{"id":22052,"date":"2026-09-25T10:38:51","date_gmt":"2026-09-25T10:38:51","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22052"},"modified":"2026-09-25T10:38:51","modified_gmt":"2026-09-25T10:38:51","slug":"amazon-aws-certified-security-specialty-scs-c03-practice-test-questions-and-exam-dumps-part14-q261-280","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-security-specialty-scs-c03-practice-test-questions-and-exam-dumps-part14-q261-280\/","title":{"rendered":"Amazon AWS Certified Security &#8211; Specialty SCS-C03 Practice Test Questions and Exam Dumps Part14 Q261-280"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-security-specialty-scs-c03-exam-dumps\"><b>Amazon AWS Certified Security &#8211; Specialty SCS-C03 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 261<\/b><\/h3>\n<p><b>Which AWS service can help monitor DNS queries made by resources within a VPC for security analysis?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudTrail<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route 53 Resolver query logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Audit Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route 53 Resolver query logging can capture DNS queries originating from resources associated with a VPC and send the records to supported destinations for analysis. Security teams can use DNS telemetry to investigate suspicious domains, identify unusual name-resolution patterns, and support incident investigations. DNS logs can be particularly useful when an endpoint communicates with a malicious domain that is not immediately obvious from other network telemetry. Organizations should protect the logs, configure suitable retention, and correlate DNS information with host, network, and identity data for stronger detection.<\/span><\/p>\n<h3><b>Question 262<\/b><\/h3>\n<p><b>A security engineer wants to prevent workloads from resolving known malicious domains through Amazon Route 53 Resolver. Which control should be considered?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route 53 Resolver DNS Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudTrail Lake<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM credential report<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Private CA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route 53 Resolver DNS Firewall can help control DNS queries by allowing organizations to create domain lists and rules that determine which domains can be resolved. Security teams can use managed or custom domain lists to block known malicious or unwanted destinations. This provides a preventive layer at the DNS-resolution stage and can help reduce communication with known threats. DNS Firewall should not be considered a complete network security solution because attackers may use other resolution mechanisms. Organizations should combine it with endpoint, network, identity, and application controls.<\/span><\/p>\n<h3><b>Question 263<\/b><\/h3>\n<p><b>An organization needs to automatically rotate an application secret using a Lambda-based rotation workflow. Which AWS service is designed to manage the secret and rotation configuration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Systems Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Secrets Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Secrets Manager is designed to securely store secrets and support automated rotation workflows for supported secret types. Rotation can use AWS Lambda functions to coordinate the process of generating and applying new credentials. Applications can retrieve the current secret rather than embedding static credentials in source code or configuration files. Security teams should ensure that the rotation function has only the permissions required to perform its task and that applications correctly retrieve updated values. Rotation should also be tested carefully before being enabled for critical production workloads.<\/span><\/p>\n<h3><b>Question 264<\/b><\/h3>\n<p><b>Which AWS service can help an organization manage encrypted configuration parameters without using a dedicated secrets-rotation workflow?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Systems Manager Parameter Store<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield Advanced<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Network Firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Systems Manager Parameter Store can store configuration values and supports encrypted parameters through AWS KMS. It can be useful for applications that need centralized configuration management without requiring the full secret-management capabilities of Secrets Manager. Security teams should distinguish between ordinary configuration parameters and credentials that require advanced lifecycle management or automatic rotation. IAM permissions should be limited to the parameters each application requires. Parameter Store is therefore useful for many configuration scenarios, while Secrets Manager is generally more appropriate when sophisticated secret management is required.<\/span><\/p>\n<h3><b>Question 265<\/b><\/h3>\n<p><b>A security administrator needs to prevent a newly created IAM user from creating permanent access keys. Which approach can enforce this restriction?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An IAM policy that denies <\/span><span style=\"font-weight: 400;\">iam:CreateAccessKey<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A security group rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An S3 lifecycle rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A CloudFront response policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IAM policy can explicitly deny the <\/span><span style=\"font-weight: 400;\">iam:CreateAccessKey<\/span><span style=\"font-weight: 400;\"> action for identities that should not create long-lived access keys. A deny statement provides a preventive authorization control and can be combined with organizational policies or permissions boundaries. This can support an architecture that prefers federation and temporary credentials over permanent IAM user credentials. Security teams should identify legitimate exceptions and manage them carefully. Preventing unnecessary access-key creation reduces credential exposure and simplifies credential lifecycle management across the organization.