{"id":22064,"date":"2026-09-25T10:40:26","date_gmt":"2026-09-25T10:40:26","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22064"},"modified":"2026-09-25T10:40:26","modified_gmt":"2026-09-25T10:40:26","slug":"amazon-aws-certified-security-specialty-scs-c03-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-security-specialty-scs-c03-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"Amazon AWS Certified Security &#8211; Specialty SCS-C03 Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-security-specialty-scs-c03-exam-dumps\"><b>Amazon AWS Certified Security &#8211; Specialty SCS-C03 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 381<\/b><\/h3>\n<p><b>A company wants to prevent administrators from disabling required CloudTrail logging in member accounts. Which AWS Organizations capability can provide a preventive governance control?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Detective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Resource Access Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Security Hub<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Organizations SCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An AWS Organizations service control policy can establish preventive guardrails across member accounts. A security team can use an SCP to deny actions that would disable or alter required CloudTrail configurations, subject to the organization&#8217;s architecture and service behavior. SCPs do not grant permissions; they define maximum permissions available to affected principals. Organizations should combine SCPs with centralized CloudTrail administration and protected log destinations. Careful testing is necessary because overly broad denies can interfere with legitimate security administration and account-management operations.<\/span><\/p>\n<h3><b>Question 382<\/b><\/h3>\n<p><b>A security team wants to apply mandatory cost-center and environment tags to resources across an organization but does not want the tag policy itself to grant resource permissions. Which AWS Organizations feature is designed for this purpose?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Tag policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource-based policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service control policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM permission boundaries<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Organizations tag policies can help standardize tagging across an organization by defining approved tag keys and values. Tags can support governance, ownership identification, cost allocation, and security automation. Tag policies are different from service control policies because they do not function as general permission boundaries for API operations. Security teams can use standardized tags to identify production resources, security ownership, or data classifications and then use other services to enforce or monitor related requirements. Tag governance should be combined with IAM, Config, and organizational controls.<\/span><\/p>\n<h3><b>Question 383<\/b><\/h3>\n<p><b>An organization wants to ensure that a newly created AWS account receives required security controls automatically as part of its governance framework. Which service can help establish standardized multi-account environments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Inspector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Control Tower<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Private CA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Control Tower helps organizations establish and govern multi-account AWS environments using standardized account structures, controls, and governance processes. It can help ensure that newly provisioned accounts follow defined organizational requirements instead of being configured independently by individual administrators. Security teams can use governance controls to establish preventive and detective safeguards across accounts. Control Tower does not replace individual AWS security services, so organizations should still configure appropriate identity, logging, monitoring, and data-protection controls. Centralized governance reduces configuration differences between accounts.<\/span><\/p>\n<h3><b>Question 384<\/b><\/h3>\n<p><b>A security engineer needs to encrypt sensitive Lambda environment variables using a customer managed KMS key. Which configuration provides this capability?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudWatch Logs subscription<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lambda destination<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">KMS encryption for environment variables<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lambda function URL<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Lambda supports encryption of environment variables, including the use of a customer managed AWS KMS key for additional control over encryption. This can help protect sensitive configuration values stored with a function. Access to the KMS key should be restricted because principals with appropriate permissions may be able to decrypt protected information. Security teams should avoid storing highly sensitive secrets unnecessarily in environment variables and should consider Secrets Manager when dedicated secret lifecycle management is required. IAM permissions and key policies should follow least-privilege principles.<\/span><\/p>\n<h3><b>Question 385<\/b><\/h3>\n<p><b>A company replicates sensitive S3 data to another Region and wants the replicated objects to remain encrypted with a customer managed KMS key in the destination Region. Which capability should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 website hosting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Transfer Acceleration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Cross-Region Replication with appropriate KMS encryption<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">S3 Cross-Region Replication can replicate objects to another AWS Region while applying appropriate encryption at the destination. When customer-managed KMS keys are used, the replication configuration and permissions must allow the replication process to use the required source and destination encryption keys. Security teams should carefully configure KMS key policies and replication roles because incorrect permissions can cause replication failures. Cross-Region replication can improve resilience, but the destination bucket should have its own access controls, retention requirements, logging, and monitoring.