AWS Certified Security - Specialty SCS-C03 Amazon Practice Exam
QuestionQ1
Infrastructure Security
Save question
A company must comply with a requirement to encrypt all data in transit. The company recently identified an Amazon Aurora cluster that fails to meet this requirement.
How can the company require encryption for every connection to the Aurora cluster?
AIn the Aurora cluster configuration, set the require_secure_transport DB cluster parameter to ON.
BUse AWS Directory Service for Microsoft Active Directory to create a user directory and to enforce Kerberos authentication with Aurora.
CConfigure the Aurora cluster to use AWS Certificate Manager (ACM) to provide encryption certificates.
DCreate an Amazon RDS proxy. Connect the proxy to the Aurora cluster to enable encryption.
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Detection
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Identity and Access Management
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Incident Response
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Identity and Access Management
0
Community Discussion
No comments yet. Be the first to start the discussion!
It's free
100% of the questions are free for all users. No strings attached.
A company operates several applications on Amazon Elastic Kubernetes Service (Amazon EKS). The company requires a solution to identify Kubernetes security risks by monitoring Amazon EKS audit logs, as well as operating system, networking, and file events. The solution must send email alerts for any detected risks to a mailing list associated with a security team.
Which solution meets these requirements?
ADeploy AWS Security Hub and enable security standards that contain EKS controls. Create an Amazon Simple Notification Service (Amazon SNS) topic and set the security team's mailiing list as a subscriber. Use an Amazon EventBridge rule to send relevant Security Hub events to the SNS topic.
BEnable Amazon Inspector container image scanning. Configure Amazon Detective to analyze EKS security logs. Create Amazon CloudWatch log groups for EKS audit logs. Use an AWS Lambda function to process the logs and to send email alerts to the security team.
CEnable Amazon GuardDuty Enable EKS Protection and Runtime Monitoring for Amazon EKS in GuardDuty. Create an Amazon Simple Notification Service (Amazon SNS) topic and set the security team's mailing list as a subscriber. Use an Amazon EventBridge rule to send relevant GuardDuty events to the SNS topic.
DInstall the AWS Systems Manager Agent (SSM Agent) on all EKS nodes. Configure Amazon CloudWatch Logs lo collect EKS audit logs. Create an Amazon Simple Notification Service (Amazon SNS) topic and set the security team's mailing list as a subscriber. Configure a CloudWatch alarm to publish a message to the SNS topic when now audit logs are generated.
A company hosts an application on an Amazon EC2 instance. The application creates invoices and saves them in an Amazon S3 bucket. The instance profile attached to the instance has the required access to the S3 bucket.
The company must share every invoice with multiple clients who do not have AWS credentials. Each client must be able to download only that client’s own invoices. Clients must download invoices within 1 hour after invoice creation. Clients must use only temporary credentials to access the company’s AWS resources.
A security engineer creates a script that runs on the EC2 instance. The script uses the instance profile to create an S3 presigned URL for the clients. Each presigned URL expires after 1 hour.
Which additional step will satisfy these requirements?
AUpdate the S3 bucket policy to ensure that clients that use presigned URLs have the S3:Get* permission and the S3:List* permission to access S3 objects in the bucket.
BAdd a StringEquals condition to the IAM role policy for the EC2 instance profile. Configure the policy condition to restrict access based on the s3:ResourceTag/ClientId tag of each invoice. Tag each generated invoice with the ID of its corresponding client.
CUpdate the script to use AWS Security Token Service (AWS STS) to obtain new credentials each time the script runs by assuming a new role that has S3 GetObject permissions. Use the credentials to generate the presigned URLs.
DGenerate an access key and a secret key for an IAM user that has S3:GetObject permissions on the S3 bucket. Embed the keys into the script. Use the keys to generate the presigned URLs.
A company operates critical workloads in an on-premises data center. The company wants to implement an AWS-based disaster recovery (DR) solution that achieves an RTO of less than 1 hour. The company must continuously replicate physical and virtual servers. It must optimize costs for data storage and bandwidth use. The DR solution must be automated.
