DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free AWS SCS-C02 Practice Questions & Answers 2026 Part1

Are you preparing for the AWS SCS-C02 certification exam? SPOTO offers the AWS SCS-C02 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
A company needs a solution to protect critical data from being permanently deleted. The data is stored in Amazon S3 buckets.The company needs to replicate the S3 objects from the company's primary AWS Region to a secondary Region to meet disaster recovery requirements. The company must also ensure that users who have administrator access cannot permanently delete the data in the secondary Region.Which solution will meet these requirements?
A. Configure AWS Backup to perform cross-Region S3 backups
B. Implement S3 Object Lock in compliance mode in the primary Region
C. Configure S3 replication to replicate the objects to an S3 bucket in the secondary Region
D. Configure S3 replication to replicate the objects to an S3 bucket in the secondary Region
View answer
Correct Answer: B

View The Updated SCS-C02 Exam Questions

SPOTO Provides 100% Real SCS-C02 Exam Questions for You to Pass Your SCS-C02 Exam!

Question #2
A company has several petabytes of data. The company must preserve this data for 7 years to comply with regulatory requirements. The company's compliance team asks a security officer to develop a strategy that will prevent anyone from changing or deleting the data.Which solution will meet this requirement MOST cost-effectively?
A. Create an Amazon S3 bucket
B. Create an Amazon S3 bucket
C. Create a vault in Amazon S3 Glacier
D. Create an Amazon S3 bucket
View answer
Correct Answer: C
Question #3
A company's security engineer wants to receive an email alert whenever Amazon GuardDuty, AWS Identity and Access Management Access Analyzer, or Amazon Made generate a high-severity security finding. The company uses AWS Control Tower to govern all of its accounts. The company also uses AWS Security Hub with all of the AWS service integrations turned on.
A. Set up separate AWS Lambda functions for GuardDuty, IAM Access Analyzer, and Macie to call each service's public API to retrieve high-severity findings
B. Create an Amazon EventBridge rule with a pattern that matches Security Hub findings events with high severity
C. Create an Amazon EventBridge rule with a pattern that matches AWS Control Tower events with high severity
D. Host an application on Amazon EC2 to call the GuardDuty, IAM Access Analyzer, and Macie APIs
View answer
Correct Answer: B
Question #4
A company has deployed Amazon GuardDuty and now wants to implement automation for potential threats. The company has decided to start with RDP brute force attacks that come from Amazon EC2 instances in the company's AWS environment. A security engineer needs to implement a solution that blocks the detected communication from a suspicious instance until investigation and potential remediation can occur.
A. Configure GuardDuty to send the event to an Amazon Kinesis data stream
B. Configure GuardDuty to send the event to Amazon EventBridge (Amazon CloudWatch Events)
C. Enable AWS Security Hub to ingest GuardDuty findings and send the event to Amazon EventBridge (Amazon CloudWatch Events)
D. Enable AWS Security Hub to ingest GuardDuty findings
View answer
Correct Answer: C
Question #5
A-company uses a third-party identity provider and SAML-based SSO for its AWS accounts. After the third-party identity provider renewed an expired signing certificate, users saw the following message when trying to log in:Error: Response Signature Invalid (Service: AWSSecurityTokenService; Status Code: 400; Error Code: InvalidIdentityToken)A security engineer needs to provide a solution that corrects the error and minimizes operational overhead.Which solution meets these requirements?
A. Upload the third-party signing certificate’s new private key to the AWS identity provider entity defined in AWS Identity and Access Management (IAM) by using the AWS Management Console
B. Sign the identity provider's metadata file with the new public key
C. Download the updated SAML metadata file from the identity service provider
D. Configure the AWS identity provider entity defined in AWS Identity and Access Management (IAM) to synchronously fetch the new public key by using the AWS Management Console
View answer
Correct Answer: C
Question #6
A company's security engineer has been tasked with restricting a contractor's IAM account access to the company’s Amazon EC2 console without providing access to any other AWS services. The contractor's IAM account must not be able to gain access to any other AWS service, even if the IAM account is assigned additional permissions based on IAM group membership.What should the security engineer do to meet these requirements?
A. Create an inline IAM user policy that allows for Amazon EC2 access for the contractor's IAM user
B. Create an IAM permissions boundary policy that allows Amazon EC2 access
C. Create an IAM group with an attached policy that allows for Amazon EC2 access
D. Create a IAM role that allows for EC2 and explicitly denies all other services
View answer
Correct Answer: B
Question #7
A company's AWS CloudTrail logs are all centrally stored in an Amazon S3 bucket. The security team controls the company's AWS account. The security team must prevent unauthorized access and tampering of the CloudTrail logs.Which combination of steps should the security team take? (Choose three.)
