Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65pass65

SCS-C03 AWS Certified Security – Specialty is now Stable and With Pass Result | Test Your Knowledge for Free

Exams4sure Dumps

SCS-C03 Practice Questions

AWS Certified Security – Specialty

Last Update 4 days ago
Total Questions : 231

Dive into our fully updated and stable SCS-C03 practice test platform, featuring all the latest AWS Certified Specialty exam questions added this week. Our preparation tool is more than just a Amazon Web Services study aid; it's a strategic advantage.

Our free AWS Certified Specialty practice questions crafted to reflect the domains and difficulty of the actual exam. The detailed rationales explain the 'why' behind each answer, reinforcing key concepts about SCS-C03. Use this test to pinpoint which areas you need to focus your study on.

SCS-C03 PDF

SCS-C03 PDF (Printable)
$54.25
$154.99

SCS-C03 Testing Engine

SCS-C03 PDF (Printable)
$59.5
$169.99

SCS-C03 PDF + Testing Engine

SCS-C03 PDF (Printable)
$74.55
$212.99
Question # 31

A company requires a specific software application to be installed on all new and existing Amazon EC2 instances across an AWS Organization. SSM Agent is installed and active.

How can the company continuously monitor deployment status of the software application?

Options:

A.  

Use AWS Config organization-wide with the ec2-managedinstance-applications-required managed rule and specify the application name.

B.  

Use approved AMIs rule organization-wide.

C.  

Use Distributor package and review output.

D.  

Use Systems Manager Application Manager inventory filtering.

Discussion 0
Question # 32

A company is undergoing a security audit. The company issues IAM user credentials for an auditor. Because of third-party integration requirements, the auditor is unable to assume an IAM role. The auditor attempts to log in to AWS for the first time to reset the account password and to configure multi-factor authentication (MFA). However, the auditor receives an “Access Denied” error during the attempt to reset the password.

The auditor’s account has the following IAM permissions:

securityhub:Get*

securityhub:List*

securityhub:BatchGet*

securityhub:Describe*

iam:ChangePassword on arn:aws:iam::*:user/${aws:username}

Which action will resolve this error?

Options:

A.  

The auditor needs to configure MFA before resetting the password.

B.  

The auditor must create a more complex password that requires additional characters or symbols.

C.  

Add iam:GetAccountPasswordPolicy with Resource: " * " to the auditor’s user account policy.

D.  

Add iam:ChangePassword with Resource: " * " to the auditor’s user account policy.

Discussion 0
Question # 33

A company has a web application that reads from and writes to an Amazon S3 bucket. The company needs to use AWS credentials to authenticate all S3 API calls to the S3 bucket.

Which solution will provide the application with AWS credentials to make S3 API calls?

Options:

A.  

Integrate with Cognito identity pools and use GetId to obtain AWS credentials.

B.  

Integrate with Cognito identity pools and use AssumeRoleWithWebIdentity to obtain AWS credentials.

C.  

Integrate with Cognito user pools and use the ID token to obtain AWS credentials.

D.  

Integrate with Cognito user pools and use the access token to obtain AWS credentials.

Discussion 0
Question # 34

A company is using an organization in AWS Organizations that contains 100 accounts. The company has configured trusted access for Amazon GuardDuty to AWS Organizations within the management account. The company has designated a member account to be the GuardDuty administrator for the organization.

GuardDuty is working properly and reports findings for the organization in the GuardDuty console. The company wants a SecOps team to receive real-time email alerts from any GuardDuty finding within the organization that is high severity according to GuardDuty severity levels.

Which solution will meet these requirements?

Options:

A.  

In the management account, create a rule in Amazon EventBridge that will react to a GuardDuty finding that has a high severity level. Configure the rule to notify an Amazon SNS topic. Subscribe the SecOps team’s email addresses to the SNS topic.

B.  

Configure trusted access for AWS Config within the organization. Create a rule in AWS Config to monitor for any non-archived findings in GuardDuty. Create a rule in Amazon EventBridge that will react if AWS Config detects a compliance change for the AWS Config rule. Configure the EventBridge rule to target an Amazon SNS topic. Subscribe the SecOps team’s email addresses to the SNS topic.

C.  

In the GuardDuty delegated administrator account, configure a rule in Amazon EventBridge that will react to a GuardDuty finding that has a high severity level. Configure the rule to notify an Amazon SNS topic. Subscribe the SecOps team’s email addresses to the SNS topic.

D.  

Configure AWS CloudTrail for the organization in the management account. Create a rule in Amazon EventBridge that will run on a ListFindings API call. Configure the rule to notify an Amazon SNS topic. Subscribe the SecOps team’s email addresses to the SNS topic.

Discussion 0
Question # 35

A company’s platform has grown rapidly over the past 6 months. The company’s platform architecture evolved quickly to accommodate the growth. The company’s development team has been deploying features quickly by using different AWS services. The development team has not performed formal architecture reviews.

The company needs to evaluate its security posture against AWS security best practices.

Which solution will meet these requirements?

