SCS-C03 Sample Questions

SCS-C03 Sample Questions & Answers

Authentication and authorization strategies carry the top share, just ahead of infrastructure security tied with data protection, watching logs and raising alerts to catch threats, planning how to respond to incidents, and foundational security governance.

Launch the full SCS-C03 simulator →

Showing 8 of 17 free samples.

  1. Question 1IntermediateSelect 2

    Detection · Design and implement logging solutions

    A security team is designing a centralized log ingestion pipeline. They need to collect logs from multiple sources and forward them to a third-party Splunk endpoint. The solution must support buffering, transformation of log data, and automatic retries. Which TWO services should be combined to build this architecture? (Select TWO)

    Show answer & explanation

    Correct answers: A, E

    Kinesis Data Firehose provides buffering, transformation (via Lambda), and direct delivery to third-party destinations like Splunk with retry capabilities.

    Subscription filters are the mechanism to extract logs from CloudWatch and push them to Kinesis Data Firehose.

  2. Question 2Intermediate

    Detection · Design and implement monitoring and alerting solutions

    A company requires real-time detection of specific security group changes that open port 22 to the world (0.0.0.0/0). The detection must trigger a remediation Lambda function within seconds. The security team is debating between using AWS Config Rules and Amazon EventBridge rules.

    Which approach provides the fastest reaction time for this specific requirement?

    Show answer & explanation

    Correct answer: C

    EventBridge allows for near real-time reaction to API calls as they happen. AWS Config rules have a recording delay (latency) before evaluation occurs, making EventBridge the faster option for immediate remediation.

  3. Question 3Beginner

    Detection · Design and implement monitoring and alerting solutions

    A developer has deployed a serverless application using AWS Lambda functions. The security team wants to automatically detect software vulnerabilities in the application code and the Lambda function layers. Which AWS service should be enabled to perform these scans automatically?

    Show answer & explanation

    Correct answer: C

    Amazon Inspector supports scanning AWS Lambda functions and layers for software vulnerabilities and network exposure.

  4. Question 4Intermediate

    Detection · Design and implement logging solutions

    A security analyst needs to configure VPC Flow Logs to capture specific TCP flag information to diagnose a potential TCP SYN flood attack. The standard flow log format does not include this detail. The analyst creates a custom format.

    Which field must be included in the custom format string to see the TCP flags?

    Show answer & explanation

    Correct answer: D

    The tcp-flags field in VPC Flow Logs custom format records the bitmask value for the TCP flags observed in the traffic.

  5. Question 5Advanced

    Incident Response · Design and test an incident response plan

    A financial services company has a critical fleet of EC2 instances processing payment transactions. The CISO mandates that in the event of a confirmed security compromise on any instance, a forensic investigation must be triggered automatically. The process must capture a memory dump and the associated EBS volumes, then isolate the instance. The solution should use a simplified, managed workflow without requiring the team to maintain complex custom scripts.

    Which solution best meets these requirements?

    Show answer & explanation

    Correct answer: C

    The 'Automated Forensics Orchestrator for Amazon EC2' is an AWS Solution that provides a pre-built, managed workflow to acquire forensic evidence (memory dumps, disk snapshots) and isolate instances, satisfying the requirement for a simplified managed workflow.

  6. Question 6Intermediate

    Incident Response · Respond to security events

    A company has suffered a ransomware attack where the attacker gained access to the root account and attempted to delete all backups. However, the backups stored in the AWS Backup vault remained intact, allowing the company to recover.

    Which AWS Backup feature likely prevented the attacker from deleting the recovery points?

    Show answer & explanation

    Correct answer: D

    AWS Backup Vault Lock in Compliance Mode enforces a Write-Once-Read-Many (WORM) model. Once the lock is active and the cooling-off period expires, not even the root user can delete the recovery points or alter the retention period.

  7. Question 7Intermediate

    Incident Response · Respond to security events

    A security engineer detects that an IAM Identity Center (AWS SSO) user's credentials have been compromised. The engineer disables the user in the identity store, but notices the user is still able to perform actions in the AWS Management Console for a short period.

    What is the most effective way to immediately revoke the user's active access across all accounts?

    Show answer & explanation

    Correct answer: D

    Disabling the user prevents new logins, but active sessions rely on temporary credentials already issued. To stop active sessions immediately, you must either revoke the sessions (if supported by the specific session type) or attach a global Deny policy (e.g., via SCP or inline policy) that invalidates actions based on the user's principal tag.

  8. Question 8Beginner

    Incident Response · Design and test an incident response plan

    True or False: AWS Systems Manager Incident Manager can automatically create an OpsItem in OpsCenter when an incident is started.

    Show answer & explanation

    Correct answer: A

    Incident Manager integrates natively with OpsCenter. When an incident is created, it automatically generates a corresponding OpsItem to track the operational work.

Ready for the real thing?

The full SCS-C03 simulator has every exam-style question, timed mode, and instant scoring.