SCS-C03 sample questions with answers

10 free practice questions for the AWS Certified Security – Specialty exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Detection

An authorized vulnerability scanner runs weekly from a fixed set of internal addresses and generates a large volume of GuardDuty reconnaissance findings. The security team wants those findings to stop reaching Security Hub and the team's EventBridge pipeline, but it must still be able to show an auditor that GuardDuty detected and recorded the scanning activity. What should the engineer configure?

  1. A.

    A GuardDuty trusted IP list containing the scanner's addresses, uploaded to the detector in the administrator account.

  2. B.

    An EventBridge rule with an event pattern that excludes the scanner's addresses so that matching findings are dropped before delivery.

  3. C.

    A GuardDuty suppression rule matching the finding type and the scanner's addresses.

  4. D.

    A Security Hub automation rule that sets the workflow status of matching findings to SUPPRESSED after they are imported.

Show answer

Answer: C

A suppression rule still generates the finding and archives it automatically, and archived findings are not exported to Security Hub, S3, Detective, or EventBridge.

  • A. A trusted IP list prevents the findings from being generated at all, so there is no record for the auditor.
  • B. Filtering in EventBridge only cleans one consumer; Security Hub still receives the findings and the noise remains.
  • C. Suppressed findings are generated and auto-archived, so they remain visible in GuardDuty for audit but are not exported to Security Hub, S3, Detective, or EventBridge.
  • D. An automation rule acts after import, so the findings have already reached Security Hub and the EventBridge pipeline.
Question 2Detection

A security engineering team already aggregates findings in AWS Security Hub. It now needs analysts in a central monitoring account to open CloudWatch dashboards that graph metrics and run Logs Insights queries over log groups that live in 30 workload accounts, without assuming a role into each account for every investigation. Which approach meets the requirement?

  1. A.

    Configure CloudWatch cross-account observability by creating a sink in the monitoring account and a link in each workload account.

  2. B.

    Create a subscription filter in each workload account that streams every log group through Firehose into a single log group in the monitoring account.

  3. C.

    Add each workload account's findings to the Security Hub home Region and build the dashboards from the aggregated Security Hub findings instead of from metrics.

  4. D.

    Create an IAM role in each workload account that the analysts assume, and document the role-switching procedure in the investigation runbook.

Show answer

Answer: A

CloudWatch cross-account observability lets a monitoring account query metrics, logs, and traces in linked source accounts directly, with no role switching and no log copying.

  • A. A sink in the monitoring account and links in the source accounts give in-place read access to metrics, logs, and traces across all thirty accounts.
  • B. Central copying doubles ingestion charges, flattens the per-account log group structure, and adds a delivery pipeline to operate and monitor.
  • C. Security Hub aggregates findings only; it carries neither CloudWatch metrics nor raw log events, so the dashboards cannot be built from it.
  • D. Role switching is the manual per-investigation step the requirement excludes and makes a single query spanning all accounts impossible.
Question 3Detection

A security operations centre consumes GuardDuty findings through an EventBridge rule that forwards them to a third-party platform. New findings arrive within a few minutes. However, when GuardDuty observes further activity for an existing finding, the updated finding reaches the platform hours later, which delays escalation. The team has not changed any GuardDuty setting since enabling the service. What should the engineer change?

  1. A.

    Enable GuardDuty Extended Threat Detection so that related activity is correlated into a single finding instead of being delivered as an update.

  2. B.

    Add a second EventBridge rule in the delegated administrator account so that updated findings are matched by their own event pattern and forwarded separately.

  3. C.

    Configure an S3 export destination for findings and have the platform poll the bucket instead of receiving events from EventBridge.

  4. D.

    Change the frequency for exporting updated findings from the default to 15 minutes.

Show answer

Answer: D

GuardDuty exports new findings within about five minutes but exports updated findings on a configurable schedule whose default is every six hours.

  • A. Extended Threat Detection produces attack sequence findings from correlated signals; it does not change the export cadence for finding updates.
  • B. An EventBridge rule can only match events that GuardDuty has already published, so another rule cannot shorten publication delay.
  • C. The same update frequency governs the S3 export, so polling a bucket would deliver the same six-hour-old data.
  • D. The frequency for updated findings defaults to six hours and can be set to 15 minutes, which is the only setting that governs this delay.
Question 4Detection

A company already aggregates security findings centrally. Its incident responders now say that findings alone are insufficient: they need the underlying CloudTrail management events, VPC Flow Logs, and Route 53 Resolver query logs from 120 accounts in one normalized, queryable place, and a third-party analytics vendor must be granted read access to the same data. Which service should the engineer deploy?

