Free practice test

SCS-C03

Free AWS Certified Security Specialty practice test

10 original Security Specialty questions, playable right now. No account, no card, no email gate. Every answer opens the full explanation: the concept, why the right option is right, and why each wrong option is wrong, cited to the authoritative documentation behind it.

Sample question 1 of 10

Infrastructure Security

A public API behind an Application Load Balancer is being hit by a flood of requests from many addresses, all requesting the same expensive endpoint. Which control addresses this most directly?

Sample question 2 of 10

Data Protection

A team must leave existing public ACLs in place for an audit trail while making S3 disregard them today. Which setting does that?

Sample question 3 of 10

Security Logging and Monitoring

An analyst queries a CloudTrail log group in Logs Insights and needs to return only the calls made by one IAM user. How is the nested user name referenced?

Sample question 4 of 10

Identity and Access Management

A bucket policy in account 222222222222 grants s3:GetObject to a role in account 111111111111. The role's identity policy is silent on that bucket. What must change?

Sample question 5 of 10

Management and Security Governance

How does AWS Control Tower implement its detective controls?

Sample question 6 of 10

Threat Detection and Incident Response

GuardDuty Malware Protection for EC2 finds malware on an instance's volume. What happens to the EBS snapshots taken for the scan?

Sample question 7 of 10

Infrastructure Security

This policy is proposed for an S3 gateway endpoint so that only one role can use it. Which change makes it a valid gateway endpoint policy?

JSON
{  "Statement": [    {      "Effect": "Allow",      "Principal": { "AWS": "arn:aws:iam::111122223333:role/ReportRole" },      "Action": "s3:GetObject",      "Resource": "arn:aws:s3:::reports-bucket/*"    }  ]}

Sample question 8 of 10

Data Protection

A regulator requires key material to stay in single-tenant HSMs the team controls, while applications keep calling KMS APIs. What supports this?

Sample question 9 of 10

Security Logging and Monitoring

CloudTrail Insights raises an event for an account. What condition triggers one?

Sample question 10 of 10

Identity and Access Management

A session's permissions boundary never mentions Amazon SQS. A queue policy in the same account grants sqs:ReceiveMessage to that session's ARN. Can it read the queue?

Full Security Specialty question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

What this test covers

These 10 questions are drawn across the published exam blueprint rather than from one chapter: this set touches Infrastructure Security, Data Protection, Security Logging and Monitoring, Identity and Access Management, Management and Security Governance, Threat Detection and Incident Response. Every question is original, written from the official objectives, and verified against a cited vendor page before it serves. None are recalled exam content, which is why the explanations can cite their sources.

A 10-question sample tells you where you stand, not whether you are ready. The full experience is numbered practice exams: 65 questions apportioned to the official domain weightings, sat under the real 170-minute clock and scored against the published cut score.

Other free Amazon Web Services (AWS) practice tests

CLF-C02SAA-C03DVA-C02SOA-C03DEA-C01MLA-C01AIF-C01SAP-C02DOP-C02ANS-C01

Keep reading

Cheat sheets

Printable reference tables, free.

Every guide and cost breakdown, by vendor