Which solution meets these requirements?
AUse AWS Backup to directly replicate the on-premises servers to AWS. Enable cross-Region backup copying and data vaulting. Configure recovery points to match the defined RTO. Use AWS Step Functions to automate recovery steps.
BConfigure an AWS Storage Gateway Volume Gateway to use Amazon Elastic Block Store (Amazon EBS) snapshots for recovery. Configure AWS Backup to manage the snapshots. Create automated recovery procedures.
CEnable AWS Elastic Disaster Recovery. Configure replication agents to continuously replicate each on-premises server. Enable the default staging area subnet configuration.
DCreate an AWS Direct Connect connection between the on-premises data center and AWS. Configure Amazon EventBridge to monitor for failures and to invoke AWS Lambda functions that launch preconfigured Amazon EC2 instances from AMIs in the event of an incident.
A company uses AWS IAM Identity Center to control access to its AWS accounts. The accounts belong to an organization in AWS Organizations.
A security engineer must establish delegated administration of IAM Identity Center in the organization’s management account.
Which combination of steps should the security engineer complete in IAM Identity Center before setting up delegated administration?
Choose three
AGrant least privilege access to the organization's management account.
BCreate a new IAM Identity Center directory in the organization's management account.
CSet up a second AWS Region in the organization's management account.
DCreate permission sets for use only in the organization's management account.
ECreate IAM users for use only in the organization's management account.
FCreate user assignments only in the organization’s management account.
QuestionQ6
Detection
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Incident Response
QuestionQ8
Data Protection
QuestionQ9
Detection
QuestionQ10
Identity and Access Management
QuestionQ11
Security Foundations and Governance
QuestionQ12
Identity and Access Management
QuestionQ13
Infrastructure Security
QuestionQ14
Detection
QuestionQ15
Infrastructure Security
QuestionQ16
Identity and Access Management
QuestionQ17
Detection
QuestionQ18
Identity and Access Management
QuestionQ19
Data Protection
QuestionQ20
Identity and Access Management
QuestionQ21
Infrastructure Security
QuestionQ22
Data Protection
QuestionQ23
Identity and Access Management
QuestionQ24
Detection
QuestionQ25
Infrastructure Security
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
A company has recently configured Amazon GuardDuty and is receiving a large number of findings from IP addresses inside the company. A security engineer has confirmed that these IP addresses are trusted and permitted.
Which combination of steps should the security engineer perform to configure GuardDuty so it does not generate findings for these IP addresses?
Choose two
ACreate a plaintext configuration file that contains the trusted IP addresses.
BCreate a JSON configuration file that contains the trusted IP addresses.
CUpload the configuration file directly to GuardDuty.
DUpload the configuration file to Amazon S3. Add a new trusted IP list to GuardDuty that points to the file.
EManually copy and paste the configuration file data into the trusted IP list in GuardDuty.
A company uses Amazon EC2 instances to host frontend services behind an Application Load Balancer. Amazon Elastic Block Store (Amazon EBS) volumes are attached to the EC2 instances. The company uses Amazon S3 buckets to store large image and music files.
The company has implemented an AWS security architecture to prevent, detect, and isolate potential ransomware attacks. The company now wants to reduce risk further.
A security engineer must develop a disaster recovery solution that can restore normal operations if an attacker bypasses the preventive and detective controls. The solution must meet an RPO of 1 hour.
Which solution will meet these requirements?
AUse AWS Backup to create backups of the EC2 instances and S3 buckets every hour. Create AWS CloudFormation templates that replicate existing architecture components. Use AWS CodeCommit to store the CloudFormation templates alongside application configuration code.
BUse AWS Backup to create backups of the EBS volumes and S3 objects every day. Use Amazon Security Lake to create a centralized data lake for AWS CloudTrail logs and VPC flow logs. Use the logs for automated response.
