AWS SCS-C03 Certification Exam

AWS Certified Security Specialty SCS-C03

The AWS Certified Security - Specialty certification validates expertise in securing workloads on AWS. The exam covers six domains: Detection, Incident Response, Infrastructure Security, Identity and Access Management, Data Protection, and Security Foundations and Governance. It draws on services such as GuardDuty, Security Hub, CloudTrail, Config, Inspector, Macie, Detective, KMS, Secrets Manager, IAM Identity Center, AWS Organizations, WAF, Shield and Network Firewall. Candidates are tested on designing controls, investigating security events and applying guardrails across an organization. This certification suits security engineers with several years of hands-on AWS experience.

Certification Overview

  • Exam name: AWS SCS-C03
  • Vendor: AWS
  • Exam code: SCS-C03
  • Duration: 170 minutes
  • Total questions: 65
  • Passing score: 75%

Who Should Take This Exam?

Security Engineer, Cloud Security Architect, Security Analyst, Compliance Engineer, DevSecOps Engineer, Incident Responder, Infrastructure Security Engineer

Prerequisites

No prior certification is required. AWS recommends three to five years of security experience and at least two years of hands-on AWS security experience.

Topics Covered

  • Detection
  • Incident Response
  • Infrastructure Security
  • Identity and Access Management
  • Data Protection
  • Security Foundations and Governance

Question Types

  • Multiple Choice (Single Answer)
  • Multiple Choice (Multiple Answers)
  • Drag and Drop

AWS SCS-C03 Practice Questions

Our question bank contains 858+ practice questions for this certification. Sample questions from each exam chapter. Expand a question to see the answer choices. With a subscription, you get unlimited practice exams with randomized questions from our full question bank.

Detection

Which TWO of the following are valid severity levels that Amazon GuardDuty uses to classify findings? (Choose two)
  • Informational
  • Medium
  • Urgent
  • Low
  • Critical
Which TWO AWS capabilities can deliver log data directly to an Amazon S3 bucket without requiring an intermediate streaming service? (Choose two)
  • AWS Trusted Advisor checks
  • VPC Flow Logs
  • Amazon Inspector findings
  • Amazon Detective behavior graphs
  • AWS CloudTrail trails
A security team wants Amazon GuardDuty to protect managed container and serverless workloads beyond EC2. Which TWO GuardDuty protection plans specifically address these workload types? (Choose two)
  • Malware Protection for EC2
  • Lambda Protection
  • S3 Protection
  • RDS Protection
  • EKS Protection

Incident Response

Which TWO AWS services generate automated findings that a security team would triage during incident detection? (Choose two)
  • AWS Service Catalog
  • AWS Cost Explorer
  • AWS License Manager
  • Amazon GuardDuty
  • AWS Security Hub
A company is writing its incident response plan. Which TWO elements should the plan document for every incident type? (Choose two)
  • The organization's S3 storage class strategy
  • The Availability Zone layout of the VPC
  • Escalation and communication paths
  • The monthly AWS bill for affected resources
  • Roles and responsibilities of responders
A retail platform's SOC confirms an EC2 instance is compromised and needs to contain it while preserving evidence. Which TWO actions should the team take? (Choose two)
  • Move the instance to an isolation security group
  • Increase the instance's provisioned IOPS
  • Immediately terminate the instance
  • Snapshot the affected EBS volumes before making changes
  • Resize the instance to a larger type

Infrastructure Security

A security team wants continuous, automatic protection against common network and transport layer DDoS attacks for every resource in an AWS account, at no additional cost. Which AWS service provides this by default?
  • AWS Shield Advanced
  • AWS Shield Standard
  • AWS WAF
  • AWS Firewall Manager
By default, which statement about a newly created Amazon VPC security group is accurate regarding inbound traffic?
  • It allows all inbound traffic until rules are added
  • It allows inbound traffic on ports 80 and 443 by default
  • It allows inbound traffic from the VPC CIDR range only
  • It denies all inbound traffic until rules are added
A company wants to block SQL injection and cross-site scripting patterns in HTTP requests before they reach a public web application behind an Application Load Balancer. Which service should the company use?
  • Amazon GuardDuty
  • AWS WAF
  • AWS Shield Advanced
  • AWS Network Firewall

Identity and Access Management

Which AWS service allows a user to sign in once and access multiple AWS accounts without maintaining separate credentials for each account?
  • AWS IAM Identity Center
  • AWS Resource Access Manager
  • AWS Control Tower
  • AWS Organizations
What does AWS recommend doing with the root user immediately after creating a new AWS account?
  • Use the root user for daily administrative tasks
  • Share the root credentials with administrators
  • Create an access key for daily use
  • Enable multi-factor authentication
An IAM MFA device typically supplements a user's password with which additional authentication factor?
  • A static PIN in the user profile
  • A time-based one-time passcode
  • A CAPTCHA challenge
  • A secondary IAM access key

Data Protection

Which TWO of the following are AWS KMS key types? (Choose two.)
  • Customer managed key
  • Security group key
  • AWS managed key
  • VPC endpoint key
  • Route table key
Which TWO Amazon S3 server-side encryption options require the customer to manage the encryption key material? (Choose two.)
  • Client-side encryption with a customer-supplied key
  • SSE-KMS with the AWS managed key
  • Default bucket encryption with no key specified
  • SSE-S3
  • SSE-C
A media company must encrypt data moving between its on-premises data center and its VPC. Which TWO AWS connectivity options provide encryption in transit by default without additional configuration? (Choose two.)
  • A standard AWS Direct Connect connection without MACsec
  • A Transit Gateway attachment with no VPN
  • AWS Site-to-Site VPN
  • A VPN connection over AWS Direct Connect
  • VPC peering

Security Foundations and Governance

Which TWO of the following are valid ways to add an existing standalone AWS account into an AWS Organizations structure? (Choose two)
  • Manually copy the account's resources into a new account inside the organization
  • Send an invitation from the management account and accept it in the member account
  • Have the member account request to join the organization
  • Enable AWS Config in the account
  • Change the account's root email address to match the organization's domain
Which THREE of the following does AWS Config record for a resource whenever its configuration changes? (Choose three)
  • The relationships to other resources
  • The IAM policy simulator result for the resource
  • The timestamp of the change
  • The estimated monthly cost of the resource
  • The CloudFormation template that created the resource
  • The resource's configuration state at that point in time
A retail platform wants every new Amazon S3 bucket created across its accounts to have versioning and default encryption enabled without engineers configuring these settings by hand. Which TWO approaches will meet this requirement? (Choose two)
  • Grant engineers broader IAM permissions so they remember to configure buckets
  • Ask engineers to enable both settings manually after each bucket is created
  • Rely on Amazon S3 Storage Lens to flag non-compliant buckets after the fact
  • Deploy buckets only through a CloudFormation StackSet that sets these properties
  • Publish a Service Catalog product with these properties fixed in the template

Frequently Asked Questions

How many questions are on the exam?

The AWS SCS-C03 exam contains 65 questions.

What is the passing score?

You need 75% to pass.

How long is the exam?

You have 170 minutes to complete the exam.

More AWS Practice Exams

Practice with realistic mock exams to prepare for your AWS certification.