39 practice questions for Domain 1 of the AWS Certified Security - Specialty (SCS-C03) exam, which makes up 16% of its scored content. Your answers count towards one score and one timer for the whole exam.
Domain 1: Detection
1. Several AWS security services must be matched to the detection task each one performs. (Match each service to its purpose.)
- Amazon GuardDuty
- Amazon Macie
- Amazon Inspector
- Amazon Detective
Answer and explanation
Answer: 1-C, 2-D, 3-A, 4-B. GuardDuty is a threat detection service working from CloudTrail, DNS, and flow log telemetry. Macie classifies stored content rather than detecting activity. Inspector assesses software and reachability rather than behaviour. Detective takes an existing finding and builds the investigative context around it. The four are frequently confused because all four produce findings, but each answers a different question: what is happening, what is stored, what is vulnerable, and what led to this.
2. A security team must be alerted whenever the account root user is used, in any member account of an organization. Which solution meets these requirements?
Answer and explanation
Answer: C. A metric filter on the userIdentity type converts root usage into a metric an alarm can act on within minutes across every account. GuardDuty surfaces suspicious activity rather than every root use, and daily review is too slow. A Config rule evaluates configuration rather than usage. A weekly credential report shows credential state rather than when the root user acted.
3. An organization must detect unusual volumes of management API activity that deviate from an account's established baseline. Which solution meets these requirements?
Answer and explanation
Answer: D. CloudTrail Insights establishes a baseline of normal management API call volume and raises events when activity deviates significantly, which is the behaviour described. Data events record object-level and function-level activity without baselining. A static threshold cannot adapt to an account's normal pattern. A Config rule evaluates configuration compliance rather than call rates.
4. Security findings from Amazon GuardDuty, Amazon Inspector, and Amazon Macie must be normalized, prioritized, and evaluated against a recognised standard across an organization. Which solution meets these requirements?
Answer and explanation
Answer: D. Security Hub ingests findings in a common format, runs automated standards checks, and aggregates across accounts under a delegated administrator. Detective investigates a single finding rather than normalizing across services. A Config aggregator collects configuration compliance rather than security findings. Exporting to S3 requires building the normalization and standards logic by hand.
5. An organization must enable Amazon GuardDuty in every account, aggregate the findings centrally, and cover accounts created in future. Which solution meets these requirements?
Answer and explanation
Answer: B. A delegated administrator with auto-enable brings existing and future accounts under one administrator with aggregated findings and no per-account action. Manual enablement misses new accounts. A custom function recreates a built-in capability with more failure modes. Security Hub aggregates findings but cannot enable GuardDuty in an account that does not have it.
6. A team must be notified of AWS-side events that affect its own resources, such as a scheduled EC2 retirement. Which solution meets these requirements?
Answer and explanation
Answer: D. AWS Health publishes account-specific events including scheduled retirements to EventBridge for routing. A status check alarm fires once the instance is already impaired. A public status page carries no account-specific detail. Config records configuration changes rather than AWS operational notices.
7. An organization must record every object-level read of a specific Amazon S3 bucket for audit purposes. Which solution meets these requirements?
Answer and explanation
Answer: B. Object-level reads are data events, which are not logged by default and must be enabled with the read category selected. Management events cover bucket-level operations rather than object access. Server access logging records requests on a best-effort basis with less reliable principal attribution. Storage Lens reports usage and activity metrics rather than an audit trail.
8. An auditor must verify the integrity of CloudTrail logs for a period during which one digest file is missing. What does the missing digest file indicate?
Answer and explanation
Answer: A. Digest files are chained, each referencing its predecessor, so a missing file breaks the chain and integrity cannot be established across the gap, which is itself evidence of tampering or deletion. Digest files are written hourly whether or not log files were delivered. They record hashes rather than encryption keys. Validation is available for single-Region trails as well.
9. Security logs from many AWS accounts and third-party tools must be centralized in a normalized schema for correlation. Which solution meets these requirements?
Answer and explanation
Answer: D. Security Lake centralizes security data from AWS and third-party sources and normalizes it into OCSF, which is what correlation across heterogeneous sources requires. A shared bucket collects raw logs in their original formats. A central log group aggregates without normalizing. Building a normalization pipeline recreates what Security Lake provides.
10. Logs written to Amazon CloudWatch Logs by an application sometimes contain payment card numbers that must not be readable. Which solution meets these requirements?
Answer and explanation
Answer: B. A data protection policy detects configured sensitive data types in log events and masks them, which is the only option that makes the values unreadable to authorised log readers. Encryption protects logs from outside readers while authorised principals still see the values. Retention governs persistence. Restricting readers is access control rather than masking.
11. An organization must retain security logs in an archive that no account administrator, including in the log archive account, can delete for seven years. Which solution meets these requirements?
