Step2Study
IT & TechnologySCS-C02100% Free

AWS Certified Security – Specialty

Practice bank
207 Qs
Real exam
65 Qs
Time limit
170 min
Passing
750 out of 1000

Exam blueprint

Domain 1: Incident Response
12%
Domain 2: Logging and Monitoring
20%
Domain 3: Infrastructure Security
20%
Domain 4: Identity and Access Management
20%
Domain 5: Data Protection
28%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 235 min · pass 75% · 207 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

AWS Certified Security – Specialty practice test questions

Sample questions from the 207-question bank, with answers and explanations.

All questions
  1. 1. A financial institution is storing sensitive customer transaction data in Amazon S3. Due to regulatory compliance, this data must be retained for 7 years in an immutable state, meaning it cannot be deleted or modified by anyone, including root users, for the duration of the retention period. After 7 years, the data can be automatically deleted. Which combination of S3 features will meet these requirements most effectively?

    Domain 5: Data Protection

    • A. S3 Glacier Deep Archive storage class with a vault lock policy set for 7 years and S3 Lifecycle rules for transition.
    • B. S3 Versioning enabled and an S3 bucket policy denying 's3:DeleteObject' and 's3:PutObject' for 7 years, then S3 Lifecycle rules.
    • C. S3 Object Lock in Compliance mode with a retention period of 7 years and S3 Lifecycle rules for expiration.
    • D. S3 Object Lock in Governance mode with a retention period of 7 years and S3 Lifecycle rules for expiration.
    Show answer

    C. S3 Object Lock in Compliance mode with a retention period of 7 years and S3 Lifecycle rules for expiration.

    S3 Object Lock in Compliance mode prevents any user, including the root user, from deleting or overwriting an object until its retention period expires. Setting a 7-year retention period directly addresses the immutability requirement. S3 Lifecycle rules can then be used to automatically expire and delete the objects after the 7 years.

  2. 2. A research institution stores highly sensitive genomic data in an Amazon S3 bucket. This data must remain immutable for a minimum of 10 years to comply with regulatory mandates, meaning it cannot be overwritten or deleted by any user, including the root account. After 10 years, the data can be automatically deleted. Which S3 feature should be used to enforce this immutability and automatic deletion?

    Domain 5: Data Protection

    • A. S3 Object Lock in Compliance mode with a retention period of 10 years and an S3 Lifecycle policy for expiration.
    • B. S3 Versioning combined with an S3 Lifecycle policy to transition to S3 Glacier Deep Archive after 10 years.
    • C. S3 Object Lock in Governance mode with a retention period of 10 years and an S3 Lifecycle policy for expiration.
    • D. S3 Bucket Policy that explicitly denies 's3:DeleteObject' and 's3:PutObject' for 10 years.
    Show answer

    A. S3 Object Lock in Compliance mode with a retention period of 10 years and an S3 Lifecycle policy for expiration.

    S3 Object Lock in Compliance mode prevents any user, including the root account, from deleting or overwriting objects for the specified retention period (10 years). An S3 Lifecycle policy can then automatically delete the objects after this period.

  3. 3. A security team needs to ensure that all IAM users in a specific AWS account are forced to enable multi-factor authentication (MFA) for console access. If a user attempts to access the console without MFA, the access should be denied. Which IAM policy condition should be used to enforce this requirement?

    Domain 4: Identity and Access Management

    • A. ```json { "Condition": { "NumericGreaterThan": { "aws:MultiFactorAuthAge": "0" } } } ```
    • B. ```json { "Condition": { "Null": { "aws:MultiFactorAuthPresent": "false" } } } ```
    • C. ```json { "Condition": { "StringEquals": { "aws:MultiFactorAuthAge": "0" } } } ```
    • D. ```json { "Condition": { "Bool": { "aws:MultiFactorAuthPresent": "true" } } } ```
    Show answer

    A. ```json { "Condition": { "NumericGreaterThan": { "aws:MultiFactorAuthAge": "0" } } } ```

    The `aws:MultiFactorAuthAge` condition key checks how long ago (in seconds) the user authenticated with MFA. By setting `NumericGreaterThan: {"aws:MultiFactorAuthAge": "0"}`, the policy ensures that the user has authenticated with MFA within the current session, effectively requiring MFA for the action. This condition is typically used in a 'Deny' statement for actions where MFA is required, or in an 'Allow' statement where MFA is a prerequisite for permission.

  4. 4. A company uses AWS SSO (IAM Identity Center) to manage access to multiple AWS accounts. They have several AWS accounts organized into Organizational Units (OUs). A new security policy requires that all users in the 'Developers' group, who are part of the 'Development' OU, must have read-only access to all S3 buckets in their respective development accounts. How should this be configured using IAM Identity Center?

