{"id":17238,"date":"2026-09-21T07:16:13","date_gmt":"2026-09-21T07:16:13","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17238"},"modified":"2026-09-21T07:16:13","modified_gmt":"2026-09-21T07:16:13","slug":"amazon-aws-certified-security-specialty-scs-c02-practice-test-questions-and-exam-dumps-part3-q41-60","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-security-specialty-scs-c02-practice-test-questions-and-exam-dumps-part3-q41-60\/","title":{"rendered":"Amazon AWS Certified Security &#8211; Specialty SCS-C02 Practice Test Questions and Exam Dumps Part3 Q41-60"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-security-specialty-scs-c02-exam-dumps\"><b>Amazon AWS Certified Security &#8211; Specialty SCS-C02 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 41<\/b><\/h3>\n<p><b>Which IAM feature helps identify unused permissions granted to roles?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM Access Advisor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IAM Access Advisor provides information about when AWS services were last accessed by an IAM principal. Security teams can use this information to review permissions and identify services that may no longer be required. This supports least-privilege initiatives by giving administrators evidence they can use when reducing excessive permissions. Access Advisor does not automatically remove permissions; administrators must review the information and make appropriate policy changes. AWS Shield focuses on DDoS protection, S3 Inventory provides object metadata reports, and Amazon Inspector identifies vulnerabilities in supported workloads.<\/span><\/p>\n<h3><b>Question 42<\/b><\/h3>\n<p><b>Which policy decision overrides an otherwise allowed IAM request?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Allow statement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Explicit deny<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Default allow<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource tag<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An explicit deny in an applicable AWS policy overrides an allow. This is a fundamental part of AWS authorization evaluation. Even when another policy grants an action, an explicit deny prevents that action from being authorized. This behavior allows organizations to create strong security guardrails that cannot easily be bypassed by adding additional allow permissions. Default IAM behavior is deny unless an applicable policy grants access. Resource tags can be used with certain policy conditions, but they are not authorization decisions by themselves. Understanding explicit denies is essential when troubleshooting complex IAM permissions.<\/span><\/p>\n<h3><b>Question 43<\/b><\/h3>\n<p><b>Which service detects malware-related activity in Amazon EKS environments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Aurora<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Glue<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon GuardDuty provides threat detection capabilities across supported AWS environments, including capabilities designed for container-related activity. For supported Amazon EKS environments, GuardDuty can analyze relevant runtime and control-plane signals to identify potentially malicious behavior. This can help security teams detect suspicious activity occurring inside containerized workloads. AWS Artifact provides compliance documentation, Aurora is a relational database service, and Glue supports data integration and analytics workflows. GuardDuty is therefore the security service most directly associated with managed threat detection for supported EKS environments.<\/span><\/p>\n<h3><b>Question 44<\/b><\/h3>\n<p><b>Which S3 control restricts access through a specific network origin?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Object metadata<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lifecycle transition<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bucket policy condition<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage class<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An S3 bucket policy can include condition elements that restrict requests based on characteristics such as source IP address, VPC endpoint, or other supported request attributes. This allows organizations to create more specific access controls rather than granting access solely based on identity. For example, a bucket policy can require requests to originate through a particular VPC endpoint. Object metadata describes stored objects, lifecycle transitions manage storage behavior over time, and storage classes determine storage characteristics and pricing. Bucket policy conditions therefore provide the policy mechanism for restricting access according to request context.<\/span><\/p>\n<h3><b>Question 45<\/b><\/h3>\n<p><b>Which AWS service automates responses to security events using event-driven rules?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EventBridge<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Snowcone<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon DocumentDB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Elastic Disaster Recovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon EventBridge can route events from AWS services and other supported sources to targets for automated processing. Security teams can use EventBridge rules to trigger actions when security findings or infrastructure changes occur. For example, an event can invoke a Lambda function that performs a predefined containment or notification task. This supports automated incident-response workflows and reduces manual intervention for repeatable events. Snowcone provides edge computing and data transfer capabilities, DocumentDB is a document database service, and Elastic Disaster Recovery focuses on workload recovery rather than event-driven security automation.<\/span><\/p>\n<h3><b>Question 46<\/b><\/h3>\n<p><b>Which KMS key type gives an organization direct control over its key policy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS owned key<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Customer managed key<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS service key<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Temporary session key<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Customer managed KMS keys provide organizations with direct administrative control over important key-management settings, including key policies, aliases, rotation configuration, and lifecycle decisions. This makes them appropriate when an organization requires detailed control over who can administer or use encryption keys. AWS owned keys are managed entirely by AWS and are used by services on behalf of customers. Temporary session keys are not a general KMS key-management category. Service-managed encryption mechanisms can simplify operations but may provide less direct administrative control than a customer managed KMS key.<\/span><\/p>\n<h3><b>Question 47<\/b><\/h3>\n<p><b>Which log source can reveal rejected network connections between VPC resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config snapshots<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC Flow Logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM Credential Reports<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudTrail digest files<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VPC Flow Logs provide metadata about network traffic associated with VPCs, subnets, or network interfaces. Depending on the configuration, flow records can indicate whether traffic was accepted or rejected. Security analysts can use these records to investigate unexpected communication, identify blocked connections, and understand network behavior during an incident. Flow Logs do not capture packet contents, but they provide valuable traffic metadata for analysis. AWS Config focuses on resource configuration history, IAM Credential Reports describe user credentials, and CloudTrail digest files help validate log-file integrity.