Free AWS-CERTIFIED-SECURITY-SPECIALTY-SCS-C03 Amazon AWS-CERTIFIED-SECURITY-SPECIALTY-SCS-C03 Practice Test Question

Loading demo links...

Showing 7–9 of 9 questions

Question 7 (Topic 1)

A company is migrating one of its legacy systems from an on-premises data center to AWS. The application server will run on AWS, but the database must remain in the on-premises data center for compliance reasons. The database is sensitive to network latency. Additionally, the data that travels between the on-premises data center and AWS must have IPsec encryption. Which combination of AWS solutions will meet these requirements? (Choose two.)

Select an option, then click Submit answer.

  • AWS Site-to-Site VPN
  • AWS Direct Connect
  • AWS VPN CloudHub
  • VPC peering
  • NAT gateway
Question 8 (Topic 1)

A company uses an organization in AWS Organizations to manage multiple AWS accounts. Users access AWS accounts by using IAM users and secret access keys. A security team requires all access to accounts to use temporary security credentials that expire after 60 minutes. Users must use a SAML-based identity provider (IdP) to access the accounts. Which solution will meet these requirements?

Select an option, then click Submit answer.

  • Enable access to the AWS Security Token Service (AWS STS). Ensure that users run the get-session-token AWS CLI command with an appropriate duration. Require users to use STS temporary credentials to access AWS accounts.
  • Set up AWS IAM Identity Center and configure an external IdP. Configure permission sets that allow the access that the users require. Configure a session duration limit. Require the users to retrieve SSO credentials by using the AWS CLI. Remove the IAM users from the AWS accounts.
  • Set up AWS Secrets Manager and Amazon Cognito in each AWS account. Configure a Cognito identity pool to use an external IdP and connect to Secrets Manager. Enable managed secret rotation in Secrets Manager. Ensure that the users run the get-secret-value AWS CLI command to access the AWS accounts.
  • Enable AWS IAM Roles Anywhere in the organization management account. Ensure that users install the credential helper tool. Configure IAM roles within the management account with an appropriate session duration. Ensure that the users retrieve temporary credentials from the credential helper tool to access the AWS accounts.
Question 9 (Topic 1)

HOTSPOT - A company uses an organization in AWS Organizations to manage multiple AWS accounts. A security engineer needs to monitor the security compliance of AWS resources across the organization. The security engineer wants to receive notifications when any AWS resources does not comply with the company's security policies. Select the correct AWS Config based solution from the following list to meet each requirement. Select each AWS Config based solution one time. • AWS Config aggregator • AWS Config conformance packs • AWS Config with AWS Systems Manager • AWS Config rules • AWS Config with AWS User Notifications

Answer is in the explanation below.