A. Configure server-side encryption with AWS KMS managed encryption keys (SSE-KMS)
B. Compress log files with secure gzip
C. Create an Amazon EventBridge rule to notify the security team of any modifications on CloudTrail log files
D. Implement least privilege access to the S3 bucket by configuring a bucket policy
E. Configure CloudTrail log file integrity validation
F. Configure Access Analyzer for S3
View answer
Correct Answer: ADE
Question #8
A company has an AWS account that hosts a production application. The company receives an email notification that Amazon GuardDuty has detected an Impact:IAMUser/AnomalousBehavior finding in the account. A security engineer needs to run the investigation playbook for this security incident and must collect and analyze the information without affecting the application.Which solution will meet these requirements MOST quickly?
A. og in to the AWS account by using read-only credentials
B. og in to the AWS account by using read-only credentials
C. og in to the AWS account by using administrator credentials
D. og in to the AWS account by using read-only credentials
View answer
Correct Answer: B
Question #9
A company has an AWS account that hosts a production application. The company receives an email notification that Amazon GuardDuty has detected an Impact:IAMUser/AnomalousBehavior finding in the account. A security engineer needs to run the investigation playbook for this security incident and must collect and analyze the information without affecting the application.Which solution will meet these requirements MOST quickly?
A. Log in to the AWS account by using read-only credentials
B. Log in to the AWS account by using read-only credentials
C. Log in to the AWS account by using administrator credentials
D. Log in to the AWS account by using read-only credentials
View answer
Correct Answer: B
Question #10
A company is running internal microservices on Amazon Elastic Container Service (Amazon ECS) with the Amazon EC2 launch type. The company is using Amazon Elastic Container Registry (Amazon ECR) private repositories.A security engineer needs to encrypt the private repositories by using AWS Key Management Service (AWS KMS). The security engineer also needs to analyze the container images for any common vulnerabilities and exposures (CVEs).Which solution will meet these requirements?
A. nable KMS encryption on the existing ECR repositories
B. ecreate the ECR repositories with KMS encryption and ECR scanning enabled
C. ecreate the ECR repositories with KMS encryption and ECR scanning enabled
D. nable KMS encryption on the existing ECR repositories
View answer
Correct Answer: B
Question #11
A company is expanding its group of stores. On the day that each new store opens, the company wants to launch a customized web application for that store. Each store's application will have a non-production environment and a production environment. Each environment will be deployed in a separate AWS account. The company uses AWS Organizations and has an OU that is used only for these accounts.The company distributes most of the development work to third-party development teams. A security engineer needs to ensure that each team follows the company's deployment plan for AWS resources. The security engineer also must limit access to the deployment plan to only the developers who need access. The security engineer already has created an AWS CloudFormation template that implements the deployment plan.What should the security engineer do next to meet the requirements in the MOST secure way?
A. Create an AWS Service Catalog portfolio in the organization's management account
B. Use the CloudFormation CLI to create a module from the CloudFormation template
C. Create an AWS Service Catalog portfolio in the organization's management account
D. Use the CloudFormation CLI to create a module from the CloudFormation template
View answer
Correct Answer: A
Question #12
A company's AWS CloudTrail logs are all centrally stored in an Amazon S3 bucket. The security team controls the company's AWS account. The security team must prevent unauthorized access and tampering of the CloudTrail logs.Which combination of steps should the security team take? (Choose three.)
A. Configure server-side encryption with AWS KMS managed encryption keys (SSE-KMS)
B. Compress log files with secure gzip
C. Create an Amazon EventBridge rule to notify the security team of any modifications on CloudTrail log files
D. Implement least privilege access to the S3 bucket by configuring a bucket policy
E. Configure CloudTrail log file integrity validation
F. Configure Access Analyzer for S3
View answer
Correct Answer: ADE
Question #13
A company that uses AWS Organizations is using AWS IAM Identity Center (AWS Single Sign-On) to administer access to AWS accounts. A security engineer is creating a custom permission set in IAM Identity Center. The company will use the permission set across multiple accounts. An AWS managed policy and a customer managed policy are attached to the permission set. The security engineer has full administrative permissions and is operating in the management account.When the security engineer attempts to assign the permission set to an IAM Identity Center user who has access to multiple accounts, the assignment fails.What should the security engineer do to resolve this failure?
A. Create the customer managed policy in every account where the permission set is assigned
B. Remove either the AWS managed policy or the customer managed policy from the permission set
C. Evaluate the logic of the AWS managed policy and the customer managed policy
D. Do not add the new permission set to the user
View answer
Correct Answer: A
Question #14
A security engineer needs to run an AWS CloudFormation script. The CloudFormation script builds AWS infrastructure to support a stack that includes web servers and a MySQL database. The stack has been deployed in pre-production environments and is ready for production.