<\/span><\/p>\n<h3><b>Question 48<\/b><\/h3>\n<p><b>Which AWS service provides centralized compliance evidence collection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Detective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Audit Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Network Firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Audit Manager helps organizations collect and organize evidence related to audits and compliance requirements. It can continuously gather evidence from supported AWS services and map collected information to control frameworks. This reduces the manual effort involved in preparing audit documentation and provides a structured way to demonstrate how controls are operating. Detective is designed for security investigations, GuardDuty detects potential threats, and Network Firewall provides network traffic inspection. Audit Manager therefore addresses the governance and evidence-collection requirement described in the question.<\/span><\/p>\n<h3><b>Question 49<\/b><\/h3>\n<p><b>Which S3 feature creates multiple recoverable versions of an object?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Versioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Select<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Batch Operations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Access Analyzer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">S3 Versioning preserves multiple versions of objects within a bucket. When an object is overwritten or deleted, previous versions can remain available, depending on the configured behavior and permissions. This can help recover from accidental overwrites or deletions. Versioning is also commonly used with other S3 protection mechanisms such as Object Lock. S3 Select is designed for querying supported object content, Batch Operations performs actions across large numbers of objects, and access analysis evaluates resource permissions. Versioning specifically provides the object-history capability described.<\/span><\/p>\n<h3><b>Question 50<\/b><\/h3>\n<p><b>Which control helps prevent an IAM role from receiving permissions beyond an approved maximum?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM permissions boundary<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudWatch alarm<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route 53 health check<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 replication rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IAM permissions boundary establishes the maximum permissions that a user or role can have. Even if an identity policy grants additional actions, permissions outside the boundary cannot become effective. This is particularly useful when organizations delegate IAM role creation to development teams while retaining centralized security controls. The boundary is not itself a permission grant; it limits the effective permission set. CloudWatch alarms monitor metrics, Route 53 health checks monitor endpoint availability, and S3 replication rules control object replication. None of those mechanisms limits an IAM principal&#8217;s maximum authorization scope.<\/span><\/p>\n<h3><b>Question 51<\/b><\/h3>\n<p><b>Which AWS service can detect public or cross-account resource access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Polly<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM Access Analyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Batch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Neptune<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IAM Access Analyzer can analyze supported resource-based policies to identify resources that can be accessed from outside an intended trust boundary. Findings can reveal public access or access granted to another AWS account, organization, or external principal. This helps security teams identify unintended exposure and review whether resource policies follow least-privilege principles. Polly provides text-to-speech capabilities, Batch runs batch computing workloads, and Neptune provides graph database functionality. Access Analyzer is therefore the relevant AWS security capability for identifying external access paths in supported resources.<\/span><\/p>\n<h3><b>Question 52<\/b><\/h3>\n<p><b>Which CloudTrail setting can validate whether log files were altered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Log file validation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EventBridge archive<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 replication time control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudWatch contributor insights<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CloudTrail log file validation helps determine whether CloudTrail log files were modified or deleted after delivery. It uses digest files and cryptographic validation mechanisms to support integrity verification. This is valuable when CloudTrail records are being used as security evidence or during forensic investigations. Enabling validation does not by itself prevent an authorized principal from deleting logs, so organizations should combine it with restrictive S3 permissions and centralized log storage. EventBridge archives events, S3 replication controls object replication, and CloudWatch Contributor Insights analyzes log or metric patterns rather than validating CloudTrail file integrity.<\/span><\/p>\n<h3><b>Question 53<\/b><\/h3>\n<p><b>Which service can automatically evaluate container images for known vulnerabilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Direct Connect<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Lex<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Organizations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Inspector can assess supported Amazon Elastic Container Registry image repositories for known software vulnerabilities. It identifies vulnerable packages and generates findings that security teams can use for remediation. This helps organizations integrate vulnerability management into container development and deployment processes. Direct Connect provides dedicated network connectivity, Lex supports conversational interfaces, and Organizations manages multiple AWS accounts. Inspector&#8217;s vulnerability assessment capabilities make it appropriate for identifying known security issues in supported container images before or during deployment.<\/span><\/p>\n<h3><b>Question 54<\/b><\/h3>\n<p><b>Which network architecture component connects multiple VPCs through a central hub?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Transit Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Elastic IP address<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Transit Gateway acts as a centralized network hub that can connect multiple VPCs and other supported networks. It simplifies network architecture by reducing the need to create numerous individual point-to-point connections. From a security perspective, administrators should carefully design route tables, attachments, segmentation, and inspection paths so that connected environments do not receive unintended access. An internet gateway provides internet connectivity, a NAT gateway supports outbound internet access for private resources, and an Elastic IP is a public IPv4 address. Transit Gateway specifically provides centralized network connectivity.