    Domain 4: Identity and Access Management

    • A. Attach an inline policy to each 'Developers' IAM user in each development account with S3 read-only permissions.
    • B. Implement a Service Control Policy (SCP) in the 'Development' OU to grant S3 read-only access to the 'Developers' group.
    • C. Define a permission set with S3 read-only access and assign it to the 'Developers' group for the 'Development' OU.
    • D. Create an IAM role with S3 read-only permissions in each development account and manually assign it to the 'Developers' group.
    Show answer

    C. Define a permission set with S3 read-only access and assign it to the 'Developers' group for the 'Development' OU.

    IAM Identity Center uses permission sets to define access to AWS accounts. By creating a permission set with S3 read-only access and assigning it to the 'Developers' group for the 'Development' OU, access is centrally managed and automatically provisioned to all accounts within that OU for the specified group.

  5. 5. A global e-commerce company uses Amazon S3 to store customer order data. Due to varying international data privacy regulations, the company must classify its data based on sensitivity (e.g., Public, Internal, Confidential, Restricted) and apply appropriate retention policies and access controls. Public data can be stored indefinitely, Internal data for 5 years, Confidential for 7 years, and Restricted for 10 years. What is the most effective and scalable way to implement this data classification and lifecycle management within AWS, ensuring compliance and minimizing operational overhead?

    Domain 5: Data Protection

    • A. Manually tag each S3 object with its classification and use S3 Lifecycle rules based on object tags.
    • B. Store data in separate S3 buckets for each classification level and apply bucket-level lifecycle rules.
    • C. Implement a custom application to analyze object content, assign metadata tags, and trigger S3 Glacier Deep Archive for long-term retention.
    • D. Utilize AWS Macie to discover and classify sensitive data, then configure S3 Lifecycle rules based on Macie findings.
    Show answer

    A. Manually tag each S3 object with its classification and use S3 Lifecycle rules based on object tags.

    Tagging S3 objects with classification metadata and then applying S3 Lifecycle rules based on these object tags is a highly effective and scalable method. It allows for granular control over data retention policies without requiring separate buckets for each classification, simplifying management and enabling flexible transitions between storage classes or deletion.

  6. 6. A large enterprise with a complex AWS environment is migrating applications that require robust, centralized logging and auditing of all AWS API calls and related events across all accounts in their AWS Organization. They need to ensure that the audit logs are immutable, encrypted, and stored in a central, secure S3 bucket that cannot be tampered with, even by root users of individual member accounts. Which solution should the security architect recommend?

    Domain 4: Identity and Access Management

    • A. Enable AWS Config recorder in all accounts and aggregate findings to a central account.
    • B. Configure individual CloudTrail trails in each member account, delivering logs to a dedicated S3 bucket in each account.
    • C. Use AWS Security Hub to aggregate security findings and CloudWatch Logs for event storage.
    • D. Implement a CloudTrail organization trail delivered to a central S3 bucket with S3 Object Lock enabled in compliance mode.
    Show answer

    D. Implement a CloudTrail organization trail delivered to a central S3 bucket with S3 Object Lock enabled in compliance mode.

    A CloudTrail organization trail centralizes logging of all API activity from all member accounts to a single S3 bucket. Enabling S3 Object Lock in compliance mode on this central bucket ensures that logs are immutable and cannot be deleted or overwritten, even by the root user, addressing the immutability and tamper-proof requirements.

  7. 7. A global software company is developing a new application that processes highly sensitive customer financial data. The company has a strict policy that all encryption keys must be generated, stored, and managed in an external key management system (KMS) located outside of AWS. The application needs to encrypt data before it is uploaded to Amazon S3. Which method should the company use to meet this requirement?

    Domain 5: Data Protection

    • A. Client-side encryption using a customer-managed encryption library that integrates with the external KMS.
    • B. AWS KMS Custom Key Store (CKS) integrated with an AWS CloudHSM cluster to store the keys.
    • C. Server-Side Encryption with Customer-Provided Keys (SSE-C).
    • D. Server-Side Encryption with AWS KMS (SSE-KMS) and a multi-Region key.
    Show answer

    A. Client-side encryption using a customer-managed encryption library that integrates with the external KMS.

    Client-side encryption, where the encryption and decryption occur on the client application side, allows the use of an external key management system entirely outside of AWS. The customer's application encrypts the data using keys from their external KMS before sending it to S3, ensuring the keys never touch AWS infrastructure.

  8. 8. A company policy dictates that all AWS IAM users must use strong, unique passwords and enable Multi-Factor Authentication (MFA). An AWS Config rule is in place to detect non-compliant MFA settings for IAM users. However, the security team needs a proactive measure to prevent users from disabling their MFA devices or changing their password policy settings after they have been configured correctly. Which IAM condition key should be used in an IAM policy to prevent these changes?

    Domain 4: Identity and Access Management

    • A. aws:SourceIp
    • B. iam:MFAPresent
    • C. aws:MultiFactorAuthAge
    • D. aws:RequestedRegion
    Show answer

    B. iam:MFAPresent

    The `iam:MFAPresent` condition key can be used in an IAM policy to require MFA for specific actions. By attaching a policy that denies actions like `iam:DeactivateMFADevice` or `iam:ChangePassword` unless `iam:MFAPresent` is 'true', users cannot disable their MFA or change password policies without MFA, providing a proactive control.