  1. A.

    AWS Security Hub with cross-Region aggregation, exporting aggregated findings to the vendor's account on a schedule.

  2. B.

    Amazon Detective, granting the vendor a role that allows it to browse the behaviour graph for every member account.

  3. C.

    Amazon CloudWatch cross-account observability, with a sink that the vendor's account creates a link to for reading log groups.

  4. D.

    Amazon Security Lake, with a subscriber created for the third-party vendor.

Show answer

Answer: D

Security Lake centralizes raw AWS log sources from an organization, normalizes them to OCSF in Parquet, and has a built-in subscriber model for granting third parties access.

  • A. Security Hub aggregates findings, so exporting from it gives the vendor detections rather than the underlying CloudTrail, flow log, and DNS records.
  • B. Detective produces an investigative behaviour graph from ingested telemetry; it does not publish normalized logs for a third party to query.
  • C. Cross-account observability reads CloudWatch telemetry in place inside the organization and does not cover flow logs and DNS logs delivered to S3 or external sharing.
  • D. Security Lake centralizes the named log sources organization-wide in OCSF Parquet and grants external parties access through its subscriber model.
Question 5Detection

An engineer enables CloudFront legacy standard access logging to a newly created S3 bucket in the same account. The distribution shows logging as enabled and traffic is flowing, but after two days the bucket is still empty. The bucket policy grants the log delivery service write access and the bucket uses default encryption with an S3 managed key. What should the engineer check?

  1. A.

    Whether the bucket's S3 Object Ownership setting disables access control lists, which prevents CloudFront from delivering legacy standard log files.

  2. B.

    Whether the distribution's price class excludes the edge locations serving the traffic, which prevents log records from being generated.

  3. C.

    Whether the log prefix contains a trailing slash, which causes CloudFront to write the files outside the bucket's configured prefix.

  4. D.

    Whether the bucket has versioning disabled, which CloudFront requires in order to write successive log files without overwriting them.

Show answer

Answer: A

Legacy CloudFront standard logging delivers through an access control list grant, so a bucket created with ACLs disabled silently receives nothing.

  • A. Legacy standard logging delivers via an ACL grant, so a bucket with ACLs disabled by its object ownership setting receives nothing.
  • B. Price class limits which edge locations serve requests; requests that are served are still logged.
  • C. A trailing slash in the prefix affects the key path within the bucket, not whether delivery succeeds.
  • D. Versioning is not a requirement for CloudFront log delivery, and log file names are already unique.
Question 6Detection

An engineer converts an existing single-account trail into an organization trail that writes to the same S3 bucket in the log archive account. After the change, log files for the management account continue to arrive, but no member account log files ever appear, and the trail reports a delivery error. The KMS key policy and the trail's Region are unchanged. What is the most likely cause?

  1. A.

    Organization trails deliver only to a bucket in the management account, so the log archive account cannot be the destination.

  2. B.

    Member accounts must each add a bucket policy statement to the log archive bucket before their log files can be delivered.

  3. C.

    The bucket policy grants PutObject only under the management account's AWSLogs prefix, and an organization trail also writes under an organization prefix.

  4. D.

    Organization trails require a dedicated bucket, so the existing bucket cannot be reused and a new one must be created for the organization.

Show answer

Answer: C

An organization trail writes member account log files under a prefix containing the organization identifier, which the original single-account bucket policy does not permit.

  • A. Delivering an organization trail to a separate log archive account is supported and is the recommended pattern.
  • B. Member accounts have no permission to modify the log archive bucket policy, and nothing requires them to.
  • C. Organization trails write member account files under an organization-identifier prefix, which needs its own PutObject statement in the bucket policy.
  • D. An existing bucket can serve an organization trail; only the bucket policy has to be extended.
Question 7Detection

A company enables access logging and INFO-level execution logging on a REST API stage in eu-central-1. The same settings work in the company's us-east-1 account, but in eu-central-1 no log group is created and no events appear. The stage settings show logging enabled and the deployment succeeded. What is the most likely cause?

  1. A.

    The access log format is missing a required context variable, which causes API Gateway to discard both access and execution logs.

  2. B.

    The API must be redeployed after any stage setting change, and the company changed the settings without creating a new deployment.

  3. C.

    REST API execution logging is available only in us-east-1, so eu-central-1 stages support access logging alone.

  4. D.

    The CloudWatch Logs role ARN has not been set on the API Gateway account settings in eu-central-1, because that setting is per Region.

Show answer

Answer: D

REST API logging depends on an account-level CloudWatch Logs role ARN that API Gateway assumes, and that setting must be configured separately in every Region.

