AmazonFree

AWS Certified Security Specialty SCSC02 AWS Certified Security Specialty SCSC02 Free Practice Test — 30 Questions

This practice set tests the ability to apply AWS security services in real-world scenarios, focusing on incident response, threat detection, data protection, and compliance. You'll analyze alerts from GuardDuty, Security Hub, and Config, and decide on remediation steps like isolating instances, modifying policies, or enabling logging. Questions emphasize the principle of least privilege, data residency controls via SCPs, and multi-layered defenses against DDoS and phishing. Behavioral competencies like adaptability under pressure are also assessed. Master the integration of services such as CloudTrail, IAM, and AWS Organizations to build robust security postures.

30
practice questions
20
recall cards
30
explanations
0
sign-ups required
Exam-focused analysis

What this AWS Certified Security Specialty SCSC02 AWS Certified Security Specialty SCSC02 practice set measures

This is an analysis of the practice bank, not a claim about the vendor's live exam blueprint. Use it to identify the knowledge, judgment, and recall patterns exercised here, then verify your coverage against the current official exam guide.

Incident Response and Forensics

This section covers the initial steps when a security incident is detected, such as unauthorized access or data exfiltration. It emphasizes using AWS CloudTrail for API activity reconstruction, GuardDuty for anomaly detection, and Security Hub for centralized findings. The practice bank tests your ability to prioritize containment, preservation of evidence, and compliance with notification timelines. Key decisions include revoking compromised credentials, isolating resources via security group changes, and enabling detailed logging.

  • Use CloudTrail logs to trace unauthorized S3 access and identify source IPs.
  • Leverage GuardDuty findings to detect malicious behavior like unusual API calls.
  • Isolate compromised EC2 instances by modifying security groups or using AWS Systems Manager.
  • Preserve evidence by enabling S3 access logs and CloudTrail with log integrity validation.

Proactive Threat Detection and Mitigation

This section focuses on preventing incidents before they escalate. It covers deploying GuardDuty for continuous threat monitoring, using AWS WAF and Shield Advanced for DDoS protection, and implementing IAM Access Analyzer to detect unintended access. The practice bank tests understanding of automated responses via EventBridge and Lambda, and the importance of custom WAF rules for application-layer attacks. You must decide between signature-based and anomaly-based detection.

  • Deploy GuardDuty for intelligent threat detection using ML and anomaly detection.
  • Implement AWS WAF with rate-based rules and AWS Shield Advanced for DDoS mitigation.
  • Use IAM Access Analyzer to continuously scan for overly permissive resource policies.
  • Automate response with EventBridge rules triggering Lambda functions for remediation.

Compliance and Data Residency Controls

This section addresses regulatory requirements like GDPR and PCI DSS. It tests knowledge of Service Control Policies (SCPs) to restrict API actions to specific regions, AWS Config rules for continuous compliance monitoring, and IAM policies with condition keys for data access control. The practice bank emphasizes preventing data exfiltration by enforcing least privilege and logging all access. You must understand how to deploy guardrails across multiple accounts using AWS Organizations.

  • Use SCPs in AWS Organizations to deny resource creation in non-approved regions.
  • Configure AWS Config rules to detect misconfigurations like publicly accessible S3 buckets.
  • Implement IAM policies with condition keys (e.g., source IP, MFA) for granular access control.
  • Enable CloudTrail and Config history for audit trails and compliance evidence.

Behavioral Competencies and Strategic Decision-Making

This section evaluates soft skills crucial for cloud security roles. Questions present scenarios requiring adaptability when new threats emerge or business priorities shift. You must demonstrate problem-solving under pressure, such as pivoting incident response strategies for serverless architectures or balancing security with business continuity during DDoS attacks. The practice bank tests leadership potential by asking you to coordinate cross-team responses and prioritize actions based on risk.

