{"id":17270,"date":"2026-09-21T07:26:29","date_gmt":"2026-09-21T07:26:29","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17270"},"modified":"2026-09-21T07:26:29","modified_gmt":"2026-09-21T07:26:29","slug":"amazon-aws-certified-security-specialty-scs-c02-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-security-specialty-scs-c02-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"Amazon AWS Certified Security &#8211; Specialty SCS-C02 Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-security-specialty-scs-c02-exam-dumps\"><b>Amazon AWS Certified Security &#8211; Specialty SCS-C02 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 361<\/b><\/h3>\n<p><b>Which RDS feature encrypts Performance Insights data with a customer managed key?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Performance Insights KMS encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enhanced Monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM database authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database Activity Streams<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon RDS Performance Insights can use AWS KMS encryption to protect its stored performance-related data. Organizations with stricter key-management requirements can use a customer managed KMS key where supported, allowing additional control through key policies and lifecycle management. Enhanced Monitoring provides operating-system-level metrics, IAM database authentication controls database login using IAM credentials, and Database Activity Streams captures database activity for auditing purposes. Performance Insights KMS encryption specifically addresses protection of Performance Insights data rather than database storage or authentication. This separation helps security teams apply appropriate encryption and authorization controls to different RDS security requirements.<\/span><\/p>\n<h3><b>Question 362<\/b><\/h3>\n<p><b>Which Secrets Manager feature allows a secret to be accessed by another AWS account?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatic rotation schedule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replica Region configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secret resource policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secret version staging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Secrets Manager supports resource-based policies that can authorize principals from another AWS account to access a secret, subject to the required permissions and conditions. This is useful when applications in separate accounts need controlled access to centrally managed credentials. Resource policies should be narrowly scoped and combined with appropriate identity permissions and encryption controls. Automatic rotation changes secret credentials on a defined schedule, version staging identifies versions such as current or previous values, and replica configuration copies supported secrets to another Region. A secret resource policy is the mechanism directly used to establish cross-account access.<\/span><\/p>\n<h3><b>Question 363<\/b><\/h3>\n<p><b>What does an S3 legal hold provide?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Faster object retrieval<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatic encryption rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatic object deletion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Indefinite preservation independent of retention periods<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An S3 Object Lock legal hold prevents an object version from being overwritten or deleted until the legal hold is explicitly removed. Unlike a retention period, a legal hold does not depend on a predetermined expiration date. This makes it useful when records must be preserved for an unresolved investigation, litigation, or regulatory matter. Object retrieval performance is unrelated to legal holds, and encryption key rotation is managed through KMS rather than S3 legal-hold functionality. Automatic deletion is also contrary to the purpose of a legal hold. The key security benefit is preservation until an authorized process releases the hold.<\/span><\/p>\n<h3><b>Question 364<\/b><\/h3>\n<p><b>Which EBS capability protects newly created volumes without requiring each user to select encryption manually?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Elastic Volumes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EBS encryption by default<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fast Snapshot Restore<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Snapshot lifecycle policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EBS encryption by default establishes automatic encryption for newly created supported EBS volumes and related resources in a Region. This reduces configuration mistakes because users do not need to remember to select encryption during every volume creation workflow. Organizations can also designate a KMS key for default encryption according to supported EBS settings. Snapshot lifecycle policies automate snapshot management, Elastic Volumes supports volume modification, and Fast Snapshot Restore improves snapshot-based volume initialization performance. Encryption by default is the preventive security control that establishes encrypted storage as the standard for new EBS resources.<\/span><\/p>\n<h3><b>Question 365<\/b><\/h3>\n<p><b>Which CloudTrail configuration can capture object-level activity in an S3 bucket?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data event selector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Management event selector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Insight event rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network event filter<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CloudTrail data events provide visibility into object-level actions such as supported S3 object API activity. Examples include operations that access, create, or delete objects. Data events are different from management events, which generally record control-plane operations such as changing bucket configuration or modifying IAM-related resources. Because data events can generate a high volume of records, organizations commonly enable them selectively for sensitive resources. Insight events identify unusual management API activity patterns, while the other listed options do not represent the CloudTrail configuration used for S3 object-level auditing.<\/span><\/p>\n<h3><b>Question 366<\/b><\/h3>\n<p><b>Which Amazon GuardDuty capability monitors supported RDS database activity for threats?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Malware Protection for S3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EKS Audit Monitoring<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RDS Protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Macie Sensitive Data Discovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon GuardDuty RDS Protection is designed to monitor supported Amazon Aurora database activity and identify potentially suspicious behavior. It extends GuardDuty&#8217;s threat-detection capabilities into the database layer, helping security teams identify activity that may indicate compromised credentials or unusual access patterns. Malware Protection for S3 focuses on scanning uploaded S3 objects for malware-related threats, while Macie focuses on sensitive data discovery. EKS-related monitoring addresses Kubernetes environments. RDS Protection is therefore the GuardDuty capability associated specifically with supported database activity.<\/span><\/p>\n<h3><b>Question 367<\/b><\/h3>\n<p><b>Which VPC feature can record accepted and rejected network traffic metadata?