Courseiva

SOA-C02 · topic practice

Security and Compliance practice questions

This domain covers IAM policies, SCPs, KMS encryption, and detective/preventive controls across AWS accounts. Questions present a compliance requirement and ask you to choose the control that enforces it org-wide, then verify or auto-remediate drift using Config, CloudTrail, and Lambda.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Security and Compliance

What the exam tests

What to know about Security and Compliance

Be able to select the right guardrail: SCPs for preventive org-wide denies, bucket policies and KMS key policies for encryption enforcement, and Config rules with SSM Automation for auto-remediation. The key is knowing which control prevents versus detects versus remediates.

Using AWS Organizations SCPs to deny actions like s3:PutBucketPublicAccessBlock across member accounts

Enforcing SSE-KMS on S3 buckets via bucket policies and aws s3api put-bucket-encryption

Configuring AWS Config rules with automatic remediation through SSM Automation documents

Auditing API activity and resource changes with CloudTrail trails and CloudWatch Logs

Watch out for

Common Security and Compliance exam traps

  • ▸Assuming an SCP grants permissions; SCPs only filter what IAM already allows and never grant access on their own.
  • ▸Thinking S3 Block Public Access set at the bucket level cannot be overridden; account and organization-level settings take precedence.
  • ▸Confusing AWS Config remediation with prevention; Config detects and remediates after the fact, while SCPs and bucket policies prevent.

Practice set

Security and Compliance questions

20 questions · select your answer, then reveal the explanation

An organization requires that all Amazon EC2 instances must be launched only with approved Amazon Machine Images (AMIs) that have been pre-approved by the security team. The SysOps administrator needs to enforce this policy for all current and future instances in the AWS account. Unapproved AMIs should be prevented from launching. Which solution meets these requirements with the least operational overhead?

A company wants to restrict access to an AWS Systems Manager Parameter Store parameter to only requests originating from the corporate network IP range (10.0.0.0/8). The SysOps administrator needs to implement this restriction using an IAM policy. Which condition key should be used?

A company is using AWS Organizations with multiple accounts. The security team wants to ensure that no IAM user in any account can create access keys for themselves. Which is the MOST effective way to enforce this policy across all accounts?

An application running on Amazon EC2 needs to encrypt data before writing to Amazon S3. The encryption key must be rotated every 90 days and access to the key must be auditable. Which solution meets these requirements?

A company uses AWS Key Management Service (KMS) to encrypt data in Amazon S3. They want to ensure that the KMS key can only be used from within a specific VPC. How can this be accomplished?

Question 6hardmultiple choice
Review the full subnetting walkthrough →

A SysOps administrator is troubleshooting an issue where an IAM user is unable to launch an EC2 instance in a specific subnet. The user has the following IAM policy:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "ec2:RunInstances",
      "Resource": "*",
      "Condition": {
        "StringEquals": {

"ec2:Subnet": "subnet-12345"

}
      }
    }
  ]
}

What is the likely cause of the failure?

A company is designing a secure application architecture. They need to ensure that sensitive data stored in Amazon S3 is not accessible from the public internet. Which TWO actions should be taken? (Choose TWO.)

A company wants to ensure that their Amazon S3 bucket policy only allows access from a specific VPC endpoint. Which TWO condition keys can be used in the bucket policy? (Choose TWO.)

Question 9hardmultiple choice
Read the full VPN explanation →

A company's security team notices that an IAM user has been making unauthorized API calls from an IP address outside the company's VPN. The team wants to immediately block all API calls from that specific IP address for all users. Which action should be taken?

A company's security team wants to ensure that all new S3 buckets created in the AWS account are automatically encrypted with server-side encryption. What should a SysOps administrator do to enforce this?

An organization requires that all data in transit between EC2 instances and the internet be encrypted. Which AWS service can be used to enforce this requirement?

A company wants to grant an IAM role in Account A access to an S3 bucket in Account B. What must be configured?

A company wants to allow an external auditor to read objects in a specific S3 bucket for 30 days. The auditor does not have an AWS account. Which method should be used?

An organization wants to enforce that all IAM users have multi-factor authentication (MFA) enabled before they can perform any action except changing their own password. Which IAM policy element is MOST appropriate?

A SysOps administrator needs to provide a developer from another AWS account access to an S3 bucket in the administrator's account. The developer must be able to list objects and get objects from the bucket. The administrator does NOT want to share AWS access keys. Which solution meets these requirements?

A company uses IAM roles to grant EC2 instances access to S3 buckets. After a recent security audit, the SysOps administrator must ensure that only instances with a specific tag (Environment=Production) can assume the role. How can this be achieved?

An organization uses AWS KMS to encrypt data in S3. A SysOps administrator needs to ensure that KMS keys cannot be deleted accidentally. What is the MOST effective way to protect against accidental key deletion?

A SysOps administrator receives an alert that an IAM user's access key was used from an unexpected geographic location. What should the administrator do to prevent future unauthorized use?

A SysOps administrator needs to securely transfer a large dataset from an on-premises server to an Amazon S3 bucket. The data is sensitive and must be encrypted in transit and at rest. Which THREE steps should the administrator take? (Choose three.)

A company uses AWS Organizations with multiple OUs. The security team wants to ensure that no one can disable AWS CloudTrail or delete CloudTrail log files from the S3 bucket. Which THREE actions should be taken? (Choose three.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security and Compliance sessions

Start a Security and Compliance only practice session

Every question in these sessions is drawn from the Security and Compliance domain — nothing else.

Related practice questions

Related SOA-C02 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SOA-C02 exam test about Security and Compliance?
Be able to select the right guardrail: SCPs for preventive org-wide denies, bucket policies and KMS key policies for encryption enforcement, and Config rules with SSM Automation for auto-remediation. The key is knowing which control prevents versus detects versus remediates.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security and Compliance questions in a focused session?
Yes — the session launcher on this page draws every question from the Security and Compliance domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SOA-C02 topics?
Use the topic links above to move to related areas, or go back to the SOA-C02 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SOA-C02 exam covers. They are not copied from any real exam or dump site.