Free practice testSCS-C03

Free AWS Certified Security Specialty practice test

10 real Security Specialty questions, playable right now. No account, no card, no email gate. Every answer opens the full explanation: the concept, why the right option is right, and why each wrong option is wrong, cited to AWS’s own documentation.

Sample question 1 of 10

Infrastructure SecurityModerate

A public API behind an Application Load Balancer is being hit by a flood of requests from many addresses, all requesting the same expensive endpoint. Which control addresses this most directly?

Sample question 2 of 10

Data ProtectionHard

A role in account B has an IAM policy allowing kms:Decrypt on a customer managed key that lives in account A. Decryption still fails with an access denied error. What is missing?

Sample question 3 of 10

Security Logging and MonitoringModerate

An analyst queries a CloudTrail log group in Logs Insights and needs to return only the calls made by one IAM user. How is the nested user name referenced?

Sample question 4 of 10

Identity and Access ManagementModerate

A bucket policy in account 222222222222 grants s3:GetObject to a role in account 111111111111. The role's identity policy is silent on that bucket. What must change?

Sample question 5 of 10

Management and Security GovernanceEasy

A tag policy specifies enforcement for Amazon EC2 instances on the Environment key. A user tries to attach Environment=prod when the policy allows only Production. What is the outcome?

Sample question 6 of 10

Threat Detection and Incident ResponseHard

A suppression rule was added to auto archive a noisy finding type. The Lambda quarantine function wired to the rule below then stopped running for those findings.

{
  "source": ["aws.guardduty"],
  "detail-type": ["GuardDuty Finding"]
}

Why did it stop?

Sample question 7 of 10

Infrastructure SecurityHard

This policy is proposed for an S3 gateway endpoint so that only one role can use it. Which change makes it a valid gateway endpoint policy?

{
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": { "AWS": "arn:aws:iam::111122223333:role/ReportRole" },
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::reports-bucket/*"
    }
  ]
}

Sample question 8 of 10

Data ProtectionEasy

A compliance team must guarantee that archived statements cannot be deleted for seven years, including by the account root user. Which Object Lock setting meets that?

Sample question 9 of 10

Security Logging and MonitoringModerate

After a trail is reconfigured to capture S3 object activity, an analyst notices that ConsoleLogin and CreateUser entries have stopped arriving from that trail. What is the likely cause?

Sample question 10 of 10

Identity and Access ManagementHard

A session's permissions boundary never mentions Amazon SQS. A queue policy in the same account grants sqs:ReceiveMessage to that session's ARN. Can it read the queue?

Full Security Specialty question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

What this test covers

These 10 questions are drawn across the published exam blueprint rather than from one chapter: this set touches Infrastructure Security, Data Protection, Security Logging and Monitoring, Identity and Access Management, Management and Security Governance, Threat Detection and Incident Response. Every question is original, written from the official objectives, and verified against a cited vendor page before it serves. None are recalled exam content, which is why the explanations can cite their sources.

A ten-question sample tells you where you stand, not whether you are ready. The full experience is numbered practice exams: 65 questions apportioned to the official domain weightings, sat under the real 170-minute clock and scored against the published cut score.

Keep reading

Every guide and cost breakdown, by vendor