Practice questions · Cybersecurity

AWS Certified Security - Specialty (SCS-C03): Practice Questions

expert 45 questions

Original, syllabus-based practice questions for AWS Certified Security - Specialty (SCS-C03). Each answer is explained, including why the other options are wrong. Filter by domain or difficulty. These are concept and scenario checks written to test understanding - not reproductions of live exam content.

By The Exam Atlas Editorial Team · Verified 2026-08-05 · ~56 min

  1. Identity and Access Management easy

    An IAM user's identity-based policy allows s3:GetObject on a bucket, but the bucket policy contains an explicit deny for that user. What is the result?

  2. Identity and Access Management medium

    What does a service control policy (SCP) in AWS Organizations actually do?

  3. Identity and Access Management medium

    A security team wants to cap the permissions a specific IAM role can ever have, without changing AWS Organizations settings. Which feature fits?

  4. Identity and Access Management medium

    A third-party vendor needs to assume a role in your account. Which element protects against the confused deputy problem in this cross-account setup?

  5. Identity and Access Management easy

    An application on an EC2 instance needs to read from an S3 bucket. What is the recommended way to give it access?

  6. Identity and Access Management medium

    Your organization wants an S3 bucket to be readable only by principals from accounts inside its AWS Organization. Which condition key achieves this cleanly?

  7. Identity and Access Management hard

    An administrator's identity-based policy allows ec2:TerminateInstances, but the SCP on the account's OU does not include that action in any Allow statement. What happens when they try?

  8. Identity and Access Management easy

    A company with many AWS accounts wants employees to sign in once with short-lived credentials to access all of them. Which service is built for this?

  9. Identity and Access Management hard

    A company wants engineers to log in to AWS with their existing corporate identity provider and stop creating IAM users entirely. What is the standard pattern?

  10. Infrastructure Security easy

    Which statement correctly contrasts security groups and network ACLs?

  11. Infrastructure Security medium

    You must block traffic from one specific IPv4 address to every instance in a subnet. Which control does this directly?

  12. Infrastructure Security medium

    A team wants interactive shell access to EC2 instances with no inbound ports open, no bastion host, and full session auditing. Which approach delivers this?

  13. Infrastructure Security medium

    Which measure prevents a server-side request forgery in a web app from harvesting the EC2 instance's role credentials via the metadata service?

  14. Infrastructure Security medium

    Private-subnet workloads must reach S3 without their traffic leaving the AWS network, and access must be restricted to specific buckets. What fits?

  15. Infrastructure Security hard

    A security team needs centralized egress filtering for many VPCs, including blocking outbound traffic by domain name and applying intrusion-prevention signatures. Which service matches?

  16. Infrastructure Security easy

    Which layer of traffic does AWS WAF inspect, and for what kind of threats?

  17. Infrastructure Security medium

    What does AWS Shield Advanced add beyond the protection every AWS customer already receives?

  18. Data Protection easy

    In envelope encryption, what is the role of the KMS key?

  19. Data Protection medium

    A compliance team must see exactly which principal used the encryption key for each S3 object access. Which encryption mode supports this?

  20. Data Protection medium

    Which statement about KMS key policies is accurate?

  21. Data Protection hard

    An application must let a service use a specific KMS key temporarily and programmatically, without editing the key policy or IAM policies. Which mechanism is designed for this?

  22. Data Protection medium

    Data encrypted in one Region must be decryptable in a second Region for disaster recovery, without exporting key material. What supports this?

  23. Data Protection hard

    Why might an organization import its own key material into KMS instead of letting KMS generate it?

  24. Data Protection easy

    A team needs database credentials stored encrypted, with automatic rotation handled by the storing service itself. Which choice is the direct fit?

  25. Data Protection medium

    Which service discovers and classifies sensitive data such as personal information stored in S3 buckets?

  26. Detection easy

    Which service continuously analyzes sources like CloudTrail events, VPC Flow Logs and DNS query logs to flag malicious activity in an account?

  27. Detection medium

    A security lead wants findings from multiple AWS services and partner tools in one place, checked against common security standards. Which service does this?

  28. Detection medium

    After a GuardDuty finding, an analyst needs to walk back through weeks of activity to understand the root cause and scope. Which service is purpose-built for that investigation?

  29. Detection medium

    Which service performs automated vulnerability scanning of EC2 instances, container images in ECR, and Lambda functions?

  30. Detection medium

    CloudTrail is enabled with default settings, but object-level reads on a sensitive S3 bucket are not appearing in the logs. Why?

  31. Detection hard

    During an audit you must demonstrate that delivered CloudTrail log files have not been modified or deleted since delivery. Which capability provides this?

  32. Detection hard

    A security team wants findings from AWS and third-party tools normalized into one open schema their SIEM can consume. Which standard is designed for this?

  33. Incident Response medium

    An IAM user's access key has been posted publicly. What should the response team do first?

  34. Incident Response medium

    An EC2 instance is behaving as if compromised. Which immediate action best preserves evidence while containing the threat?

  35. Incident Response hard

    Before performing disk forensics on a compromised instance's EBS volume, what is the recommended handling of the volume data?

  36. Incident Response hard

    The team wants compromised instances quarantined within seconds of specific GuardDuty findings, without waiting for a human. What is the standard pattern?

  37. Incident Response medium

    Suspicious console activity suggests the account's root user credentials may be compromised. Which response is appropriate?

  38. Incident Response easy

    After containing an incident, the team documents what happened and updates runbooks and controls. Which incident-response phase is this?

  39. Security Foundations and Governance easy

    Under the shared responsibility model, who patches the guest operating system on an EC2 instance?

  40. Security Foundations and Governance medium

    How does the customer's security responsibility change when moving a workload from EC2 to a managed service such as Lambda?

  41. Security Foundations and Governance medium

    A company runs dozens of AWS accounts and wants central guardrails, consolidated billing, and grouped account management. Which service is the foundation for this?

  42. Security Foundations and Governance medium

    Which service sets up and governs a secure multi-account environment using an opinionated landing zone with preventive and detective controls?

  43. Security Foundations and Governance easy

    An auditor asks for AWS's own compliance certifications, such as SOC and ISO reports. Where does the customer retrieve these?

  44. Security Foundations and Governance hard

    Security wants every account's CloudTrail activity collected in one place that workload teams cannot alter. What is the standard multi-account pattern?

  45. Security Foundations and Governance medium

    Which practice best expresses defense in depth for a web workload on AWS?

Practice questions FAQ

Are these real SCS-C03 exam questions?
No. These are original study questions written to test understanding. They are not real exam questions, exam dumps, or copied from any provider.
How should I use these practice questions?
Answer each one, read the explanation (including why the wrong options are wrong), and use the per-domain score below to focus your revision on weak areas. Revisit before exam day.
How many questions should I do before the exam?
Enough to score consistently across every domain, alongside full-length practice from official or reputable providers. Understanding why each answer is right matters more than raw volume.
What score means I am ready?
A good signal is consistently scoring around 80% or higher across all domains on questions you have not seen before, and being able to explain why the wrong options are wrong.
Should I use exam dumps?
No. Dumps (real or leaked questions) breach provider policy, can void your certification, and do not build the understanding the exam actually tests.

Sources