dc dotCreds
AWS Certified Security – Specialty Practice Test

AWS Security Specialty Practice Test

Start today’s free 10-question AWS Security Specialty set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 17, 2026, 11:07 AM CDT

Go Pro - One Time Unlock

Unlock the full SCS-C03 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 AWS Security Specialty questions

Use this AWS Security Specialty practice test to review AWS Certified Security – Specialty. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Select encryption for data at rest 5. Data Protection (18%)

A payment application stores cardholder data in S3. The security team requires auditable control over who can use the encryption key, the ability to disable the key, and customer-controlled rotation. Which at-rest encryption design BEST meets the requirement?

Concept tested:
Question 2 of 10
Objective Collect audit and compliance evidence 6. Security Foundations and Governance (14%)

An auditor asks the company to prove that a control requiring encryption and restricted S3 access is operating for a defined set of production buckets. Which evidence package BEST answers the request?

Concept tested:
Question 3 of 10
Objective Use infrastructure as code across accounts and Regions 6. Security Foundations and Governance (14%)

A regulated organization uses infrastructure as code for production. Security requires the same approved baseline to be deployed to multiple accounts and Regions, and changes must be repeatable rather than performed manually in each account. Which design BEST supports this requirement?

Concept tested:
Question 4 of 10
Objective Apply least privilege with IAM policies 4. Identity and Access Management (20%)

A development team requires access to several S3 buckets containing sensitive customer data for testing purposes. To adhere to the principle of least privilege and minimize potential security risks, what is the most appropriate immediate action to implement for granting this access?

Concept tested:
Question 5 of 10
Objective Protect audit evidence 1. Detection (16%)

A dedicated security account receives security logs from production workloads. Application administrators must be able to operate their workloads but must not be able to alter the retained security evidence. Which control set BEST protects the log archive?

Concept tested:
Question 6 of 10
Objective Use private service connectivity 3. Infrastructure Security (18%)

An application in private subnets must retrieve secrets from AWS Secrets Manager. The security team requires the API traffic to stay on private AWS connectivity and not require a NAT gateway or internet gateway. Which solution BEST meets the requirement?

Concept tested:
Question 7 of 10
Objective Validate security findings for event scope and impact 2. Incident Response (14%)

GuardDuty reports anomalous credential use on an IAM role, Security Hub shows a related Inspector finding on an EC2 instance that assumed the role, and CloudTrail shows subsequent S3 data access. Before broad remediation, what should the incident responder do to assess scope and impact?

Concept tested:
Question 8 of 10
Objective Manage identity across accounts 4. Identity and Access Management (20%)

A security team wants contractors to authenticate through the corporate identity provider and receive temporary access to only two AWS accounts for a 90-day engagement. The company wants centralized assignment rather than creating IAM users. Which approach is BEST?

Concept tested:
Question 9 of 10
Objective Design centralized security logging 1. Detection (16%)

A security organization wants a searchable security data lake that ingests supported AWS security logs across accounts and Regions and normalizes supported AWS sources into OCSF for analytics and third-party subscribers. Which service is the BEST fit?

Concept tested:
Question 10 of 10
Objective Store and rotate secrets securely 5. Data Protection (18%)

A financial institution is migrating a legacy application to AWS and needs to securely manage database credentials. To ensure regular rotation and strict access control while adhering to encryption design requirements that match data classification, which approach provides the most robust and compliant solution for storing and managing these sensitive credentials?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
SCS-C03 Pro $4.99 one-time

Unlock all 200 AWS Security Specialty questions, explanations, review tools, and exam-style practice.

50 Exam Practice Test $1.99 one-time

A 50-question SCS-C03 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

AWS Access Bundle $6.99/month

AWS practitioner, architect, and machine learning practice in one monthly unlock.

What’s includedAWS AI Practitioner, AWS Cloud Practitioner, AWS Developer Associate, AWS Advanced Networking Specialty, AWS Security Specialty, AWS ML Engineer Associate, AWS SAA-C03
Cybersecurity Access Bundle $6.99/month

Security, defensive analysis, and network security practice in one monthly unlock.

What’s includedSecurity+, CySA+, Certified Ethical Hacker, ISC2 CISSP, ISC2 CCSP, ISACA CISM, AWS Security Specialty, Cisco CyberOps Associate, CCNA

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full SCS-C03 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily SCS-C03 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily AWS Security Specialty set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A payment application stores cardholder data in S3. The security team requires auditable control over who can use the encryption key, the ability to disable the key, and customer-controlled rotation. Which at-rest encryption design BEST meets the requirement?

