We offer the latest SCS-C02 practice test designed for free and effective online AWS Certified Security Specialty certification preparation. It's a simulation of the real SCS-C02 exam experience, built to help you understand the structure, complexity, and topics you'll face on exam day.
A company is running its workloads in a single AWS Region and uses AWS Organizations. A security
engineer must implement a solution to prevent users from launching resources in other Regions. Which solution will meet these requirements with the LEAST operational overhead?
A company has two VPCs in the same AWS Region and in the same AWS account Each VPC uses a CIDR
block that does not overlap with the CIDR block of the other VPC One VPC contains AWS Lambda functions
that run inside a subnet that accesses the internet through a NAT gateway. The Lambda functions require
access to a publicly accessible Amazon Aurora MySQL database that is running in the other VPC
A security engineer determines that the Aurora database uses a security group rule that allows connections
from the NAT gateway IP address that the Lambda functions use. The company's security policy states that no
database should be publicly accessible.
What is the MOST secure way that the security engineer can provide the Lambda functions with access to the Aurora database?
A company uses Amazon EC2 instances to host frontend services behind an Application Load Balancer.
Amazon Elastic Block Store (Amazon EBS) volumes are attached to the EC2 instances. The company uses
Amazon S3 buckets to store large files for images and music.
The company has implemented a security architecture oit>AWS to prevent, identify, and isolate potential
ransomware attacks. The company now wants to further reduce risk.
A security engineer must develop a disaster recovery solution that can recover to normal operations if an
attacker bypasses preventive and detective controls. The solution must meet an RPO of 1 hour.
Which solution will meet these requirements?
A Security Engineer is troubleshooting an issue with a company's custom logging application. The application
logs are written to an Amazon S3 bucket with event notifications enabled to send events lo an Amazon SNS
topic. All logs are encrypted at rest using an IAM KMS CMK. The SNS topic is subscribed to an encrypted
Amazon SQS queue. The logging application polls the queue for new messages that contain metadata about
the S3 object. The application then reads the content of the object from the S3 bucket for indexing.
The Logging team reported that Amazon CloudWatch metrics for the number of messages sent or received is
showing zero. No togs are being received.
What should the Security Engineer do to troubleshoot this issue?
© Copyrights FreePDFQuestions 2025. All Rights Reserved
We use cookies to ensure that we give you the best experience on our website (FreePDFQuestions). If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the FreePDFQuestions.