Higher Test Marks with Free Online SCS-C02 Exam Practice

Assess the CertsIQ’s updated SCS-C02 exam questions for free online practice of your AWS Certified Security Specialty test. Our SCS C02 dumps questions will enhance your chances of passing the AWS Certified Specialty certification exam with higher marks.

Exam Code: SCS-C02
Exam Questions: 569
AWS Certified Security Specialty
Updated: 08 Oct, 2025
Question 1

A security vulnerability has been discovered that could lead to sensitive data being leaked on TCP port 5601. The development team is working on updating the code, but it could take several days. A security engineer must identify any hosts attempting to send data over port 5601 and prevent the traffic leaving the network.
How can the security engineer accomplish this goal?

Options :
Answer: A

Question 2

A multinational enterprise uses AWS Organizations to manage several AWS accounts spread across different regions. The company's IT department centrally manages the creation of IAM roles. Recently, the company decided to delegate the IAM role creation to various regional teams to speed up the process and reduce the IT department's workload. However, it is critical to prevent privilege escalation and ensure the scope of IAM roles remains within the defined limits.
Which solution will meet these requirements with the LEAST operational overhead?

Options :
Answer: C

Question 3

A company is running an Amazon RDS for MySQL DB instance in a VPC. The VPC must not send or receive network traffic through the internet. A security engineer wants to use AWS Secrets Manager to rotate the DB instance credentials automatically. Because of a security policy, the security engineer cannot use the standard AWS Lambda function that Secrets Manager provides to rotate the credentials. The security engineer deploys a custom Lambda function in the VPC. The custom Lambda function will be responsible for rotating the secret in Secrets Manager. The security engineer edits the DB instance's security group to allow connections from this function. When the function is invoked, the function cannot communicate with Secrets Manager to rotate the secret properly. What should the security engineer do so that the function can rotate the secret?

Options :
Answer: D

Question 4

A developer is attempting to access an Amazon S3 bucket in a member account in AWS Organizations. The developer is logged in to the account with user credentials and has received an access denied error with no bucket listed. The developer should have read-only access to all buckets in the account.
A security engineer has reviewed the permissions and found that the developer's IAM user has been granted read-only access to all S3 buckets in the account.
Which additional steps should the security engineer take to troubleshoot the issue? (Select TWO.)

Options :
Answer: A,B

Question 5

A company has a batch-processing system that uses Amazon S3, Amazon EC2, and AWS Key Management Service (AWS KMS). The system uses two AWS accounts: Account A and Account B. Account A hosts an S3 bucket that stores the objects that will be processed. The S3 bucket also stores the results of the processing. All the S3 bucket objects are encrypted by a KMS key that is managed in Account A. Account B hosts a VPC that has a fleet of EC2 instances that access the S3 buck-et in Account A by using statements in the bucket policy. The VPC was created with DNS hostnames enabled and DNS resolution enabled. A security engineer needs to update the design of the system without changing any of the system's code. No AWS API calls from the batch-processing EC2 in-stances can travel over the internet. Which combination of steps will meet these requirements? (Select TWO.)

Options :
Answer: B,C

Viewing Page : 1 - 57
Practicing : 1 - 5 of 569 Questions

© Copyrights CertsIQ 2025. All Rights Reserved

We use cookies to ensure that we give you the best experience on our website (CertsIQ). If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the CertsIQ.