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC Peering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC Flow Logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internet Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Elastic IP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VPC Flow Logs capture metadata about network traffic to and from supported network interfaces. Depending on configuration and flow-log format, records can include source and destination addresses, ports, protocols, packet information, and whether traffic was accepted or rejected. This information is valuable during incident investigations because it can reveal unexpected communication paths or blocked connections. VPC peering connects networks, an Internet Gateway provides connectivity for supported internet-bound traffic, and an Elastic IP provides a static public IPv4 address. None of these features independently provides network-flow logging.<\/span><\/p>\n<h3><b>Question 368<\/b><\/h3>\n<p><b>Which IAM feature can require users to authenticate with MFA before sensitive API actions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 replication configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM policy MFA condition<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudFront response policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EBS snapshot archive<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IAM policies can use MFA-related condition keys to require multi-factor authentication for specific operations. This allows organizations to apply stronger authentication requirements to sensitive actions rather than treating every API request identically. A policy can evaluate whether the request was made using MFA and deny selected operations when that requirement is not satisfied. S3 replication controls object replication, CloudFront response policies influence response headers, and EBS snapshot archive concerns snapshot storage options. The IAM MFA condition directly provides policy-based enforcement for authentication-sensitive API actions.<\/span><\/p>\n<h3><b>Question 369<\/b><\/h3>\n<p><b>Which AWS service can automatically rotate supported database credentials stored as secrets?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Secrets Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Detective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield Advanced<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Secrets Manager supports automatic rotation for supported secrets and integrated services, including supported database credentials. Rotation can periodically generate new credentials and update the corresponding secret, reducing the lifetime of static passwords. This is a key security practice because credentials that remain unchanged for long periods provide a larger window of opportunity if exposed. AWS Artifact provides compliance documentation, Detective supports security investigations, and Shield Advanced provides enhanced DDoS protection. Secrets Manager is the service specifically designed to centrally store, retrieve, and rotate application credentials and other sensitive secrets.<\/span><\/p>\n<h3><b>Question 370<\/b><\/h3>\n<p><b>Which security control can block traffic based on domain names in VPC DNS queries?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network Load Balancer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route 53 Resolver DNS Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC Traffic Mirroring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route 53 Resolver DNS Firewall allows organizations to control DNS queries originating from VPC resources by using domain lists and rule groups. Security teams can block or alert on queries for domains associated with malware, command-and-control infrastructure, or other prohibited destinations. Because DNS resolution occurs before many application connections are established, this can provide an additional preventive layer for outbound traffic. A Network Load Balancer distributes network connections, a NAT Gateway provides address translation, and Traffic Mirroring copies network traffic for inspection. DNS Firewall specifically addresses domain-based DNS query control.<\/span><\/p>\n<h3><b>Question 371<\/b><\/h3>\n<p><b>Which AWS service centrally manages supported firewall policies across multiple accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Systems Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Private CA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Firewall Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Firewall Manager provides centralized management of supported security policies across accounts and resources in an AWS Organization. It can help administrators apply and maintain policies for services such as AWS WAF, AWS Shield Advanced, security groups, and AWS Network Firewall according to supported configurations. This is particularly useful in multi-account environments where individually configuring every account can lead to inconsistent controls. Inspector focuses on vulnerability assessment, Systems Manager manages operational tasks, and Private CA manages private certificates. Firewall Manager is the service designed for centralized firewall-policy administration.<\/span><\/p>\n<h3><b>Question 372<\/b><\/h3>\n<p><b>Which KMS feature can limit a grant to a specific encryption context?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key alias<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Grant constraint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Key rotation schedule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Imported key material<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">KMS grants can include constraints that limit how the granted permissions may be used. An encryption-context constraint can require cryptographic requests to contain an appropriate encryption context before the grant is effective. This provides an additional layer of authorization and can help ensure that delegated key use is tied to a particular application or data context. Key aliases provide alternate names, rotation schedules govern supported key-material rotation, and imported key material concerns the origin of cryptographic material. Grant constraints are specifically intended to narrow the circumstances under which delegated KMS permissions can be exercised.<\/span><\/p>\n<h3><b>Question 373<\/b><\/h3>\n<p><b>Which service helps enforce preventive controls across AWS Organizations accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Organizations SCPs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudFront<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Audit Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Service control policies, or SCPs, are organization-level controls that define the maximum available permissions for principals within affected AWS accounts. They can prevent actions such as using certain services, creating resources in prohibited Regions, or modifying protected configurations. SCPs do not grant permissions themselves; IAM policies are still required to authorize allowed actions. Macie focuses on S3 sensitive-data discovery, CloudFront provides content delivery, and Audit Manager collects evidence for assessments. SCPs are therefore the preventive governance mechanism used to establish permission boundaries across accounts in AWS Organizations.<\/span><\/p>\n<h3><b>Question 374<\/b><\/h3>\n<p><b>Which AWS feature can detect whether an IAM policy grants access to an external principal?