{"id":17256,"date":"2026-09-21T07:23:34","date_gmt":"2026-09-21T07:23:34","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17256"},"modified":"2026-09-21T07:23:34","modified_gmt":"2026-09-21T07:23:34","slug":"amazon-aws-certified-security-specialty-scs-c02-practice-test-questions-and-exam-dumps-part12-q221-240","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-security-specialty-scs-c02-practice-test-questions-and-exam-dumps-part12-q221-240\/","title":{"rendered":"Amazon AWS Certified Security &#8211; Specialty SCS-C02 Practice Test Questions and Exam Dumps Part12 Q221-240"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-security-specialty-scs-c02-exam-dumps\"><b>Amazon AWS Certified Security &#8211; Specialty SCS-C02 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 221<\/b><\/h3>\n<p><b>Which KMS feature lets a customer control how often key material is rotated?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key grants<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key aliases<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key deletion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS KMS key rotation replaces the cryptographic key material associated with a customer managed key according to the configured rotation behavior. Automatic rotation reduces the need for administrators to manually create replacement keys and can help organizations meet internal cryptographic lifecycle requirements. The KMS key itself retains its identity while older key material remains available for decrypting data that was encrypted with it. Grants delegate permissions, aliases provide alternate names for keys, and deletion permanently schedules a key for removal after the required waiting period. Key rotation is therefore the KMS capability specifically concerned with periodically replacing cryptographic material.<\/span><\/p>\n<h3><b>Question 222<\/b><\/h3>\n<p><b>Which S3 encryption option uses two independent layers of encryption?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DSSE-KMS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSE-S3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Client-side encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSE-C<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon S3 dual-layer server-side encryption with AWS KMS keys, known as DSSE-KMS, applies two independent layers of server-side encryption to S3 objects. It is intended for workloads that require an additional layer of protection beyond standard server-side encryption with a KMS key. SSE-S3 uses S3-managed encryption keys, SSE-C allows the customer to provide encryption keys with requests, and client-side encryption occurs before data reaches S3. DSSE-KMS is therefore appropriate when an organization&#8217;s security requirements call for two distinct server-side encryption layers for stored S3 data.<\/span><\/p>\n<h3><b>Question 223<\/b><\/h3>\n<p><b>Which service securely stores application secrets and supports automatic rotation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Secrets Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Secrets Manager is designed to securely store sensitive information such as database credentials, API keys, and application secrets. It can integrate with supported services and Lambda-based rotation workflows to periodically change stored credentials without requiring applications to embed long-lived secrets directly in code. Artifact provides compliance documentation, Inspector identifies workload vulnerabilities, and Config evaluates resource configurations. Secrets Manager is particularly useful when applications need controlled retrieval of credentials at runtime while security teams want centralized management, auditing, and rotation of those secrets.<\/span><\/p>\n<h3><b>Question 224<\/b><\/h3>\n<p><b>Which Systems Manager capability provides shell access without opening inbound SSH ports?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Run Command<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Patch Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">State Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Systems Manager Session Manager provides interactive shell access to supported managed instances without requiring inbound SSH or RDP ports to be opened. Connections are established through Systems Manager infrastructure, allowing organizations to reduce exposure from publicly reachable administration ports. Session activity can also be integrated with logging and auditing mechanisms. Run Command executes commands without providing an interactive session, Patch Manager manages patching operations, and State Manager maintains desired instance configurations. Session Manager is therefore the feature suited for secure interactive administration while minimizing traditional network-based remote-access exposure.<\/span><\/p>\n<h3><b>Question 225<\/b><\/h3>\n<p><b>Which AWS service can create vulnerability findings for container images stored in Amazon ECR?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Detective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Security Hub<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Inspector can scan supported Amazon ECR container images for software vulnerabilities and generate findings when affected packages are identified. This allows security teams to discover known vulnerabilities in container workloads before or during deployment. Inspector can also provide vulnerability information for other supported AWS workloads. Macie focuses on sensitive data discovery, Detective assists with security investigations, and Security Hub aggregates findings from multiple security services. Inspector is therefore the service directly associated with identifying vulnerabilities in container images stored in Amazon ECR.<\/span><\/p>\n<h3><b>Question 226<\/b><\/h3>\n<p><b>Which RDS feature allows database authentication using temporary IAM credentials?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM database authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RDS Proxy authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security group authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">KMS credential federation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon RDS IAM database authentication allows supported database engines to authenticate users through AWS Identity and Access Management instead of requiring a long-lived database password. Applications or users obtain temporary authentication tokens through IAM and use those tokens when connecting to the database. This approach can reduce reliance on permanent database credentials and allows access to be controlled through IAM policies. RDS Proxy provides connection management and pooling, security groups control network connectivity, and KMS handles encryption. IAM database authentication specifically addresses identity-based authentication for supported RDS databases.<\/span><\/p>\n<h3><b>Question 227<\/b><\/h3>\n<p><b>Which EFS configuration protects data while it travels between the client and file system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption at rest<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Transit encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup vault encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Snapshot locking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon EFS supports encryption in transit to protect file-system traffic between an EFS client and the file system. This is distinct from encryption at rest, which protects stored data on the EFS file system. Encryption in transit is particularly important when sensitive information moves across the network during application access. Backup encryption and snapshot controls address data-protection mechanisms rather than the communication channel itself. When an organization needs to protect the confidentiality of EFS traffic while files are being accessed, transit encryption provides the appropriate security control.