  • A. An incomplete access log format weakens correlation but does not suppress execution logging or prevent log group creation.
  • B. Stage setting changes such as enabling logging take effect without redeploying the API.
  • C. REST API execution logging is available in all Regions where API Gateway runs; it is not restricted to us-east-1.
  • D. The CloudWatch Logs role ARN is an account-level API Gateway setting configured per Region, so it must be set in eu-central-1 as well.
Question 8Detection

A company stores clinical documents in an S3 bucket. The security team must raise an alert within minutes whenever an object in a particular prefix is downloaded by a principal outside a named role, and the record of that access must be usable as audit evidence. The team is choosing between S3 server access logging and CloudTrail data events. Which choice meets the requirement, and why?

  1. A.

    S3 server access logging, because it records every request to the bucket at no additional request charge.

  2. B.

    CloudTrail data events, because management events already cover object access and no further configuration is needed.

  3. C.

    S3 server access logging, because only it records the requester identity for object-level operations.

  4. D.

    CloudTrail data events, because they are delivered as CloudTrail events that EventBridge and CloudWatch Logs can act on within minutes and can be scoped to the prefix.

Show answer

Answer: D

CloudTrail data events are real CloudTrail events, so they reach EventBridge and CloudWatch Logs within minutes and can be scoped to a prefix with advanced event selectors.

  • A. Server access log delivery is best-effort and can lag by hours, so it cannot support an alert within minutes however cheap it is.
  • B. Object-level access is a data event; a trail logs management events by default and records nothing about object downloads until data events are configured.
  • C. Both sources record the requester, so this is not a distinguishing property of server access logging.
  • D. Data events flow into CloudWatch Logs and EventBridge for minutes-level alerting, and advanced event selectors scope them to the prefix.
Question 9Detection

A manufacturer connects 40 VPCs and two on-premises sites through an AWS Transit Gateway. After an incident, investigators could not tell which attachment a flow entered the transit gateway on, and packets that the transit gateway dropped because no route matched were absent from every VPC's flow logs. The security team wants this visibility for future investigations. What should the engineer enable?

  1. A.

    Transit gateway flow logs on the transit gateway, delivered to Amazon S3.

  2. B.

    AWS Network Firewall alert and flow logging on the inspection VPC's firewall endpoints.

  3. C.

    VPC Flow Logs at the subnet level in the inspection VPC with a one-minute aggregation interval.

  4. D.

    VPC Flow Logs on every transit gateway attachment subnet in each of the 40 VPCs.

Show answer

Answer: A

Only transit gateway flow logs record traffic at the transit gateway itself, including the attachment a flow arrived on and packets dropped for having no matching route.

  • A. Transit gateway flow logs capture flows at the gateway, including attachment context and packets dropped because no route matched.
  • B. Network Firewall logs describe traffic the firewall inspected and cannot show attachment context or transit gateway routing drops.
  • C. An inspection VPC only observes traffic that routing delivers to it, so flows dropped at the transit gateway remain invisible.
  • D. VPC Flow Logs are generated by network interfaces, so packets the transit gateway dropped before reaching a VPC are never recorded.
Question 10Detection

A company enabled Amazon Macie and built its alerting entirely on AWS Security Hub. Macie policy findings about public buckets appear in Security Hub and page the on-call engineer correctly. However, findings that report credentials and payment card data inside objects never appear there, even though the Macie console shows them. What should the engineer do to alert on those findings?

  1. A.

    Create an EventBridge rule that matches Macie sensitive data findings and targets the notification pipeline.

  2. B.

    Enable Macie automated sensitive data discovery in the delegated administrator account so that the findings become eligible for Security Hub.

  3. C.

    Increase the Macie publication frequency so that sensitive data findings are published to Security Hub on the same schedule as policy findings.

  4. D.

    Add a Security Hub automation rule that raises the severity of sensitive data findings so that they are no longer filtered out of the console view.

Show answer

Answer: A

Macie publishes policy findings to Security Hub but not sensitive data findings, while every Macie finding of both categories is published to EventBridge automatically.

  • A. Macie publishes every finding, including sensitive data findings, to EventBridge automatically, so a rule there reaches the category Security Hub does not receive.
  • B. Automated sensitive data discovery is already producing the findings, as the Macie console shows them, so enabling it changes nothing.
  • C. Publication frequency governs how often updates to existing policy findings are published; it cannot route a category that is not sent to Security Hub.
  • D. A Security Hub automation rule can only act on findings Security Hub has imported, and these findings never arrive.

Keep going with 492 more SCS-C03 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.