AWS Certified Security - Specialty
Advance your career in cloud cybersecurity with the AWS Certified Security - Specialty Exam Simulator! Tailored for professionals, this tool offers realistic practice exams to mirror the official exam.
Exam domains
The SCS-C02 questions are grouped into 6 domains divided into 22 tasks.
SCS-C02 example questions
One example question per domain from the SCS-C02 question bank, with the correct answer and its explanation. Sign in to the simulator to answer them with all answer options.
A company with multiple AWS accounts is using AWS Organizations to manage these accounts. The security team wants to enhance threat detection and incident response across the organization. They plan to implement a centralized logging solution using Amazon CloudWatch Logs and to create custom metric filters that match the patterns of known incidents. When a threat is detected, they want to automate the response by triggering AWS Lambda functions to remediate the issue. To ensure that threat detection events are managed centrally and that appropriate responses are automatically initiated, the team decides to use Amazon EventBridge. Which of the following steps should the security team take to configure integration and incident response using Amazon EventBridge, without adding unnecessary complexity or permissions?
Show answer
CORRECT ANSWERCreate an EventBridge event bus in the management account, enable EventBridge to receive events across the associated accounts in AWS Organizations, and create rules in the central event bus to trigger Lambda functions in response to specific threat detection patterns.
This approach allows for centralized management of events and automated responses. EventBridge can be set up in a multi-account environment using event buses to pull in events from all the linked accounts in AWS Organizations. This simplifies the operation and ensures that proper actions are taken without direct intervention, streamlining the incident response process.
A company is using AWS for their production environment, where they have multiple EC2 instances, S3 buckets and RDS databases in use. They want to aggregate all logs into a central repository for analysis to improve security through better visibility. To automate the process of normalizing, parsing, and correlating these logs for consistent formatting and simplified analysis, they are planning on leveraging AWS services. Which of the following approaches using AWS Lambda is most appropriate for meeting their need to analyze security logs in a cost-effective and scalable way?
Show answer
CORRECT ANSWERUse AWS Lambda functions triggered by S3 event notifications whenever new logs are delivered to the S3 bucket. The Lambda function can parse, normalize, and then push the transformed logs to Amazon Elasticsearch Service for correlation and analysis.
This method is cost-effective as AWS Lambda runs only when triggered, thereby saving on idle resources. It also scales automatically with the number of events, making it a good fit for variable log data. Moreover, Amazon Elasticsearch Service is well-suited for log analysis and correlation.
A company has deployed its critical application across multiple EC2 instances within a VPC. Recently, there have been reports of atypical network behavior and potential security issues affecting the application's performance. As a security specialist tasked with investigating this issue, you decide to use AWS services to capture and analyze the traffic to and from the affected EC2 instances without impacting their performance or network throughput. Which AWS feature would you use to accomplish this task?
Show answer
CORRECT ANSWEREnable VPC Traffic Mirroring on the affected EC2 instances to capture and analyze their network traffic.
VPC Traffic Mirroring allows for the capture of network traffic from EC2 instances and then sends the traffic to a security appliance or monitoring instance for analysis. It is non-intrusive, as it doesn't affect the performance of the instances whose traffic is being mirrored.
A developer at a company attempted to deploy an application on AWS using an IAM user account. The application needed to write logs to an Amazon S3 bucket; however, the deployment failed with an 'Access Denied' error when trying to write to the bucket. After reviewing the IAM policy attached to the user, the developer discovered that the policy provided the necessary 's3:PutObject' permission for the bucket. Upon further investigation, the developer found no explicit deny in the IAM policy that could have caused the error. Which of the following could be the MOST likely reason for the observed 'Access Denied' error?
Show answer
CORRECT ANSWERThe S3 bucket had a bucket policy that explicitly denied write access to the IAM user.
Even though the IAM user had the correct IAM policy with the 's3:PutObject' permission, S3 bucket policies can override these permissions. If the bucket policy explicitly denies access to the IAM user or the user's group, the user would not be able to write to the bucket despite having the required permissions in their IAM policy.
A financial services company is migrating its relational database workloads to AWS and has chosen Amazon Aurora as their database service because of its high performance and availability. The company's chief information security officer (CISO) has emphasized the importance of securing sensitive customer data at rest to comply with stringent financial industry regulations. The CISO is considering various encryption options to ensure data confidentiality and integrity. Which encryption technique should be used to meet the company's business requirements for encrypting data at rest in Amazon Aurora?
Show answer
CORRECT ANSWEREncrypt the Amazon Aurora database using AWS Key Management Service (AWS KMS) customer managed keys.
This is the correct answer because Amazon Aurora integrates with AWS KMS, allowing you to create and control the encryption keys. Using AWS KMS customer managed keys provides a robust encryption and key management solution that helps meet compliance requirements for data protection by offering an additional layer of control and security.