CUse Amazon Security Lake to create a centralized data lake for AWS CloudTrail logs and VPC flow logs. Use the logs for automated response. Enable AWS Security Hub to establish a single location for recovery procedures. Create AWS CloudFormation templates that replicate existing architecture components. Use AWS CodeCommit to store the CloudFormation templates alongside application configuration code.
DCreate EBS snapshots every 4 hours. Enable Amazon GuardDuty Malware Protection. Create automation to immediately restore the most recent snapshot for any EC2 instances that produce an Execution:EC2/MaliciousFile finding in GuardDuty.
A company operates workloads in the us-east-1 Region. The company has never deployed resources in any other AWS Region and has no multi-Region resources. The company must replicate its workloads and infrastructure to the us-west-1 Region.
A security engineer must implement a solution that uses AWS Secrets Manager to store secrets in both Regions. The solution must use AWS Key Management Service (AWS KMS) to encrypt the secrets, minimize latency, and continue to work when only one Region is available.
The security engineer creates the secrets in us-east-1 by using Secrets Manager.
What should the security engineer do next to meet these requirements?
AEncrypt the secrets in us-east-1 by using an AWS managed KMS key. Replicate the secrets to us-west-1. Encrypt the secrets in us-west-1 by using a new AWS managed KMS key in us-west-1.
BEncrypt the secrets in us-east-1 by using an AWS managed KMS key. Configure resources in us-west-1 to call the Secrets Manager endpoint in us-east-1.
CEncrypt the secrets in us-east-1 by using a customer managed KMS key. Configure resources in us-west-1 to call the Secrets Manager endpoint in us-east-1.
DEncrypt the secrets in us-east-1 by using a customer managed KMS key. Replicate the secrets to us-west-1. Encrypt the secrets in us-west-1 by using the customer managed KMS key from us-east-1.
A company uses Amazon API Gateway to expose REST APIs to its users. An API developer needs to analyze API access patterns without having to parse log files.
Which combination of steps meets these requirements with the LEAST effort?
Choose two
AConfigure access logging for the required API stage.
BConfigure an AWS CloudTrail trail destination for API Gateway events. Configure filters on the userIdentity, userAgent, and sourceIPAddress fields.
CConfigure an Amazon S3 destination for API Gateway logs. Run Amazon Athena queries to analyze API access information.
DUse Amazon CloudWatch Logs Insights to analyze API access information.
ESelect the Enable Detailed CloudWatch Metrics option on the required API stage.
A company uses an AWS Organizations organization to manage multiple AWS accounts. Users access the AWS accounts by using IAM users and secret access keys. A security team requires that all account access use temporary security credentials that expire after 60 minutes. Users must use a SAML-based identity provider (IdP) to access the accounts.
Which solution meets these requirements?
AEnable access to the AWS Security Token Service (AWS STS). Ensure that users run the get-session-token AWS CLI command with an appropriate duration. Require users to use STS temporary credentials to access AWS accounts.
BSet up AWS IAM Identity Center and configure an external IdP. Configure permission sets that allow the access that the users require. Configure a session duration limit. Require the users to retrieve SSO credentials by using the AWS CLI. Remove the IAM users from the AWS accounts.
CSet up AWS Secrets Manager and Amazon Cognito in each AWS account. Configure a Cognito identity pool to use an external IdP and connect to Secrets Manager. Enable managed secret rotation in Secrets Manager. Ensure that the users run the get-secret-value AWS CLI command to access the AWS accounts.
DEnable AWS IAM Roles Anywhere in the organization management account. Ensure that users install the credential helper tool. Configure IAM roles within the management account with an appropriate session duration. Ensure that the users retrieve temporary credentials from the credential helper tool to access the AWS accounts.
A security engineer must prepare for a security audit of an AWS account.
Choose the AWS resource that meets each requirement. Each resource can be selected once or not at all.
Select
Automatically collect evidence from AWS CloudTrail, AWS Config, and AWS Security Hub for an assessment report.