  9. 9. A global banking institution uses Amazon S3 to store transaction logs. Due to compliance regulations, these logs must be retained for 7 years and remain immutable, meaning they cannot be deleted or modified by any user, including the root account. After the 7-year retention period, the logs can be automatically deleted to manage storage costs. Which S3 configuration should be implemented?

    Domain 5: Data Protection

    • A. Apply S3 Object Lock in Compliance mode with a retention period of 7 years and a lifecycle rule to expire objects.
    • B. Enable S3 Versioning on the bucket and configure a lifecycle rule to expire current versions after 7 years.
    • C. Apply S3 Object Lock in Governance mode with a retention period of 7 years and a lifecycle rule to expire objects.
    • D. Implement an S3 bucket policy denying all `s3:DeleteObject` and `s3:PutObject` actions for 7 years, then remove the policy.
    Show answer

    A. Apply S3 Object Lock in Compliance mode with a retention period of 7 years and a lifecycle rule to expire objects.

    S3 Object Lock in Compliance mode provides the strongest immutability, preventing deletion or modification by any user, including the root account, for the specified 7-year retention period. A lifecycle rule will then automatically delete the objects upon expiration.

  10. 10. A research institution is storing petabytes of genomic data in Amazon S3. This data is rarely accessed after its initial upload and processing, but must be retained for at least 10 years for compliance reasons. The institution needs to minimize storage costs while ensuring data integrity and durability. Which S3 storage class is the most cost-effective solution for this scenario?

    Domain 5: Data Protection

    • A. Amazon S3 Glacier Instant Retrieval
    • B. Amazon S3 Glacier Deep Archive
    • C. Amazon S3 Standard-Infrequent Access (S3 Standard-IA)
    • D. Amazon S3 One Zone-Infrequent Access (S3 One Zone-IA)
    Show answer

    B. Amazon S3 Glacier Deep Archive

    Amazon S3 Glacier Deep Archive is designed for long-term archival and is the lowest-cost storage class in S3. Given the requirement for 10-year retention and rare access, it perfectly aligns with minimizing storage costs while providing high durability.

  11. 11. A research institution is storing petabytes of genomic data in Amazon S3. This data is rarely accessed (less than once a year) but must be retained for regulatory purposes for at least 10 years. When access is required, it can tolerate retrieval times of several hours. The institution needs the most cost-effective storage solution while meeting these requirements. Which S3 storage class should be used?

    Domain 5: Data Protection

    • A. Amazon S3 Standard-Infrequent Access (S3 Standard-IA)
    • B. Amazon S3 Glacier Deep Archive
    • C. Amazon S3 Glacier
    • D. Amazon S3 One Zone-Infrequent Access (S3 One Zone-IA)
    Show answer

    B. Amazon S3 Glacier Deep Archive

    Amazon S3 Glacier Deep Archive is the lowest-cost storage class for archival data in S3, designed for data accessed once or twice a year, with retrieval times of 12-48 hours. This perfectly matches the requirement for rarely accessed data, 10-year retention, and tolerance for multi-hour retrieval times.

  12. 12. A company is using AWS Cognito User Pools for customer authentication in their mobile application. They want to integrate with another backend service that requires temporary, fine-grained access to AWS resources (e.g., uploading files to a specific S3 bucket). The integration needs to be secure and minimize the exposure of long-term credentials. Which service should be used to provide these temporary AWS credentials to the authenticated Cognito users?

    Domain 4: Identity and Access Management

    • A. AWS Security Token Service (STS) `AssumeRole` API call directly from the mobile app.
    • B. An Amazon Cognito Identity Pool (Federated Identities).
    • C. AWS IAM users with programmatically generated access keys.
    • D. AWS IAM Identity Center (formerly AWS SSO)
    Show answer

    B. An Amazon Cognito Identity Pool (Federated Identities).

    Amazon Cognito Identity Pools (Federated Identities) are specifically designed to provide temporary AWS credentials to users authenticated through various identity providers, including Cognito User Pools. After a user authenticates with a User Pool, the Identity Pool exchanges the User Pool token for temporary, role-based AWS credentials, allowing the mobile application to securely access AWS resources.

  13. 13. A company is implementing a new compliance requirement that mandates all access to AWS resources must originate from corporate IP addresses, with the exception of specific mobile users who need to access resources from anywhere using multi-factor authentication (MFA). How can this be achieved using IAM policies?