Your company is utilizing AWS for their critical web application and relies heavily on the AWS network infrastructure for protection against DDoS attacks. You, as a security specialist, have been tasked to ensure that all the AWS accounts under organizational units (OUs) comply with the company's strict security policies, which include DDoS protection for all resources. You need to deploy a solution that automates the application of DDoS protection policies and integrates with AWS Shield Advanced for additional protection. Which AWS service should you implement to meet this requirement while adhering to the security governance domain and ensuring a secure and consistent deployment strategy for cloud resources?
Show answer
CORRECT ANSWERDeploy AWS Firewall Manager with AWS Shield Advanced integration to automatically apply the necessary DDoS protection policies to the accounts in the OUs.
AWS Firewall Manager simplifies your AWS WAF, AWS Shield Advanced, and Amazon VPC security groups administration and maintenance tasks across multiple accounts and resources. With Firewall Manager, you can deploy and manage security policies to protect against DDoS attacks, which integrates with AWS Shield Advanced for enhanced protection.
Exam mode and practice mode
| Exam mode | Practice mode | |
|---|---|---|
| Questions count | 65 | 1 - 65 |
| Time limit | 170 minutes | Optional, 10 - 200 minutes |
| Exam scope | 6 domains with the official questions ratio | Selected domains with the official questions ratio |
| Correct answers | After exam submission | After exam submission or after each answer |
| Question types | Mix of single and multiple correct answers | Single, multiple or both |
| Question hints | Never | Optional |
| Question domain | Revealed after exam submission | Revealed after submission or during the exam |
| Scoring | 15 of 65 questions do not count towards the result | Official AWS method or mathematical mean |
See all simulator features on the AWS Exam Simulator page.
About the SCS-C02 exam
Don't be fooled by the relatively short list of exam scope services. You really have to know them all in great detail. Each service is integrated with others and encompasses countless concepts and technologies you must be well familiar with.
The AWS Certified Security - Specialty certification is known for its high level of difficulty, requiring both broad and deep knowledge of security principles and AWS services. This certification tests your ability to secure applications and data on the AWS platform, demanding a thorough understanding of core security services and best practices for securing AWS environments.
The exam emphasizes an understanding of key AWS security services such as IAM, KMS, CloudTrail, Config, Shield, WAF, Security Hub, and GuardDuty. You need to know how these services work, how to configure them, and how to integrate them into a secure architecture.
You must be able to solve complex, real-world security problems. This includes designing secure infrastructures, implementing robust access controls, managing data protection, and performing incident response. Understanding how to monitor and audit AWS environments for compliance and security issues is also essential, involving tools like CloudWatch, CloudTrail, and AWS Config.
Regulatory compliance is another critical aspect. Candidates must understand various regulatory requirements such as HIPAA, GDPR, and PCI-DSS, and how to implement and maintain compliance within AWS environments. This includes using AWS services to meet these regulatory standards and setting up audit trails and monitoring systems to ensure ongoing compliance.
The certification also requires a solid grasp of AWS's global infrastructure, including regions and availability zones, and how to design applications that ensure high availability, fault tolerance, and disaster recovery.
Furthermore, the exam demands familiarity with advanced security practices, including encryption mechanisms, secure data storage and transfer, and identity and access management. You need to understand how to leverage these practices to protect sensitive data and maintain security across various AWS services.
Technologies and concepts
Infrastructure as code (IaC)
Infrastructure as Code (IaC) involves managing and provisioning computing infrastructure via machine-readable definition files, supported by AWS services like CloudFormation for automating resource setup, CDK for defining infrastructure with programming languages, OpsWorks for configuration management, Elastic Beanstalk for simplified application deployment, and the widely-used Terraform for multi-cloud infrastructure management, enabling consistent, error-free, and streamlined deployment across environments.
Secure remote access
Secure remote access enables safe and encrypted connections to networks and resources from remote locations. AWS enhances secure remote access with services like AWS Client VPN for securely connecting to AWS and on-premises networks, AWS Direct Connect for private network connections, and AWS Identity and Access Management (IAM) for managing user access. These tools ensure secure, reliable, and managed remote access to critical resources.
Certificate management
Certificate management involves overseeing the lifecycle of digital certificates to ensure secure communications and authentication. AWS enhances certificate management with services like AWS Certificate Manager (ACM) for provisioning, managing, and deploying SSL/TLS certificates, ACM Private CA for creating private certificates, and AWS Secrets Manager for securely storing and retrieving certificates. These tools simplify the management process, ensuring robust security and compliance.
Services on the exam
All 26 AWS services that can appear on the SCS-C02 exam.