SCS-C03AWS Certified Security Specialty

Practice Exam 2

The first 5 of 65 questions, free. The explanation on every one of them is free too, at every tier, and always will be.

  1. Question 1 of 65

    GuardDuty Malware Protection for EC2Threat Detection and Incident ResponseModerate

    A team turns on snapshot retention for Malware Protection for EC2 and expects a snapshot from every scan. Which scans actually leave a snapshot behind?

  2. Question 2 of 65

    GuardDuty Malware Protection for EC2Threat Detection and Incident ResponseModerate

    A finding that indicates possible malware fires twice against one instance in an afternoon, and only the first triggers an automatic EBS scan. What explains the second?

  3. Question 3 of 65

    Credential compromiseThreat Detection and Incident ResponseModerate

    GuardDuty reports UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration, meaning an EC2 instance role's credentials were used from outside AWS. What is the correct first action?

  4. Question 4 of 65

    GuardDuty finding severityThreat Detection and Incident ResponseEasy

    A responder opens the finding below and has to decide how urgently it should be worked.

    {
      "schemaVersion": "2.0",
      "accountId": "111122223333",
      "region": "us-east-1",
      "type": "Behavior:EC2/NetworkPortUnusual",
      "severity": 5,
      "resource": {
        "resourceType": "Instance",
        "instanceDetails": { "instanceId": "i-0ab1c2d3e4f56789a" }
      },
      "service": { "archived": false, "count": 3 }
    }

    What does that severity value describe?

  5. Question 5 of 65

    GuardDuty Malware Protection for EC2Threat Detection and Incident ResponseEasy

    An application runs as ECS tasks on AWS Fargate. Security asks whether GuardDuty Malware Protection for EC2 will scan those tasks. What is the answer?

0 of 65 completed

0%

The remaining 60 questions are the rest of this form: same 170 minute clock, same 750 cut score, and the same explanation on every question, which is never behind the wall. Practice Exam 2 of 2 on Security Specialty.

What the rest of this exam covers

  • Threat Detection and Incident Response9 questions / 14% of the exam
  • Security Logging and Monitoring12 questions / 18% of the exam
  • Infrastructure Security13 questions / 20% of the exam
  • Identity and Access Management10 questions / 16% of the exam
  • Data Protection12 questions / 18% of the exam
  • Management and Security Governance9 questions / 14% of the exam

Checking what you already have access to.

Every question is original, written from the published objectives. We never reproduce, paraphrase, or imitate real exam content, and neither should anything else you study from.