Answer and explanation
Answer: C. Compliance mode prevents any principal, including the root user of the owning account, from deleting a locked object version until retention expires. A bucket policy can be modified by whoever administers the account. Versioning preserves history but versions remain deletable. MFA Delete adds an authentication step rather than creating immutability.
12. A third-party security tool must consume the organization's security data in a vendor-neutral schema. Which solution meets these requirements?
Answer and explanation
Answer: D. Security Lake publishes data in OCSF, an open schema that third-party tools consume without custom parsing. Raw CloudTrail objects are in an AWS-specific format. Email notification is not a data feed. Scheduled CSV export introduces a custom format and a batch delay.
13. An expected Amazon GuardDuty finding has not appeared for activity that should have triggered it. Which cause should the team investigate first?
Answer and explanation
Answer: B. Suppression rules and trusted IP lists deliberately prevent findings being surfaced and are the usual reason an expected finding is absent. Metric quotas affect CloudWatch rather than GuardDuty detection. Export frequency changes how often findings reach downstream destinations rather than whether they are generated. Tags have no bearing on detection.
14. CloudTrail events for a Region are not appearing in the expected Amazon S3 bucket. Which cause should the team investigate first?
Answer and explanation
Answer: C. A single-Region trail and a bucket policy that does not permit the CloudTrail service principal are the two common reasons delivery fails. Versioning affects object history rather than delivery. Config is a separate service. A lifecycle transition moves objects after delivery rather than preventing it.
15. A GuardDuty finding type must stop generating alerts for a known benign source without losing the finding record. Which approach is appropriate?
Answer and explanation
Answer: A. A suppression rule archives matching findings so they stop alerting but remain available for later review. A trusted IP list prevents generation entirely and applies only to certain finding types. Disabling the type loses genuine instances. Deleting destroys the record.
16. Security Hub findings from a member account stopped appearing in the delegated administrator account. Which cause should be investigated first?
Answer and explanation
Answer: D. Findings stop flowing when the association is severed or the service is disabled in the member account. Quota limits would affect all members rather than one. Finding age governs retention rather than ingestion. Security Hub aggregates per Region by design, so a Region mismatch would have prevented findings appearing at all rather than stopping them.
17. An alert must fire when a KMS key policy is modified in any account in the organization. Which approach is appropriate?
Answer and explanation
Answer: C. Matching the specific API event routes the change to an alert within minutes. A Config rule evaluates the resulting state rather than alerting on the modification event. Insights baselines call volume rather than matching a specific call. A quarterly audit is far too slow for a key policy change.
18. An organization must know when a member account's security services are disabled by someone inside that account. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: A, E. A service control policy blocks the action and an event alert makes any attempt visible, which together give prevention and detection. Detailed monitoring reports resource metrics. Monthly review leaves a long gap. Longer retention preserves evidence without detecting the event.
19. An Amazon Detective investigation must begin from a GuardDuty finding. Which prerequisite is required?
Answer and explanation
Answer: B. Detective builds its behaviour graph from data ingested while it is enabled, so it must have been running during the period being investigated. Enabling it at investigation time produces no history for the past. Finding age and Security Hub archival do not govern graph coverage.
20. An organization trail must capture object-level activity for one specific bucket without recording it for every bucket in the account. Which configuration is required?
Answer and explanation
Answer: C. A data event selector scoped to a bucket ARN records only that bucket, which controls both cost and volume. Selecting all buckets and filtering later pays to record everything. Management events do not include object-level activity. Server access logging is a separate mechanism with less reliable principal attribution.
21. VPC Flow Logs must record whether a specific rejected connection was blocked by a security group or a network ACL. Which statement is correct?
Answer and explanation
Answer: D. Flow Logs capture accept and reject outcomes without attributing the decision to a specific control, so determining which one blocked the traffic requires examining the rules or running path analysis. No rule identifier is included, and both control types can produce reject records.
22. A CloudTrail trail must deliver to a bucket in another account, and delivery is failing. Which cause should be investigated first?
Answer and explanation
Answer: D. Cross-account delivery requires the destination bucket policy to permit the CloudTrail service principal, commonly conditioned on the source trail ARN. Versioning, Region scope, and lifecycle rules do not prevent the service writing.
23. Security Lake must make its data queryable by an analytics team without granting them access to the underlying storage. Which approach is appropriate?
Answer and explanation
Answer: B. A query-access subscriber exposes the data through the catalog with permissions managed by Lake Formation, without bucket access. Direct bucket access grants more than querying requires. Copying and scheduled export both duplicate the data and drift.
24. An investigation requires CloudTrail events from eight months ago, and the account has only the default event history. Which statement is correct?
