Skip to content

Security - Speciality Practice Questions

Prepare for SCS-C03 with more than an answer.

275 questions in the full set17 sample questionsUpdated Jan 28, 2026

Unlock the full exam and previous versions

  • v1AWS Certified Security - Speciality 275 questions Current
  • SCS-C01Legacy AWS Certified Security - Specialty 223 questions Locked
  • SCS-C02Legacy AWS Certified Security - Specialty 71 questions Locked
Exam fee
$300 USD
Level
Specialty
Valid for
3 years
Domains covered on the exam 6
  1. Detection16%
  2. Incident Response14%
  3. Infrastructure Security18%
  4. Identity and Access Management20%
  5. Data Protection18%
  6. Security Foundations and Governance14%
  1. 1

    True or False: AWS Systems Manager Incident Manager can automatically create an OpsItem in OpsCenter when an incident is started.

    Show answer details

    Correct answer: A

    Incident Manager integrates natively with OpsCenter. When an incident is created, it automatically generates a corresponding OpsItem to track the operational work.

  2. 2

    An EC2 instance is suspected of being compromised by malware. A security responder needs to isolate the instance for forensic analysis while ensuring the volatile memory (RAM) is preserved for later inspection. The instance is in a private subnet.

    Which sequence of actions is most appropriate?

    Show answer details

    Correct answer: A

    This sequence ensures network isolation (stopping lateral movement) while keeping the instance running to capture volatile memory. Only after memory capture is complete should the instance be stopped.

  3. 3

    A security analyst needs to investigate an incident involving an IAM Access Key that occurred 18 months ago. The organization has an organization-wide CloudTrail trail logging to S3, but querying the raw JSON files in S3 is proving too slow and complex.

    Which solution allows the analyst to run SQL-like queries on this historical data with the LEAST operational setup?

    Show answer details

    Correct answer: A

    CloudTrail Lake supports importing existing trail logs from S3. Once imported, it provides an immutable, managed data store that allows SQL-based querying without needing to define schemas or manage crawlers like Athena requires.

  4. 4

    A company is under a massive DDoS attack. They are subscribed to AWS Shield Advanced. The security team wants to escalate the incident to the AWS Shield Response Team (SRT) for specialized assistance. Which prerequisite MUST be met before the SRT can actively assist in mitigating the attack?

    Show answer details

    Correct answer: A

    The SRT cannot access customer resources to analyze or mitigate attacks unless the customer explicitly provisions the specific IAM role that grants them permission.

  5. 5

    A multinational corporation is adopting a Zero Trust architecture. They want to provide their employees secure access to internal corporate applications hosted on private subnets in AWS without using a VPN. The solution must authenticate users against their corporate Identity Provider (IdP) and evaluate the security posture of the user's device before granting access.

    Which architecture should the security architect design?

    Show answer details

    Correct answer: A

    AWS Verified Access is specifically designed for VPN-less, Zero Trust access. It validates every request by evaluating identity (from OIDC) and device posture (from trust providers) against Cedar-based policies before routing traffic to private applications.

    flowchart LR User[User Device] -->|HTTPS| AVA[AWS Verified Access] AVA -->|Auth Check| IdP[Identity Provider] AVA -->|Health Check| Trust[Device Trust Provider] AVA -->|Allowed| App[Private App in VPC]
  6. 6

    A security engineer is configuring AWS Network Firewall to inspect outbound traffic from a VPC. The requirement is to allow HTTPS traffic ONLY to *.example.com and *.partner-site.org, and deny all other HTTPS traffic. Which TWO configuration steps are required to achieve this? (Select TWO)

    Show answer details

    Correct answer: A, B

    Stateful rule groups in AWS Network Firewall support domain list specifications for HTTP/HTTPS traffic inspection.

    To create an allow-list model, you must ensure that traffic not matching the allow-list is dropped. This is typically done by setting the default action order to 'Strict' and having a default drop, or ensuring the firewall policy handles non-matching traffic as deny.

  7. 7

    A financial institution is implementing a centralized logging architecture to comply with strict regulatory requirements. They need to aggregate security logs from Amazon GuardDuty, AWS Security Hub, and Amazon Route 53 Resolver DNS Firewall across 50 AWS accounts into a central security account. The solution must support the Open Cybersecurity Schema Framework (OCSF) to facilitate integration with a third-party SIEM. The security team prioritizes a solution that minimizes custom transformation logic and operational overhead.

    Which solution should the security architect implement?

    Show answer details

    Correct answer: A

    Amazon Security Lake automatically centralizes security data from AWS environments, SaaS providers, and on-premises sources into a purpose-built data lake stored in your account. It automatically converts incoming log data to the Open Cybersecurity Schema Framework (OCSF) standard, which meets the requirement for minimized transformation logic and SIEM integration.

  8. 8

    A security engineer is troubleshooting a new Amazon GuardDuty deployment in an Amazon EKS environment. The engineer has enabled GuardDuty EKS Protection, but the security team is not receiving findings related to suspicious process executions within the Kubernetes pods. The Audit logs are being correctly ingested.

    What is the most likely cause of this issue?

    Show answer details

    Correct answer: A

    GuardDuty EKS Protection consists of two parts: Audit Log Monitoring (control plane) and Runtime Monitoring (data plane). Suspicious process executions inside a pod are detected by the Runtime Monitoring agent. If only Audit logs are working, the Runtime Monitoring component is likely missing or disabled.

Create an account to continue.