Options:

A.  

Create a new workload in the AWS Well-Architected Tool. Work with the development team to answer security questions based on the team’s current state. Use the save milestone feature to track improvements against identified high-risk items.

B.  

Use the cost recommendations in AWS Cost Explorer. Analyze the cost implications of security misconfigurations. Prioritize architectural changes based on potential cost savings as a result of implementing AWS security best practices.

C.  

Enable AWS Security Hub CSPM. Create a Security Hub CSPM automation rule to map existing services to approved architecture patterns. Use the data to identify non-compliance against AWS best practices and generate a compliance report.

D.  

Enable Amazon Detective. Create a Detective investigation for AWS security best practices. Use a behavior graph to visualize the data. Analyze the entities to identify architectural components that do not follow AWS security best practices.

Discussion 0
Question # 36

A company in France uses Amazon Cognito with the Cognito Hosted UI as an identity broker for sign-in and sign-up processes. The company is marketing an application and expects that all the application ' s users will come from France. When the company launches the application, the company ' s security team observes fraudulent sign-ups for the application. Most of the fraudulent registrations are from users outside of France. The security team needs a solution to perform custom validation at sign-up. Based on the results of the validation, the solution must accept or deny the registration request.

Which combination of steps will meet these requirements? (Select TWO.)

Options:

A.  

Create a pre sign-up AWS Lambda trigger. Associate the Amazon Cognito function with the Amazon Cognito user pool.

B.  

Use a geographic match rule statement to configure an AWS WAF web ACL. Associate the web ACL with the Amazon Cognito user pool.

C.  

Configure an app client for the application ' s Amazon Cognito user pool. Use the app client ID to validate the requests in the hosted UI.

D.  

Update the application ' s Amazon Cognito user pool to configure a geographic restriction setting.

E.  

Use Amazon Cognito to configure a social identity provider (IdP) to validate the requests on the hosted UI.

Discussion 0
Question # 37

A security engineer has designed a VPC to segment private traffic from public traffic. The VPC includes two Availability Zones. The security engineer has provisioned each Availability Zone with one private subnet and one public subnet. The security engineer has created three route tables for use with the environment. One route table is for the public subnets, and two route tables are for the private subnets (one route table for the private subnet in each Availability Zone).

The security engineer discovers that all four subnets are attempting to route traffic out through the internet gateway that is attached to the VP

C.  

Which combination of steps should the security engineer take to remediate this scenario? (Select TWO.)

Options:

A.  

Verify that a NAT gateway has been provisioned in the public subnet in each Availability Zone.

B.  

Verify that a NAT gateway has been provisioned in the private subnet in each Availability Zone.

C.  

Modify the route tables that are associated with each of the public subnets. Create a new route for local destinations to the VPC CIDR range.

D.  

Modify the route tables that are associated with each of the private subnets. Create a new route for the destination 0.0.0.0/0. Specify the NAT gateway in the public subnet of the same Availability Zone as the target of the route.

E.  

Modify the route tables that are associated with each of the private subnets. Create a new route for the destination 0.0.0.0/0. Specify the internet gateway as the target of the route.

Discussion 0
Question # 38

A company uses an organization in AWS Organizations to manage multiple AWS accounts. The company wants to centrally give users the ability to access Amazon Q Developer.

Which solution will meet this requirement?

Options:

A.  

Enable AWS IAM Identity Center and set up Amazon Q Developer as an AWS managed application.

B.  

Enable Amazon Cognito and create a new identity pool for Amazon Q Developer.

C.  

Enable Amazon Cognito and set up Amazon Q Developer as an AWS managed application.

D.  

Enable AWS IAM Identity Center and create a new identity pool for Amazon Q Developer.

Discussion 0
Question # 39

A company runs ECS services behind an internet-facing ALB that is the origin for CloudFront. An AWS WAF web ACL is associated with CloudFront, but clients can bypass it by accessing the ALB directly.

Which solution will prevent direct access to the ALB?

Options:

A.  

Use AWS PrivateLink with the AL

B.  

B.  

Replace the ALB with an internal AL

B.  

C.  

Restrict ALB listener rules to CloudFront IP ranges.

D.  

Require a custom header from CloudFront and validate it at the AL

B.  

Discussion 0
Question # 40

A company ' s security engineer receives an abuse notification from AWS indicating that malware is being hosted from the company’s AWS account. The security engineer discovers that an IAM user created a new Amazon S3 bucket without authorization.

Which combination of steps should the security engineer take to MINIMIZE the consequences of this compromise? (Select THRE

E.  

)

Options:

A.  

Encrypt all AWS CloudTrail logs.

B.  

Turn on Amazon GuardDuty.

C.  

Change the password for all IAM users.

D.  

Rotate or delete all AWS access keys.

E.  

Take snapshots of all Amazon Elastic Block Store (Amazon EBS) volumes.

F.  

Delete any resources that are unrecognized or unauthorized.

Discussion 0
Get SCS-C03 dumps and pass your exam in 24 hours!

Free Exams Sample Questions