37 practice questions for Domain 5 of the AWS Certified Security - Specialty (SCS-C03) exam, which makes up 18% of its scored content. Your answers count towards one score and one timer for the whole exam.
Domain 5: Data Protection
140. A Direct Connect link carrying regulated traffic must be encrypted at layer 2 between the customer router and the AWS device. Which solution meets these requirements?
Answer and explanation
Answer: A. MACsec encrypts traffic at layer 2 on supported Direct Connect connections. A VPN over Direct Connect encrypts at layer 3 and adds overhead. Application TLS protects individual sessions rather than the link. Subnet placement and ACLs control reachability rather than encrypting frames.
141. An Amazon EMR cluster processing regulated data must encrypt communication between its nodes. Which solution meets these requirements?
Answer and explanation
Answer: D. An EMR security configuration enables in-transit encryption for inter-node communication, which is the traffic named. At-rest encryption protects stored data. Subnet placement and security groups control reachability. Client TLS protects the connection to the cluster rather than within it.
142. TLS certificates for internet-facing load balancers must renew automatically without operational effort. Which solution meets these requirements?
Answer and explanation
Answer: D. ACM-issued public certificates renew automatically when the domain validation remains in place and the certificate is in use by an integrated service. Imported certificates must be renewed and reimported manually. Private CA certificates are not trusted by public browsers. A self-signed certificate produces a browser warning and has no renewal mechanism.
143. An application must encrypt a 50 MB object locally using envelope encryption with AWS KMS before storing it in Amazon S3. (Place the steps in the correct order.)
Answer and explanation
Answer: D → A → C → B. The data key is requested first because nothing can be encrypted without it, and KMS returns both a plaintext and an encrypted copy in one call. Encryption happens locally, which is what avoids the KMS payload limit. The plaintext key is discarded immediately after use so it does not persist beyond the operation. The encrypted data key is stored with the ciphertext so the object can be decrypted later by whoever holds permission on the KMS key.
144. Several data protection mechanisms must be matched to the requirement each one satisfies. (Match each mechanism to its requirement.)
- S3 Object Lock in compliance mode
- AWS KMS external key store
- S3 Versioning
- AWS Private Certificate Authority
Answer and explanation
Answer: 1-A, 2-D, 3-B, 4-C. Compliance mode is the only option that binds the root user, which is what an absolute retention requirement demands. An external key store holds material outside AWS entirely, unlike a customer managed key whose material resides in KMS. Versioning preserves history but does not prevent deletion. Private CA operates a certificate authority rather than protecting stored objects, and is included because it is commonly mistaken for a data-at-rest control.
145. Objects in Amazon S3 must be unreadable without permission on a specific key, so that object permissions alone are insufficient. Which solution meets these requirements?
Answer and explanation
Answer: A. With SSE-KMS the object cannot be decrypted without kms:Decrypt on the key, so the key policy becomes a second independent gate. S3 managed keys are applied transparently with no separate permission check. Block Public Access prevents public exposure but authenticated principals with object permissions still read the data. Versioning preserves history.
146. A compliance requirement states that AWS must have no technical means to decrypt the organization's data. Which solution meets these requirements?
Answer and explanation
Answer: C. An external key store keeps key material in an external key manager the customer operates, so AWS never holds the material. A customer managed key's material resides in KMS. A CloudHSM custom key store keeps material in a customer-owned cluster within AWS. A key stored in Secrets Manager is held by AWS and retrievable with the right permissions.
147. A compliance archive must be immutable for seven years, and no principal including the account root user may delete it. Which solution meets these requirements?
Answer and explanation
Answer: C. Compliance mode blocks deletion and overwrite by every principal including root until retention expires. Governance mode can be bypassed by principals holding the bypass permission. A bucket policy can be modified by an administrator. MFA Delete adds an authentication step rather than creating immutability.
148. An organization must confirm that every Amazon EBS volume created in an account is encrypted, without relying on the requester. Which solution meets these requirements?
Answer and explanation
Answer: B. Encryption by default causes every new volume and snapshot to be encrypted regardless of the request, preventing the non-compliant state. A Config rule detects the volume after it exists and cannot encrypt it in place. An IAM deny applies only to principals it is attached to. A tag asserts intent without encrypting.
149. An organization must supply its own key material to an AWS KMS key so that it can be removed on demand. (Place the steps in the correct order.)
Answer and explanation
Answer: C → D → B → A. The key must exist with an external origin before any material can be imported, because the origin cannot be changed afterwards. The wrapping key and import token are then retrieved together and the token is valid for a limited period. The material is encrypted under the wrapping key before import so it is never transmitted in the clear. Expiration or deletion of the material is what makes the key immediately unusable, which is the control the requirement describes.