A. Use IAM Access Analyzer policy generation to generate a policy that allows the CloudFormation script to run and manage the stack
B. Create an IAM policy that allows ec2:* and rds:* permissions
C. Use IAM Access Analyzer policy generation to generate a policy that allows the CloudFormation script to run and manage the stack
D. Create an IAM policy that allows ec2:* and rds:* permissions
View answer
Correct Answer: A
Question #15
A company has several petabytes of data. The company must preserve this data for 7 years to comply with regulatory requirements. The company's compliance team asks a security officer to develop a strategy that will prevent anyone from changing or deleting the data.Which solution will meet this requirement MOST cost-effectively?
A. Create an Amazon S3 bucket
B. Create an Amazon S3 bucket
C. Create a vault in Amazon S3 Glacier
D. Create an Amazon S3 bucket
View answer
Correct Answer: C
Question #16
A company has several workloads running on AWS. Employees are required to authenticate using on-premises ADFS and SSO to access the AWS Management Console. Developers migrated an existing legacy web application to an Amazon EC2 instance. Employees need to access this application from anywhere on the internet, but currently, there is no authentication system built into the application.How should the security engineer implement employee-only access to this system without changing the application?
A. Place the application behind an Application Load Balancer (ALB)
B. Implement AWS IAM Identity Center (AWS Single Sign-On) in the management account and link it to ADFS as an identity provider
C. Define an Amazon Cognito identity pool, then install the connector on the Active Directory server
D. Create an AWS Lambda custom authorizer as the authenticator for a reverse proxy on Amazon EC2
View answer
Correct Answer: A
Question #17
A security engineer is checking an AWS CloudFormation template for vulnerabilities. The security engineer finds a parameter that has a default value that exposes an application's API key in plaintext. The parameter is referenced several times throughout the template. The security engineer must replace the parameter while maintaining the ability to reference the value in the template.Which solution will meet these requirements in the MOST secure way?
A. Store the API key value as a SecureString parameter in AWS Systems Manager Parameter Store
B. Store the API key value in AWS Secrets Manager
C. Store the API key value in Amazon DynamoDB
D. Store the API key value in a new Amazon S3 bucket
View answer
Correct Answer: B
Question #18
An ecommerce company has a web application architecture that runs primarily on containers. The application containers are deployed on Amazon Elastic Container Service (Amazon ECS). The container images for the application are stored in Amazon Elastic Container Registry (Amazon ECR).The company's security team is performing an audit of components of the application architecture. The security team identifies issues with some container images that are stored in the container repositories.The security team wants to address these issues by implementing continual scanning and on-push scanning of the container images. The security team needs to implement a solution that makes any findings from these scans visible in a centralized dashboard. The security team plans to use the dashboard to view these findings along with other security-related findings that they intend to generate in the future. There are specific repositories that the security team needs to exclude from the scanning process.Which solution will meet these requirements?
A. Use Amazon Inspector
B. Use ECR basic scanning of container images
C. Use ECR basic scanning of container images
D. Use Amazon Inspector
View answer
Correct Answer: A
Question #19
A security engineer is configuring a new website that is named example.com. The security engineer wants to secure communications with the website by requiring users to connect to example.com through HTTPS.Which of the following is a valid option for storing SSL/TLS certificates?
A. Custom SSL certificate that is stored in AWS Key Management Service (AWS KMS)
B. Default SSL certificate that is stored in Amazon CloudFront
C. Custom SSL certificate that is stored in AWS Certificate Manager (ACM)
D. Default SSL certificate that is stored in Amazon S3
View answer
Correct Answer: C
Question #20
A-company uses a third-party identity provider and SAML-based SSO for its AWS accounts. After the third-party identity provider renewed an expired signing certificate, users saw the following message when trying to log in:Error: Response Signature Invalid (Service: AWSSecurityTokenService; Status Code: 400; Error Code: InvalidIdentityToken)A security engineer needs to provide a solution that corrects the error and minimizes operational overhead.Which solution meets these requirements?
A. Upload the third-party signing certificate’s new private key to the AWS identity provider entity defined in AWS Identity and Access Management (IAM) by using the AWS Management Console
B. Sign the identity provider's metadata file with the new public key
C. Download the updated SAML metadata file from the identity service provider
D. Configure the AWS identity provider entity defined in AWS Identity and Access Management (IAM) to synchronously fetch the new public key by using the AWS Management Console
View answer
Correct Answer: C
Question #21
A company uses AWS Organizations. The company wants to implement short-term cre-dentials for third-party AWS accounts to use to access accounts within the com-pany's organization. Access is for the AWS Management Console and third-party software-as-a-service (SaaS) applications. Trust must be enhanced to prevent two external accounts from using the same credentials. The solution must require the least possible operational effort.Which solution will meet these requirements?
