AWS Security Specialty Practice

Practice 60 original AWS Certified Security - Specialty questions covering threat detection, logging, infrastructure security, IAM, data protection, and governance, with detailed explanations.

Level: AWS Certified Security - Specialty (SCS-C02) Difficulty: advanced 60 questions 60 min
Choose a practice mode, answer each AWS Security Specialty question, then review the explanation. Wrong answers are saved locally for review.
Day streak: 0 days Saved only on this device
Progress 0 / 60
Question 1

Which AWS service continuously monitors accounts and workloads for threats and generates security findings?

Select an answer
Question 2

Which data sources does Amazon GuardDuty analyze?

Select an answer
Question 3

Which AWS service provides a central place to aggregate security findings from multiple accounts?

Select an answer
Question 4

Which AWS service provides managed incident response and remediation workflows?

Select an answer
Question 5

Which AWS service protects applications from distributed denial-of-service attacks?

Select an answer
Question 6

Which AWS service provides a managed web application firewall?

Select an answer
Question 7

Which AWS service scans EC2 instances and container images for software vulnerabilities?

Select an answer
Question 8

What is the first priority during an AWS security incident?

Select an answer
Question 9

Which AWS service can detect cryptocurrency mining activity on EC2 instances?

Select an answer
Question 10

Match each AWS security service to its main purpose.

Question 11

Which AWS service records API calls in an AWS account for auditing?

Select an answer
Question 12

Which AWS feature captures metadata about network traffic in a VPC?

Select an answer
Question 13

Which service stores and monitors application and system logs?

Select an answer
Question 14

Which CloudTrail feature can help detect whether log files were modified?

Select an answer
Question 15

Which agent should you install on EC2 instances to send operating system logs to CloudWatch?

Select an answer
Question 16

Which CloudWatch Logs feature extracts numeric values from log events to create metrics?

Select an answer
Question 17

Which feature lets you query and analyze logs stored in CloudWatch Logs?

Select an answer
Question 18

Which AWS approach centralizes CloudTrail logs from all accounts in an organization?

Select an answer
Question 19

Which CloudWatch feature sends a notification when a security metric crosses a threshold?

Select an answer
Question 20

Match each AWS logging feature to its purpose.

Question 21

Which VPC component filters traffic at the instance level?

Select an answer
Question 22

Which VPC component filters traffic at the subnet level?

Select an answer
Question 23

Which AWS service provides private connectivity from a VPC to supported services without traversing the internet?

Select an answer
Question 24

Which AWS service connects many VPCs and on-premises networks through a central hub?

Select an answer
Question 25

Which AWS service provides a managed network firewall for a VPC?

Select an answer
Question 26

Which AWS service lets you manage EC2 instances without opening SSH ports or using public IP addresses?

Select an answer
Question 27

What is a bastion host used for?

Select an answer
Question 28

Which AWS service lets you apply service control policies across an organization?

Select an answer
Question 29

Which AWS service provides secure encrypted tunnels between on-premises networks and AWS?

Select an answer
Question 30

Match each VPC security component to its purpose.

Question 31

What is an IAM role?

Select an answer
Question 32

What is an IAM policy?

Select an answer
Question 33

Which AWS service issues temporary security credentials?

Select an answer
Question 34

What does an IAM trust policy define?

Select an answer
Question 35

What does least privilege mean?

Select an answer
Question 36

Which AWS service provides workforce identity federation across AWS accounts and applications?

Select an answer
Question 37

What is an IAM permission boundary?

Select an answer
Question 38

Which IAM condition key can require multifactor authentication?

Select an answer
Question 39

Which IAM best practice applies to the AWS root user?

Select an answer
Question 40

Match each IAM concept to its purpose.

Question 41

Which AWS service creates and manages encryption keys?

Select an answer
Question 42

Which AWS service securely stores and automatically rotates database credentials and secrets?

Select an answer
Question 43

Which AWS service manages SSL/TLS certificates for AWS services?

Select an answer
Question 44

What is envelope encryption?

Select an answer
Question 45

Which S3 encryption option uses an AWS-managed key automatically?

Select an answer
Question 46

Which mechanism protects data in transit to AWS?

Select an answer
Question 47

Which AWS service provides dedicated single-tenant hardware security modules?

Select an answer
Question 48

Which S3 feature prevents objects from being deleted or overwritten for a fixed period?

Select an answer
Question 49

Which AWS service centralizes encryption keys and integrates with many AWS services?

Select an answer
Question 50

Match each data protection service to its purpose.

Question 51

Which AWS service provides compliance reports, certifications, and agreements?

Select an answer
Question 52

Which AWS service tracks resource configurations and evaluates them against rules?

Select an answer
Question 53

Which AWS service helps you centrally manage accounts, budgets, and service control policies?

Select an answer
Question 54

What is a service control policy?

Select an answer
Question 55

Which AWS Config feature bundles multiple rules for compliance frameworks?

Select an answer
Question 56

Which AWS service provides recommendations for security, cost, performance, and reliability?

Select an answer
Question 57

Which AWS service can automatically remediate noncompliant resources?

Select an answer
Question 58

Which AWS service provides a single dashboard for security posture and compliance?

Select an answer
Question 59

Which AWS Organizations feature restricts the AWS services an account can use?

Select an answer
Question 60

Match each governance service to its purpose.