{"id":22034,"date":"2026-09-25T10:34:50","date_gmt":"2026-09-25T10:34:50","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22034"},"modified":"2026-09-25T10:34:50","modified_gmt":"2026-09-25T10:34:50","slug":"amazon-aws-certified-security-specialty-scs-c03-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-security-specialty-scs-c03-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"Amazon AWS Certified Security &#8211; Specialty SCS-C03 Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-security-specialty-scs-c03-exam-dumps\"><b>Amazon AWS Certified Security &#8211; Specialty SCS-C03 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 81<\/b><\/h3>\n<p><b>Which AWS service can identify sensitive data stored in Amazon S3 buckets?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Detective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Macie is designed to discover and help protect sensitive data stored in Amazon S3. It uses automated discovery and machine learning techniques to identify sensitive information and can generate findings when potentially sensitive data is detected. Security teams can use Macie to understand where sensitive information exists and investigate unexpected exposure. Macie complements access controls, encryption, logging, and data-loss prevention processes. It does not replace IAM or S3 bucket policies, which remain essential for controlling who can access protected objects.<\/span><\/p>\n<h3><b>Question 82<\/b><\/h3>\n<p><b>A company wants to require MFA when users perform sensitive IAM operations. Which policy mechanism can enforce this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM policy condition using MFA context<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 lifecycle configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC route table<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF managed rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IAM policies can use MFA-related condition keys to require multi-factor authentication for sensitive operations. For example, an organization can require users to authenticate with MFA before performing particular actions or accessing protected resources. This provides an additional authentication control beyond a password or other primary credential. The policy must be designed carefully so that required administrative workflows remain functional. Organizations should also protect the root user with MFA and use stronger identity-management practices such as federation and temporary credentials whenever appropriate.<\/span><\/p>\n<h3><b>Question 83<\/b><\/h3>\n<p><b>Which AWS service provides a centralized location for security findings from multiple AWS security services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudWatch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Security Hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Certificate Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Security Hub provides centralized aggregation and management of security findings from supported AWS services and integrated third-party products. It helps security teams review findings in a consolidated view instead of investigating each security service independently. Security Hub can also support automation through integrations with services such as EventBridge. This centralized approach can improve visibility across accounts and workloads. Organizations should still establish severity, ownership, remediation, and escalation processes because collecting findings alone does not automatically resolve security issues.<\/span><\/p>\n<h3><b>Question 84<\/b><\/h3>\n<p><b>An administrator needs temporary permissions to access an AWS account without creating a long-term access key. Which AWS service should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS STS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Security Token Service provides temporary security credentials that can be used to access AWS resources for a limited period. Temporary credentials are useful for federation, cross-account access, applications, and other situations where permanent credentials would create unnecessary risk. They typically include an access key ID, secret access key, and session token. Security teams should grant only the permissions required for the session and configure appropriate session durations. Temporary credentials reduce the risks associated with distributing and storing long-lived access keys.<\/span><\/p>\n<h3><b>Question 85<\/b><\/h3>\n<p><b>Which AWS service can analyze relationships between AWS resources and help investigators understand the potential impact of a security event?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Detective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Certificate Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Detective helps security teams investigate security findings by analyzing relationships and activity associated with AWS resources. It can provide contextual information that helps analysts understand what happened, which resources were involved, and how activity may be connected. Detective is particularly useful after a suspicious event has been identified by another security service. It complements detection services such as GuardDuty and centralized finding services such as Security Hub. Investigators should combine Detective insights with CloudTrail, network logs, and application evidence.<\/span><\/p>\n<h3><b>Question 86<\/b><\/h3>\n<p><b>Which control is most appropriate for preventing resources in a development account from using services that the organization prohibits?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service control policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 bucket policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM permissions boundary<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A service control policy can define permission guardrails for accounts within AWS Organizations. SCPs do not grant permissions themselves; instead, they limit the maximum permissions available to principals in affected accounts. This makes them useful for enforcing organization-wide restrictions, such as preventing the use of particular AWS services or actions. Administrators should understand that SCPs apply at the account or organizational level and must be combined with identity-based or resource-based policies that actually grant required permissions.<\/span><\/p>\n<h3><b>Question 87<\/b><\/h3>\n<p><b>A security analyst needs to determine whether an EC2 instance communicated with a suspicious IP address. Which log source is particularly useful for reviewing network connection metadata?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC Flow Logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Audit Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VPC Flow Logs provide metadata about network traffic to and from network interfaces. Analysts can use them to investigate whether an EC2 instance communicated with a particular IP address, identify accepted or rejected traffic, and establish network activity timelines. Flow Logs do not contain packet payloads, so they cannot by themselves reveal the contents of communications. Security teams can combine flow-log information with GuardDuty findings, DNS logs, CloudTrail events, and host-level evidence to develop a more complete understanding of suspicious network activity.