تدرب على 60 سؤالًا أصليًا في AWS Security Specialty تغطي الكشف والسجلات وأمان البنية والهوية وحماية البيانات والحوكمة.
المستوى: AWS Certified Security - Specialty (SCS-C02)الصعوبة: advanced60 سؤال60 دقيقة
اختر وضع التدريب وأجب عن كل سؤال ثم راجع الشرح. تُحفظ الأخطاء محليًا.
أيام متتالية: 0 أياممحفوظ على هذا الجهاز فقط
التقدم0 / 60
الوقت المتبقي: 00:00
لا توجد أخطاء محفوظة بعد.
لا توجد أسئلة تطابق عوامل التصفية.
سؤال 1
Which AWS service continuously monitors accounts and workloads for threats and generates security findings?
Amazon GuardDuty analyzes CloudTrail, VPC Flow Logs, and DNS logs to detect threats. Route 53 is DNS, CloudFormation is infrastructure as code, and Elasticsearch is search.
سؤال 2
Which data sources does Amazon GuardDuty analyze?
GuardDuty uses CloudTrail, VPC Flow Logs, DNS query logs, and additional sources to find suspicious behavior. It does not rely only on instance storage, S3 events, or billing alarms.
سؤال 3
Which AWS service provides a central place to aggregate security findings from multiple accounts?
Security Hub aggregates, prioritizes, and correlates security findings across accounts. CloudFormation deploys infrastructure, ECS runs containers, and Lambda runs functions.
سؤال 4
Which AWS service provides managed incident response and remediation workflows?
Incident Manager helps you prepare for, respond to, and recover from incidents. S3 stores objects, QuickSight visualizes data, and App Mesh manages service mesh.
سؤال 5
Which AWS service protects applications from distributed denial-of-service attacks?
AWS Shield provides DDoS protection, with Shield Advanced offering enhanced detection and mitigation. Glue is ETL, Athena queries S3, and CodePipeline deploys software.
سؤال 6
Which AWS service provides a managed web application firewall?
AWS WAF filters HTTP and HTTPS requests using rules such as IP sets and SQL injection patterns. GuardDuty detects threats, CloudTrail records API calls, and Inspector scans workloads.
سؤال 7
Which AWS service scans EC2 instances and container images for software vulnerabilities?
Amazon Inspector assesses workloads for vulnerabilities and network exposure. CloudWatch monitors metrics, ACM manages certificates, and Transfer Family handles file transfers.
سؤال 8
What is the first priority during an AWS security incident?
Incident response begins with preserving evidence and containing impact so you can investigate safely. Deleting logs, terminating accounts, or public disclosure are dangerous.
سؤال 9
Which AWS service can detect cryptocurrency mining activity on EC2 instances?
GuardDuty includes findings for unusual compute activity such as cryptocurrency mining. Glacier is archive storage, Direct Connect is private networking, and Lex is conversational AI.
سؤال 10
Match each AWS security service to its main purpose.
GuardDuty detects threats, Security Hub aggregates findings, Inspector scans workloads, and WAF filters web traffic.
سؤال 11
Which AWS service records API calls in an AWS account for auditing?
CloudTrail records management and data events performed through APIs. VPC Flow Logs capture network traffic, Budgets track cost, and Route 53 is DNS.
سؤال 12
Which AWS feature captures metadata about network traffic in a VPC?
VPC Flow Logs capture IP traffic metadata for network analysis. CloudTrail records API calls, Config tracks configuration, and GuardDuty detects threats.
سؤال 13
Which service stores and monitors application and system logs?
CloudWatch Logs stores, monitors, and queries log data. Glacier is archive storage, ACM manages certificates, and ECR stores container images.
سؤال 14
Which CloudTrail feature can help detect whether log files were modified?
CloudTrail log file validation uses hashes to detect changes. S3 versioning and replication preserve objects, and lifecycle policies manage retention, but validation specifically proves integrity.
سؤال 15
Which agent should you install on EC2 instances to send operating system logs to CloudWatch?
The CloudWatch agent collects OS and application logs plus custom metrics. CLI is a command tool, ECS agent runs containers, and WAF has no host agent.
سؤال 16
Which CloudWatch Logs feature extracts numeric values from log events to create metrics?
Metric filters scan log events and create metrics from matched patterns. Alarms trigger on metrics, log groups store logs, and export tasks move logs.