  • Adapt incident playbooks to handle zero-day exploits or new service deployments.
  • Prioritize containment and mitigation while minimizing service disruption.
  • Engage compliance teams when regulatory requirements change.
  • Evaluate trade-offs between security controls and operational agility.
Active recall deck

Practice AWS Certified Security Specialty SCSC02 AWS Certified Security Specialty SCSC02 with real flashcards

Read the prompt, commit to an answer, then flip the card. Move through the deck at your own pace and repeat any topic that does not come back quickly.

20 free cards

Card 1 of 20

1 reviewed this session

Static practice bank

Start the 30-question diagnostic

The complete question bank is embedded in this pre-rendered page. There is no database request or second content download when you begin.

Question 1 of 30

A multinational e-commerce company operating on AWS has detected anomalous outbound network traffic originating from an EC2 instance in its European (Frankfurt) region. Initial investigations suggest a potential exfiltration of customer data, including Personally Identifiable Information (PII), which could trigger stringent notification requirements under regulations like the GDPR. The company’s Chief Information Security Officer (CISO) needs a consolidated view of security findings, an assessment of the potential impact on sensitive data, and a mechanism to streamline the preparation of evidence for regulatory compliance reporting. Which AWS service would be most instrumental in facilitating this initial assessment and compliance preparation phase of the incident response?

1 correct answers

Study workflow

Turn one AWS Certified Security Specialty SCSC02 AWS Certified Security Specialty SCSC02 attempt into a study plan

  1. 1

    Contain and Investigate

    Immediately revoke compromised credentials or isolate affected resources. Enable detailed logging via CloudTrail and VPC Flow Logs. Correlate alerts from GuardDuty and Security Hub to understand attack vector.

  2. 2

    Apply Least Privilege

    Review IAM policies and S3 bucket policies. Use IAM Access Analyzer to identify overly permissive access. Implement SCPs to deny actions in non-compliant regions. Enforce MFA for all users.

  3. 3

    Automate Detection and Response

    Set up EventBridge rules to trigger Lambda functions on high-severity findings. Use AWS Config rules to automatically remediate misconfigurations. Integrate Security Hub for centralized alerting.

  4. 4

    Mitigate DDoS and Application Attacks

    Activate AWS Shield Advanced for network-layer protection. Deploy AWS WAF with custom rate-based rules and geo-blocking. Ensure scalability using auto-scaling groups to absorb traffic.

  5. 5

    Maintain Compliance Posture

    Enable AWS Config for continuous monitoring against regulatory benchmarks. Schedule regular audits with CloudTrail logs. Use Security Hub to track compliance scores and generate reports for auditors.

FAQ

Questions about this exam practice page

Clear boundaries on what the bank covers, how to use it, and where official vendor information still matters.

What is the primary difference between AWS GuardDuty and AWS Security Hub?+

GuardDuty is a threat detection service that analyzes logs for malicious activity and generates findings. Security Hub aggregates findings from multiple services, including GuardDuty, and provides a centralized view of your security posture and compliance.

How can I enforce data residency in AWS for GDPR compliance?+

Use AWS Organizations Service Control Policies (SCPs) to deny API actions in non-approved regions. Also, implement AWS Config rules to detect resources deployed outside allowed regions and trigger alerts or remediation.

What steps should I take first when a data exfiltration incident is detected?+

Immediately revoke compromised credentials and isolate the affected resource (e.g., modify security group). Enable detailed logging via CloudTrail and VPC Flow Logs. Analyze GuardDuty findings and CloudTrail logs to identify the source and scope.

Can AWS WAF alone stop all DDoS attacks?+

No. AWS WAF protects against application-layer attacks, but for network-layer volumetric attacks you also need AWS Shield Advanced which provides enhanced detection and mitigation. A multi-layered approach using both is recommended.

How do I ensure that only authorized administrators can access sensitive S3 buckets?+

Use IAM policies with condition keys (e.g., requiring MFA, specific source IP, or time-of-day). Enable S3 access logging and CloudTrail for auditing. Regularly review permissions with IAM Access Analyzer.

Keep studying

Build the next review session

Browse another free bank or use the study strategy guide to turn your misses into spaced review.