<\/span><\/p>\n<h3><b>Question 266<\/b><\/h3>\n<p><b>A company wants workforce users to authenticate through an existing corporate identity provider while receiving access to multiple AWS accounts. Which AWS capability is most appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM Identity Center<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS KMS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Network Firewall<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IAM Identity Center can integrate workforce access with supported identity providers and provide centralized access to multiple AWS accounts and applications. Users can authenticate through the organization&#8217;s identity system and receive assigned permission sets without requiring separate IAM users in every account. This supports centralized identity lifecycle management and can simplify onboarding and offboarding. Security teams should enforce appropriate authentication controls, permission-set design, and least privilege. Regular access reviews are also important to ensure users retain only the account and permission assignments required for their current responsibilities.<\/span><\/p>\n<h3><b>Question 267<\/b><\/h3>\n<p><b>Which AWS feature can require users to authenticate with MFA before performing sensitive IAM actions when supported by the policy conditions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">aws:PrincipalOrgID<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">aws:MultiFactorAuthPresent<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">aws:SourceVpce<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">aws:RequestedRegion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">aws:MultiFactorAuthPresent<\/span><span style=\"font-weight: 400;\"> condition key can be used in IAM policies to make authorization decisions based on whether MFA was used for authentication. Organizations can use this condition to require stronger authentication before sensitive operations or access to protected resources. The exact behavior depends on how authentication and credentials are used, so policies should be designed and tested carefully. MFA conditions are an additional authorization control and do not replace least privilege. Security teams should also monitor authentication activity and protect the underlying identity provider.<\/span><\/p>\n<h3><b>Question 268<\/b><\/h3>\n<p><b>An organization wants to identify whether an S3 bucket policy grants access to an external AWS account before deploying the policy. Which tool can analyze the policy for external access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS IAM Access Analyzer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon GuardDuty<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudWatch<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IAM Access Analyzer can analyze supported resource policies and identify access that extends beyond an intended trust boundary, including external access. This is useful when reviewing S3 bucket policies before or after deployment. Security teams can investigate whether the external access is intentional and modify the policy when it is unnecessary. Policy analysis should be part of a broader access-review process because an external-access finding is not automatically a security incident. Organizations should document approved cross-account relationships and continuously review resource-based policies.<\/span><\/p>\n<h3><b>Question 269<\/b><\/h3>\n<p><b>A security team wants to make security findings from several AWS accounts available to a central security account. Which Security Hub capability supports this architecture?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-Region replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multi-account aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Transfer Acceleration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudFront origin failover<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Security Hub supports centralized management of security findings across multiple AWS accounts. Organizations can designate a central security account and configure member relationships so security teams can view and manage findings from participating accounts. This provides a consolidated security posture and reduces the need for analysts to inspect each workload account separately. Security Hub does not eliminate the need for account-level permissions or service configuration. Organizations should establish clear ownership and remediation workflows so centralized findings are acted upon efficiently.<\/span><\/p>\n<h3><b>Question 270<\/b><\/h3>\n<p><b>Which AWS service can automatically apply security group policies across accounts according to centrally defined organizational rules?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Firewall Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Athena<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Private CA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Firewall Manager can centrally manage security group policies across supported AWS accounts and resources. This enables security teams to establish common baseline rules while reducing configuration differences between accounts. Central policies can help prevent unauthorized or overly permissive security group configurations from remaining in the environment. Organizations should define exceptions carefully for workloads with legitimate specialized requirements. Firewall Manager should complement, rather than replace, local security group design, network segmentation, identity controls, and continuous monitoring.