
AWSCertified Security - Specialty
Domain 5Objective 1
Task 5.1: Design and Implement Controls for Data in Transit SCS-C03 Practice Questions (Page 3)
Part of the Content Domain 5: Data Protection domain, which accounts for 18% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~13–21 in this domain), expect 4–7 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
10concepts
18%of the exam
Questions 11–15
- 11
A company runs a web application behind an Application Load Balancer (ALB). A security audit requires that all client connections use TLS 1.2 or higher and that weak cipher suites are disabled. The application team must not change the application code. What should the security engineer do?
Select an answer first - 12
What is the primary purpose of AWS PrivateLink?
Select an answer first - 13
Which approach is commonly used to encrypt node-to-node communication in an Amazon EKS cluster?
Select an answer first - 14
What is the purpose of AWS Nitro System encryption for data in transit?
Select an answer first - 15
A company runs an Amazon EMR cluster that processes sensitive data. The security team requires that data in transit between cluster nodes be encrypted. The cluster also needs to access data in an S3 bucket. The company wants to minimize the performance impact of encryption. What should the security engineer configure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.