<\/span><\/p>\n<h3><b>Question 228<\/b><\/h3>\n<p><b>Which AWS feature allows encrypted EBS volumes to use a customer managed KMS key?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EBS encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EC2 placement groups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Instance metadata<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Elastic IP association<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon EBS encryption can use an AWS KMS key to protect volume data, snapshots, and related data encryption operations. Organizations can select a customer managed KMS key when they need greater control over key policies, access, rotation, or auditing. EBS encryption can also be enabled by default for an AWS account and Region, helping ensure newly created volumes are encrypted automatically. Placement groups control instance placement, instance metadata provides information to EC2 instances, and Elastic IP associations concern networking. EBS encryption combined with KMS provides cryptographic protection for block storage resources.<\/span><\/p>\n<h3><b>Question 229<\/b><\/h3>\n<p><b>Which S3 protection helps prevent accidental deletion of versioned objects by requiring MFA?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MFA Delete<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bucket Key<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access Analyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Object Tagging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">S3 MFA Delete adds a multi-factor authentication requirement to certain sensitive operations involving versioned buckets. It can help protect object versions from destructive actions by requiring an additional authentication factor for supported operations. This is particularly useful when an organization wants stronger protection against accidental or unauthorized deletion of retained data. S3 Bucket Keys reduce the number of KMS requests associated with SSE-KMS encryption, Access Analyzer evaluates access policies, and object tagging attaches metadata to objects. MFA Delete specifically addresses additional authentication requirements for certain version-management operations.<\/span><\/p>\n<h3><b>Question 230<\/b><\/h3>\n<p><b>Which AWS service provides DDoS protection for applications at the network and transport layers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Shield provides managed protection against distributed denial-of-service attacks. AWS Shield Standard is automatically available for AWS resources and provides baseline protection against common network and transport layer attacks. AWS Shield Advanced provides additional capabilities for organizations requiring enhanced DDoS protection and response support. AWS WAF focuses on filtering HTTP and HTTPS requests using web application rules, while Inspector identifies vulnerabilities and GuardDuty detects suspicious activity. Shield is therefore the service specifically designed to help protect AWS workloads from DDoS attacks at supported network and transport layers.<\/span><\/p>\n<h3><b>Question 231<\/b><\/h3>\n<p><b>Which IAM control limits permissions that identity policies can grant to a role?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permissions boundary<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trust relationship<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session tag<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access key<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IAM permissions boundary establishes the maximum permissions that an IAM user or role can receive through identity-based policies. It does not grant permissions by itself. Instead, the boundary limits the effective permissions available to the identity. This is useful for delegated administration because administrators can permit teams to create or manage identities while restricting the maximum privileges those identities can obtain. A trust relationship determines who can assume a role, session tags provide contextual attributes during sessions, and access keys provide programmatic credentials. Permissions boundaries specifically address the upper limit of permissions an identity may receive.<\/span><\/p>\n<h3><b>Question 232<\/b><\/h3>\n<p><b>Which service can automatically discover security risks caused by publicly accessible resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM Access Analyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudWatch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Backup<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IAM Access Analyzer can identify resource policies that provide access outside an intended trust boundary, including certain resources that are publicly accessible or accessible from external accounts. These findings can help administrators review resource-based policies and determine whether access is intentional. Artifact provides compliance reports, CloudWatch provides monitoring and observability, and Backup protects data through backup mechanisms. Access Analyzer is particularly useful for identifying unintended external access because it evaluates resource policies and analyzes the resulting access relationships rather than simply monitoring runtime activity.<\/span><\/p>\n<h3><b>Question 233<\/b><\/h3>\n<p><b>Which AWS service helps establish centralized governance for a multi-account environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Control Tower<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Detective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Certificate Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Control Tower helps organizations establish and manage a governed multi-account AWS environment. It provides mechanisms for setting up accounts, applying governance controls, and maintaining consistent organizational standards across accounts. This can simplify security and compliance administration when an organization operates many AWS accounts. Macie focuses on sensitive data discovery, Detective supports security investigations, and Certificate Manager handles certificate management. Control Tower is therefore relevant when the security requirement involves establishing standardized governance and account-level controls across an AWS multi-account architecture.<\/span><\/p>\n<h3><b>Question 234<\/b><\/h3>\n<p><b>Which Organizations capability allows another account to administer a supported service centrally?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service-linked role<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delegated administrator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Root credential<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource share<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Organizations supports delegated administrator accounts for supported AWS services. This allows an organization management account to designate another account to perform administrative tasks for a service across the organization. Delegation can reduce the need to use the management account for routine security administration and supports separation of duties. Service-linked roles allow AWS services to access resources, root credentials belong to the account itself, and resource shares are associated with AWS Resource Access Manager. Delegated administration is the specific Organizations capability used to assign centralized service-management responsibilities to another member account.