36 practice questions for Domain 6 of the AWS Certified Security - Specialty (SCS-C03) exam, which makes up 14% of its scored content. Your answers count towards one score and one timer for the whole exam.
Domain 6: Security Foundations and Governance
177. A new AWS Organizations member account must be brought under central security governance. (Place the steps in the correct order.)
Answer and explanation
Answer: D → B → C → A. Placement in the correct organizational unit comes first because policy inheritance follows the hierarchy, and nothing else applies until the account sits in the right place. Confirming the service control policies took effect verifies the preventive layer. Enabling the security services through the delegated administrator establishes detection. Reviewing findings last confirms the whole baseline is reporting, which cannot be verified before the services are enabled.
178. An organization using AWS Control Tower must block a non-compliant resource configuration before it is created rather than detecting it afterwards. Which control type should be applied?
Answer and explanation
Answer: C. Proactive controls evaluate a resource configuration before provisioning and block a non-compliant deployment, which is the requirement. Detective controls, with or without remediation, act after the resource exists. A preventive service control policy could deny the resource type outright but cannot distinguish a compliant configuration from a non-compliant one.
179. An organization must enforce a service configuration, such as blocking public access, across all accounts in a way that cannot be altered locally and applies to accounts created later. Which solution meets these requirements?
Answer and explanation
Answer: B. Declarative policies enforce a service configuration centrally so the desired state persists even as services add features, and they apply to accounts that join later. Manual application drifts. StackSets deploy resources that can be changed locally afterwards. A conformance pack reports rather than enforces.
180. A service control policy restricting aws:RequestedRegion has been applied, and IAM and AWS Organizations calls in member accounts have begun failing. Which correction should be made?
Answer and explanation
Answer: C. Global services such as IAM, Organizations, and Route 53 direct their calls to a single Region endpoint, so a blanket region condition denies them and a NotAction exception is required. Source IP restricts by network location rather than Region. Attachment point does not change how the condition evaluates. The management account is not affected by service control policies in any case.
181. A security tooling account must be able to administer Amazon GuardDuty, AWS Security Hub, and IAM Access Analyzer for the whole organization without using the management account. Which solution meets these requirements?
Answer and explanation
Answer: C. Delegated administration gives a member account organization-wide control of a security service while keeping the management account reserved for organization operations. Cross-account roles into every account is far more access than administering the service requires. Sharing management account credentials violates every credential guideline. A separate organization would not include the accounts to be administered.
182. An organization must prevent member accounts from disabling AWS CloudTrail or deleting its trails. Which solution meets these requirements?
Answer and explanation
Answer: C. A service control policy caps the permissions available in a member account and cannot be removed from inside it. An IAM deny attached to administrators can be detached by those administrators. A remediation rule acts after logging has already stopped. Log file validation proves integrity of delivered files rather than preventing the trail being stopped.
183. An infrastructure pipeline must prevent a template that would create a publicly readable Amazon S3 bucket from ever being deployed. Which solution meets these requirements?
Answer and explanation
Answer: B. Scanning templates in the pipeline evaluates the intended configuration before any resource exists and fails the build, which is prevention. A Config rule detects the bucket after creation. A manual approval depends on a reviewer noticing one setting in a large template. Applying Block Public Access afterwards leaves a window of exposure.
184. AWS WAF rules and security group baselines must be deployed and continuously enforced across every account from a single place. Which solution meets these requirements?
Answer and explanation
Answer: C. Firewall Manager centrally creates and enforces protection policies across an organization and remediates drift automatically. StackSets deploy the resources without continuously enforcing them. A service control policy restricts actions rather than requiring resources to exist. A conformance pack reports without applying.
185. A deployment role used by a pipeline must be prevented from granting itself broader permissions. Which solution meets these requirements?
Answer and explanation
Answer: C. A permissions boundary caps effective permissions, and requiring it on created roles closes the escalation path through role creation. Denying all IAM actions breaks deployments that legitimately manage roles. Multi-factor authentication does not apply to a service role assumed by a pipeline. A shorter session limits exposure time without preventing escalation.
186. An organization must allow developers to provision only approved infrastructure patterns without granting them broad creation permissions. Which solution meets these requirements?
