
AWSCertified Solutions Architect - Professional
Domain 2Objective 3
Task 2.3: Determine Security Controls Based on Requirements SAP-C02 Practice Questions (Page 6)
Part of the Content Domain 2: Design for New Solutions domain, which makes up ~31% of our current practice bank. AWS does not publish an official question count, but from its 180-minute exam (~70–120 total, ~22–37 in this domain), expect 4–6 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
10concepts
Questions 26–30
- 26
A solutions architect is designing a data protection strategy. The architect needs to apply different levels of protection based on the sensitivity of the data. Which AWS service can be used to automatically discover and classify sensitive data stored in Amazon S3?
Select an answer first - 27
A company is using AWS Organizations to manage multiple accounts. The security team wants to enforce a policy that prevents any IAM user from creating access keys, but allows roles to be used for programmatic access. Which solution should the solutions architect implement?
Select an answer first - 28
A company is designing a new application that will be accessible over the internet. The security team is performing a threat model and identifies that the application could be vulnerable to distributed denial of service (DDoS) attacks. Which security control should the solutions architect implement to mitigate this threat?
Select an answer first - 29
A security team is performing threat modeling for a new API. They want to systematically identify potential threats by examining each component of the system. Which of the following is a common threat modeling methodology that involves decomposing the application and creating data flow diagrams?
Select an answer first - 30
A solutions architect is designing a new web application that will store customer personal data in Amazon S3. The architect must select security controls based on the application's specific requirements. Which control is primarily used to restrict access to the S3 bucket based on the requester's identity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SAP-C02” is a trademark of its owner, used for identification only.