<\/span><\/p>\n<h3><b>Question 271<\/b><\/h3>\n<p><b>A company wants to ensure that a specific IAM action can be performed only when requests originate from a designated AWS Region. Which policy condition is relevant?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">aws:RequestedRegion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">aws:SourceIp<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">aws:SecureTransport<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">aws:PrincipalTag<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">aws:RequestedRegion<\/span><span style=\"font-weight: 400;\"> global condition key can be used to evaluate the AWS Region targeted by an API request. Organizations can use it to limit operations to approved Regions and prevent users or workloads from creating or modifying resources in locations that are outside organizational requirements. Security teams should account for services with global endpoints and actions whose regional behavior differs. Region restrictions are governance controls rather than complete security boundaries, so they should be combined with identity, network, data-protection, and organizational policies.<\/span><\/p>\n<h3><b>Question 272<\/b><\/h3>\n<p><b>Which AWS service can provide a record of configuration changes to supported AWS resources over time?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Config can record configuration information for supported resources and maintain configuration history. This allows security teams to investigate how a resource&#8217;s configuration changed over time and determine when a potentially insecure state was introduced. Configuration history can be useful during incident response, compliance reviews, and troubleshooting. Organizations should ensure Config recording is enabled for the resources and Regions that matter to their security objectives. Configuration history is complementary to CloudTrail because Config focuses on resource state while CloudTrail records API activity.<\/span><\/p>\n<h3><b>Question 273<\/b><\/h3>\n<p><b>A security engineer wants to determine which IAM policy statements allow a principal to access a resource without actually granting that access in production. Which AWS capability can help test the policy logic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM policy simulator<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route 53 Resolver<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The IAM policy simulator can help administrators evaluate how IAM policies affect authorization decisions without requiring the intended action to be performed against production resources. It can be useful for testing whether a particular action would be allowed or denied under specified policies. Security teams can use this capability when troubleshooting permissions or validating changes before deployment. Simulation does not replace full testing because resource policies, permissions boundaries, SCPs, and other contextual conditions can affect authorization. Policy analysis should therefore consider the complete authorization environment.<\/span><\/p>\n<h3><b>Question 274<\/b><\/h3>\n<p><b>A security team needs to investigate a GuardDuty finding by examining related entities and historical relationships between AWS resources. Which service is designed for this type of investigation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Detective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Certificate Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Backup<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Detective is designed to help security teams investigate security findings by providing contextual information and visualizing relationships between entities such as users, IP addresses, resources, and AWS activity. It can help analysts move beyond an individual alert and understand related behavior over time. Detective works with relevant AWS telemetry to support investigation and analysis. It is not primarily a prevention service, so security teams should use its findings alongside containment, remediation, identity controls, network protections, and other incident-response procedures.<\/span><\/p>\n<h3><b>Question 275<\/b><\/h3>\n<p><b>An organization wants to prevent an S3 object from being permanently deleted for a defined retention period. Which feature is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Object Lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Transfer Acceleration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudFront Origin Access Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Lifecycle rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">S3 Object Lock can prevent protected objects from being deleted or overwritten during a defined retention period. It supports retention modes that can be used to establish immutability for sensitive records, backups, and security logs. This can help defend against accidental deletion and certain malicious attempts to destroy evidence or recovery data. Security teams should carefully select retention requirements and understand the differences between governance and compliance modes. Object Lock should be incorporated into a broader data-protection strategy that includes access control, encryption, monitoring, and recovery planning.<\/span><\/p>\n<h3><b>Question 276<\/b><\/h3>\n<p><b>A company wants to identify suspicious changes to IAM policies and other security-sensitive AWS configurations. Which combination provides useful audit evidence?