Answer and explanation
Answer: B. Service Catalog publishes curated products with launch constraints, so users provision approved patterns without holding the underlying creation permissions. Granting those actions is the broad permission being avoided. Config reports non-compliance after resources exist. A shared repository relies on developers choosing the right template.
187. An organization must continuously evaluate every account against a published control framework and collect the evidence an auditor will request. Which solution meets these requirements?
Answer and explanation
Answer: B. Audit Manager maps controls to evidence sources and collects the evidence continuously, producing an assessment report for the auditor. A conformance pack evaluates configuration rules without assembling framework evidence. Security Hub standards check security configuration rather than mapping to an audit framework. Trusted Advisor provides best-practice checks.
188. An organization conformance pack deployed from the delegated administrator account is reported as non-compliant in several member accounts, although the rules themselves evaluate correctly elsewhere. Which cause should the team investigate first?
Answer and explanation
Answer: C. A conformance pack evaluates recorded configuration items, so an account where the configuration recorder is absent or stopped reports non-compliance regardless of the rules. A rule count limit would prevent deployment rather than produce evaluation failures. Region opt-out would prevent the pack deploying at all. Security Hub consumes Config findings but its absence does not affect evaluation.
189. An auditor requires the AWS SOC 2 report and the signed Business Associate Addendum on demand. Which solution meets these requirements?
Answer and explanation
Answer: B. Artifact is the self-service portal for AWS audit artifacts and agreements including SOC reports and the Business Associate Addendum. Audit Manager produces evidence about the customer's own environment rather than AWS audit reports. Security Hub reports the customer's own compliance posture. A quota case is unrelated to compliance documentation.
190. A service control policy must permit a specific action while denying everything else in a member account. Which policy structure is required?
Answer and explanation
Answer: C. A service control policy filters what identity policies can take effect, so an allow list defines the ceiling and identity policies must still grant within it. Enumerating every action to deny is impractical. An allow wildcard with denies is a valid pattern but does not match a requirement to permit only a specific action. Permissions boundaries attach to identities rather than organizational units.
191. A declarative policy and a service control policy both apply to the same account. Which statement describes their relationship?
Answer and explanation
Answer: D. Declarative policies enforce a desired service configuration that persists as the service evolves, while service control policies bound what principals may do. They are complementary rather than competing. Attachment proximity governs inheritance within a policy type rather than between types.
192. A delegated administrator for a security service must be changed to a different member account. Which consideration applies?
Answer and explanation
Answer: D. A service supports one delegated administrator at a time, so the existing designation is removed first, and data accumulated in the previous administrator may not move. Simultaneous delegation and automatic transfer are not supported. Recreating the organization is unnecessary.
193. A CloudFormation template must be prevented from deploying a resource configuration that violates policy, and the check must run before any resource is created. Which approach is appropriate?
Answer and explanation
Answer: A. Evaluating the template before deployment prevents the resource existing at all. Config detects after creation. A stack policy governs updates to an existing stack. Pull request review depends on a reviewer noticing one setting.
194. A Service Catalog product must let users provision a resource without holding permission to create it directly. Which configuration is required?
Answer and explanation
Answer: B. A launch constraint means Service Catalog provisions with its own role, so the user needs no underlying permission. Granting the creation permission is what the constraint avoids. A template constraint limits parameter values. Tag options apply tags.
195. An organization must ensure that only container images signed by its build system are deployed. Which approach is appropriate?
Answer and explanation
Answer: A. Signature verification at admission establishes provenance at the moment of deployment. Push restrictions control who writes to one registry but do not prevent deploying from elsewhere. Vulnerability scanning assesses content rather than origin. A recorded digest identifies an image without proving who built it.
196. An AWS Config rule must evaluate resources continuously rather than only when they change. Which configuration is required?
Answer and explanation
Answer: A. A periodic trigger evaluates on a schedule regardless of whether a change occurred. Delivery frequency governs configuration snapshot delivery. Regional enablement affects coverage rather than timing. Remediation acts on results.
197. An Audit Manager assessment reports evidence gaps for a control although the underlying data sources are configured. Which cause should be investigated first?
Answer and explanation
Answer: C. Evidence is collected only from accounts and Regions within the assessment scope, so a gap commonly reflects scope rather than configuration. Framework version affects which controls are assessed. Report generation renders collected evidence. A delegated administrator change would affect the assessment more broadly.