Answer and explanation
Answer: A. Event history covers 90 days, so longer retention requires a trail delivering to storage or a CloudTrail Lake event data store configured in advance. A trail cannot be backdated. Insights generates events about call volume rather than retaining the underlying records.
25. Logs in a dedicated archive account must be readable by investigators but not deletable by anyone. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: A, C. Compliance mode prevents deletion by every principal including root, and a read-only role gives investigators what they need without more. Administrator access permits configuration changes. A named-principal deny is bypassed by any principal not named. MFA Delete adds an authentication step rather than immutability.
26. A metric filter on a CloudWatch log group is not producing data points although matching lines appear in the logs. Which cause should be investigated first?
Answer and explanation
Answer: C. A pattern mismatch is the usual cause when matching lines exist but no data points appear, and JSON and text patterns are written differently. Retention governs how long logs persist. Encryption does not prevent filtering. An absent alarm would not stop the metric being produced.
27. An Amazon Macie job reports no sensitive data findings for a bucket known to contain personal information. Which cause should be investigated first?
Answer and explanation
Answer: C. A job that excludes the relevant prefixes or cannot decrypt the objects produces no findings. Versioning and Intelligent-Tiering do not prevent analysis. Finding retention would affect older results rather than a current job.
28. A Security Hub finding must be routed to a ticketing system as soon as it is generated. Which approach is appropriate?
Answer and explanation
Answer: B. Security Hub publishes findings to EventBridge as they are imported. Nightly export and hourly polling both add latency. Console review depends on a person.
29. An alarm must fire when the number of failed console sign-in attempts exceeds a threshold. Which configuration is required?
Answer and explanation
Answer: C. A metric filter converts matching CloudTrail events into an alarmable metric. An API call count does not isolate failed sign-ins. GuardDuty may surface related findings but is not a threshold on this specific event. Access Analyzer evaluates policies.
30. GuardDuty must analyse activity within EKS clusters as well as at the account level. Which configuration is required?
Answer and explanation
Answer: A. EKS protection is a feature enabled on the detector. Default settings cover foundational sources. CloudTrail data events and Container Insights serve different purposes.
31. An organization must receive one aggregated notification rather than an alert per account for the same finding type. Which approach is appropriate?
Answer and explanation
Answer: A. Aggregating centrally and alerting once removes duplication at the source. Per-account alerts with downstream filtering pays for every alert. Disabling the type loses detection. Severity thresholds change what is reported rather than where.
32. CloudTrail must record events for a Region that was enabled after the trail was created. Which configuration ensures this?
Answer and explanation
Answer: B. A multi-Region trail includes Regions as they are enabled. An additional trail and recreation both require action per Region. Insights analyses call volume.
33. An organization must retain CloudTrail events in a queryable form for two years without managing an ingestion pipeline. Which approach is appropriate?
Answer and explanation
Answer: C. CloudTrail Lake stores events with configurable retention and SQL query support with no pipeline. S3 with Athena requires building partitioning and tables. CloudWatch Logs at this retention is costly. OpenSearch requires provisioning and ingestion.
34. VPC Flow Logs must include the AWS service that the traffic was destined for. Which configuration is required?
Answer and explanation
Answer: D. A custom format can include extended fields the default omits. The default format carries a fixed field set. Traffic Mirroring captures packets. DNS query logging records name lookups.
35. DNS queries made from a VPC must be recorded for investigation. Which configuration is required?
Answer and explanation
Answer: A. Resolver query logging records DNS queries from the VPC. Flow Logs record connection metadata without query names. CloudTrail records API calls rather than resolution. GuardDuty analyses DNS telemetry for threats without providing a query log.
36. An S3 bucket receiving CloudTrail logs must be protected so the trail's own deliveries continue while other writes are refused. Which approach is appropriate?
Answer and explanation
Answer: B. A policy permitting the service principal with a source condition and denying others allows delivery while refusing other writers. Denying all writes blocks delivery. Block Public Access prevents public exposure. Object Lock prevents deletion rather than writes.
37. An organization must confirm that every account's CloudTrail delivers to the central archive. Which approach is appropriate?
Answer and explanation
Answer: D. An organization trail covers every member account including new ones from one configuration. Owner confirmation and quarterly review rely on people. StackSets deploy trails that can be modified locally.
38. A Security Hub standard's control shows as failed although the underlying resource appears correctly configured. Which cause should be investigated first?
Answer and explanation
Answer: B. Many controls depend on AWS Config recording in the Region, and a missing recorder produces failures unrelated to the resource. Resource age, standard version, and archival state do not cause a false failure.
39. An EventBridge rule matching a security finding is not invoking its target. Which cause should be investigated first?
Answer and explanation
Answer: A. A pattern mismatch or missing invoke permission are the usual causes. Severity affects whether a finding is generated rather than whether a matching rule fires. Availability Zone and creation date are irrelevant.