S3 buckets only, not account-wide API calls.

75
MCQmedium

A security team needs to centralize audit logs from multiple AWS accounts into a single S3 bucket. The solution must be scalable and support future account additions. Which approach meets these requirements?

A.Use Amazon CloudWatch Logs to stream logs from each account to a central account.
B.Use AWS Trusted Advisor to collect logs from all accounts.
C.Configure CloudTrail in each account to deliver logs to the same S3 bucket.
D.Use AWS Organizations to create a CloudTrail trail that applies to all accounts in the organization.
AnswerD

An AWS Organizations trail is the native solution: CloudTrail is enabled in the management account and automatically applies to every member account, including accounts added later. The management account creates a service-linked role that allows CloudTrail to deliver log files from all member accounts to a designated S3 bucket in the management account. This centralizes all API activity across the organization into a single auditable store without per-account manual setup.

Why this answer

AWS Organizations allows you to create an organization-wide CloudTrail trail that automatically applies to all existing and future accounts in the organization. This is the most scalable approach because new accounts added to the organization are automatically covered without manual configuration per account. The trail delivers logs to a central S3 bucket, meeting the requirement to centralize audit logs.

Exam trap

The trap is choosing per-account CloudTrail configuration (Option C) because it seems straightforward, but the question emphasizes scalability and future account additions — only the organization trail automatically covers new accounts without manual intervention.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs streaming from each account to a central account requires per-account configuration and does not automatically cover new accounts — it is not scalable for future account additions without automation. Option B is wrong because AWS Trusted Advisor is a service that provides recommendations on cost, security, performance, and fault tolerance; it does not collect or centralize audit logs. Option C is wrong because configuring CloudTrail in each account to deliver to the same S3 bucket requires manual setup in every account and does not automatically apply to new accounts, making it less scalable than an organization trail.

Page 1 of 3 · 168 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security Governance questions.