<\/span><\/p>\n<h3><b>Question 55<\/b><\/h3>\n<p><b>Which control protects an S3 bucket from accidental public policy changes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Block Public Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Multipart Upload<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Transfer Acceleration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">S3 Block Public Access provides preventive controls designed to help stop public access configurations on S3 resources. It can be applied at multiple scopes and helps protect against common mistakes involving bucket policies and access control lists. This makes it an important baseline control for organizations that do not intentionally expose S3 data publicly. Multipart Upload supports large object uploads, Inventory produces object reports, and Transfer Acceleration improves transfer performance. These features serve operational purposes rather than acting as a preventive control against public S3 exposure.<\/span><\/p>\n<h3><b>Question 56<\/b><\/h3>\n<p><b>Which service can quarantine a compromised workload through automated remediation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EventBridge<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Lambda<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon WorkSpaces<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Marketplace<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Lambda can execute automated remediation code in response to security events. For example, a Lambda function can modify security group rules, update resource configurations, or perform other containment actions when triggered by an event source such as EventBridge or a security finding. Automated remediation should be carefully designed and tested because incorrect actions can disrupt legitimate workloads. EventBridge is commonly used to route the triggering event, while WorkSpaces provides virtual desktops and Marketplace distributes software and services. Lambda provides the compute mechanism that can execute the custom response logic.<\/span><\/p>\n<h3><b>Question 57<\/b><\/h3>\n<p><b>Which RDS option encrypts database storage using AWS KMS?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance Insights<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enhanced Monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Read replica<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon RDS storage encryption protects database storage using AWS KMS encryption keys. When encryption is enabled, related storage components such as automated backups, read replicas in supported configurations, and snapshots can also receive encryption protection according to AWS behavior and configuration. Storage encryption helps protect data at rest from unauthorized access to the underlying storage. Performance Insights provides database performance visibility, Enhanced Monitoring supplies operating-system metrics, and read replicas provide additional database copies for scaling or availability. These features do not themselves represent the database storage encryption mechanism.<\/span><\/p>\n<h3><b>Question 58<\/b><\/h3>\n<p><b>Which AWS service helps enforce governance across multiple AWS accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Organizations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Comprehend<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS IoT Device Defender<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Kinesis Analytics<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Organizations provides centralized management capabilities for multiple AWS accounts. Security teams can use organizational units, service control policies, and account-level governance mechanisms to establish consistent controls across an AWS environment. Organizations is especially important in multi-account security architectures because it allows central administrators to define guardrails that member accounts must operate within. Comprehend provides natural-language processing, IoT Device Defender helps monitor IoT security posture, and Kinesis Analytics supports stream-processing workloads. Organizations directly addresses centralized multi-account governance.<\/span><\/p>\n<h3><b>Question 59<\/b><\/h3>\n<p><b>Which security practice preserves evidence before modifying a compromised instance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete temporary files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Create a forensic snapshot<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reinstall the operating system<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rotate every account credential immediately<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Creating a forensic snapshot before making significant changes to a compromised workload can help preserve evidence for later investigation. For an EC2 instance, security teams may capture relevant EBS volume snapshots and document the incident state before performing containment or remediation. Evidence preservation should follow the organization&#8217;s incident-response procedures and access controls. Immediately deleting files or reinstalling the operating system can destroy useful evidence. Credential rotation may be necessary during an incident, but it does not preserve the state of the compromised system itself.<\/span><\/p>\n<h3><b>Question 60<\/b><\/h3>\n<p><b>Which AWS service provides centralized detection findings for security operations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Security Hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon AppStream<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Data Exchange<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Chime SDK<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Security Hub provides a centralized location for reviewing security findings from supported AWS services and integrated third-party products. It can normalize findings into a consistent format and help security teams identify issues across multiple accounts and workloads. Security Hub can also support security standards and automated response workflows when integrated with other AWS services. AppStream provides application streaming, Data Exchange facilitates data subscriptions, and Chime SDK provides communication capabilities. Security Hub is therefore the service designed for centralized security-finding visibility and security operations workflows.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified Security &#8211; Specialty SCS-C02 Exam Dumps and Practice Test Dumps &nbsp; Question 41 Which IAM feature helps identify unused permissions granted to roles? IAM Access Advisor AWS Shield S3 Inventory Amazon Inspector Correct Answer: 1 Explanation: IAM Access Advisor provides information about when AWS services were last accessed by an [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17238"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17238"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17238\/revisions"}],"predecessor-version":[{"id":17239,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17238\/revisions\/17239"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17238"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}