dc dotCreds
AWS Certified Security – Specialty Practice Test

AWS Security Specialty Practice Test

Start today’s free 10-question AWS Security Specialty set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 23, 2026, 8:12 PM CDT

Go Pro - One Time Unlock

Unlock the full SCS-C03 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 AWS Security Specialty questions

Use this AWS Security Specialty practice test to review AWS Certified Security – Specialty. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Protect audit evidence 1. Detection (16%)

CloudTrail data-event logging for a high-volume S3 bucket is generating far more events and cost than expected. Security must retain the data events that are useful for investigations but reduce unnecessary logging. What should the engineer do?

Concept tested:
Question 2 of 10
Objective Use infrastructure as code across accounts and Regions 6. Security Foundations and Governance (14%)

A regulated organization uses infrastructure as code for production. Security requires the same approved baseline to be deployed to multiple accounts and Regions, and changes must be repeatable rather than performed manually in each account. Which design BEST supports this requirement?

Concept tested:
Question 3 of 10
Objective Select AWS threat-detection services 1. Detection (16%)

An organization is investigating a potential data breach involving unauthorized access to S3 buckets containing sensitive customer data. To proactively detect and respond to this threat, leveraging appropriate evidence sources, which combination of AWS services should be implemented?

Concept tested:
Question 4 of 10
Objective Troubleshoot explicit and implicit denies 4. Identity and Access Management (20%)

An EC2 instance role can list an S3 bucket and read SSE-S3 objects, but GetObject fails with AccessDenied for objects encrypted under a customer managed KMS key. The S3 permissions are otherwise identical. What is the MOST likely missing authorization?

Concept tested:
Question 5 of 10
Objective Design AWS KMS key policies and grants 5. Data Protection (18%)

A KMS customer managed key protects production data. Security administrators must be able to manage the key, but an application role must only encrypt and decrypt application data. Which authorization design BEST enforces separation of duties?

Concept tested:
Question 6 of 10
Objective Perform root-cause and impact analysis 2. Incident Response (14%)

During incident analysis, CloudTrail shows the first unauthorized API call was made by a newly assumed role. Later events show persistence through a second role and changes to security controls. What should the responder reconstruct to determine root cause and impact?

Concept tested:
Question 7 of 10
Objective Segment VPC workloads 3. Infrastructure Security (18%)

A three-tier application places web, application, and database workloads in separate subnets. The security architect wants stateful workload-level allow rules and an optional stateless subnet-level deny layer. Which design meets the requirement?

Concept tested:
Question 8 of 10
Objective Govern multiple accounts 6. Security Foundations and Governance (14%)

A company separates workloads into production, development, security, and log-archive AWS accounts. Security operations must remain centralized while workload administrators must not be able to alter organization-wide logging or security guardrails. Which model BEST meets the requirement?

Concept tested:
Question 9 of 10
Objective Protect audit evidence 1. Detection (16%)

A dedicated security account receives security logs from production workloads. Application administrators must be able to operate their workloads but must not be able to alter the retained security evidence. Which control set BEST protects the log archive?

Concept tested:
Question 10 of 10
Objective Manage identity across accounts 4. Identity and Access Management (20%)

A security team wants contractors to authenticate through the corporate identity provider and receive temporary access to only two AWS accounts for a 90-day engagement. The company wants centralized assignment rather than creating IAM users. Which approach is BEST?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
SCS-C03 Pro $4.99 one-time

50 Exam Practice Test $1.99 one-time

A 50-question SCS-C03 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

AWS Security & Networking Bundle $9.99 one-time

Unlock all 3 active AWS Security & Networking Bundle practice banks in one permanent purchase.

What’s includedAWS Security Specialty, AWS Advanced Networking Specialty, AWS SAA-C03
All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full SCS-C03 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily SCS-C03 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily AWS Security Specialty set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 CloudTrail data-event logging for a high-volume S3 bucket is generating far more events and cost than expected. Security must retain the data events that are useful for investigations but reduce unnecessary logging. What should the engineer do?