    Domain 4: Identity and Access Management

    • A. Create an IAM policy that explicitly denies access if the source IP is not from corporate ranges, and then create a separate policy for mobile users that allows access only if `aws:MultiFactorAuthPresent` is 'true'.
    • B. Use AWS WAF to block non-corporate IPs and rely on IAM policies for MFA enforcement.
    • C. Create an IAM policy that includes a `Condition` to allow access only from corporate IP ranges and another `Condition` to allow access if MFA is present, applying this policy to all users.
    • D. Create two separate IAM policies: one that denies access if the source IP is not from corporate ranges, and another that allows access only if MFA is present, attaching both to all users.
    Show answer

    A. Create an IAM policy that explicitly denies access if the source IP is not from corporate ranges, and then create a separate policy for mobile users that allows access only if `aws:MultiFactorAuthPresent` is 'true'.

    IAM policies are evaluated in a specific order: explicit deny takes precedence over explicit allow, which takes precedence over implicit deny. By creating an explicit deny for non-corporate IPs and then a separate allow policy for mobile users that requires MFA, the system correctly enforces the corporate IP restriction while providing a specific, secure exception for mobile users. The explicit deny policy ensures that without the specific MFA 'allow' for mobile, all non-corporate IPs are blocked.

  14. 14. A global enterprise collects and processes customer data from various regions worldwide. Due to strict data residency regulations in the EU, all data originating from EU customers must be stored and processed exclusively within the EU. The enterprise uses Amazon S3 for data storage and AWS Lambda for processing. How can the company ensure data residency for EU customer data?

    Domain 5: Data Protection

    • A. Implement client-side encryption for all EU customer data before uploading to S3, regardless of the S3 bucket's region.
    • B. Use AWS PrivateLink to connect S3 buckets in any region to on-premises data centers located in the EU.
    • C. Store all EU customer data in an S3 bucket in a US region and apply a bucket policy that denies access from outside the EU.
    • D. Utilize an S3 bucket in an EU region (e.g., eu-west-1) and configure Lambda functions to run exclusively in the same EU region.
    Show answer

    D. Utilize an S3 bucket in an EU region (e.g., eu-west-1) and configure Lambda functions to run exclusively in the same EU region.

    To ensure data residency, both storage and processing must occur within the specified geographic region. Storing data in an S3 bucket in an EU region and configuring Lambda functions to execute within the same EU region ensures that the data and its processing remain within the EU boundaries, satisfying the regulatory requirement.

  15. 15. A healthcare provider stores sensitive patient health information (PHI) in an Amazon S3 bucket. They are required to encrypt all new objects uploaded to this bucket by default. Additionally, they need to ensure that the encryption keys are centrally managed and that access to these keys is auditable. Which S3 encryption configuration meets these requirements while providing central key management and auditability?

    Domain 5: Data Protection

    • A. Implement client-side encryption using the AWS Encryption SDK with a customer-provided encryption key (SSE-C).
    • B. Configure S3 bucket default encryption to use Server-Side Encryption with S3-managed keys (SSE-S3).
    • C. Use S3 bucket policies to enforce that only objects encrypted with customer-provided encryption keys (SSE-C) are allowed.
    • D. Configure S3 bucket default encryption to use Server-Side Encryption with AWS Key Management Service (AWS KMS) customer managed keys (CMKs).
    Show answer

    D. Configure S3 bucket default encryption to use Server-Side Encryption with AWS Key Management Service (AWS KMS) customer managed keys (CMKs).

    SSE-KMS, configured as default bucket encryption, ensures all new objects are encrypted automatically. Using a KMS CMK provides central key management, allows for granular key policies, and integrates with AWS CloudTrail for auditing all key usage, fulfilling all stated requirements.

  16. 16. A company is implementing a data loss prevention (DLP) strategy for sensitive documents stored in Amazon S3. The company needs to automatically identify documents containing PII (e.g., social security numbers, credit card numbers) and prevent them from being shared publicly or with unauthorized external parties. Which AWS service is best suited for automatically discovering, classifying, and reporting on such sensitive data in S3?

    Domain 5: Data Protection

    • A. AWS Detective
    • B. Amazon Macie
    • C. AWS Security Hub
    • D. AWS Config
    Show answer

    B. Amazon Macie

    Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to discover, classify, and protect sensitive data in AWS, specifically focusing on S3. It automatically detects and alerts on PII and other sensitive data, making it ideal for DLP strategies.

  17. 17. A financial institution is migrating its on-premises applications to AWS. These applications rely heavily on Kerberos authentication and LDAP for user and group management. The institution requires a fully managed directory service that can seamlessly integrate with their existing on-premises Active Directory while providing high availability and disaster recovery within AWS. They also need to ensure that AWS services can directly authenticate against this directory. Which AWS directory service best meets these requirements?

    Domain 4: Identity and Access Management

    • A. AWS Directory Service for Simple AD
    • B. AWS Directory Service for AD Connector
    • C. Amazon Cognito User Pools
    • D. AWS Directory Service for Microsoft Active Directory (Enterprise Edition)
    Show answer

    D. AWS Directory Service for Microsoft Active Directory (Enterprise Edition)

    AWS Directory Service for Microsoft Active Directory (Enterprise Edition) is a fully managed, highly available directory that provides true Microsoft Active Directory functionality. It supports Kerberos, LDAP, and seamless integration with existing on-premises AD, making it ideal for the requirements of a financial institution.