Determine which IAM principals within the AWS account have access to a specified resource.
Download AWS security and compliance documents on demand.
A security team manages a company’s AWS Key Management Service (AWS KMS) customer managed keys. Only members of the security team can administer the KMS keys. The company’s application team has a software process that occasionally requires temporary access to the keys. The security team must provide that software process with access to the keys.
Which solution meets these requirements with the LEAST operational overhead?
AExport the KMS key material to an on-premises hardware security module (HSM). Give the application team access to the key material.
BEdit the key policy that grants the security team access to the KMS keys by adding the application team as principals. Revert this change when the application team no longer needs access
CCreate a key grant to allow the application team to use the KMS keys. Revoke the grant when the application team no longer needs access.
DCreate a new KMS key by generating key material on promises. Import the key material to AWS KMS whenever the application team needs access. Grant the application team permissions to use the key.
A corporate cloud-security policy states that communications between the company’s VPC and KMS must remain entirely within the AWS network and must not use public service endpoints.
Which combination of the following actions MOST fulfills this requirement?
Choose two
AAdd the aws:sourceVpce condition to the AWS KMS key policy referencing the company’s VPC endpoint ID.
BRemove the VPC internet gateway from the VPC and add a virtual private gateway to the VPC to prevent direct, public internet connectivity.
CCreate a VPC endpoint for AWS KMS with private DNS enabled.
DUse the KMS Import Key feature to securely transfer the AWS KMS key over a VPN.
EAdd the following condition to the AWS KMS key policy: "aws:SourceIp": "10.0.0.0/16".
A company discovers that one of its Amazon EC2 instances suddenly has high CPU utilization. The company does not know whether the EC2 instance has been compromised or whether the operating system is conducting background cleanup.
Which combination of steps should a security engineer take before investigating the issue?
Choose three
ADisable termination protection for the EC2 instance if termination protection has not been disabled.
BEnable termination protection for the EC2 instance if termination protection has not been enabled.
CTake snapshots of the Amazon Elastic Block Store (Amazon EBS) data volumes that are attached to the EC2 instance.
DRemove all snapshots of the Amazon Elastic Block Store (Amazon EBS) data volumes that are attached to the EC2 instance.
ECapture the EC2 instance metadata, and then tag the EC2 instance as under quarantine.
FImmediately remove any entries in the EC2 instance metadata that contain sensitive information.
A startup uses one AWS account with resources in one AWS Region. A security engineer configures an AWS CloudTrail trail in that same Region, using the AWS CLI, to deliver log files to an Amazon S3 bucket.
Because the company is expanding, it adds resources in multiple Regions. The security engineer finds that logs from the new Regions are not arriving in the S3 bucket.
What should the security engineer do to resolve this issue with the LEAST operational overhead?
ACreate a new CloudTrail trail. Select the new Regions where the company added resources.
BChange the S3 bucket to receive notifications to track all actions from all Regions.
CCreate a new CloudTrail trail that applies to all Regions.
DChange the existing CloudTrail trail so that it applies to all Regions.
A company in France uses Amazon Cognito with the Cognito Hosted UI as an identity broker for its sign-in and sign-up processes. The company is marketing an application and expects that every application user will be from France.
When the company launches the application, its security team notices fraudulent application sign-ups. Most fraudulent registrations originate from users outside France.
The security team requires a solution that performs custom validation at sign-up. Based on the validation results, the solution must allow or deny the registration request.
Which combination of steps meets these requirements?
Choose two
ACreate a pre sign-up AWS Lambda trigger. Associate the Amazon Cognito function with the Amazon Cognito user pool.
BUse a geographic match rule statement to configure an AWS WAF web ACL. Associate the web ACL with the Amazon Cognito user pool.
CConfigure an app client for the application’s Amazon Cognito user pool. Use the app client ID to validate the requests in the hosted UI.
DUpdate the application’s Amazon Cognito user pool to configure a geographic restriction setting.
EUse Amazon Cognito to configure a social identity provider (IdP) to validate the requests on the hosted UI.
