{"id":17268,"date":"2026-09-21T07:25:36","date_gmt":"2026-09-21T07:25:36","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17268"},"modified":"2026-09-21T07:25:36","modified_gmt":"2026-09-21T07:25:36","slug":"amazon-aws-certified-security-specialty-scs-c02-practice-test-questions-and-exam-dumps-part18-q341-360","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-security-specialty-scs-c02-practice-test-questions-and-exam-dumps-part18-q341-360\/","title":{"rendered":"Amazon AWS Certified Security &#8211; Specialty SCS-C02 Practice Test Questions and Exam Dumps Part18 Q341-360"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-security-specialty-scs-c02-exam-dumps\"><b>Amazon AWS Certified Security &#8211; Specialty SCS-C02 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 341<\/b><\/h3>\n<p><b>Which S3 feature can retain deleted objects for forensic investigation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Transfer Acceleration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Select<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Batch Operations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Versioning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon S3 Versioning preserves multiple versions of an object, including versions that result from overwrite or deletion operations. This can be valuable during security investigations because a deleted or modified object may still have an earlier version available for examination. Security teams can combine versioning with Object Lock, restrictive permissions, and logging to strengthen evidence preservation. Transfer Acceleration improves transfer performance, S3 Select filters object contents during retrieval, and Batch Operations performs large-scale object actions. Versioning specifically provides historical object states that can assist with recovery and forensic analysis after accidental or malicious changes.<\/span><\/p>\n<h3><b>Question 342<\/b><\/h3>\n<p><b>Which IAM feature limits a role session beyond its attached permissions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service control policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource tag<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity center directory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IAM session policy can further restrict the permissions available during a particular role session. It does not expand the permissions granted by the role. Instead, the effective permissions are constrained by the intersection of the role&#8217;s identity-based permissions and the applicable session policy. This can be useful when temporary credentials need narrower access than the underlying role normally permits. Service control policies establish organization-level permission boundaries, resource tags provide metadata for resources, and an IAM Identity Center directory manages identities. Session policies are specifically useful when temporary role sessions require additional permission restrictions.<\/span><\/p>\n<h3><b>Question 343<\/b><\/h3>\n<p><b>What does AWS RAM primarily enable across AWS accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sharing supported resources<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encrypting EBS volumes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Inspecting container images<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recording API events<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Resource Access Manager, or AWS RAM, allows supported AWS resources to be shared across AWS accounts, organizational units, or an entire AWS Organization. Resource sharing can reduce duplication and centralize infrastructure while maintaining controlled access. Examples of shareable resources include certain network and infrastructure components. RAM itself does not provide encryption for EBS volumes, vulnerability scanning for container images, or API-event recording. Those responsibilities belong to other AWS services. From a security perspective, RAM should be configured carefully so that shared resources are exposed only to intended principals and accounts.<\/span><\/p>\n<h3><b>Question 344<\/b><\/h3>\n<p><b>Which control can prevent an S3 bucket from accepting unencrypted uploads?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bucket policy requiring encryption headers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Lifecycle<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multipart upload configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An S3 bucket policy can require specific encryption-related request attributes before allowing an object upload. For example, a policy can deny PutObject requests that do not use an approved server-side encryption mechanism. This creates a preventive control rather than merely detecting unencrypted objects after they arrive. S3 Inventory produces reports about stored objects, Lifecycle manages retention and transitions, and multipart upload controls how large objects are uploaded in parts. A bucket policy is therefore the appropriate mechanism for enforcing encryption requirements at the time objects are written.<\/span><\/p>\n<h3><b>Question 345<\/b><\/h3>\n<p><b>Which AWS capability can create a private certificate authority hierarchy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Private Certificate Authority<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Detective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Private Certificate Authority, commonly called AWS Private CA, allows organizations to create and operate private certificate authorities within AWS. It can issue certificates for internal applications, services, devices, and workloads that do not need certificates from a public certificate authority. Organizations can establish CA hierarchies and integrate certificate issuance with supported AWS services and applications. Detective focuses on security investigations, Shield provides DDoS protection, and Inspector assesses vulnerabilities. Private CA is therefore the appropriate service when an organization requires its own internal public-key infrastructure and certificate issuance capability.<\/span><\/p>\n<h3><b>Question 346<\/b><\/h3>\n<p><b>What is a primary security benefit of EBS encryption by default?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It blocks all snapshot creation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It automatically encrypts new supported volumes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It disables cross-account access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It removes the need for IAM<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EBS encryption by default ensures that newly created supported EBS volumes and certain related resources are encrypted automatically within the configured Region. This reduces the possibility that an administrator or application accidentally creates unencrypted storage. Organizations can use AWS managed or customer managed KMS keys according to their requirements. The setting does not prevent snapshot creation, eliminate all cross-account access considerations, or replace IAM authorization. Encryption by default is primarily a preventive storage-protection measure that establishes encryption as the standard behavior for new EBS resources.<\/span><\/p>\n<h3><b>Question 347<\/b><\/h3>\n<p><b>Which RDS capability protects database storage using AWS KMS encryption?