  18. 18. A company is implementing a new policy that requires all S3 buckets to be encrypted at rest. They want to ensure that if a user attempts to upload an unencrypted object to any S3 bucket, the upload fails. Additionally, all existing unencrypted objects must be encrypted. Which combination of S3 features will provide the most comprehensive solution without requiring changes to existing application code?

    Domain 4: Identity and Access Management

    • A. Use AWS Config rules to detect unencrypted objects and trigger a Lambda function to encrypt them.
    • B. Configure S3 Block Public Access at the account level and enable default encryption with SSE-S3.
    • C. Implement an S3 bucket policy that explicitly denies `s3:PutObject` if `s3:x-amz-server-side-encryption` header is not present, and enable S3 Inventory with a Lambda function for existing objects.
    • D. Enable default encryption for all S3 buckets with SSE-KMS and use S3 Batch Operations to encrypt existing objects.
    Show answer

    D. Enable default encryption for all S3 buckets with SSE-KMS and use S3 Batch Operations to encrypt existing objects.

    Enabling default encryption with SSE-KMS for all buckets ensures that all *new* objects are automatically encrypted upon upload without requiring client-side headers. S3 Batch Operations can then be used to efficiently encrypt all *existing* unencrypted objects in the buckets. This provides both preventative control for new objects and remediation for existing ones, without application code changes.

  19. 19. A global technology company is developing a new serverless application that processes highly sensitive personal data. The data will be stored in an Amazon RDS PostgreSQL database. Due to data residency regulations, all data must remain within the EU. The company also requires that the encryption keys for the database are customer-managed and automatically rotated annually. Which solution meets these requirements?

    Domain 5: Data Protection

    • A. Deploy the RDS PostgreSQL instance in an EU region and enable encryption at rest with a customer-managed AWS KMS CMK, performing manual key rotation annually.
    • B. Deploy the RDS PostgreSQL instance in an EU region and use client-side encryption for all data before storing it in the database.
    • C. Deploy the RDS PostgreSQL instance in an EU region (e.g., eu-central-1) and enable encryption at rest with a customer-managed AWS KMS CMK with automatic key rotation enabled.
    • D. Deploy the RDS PostgreSQL instance in a non-EU region and enable encryption at rest with an AWS-managed key.
    Show answer

    C. Deploy the RDS PostgreSQL instance in an EU region (e.g., eu-central-1) and enable encryption at rest with a customer-managed AWS KMS CMK with automatic key rotation enabled.

    Deploying the RDS instance in an EU region ensures data residency. Enabling encryption at rest with a customer-managed AWS KMS CMK (Customer Master Key) means the customer controls the encryption key. Enabling automatic key rotation for this CMK in KMS fulfills the annual rotation requirement, making this the most comprehensive and efficient solution.

  20. 20. A media streaming company uses Amazon DynamoDB to store user preferences and viewing history. Due to performance requirements, the table is configured for on-demand capacity. The company's compliance regulations mandate that all data at rest must be encrypted with customer-managed keys (CMKs) from AWS KMS. What is the most straightforward way to ensure that the DynamoDB table's data is encrypted with the specified CMK?

    Domain 5: Data Protection

    • A. DynamoDB encrypts all data at rest with AWS-owned keys by default, and this cannot be changed.
    • B. Use a custom application to encrypt data before writing it to DynamoDB, and decrypt it upon retrieval.
    • C. Configure an IAM policy for the DynamoDB table to enforce the use of a specific KMS CMK for encryption.
    • D. Enable the 'Encryption at rest' option in the DynamoDB table settings and select the desired KMS CMK.
    Show answer

    D. Enable the 'Encryption at rest' option in the DynamoDB table settings and select the desired KMS CMK.

    DynamoDB offers the option to encrypt data at rest using either AWS-owned keys (default), AWS-managed keys (AWS KMS), or customer-managed keys (AWS KMS CMKs). To use a specific customer-managed CMK, you simply enable the 'Encryption at rest' setting in the DynamoDB table configuration and choose your desired KMS CMK.

  21. 21. A security auditor discovers that an IAM role in an AWS account has a trust policy that allows an external AWS account (Account B) to assume it. However, the external account is no longer managed by the company. The auditor needs to revoke access for Account B immediately and ensure no other external accounts can assume this role in the future, while still allowing existing internal trusted entities to assume the role. Which action should the auditor take?

    Domain 4: Identity and Access Management

    • A. Disable the IAM role temporarily and review its permissions later.
    • B. Delete the IAM role and recreate it with a new trust policy.
    • C. Attach an explicit deny IAM policy to the IAM role that denies `sts:AssumeRole` for Account B.
    • D. Modify the IAM role's trust policy to remove Account B's ARN from the `Principal` element and ensure only internal accounts are listed.
    Show answer

    D. Modify the IAM role's trust policy to remove Account B's ARN from the `Principal` element and ensure only internal accounts are listed.