150. An organization must supply its own key material to an AWS KMS key and be able to render the key unusable on demand. Which solution meets these requirements?
Answer and explanation
Answer: B. Imported material is supplied by the customer and can be deleted independently of the key, which makes the key immediately unusable while the key itself persists. Disabling an AWS generated key can be reversed by anyone with the permission. Scheduling deletion has a mandatory waiting period and destroys the key permanently. Rotation creates new material without removing access.
151. A Secrets Manager rotation function for a database in private subnets fails on every scheduled run, although its IAM permissions are correct. Which cause should the team investigate first?
Answer and explanation
Answer: A. A rotation function placed in a VPC to reach a private database also needs a route to the Secrets Manager service, normally through an interface endpoint, and lacking either connection causes every run to fail. A maintenance window overlap would cause intermittent rather than consistent failure. The key type affects permissions rather than reachability. A password policy conflict would produce a rejection from the database rather than a function failure.
152. An organization must issue and manage private TLS certificates for internal services from an authority it controls. Which solution meets these requirements?
Answer and explanation
Answer: C. Private CA operates a certificate authority the organization controls and integrates with ACM for issuance and renewal. Public ACM certificates require domain validation and are for internet-facing endpoints. Self-signed certificates require manual trust distribution and have no revocation path. Storing external certificates does not create a controlled authority.
153. An organization must locate personally identifiable information across its Amazon S3 estate before granting analysts broader access. Which solution meets these requirements?
Answer and explanation
Answer: B. Macie applies managed and custom data identifiers to discover and classify sensitive data across S3. A crawler infers schema and column names without classifying values. Sampling is neither systematic nor complete. CloudTrail records who accessed objects rather than what they contain.
154. A KMS key used by several applications must be restricted so it can only decrypt data for requests originating from a specific VPC endpoint. Which solution meets these requirements?
Answer and explanation
Answer: A. Key policies support condition keys including aws:sourceVpce, which restricts use of the key to requests arriving through a named endpoint. KMS keys are not network resources and take no security group. Keys are regional service resources and are not placed in subnets. Grants scope operations to principals rather than to network paths.
155. An Application Load Balancer must reject clients negotiating an outdated TLS version. Which configuration is required?
Answer and explanation
Answer: A. The listener's security policy determines which protocol versions and ciphers are permitted. Certificate key length is independent of protocol version. Mutual TLS authenticates the client. WAF inspects request content after the connection is established.
156. Traffic between two VPCs must be encrypted even though it traverses only the AWS network. Which approach is appropriate?
Answer and explanation
Answer: A. Application-level TLS encrypts the payload irrespective of the underlying path, which is what a requirement to encrypt in transit means. Physical security is not encryption. Flow logs record metadata. Zone placement does not encrypt.
157. A Direct Connect connection must be encrypted, and the connection does not support MACsec. Which approach is appropriate?
Answer and explanation
Answer: A. A VPN over Direct Connect provides encryption where MACsec is unavailable, at some throughput cost. MACsec is supported only on specific connection types and locations. At-rest encryption does not protect the link. Reducing port speed does not add encryption.
158. An S3 bucket must reject any upload that does not specify encryption with a particular KMS key. Which approach is appropriate?
Answer and explanation
Answer: B. A bucket policy condition rejects a non-conforming upload from any principal. Default encryption applies the key when none is specified but does not reject an upload specifying a different one. Block Public Access prevents public exposure. An IAM policy binds only the principals it is attached to.
159. An EBS volume encrypted with one KMS key must be re-encrypted with a different key. Which approach is appropriate?
Answer and explanation
Answer: B. Re-encryption is performed by copying a snapshot with the new key and creating a volume from the copy, since a volume's key cannot be changed in place. Attaching does not change encryption. Encryption by default applies to newly created volumes.
160. Objects encrypted with SSE-KMS are generating a high volume of KMS requests and approaching a quota. Which approach is appropriate?
Answer and explanation
Answer: A. Bucket Keys derive a short-lived bucket-level key that dramatically reduces KMS request volume while retaining customer managed key control. Switching to S3 managed keys loses the key policy and audit trail. A quota increase treats the symptom at higher cost. Reducing object count changes the workload.
161. A KMS key must be made permanently unusable, and the organization requires the shortest possible waiting period. Which approach is appropriate?
Answer and explanation
Answer: A. Scheduled deletion enforces a waiting period with a documented minimum, and that wait cannot be bypassed for a standard key. Disabling is reversible rather than permanent. Removing the key policy leaves the key present and restorable. Material deletion applies to imported material rather than AWS generated material.