A. mplement AWS IAM Identity Center (AWS Single Sign-On), and use an identi-ty source of choice
B. reate a unique IAM role for each external account
C. reate a unique IAM role for each external account
D. se a bearer token authentication with OAuth or SAML to manage and share a central Amazon Cognito user pool across multiple Amazon API Gateway APIs
View answer
Correct Answer: B
Question #22
[Identity and Access Management]A company's security engineer has been tasked with restricting a contractor's IAM account access to the company's Amazon EC2 console without providing access to any other IAM services The contractors IAM account must not be able to gain access to any other IAM service, even it the IAM account rs assigned additional permissions based on IAM group membershipWhat should the security engineer do to meet these requirements''
A. Create an mime IAM user policy that allows for Amazon EC2 access for the contractor's IAM user
B. Create an IAM permissions boundary policy that allows Amazon EC2 access Associate the contractor's IAM account with the IAM permissions boundary policy
C. Create an IAM group with an attached policy that allows for Amazon EC2 access Associate the contractor's IAM account with the IAM group
D. Create a IAM role that allows for EC2 and explicitly denies all other services Instruct the contractor to always assume this role
View answer
Correct Answer: B
Question #23
You have an S3 bucket defined in IAM. You want to ensure that you encrypt the data before sending it across the wire. What is the best way to achieve this. Please select
A. Enable server side encryption for the S3 bucket
B. Use the IAM Encryption CLI to encrypt the data first
C. Use a Lambda function to encrypt the data before sending it to the S3 bucket
D. Enable client encryption for the bucket
View answer
Correct Answer: B
Question #24
A company has a single AWS account and uses an Amazon EC2 instance to test application code. The company recently discovered that the instance was compromised. The instance was serving up malware. The analysis of the instance showed that the instance was compromised 35 days ago.A security engineer must implement a continuous monitoring solution that automatically notifies the company's security team about compromised instances through an email distribution list for high severity findings. The security engineer must implement the solution as soon as possible.Which combination of steps should the security engineer take to meet these requirements? (Choose three.)
A. nable AWS Security Hub in the AWS account
B. nable Amazon GuardDuty in the AWS account
C. reate an Amazon Simple Notification Service (Amazon SNS) topic
D. reate an Amazon Simple Queue Service (Amazon SQS) queue
E. reate an Amazon EventBridge rule for GuardDuty findings of high severity
F. reate an Amazon EventBridge rule for Security Hub findings of high severity
View answer
Correct Answer: BCE
Question #25
A security engineer needs to develop a process to investigate and respond to potential security events on a company's Amazon EC2 instances. All the EC2 instances are backed by Amazon Elastic Block Store (Amazon EBS). The company uses AWS Systems Manager to manage all the EC2 instances and has installed Systems Manager Agent (SSM Agent) on all the EC2 instances.The process that the security engineer is developing must comply with AWS security best practices and must meet the following requirements:A compromised EC2 instance's volatile memory and non-volatile memory must be preserved for forensic purposes.A compromised EC2 instance's metadata must be updated with corresponding incident ticket information.A compromised EC2 instance must remain online during the investigation but must be isolated to prevent the spread of malware.Any investigative activity during the collection of volatile data must be captured as part of the process.Which combination of steps should the security engineer take to meet these requirements with the LEAST operational overhead? (Choose three.)
A. Gather any relevant metadata for the compromised EC2 instance
B. Gather any relevant metadata for the compromised EC2 instance
C. Use Systems Manager Run Command to invoke scripts that collect volatile data
D. Establish a Linux SSH or Windows Remote Desktop Protocol (RDP) session to the compromised EC2 instance to invoke scripts that collect volatile data
E. Create a snapshot of the compromised EC2 instance's EBS volume for follow-up investigations
F. Create a Systems Manager State Manager association to generate an EBS volume snapshot of the compromised EC2 instance
View answer
Correct Answer: ACE
Question #26
A company needs a security engineer to implement a scalable solution for multi-account authentication and authorization. The solution should not introduce additional user-managed architectural components. Native AWS features should be used as much as possible. The security engineer has set up AWS Organizations with all features activated and AWS IAM Identity Center (AWS Single Sign-On) enabled.Which additional steps should the security engineer take to complete the task?
A. se AD Connector to create users and groups for all employees that require access to AWS accounts
B. se an IAM Identity Center default directory to create users and groups for all employees that require access to AWS accounts
C. se an IAM Identity Center default directory to create users and groups for all employees that require access to AWS accounts
D. se AWS Directory Service for Microsoft Active Directory to create users and groups for all employees that require access to AWS accounts
View answer
Correct Answer: B
Question #27
A company is using Amazon Macie, AWS Firewall Manager, Amazon Inspector, and AWS Shield Advanced in its AWS account. The company wants to receive alerts if a DDoS attack occurs against the account.Which solution will meet this requirement?