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Backup<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudWatch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM Access Analyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Control Tower<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IAM Access Analyzer helps identify resources that are accessible from outside an intended trust boundary, such as an AWS account or organization. It analyzes resource-based policies and can generate findings when resources are configured to allow access by external principals. This is useful for detecting unintended public or cross-account exposure. AWS Backup protects data through backup workflows, CloudWatch provides monitoring and observability, and Control Tower helps establish and govern multi-account environments. Access Analyzer is the appropriate service for analyzing resource policies and identifying unintended external access.<\/span><\/p>\n<h3><b>Question 375<\/b><\/h3>\n<p><b>Which S3 control can restrict access through a specific access point?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage Lens dashboard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Access point policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Inventory configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lifecycle transition<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An S3 access point can have its own resource policy that defines which principals can use that access point and under what conditions. This allows organizations to create different controlled entry points to the same bucket for different applications, teams, or environments. Access point policies can complement the underlying bucket policy and other S3 authorization controls. Storage Lens provides visibility into storage usage and activity, Inventory produces object reports, and Lifecycle controls retention or storage transitions. The access point policy is the mechanism specifically designed to govern access through an individual S3 access point.<\/span><\/p>\n<h3><b>Question 376<\/b><\/h3>\n<p><b>Which service can scan container images for known software vulnerabilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Secrets Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudTrail<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Inspector supports vulnerability assessment for container images stored in Amazon Elastic Container Registry, or Amazon ECR. It can identify known software vulnerabilities in packages contained within supported images and generate findings for security teams. This helps organizations detect vulnerable dependencies before images are deployed or while they remain in the registry. Secrets Manager manages sensitive credentials, Route 53 provides DNS functionality, and CloudTrail records API activity. Inspector is therefore the service among these choices directly associated with vulnerability scanning of supported container images.<\/span><\/p>\n<h3><b>Question 377<\/b><\/h3>\n<p><b>Which AWS capability can automatically remediate a noncompliant resource after an AWS Config finding?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudFront cache behavior<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 replication rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Config remediation action<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">KMS alias<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Config supports remediation actions that can automatically invoke supported Systems Manager Automation documents when a resource is found to be noncompliant. This allows organizations to move from detection toward corrective action. For example, a remediation workflow can address an insecure configuration after a Config rule identifies it. CloudFront cache behaviors control content delivery, S3 replication moves objects between destinations, and KMS aliases provide alternate key names. Config remediation is therefore useful for building automated compliance workflows that detect and correct security configuration drift.<\/span><\/p>\n<h3><b>Question 378<\/b><\/h3>\n<p><b>Which AWS service provides managed DDoS protection for applications and resources?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon ECR<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Shield provides managed protection against distributed denial-of-service attacks for supported AWS resources. Shield Standard is automatically available for supported AWS services, while Shield Advanced provides additional capabilities and protections for organizations with more demanding DDoS defense requirements. Macie identifies sensitive data in S3, Config evaluates resource configurations, and ECR stores container images. DDoS protection focuses on maintaining availability when malicious traffic attempts to overwhelm network or application resources. Shield is therefore the AWS service specifically dedicated to managed DDoS protection.<\/span><\/p>\n<h3><b>Question 379<\/b><\/h3>\n<p><b>Which IAM concept allows temporary credentials to inherit additional restrictions during role assumption?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 replication metrics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudTrail digest files<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session tags<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ACM renewal rules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IAM session tags are attributes passed into a role session and can be used with policy conditions to implement attribute-based access-control designs. When configured appropriately, session attributes can influence authorization decisions and help organizations apply contextual restrictions to temporary credentials. This is useful in environments where access should depend on characteristics such as project, department, or workload context. S3 replication metrics monitor replication activity, CloudTrail digest files support log-integrity validation, and ACM renewal handles certificate lifecycle operations. Session tags specifically provide contextual information that can participate in authorization decisions during role sessions.<\/span><\/p>\n<h3><b>Question 380<\/b><\/h3>\n<p><b>Which AWS service can provide a centralized, normalized security data lake?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Security Lake<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Certificate Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon ElastiCache<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Database Migration Service<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Security Lake is designed to centrally collect security-related data from supported AWS, third-party, and custom sources and normalize it using the Open Cybersecurity Schema Framework. This creates a centralized security data lake that can support threat detection, investigation, analytics, and downstream security tooling. Certificate Manager handles certificate issuance and management, ElastiCache provides in-memory caching, and Database Migration Service supports database migration workflows. Security Lake is specifically designed for centralized security-data collection and normalization across diverse security sources.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified Security &#8211; Specialty SCS-C02 Exam Dumps and Practice Test Dumps &nbsp; Question 361 Which RDS feature encrypts Performance Insights data with a customer managed key? Performance Insights KMS encryption Enhanced Monitoring IAM database authentication Database Activity Streams Correct Answer: 1 Explanation: Amazon RDS Performance Insights can use AWS KMS encryption [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17270"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17270"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17270\/revisions"}],"predecessor-version":[{"id":17271,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17270\/revisions\/17271"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17270"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17270"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17270"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}