198. A compliance requirement states that an AWS SOC report must be provided to an auditor under a non-disclosure agreement. Which approach is appropriate?
Answer and explanation
Answer: C. Artifact distributes AWS audit reports with their terms of use presented at download. Support cases are for technical issues. Audit Manager produces evidence about the customer's own environment. Public web pages summarise compliance programmes rather than providing the report.
199. An organization must apply a control to all accounts except one that requires an exception. Which approach is appropriate?
Answer and explanation
Answer: B. Organizational unit structure expresses policy differences cleanly. Conditional exceptions in a root policy grow complex and error-prone. Omitting the control leaves everything unprotected. Manual application drifts.
200. An organization must ensure a newly created account is enrolled in centralized security services automatically. Which approach is appropriate?
Answer and explanation
Answer: C. Automatic enrolment covers new accounts without action. Manual onboarding and process reliance both depend on people. A weekly sweep leaves a gap.
201. An organization must confirm which accounts are not covered by a required control. Which approach is appropriate?
Answer and explanation
Answer: D. Aggregated compliance data reports coverage across the organization. Per-account checking and owner confirmation do not scale. An account list shows membership rather than control coverage.
202. A management account must be protected because service control policies do not apply to it. Which approach is appropriate?
Answer and explanation
Answer: A. Service control policies do not constrain the management account, so the mitigation is to keep workloads out and restrict access. Attaching a policy to it has no effect. Broad administrator access widens exposure. Enabling detection in one account leaves others uncovered.
203. An organization must be able to revoke a member account's access to a shared resource immediately. Which approach is appropriate?
Answer and explanation
Answer: D. Removing the account from the share revokes its access to that resource. Deleting the resource affects every consumer. Removing the account from the organization is disproportionate. Tags do not govern share membership.
204. An organization must prevent member accounts from creating IAM users while permitting role creation. Which approach is appropriate?
Answer and explanation
Answer: A. A service control policy denying the specific action achieves exactly the stated split. Denying all IAM actions blocks role creation too. Deletion after creation leaves a window. Multi-factor authentication permits creation by an authenticated principal.
205. An organization must prevent a CloudFormation stack from creating a resource type that policy forbids. Which approach is appropriate?
Answer and explanation
Answer: A. A service control policy denies the underlying create action irrespective of how it is invoked. Manual review depends on a reviewer. A Config rule reports after creation. A template library does not prevent other templates.
206. A pipeline's deployment role must be prevented from modifying security controls. Which approach is appropriate?
Answer and explanation
Answer: D. An explicitly scoped and denied policy prevents the modification. Administrator access with monitoring detects afterwards. Approval addresses intent rather than capability. Session duration limits time.
207. An organization must ensure infrastructure templates are scanned for policy violations before merge. Which approach is appropriate?
Answer and explanation
Answer: D. A required pull request check blocks a violating template before it merges. Post-deployment scanning, meeting review, and published policy are all after the fact or advisory.
208. An organization must apply consistent security group baselines across accounts and remediate drift. Which approach is appropriate?
Answer and explanation
Answer: D. Firewall Manager applies and continuously remediates security group policies across the organization. StackSets deploy without ongoing enforcement. A Config rule reports. Quarterly audit is periodic.
209. An organization must ensure that only approved AMIs can be used to launch instances. Which approach is appropriate?
Answer and explanation
Answer: A. A launch condition prevents non-conforming instances existing. Documentation is advisory. Deleting AMIs does not prevent using shared or public ones. A Config rule reports after launch.
210. An organization must produce evidence that a control operated across every account for an audit period. Which approach is appropriate?
Answer and explanation
Answer: B. An organization-scoped assessment collects evidence continuously across accounts. Point-in-time exports, screenshots, and attestations do not demonstrate sustained operation.
211. A conformance pack must be applied across an organization with account-specific parameter values. Which approach is appropriate?
Answer and explanation
Answer: D. Organization conformance packs support parameters that can differ by organizational unit. Per-account packs multiply maintenance. A single value ignores genuine differences. Manual deployment drifts.
212. An organization must detect when an account drifts from its Control Tower baseline. Which approach is appropriate?
Answer and explanation
Answer: A. Control Tower detects drift and supports re-enrollment or remediation. Redeploying the landing zone is disproportionate. Manual review does not scale. Removing the account abandons governance.