Answer choices

  1. A. Enable S3 versioning because versioning reduces the number of CloudTrail API events generated, for the described technical objective and its associated operational control requirements.
  2. B. Disable CloudTrail entirely for the account, for the described technical objective and its associated operational control requirements, within the . detection (16%) context.
  3. C. Review the investigation requirements and refine CloudTrail advanced event selectors to capture the required S3 data events instead of logging unnecessary object activity, within the proposed design.
  4. D. Delete historical CloudTrail logs to reduce the current event-ingestion rate, for the described technical objective and its associated operational control requirements, within the proposed design.

Correct answer

Review the investigation requirements and refine CloudTrail advanced event selectors to capture the required S3 data events instead of logging unnecessary object activity, within the proposed design.

CloudTrail logging scope should match the evidence requirement. Event selectors and advanced event selectors allow engineers to control which management and data events are recorded. S3 versioning does not reduce the number of API calls that CloudTrail observes.

Wrong-answer review

  • A. Enable S3 versioning because versioning reduces the number of CloudTrail API events generated, for the described technical objective and its associated operational control requirements.: Incorrect. Versioning changes object history behavior; it does not suppress API event generation.
  • B. Disable CloudTrail entirely for the account, for the described technical objective and its associated operational control requirements, within the . detection (16%) context.: Incorrect. Disabling CloudTrail removes critical audit visibility.
  • D. Delete historical CloudTrail logs to reduce the current event-ingestion rate, for the described technical objective and its associated operational control requirements, within the proposed design.: Incorrect. Deleting old logs affects retention, not current event generation.

Extra learning features

Why candidates miss this

The 'Disable CloudTrail entirely' distractor is tempting because it's a drastic solution. However, disabling CloudTrail removes critical audit visibility, potentially hindering investigations and compliance efforts. The decisive clue is the requirement to retain useful data events. Likely wrong answer: Disable CloudTrail entirely for the account. Review focus: Creating a trail for an organization

Interview question

Q: CloudTrail logging scope should match the evidence requirement. Event selectors and advanced event selectors allow engineers to control which management and data events are recorded. Strong answer: The engineer should refine CloudTrail event selectors to capture the required S3 data events instead of logging unnecessary object activity.

  • event selectors
  • advanced event selectors
  • logging scope
  • management and data events

Caution: Do not restate the multiple-choice stem or ask the learner merely to name a product, rule, or term.

Why this matters

Over-logging CloudTrail generates excessive costs and performance impacts. Precise event selection minimizes these costs, directly reducing operational expenses and improving resource utilization. This is critical for maintaining budget control and efficient cloud operations.

Objective/domain: 1. Detection (16%)

Source: Creating a trail for an organization

Question 2 A regulated organization uses infrastructure as code for production. Security requires the same approved baseline to be deployed to multiple accounts and Regions, and changes must be repeatable rather than performed manually in each account. Which design BEST supports this requirement?

Answer choices

  1. A. Use CloudTrail to replay resource-creation API calls from a reference account, under the organization’s defined implementation and exception-management process.
  2. B. Give local account administrators a checklist and let each administrator build the baseline manually, under the stated technical, operational, and governance constraints.
  3. C. Use an organization trail to create the security resources in each member account, within organization-wide risk-and-accountability boundaries.
  4. D. Use CloudFormation StackSets for the approved baseline and deploy stack instances to the required accounts and Regions, for the stated implementation and support requirements.

Correct answer

Use CloudFormation StackSets for the approved baseline and deploy stack instances to the required accounts and Regions, for the stated implementation and support requirements.

Objective/domain: 6. Security Foundations and Governance (14%)

Source: Managing stacks across accounts and Regions with StackSets – AWS CloudFormation

Question 3 An organization is investigating a potential data breach involving unauthorized access to S3 buckets containing sensitive customer data. To proactively detect and respond to this threat, leveraging appropriate evidence sources, which combination of AWS services should be implemented?