A security engineer is designing security controls for a fleet of Amazon EC2 instances running sensitive workloads in a VPC. The engineer must implement a solution that detects and mitigates software vulnerabilities on the EC2 instances.
Which solution meets this requirement?
AScan the EC2 instances by using Amazon Inspector. Apply security patches and updates by using AWS Systems Manager Patch Manager.
BInstall host-based firewall and antivirus software on each EC2 instance. Use AWS Systems Manager Run Command to update the firewall and antivirus software.
CInstall the Amazon CloudWatch agent on the EC2 instances. Enable detailed logging. Use Amazon EventBridge to review the software logs for anomalies.
DScan the EC2 instances by using Amazon GuardDuty Malware Protection. Apply security patches and updates by using AWS Systems Manager Patch Manager.
A company is developing a web application that must authenticate external users across multiple microservices hosted on Amazon Elastic Container Service (Amazon ECS). The solution must use temporary credentials and minimize the administrative overhead of maintaining user databases.
Select and arrange the correct steps from the list to implement a secure authentication strategy that satisfies these requirements. Select each step once or not at all.
Select
Step 1:
Step 2:
Step 3:
A company uses AWS Config rules to find Amazon S3 buckets that do not comply with the company’s data protection policy. The S3 buckets are hosted across several AWS Regions and several AWS accounts. The accounts belong to an organization in AWS Organizations.
The company requires a solution that remediates the organization’s existing noncompliant S3 buckets and any noncompliant S3 buckets created in the future.
Which solution meets these requirements?
ADeploy an AWS Config aggregator with organization-wide resource data aggregation. Create an AWS Lambda function that responds to AWS Config findings of noncompliant S3 buckets by deleting or reconfiguring the S3 buckets.
BDeploy an AWS Config aggregator with organization-wide resource data aggregation. Create an SCP that contains a Deny statement that prevents the creation of new noncompliant S3 buckets. Apply the SCP to all OUs in the organization.
CDeploy an AWS Config aggregator that scopes only the accounts and Regions that the company currently uses. Create an AWS Lambda function that responds to AWS Config findings of noncompliant S3 buckets by deleting or reconfiguring the S3 buckets.
DDeploy an AWS Config aggregator that scopes only the accounts and Regions that the company currently uses. Create an SCP that contains a Deny statement that prevents the creation of new noncompliant S3 buckets. Apply the SCP to all OUs in the organization.
A company uses an AWS Organizations organization to manage multiple AWS accounts. The company wants to centrally provide users with access to Amazon Q Developer.
Which solution meets this requirement?
AEnable AWS IAM Identity Center and set up Amazon Q Developer as an AWS managed application.
BEnable Amazon Cognito and create a new identity pool for Amazon Q Developer.
CEnable Amazon Cognito and set up Amazon Q Developer as an AWS managed application
DEnable AWS IAM Identity Center and create a new identity pool for Amazon Q Developer.
A company uses two AWS accounts: Account A and Account B. Each account contains a VPC. An application running in the VPC in Account A must write to an Amazon S3 bucket in Account B. The application in Account A already has permission to write to the S3 bucket in Account B.
The application and the S3 bucket are located in the same AWS Region. The company must not send network traffic across the public internet.
Which solution satisfies these requirements?
AIn both accounts, create a transit gateway and VPC attachments in a subnet in each Availability Zone. Update the VPC route tables.
BDeploy a software VPN appliance in Account A. Create a VPN connection between the software VPN appliance and a virtual private gateway in Account B.
CCreate a VPC peering connection between the VPC in Account A and the VPC in Account B. Update the VPC route tables, network ACLs, and security groups to allow network traffic between the peered IP ranges.
DIn Account A, create a gateway VPC endpoint for Amazon S3. Update the VPC route table in Account A.
A security engineer needs to assess configuration changes to a particular AWS resource to confirm that the resource complies with standards. However, the security engineer is worried about cases where several configuration changes occur on the resource in rapid succession. The security engineer wants to record only that resource’s most recent configuration to show the cumulative effect of the changes.
