Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65pass65

Free AWS Certified Security Specialty (SCS-C03) Practice Questions

Exams4sure Dumps

Exam style questions across every AWS-Security-Specialty domain

Last Update 3 days ago
Total Questions : 179

Start with our free AWS-Security-Specialty practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real AWS Certified Security Specialty exam. Each AWS-Security-Specialty exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your Amazon weak domains, see where you're losing marks, and build a focused study plan in minutes.

AWS-Security-Specialty PDF

AWS-Security-Specialty PDF (Printable)
$52.5
$150

AWS-Security-Specialty Testing Engine

AWS-Security-Specialty PDF (Printable)
$70
$200

AWS-Security-Specialty PDF + Testing Engine

AWS-Security-Specialty PDF (Printable)
$104.65
$299
Question # 51

A company ' s security team wants to receive near-real-time email notifications about AWS abuse reports related to DoS attacks. An Amazon SNS topic already exists and is subscribed to by the security team.

What should the security engineer do next?

Options:

A.  

Poll Trusted Advisor for abuse notifications by using a Lambda function.

B.  

Create an Amazon EventBridge rule that matches AWS Health events for AWS_ABUSE_DOS_REPORT and publishes to SNS.

C.  

Poll the AWS Support API for abuse cases by using a Lambda function.

D.  

Detect abuse reports by using CloudTrail logs and CloudWatch alarms.

Discussion 0
Question # 52

A company uploads data files as objects into an Amazon S3 bucket. A vendor downloads the objects to perform data processing.

A security engineer must implement a solution that prevents objects from residing in the S3 bucket for longer than 72 hours.

Options:

A.  

Configure S3 Versioning to expire object versions that have been in the bucket for 72 hours.

B.  

Configure an S3 Lifecycle configuration rule on the bucket to expire objects after 72 hours.

C.  

Use the S3 Intelligent-Tiering storage class and configure expiration after 72 hours.

D.  

Generate presigned URLs that expire after 72 hours.

Discussion 0
Question # 53

A company is planning to deploy a new log analysis environment. The company needs to analyze logs from multiple AWS services in near real time. The solution must provide the ability to search the logs and must send alerts to an existing Amazon Simple Notification Service (Amazon SNS) topic when specific logs match detection rules.

Which solution will meet these requirements?

Options:

A.  

Analyze the logs by using Amazon OpenSearch Service. Search the logs from the OpenSearch API. Use OpenSearch Service Security Analytics to match logs with detection rules and to send alerts to the SNS topic.

B.  

Analyze the logs by using AWS Security Hub. Search the logs from the Findings page in Security Hub. Create custom actions to match logs with detection rules and to send alerts to the SNS topic.

C.  

Analyze the logs by using Amazon CloudWatch Logs. Use a subscription filter to match logs with detection rules and to send alerts to the SNS topic. Search the logs manually by using CloudWatch Logs Insights.

D.  

Analyze the logs by using Amazon QuickSight. Search the logs by listing the query results in a dashboard. Run queries to match logs with detection rules and to send alerts to the SNS topic.

Discussion 0

Free Exams Sample Questions