Answer choices

  1. A. Amazon Inspector and AWS Config only, for the affected environment.
  2. B. Amazon Detective and S3 Lifecycle policies only, within the proposed design.
  3. C. Amazon GuardDuty, Security Hub, and Macie, for evaluation.
  4. D. Amazon CloudTrail and AWS Lambda only, under the documented operational and governance requirements.

Correct answer

Amazon GuardDuty, Security Hub, and Macie, for evaluation.

Objective/domain: 1. Detection (16%)

Source: What is Amazon GuardDuty?

Question 4 An EC2 instance role can list an S3 bucket and read SSE-S3 objects, but GetObject fails with AccessDenied for objects encrypted under a customer managed KMS key. The S3 permissions are otherwise identical. What is the MOST likely missing authorization?

Answer choices

  1. A. A CloudTrail permission allowing GetObject, for the described technical objective and its associated operational control requirements, for review.
  2. B. An inbound security-group rule on the S3 bucket, within the documented scope, ownership, and validation boundaries.
  3. C. kms:Decrypt on the customer managed KMS key, permitted by the effective KMS key/IAM policy configuration, within organization-wide risk-and-accountability boundaries.
  4. D. An explicit Allow in the EC2 instance's network ACL for the KMS key ARN, for the described technical objective and its associated operational control requirements, for this task.

Correct answer

kms:Decrypt on the customer managed KMS key, permitted by the effective KMS key/IAM policy configuration, within organization-wide risk-and-accountability boundaries.

Objective/domain: 4. Identity and Access Management (20%)

Source: Key policies in AWS KMS

Question 5 A KMS customer managed key protects production data. Security administrators must be able to manage the key, but an application role must only encrypt and decrypt application data. Which authorization design BEST enforces separation of duties?

Answer choices

  1. A. Use the KMS key policy to authorize a key-administrator role for administrative actions and a separate application role only for the required cryptographic operations; use IAM policies or grants where appropriate, within the stated policy framework.
  2. B. Give the application role kms:* so it can recover from key-policy mistakes without administrator assistance, for the described technical objective and its associated operational control requirements, as the primary proposed approach.
  3. C. Give the key administrators access to decrypt all production data because they already manage the key, for the described technical objective and its associated operational control requirements, as the selected approach for the stated technical and business outcome.
  4. D. Rely only on CloudTrail monitoring and grant both groups full KMS permissions, for the described technical objective and its associated operational control requirements, as the primary implementation for the described business requirement.

Correct answer

Use the KMS key policy to authorize a key-administrator role for administrative actions and a separate application role only for the required cryptographic operations; use IAM policies or grants where appropriate, within the stated policy framework.

Objective/domain: 5. Data Protection (18%)

Source: Key policies in AWS KMS

Question 6 During incident analysis, CloudTrail shows the first unauthorized API call was made by a newly assumed role. Later events show persistence through a second role and changes to security controls. What should the responder reconstruct to determine root cause and impact?

Answer choices

  1. A. Only the final resource that the attacker modified because earlier activity is no longer relevant, under the stated technical, operational, and governance constraints.
  2. B. Only the source IP address of the first unauthorized API call, within the documented operational, security, ownership, and validation requirements, as selected.
  3. C. The initial access path, affected resources, actions performed, persistence mechanisms, and failed or bypassed controls, for the stated scenario.
  4. D. The current account configuration without comparing it with the sequence of attacker actions, under the stated decision criteria.

Correct answer

The initial access path, affected resources, actions performed, persistence mechanisms, and failed or bypassed controls, for the stated scenario.

Objective/domain: 2. Incident Response (14%)

Source: What is Amazon Detective?