162. A secret must be shared with another account without copying its value. Which approach is appropriate?
Answer and explanation
Answer: B. A resource policy on the secret plus key permission allows the other account to retrieve it in place, so rotation propagates automatically. A synchronized copy drifts after rotation. A shared object and a passed parameter both duplicate the value outside the secret store.
163. A rotation function completes successfully but applications continue to receive the previous credential. Which cause should be investigated first?
Answer and explanation
Answer: C. Clients that cache a retrieved secret indefinitely continue using the old value regardless of rotation. A misconfigured schedule or missing permissions would prevent rotation completing, which the question excludes. Decrypt permission affects retrieval rather than freshness.
164. A private certificate authority's subordinate CA private key must never exist in software. Which approach is appropriate?
Answer and explanation
Answer: A. Hardware-backed key storage means the private key is generated in and never leaves the module. Generating in software creates a moment where it exists exportable. Storing a private key in a secret store keeps it exportable by design. Encrypting a key file still requires decrypting it to use.
165. A CloudWatch Logs data protection policy masks a value, but an operator with broad permissions can still read it. Which cause explains this?
Answer and explanation
Answer: A. Data protection masks values for readers without the unmask permission, so an operator holding it sees the original. Policies apply to new events, but the scenario describes a reader seeing the value rather than a timing gap. Encryption and identifier matching affect storage and detection rather than who may unmask.
166. An ACM certificate must be used by an Application Load Balancer in another Region. Which approach is required?
Answer and explanation
Answer: A. ACM certificates are Regional and must exist in the resource's Region, with CloudFront requiring one in a specific Region. Copying and cross-Region ARN references are not supported, and ACM-issued private keys cannot be exported.
167. An organization must be alerted before an ACM certificate expires. Which approach is appropriate?
Answer and explanation
Answer: B. Metric or event based alerting warns before expiry. Monthly review may miss a short window. Automatic renewal applies to eligible certificates and can fail validation. Calendar reminders drift as certificates change.
168. An API Gateway REST API must accept connections only over a minimum TLS version. Which configuration is appropriate?
Answer and explanation
Answer: C. The custom domain's security policy sets the minimum TLS version. WAF inspects application-layer requests after the connection. Mutual TLS authenticates clients. A resource policy restricts callers.
169. An organization must confirm that a KMS key has not been used by an unexpected principal. Which source is appropriate?
Answer and explanation
Answer: D. CloudTrail records every cryptographic operation with the caller. A key policy shows what is permitted rather than what occurred. Rotation status and aliases are configuration.
170. An RDS database must be encrypted, and it was created without encryption. Which approach is required?
Answer and explanation
Answer: C. An unencrypted RDS instance is encrypted by copying its snapshot with encryption and restoring. Encryption cannot be enabled in place, a Region default applies to new instances, and parameter groups do not control storage encryption.
171. An organization must ensure EFS file systems are encrypted at rest across all accounts. Which approach is appropriate?
Answer and explanation
Answer: A. A Config rule detects and a policy condition prevents. EFS encryption cannot be enabled after creation. Monthly review is retrospective. Instance volume encryption is unrelated to the file system.
172. A secret must be accessible only from a specific VPC endpoint. Which approach is appropriate?
Answer and explanation
Answer: D. A resource policy condition on the source endpoint restricts where retrieval may occur from. Secrets are not placed in subnets. Encryption protects the value. A tag condition restricts by resource attribute rather than network path.
173. An organization must discover secrets accidentally committed to source repositories. Which approach is appropriate?
Answer and explanation
Answer: B. Automated scanning finds committed secrets systematically and rotation removes the exposure. Self-review does not scale. Blanket rotation does not identify what leaked. Read restrictions do not remove the secret from history.
174. A Macie job must classify data using a pattern specific to the organization's internal identifiers. Which configuration is required?
Answer and explanation
Answer: D. A custom data identifier matches organization-specific patterns the managed identifiers do not know. Sampling depth and frequency affect coverage rather than what is recognised.
175. An organization must prevent a KMS key from being deleted accidentally. Which approach is appropriate?
Answer and explanation
Answer: B. A policy denying the deletion action prevents it being scheduled. The waiting period allows cancellation but the deletion is still initiated. Rotation and aliases are unrelated to deletion.
176. An application must use a certificate from AWS Private CA on an EC2 instance, with automatic renewal. Which approach is appropriate?
Answer and explanation
Answer: C. Managed integration handles issuance and renewal on the instance. Manual requests with reminders drift. Copying a certificate leaves renewal manual. A public certificate is not issued by the organization's private authority.