Answer choices

  1. A. Disable server-side encryption and rely on TLS.
  2. B. Rely only on the S3 default SSE-S3 configuration.
  3. C. Use SSE-C and distribute the same customer-provided key to every application instance.
  4. D. Use SSE-KMS with a customer managed KMS key and a least-privilege key policy.

Correct answer

Use SSE-KMS with a customer managed KMS key and a least-privilege key policy.

S3 encrypts new objects by default, but a customer managed KMS key provides the additional customer controls described in the scenario, including key policy control, auditing, disabling, and rotation options.

Wrong-answer review

  • A. Disable server-side encryption and rely on TLS.: Incorrect. TLS protects data in transit, not data at rest.
  • B. Rely only on the S3 default SSE-S3 configuration.: Incorrect. SSE-S3 provides encryption but not the requested customer-managed KMS controls.
  • C. Use SSE-C and distribute the same customer-provided key to every application instance.: Incorrect. SSE-C shifts key handling to the customer and creates unnecessary distribution and operational risk for this requirement.

Extra learning features

Why candidates miss this

The distractors, 'Disable server-side encryption and rely on TLS' and 'Rely only on the S3 default SSE-S3 configuration,' are tempting because they represent simpler, less controlled encryption options. The decisive clue is the explicit requirement for auditable control and customer management, which SSE-KMS uniquely provides. Likely wrong answer: Disable server-side encryption and rely on TLS. Review focus: Using server-side encryption with AWS KMS keys (SSE-KMS)

Interview question

Q: Given the requirement for auditable control over encryption key usage, rotation, and customer management, the SSE-KMS solution offers the most granular control and aligns directly with the scenario's needs. Strong answer: The customer-managed KMS key provides the necessary controls for key policy, auditing, disabling, and rotation, directly addressing the security team's requirements.

  • key policy control
  • auditing
  • disabling
  • rotation
  • customer managed KMS key

Caution: The question tests the ability to select the correct encryption design based on specific requirements.

Objective/domain: 5. Data Protection (18%)

Source: Using server-side encryption with AWS KMS keys (SSE-KMS)

Question 2 An auditor asks the company to prove that a control requiring encryption and restricted S3 access is operating for a defined set of production buckets. Which evidence package BEST answers the request?

Answer choices

  1. A. A screenshot showing that Amazon S3 supports encryption features, plus a list of bucket names.
  2. B. A vulnerability scan of the EC2 fleet performed during the same audit period.
  3. C. Mapped control evidence showing current bucket encryption and access configuration, along with supported automated assessment evidence or API snapshots collected for the audit period.
  4. D. A policy document stating that production buckets should be encrypted, without resource-level evidence.

Correct answer

Mapped control evidence showing current bucket encryption and access configuration, along with supported automated assessment evidence or API snapshots collected for the audit period.

Objective/domain: 6. Security Foundations and Governance (14%)

Source: What is AWS Audit Manager?

Question 3 A regulated organization uses infrastructure as code for production. Security requires the same approved baseline to be deployed to multiple accounts and Regions, and changes must be repeatable rather than performed manually in each account. Which design BEST supports this requirement?

Answer choices

  1. A. Use CloudTrail to replay resource-creation API calls from a reference account.
  2. B. Give local account administrators a checklist and let each administrator build the baseline manually.
  3. C. Use an organization trail to create the security resources in each member account.
  4. D. Use CloudFormation StackSets for the approved baseline and deploy stack instances to the required accounts and Regions.

Correct answer

Use CloudFormation StackSets for the approved baseline and deploy stack instances to the required accounts and Regions.

Objective/domain: 6. Security Foundations and Governance (14%)

Source: Managing stacks across accounts and Regions with StackSets – AWS CloudFormation

Question 4 A development team requires access to several S3 buckets containing sensitive customer data for testing purposes. To adhere to the principle of least privilege and minimize potential security risks, what is the most appropriate immediate action to implement for granting this access?

Answer choices

  1. A. Utilize a pre-defined AWS managed policy for developers accessing S3, simplifying access management.
  2. B. Grant the development team full S3 administrator access for all buckets to expedite testing workflows.
  3. C. Rotate the development team’s IAM access keys every 24 hours to limit the impact of potential compromise.
  4. D. Create a custom IAM policy granting read-only access to the specific buckets and objects needed for testing.

Correct answer

Create a custom IAM policy granting read-only access to the specific buckets and objects needed for testing.

Objective/domain: 4. Identity and Access Management (20%)

Source: IAM Access Analyzer policy generation

Question 5 A dedicated security account receives security logs from production workloads. Application administrators must be able to operate their workloads but must not be able to alter the retained security evidence. Which control set BEST protects the log archive?