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudTrail management events and AWS Config<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 lifecycle rules and CloudFront logs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie and AWS Certificate Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route 53 health checks and AWS Backup<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CloudTrail management events can record API operations involving security-sensitive resources such as IAM policies, while AWS Config can provide information about resulting resource configuration states and their history. Using both sources gives investigators complementary information: CloudTrail helps answer who performed an API operation and when, while Config can show how the resource configuration changed. Correlating the two can improve incident investigation and compliance auditing. Security teams should protect both data sources, configure appropriate retention, and ensure access is limited to authorized investigators.<\/span><\/p>\n<h3><b>Question 277<\/b><\/h3>\n<p><b>Which AWS service can help automatically discover and classify sensitive data in S3 without requiring analysts to inspect every object manually?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudTrail<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Macie uses automated data discovery and analysis capabilities to help identify sensitive information stored in Amazon S3. This can reduce the need for security teams to manually inspect large numbers of objects and can help identify where sensitive data exists across an organization. Macie can provide findings that support investigation and data-protection decisions. Organizations should combine discovery with preventive controls, such as restrictive bucket policies, encryption, access monitoring, and appropriate retention. Sensitive-data discovery is most effective when integrated into an ongoing data-security program.<\/span><\/p>\n<h3><b>Question 278<\/b><\/h3>\n<p><b>A security administrator wants an organization-wide restriction that prevents member accounts from disabling a required security service. Which control can provide an organizational guardrail?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service control policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 bucket ACL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">KMS grant<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A service control policy can establish an organizational guardrail that limits what actions member accounts are permitted to perform. An SCP can deny specific actions, including selected administrative operations, even when an account-level IAM policy otherwise permits them. This makes SCPs useful for enforcing security requirements consistently across accounts. SCPs do not grant permissions, so account identities still require appropriate IAM permissions. Organizations should test restrictive policies carefully and provide controlled exceptions where required to avoid interfering with legitimate security administration or operational recovery.<\/span><\/p>\n<h3><b>Question 279<\/b><\/h3>\n<p><b>A security team wants to collect and analyze security data from multiple AWS accounts in a standardized format for use by different analytics tools. Which service is designed for this purpose?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Security Lake<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Certificate Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudFront<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Backup<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Security Lake is designed to centralize security-related data from supported sources and normalize it using the Open Cybersecurity Schema Framework. Standardization can make security information easier to consume across analytics, investigation, and detection tools. A centralized security data lake can also support broader analysis across multiple accounts and environments. Organizations should carefully define data sources, retention, access permissions, and encryption because security telemetry can contain sensitive information. Security Lake complements individual detection services rather than replacing them.<\/span><\/p>\n<h3><b>Question 280<\/b><\/h3>\n<p><b>Which AWS capability can help an organization enforce a consistent baseline of preventive and detective controls across multiple AWS accounts?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Organizations with centralized governance controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon CloudFront<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Certificate Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Organizations provides the account structure needed for centralized governance, while services such as SCPs and supported governance capabilities can enforce organization-wide security guardrails. This approach allows security teams to establish requirements that apply consistently across multiple member accounts rather than relying entirely on individual account administrators. Additional services can provide configuration monitoring, centralized findings, and automated remediation. Organizations should combine preventive and detective controls because no single governance mechanism addresses every security requirement. Regular reviews are also necessary as workloads and organizational policies change.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified Security &#8211; Specialty SCS-C03 Exam Dumps and Practice Test Dumps. &nbsp; Question 261 Which AWS service can help monitor DNS queries made by resources within a VPC for security analysis? AWS CloudTrail Amazon Inspector Route 53 Resolver query logging AWS Audit Manager Correct Answer: 3 Explanation Route 53 Resolver query [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22052"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22052"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22052\/revisions"}],"predecessor-version":[{"id":22053,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22052\/revisions\/22053"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22052"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22052"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22052"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}