سؤال 17
Which feature lets you query and analyze logs stored in CloudWatch Logs?
Logs Insights provides interactive queries for CloudWatch Logs. WAF filters web traffic, GuardDuty detects threats, and Shield protects against DDoS.
سؤال 18
Which AWS approach centralizes CloudTrail logs from all accounts in an organization?
An organization trail delivers management events for all member accounts to a central S3 bucket. Regional trails alone, VPC peering, and security groups do not centralize logs.
سؤال 19
Which CloudWatch feature sends a notification when a security metric crosses a threshold?
CloudWatch Alarms monitor metrics and trigger actions such as SNS notifications. Dashboards display data, log groups store logs, and subscriptions route log data.
سؤال 20
Match each AWS logging feature to its purpose.
CloudTrail records API calls, Flow Logs capture network metadata, CloudWatch Logs stores logs, and Insights queries them.
سؤال 21
Which VPC component filters traffic at the instance level?
Security groups act as virtual instance firewalls with allow-only rules. NACLs filter at the subnet level, route tables direct traffic, and internet gateways provide public access.
سؤال 22
Which VPC component filters traffic at the subnet level?
Network ACLs are stateless subnet-level filters with allow and deny rules. Security groups filter instances, EBS volumes store data, and NAT gateways provide outbound internet.
سؤال 23
Which AWS service provides private connectivity from a VPC to supported services without traversing the internet?
PrivateLink exposes services through private endpoints inside a VPC. Direct Connect is a private physical link, VPN uses encrypted tunnels, and CloudFront is a CDN.
سؤال 24
Which AWS service connects many VPCs and on-premises networks through a central hub?
Transit Gateway simplifies hub-and-spoke connectivity between VPCs and on-prem networks. Shield is DDoS protection, Cognito is identity, and AppSync is GraphQL.
سؤال 25
Which AWS service provides a managed network firewall for a VPC?
AWS Network Firewall filters traffic at the VPC level with stateful rules. WAF protects web apps, Shield stops DDoS, and Inspector scans workloads.
سؤال 26
Which AWS service lets you manage EC2 instances without opening SSH ports or using public IP addresses?
Session Manager provides secure browser-based shell access without public inbound ports. Direct Connect is private connectivity, Global Accelerator improves routing, and Route 53 is DNS.
سؤال 27
What is a bastion host used for?
A bastion host is a hardened entry point that administrators use to reach private resources. Load balancers distribute traffic, DNS resolves names, and vaults store backups.
سؤال 28
Which AWS service lets you apply service control policies across an organization?
AWS Organizations manages accounts and applies SCPs centrally. CloudWatch monitors metrics, CloudTrail records API calls, and GuardDuty detects threats.
سؤال 29
Which AWS service provides secure encrypted tunnels between on-premises networks and AWS?
Site-to-Site VPN creates encrypted tunnels between on-prem and AWS. S3 stores objects, Elastic Beanstalk deploys apps, and Athena queries data.
سؤال 30
Match each VPC security component to its purpose.
Security groups filter instances, NACLs filter subnets, PrivateLink exposes private endpoints, and Network Firewall provides stateful filtering.
سؤال 31
What is an IAM role?
An IAM role is an identity with permissions attached, assumed by users, services, or federated identities. It is not a static login or resource.
سؤال 32
What is an IAM policy?
IAM policies are JSON documents granting or denying actions on resources. Routes, schemas, and backup plans are unrelated.
سؤال 33
Which AWS service issues temporary security credentials?
AWS Security Token Service issues temporary credentials for roles and federated sessions. Route 53 is DNS, ACM manages certificates, and EBS provides volumes.
سؤال 34
What does an IAM trust policy define?
A trust policy controls who or what can assume a role. Buckets, VPC peering, and log groups are not defined by trust policies.
سؤال 35
What does least privilege mean?
Least privilege limits permissions to what is necessary. Granting admin access, removing users, or using root account only are not least privilege practices.
سؤال 36
Which AWS service provides workforce identity federation across AWS accounts and applications?
IAM Identity Center centralizes workforce identities and single sign-on. GuardDuty detects threats, WAF filters web traffic, and Inspector scans workloads.
سؤال 37
What is an IAM permission boundary?
A permission boundary caps the maximum permissions granted by policies. Firewall rules, lifecycle rules, and alarms are unrelated.