Question 7 A three-tier application places web, application, and database workloads in separate subnets. The security architect wants stateful workload-level allow rules and an optional stateless subnet-level deny layer. Which design meets the requirement?

Answer choices

  1. A. Use route tables as the primary packet-filtering control and remove security groups, for the specified implementation requirement.
  2. B. Use one security group for all tiers and rely on DNS names to provide segmentation, within organization-wide risk-and-accountability boundaries.
  3. C. Use security groups for workload-level stateful filtering and network ACLs for subnet-level stateless filtering, for the required outcome.
  4. D. Use network ACLs for stateful workload-level filtering and security groups for stateless subnet-level filtering, as described.

Correct answer

Use security groups for workload-level stateful filtering and network ACLs for subnet-level stateless filtering, for the required outcome.

Objective/domain: 3. Infrastructure Security (18%)

Source: Infrastructure security in Amazon VPC

Question 8 A company separates workloads into production, development, security, and log-archive AWS accounts. Security operations must remain centralized while workload administrators must not be able to alter organization-wide logging or security guardrails. Which model BEST meets the requirement?

Answer choices

  1. A. Give each workload account complete control of its own security logging and require quarterly manual reviews, as the selected approach for the stated technical and business outcome.
  2. B. Use a single account so every team shares the same IAM policies, for the described technical objective and its associated operational control requirements, under this approach.
  3. C. Use separate accounts for workload and security duties, plus centralized guardrails, organization logging, delegated security administration, and centralized findings.
  4. D. Use a shared root credential across all accounts for centralized administration, for the described technical objective and its associated operational control requirements, under the documented operational and governance requirements.

Correct answer

Use separate accounts for workload and security duties, plus centralized guardrails, organization logging, delegated security administration, and centralized findings.

Objective/domain: 6. Security Foundations and Governance (14%)

Source: Creating a trail for an organization

Question 9 A dedicated security account receives security logs from production workloads. Application administrators must be able to operate their workloads but must not be able to alter the retained security evidence. Which control set BEST protects the log archive?

Answer choices

  1. A. Give application administrators write access to the archive so they can correct malformed records, for the stated security, delivery, and accountability requirements.
  2. B. Reduce the retention period to the minimum possible so there is less evidence to protect, under organization-wide implementation-governance requirements.
  3. C. Store the logs with the monitored workloads and depend on application backups for integrity, within the documented operational, security, ownership, and validation requirements.
  4. D. Use a separate central log archive with least-privilege access, encryption, integrity protections where supported, and an approved retention policy, within the stated policy framework.

Correct answer

Use a separate central log archive with least-privilege access, encryption, integrity protections where supported, and an approved retention policy, within the stated policy framework.

Objective/domain: 1. Detection (16%)

Source: Validating CloudTrail log file integrity

Question 10 A security team wants contractors to authenticate through the corporate identity provider and receive temporary access to only two AWS accounts for a 90-day engagement. The company wants centralized assignment rather than creating IAM users. Which approach is BEST?

Answer choices

  1. A. Create a long-lived IAM access key in every AWS account and email the keys to the contractors, for the described technical objective and its associated operational control requirements, for this task.
  2. B. Create a security group that lists contractor public IP addresses and treat it as identity authorization, as the primary implementation for the described business requirement.
  3. C. Use IAM Identity Center federation and assign the contractor group permission sets only to the required accounts; remove the assignments when the engagement ends, within this context.
  4. D. Use an SCP to grant the contractors read-only access, for the described technical objective and its associated operational control requirements, for the stated scenario.

Correct answer

Use IAM Identity Center federation and assign the contractor group permission sets only to the required accounts; remove the assignments when the engagement ends, within this context.

Objective/domain: 4. Identity and Access Management (20%)

Source: What is IAM Identity Center?

Where to go after the daily web set

How are AWS Security Specialty questions generated?

dotCreds builds AWS Security Specialty practice questions from public exam objectives and AWS certification and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start AWS Security Specialty practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.