Free SCS-C03 sample questions
Real questions from the Security - Speciality practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 8 of 17 free sample questions.
A security engineer is troubleshooting a new Amazon GuardDuty deployment in an Amazon EKS environment. The engineer has enabled GuardDuty EKS Protection, but the security team is not receiving findings related to suspicious process executions within the Kubernetes pods. The Audit logs are being correctly ingested. What is the most likely cause of this issue?
A healthcare organization uses Amazon Macie to detect sensitive patient data in Amazon S3. The organization has specific medical record numbers (MRN) that follow a proprietary format (e.g., `HOSP-12345-X`). The default managed data identifiers in Macie are not detecting these specific patterns. Which action should the security administrator take to ensure these MRNs are discovered?
A large e-commerce platform wants to monitor high-cardinality security data in real-time. They need to identify the top 10 IP addresses being blocked by AWS WAF across 200 web applications. The solution must provide a visual ranking that updates dynamically without requiring complex log parsing infrastructure. Which solution meets these requirements?
A security team is designing a centralized log ingestion pipeline. They need to collect logs from multiple sources and forward them to a third-party Splunk endpoint. The solution must support buffering, transformation of log data, and automatic retries. Which TWO services should be combined to build this architecture? (Select TWO)
A company requires real-time detection of specific security group changes that open port 22 to the world (0.0.0.0/0). The detection must trigger a remediation Lambda function within seconds. The security team is debating between using AWS Config Rules and Amazon EventBridge rules. Which approach provides the fastest reaction time for this specific requirement?
A developer has deployed a serverless application using AWS Lambda functions. The security team wants to automatically detect software vulnerabilities in the application code and the Lambda function layers. Which AWS service should be enabled to perform these scans automatically?
A security analyst needs to configure VPC Flow Logs to capture specific TCP flag information to diagnose a potential TCP SYN flood attack. The standard flow log format does not include this detail. The analyst creates a custom format. Which field must be included in the custom format string to see the TCP flags?
9 more free samples are waiting
Create a free account to unlock the whole SCS-C03 sample bank, or get full access to all 275 practice questions in the simulator.