A. Use Macie to detect an active DDoS event
B. Use Amazon inspector to review resources and to invoke Amazon CloudWatch alarms for any resources that are vulnerable to DDoS attacks
C. Create an Amazon CloudWatch alarm that monitors Firewall Manager metrics for an active DDoS event
D. Create an Amazon CloudWatch alarm that monitors Shield Advanced metrics for an active DDoS event
View answer
Correct Answer: D
Question #28
A company manages multiple AWS accounts using AWS Organizations. The company’s security team notices that some member accounts are not sending AWS CloudTrail logs to a centralized Amazon S3 logging bucket. The security team wants to ensure there is at least one trail configured for all existing accounts and for any account that is created in the future.Which set of actions should the security team implement to accomplish this?
A. Create a new trail and configure it to send CloudTrail logs to Amazon S3
B. Deploy an AWS Lambda function in every account to check if there is an existing trail and create a new trail, if needed
C. Edit the existing trail in the Organizations management account and apply it to the organization
D. Create an SCP to deny the cloudtrail:Delete* and cloudtrail:Stop* actions
View answer
Correct Answer: C
Question #29
A company is developing an ecommerce application. The application uses Amazon EC2 instances and an Amazon RDS MySQL database. For compliance reasons, data must be secured in transit and at rest. The company needs a solution that minimizes operational overhead and minimizes cost.Which solution meets these requirements?
A. Use TLS certificates from AWS Certificate Manager (ACM) with an Application Load Balancer
B. Use TLS certificates from a third-party vendor with an Application Load Balancer
C. Use AWS CloudHSM to generate TLS certificates for the EC2 instances
D. Use Amazon CloudFront with AWS WAF
View answer
Correct Answer: A
Question #30
What are the MOST secure ways to protect the AWS account root user of a recently opened AWS account? (Choose two.)
A. Use the AWS account root user access keys instead of the AWS Management Console
B. Enable multi-factor authentication for the AWS IAM users with the AdministratorAccess managed policy attached to them
C. Use AWS KMS to encrypt all AWS account root user and AWS IAM access keys and set automatic rotation to 30 days
D. Do not create access keys for the AWS account root user; instead, create AWS IAM users
E. Enable multi-factor authentication for the AWS account root user
View answer
Correct Answer: DE
Question #31
A company's security engineer has been tasked with restricting a contractor's IAM account access to the company’s Amazon EC2 console without providing access to any other AWS services. The contractor's IAM account must not be able to gain access to any other AWS service, even if the IAM account is assigned additional permissions based on IAM group membership.What should the security engineer do to meet these requirements?
A. reate an inline IAM user policy that allows for Amazon EC2 access for the contractor's IAM user
B. reate an IAM permissions boundary policy that allows Amazon EC2 access
C. reate an IAM group with an attached policy that allows for Amazon EC2 access
D. reate a IAM role that allows for EC2 and explicitly denies all other services
View answer
Correct Answer: B
Question #32
[Logging and Monitoring]A company uses SAML federation to grant users access to AWS accounts. A company workload that is in an isolated AWS account runs on immutable infrastructure with no human access to Amazon EC2. The company requires a specialized user known as a break glass user to have access to the workload AWS account and instances in the case of SAML errors. A recent audit discovered that the company did not create the break glass user for the AWS account that contains the workload.The company must create the break glass user. The company must log any activities of the break glass user and send the logs to a security team.Which combination of solutions will meet these requirements?(Select TWO.)
A. Create a local individual break glass IAM user for the security team
B. Create a break glass EC2 key pair for the AWS account
C. Create a break glass IAM role for the account
D. Create a local individual break glass IAM user on the operating system level of each workload instance
E. Configure AWS Systems Manager Session Manager for Amazon EC2
View answer
Correct Answer: AE
Question #33
A company is migrating one of its legacy systems from an on-premises data center to AWS. The application server will run on AWS, but the database must remain in the on-premises data center for compliance reasons. The database is sensitive to network latency. Additionally, the data that travels between the on-premises data center and AWS must have IPsec encryption.Which combination of AWS solutions will meet these requirements? (Choose two.)
A. AWS Site-to-Site VPN
B. AWS Direct Connect
C. AWS VPN CloudHub
D. VPC peering
E. NAT gateway
View answer
Correct Answer: AB
Question #34
[Incident Response]Example.com is hosted on Amazon EC2 instances behind an Application Load Balancer (ALB). Third-party host intrusion detection system (HIDS) agents that capture the traffic of the EC2 instance are running on each host. The company must ensure they are using privacy enhancing technologies for users, without losing the assurance the third-party solution offers.What is the MOST secure way to meet these requirements?
