Sign In
Home/AWS/Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03/Free questions

AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 — Free Practice Questions

10 free sample questions from a bank of 405, with the correct answers and explanations. No signup required — start practising right now.

1A security engineer is troubleshooting an AWS Lambda function that is named MyLambdaFunction. The function is encountering an error when the function attempts to read the objects in an Amazon S3 bucket that is named DOC-EXAMPLE-BUCKET. The S3 bucket has the following bucket policy: Which change should the security engineer make to the policy to ensure that the Lambda function can read the bucket objects?
AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 1AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 1AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 1AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 1
  • Remove the Condition element. Change the Principal element to the following:
  • Change the Action element to the following:
  • Change the Resource element to "arn:aws:s3:::DOC-EXAMPLE- BUCKET/*''.
  • Change the Resource element to "arn:aws:lambda:::function:MyLambdaFunction". Change the Principal element to the following:
Answer: C
2HOTSPOT A company is building a web application that needs to authenticate external users across multiple microservices that the company hosts on Amazon Elastic Container Service (Amazon ECS). The solution must use temporary credentials and minimize the management overhead required to maintain user databases. Select and order the correct steps from the following list to implement a secure authentication strategy that meets these requirements. Select each step one time or not at all. Configure Amazon Cognito user pools for user authentication. Set up an IAM role for each microservice. Grant each role appropriate permissions. Implement an Amazon API Gateway HTTP API with AWS Lambda authorizers to validate tokens before forwarding requests to microservices. Create an Amazon DynamoDB table to store user credentials for each microservice. Create an Amazon Cognito application client to interact with the web application. Set up AWS IAM Identity Center to give users access to the microservices.
AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 2AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 2
    Answer:
    3An AWS account administrator created an IAM group and applied the following managed policy to require that each individual user authenticate using multi-factor authentication: After implementing the policy, the administrator receives reports that users are unable to perform Amazon EC2 commands using the AWS CLI. What should the administrator do to resolve this problem while still enforcing multi-factor authentication?
    AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 3
    • Change the value of aws:MultiFactorAuthPresent to true.
    • Instruct users to run the aws sts get-session-token CLI command and pass the multi-factor authentication --serial-number and -token-code parameters. Use these resulting values to make API/CLI calls.
    • Implement federated API/CLI access using SAML 2.0, then configure the identity provider to enforce multi-factor authentication.
    • Create a role and enforce multi-factor authentication in the role trust policy. Instruct users to run the sts assume-role CLI command and pass --serial-number and --token-code parameters. Store the resulting values in environment variables. Add sts:AssumeRole to NotAction in the policy.
    Answer: B
    4A company is using AWS Organizations with the default SCP. The company needs to restrict AWS usage for all AWS accounts that are in a specific OU. Except for some desired global services, the AWS usage must occur only in the eu-west-1 Region for all accounts in the OU. A security engineer must create an SCP that applies the restriction to existing accounts and any new accounts in the OU. Which SCP will meet these requirements?
    AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 4AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 4AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 4AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 4
    Answer: C
    5HOTSPOT A security engineer needs to implement AWS IAM Identity Center with an exlemai identity provider (IdP). Select and order the correct steps from the following list to meet this requirement. Select each step one time or not at all. Configure the external IdP as the identity source in IAM Identity Center. Create an IAM role that has a trust policy that specifics the IdP's API endpoint. Enable automatic provisioning in IAM Identity Center settings Enable automatic provisioning in the external IdP. Obtain the SAML metadata from IAM Identity Center. Obtain the SAML metadata from the external IdP.
    AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 5AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 5
      Answer:
      6What is the effect of the following AWS Key Management Service (AWS KMS} key policy that is attached to a customer managed key?
      AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 6
