Free AWS Certified Security Specialty practice test
10 real Security Specialty questions, playable right now. No account, no card, no email gate. Every answer opens the full explanation: the concept, why the right option is right, and why each wrong option is wrong, cited to AWS’s own documentation.
Sample question 1 of 10
A public API behind an Application Load Balancer is being hit by a flood of requests from many addresses, all requesting the same expensive endpoint. Which control addresses this most directly?
Sample question 2 of 10
A role in account B has an IAM policy allowing kms:Decrypt on a customer managed key that lives in account A. Decryption still fails with an access denied error. What is missing?
Sample question 3 of 10
An analyst queries a CloudTrail log group in Logs Insights and needs to return only the calls made by one IAM user. How is the nested user name referenced?
Sample question 4 of 10
A bucket policy in account 222222222222 grants s3:GetObject to a role in account 111111111111. The role's identity policy is silent on that bucket. What must change?
Sample question 5 of 10
A tag policy specifies enforcement for Amazon EC2 instances on the Environment key. A user tries to attach Environment=prod when the policy allows only Production. What is the outcome?
Sample question 6 of 10
A suppression rule was added to auto archive a noisy finding type. The Lambda quarantine function wired to the rule below then stopped running for those findings.
{
"source": ["aws.guardduty"],
"detail-type": ["GuardDuty Finding"]
}Why did it stop?
Sample question 7 of 10
This policy is proposed for an S3 gateway endpoint so that only one role can use it. Which change makes it a valid gateway endpoint policy?
{
"Statement": [
{
"Effect": "Allow",
"Principal": { "AWS": "arn:aws:iam::111122223333:role/ReportRole" },
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::reports-bucket/*"
}
]
}Sample question 8 of 10
A compliance team must guarantee that archived statements cannot be deleted for seven years, including by the account root user. Which Object Lock setting meets that?
Sample question 9 of 10
After a trail is reconfigured to capture S3 object activity, an analyst notices that ConsoleLogin and CreateUser entries have stopped arriving from that trail. What is the likely cause?
Sample question 10 of 10
A session's permissions boundary never mentions Amazon SQS. A queue policy in the same account grants sqs:ReceiveMessage to that session's ARN. Can it read the queue?
Full Security Specialty question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
What this test covers
These 10 questions are drawn across the published exam blueprint rather than from one chapter: this set touches Infrastructure Security, Data Protection, Security Logging and Monitoring, Identity and Access Management, Management and Security Governance, Threat Detection and Incident Response. Every question is original, written from the official objectives, and verified against a cited vendor page before it serves. None are recalled exam content, which is why the explanations can cite their sources.
A ten-question sample tells you where you stand, not whether you are ready. The full experience is numbered practice exams: 65 questions apportioned to the official domain weightings, sat under the real 170-minute clock and scored against the published cut score.
Keep reading
Security Specialty practice questions
Free sample questions with the full explanation on every answer.
Security Specialty passing score
The exact cut score, what kind of number it is, and the retake terms.
How hard is Security Specialty?
An honest difficulty read from the format, the clock and the weights.