<\/span><\/p>\n<h3><b>Question 88<\/b><\/h3>\n<p><b>Which AWS service can provide a managed public key infrastructure for issuing private certificates?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Private Certificate Authority<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Firewall Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Private Certificate Authority provides a managed private certificate authority service that organizations can use to issue and manage private digital certificates. Private certificates can support internal applications, services, devices, and TLS-based authentication requirements. The service reduces the need to operate a certificate authority infrastructure entirely on-premises. Security teams should carefully protect CA permissions and establish certificate issuance policies because compromise or misuse of a private CA can affect many systems. Certificate lifecycle management should include issuance, renewal, revocation, and monitoring.<\/span><\/p>\n<h3><b>Question 89<\/b><\/h3>\n<p><b>A company wants to centrally manage firewall rules across multiple AWS accounts and Regions. Which service is designed for this purpose?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Firewall Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Detective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Firewall Manager provides centralized management of firewall and security policies across AWS accounts and resources. It can help organizations apply consistent protections for supported AWS WAF configurations, security groups, Network Firewall policies, and other supported controls. This is especially useful in multi-account environments where manually maintaining security configurations can result in inconsistent controls. Firewall Manager works with AWS Organizations and can enforce centrally managed policies while allowing teams to maintain appropriate application-specific configurations within organizational guardrails.<\/span><\/p>\n<h3><b>Question 90<\/b><\/h3>\n<p><b>Which S3 security feature can help prevent a bucket from becoming publicly accessible because of an accidental access policy or ACL configuration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Versioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Transfer Acceleration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Block Public Access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Inventory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon S3 Block Public Access provides centralized controls that help prevent public access to S3 buckets and objects through several types of public policies and ACL configurations. It is an important preventive control because accidental changes to bucket permissions can otherwise expose sensitive data. Organizations can configure Block Public Access at the account, bucket, or other supported levels. This control should be combined with least-privilege IAM policies, bucket policies, encryption, logging, and continuous monitoring to provide comprehensive S3 security.<\/span><\/p>\n<h3><b>Question 91<\/b><\/h3>\n<p><b>Which AWS service records actions performed through the AWS Management Console, AWS CLI, and AWS SDKs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudTrail<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS CloudTrail records AWS API activity generated through the console, command-line tools, SDKs, and supported AWS services. Events can include information about the identity that made a request, the action performed, the resource involved, and when the activity occurred. CloudTrail is therefore an important source of evidence for security investigations and auditing. Organizations should configure appropriate trails or event data stores, protect log destinations, establish retention requirements, and monitor significant events to detect suspicious administrative activity.<\/span><\/p>\n<h3><b>Question 92<\/b><\/h3>\n<p><b>A security team wants to detect potentially malicious behavior affecting AWS accounts and workloads. Which service is specifically designed for threat detection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Audit Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon GuardDuty is a threat detection service that continuously analyzes supported AWS data sources and signals to identify potentially malicious or unauthorized activity. It can generate findings related to suspicious behavior involving accounts, workloads, and other supported resources. Security teams can investigate GuardDuty findings using services such as Security Hub and Detective. Findings should be validated and correlated with additional evidence when determining scope and impact. GuardDuty is a detection capability and should operate alongside preventive controls, logging, response procedures, and recovery processes.<\/span><\/p>\n<h3><b>Question 93<\/b><\/h3>\n<p><b>Which AWS capability can enforce organization-wide restrictions even when an administrator in an individual account has broad IAM permissions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM access key<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Service control policies provide organization-level permission guardrails that can restrict what actions principals in member accounts are allowed to perform. An SCP does not grant permissions, but it can prevent actions even when an identity-based policy in the account would otherwise allow them. This makes SCPs valuable for enforcing centralized security requirements across multiple accounts. Administrators should carefully test SCP changes because overly restrictive policies can disrupt legitimate workloads. Exceptions and delegated administration requirements should be considered when designing organizational controls.<\/span><\/p>\n<h3><b>Question 94<\/b><\/h3>\n<p><b>Which encryption approach allows applications to encrypt large amounts of data efficiently while using AWS KMS to protect the encryption key?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Envelope encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security group encryption<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM policy encryption<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Envelope encryption uses a data key to encrypt application data while a separate key, such as an AWS KMS key, protects the data key. This approach allows applications to encrypt large amounts of data efficiently without sending all plaintext data through KMS for encryption. The encrypted data key can be stored with the encrypted data and later decrypted when access is authorized. AWS services commonly use envelope encryption as part of their encryption architectures, helping combine efficient data encryption with centralized key-management controls.