سؤال 38
Which IAM condition key can require multifactor authentication?
The aws:MultiFactorAuthPresent condition checks whether MFA was used. SourceIp checks the IP, TagKeys checks tags, and ec2:ResourceTag checks EC2 tags.
سؤال 39
Which IAM best practice applies to the AWS root user?
The root user should have MFA enabled and be used only for limited account management tasks. Sharing credentials or disabling MFA increases risk.
سؤال 40
Match each IAM concept to its purpose.
Roles are assumable identities, policies define permissions, STS issues temporary credentials, and boundaries limit maximum permissions.
سؤال 41
Which AWS service creates and manages encryption keys?
AWS Key Management Service creates, rotates, and controls encryption keys. GuardDuty detects threats, CloudTrail records calls, and QuickSight visualizes data.
سؤال 42
Which AWS service securely stores and automatically rotates database credentials and secrets?
Secrets Manager stores secrets and supports automated rotation. S3 stores objects, ACM manages certificates, and ECR stores container images.
سؤال 43
Which AWS service manages SSL/TLS certificates for AWS services?
ACM provisions and renews SSL/TLS certificates. KMS manages keys, GuardDuty detects threats, and Config tracks configurations.
سؤال 44
What is envelope encryption?
Envelope encryption wraps a data key with a master key, then uses the data key to encrypt data. Plaintext keys and shared passwords are insecure.
سؤال 45
Which S3 encryption option uses an AWS-managed key automatically?
SSE-S3 uses Amazon S3 managed keys automatically. SSE-C uses customer-provided keys, and client-side encryption happens before upload.
سؤال 46
Which mechanism protects data in transit to AWS?
TLS encrypts traffic between clients and AWS services. Snapshots, versioning, and policies protect other aspects of storage and access.
سؤال 47
Which AWS service provides dedicated single-tenant hardware security modules?
CloudHSM gives you dedicated HSM appliances for cryptographic operations. KMS is a managed key service, WAF filters traffic, and GuardDuty detects threats.
سؤال 48
Which S3 feature prevents objects from being deleted or overwritten for a fixed period?
S3 Object Lock enforces write-once-read-many retention. Lifecycle policies manage transitions, replication copies data, and CloudFront is a CDN.
سؤال 49
Which AWS service centralizes encryption keys and integrates with many AWS services?
KMS integrates with most AWS services for encryption. EFS is file storage, Glue is ETL, and Athena queries data.
سؤال 50
Match each data protection service to its purpose.
Which AWS service provides compliance reports, certifications, and agreements?
AWS Artifact provides on-demand access to compliance reports and agreements. GuardDuty detects threats, CloudTrail records calls, and S3 stores data.
سؤال 52
Which AWS service tracks resource configurations and evaluates them against rules?
AWS Config records resource configuration changes and evaluates compliance with rules. CloudFormation deploys infrastructure, Route 53 is DNS, and Direct Connect is networking.
سؤال 53
Which AWS service helps you centrally manage accounts, budgets, and service control policies?
AWS Organizations manages multiple accounts, applies SCPs, and supports consolidated billing. CloudWatch monitors, WAF filters traffic, and Inspector scans workloads.
سؤال 54
What is a service control policy?
SCPs define the maximum permissions available to accounts in an organization. S3 policies, routes, and dashboards are different.
سؤال 55
Which AWS Config feature bundles multiple rules for compliance frameworks?
Conformance packs deploy collections of Config rules and remediation actions. Metric filters, log groups, and alarms are CloudWatch features.
سؤال 56
Which AWS service provides recommendations for security, cost, performance, and reliability?
Trusted Advisor reviews accounts and recommends improvements. GuardDuty detects threats, WAF filters web traffic, and Inspector scans for vulnerabilities.
سؤال 57
Which AWS service can automatically remediate noncompliant resources?
AWS Config rules can trigger remediation actions such as Systems Manager documents. Route 53 is DNS, Shield is DDoS protection, and QuickSight visualizes data.
سؤال 58
Which AWS service provides a single dashboard for security posture and compliance?
Security Hub gives a consolidated security and compliance dashboard. CodeBuild builds code, ECS runs containers, and App Runner deploys web apps.
سؤال 59
Which AWS Organizations feature restricts the AWS services an account can use?
SCPs can deny access to specific services or actions at the organization level. Flow logs, dashboards, and lifecycle policies do not restrict service use.