Amazon certification preparation
SCS-C03 Practice Questions
Practice exam-style questions, check your answers, and review explanations and source references where they are available.
- Exam
- SCS-C03
- Provider
- Amazon
- Full set
- 227 questions
- Last Update Check
A security engineer has designed a VPC to segment private traffic from public traffic. The VPC
includes two Availability Zones. Each Availability Zone contains one public subnet and one private
subnet. Three route tables exist: one for the public subnets and one for each private subnet.
The security engineer discovers that all four subnets are routing traffic through the internet gateway
that is attached to the VPC.
Which combination of steps should the security engineer take to remediate this scenario? (Select
TWO.)
Question 1 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
A company uses AWS Organizations to manage an organization that consists of three workload OUs:
Production, Development, and Testing. The company uses AWS CloudFormation templates to define
and deploy workload infrastructure in AWS accounts that are associated with the OUs. Different SCPs
are attached to each workload OU.
The company successfully deployed a CloudFormation stack update to workloads in the
Development OU and the Testing OU. When the company uses the same CloudFormation template
to deploy the stack update in an account in the Production OU, the update fails. The error message
reports insufficient IAM permissions.
What is the FIRST step that a security engineer should take to troubleshoot this issue?
Question 2 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
A company uses AWS IAM Identity Center with SAML 2.0 federation. The company decides to change
its federation source from one identity provider (IdP) to another. The underlying directory for both
IdPs is Active Directory.
Which solution will meet this requirement?
Question 3 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
A company runs a public web application on Amazon EKS behind Amazon CloudFront and an
Application Load Balancer (ALB). A security engineer must send a notification to an existing Amazon
SNS topic when the application receives 10,000 requests from the same end-user IP address within
any 5-minute period.
Which solution will meet these requirements?
Question 4 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
A consultant agency needs to perform a security audit for a company's production AWS account.
Several consultants need access to the account. The consultant agency already has its own AWS
account. The company requires multi-factor authentication (MFA) for all access to its production
account. The company also forbids the use of long-term credentials.
Which solution will provide the consultant agency with access that meets these requirements?
Question 5 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
A company’s data scientists use Amazon SageMaker with datasets stored in Amazon S3. Data older
than 45 days must be removed according to policy.
Which action should enforce this policy?
Question 6 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
A security administrator is setting up a new AWS account. The security administrator wants to secure
the data that a company stores in an Amazon S3 bucket. The security administrator also wants to
reduce the chance of unintended data exposure and the potential for misconfiguration of objects
that are in the S3 bucket.
Which solution will meet these requirements with the LEAST operational overhead?
Question 7 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
A company uses AWS to run a web application that manages ticket sales in several countries. The
company recently migrated the application to an architecture that includes Amazon API Gateway,
AWS Lambda, and Amazon Aurora Serverless. The company needs the application to comply with
Payment Card Industry Data Security Standard (PCI DSS) v4.0. A security engineer must generate a
report that shows the effectiveness of the PCI DSS v4.0 controls that apply to the application. The
company's compliance team must be able to add manual evidence to the report.
Which solution will meet these requirements?
Question 8 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
A company must capture AWS CloudTrail data events and must retain the logs for 7 years. The logs
must be immutable and must be available to be searched by complex queries. The company also
needs to visualize the data from the logs.
Which solution will meet these requirements MOST cost-effectively?
Question 9 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
A company is running its application on AWS. The company has a multi-environment setup, and each
environment is isolated in a separate AWS account. The company has an organization in AWS
Organizations to manage the accounts. There is a single dedicated security account for the
organization. The company must create an inventory of all sensitive data that is stored in Amazon S3
buckets across the organization's accounts. The findings must be visible from a single location.
Which solution will meet these requirements?
Question 10 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 10
Source context
How this practice set is maintained
Maintained by the CertMage content team, this page loads questions from the exam dataset connected to its preparation resource. When an answer includes a supporting reference, it is shown with that answer so you can review the underlying vendor documentation.
Certification objectives, interfaces, and vendor services can change. Verify important details against the provider's current exam guide and documentation before your exam.
