AWS Certified Security - Specialty Practice Questions
Prepare for SCS-C02 with more than an answer.
Unlock the full exam and previous versions
- v1AWS Certified Security - Speciality 275 questions Locked
- SCS-C01Legacy AWS Certified Security - Specialty 223 questions Locked
- SCS-C02Legacy AWS Certified Security - Specialty 71 questions Current
- Exam fee
- $300 USD
- Level
- Specialty
- Valid for
- 3 years
Domains covered on the exam 6
- Threat Detection and Incident Response14%
- Security Logging and Monitoring18%
- Infrastructure Security20%
- Identity and Access Management16%
- Data Protection18%
- Management and Security Governance14%
- 1
A company needs a security engineer to implement a scalable solution for multi-account authentication and authorization. The solution should not introduce additional user-managed architectural components. Native AWS features should be used as much as possible. The security engineer has set up AWS Organizations with all features activated and AWS IAM Identity Center (AWS Single Sign-On) enabled.Which additional steps should the security engineer take to complete the task?
Show answer details
Correct answer: B
- 2
A company has deployed Amazon GuardDuty and now wants to implement automation for potential threats. The company has decided to start with RDP brute force attacks that come from Amazon EC2 instances in the company's AWS environment. A security engineer needs to implement a solution that blocks the detected communication from a suspicious instance until investigation and potential remediation can occur.Which solution will meet these requirements?
Show answer details
Correct answer: C
- 3
A company has an AWS account that hosts a production application. The company receives an email notification that Amazon GuardDuty has detected an Impact:IAMUser/AnomalousBehavior finding in the account. A security engineer needs to run the investigation playbook for this security incident and must collect and analyze the information without affecting the application.Which solution will meet these requirements MOST quickly?
Show answer details
Correct answer: B
- 4
Company A has an AWS account that is named Account A. Company A recently acquired Company B, which has an AWS account that is named Account B. Company B stores its files in an Amazon S3 bucket. The administrators need to give a user from Account A full access to the S3 bucket in Account B.After the administrators adjust the IAM permissions for the user in Account A to access the S3 bucket in Account B, the user still cannot access any files in the S3 bucket.Which solution will resolve this issue?
Show answer details
Correct answer:
- 5
A company has an AWS Lambda function that creates image thumbnails from larger images. The Lambda function needs read and write access to an Amazon S3 bucket in the same AWS account.Which solutions will provide the Lambda function this access? (Choose two.)
Show answer details
Correct answer: C, D
