
AWSCertified Solutions Architect - Professional
Domain 2Objective 3
Task 2.3: Determine Security Controls Based on Requirements SAP-C02 Practice Questions (Page 5)
Part of the Content Domain 2: Design for New Solutions domain, which makes up ~31% of our current practice bank. AWS does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 4–6 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
10concepts
Questions 21–25
- 21
A company is deploying a new application on AWS and needs to detect and respond to security events. The security team wants to centralize logs from multiple AWS services, including CloudTrail, VPC Flow Logs, and application logs. They also need to create alerts for specific patterns, such as multiple failed login attempts. Which solution should the solutions architect implement?
Select an answer first - 22
A company is designing a new web application that will be publicly accessible. The security team is performing a threat model and identifies that the application could be vulnerable to SQL injection attacks. Which security control should the solutions architect implement to mitigate this threat?
Select an answer first - 23
A company is deploying a multi-tier application on AWS. The web tier is in a public subnet, and the application tier is in a private subnet. The security team has identified that the application tier should not be directly accessible from the internet. However, the application tier needs to make outbound calls to a third-party API over HTTPS. The company also wants to ensure that if the web tier is compromised, the attacker cannot use it to access the application tier. Which solution should the solutions architect implement?
Select an answer first - 24
A company processes credit card payments and must comply with the Payment Card Industry Data Security Standard (PCI DSS). Which security control is explicitly required by PCI DSS for cardholder data at rest?
Select an answer first - 25
An application running on an Amazon EC2 instance needs to access an Amazon S3 bucket. Which IAM mechanism is the recommended way to grant the EC2 instance access without embedding long-term credentials in the application?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SAP-C02” is a trademark of its owner, used for identification only.