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance Insights<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enhanced Monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encryption at rest<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database Activity Streams<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon RDS encryption at rest protects supported database storage, automated backups, read replicas, and snapshots associated with an encrypted database using AWS KMS. Customer managed KMS keys can provide additional control over key policies and lifecycle management. Encryption at rest is distinct from monitoring and auditing capabilities. Performance Insights provides database performance information, Enhanced Monitoring supplies operating-system metrics, and Database Activity Streams focuses on database activity auditing for supported engines. For protecting the underlying stored database data from unauthorized access to storage media, RDS encryption at rest is the relevant security control.<\/span><\/p>\n<h3><b>Question 348<\/b><\/h3>\n<p><b>Which mechanism can restrict an interface VPC endpoint to selected API actions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Endpoint policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network ACL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route table propagation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP option set<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An interface VPC endpoint can have an endpoint policy that controls which principals can perform supported actions through the endpoint. This provides an additional authorization layer for private access to AWS services. For example, an organization may permit access to a service while limiting the specific resources or operations that can be reached through the endpoint. Network ACLs operate at the subnet network boundary, route tables control traffic paths, and DHCP option sets provide network configuration parameters. Endpoint policies are therefore the mechanism designed to refine authorization for traffic reaching supported AWS services through VPC endpoints.<\/span><\/p>\n<h3><b>Question 349<\/b><\/h3>\n<p><b>Which GuardDuty protection can identify suspicious activity involving Amazon EKS clusters?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EKS Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Macie classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Config conformance packs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudTrail Lake<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon GuardDuty EKS Protection extends threat detection to Kubernetes activity associated with Amazon EKS. It can analyze relevant activity and generate findings when behavior matches supported threat-detection scenarios. This helps security teams identify suspicious actions involving containerized workloads without relying exclusively on traditional host-based controls. Macie focuses on sensitive S3 data, AWS Config evaluates resource configuration, and CloudTrail Lake provides storage and querying capabilities for CloudTrail events. EKS Protection is therefore the GuardDuty capability specifically associated with security monitoring of EKS environments.<\/span><\/p>\n<h3><b>Question 350<\/b><\/h3>\n<p><b>Which control helps prevent unrestricted cross-account use of a KMS key?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">KMS alias naming<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key policy authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudWatch dashboard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 replication rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">KMS key policies determine which principals are authorized to use or manage a customer managed KMS key. When cross-account access is required, the key policy and the requesting account&#8217;s IAM permissions must be configured consistently. Administrators can use explicit principals and conditions to narrow the permitted access rather than allowing broad account-level usage. An alias provides a convenient key identifier, CloudWatch dashboards visualize metrics, and S3 replication moves objects between buckets. The key policy is therefore the central control for limiting who can use a KMS key across account boundaries.<\/span><\/p>\n<h3><b>Question 351<\/b><\/h3>\n<p><b>Which service can continuously evaluate AWS resource configurations against security rules?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Cognito<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudFront<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Config records resource configurations and evaluates them against configurable rules. Security teams can use Config rules to identify resources that violate organizational requirements, such as overly permissive security groups, missing encryption settings, or unsupported configurations. Config can also provide historical configuration information that helps investigators understand when a resource changed. Cognito provides application identity capabilities, Artifact provides AWS compliance documentation, and CloudFront delivers content through a global distribution network. AWS Config is therefore the service used for continuous configuration assessment against defined compliance or security requirements.<\/span><\/p>\n<h3><b>Question 352<\/b><\/h3>\n<p><b>What is the main purpose of a Security Hub automation rule?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Create IAM users<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatically update matching findings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Encrypt S3 objects<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rotate database credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Security Hub automation rules allow organizations to automatically update security findings when they match defined criteria. Rules can be used to change finding status, severity, workflow status, or other supported attributes based on organizational processes. This reduces repetitive manual handling and helps standardize security operations. Automation rules do not create IAM users, directly encrypt S3 objects, or rotate database credentials. Those tasks are handled through other AWS services and controls. Security Hub automation is particularly useful for routing, suppressing, prioritizing, or updating findings according to consistent operational conditions.<\/span><\/p>\n<h3><b>Question 353<\/b><\/h3>\n<p><b>Which S3 Object Lock mode prevents protected objects from being permanently deleted before retention expires?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Governance mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compliance mode<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Intelligent-Tiering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">One Zone-IA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">S3 Object Lock Compliance mode provides strong immutability by preventing protected object versions from being deleted or overwritten during their retention period, including by users with elevated permissions. This makes it appropriate for situations where regulatory or legal requirements demand strict write-once-read-many behavior. Governance mode provides retention protection with special administrative considerations, while Intelligent-Tiering and One Zone-IA are storage classes rather than retention controls. Compliance mode is particularly important when evidence or regulated records must remain immutable for a defined period and ordinary administrative privileges should not bypass the retention requirement.<\/span><\/p>\n<h3><b>Question 354<\/b><\/h3>\n<p><b>Which AWS service can aggregate findings from multiple security services into one view?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Secrets Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Security Hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Private CA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Security Hub provides centralized visibility into security findings from supported AWS services and integrated third-party security products. It normalizes findings and presents them in a consolidated security view, making it easier for teams to identify and manage security issues across accounts and Regions. Security Hub can also support standards checks and automated finding workflows. Secrets Manager manages credentials and secrets, Private CA manages private certificates, and Route 53 provides DNS services. Security Hub is therefore the service designed to consolidate security findings from multiple sources into a central operational view.