A. Enable TLS pass through on the ALB, and handle decryption at the server using Elliptic Curve Diffie-Hellman (ECDHE) cipher suites
B. Create a listener on the ALB that uses encrypted connections with Elliptic Curve Diffie-Hellman (ECDHE) cipher suites, and pass the traffic in the clear to the server
C. Create a listener on the ALB that uses encrypted connections with Elliptic Curve Diffie-Hellman (ECDHE) cipher suites, and use encrypted connections to the servers that do not enable Perfect Forward Secrecy (PFS)
D. Create a listener on the ALB that does not enable Perfect Forward Secrecy (PFS) cipher suites, and use encrypted connections to the servers using Elliptic Curve Diffie-Hellman (ECDHE) cipher suites
View answer
Correct Answer: D
Question #35
A company has a single AWS account and uses an Amazon EC2 instance to test application code. The company recently discovered that the instance was compromised. The instance was serving up malware. The analysis of the instance showed that the instance was compromised 35 days ago.A security engineer must implement a continuous monitoring solution that automatically notifies the company's security team about compromised instances through an email distribution list for high severity findings. The security engineer must implement the solution as soon as possible.Which combination of steps should the security engineer take to meet these requirements? (Choose three.)
A. Enable AWS Security Hub in the AWS account
B. Enable Amazon GuardDuty in the AWS account
C. Create an Amazon Simple Notification Service (Amazon SNS) topic
D. Create an Amazon Simple Queue Service (Amazon SQS) queue
E. Create an Amazon EventBridge rule for GuardDuty findings of high severity
F. Create an Amazon EventBridge rule for Security Hub findings of high severity
View answer
Correct Answer: BCE
Question #36
Your company has a set of EC2 Instances defined in IAM. These Ec2 Instances have strict security groups attached to them. You need to ensure that changes to the Security groups are noted and acted on accordingly. How can you achieve this? Please select
A. Use Cloudwatch logs to monitor the activity on the Security Groups
B. Use Cloudwatch metrics to monitor the activity on the Security Groups
C. Use IAM inspector to monitor the activity on the Security Groups
D. Use Cloudwatch events to be triggered for any changes to the Security Groups
View answer
Correct Answer: D
Question #37
A company's AWS CloudTrail logs are all centrally stored in an Amazon S3 bucket. The security team controls the company's AWS account. The security team must prevent unauthorized access and tampering of the CloudTrail logs.Which combination of steps should the security team take? (Choose three.)
A. Configure server-side encryption with AWS KMS managed encryption keys (SSE-KMS)
B. Compress log files with secure gzip
C. Create an Amazon EventBridge rule to notify the security team of any modifications on CloudTrail log files
D. Implement least privilege access to the S3 bucket by configuring a bucket policy
E. Configure CloudTrail log file integrity validation
F. Configure Access Analyzer for S3
View answer
Correct Answer: ADE
Question #38
A company has an AWS account that hosts a production application. The company receives an email notification that Amazon GuardDuty has detected an Impact:IAMUser/AnomalousBehavior finding in the account. A security engineer needs to run the investigation playbook for this security incident and must collect and analyze the information without affecting the application.Which solution will meet these requirements MOST quickly?
A. Log in to the AWS account by using read-only credentials
B. Log in to the AWS account by using read-only credentials
C. Log in to the AWS account by using administrator credentials
D. Log in to the AWS account by using read-only credentials
View answer
Correct Answer: B
Question #39
A company has several workloads running on AWS. Employees are required to authenticate using on-premises ADFS and SSO to access the AWS Management Console. Developers migrated an existing legacy web application to an Amazon EC2 instance. Employees need to access this application from anywhere on the internet, but currently, there is no authentication system built into the application.How should the security engineer implement employee-only access to this system without changing the application?
A. Place the application behind an Application Load Balancer (ALB)
B. Implement AWS IAM Identity Center (AWS Single Sign-On) in the management account and link it to ADFS as an identity provider
C. Define an Amazon Cognito identity pool, then install the connector on the Active Directory server
D. Create an AWS Lambda custom authorizer as the authenticator for a reverse proxy on Amazon EC2
View answer
Correct Answer: A
Question #40
A company has a legacy application that runs on a single Amazon EC2 instance. A security audit shows that the application has been using an IAM access key within its code to access an Amazon S3 bucket that is named DOC-EXAMPLE-BUCKET1 in the same AWS account. This access key pair has the s3:GetObject permission to all objects in only this S3 bucket. The company takes the application offline because the application is not compliant with the company’s security policies for accessing other AWS resources from Amazon EC2.A security engineer validates that AWS CloudTrail is turned on in all AWS Regions. CloudTrail is sending logs to an S3 bucket that is named DOC-EXAMPLE-BUCKET2. This S3 bucket is in the same AWS account as DOC-EXAMPLE-BUCKET1. However, CloudTrail has not been configured to send logs to Amazon CloudWatch Logs.The company wants to know if any objects in DOC-EXAMPLE-BUCKET1 were accessed with the IAM access key in the past 60 days. If any objects were accessed, the company wants to know if any of the objects that are text files (.txt extension) contained personally identifiable information (PII).Which combination of steps should the security engineer take to gather this information? (Choose two.)
