About the Exam

This exam is intended for experienced individuals responsible for securing cloud solutions, especially AWS workloads and applications. It covers security services and practices including detection, incident response, infrastructure security, identity and access management, data protection, and security foundations and governance. Passing demonstrates the ability to apply AWS security mechanisms to help design and operate secure production environments.

Exam Topics

  • Detection16%
  • Incident Response14%
  • Infrastructure Security18%
  • Identity and Access Management20%
  • Data Protection18%
  • Security Foundations and Governance14%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated September 9, 2026 at 6:23 PM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Infrastructure Security

A company must comply with a requirement to encrypt all data in transit. The company recently identified an Amazon Aurora cluster that fails to meet this requirement.

How can the company require encryption for every connection to the Aurora cluster?

Explanation

Setting the Aurora MySQL DB cluster parameter require_secure_transport to ON requires TLS for user connections and rejects clients that cannot establish an encrypted connection. This directly enforces encryption of data in transit for connections to the cluster.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Detection

A company operates several applications on Amazon Elastic Kubernetes Service (Amazon EKS). The company requires a solution to identify Kubernetes security risks by monitoring Amazon EKS audit logs, as well as operating system, networking, and file events. The solution must send email alerts for any detected risks to a mailing list associated with a security team.

Which solution meets these requirements?

Explanation

Amazon GuardDuty EKS Protection monitors Kubernetes audit logs for potential EKS security threats, and GuardDuty Runtime Monitoring analyzes operating system-level, networking, and file events in EKS workloads. GuardDuty publishes findings to Amazon EventBridge, which can route matching findings to an Amazon SNS topic that delivers email to the security team mailing list.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Identity and Access Management

A company hosts an application on an Amazon EC2 instance. The application creates invoices and saves them in an Amazon S3 bucket. The instance profile attached to the instance has the required access to the S3 bucket.

The company must share every invoice with multiple clients who do not have AWS credentials. Each client must be able to download only that client’s own invoices. Clients must download invoices within 1 hour after invoice creation. Clients must use only temporary credentials to access the company’s AWS resources.

A security engineer creates a script that runs on the EC2 instance. The script uses the instance profile to create an S3 presigned URL for the clients. Each presigned URL expires after 1 hour.

Which additional step will satisfy these requirements?

Explanation

AWS STS AssumeRole returns temporary security credentials. Presigning each invoice’s S3 GetObject request with newly assumed-role credentials grants access only to the specific object identified by that URL and limits access to the URL’s configured one-hour lifetime. The clients need no IAM user credentials or broader S3 permissions.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Incident Response

A company operates critical workloads in an on-premises data center. The company wants to implement an AWS-based disaster recovery (DR) solution that achieves an RTO of less than 1 hour. The company must continuously replicate physical and virtual servers. It must optimize costs for data storage and bandwidth use. The DR solution must be automated.

Which solution meets these requirements?

Explanation

AWS Elastic Disaster Recovery uses replication agents to continuously perform block-level replication of physical and virtual source servers into a low-cost staging area. It provides recovery orchestration and automated server conversion, with recovery time objectives typically measured in minutes, which meets an RTO of less than one hour while minimizing steady-state storage and compute costs.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Identity and Access Management

A company uses AWS IAM Identity Center to control access to its AWS accounts. The accounts belong to an organization in AWS Organizations.

A security engineer must establish delegated administration of IAM Identity Center in the organization’s management account.

Which combination of steps should the security engineer complete in IAM Identity Center before setting up delegated administration?

Choose three
Explanation

IAM Identity Center delegated-administration best practices are to grant least-privilege access to the highly privileged management account, use dedicated permission sets for that account because delegated administrators cannot modify permission sets provisioned there, and assign users directly to management-account permission sets rather than groups. Direct user assignments reduce the risk that group-membership changes grant unintended access to the management account.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home