    The trust policy of an IAM role explicitly defines which principals (users, roles, or AWS accounts) are allowed to assume that role. Modifying the trust policy to remove the external account's ARN is the direct and most effective way to revoke its access. Ensuring only internal accounts are listed prevents unintended external access.

  22. 22. A global company uses AWS Organizations and has a multi-account strategy. They want to ensure that all IAM users across all member accounts are required to use Multi-Factor Authentication (MFA) when accessing the AWS Management Console. Furthermore, they want to prevent any member account from disabling this MFA requirement. Which AWS service or feature should the security team use to enforce this policy centrally?

    Domain 4: Identity and Access Management

    • A. Service Control Policies (SCPs) in AWS Organizations
    • B. IAM password policy in each account
    • C. AWS Config rules across all accounts
    • D. AWS Control Tower guardrails
    Show answer

    A. Service Control Policies (SCPs) in AWS Organizations

    Service Control Policies (SCPs) in AWS Organizations allow you to centrally manage permissions for all accounts in your organization. You can use an SCP to explicitly deny actions that would disable MFA or allow console access without MFA, enforcing the requirement across all member accounts.

  23. 23. A global e-commerce company uses Amazon S3 to store customer order data, which is classified into 'Public', 'Internal', and 'Confidential' based on its sensitivity. The security team needs to automatically discover and classify new objects uploaded to S3 into these categories and identify any 'Confidential' data that might be inadvertently exposed. Which AWS service is best suited for this task?

    Domain 5: Data Protection

    • A. AWS Config rules to monitor S3 bucket policies for public access.
    • B. Amazon GuardDuty to detect unusual and unauthorized behavior in S3.
    • C. AWS CloudTrail to log S3 API calls and analyze for sensitive data access patterns.
    • D. Amazon Macie to discover, classify, and protect sensitive data in S3.
    Show answer

    D. Amazon Macie to discover, classify, and protect sensitive data in S3.

    Amazon Macie is specifically designed for data discovery and classification in Amazon S3. It uses machine learning to identify sensitive data (like PII, financial data) and provides visibility into data access and security posture, making it ideal for the described scenario.

  24. 24. A development team uses AWS CodeBuild to run CI/CD pipelines. The CodeBuild projects need to access resources in other AWS accounts, such as pulling code from a CodeCommit repository in a 'Source' account and deploying artifacts to an S3 bucket in a 'Deployment' account. The security team wants to ensure that these cross-account interactions adhere to the principle of least privilege and are auditable. What is the most secure and scalable approach?

    Domain 4: Identity and Access Management

    • A. Create an IAM role in the 'Source' account and another in the 'Deployment' account, each with a trust policy allowing the CodeBuild service role from the 'Build' account to assume them. Grant minimal necessary permissions to each role.
    • B. Attach an SCP to the 'Source' and 'Deployment' accounts to explicitly allow CodeBuild access from the 'Build' account.
    • C. Create an IAM user in the 'Source' and 'Deployment' accounts with programmatic access keys and configure CodeBuild to use these credentials.
    • D. Configure the CodeBuild service role in the 'Build' account to have full administrative access to all AWS resources in the 'Source' and 'Deployment' accounts.
    Show answer

    A. Create an IAM role in the 'Source' account and another in the 'Deployment' account, each with a trust policy allowing the CodeBuild service role from the 'Build' account to assume them. Grant minimal necessary permissions to each role.

    Creating specific IAM roles in the 'Source' and 'Deployment' accounts, each with a trust policy allowing the CodeBuild service role to assume them, and granting only the necessary permissions (e.g., CodeCommit read, S3 write), adheres to the principle of least privilege and enables auditable cross-account access.

  25. 25. A media company uses Amazon S3 to store large video files that are frequently accessed by content delivery networks (CDNs). They need to ensure that all data is encrypted at rest and in transit. The company also wants to minimize operational overhead for key management. Which encryption solution meets these requirements with the least operational burden?

    Domain 5: Data Protection

    • A. Configure S3 bucket default encryption to use Server-Side Encryption with AWS KMS managed keys (SSE-KMS).
    • B. Configure S3 bucket default encryption to use Server-Side Encryption with S3-managed keys (SSE-S3).
    • C. Implement client-side encryption using a customer-provided encryption key (SSE-C) before uploading objects to S3.
    • D. Implement client-side encryption using the AWS Encryption SDK with a customer managed key (CMK) from AWS KMS.
    Show answer

    B. Configure S3 bucket default encryption to use Server-Side Encryption with S3-managed keys (SSE-S3).

    SSE-S3 provides encryption at rest with virtually no operational overhead, as AWS manages all encryption keys and key rotation. S3 automatically encrypts data upon upload and decrypts upon download. Encryption in transit is handled by HTTPS/TLS, which is standard for S3 interactions.