<\/span><\/p>\n<h3><b>Question 235<\/b><\/h3>\n<p><b>Which AWS service helps enforce firewall policies consistently across an organization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Firewall Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon ECR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Audit Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EventBridge<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Firewall Manager provides centralized management and enforcement of supported firewall policies across accounts and resources in AWS Organizations. It can help security teams maintain consistent protection instead of manually configuring individual accounts. Depending on the supported policy type, Firewall Manager can centrally manage protections involving services such as AWS WAF, AWS Shield Advanced, security groups, and AWS Network Firewall. ECR stores container images, Audit Manager collects evidence for audits, and EventBridge routes events. Firewall Manager is therefore the service designed for organization-wide firewall policy administration.<\/span><\/p>\n<h3><b>Question 236<\/b><\/h3>\n<p><b>Which CloudTrail capability stores events in a managed searchable event data store?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudTrail Lake<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudWatch Metrics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC Flow Logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Inventory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS CloudTrail Lake provides a managed environment for collecting, storing, querying, and analyzing CloudTrail activity in event data stores. It can simplify security investigations and auditing by allowing administrators to run queries against collected event records without building a separate analytics pipeline. CloudWatch Metrics contains monitoring measurements, VPC Flow Logs capture network-flow information, and S3 Inventory reports object metadata. CloudTrail Lake is therefore suited to organizations that need centralized analysis of AWS activity records for security investigations, compliance review, and operational auditing.<\/span><\/p>\n<h3><b>Question 237<\/b><\/h3>\n<p><b>Which event-routing feature allows previously stored EventBridge events to be processed again?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Event archive and replay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudTrail validation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Config snapshot<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 replication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon EventBridge supports event archives and replay, allowing events that were previously stored in an archive to be sent through event processing again. This capability can be useful for testing event-driven applications, recovering from processing issues, or rebuilding downstream state after an incident. CloudTrail log validation verifies log-file integrity, Config snapshots capture resource configuration information, and S3 replication copies objects between supported locations. EventBridge replay is specifically intended to reprocess archived events without requiring the original events to be generated again.<\/span><\/p>\n<h3><b>Question 238<\/b><\/h3>\n<p><b>Which security service can automatically apply actions to findings using automation rules?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Security Hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon EFS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Security Hub supports automation rules that can automatically update or act on security findings based on defined criteria. Organizations can use these rules to standardize repetitive responses, such as changing finding statuses, assigning ownership information, or updating other supported finding fields. This reduces manual work when large numbers of security findings are generated across an environment. Route 53 provides DNS services, Artifact supplies compliance documentation, and EFS provides managed file storage. Security Hub automation rules are therefore appropriate when the objective is to automate consistent handling of centralized security findings.<\/span><\/p>\n<h3><b>Question 239<\/b><\/h3>\n<p><b>Which AWS service provides evidence collection for security and compliance audits?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Audit Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Network Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudFront<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Audit Manager helps organizations collect and organize evidence that can support audits and compliance assessments. It can continuously gather evidence from supported AWS services and map collected information to control requirements and frameworks. This can reduce the manual effort involved in preparing audit evidence and help maintain a structured record of compliance-related information. GuardDuty focuses on threat detection, Network Firewall provides network traffic inspection and filtering, and CloudFront delivers content through a global edge network. Audit Manager is therefore the AWS service specifically focused on evidence collection and audit preparation.<\/span><\/p>\n<h3><b>Question 240<\/b><\/h3>\n<p><b>Which AWS service provides access to compliance reports and agreements from AWS?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Secrets Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Artifact provides on-demand access to AWS security and compliance documentation, including reports and agreements that can help organizations evaluate AWS compliance responsibilities. Security and audit teams can use Artifact when they need official AWS compliance materials for assessments, governance activities, or regulatory documentation. Config evaluates resource configurations, Inspector identifies vulnerabilities, and Secrets Manager securely manages application credentials. Artifact is therefore the appropriate service when an organization needs to obtain AWS compliance reports and related documentation rather than monitor resources or detect security threats.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified Security &#8211; Specialty SCS-C02 Exam Dumps and Practice Test Dumps &nbsp; Question 221 Which KMS feature lets a customer control how often key material is rotated? Key grants Key aliases Key rotation Key deletion Correct Answer: 3 Explanation: AWS KMS key rotation replaces the cryptographic key material associated with a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17256"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17256"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17256\/revisions"}],"predecessor-version":[{"id":17257,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17256\/revisions\/17257"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17256"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17256"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17256"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}