      • Amazon WorkMail and Amazon Simple Email Service (Amazon SES) have delegated KMS encrypt and decrypt permissions to the ExampleRole principal in the 111122223333 account.
      • The ExampleRole principal can transparently encrypt and decrypt email exchanges specifically between ExampleRole and AWS.
      • The customer managed key can be used for encrypting and decrypting only when the principal is ExampleRole and when the request comes from Amazon WorkMail or Amazon Simple Email Service (Amazon SES) in the specified AWS Region.
      • The key policy allows Amazon WorkMail or Amazon Simple Email Service (Amazon SES) to encrypt or decrypt on behalf of the ExampleRole for any customer managed key in the account.
      Answer: C
      7A company wants to deny a specific federated user named Bob access to an Amazon S3 bucket named DOC-EXAMPLE-BUCKET. The company wants to meet this requirement by using a bucket policy. The company also needs to ensure that this bucket policy affects Bob's S3 permissions only. Any other permissions that Bob has must remain intact. Which policy should the company use to meet these requirements?
      AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 7AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 7AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 7AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 7
      Answer: B
      8HOTSPOT A company is designing its security monitoring strategy for an existing sensitive workload on AWS. The security team has identified several scenarios that require monitoring strategies. Select the correct monitoring strategy from the following list for each monitoring scenario. Select each monitoring strategy one time. Automatically isolate Amazon EC2 distances when malware detection findings are confirmed. Correlate security findings from multiple AWS detection services to identify multi-stage attacks. Detect when privileged users perform an unusually high volume of resource deletion operations. Identify patterns of more than 50 failed authentication attempts from specific IP addresses in 1 hour. Monitor network traffic patterns especially large data transfers to external IP addresses outside normal office hours. Configure VPC Flow Logs with Amazon CloudWatch Logs Insights queries to analyze traffic volume and destination patterns during specific time windows.
      AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 8AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03 question 8
        Answer:
        9A company needs a solution to protect critical data from being permanently deleted. The data is stored in Amazon S3 buckets. The company needs to replicate the S3 objects from the company's primary AWS Region to a secondary Region to meet disaster recovery requirements. The company must also ensure that users who have administrator access cannot permanently delete the data in the secondary Region. Which solution will meet these requirements?
        • Configure AWS Backup to perform cross-Region S3 backups. Select a backup vault in the secondary Region. Enable AWS Backup Vault Lock in governance mode for the backups in the secondary Region.
        • Implement S3 Object Lock in compliance mode in the primary Region. Configure S3 replication to replicate the objects to an S3 bucket in the secondary Region.
        • Configure S3 replication to replicate the objects to an S3 bucket in the secondary Region. Create an S3 bucket policy to deny the s3:ReplicateDelete action on the S3 bucket in the secondary Region.
        • Configure S3 replication to replicate the objects to an S3 bucket in the secondary Region. Configure S3 object versioning on the S3 bucket in the secondary Region.
        Answer: B
        10A security engineer is responding to an incident that is affecting an AWS account. The ID of the account is 1234156789012. The attack created workloads that are distributed across multiple AWS Regions. The security engineer contains the attack. The security engineer removes all compute and storage resources from all affected Regions. However, the attacker also created an AWS KMS key. The key policy on the KMS key explicitly allows IAM principal kms:* permissions. The key was scheduled to be deleted the previous day. However, the key is still enabled and usable. The key has an ARN of arn:aws;kms:us-east-2:123456789012:key/mrk-0bb0212cd9864fdea0dcamzo26efb5670. The security engineer must delete the key as quickly as possible. Which solution will meet this requirement?
        • Log in to the account by using the account root user credentials. Re-issue the deletion request for the KMS key with a waiting period of 7 days.
        • Identify the other Regions where the KMS key ID is present and schedule the key for deletion in 7 days.
        • Update the IAM principal lo allow kms:* permissions on the KMS key ARN. Re-issue the deletion request for the KMS key with a waiting period of 7 days.
        • Disable the KMS key. Re-issue the deletion request for the KMS key in 30 days.
        Answer: B

        Want the full bank of 405 questions for AWS Certified Security - Specialty SCS-C03: AWS Certified Security - Specialty SCS-C03? See all practice exams.