A. Use Amazon CloudWatch Logs Insights to identify any objects in DOC-EXAMPLE-BUCKET1 that contain PII and that were available to the access key
B. Use Amazon OpenSearch Service to query the CloudTrail logs in DOC-EXAMPLE-BUCKET2 for API calls that used the access key to access an object that contained PII
C. Use Amazon Athena to query the CloudTrail logs in DOC-EXAMPLE-BUCKET2 for any API calls that used the access key to access an object that contained PII
D. Use AWS Identity and Access Management Access Analyzer to identify any API calls that used the access key to access objects that contained PII in DOC-EXAMPLE-BUCKET1
E. Configure Amazon Macie to identify any objects in DOC-EXAMPLE-BUCKET1 that contain PII and that were available to the access key
View answer
Correct Answer: CE
Question #41
A company uses identity federation to authenticate users into an identity account (987654321987) where the users assume an IAM role named IdentityRole. The users then assume an IAM role named JobFunctionRole in the target AWS account (123456789123) to perform their job functions.A user is unable to assume the IAM role in the target account. The policy attached to the role in the identity account is:What should be done to enable the user to assume the appropriate role in the target account?
A. pdate the IAM policy attached to the role in the identity account to be:
B. pdate the trust policy on the role in the target account to be:
C. pdate the trust policy on the role in the identity account to be:
D. pdate the IAM policy attached to the role in the target account to be:
View answer
Correct Answer: B
Question #42
A team is using AWS Secrets Manager to store an application database password. Only a limited number of IAM principals within the account can have access to the secret. The principals who require access to the secret change frequently. A security engineer must create a solution that maximizes flexibility and scalability.Which solution will meet these requirements?
A. Use a role-based approach by creating an IAM role with an inline permissions policy that allows access to the secret
B. Deploy a VPC endpoint for Secrets Manager
C. Use a tag-based approach by attaching a resource policy to the secret
D. Use a deny-by-default approach by using IAM policies to deny access to the secret explicitly
View answer
Correct Answer: C
Question #43
A company's public Application Load Balancer (ALB) recently experienced a DDoS attack. To mitigate this issue, the company deployed Amazon CloudFront in front of the ALB so that users would not directly access the Amazon EC2 instances behind the ALB.The company discovers that some traffic is still coming directly into the ALB and is still being handled by the EC2 instances.Which combination of steps should the company take to ensure that the EC2 instances will receive traffic only from CloudFront? (Choose two.)
A. Configure CloudFront to add a cache key policy to allow a custom HTTP header that CloudFront sends to the ALB
B. Configure CloudFront to add a custom HTTP header to requests that CloudFront sends to the AL
C. Configure the ALB to forward only requests that contain the custom HTTP header
D. Configure the ALB and CloudFront to use the X-Forwarded-For header to check client IP addresses
E. Configure the ALB and CloudFront to use the same X
View answer
Correct Answer: BC
Question #44
A company has several workloads running on AWS. Employees are required to authenticate using on-premises ADFS and SSO to access the AWS Management Console. Developers migrated an existing legacy web application to an Amazon EC2 instance. Employees need to access this application from anywhere on the internet, but currently, there is no authentication system built into the application.How should the security engineer implement employee-only access to this system without changing the application?
A. Place the application behind an Application Load Balancer (ALB)
B. Implement AWS IAM Identity Center (AWS Single Sign-On) in the management account and link it to ADFS as an identity provider
C. Define an Amazon Cognito identity pool, then install the connector on the Active Directory server
D. Create an AWS Lambda custom authorizer as the authenticator for a reverse proxy on Amazon EC2
View answer
Correct Answer: A
Question #45
There is a requirement for a company to transfer large amounts of data between IAM and an on - premise location. There is an additional requirement for low latency and high consistency traffic to IAM. Given these requirements how would you design a hybrid architecture? Choose the correct answer from the options below Please select
A. Provision a Direct Connect connection to an IAM region using a Direct Connect partner
B. Create a VPN tunnel for private connectivity, which increases network consistency and reduceslatency
C. Create an iPSec tunnel for private connectivity, which increases network consistency and reduces latency
D. Create a VPC peering connection between IAM and the Customer gateway
View answer
Correct Answer: A
Question #46
A company's AWS CloudTrail logs are all centrally stored in an Amazon S3 bucket. The security team controls the company's AWS account. The security team must prevent unauthorized access and tampering of the CloudTrail logs.Which combination of steps should the security team take? (Choose three.)