<\/span><\/p>\n<h3><b>Question 386<\/b><\/h3>\n<p><b>A security administrator wants to prevent an S3 access point from being reachable through the public internet and allow access only from a VPC. Which configuration should be selected?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Access Point with VPC network origin<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Transfer Acceleration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 static website hosting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudFront public distribution<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An S3 Access Point can be configured with a VPC network origin so that requests must originate through the specified VPC rather than through a public network path. This provides a useful network boundary for applications that access sensitive S3 data privately. The access point policy and underlying bucket policy still determine whether the requesting principal is authorized. Security teams should also review VPC endpoint configuration and IAM permissions. Network-origin restrictions are most effective when combined with encryption, monitoring, least privilege, and appropriate data-classification controls.<\/span><\/p>\n<h3><b>Question 387<\/b><\/h3>\n<p><b>A security team needs to identify whether a particular AWS resource is being accessed by an external principal through a resource policy. Which information is most directly relevant to the investigation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 storage class<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudFront cache status<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource-based policy principal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EC2 instance type<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The principal specified in a resource-based policy determines which identity or account can potentially access the resource under that policy. Reviewing the principal is therefore essential when investigating external access. Security teams should determine whether the principal represents an approved partner, organizational account, public access, or an unintended external identity. IAM Access Analyzer can assist with identifying external access relationships for supported resources. Analysts should also evaluate conditions, explicit denies, identity-based policies, and organization boundaries because a resource policy alone does not always determine the final authorization result.<\/span><\/p>\n<h3><b>Question 388<\/b><\/h3>\n<p><b>A company wants to collect EKS control plane audit logs for security investigations. Which configuration should be enabled?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route 53 query logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EKS control plane logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 server access logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudFront access logging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon EKS control plane logging can provide logs from supported control plane components, including audit-related information useful for security monitoring and investigations. Kubernetes audit activity can help identify actions performed against the cluster API, including potentially unauthorized changes. Security teams should select the required log types, configure appropriate destinations and retention, and protect access to the resulting logs. Control plane logs should complement workload-level monitoring, IAM analysis, network telemetry, and Kubernetes security controls. Centralized collection can improve incident-response visibility across multiple clusters and accounts.<\/span><\/p>\n<h3><b>Question 389<\/b><\/h3>\n<p><b>A security engineer wants to prevent a Lambda function from accessing resources that are outside the permissions approved for that workload, even if additional identity policies are attached later. Which IAM feature can provide a maximum-permissions boundary?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudTrail event selector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 bucket versioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM permissions boundary<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF rule group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IAM permissions boundary establishes the maximum permissions that an IAM identity can receive through identity-based policies. This can be useful for delegated administration and workload governance because additional permissions cannot exceed the boundary&#8217;s limits. The boundary itself does not grant permissions. Effective access results from the interaction of identity policies, the permissions boundary, resource policies, SCPs, session policies, and explicit denies. Security teams should design boundaries around the resources and actions that a workload genuinely requires and periodically review them as application requirements change.<\/span><\/p>\n<h3><b>Question 390<\/b><\/h3>\n<p><b>A company wants to identify whether a KMS key is being used by an application and investigate unexpected key usage. Which source can provide API-level evidence of KMS operations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS CloudTrail<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS CloudTrail can record supported AWS KMS API activity, providing information about operations performed against KMS resources. Security teams can use this evidence to investigate unexpected encryption or decryption activity, identify the calling identity, and establish when an operation occurred. KMS key policies and IAM policies determine authorization, while CloudTrail provides valuable audit evidence about actual API activity. Organizations should protect CloudTrail logs from unauthorized modification and retain them according to security and compliance requirements. Monitoring sensitive KMS operations can help identify misuse of cryptographic permissions.