Answer choices

  1. A. Give application administrators write access to the archive so they can correct malformed records.
  2. B. Reduce the retention period to the minimum possible so there is less evidence to protect.
  3. C. Store the logs with the monitored workloads and depend on application backups for integrity.
  4. D. Use a separate central log archive with least-privilege access, encryption, integrity protections where supported, and an approved retention policy.

Correct answer

Use a separate central log archive with least-privilege access, encryption, integrity protections where supported, and an approved retention policy.

Objective/domain: 1. Detection (16%)

Source: Validating CloudTrail log file integrity

Question 6 An application in private subnets must retrieve secrets from AWS Secrets Manager. The security team requires the API traffic to stay on private AWS connectivity and not require a NAT gateway or internet gateway. Which solution BEST meets the requirement?

Answer choices

  1. A. Create a gateway VPC endpoint for Secrets Manager because gateway endpoints support every AWS service.
  2. B. Create an interface VPC endpoint for Secrets Manager and restrict endpoint access with appropriate endpoint and IAM policies.
  3. C. Create an internet gateway and rely only on TLS because encrypted traffic is equivalent to private connectivity.
  4. D. Assign public IP addresses to the application instances and restrict outbound HTTPS to the Secrets Manager public IP ranges.

Correct answer

Create an interface VPC endpoint for Secrets Manager and restrict endpoint access with appropriate endpoint and IAM policies.

Objective/domain: 3. Infrastructure Security (18%)

Source: Using an AWS Secrets Manager VPC endpoint

Question 7 GuardDuty reports anomalous credential use on an IAM role, Security Hub shows a related Inspector finding on an EC2 instance that assumed the role, and CloudTrail shows subsequent S3 data access. Before broad remediation, what should the incident responder do to assess scope and impact?

Answer choices

  1. A. Immediately delete the EC2 instance and all S3 objects it accessed.
  2. B. Treat every finding as an independent incident and remediate each service without correlation.
  3. C. Correlate the findings and supporting telemetry to validate the security event, identify affected principals/resources, and determine the actions performed and data potentially accessed.
  4. D. Suppress the GuardDuty finding because Inspector reported a different finding type.

Correct answer

Correlate the findings and supporting telemetry to validate the security event, identify affected principals/resources, and determine the actions performed and data potentially accessed.

Objective/domain: 2. Incident Response (14%)

Source: Introduction to AWS Security Hub CSPM

Question 8 A security team wants contractors to authenticate through the corporate identity provider and receive temporary access to only two AWS accounts for a 90-day engagement. The company wants centralized assignment rather than creating IAM users. Which approach is BEST?

Answer choices

  1. A. Create a long-lived IAM access key in every AWS account and email the keys to the contractors.
  2. B. Create a security group that lists contractor public IP addresses and treat it as identity authorization.
  3. C. Use IAM Identity Center federation and assign the contractor group permission sets only to the required accounts; remove the assignments when the engagement ends.
  4. D. Use an SCP to grant the contractors read-only access.

Correct answer

Use IAM Identity Center federation and assign the contractor group permission sets only to the required accounts; remove the assignments when the engagement ends.

Objective/domain: 4. Identity and Access Management (20%)

Source: What is IAM Identity Center?

Question 9 A security organization wants a searchable security data lake that ingests supported AWS security logs across accounts and Regions and normalizes supported AWS sources into OCSF for analytics and third-party subscribers. Which service is the BEST fit?

Answer choices

  1. A. AWS Security Hub CSPM.
  2. B. Amazon Security Lake.
  3. C. AWS Config.
  4. D. Amazon Detective.

Correct answer

Amazon Security Lake.

Objective/domain: 1. Detection (16%)

Source: What is Amazon Security Lake?

Question 10 A financial institution is migrating a legacy application to AWS and needs to securely manage database credentials. To ensure regular rotation and strict access control while adhering to encryption design requirements that match data classification, which approach provides the most robust and compliant solution for storing and managing these sensitive credentials?

Answer choices

  1. A. Manually update credentials every six months and store them in an encrypted file within an S3 bucket with limited access.
  2. B. Implement AWS Secrets Manager with automated rotation enabled and enforce granular IAM policies restricting access to authorized users and services.
  3. C. Store credentials directly in application code, relying on network firewalls for access control and periodic manual review.
  4. D. Utilize Systems Manager Parameter Store with manual rotation and broad user access for simplicity.

Correct answer

Implement AWS Secrets Manager with automated rotation enabled and enforce granular IAM policies restricting access to authorized users and services.

Objective/domain: 5. Data Protection (18%)

Source: Rotate AWS Secrets Manager secrets

Where to go after the daily web set

How are AWS Security Specialty questions generated?

dotCreds builds AWS Security Specialty practice questions from public exam objectives and AWS certification and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start AWS Security Specialty practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.