Which solution meets this requirement in the MOST operationally efficient manner?
AUse AWS CloudTrail to detect the configuration changes by filtering API calls to monitor the changes. Use the most recent API call to indicate the cumulative impact of multiple calls.
BUse AWS Config to detect the configuration changes and to record the latest configuration in case of multiple configuration changes.
CUse Amazon CloudWatch to detect the configuration changes by filtering API calls to monitor the changes. Use the most recent API call to indicate the cumulative impact of multiple calls.
DUse AWS Cloud Map to detect the configuration changes. Generate a report of configuration changes from AWS Cloud Map to track the latest state by using a sliding time window.
A company has engaged a third party to audit multiple AWS accounts. Cross-account IAM roles have been created in every account being audited to support the audit. The auditor is experiencing difficulty accessing some accounts.
Which of the following could be causing this issue?
Choose three
AThe external ID used by the auditor is missing or incorrect.
BThe auditor is using the incorrect password.
CThe auditor has not been granted sts:AssumeRole for the role in the destination account.
DThe Amazon EC2 role used by the auditor must be set to the destination account role.
EThe secret key used by the auditor is missing or incorrect.
FThe role ARN used by the auditor is missing or incorrect.
A company is investigating a rise in its monthly AWS bill. The company determines that malicious actors compromised several Amazon EC2 instances and used them to host webpages for a large email-phishing campaign.
A security engineer must implement a solution that monitors future cost increases to help identify malicious activity.
Which solution will provide the company with the EARLIEST detection of cost increases?
ACreate an Amazon EventBridge rule that invokes an AWS Lambda function hourly. Program the Lambda function to download an AWS usage report from AWS Data Exports about usage of all services. Program the Lambda function to analyze the report and to send a notification when anomalies are detected.
BCreate a cost monitor in AWS Cost Anomaly Detection. Configure an individual alert to notify an Amazon Simple Notification Service (Amazon SNS) topic when the percentage above the expected cost exceeds a threshold.
CReview AWS Cost Explorer daily to detect anomalies in cost from prior months. Review the usage of any services that experience a significant cost increase from prior months.
DCapture VPC flow logs from the VPC where the EC2 instances run. Use a third-party network analysis tool to analyze the flow logs and to detect anomalies in network traffic that might increase cost.
A company operates an internet-facing open-source software platform. The legacy platform no longer receives security updates. It uses Amazon Route 53 weighted load balancing to route traffic to two Amazon EC2 instances that connect to an Amazon RDS cluster. A recent report indicates that the platform is vulnerable to SQL injection attacks and includes attack samples. The company’s security engineer must secure the system against SQL injection attacks within 24 hours. The solution must require the least effort and maintain normal operations throughout implementation.
What should the security engineer do to satisfy these requirements?
ACreate an Application Load Balancer with the existing EC2 instances as a target group. Create an AWS WAF web ACL containing rules that protect the application from this attack, then apply it to the ALB. Test to ensure the vulnerability has been mitigated, then redirect the Route 53 records to point to the ALB. Update security groups on the EC2 instances to prevent direct access from the internet.
BCreate an Amazon CloudFront distribution specifying one EC2 instance as an origin. Create an AWS WAF web ACL containing rules that protect the application from this attack, then apply it to the distribution. Test to ensure the vulnerability has been mitigated, then redirect the Route 53 records to point to CloudFront.
CObtain the latest source code for the platform and make the necessary updates. Test the updated code to ensure that the vulnerability has been mitigated, then deploy the patched version of the platform to the EC2 instances.
DUpdate the security group that is attached to the EC2 instances, removing access from the internet to the TCP port used by the SQL database. Create an AWS WAF web ACL containing rules that protect the application from this attack, then apply it to the EC2 instances. Test to ensure the vulnerability has been mitigated, then restore the security group to the original setting.
Community Discussion