AWS Certified Security – Specialty flashcards

Tap a card to flip it. 159 flashcards in the full deck.

  • S3 Object Lock Compliance Mode

    Flip card

    An Amazon S3 feature that prevents an object from being deleted or overwritten for a fixed amount of time or indefinitely. In Compliance mode, no user, including the root user, can delete the object version or change its lock settings.

    • Provides WORM (Write Once, Read Many) protection.
    • Compliance mode offers the strongest protection, even against the root user.
    • Used for regulatory compliance and data retention requirements.
    Study this card →
  • IAM Condition Key: aws:MultiFactorAuthAge

    Flip card

    An IAM condition key that specifies the number of seconds since the IAM principal authenticated with multi-factor authentication (MFA).

    • Value is an integer representing seconds.
    • A value of '0' means MFA was not used for the current session.
    • Commonly used with `NumericGreaterThan` to enforce MFA for sensitive actions.
    Study this card →
  • IAM Identity Center Permission Sets

    Flip card

    A collection of administrative policies that define a user's access to an AWS account, managed centrally by IAM Identity Center.

    • Defines permissions for users/groups to access AWS accounts.
    • Applied to groups and assigned to specific accounts or OUs.
    • IAM Identity Center automatically provisions corresponding IAM roles in target accounts.
    Study this card →
  • S3 Object Tags with Lifecycle Rules

    Flip card

    S3 Object Tags are key-value pairs that can be applied to individual S3 objects, enabling granular data classification. S3 Lifecycle rules can then be configured to perform actions (e.g., transition to different storage classes, expire) based on these object tags.

    • Allows up to 10 tags per object.
    • Enables fine-grained control over data lifecycle.
    • Reduces the need for multiple buckets for classification.
    Study this card →
  • CloudTrail Organization Trails with S3 Object Lock

    Flip card

    A centralized logging solution for AWS Organizations that delivers immutable audit logs to a secure S3 bucket.

    • CloudTrail organization trails capture all AWS API activity across all member accounts.
    • S3 Object Lock in compliance mode prevents deletion or modification of objects for a specified retention period, even by the root user.
    • Ensures audit trail integrity and non-repudiation for compliance.
    Study this card →
  • External Key Management (Client-Side Encryption)

    Flip card

    Encrypting data on the client side using an encryption library that interfaces with an external Key Management System (KMS) located outside of AWS, ensuring that encryption keys never enter the AWS environment.

    • Keys are fully controlled and managed by the customer outside AWS.
    • Data is encrypted before transmission to AWS.
    • Provides the highest level of key sovereignty and data control.
    Study this card →
  • IAM Condition Key: iam:MFAPresent

    Flip card

    An IAM condition key that evaluates whether the principal making the request has authenticated with MFA.

    • Used to enforce MFA for sensitive actions.
    • Value is 'true' if MFA was used, 'false' otherwise.
    • Can be used in a `Deny` statement to prevent actions without MFA.
    Study this card →
  • S3 Object Lock Compliance Mode for WORM

    Flip card

    Amazon S3 Object Lock, specifically in Compliance mode, enforces a Write Once, Read Many (WORM) model, making data immutable for a specified retention period against any user, including the root account. It's crucial for regulatory compliance requiring tamper-proof storage.

    • Prevents objects from being overwritten or deleted by *any* user during the retention period.
    • Ideal for regulatory compliance (e.g., FINRA, HIPAA, SEC Rule 17a-4).
    • Can be combined with S3 Lifecycle policies for automatic object expiration after the retention period.
    Study this card →
  • S3 Glacier Deep Archive

    Flip card

    The lowest-cost Amazon S3 storage class designed for long-term data archival that is accessed rarely (e.g., once or twice a year) and can tolerate retrieval times of several hours.

    • Offers the lowest storage price in S3.
    • Suitable for data retained for 7-10 years or more.
    • Retrieval times typically range from 12 to 48 hours.
    Study this card →
  • Amazon S3 Glacier Deep Archive

    Flip card

    The lowest-cost Amazon S3 storage class for long-term archival, designed for data that is accessed once or twice a year and can tolerate retrieval times of 12-48 hours.

    • Lowest storage cost among S3 classes.
    • Ideal for long-term data retention (7-10+ years).
    • Retrieval times range from 12 to 48 hours for standard requests.
    Study this card →
  • Amazon Cognito Identity Pools

    Flip card

    An AWS service that provides temporary, limited-privilege AWS credentials to users who have been authenticated by an identity provider, enabling them to access AWS resources.

    • Also known as Federated Identities.
    • Integrates with Cognito User Pools, social identity providers (Google, Facebook), and SAML.
    • Exchanges identity tokens for temporary AWS credentials.
    Study this card →
  • IAM Policy Evaluation Logic

    Flip card

    The order in which IAM policies are evaluated: explicit deny > explicit allow > implicit deny (default).