<\/span><\/p>\n<h3><b>Question 391<\/b><\/h3>\n<p><b>A security team wants to ensure that only specific IAM principals can use a customer managed KMS key for cryptographic operations. Which control is central to this requirement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudFront cache policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">KMS key policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 lifecycle rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route 53 health check<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The KMS key policy is a fundamental authorization mechanism for customer managed KMS keys. It can specify which principals are permitted to perform operations such as encryption, decryption, or key administration, subject to the applicable AWS authorization model. Security teams should scope key permissions carefully and separate key administration from routine cryptographic usage when practical. IAM policies can also participate in authorization depending on the key policy design. Broad KMS permissions should be avoided because unauthorized decryption or key administration can have significant security consequences.<\/span><\/p>\n<h3><b>Question 392<\/b><\/h3>\n<p><b>A company wants to prevent administrators from using an IAM policy to grant permissions that exceed a predefined maximum for delegated users. Which mechanism should be applied to those users?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudTrail Insights<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Object Lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS WAF CAPTCHA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM permissions boundary<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IAM permissions boundary limits the maximum permissions that an IAM user or role can receive through identity-based policies. This is useful when an organization delegates permission management but wants to prevent delegated administrators from creating identities with unrestricted privileges. A boundary does not itself grant permissions, so the identity still requires appropriate identity-based permissions to perform actions. Security teams should combine boundaries with SCPs and carefully designed administrative roles. Regular reviews are necessary to ensure that boundaries remain restrictive enough for the organization&#8217;s security requirements.<\/span><\/p>\n<h3><b>Question 393<\/b><\/h3>\n<p><b>A security administrator needs to determine whether a private certificate authority has issued certificates that should no longer be trusted. Which certificate-management capability is relevant?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WAF rate limiting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudTrail Insights<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate revocation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 versioning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Certificate revocation allows a certificate authority to indicate that a previously issued certificate should no longer be trusted before its normal expiration date. This can be necessary when a private key is compromised, a certificate is issued incorrectly, or the associated identity should no longer use the certificate. AWS Private CA supports certificate lifecycle capabilities that organizations can incorporate into their internal PKI processes. Security teams should define revocation procedures and ensure applications can appropriately determine certificate status when required. Certificate lifecycle management should include issuance, renewal, revocation, and auditing.<\/span><\/p>\n<h3><b>Question 394<\/b><\/h3>\n<p><b>A company wants to reduce the risk of attackers obtaining credentials from an EC2 instance&#8217;s metadata service through an SSRF vulnerability. Which configuration provides stronger protection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Require IMDSv2<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assign an administrator IAM role<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enable IMDSv1 only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable security groups<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Requiring IMDSv2 provides stronger protection for EC2 instance metadata access by requiring a session-oriented interaction with the metadata service. This can reduce the effectiveness of certain SSRF techniques that attempt to retrieve instance credentials from metadata. Security teams should configure supported workloads to require IMDSv2 and verify that applications are compatible. The instance role itself should also follow least privilege because metadata protection does not eliminate the impact of a credential compromise. Network controls, application security, and monitoring remain important layers of EC2 workload protection.<\/span><\/p>\n<h3><b>Question 395<\/b><\/h3>\n<p><b>A security team wants to make a KMS grant usable only when a specified encryption context is present. Which KMS feature can impose such a restriction?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CloudFront signed cookies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Grant constraints<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM credential report<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 bucket versioning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">KMS grant constraints can restrict the circumstances under which a grant permits cryptographic operations. One supported approach is to use encryption-context-related constraints so that the grant applies only when the expected encryption context conditions are satisfied. This can provide more granular authorization than simply allowing broad use of a KMS key. Security teams should ensure that applications consistently supply the expected encryption context and understand how it participates in authorization. Grant design should follow least privilege and be reviewed regularly to prevent unnecessary cryptographic access.