A. Configure server-side encryption with AWS KMS managed encryption keys (SSE-KMS)
B. Compress log files with secure gzip
C. Create an Amazon EventBridge rule to notify the security team of any modifications on CloudTrail log files
D. Implement least privilege access to the S3 bucket by configuring a bucket policy
E. Configure CloudTrail log file integrity validation
F. Configure Access Analyzer for S3
View answer
Correct Answer: ADE
Question #47
A company's AWS CloudTrail logs are all centrally stored in an Amazon S3 bucket. The security team controls the company's AWS account. The security team must prevent unauthorized access and tampering of the CloudTrail logs.Which combination of steps should the security team take? (Choose three.)
A. Configure server-side encryption with AWS KMS managed encryption keys (SSE-KMS)
B. Compress log files with secure gzip
C. Create an Amazon EventBridge rule to notify the security team of any modifications on CloudTrail log files
D. Implement least privilege access to the S3 bucket by configuring a bucket policy
E. Configure CloudTrail log file integrity validation
F. Configure Access Analyzer for S3
View answer
Correct Answer: ADE
Question #48
A company has enabled Amazon GuardDuty in all AWS Regions as part of its security monitoring strategy. In one of its VPCs, the company hosts an Amazon EC2 instance that works as an FTP server. A high number of clients from multiple locations contact the FTP server. GuardDuty identifies this activity as a brute force attack because of the high number of connections that happen every hour.The company has flagged the finding as a false positive, but GuardDuty continues to raise the issue. A security engineer must improve the signal-to-noise ratio without compromising the company's visibility of potential anomalous behavior.Which solution will meet these requirements?
A. isable the FTP rule in GuardDuty in the Region where the FTP server is deployed
B. dd the FTP server to a trusted IP list
C. reate a suppression rule in GuardDuty to filter findings by automatically archiving new findings that match the specified criteria
D. reate an AWS Lambda function that has the appropriate permissions to delete the finding whenever a new occurrence is reported
View answer
Correct Answer: C
Question #49
A company has hundreds of AWS accounts in an organization in AWS Organizations. The company operates out of a single AWS Region. The company has a dedicated security tooling AWS account in the organization. The security tooling account is configured as the organization's delegated administrator for Amazon GuardDuty and AWS Security Hub. The company has configured the environment to automatically enable GuardDuty and Security Hub for existing AWS accounts and new AWS accounts.The company is performing control tests on specific GuardDuty findings to make sure that the company's security team can detect and respond to security events. The security team launched an Amazon EC2 instance and attempted to run DNS requests against a test domain, example.com, to generate a DNS finding. However, the GuardDuty finding was never created in the Security Hub delegated administrator account.Why was the finding was not created in the Security Hub delegated administrator account?
A. PC flow logs were not turned on for the VPC where the EC2 instance was launched
B. he VPC where the EC2 instance was launched had the DHCP option configured for a custom OpenDNS resolver
C. he GuardDuty integration with Security Hub was never activated in the AWS account where the finding was generated
D. ross-Region aggregation in Security Hub was not configured
View answer
Correct Answer: B
Question #50
[Infrastructure Security] A company is using AWS Organizations to manage multiple accounts. The company needs to allow an IAM user to use a role to access resources that are in another organization's AWS account. Which combination of steps must the company perform to meet this requirement? (Select TWO.) To allow cross-account access to resources using IAM roles, the following steps are required: Create a role in the AWS account that contains the resources (the trusting account) and specify the AWS account that contains the IAM user (the trusted account) as a trusted entity in the role's trust policy. This allows users from the trusted account to assume the role and access resources in the trusting account. Ensure that the IAM user has permission to assume the role in their own AWS account. This can be done by creating an identity policy that allows the sts:AssumeRole action and attaching it to the IAM user or their group. Ensure that there are no service control policies (SCPs) in the organization that owns the resources that deny or restrict access to the sts:AssumeRole action or the role itself. SCPs are applied to all accounts in an organization and can override any permissions granted by IAM policies. Verified References: https://repost.aws/knowledge-center/cross-account-access-iam https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_accounts_access.html https://docs.aws.amazon.com/IAM/latest/UserGuide/tutorial_cross-account-with-roles.html
A. Create an identity policy that allows the sts: AssumeRole action in the AWS account that contains the resources
B. Ensure that the sts: AssumeRole action is allowed by the SCPs of the organization that owns the resources that the IAM user needs to access
C. Create a role in the AWS account that contains the resources
D. Establish a trust relationship between the IAM user and the AWS account that contains the resources
E. Create a role in the IAM user's AWS account
View answer
Correct Answer: BC

View The Updated AWS Exam Questions

SPOTO Provides 100% Real AWS Exam Questions for You to Pass Your AWS Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us