Official Bank 0/418

Amazon AWS Certified Security – Specialty (SCS-C02) - AWS Exam Questions

Last updated on July 22, 2026

97% Exam Compliance
418 Total Questions
1
Question
[Incident Response] A security analyst attempted to troubleshoot the monitoring of suspicious security group changes. The analyst was told that there is an Amazon CloudWatch alarm in place for these AWS CloudTrail log events. The analyst tested the monitoring setup by making a configuration change to the security group but did not receive any alerts.

Which of the following troubleshooting steps should the analyst perform?
Options
A Ensure that CloudTrail and S3 bucket access logging is enabled for the analyst's AWS account.
B Verify that a metric filter was created and then mapped to an alarm. Check the alarm notification action.
C Check the CloudWatch dashboards to ensure that there is a metric configured with an appropriate dimension for security group changes.
D Verify that the analyst's account is mapped to an IAM policy that includes permissions for cloudwatch:GetMetricStatistics andcloudwatch:ListMetrics.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
A company uses AWS Organizations to manage its AWS accounts. The company needs to enforce server-side encryption with AWS KMS keys (SSE-KMS) on its Amazon S3 buckets Which solution will meet this requirement?
Options
A Edit the S3 bucket policies to require requests to include the s3 x-amz-server-side-encryption header.
B Edit the S3 bucket policies to require requests to include the s3 x-amz-server-side-encryption-aws- kms-key-id header.
C Create an SCP that requires requests to include the s3 x-amz-server-side-encryption header Attach the SCP to the root OU.
D Create an SCP that requires requests to include the s3 x-amz-server-side-encryption-customer- algorithm header Attach the SCP to the root OU.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
[Identity and Access Management] A security engineer recently rotated the host keys for an Amazon EC2 instance. The security engineer is trying to access the EC2 instance by using the EC2 Instance. Connect feature. However, the security engineer receives an error (or failed host key validation. Before the rotation of the host keys EC2 Instance Connect worked correctly with this EC2 instance.

What should the security engineer do to resolve this error?
Options
A Import the key material into AWS Key Management Service (AWS KMS).
B Manually upload the new host key to the AWS trusted host keys database.
C Create a new SSH key pair for the EC2 instance.
D Ensure that the AmazonSSMManagedInstanceCore policy is attached to the EC2 instance profile.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
[Infrastructure Security] A company is building a data processing application mat uses AWS Lambda functions. The application's Lambda functions need to communicate with an Amazon RDS OB instance that is deployed within a VPC in the same AWS account

Which solution meets these requirements in the MOST secure way?
Options
A Configure the DB instance to allow public access Update the DB instance security group to allow access from the Lambda public address space for the AWS Region
B Deploy the Lambda functions inside the VPC Attach a network ACL to the Lambda subnet Provide outbound rule access to the VPC CIDR range only Update the DB instance security group to allow traffic from 0.0.0.0/0
C Peer the Lambda default VPC with the VPC that hosts the DB instance to allow direct network access without the need for security groups
D Deploy the Lambda functions inside the VPC Attach a security group to the Lambda functions Provide outbound rule access to the VPC CIDR range only Update the DB instance security group to allow traffic from the Lambda security group
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
[Identity and Access Management] A company uses an organization in AWS Organizations to manage its AWS accounts. The company has implemented a Service Control Policy (SCP) in the root account to prevent resources from being shared with external accounts. The company now needs to allow applications in its marketing team's AWS account to share resources with external accounts. The company must continue to prevent all the other accounts in the organization from sharing resources with external accounts. All the accounts in the organization are members of the same Organizational Unit (OU).

Which solution will meet these requirements?
Options
A Create a new SCP in the marketing team's account. Configure the SCP to explicitly allow resource sharing.
B Edit the existing SCP to add a Condition statement that excludes the marketing team's account.
C Edit the existing SCP to include an Allow statement that specifies the marketing team's account.
D Create an IAM permissions boundary policy to explicitly allow resource sharing. Attach the policy to IAM users in the marketing team's account.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.