<\/span><\/p>\n<h3><b>Question 396<\/b><\/h3>\n<p><b>A company wants to identify sensitive data stored in S3 without manually opening each object. Which service provides automated data discovery capabilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Network Firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Private CA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Macie provides automated sensitive-data discovery capabilities for Amazon S3. It can analyze supported objects and identify sensitive information according to configured discovery and classification capabilities. This can help security teams understand where sensitive information resides and identify unexpected storage locations or exposure risks. Macie findings can support remediation decisions, but the service does not automatically replace S3 authorization controls. Organizations should combine data discovery with appropriate encryption, least-privilege access, retention policies, logging, and classification procedures to protect sensitive information throughout its lifecycle.<\/span><\/p>\n<h3><b>Question 397<\/b><\/h3>\n<p><b>A security administrator wants to ensure that a workload cannot access AWS services that are not approved for a particular account, even if an identity policy allows those services. Which organization-level control is appropriate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Certificate Manager<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Detective<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Access Point<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Organizations SCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An AWS Organizations service control policy can establish organization-level permission guardrails that restrict which AWS services or actions can be used by affected accounts. An SCP can deny access to services that are not approved, even when an identity-based policy attempts to allow the operation. SCPs do not grant permissions, so normal IAM authorization is still required. Security teams should carefully identify required services and account-management exceptions before applying broad restrictions. Service-denial guardrails can reduce the attack surface and improve consistency across large multi-account environments.<\/span><\/p>\n<h3><b>Question 398<\/b><\/h3>\n<p><b>A company wants to protect a centralized S3 log bucket from accidental deletion of log objects during their required retention period. Which feature provides object-level retention protection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Object Lock<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Inventory<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Transfer Acceleration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Select<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">S3 Object Lock can prevent protected objects from being deleted or overwritten during a configured retention period. This is particularly useful for centralized security logs that may need to remain available for investigations, audits, or compliance requirements. Security teams should carefully configure retention settings and restrict administrative access to the bucket. Object Lock is not a substitute for encryption or IAM controls, so the log repository should still have strong authorization and monitoring. Immutable retention can provide an important additional defense against accidental deletion and certain attacker actions.<\/span><\/p>\n<h3><b>Question 399<\/b><\/h3>\n<p><b>A security team wants to receive notifications when an AWS Config rule detects a new noncompliant resource. Which service can route the resulting event to a notification or automation target?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Private CA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Amazon Macie<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS EventBridge<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS EventBridge can receive supported AWS Config events and route them to targets such as notification services, Lambda functions, or Systems Manager Automation workflows. This allows organizations to respond to configuration compliance changes without continuously polling resources manually. Security teams can create event patterns that focus on particular rule names, compliance states, resource types, or other relevant attributes. Automated responses should be tested carefully because a configuration finding may require investigation before corrective action. Event-driven remediation can improve response speed when implemented with appropriate safeguards.<\/span><\/p>\n<h3><b>Question 400<\/b><\/h3>\n<p><b>A security administrator needs to determine which IAM permissions are actually used before reducing a role&#8217;s policy. Which combination provides useful evidence for a least-privilege review?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Artifact and AWS Private CA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">S3 Transfer Acceleration and CloudFront<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AWS Shield and Route 53<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IAM policy analysis and CloudTrail activity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IAM policy analysis combined with CloudTrail activity can provide useful evidence when reducing excessive permissions. Policy analysis identifies what the role is currently authorized to do, while CloudTrail provides evidence of API activity performed by identities over time. Security teams should consider the observation period carefully because infrequently used scheduled jobs may not appear during a short review. After removing permissions, applications should be tested and monitored for authorization failures. This iterative process helps organizations move toward least privilege while minimizing unnecessary disruption to legitimate workloads.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified Security &#8211; Specialty SCS-C03 Exam Dumps and Practice Test Dumps. &nbsp; Question 381 A company wants to prevent administrators from disabling required CloudTrail logging in member accounts. Which AWS Organizations capability can provide a preventive governance control? Amazon Detective AWS Resource Access Manager AWS Security Hub AWS Organizations SCP Correct [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22064"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22064"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22064\/revisions"}],"predecessor-version":[{"id":22065,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22064\/revisions\/22065"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22064"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22064"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22064"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}