    • Explicit Deny always overrides Explicit Allow.
    • Explicit Allow overrides Implicit Deny.
    • If no matching Allow policy, access is implicitly denied.
    Study this card →
  • AWS Data Residency Enforcement

    Flip card

    Ensuring that data is stored and processed exclusively within a specified geographic region to comply with local regulations, typically achieved by selecting appropriate AWS regions for resources.

    • Involves selecting specific AWS regions for data storage and processing.
    • Critical for compliance with regulations like GDPR.
    • Affects where S3 buckets, EC2 instances, Lambda functions, etc., are provisioned.
    Study this card →
  • SSE-KMS for Central Key Management & Audit

    Flip card

    Server-Side Encryption with AWS KMS customer managed keys (CMKs) provides encryption at rest for Amazon S3 objects, offering central key management, granular access control via key policies, and auditability of key usage through AWS CloudTrail.

    • CMKs are managed within AWS KMS, providing a central point of control.
    • Key policies define who can use and manage the CMK.
    • All API calls to KMS for key usage are logged in AWS CloudTrail for auditing.
    Study this card →
  • Amazon Macie

    Flip card

    Amazon Macie is a data security and data privacy service that uses machine learning and pattern matching to discover, classify, and protect sensitive data in AWS, especially in Amazon S3.

    • Automatically detects sensitive data like PII.
    • Provides visibility into S3 bucket security.
    • Generates findings for security posture analysis.
    Study this card →
  • AWS Directory Service for Microsoft AD (Enterprise)

    Flip card

    A fully managed, highly available Microsoft Active Directory hosted in AWS, offering full AD functionality, Kerberos, LDAP, and trust relationships with on-premises AD.

    • True Microsoft Active Directory functionality.
    • Supports Kerberos and LDAP for enterprise applications.
    • Enables trust relationships with on-premises AD for hybrid environments.
    Study this card →
  • S3 Default Encryption & Batch Operations

    Flip card

    S3 Default Encryption automatically encrypts new objects. S3 Batch Operations allow large-scale operations (like encryption) on existing objects.

    • Default encryption prevents unencrypted uploads.
    • SSE-KMS offers managed key control.
    • Batch Operations for re-encrypting existing objects.
    Study this card →
  • RDS Data Residency with KMS

    Flip card

    Ensuring an Amazon RDS database and its encryption keys comply with data residency requirements by provisioning the database in a specific AWS region and using customer-managed AWS KMS CMKs with automatic key rotation.

    • Region selection dictates data residency.
    • KMS CMKs provide customer control over encryption keys.
    • Automatic key rotation enhances security without manual intervention.
    Study this card →
  • DynamoDB Encryption at Rest

    Flip card

    Amazon DynamoDB encrypts all data at rest by default. Customers can choose between AWS-owned keys, AWS-managed keys (KMS), or customer-managed keys (KMS CMKs) for encryption, providing flexibility for compliance.

    • Always encrypted at rest.
    • Choice of AWS-owned, AWS-managed, or customer-managed (KMS CMK) keys.
    • Configured in table settings during creation or modification.
    Study this card →
  • IAM Role Trust Policy

    Flip card

    A JSON policy attached to an IAM role that specifies which principals are allowed to assume the role.

    • Defines the 'who' can assume the role.
    • Uses the `Principal` element to specify trusted entities (AWS accounts, IAM users/roles).
    • Must grant `sts:AssumeRole` action.
    Study this card →
  • Service Control Policies (SCPs)

    Flip card

    Policy type used in AWS Organizations to manage permissions and set maximum available permissions for all accounts in an organization.

    • Apply to all IAM users and roles in affected accounts, including the root user.
    • Are preventative controls; they define the maximum available permissions.
    • Do not grant permissions; they filter permissions granted by IAM policies.
    Study this card →
  • Cross-Account Role Assumption

    Flip card

    Allows an IAM principal in one AWS account to temporarily access resources in another AWS account by assuming a role.

    • Relies on a trust policy in the target account's role, specifying which principals can assume it.
    • Provides temporary security credentials, reducing the risk of long-lived access keys.
    • Enables granular, least-privilege access across account boundaries.
    Study this card →
  • SSE-S3 for Minimal Overhead

    Flip card

    Server-Side Encryption with S3-managed encryption keys (SSE-S3) automatically encrypts objects before saving them to S3 and decrypts them when downloaded, with AWS managing all key lifecycle, offering the lowest operational overhead.

    • AWS manages the encryption keys completely.
    • Encrypts data at rest automatically.
    • Requires no changes to your application code for encryption/decryption.
    Study this card →
  • S3 Standard-IA for Infrequent Access

    Flip card

    Amazon S3 Standard-Infrequent Access (S3 Standard-IA) is an S3 storage class optimized for data that is accessed less frequently but requires rapid access when needed, offering lower storage costs compared to S3 Standard.

    • Ideal for long-lived, infrequently accessed data.
    • Offers millisecond retrieval times.
    • Has a minimum storage duration of 30 days and a retrieval fee per GB.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.