<\/span><\/p>\n<h3><b>Question 355<\/b><\/h3>\n<p><b>Which mechanism can identify unusual API activity for investigation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudTrail event history<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 storage class<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ACM certificate renewal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EBS volume type<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS CloudTrail event history provides a searchable record of recent management activity made through AWS APIs, consoles, SDKs, and command-line tools. Security teams can use it to investigate unexpected actions such as changes to IAM permissions, security groups, KMS policies, or resource configurations. For longer-term centralized analysis, organizations can also configure trails or CloudTrail Lake. S3 storage classes manage object storage characteristics, ACM handles certificates, and EBS volume types determine storage performance characteristics. CloudTrail event history is therefore a practical starting point when investigating suspicious API activity.<\/span><\/p>\n<h3><b>Question 356<\/b><\/h3>\n<p><b>Which feature can require MFA before a role is assumed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 bucket notification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM trust-policy condition<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudFront invalidation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC endpoint route<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IAM role trust policy can include conditions that require MFA for role assumption. This is useful when organizations want stronger authentication assurance before granting temporary elevated or sensitive permissions. The trust relationship can combine the trusted principal with conditions such as MFA requirements and other supported context keys. S3 notifications trigger downstream actions when bucket events occur, CloudFront invalidations remove cached content, and VPC routing determines packet paths. The trust-policy condition directly controls whether an authentication requirement is satisfied before the principal can obtain the role&#8217;s temporary credentials.<\/span><\/p>\n<h3><b>Question 357<\/b><\/h3>\n<p><b>Which AWS service is designed to investigate relationships among security events and resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Firewall Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Detective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Certificate Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon ECR<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Detective helps security teams investigate security findings by analyzing relationships among resources, users, IP addresses, API activity, and other relevant behavior. It builds an investigation-oriented view from supported data sources, helping analysts understand what happened before, during, and after suspicious activity. Firewall Manager centrally manages supported security policies, Certificate Manager handles certificates, and Amazon ECR provides container image storage. Detective is therefore particularly useful after a security alert has been generated and analysts need contextual information to understand the sequence and relationships associated with the event.<\/span><\/p>\n<h3><b>Question 358<\/b><\/h3>\n<p><b>Which backup control can help enforce immutable retention requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backup Vault Lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EC2 user data<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route 53 Resolver rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM access key<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Backup Vault Lock helps enforce retention controls for recovery points stored in a backup vault. Once configured according to its supported settings and requirements, it can prevent backup recovery points from being prematurely deleted or retention periods from being shortened. This provides an important defense against attempts to destroy backups during ransomware or other destructive incidents. EC2 user data configures instance initialization behavior, Resolver rules influence DNS resolution, and IAM access keys provide programmatic credentials. Backup Vault Lock specifically addresses immutability and retention protection for backups.<\/span><\/p>\n<h3><b>Question 359<\/b><\/h3>\n<p><b>Which service can detect exposed secrets in source-code repositories?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CodeGuru Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon CodeGuru Security can identify security vulnerabilities and coding issues in application source code, including certain types of sensitive information exposure. Detecting credentials or secrets in code is important because committed credentials can potentially be used to access AWS resources or other systems. Security teams should combine automated detection with credential revocation, secure secret storage, and repository controls. AWS WAF protects web applications from supported request threats, Macie focuses on sensitive data in S3, and Shield provides DDoS protection. CodeGuru Security is therefore the relevant application-code security capability among these choices.<\/span><\/p>\n<h3><b>Question 360<\/b><\/h3>\n<p><b>Which IAM mechanism can require a specific organizational context for requests?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Object Lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">aws:PrincipalOrgID condition<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">KMS automatic rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudTrail Insights<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><b><br \/>\n<\/b><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The aws:PrincipalOrgID global condition key can be used in supported resource policies to restrict access to principals belonging to a specific AWS Organization. This is useful for creating organization-wide data access boundaries while avoiding long lists of individual account IDs. For example, a resource policy can permit access only when the requesting principal belongs to the organization&#8217;s identifier. S3 Object Lock controls object retention, KMS automatic rotation manages supported key material rotation, and CloudTrail Insights detects unusual API activity patterns. The organization ID condition directly addresses organizational-context authorization.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified Security &#8211; Specialty SCS-C02 Exam Dumps and Practice Test Dumps &nbsp; Question 341 Which S3 feature can retain deleted objects for forensic investigation? S3 Transfer Acceleration S3 Select S3 Batch Operations S3 Versioning Correct Answer: 4 Explanation: Amazon S3 Versioning preserves multiple versions of an object, including versions that result [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17268"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17268"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17268\/revisions"}],"predecessor-version":[{"id":17269,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17268\/revisions\/17269"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17268"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17268"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17268"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}