<\/span><\/p>\n<h3><b>Question 95<\/b><\/h3>\n<p><b>A company needs to ensure that a web application is protected from unusually high request rates that could indicate abuse. Which AWS WAF capability is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP address allow list only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Rate-based rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 bucket policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM role<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS WAF rate-based rules can help detect and control excessive request rates from clients that exceed a configured threshold. They are useful for mitigating certain forms of request flooding, automated abuse, and other high-volume HTTP traffic patterns. A rate-based rule can be combined with additional WAF rules and application-specific protections. Security teams should select thresholds based on legitimate traffic patterns because overly aggressive limits can block valid users. Rate-based rules should be viewed as one layer within a broader application security strategy.<\/span><\/p>\n<h3><b>Question 96<\/b><\/h3>\n<p><b>Which AWS service helps organizations collect evidence to support audits against compliance frameworks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Detective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Audit Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Network Firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Audit Manager helps organizations collect and organize evidence that can support audits and compliance assessments. It can continuously gather evidence from supported AWS services and help map collected information to defined control requirements. This reduces the need to manually gather every piece of evidence for an assessment. Audit Manager does not itself make an organization compliant; organizations remain responsible for implementing appropriate controls and validating their effectiveness. Security and compliance teams can use its evidence capabilities alongside AWS Config, CloudTrail, and organizational policies.<\/span><\/p>\n<h3><b>Question 97<\/b><\/h3>\n<p><b>A security architect wants private connectivity between VPCs without exposing application traffic to the public internet. Which AWS networking capability is appropriate for connecting VPCs through a centralized network architecture?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Transit Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudFront<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Transit Gateway can provide centralized connectivity between multiple VPCs and supported networks. It is useful in environments where many VPCs need controlled communication without creating a complex mesh of individual connections. Security teams can use routing tables and network controls to segment traffic and restrict which networks can communicate. Transit Gateway should be combined with security groups, network ACLs, Network Firewall, and appropriate route controls when sensitive workloads require strong segmentation. Centralized architecture also simplifies network governance and monitoring.<\/span><\/p>\n<h3><b>Question 98<\/b><\/h3>\n<p><b>Which IAM approach allows permissions to be assigned according to attributes such as department, project, or environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static access keys<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attribute-based access control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security group rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network ACLs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attribute-based access control uses attributes, often represented through tags, to determine whether an identity should receive access to a resource. In AWS, IAM policy conditions can evaluate supported principal and resource tags to create scalable authorization models. ABAC can reduce the need to create separate policies for every individual resource or user when organizational attributes are consistently managed. Successful implementation requires reliable tagging standards, controlled tag modification permissions, and carefully designed IAM conditions to prevent unauthorized access through manipulated attributes.<\/span><\/p>\n<h3><b>Question 99<\/b><\/h3>\n<p><b>A security team wants to receive an event when a GuardDuty finding is generated and automatically invoke a remediation function. Which combination is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS EventBridge and AWS Lambda<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon S3 and CloudFront<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact and AWS Audit Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Route 53 and AWS Certificate Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon EventBridge can receive events generated by supported AWS services, including security findings, and route matching events to targets such as AWS Lambda. A security team can use this combination to automate responses to specific GuardDuty findings. For example, a workflow could invoke a Lambda function that applies a predefined containment action or creates an incident ticket. Automated remediation should use narrowly scoped IAM permissions and include safeguards, logging, and error handling because an incorrect automated action can affect legitimate production resources.<\/span><\/p>\n<h3><b>Question 100<\/b><\/h3>\n<p><b>Which security principle requires granting users and workloads only the permissions necessary to perform their required tasks?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Nonrepudiation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fault tolerance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The principle of least privilege requires users, applications, and services to receive only the permissions necessary to perform their legitimate tasks. Applying least privilege reduces the potential impact of compromised credentials, accidental actions, and unauthorized activity. AWS organizations can implement this principle through IAM policies, roles, permission boundaries, resource policies, SCPs, and conditions. Permissions should be reviewed regularly because access requirements change over time. Tools such as IAM Access Analyzer can help identify opportunities to reduce unnecessary or unused access.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified Security &#8211; Specialty SCS-C03 Exam Dumps and Practice Test Dumps. &nbsp; Question 81 Which AWS service can identify sensitive data stored in Amazon S3 buckets? Amazon Detective Amazon Inspector Amazon Macie AWS Shield Correct Answer: 3 Explanation Amazon Macie is designed to discover and help protect sensitive data stored in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22034"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22034"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22034\/revisions"}],"predecessor-version":[{"id":22035,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22034\/revisions\/22035"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22034"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22034"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22034"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}