
AWSCertified Security - Specialty
Domain 5Objective 1
Task 5.1: Design and Implement Controls for Data in Transit SCS-C03 Practice Questions (Page 4)
Part of the Content Domain 5: Data Protection domain, which accounts for 18% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~13–21 in this domain), expect 4–7 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
10concepts
18%of the exam
Questions 16–20
- 16
A company runs a critical application on EC2 instances that communicate with each other over the network. The security team wants to ensure that data in transit between these instances is encrypted at the network layer without requiring application-level changes. What should the security engineer do?
Select an answer first - 17
Which AWS resource type has a configurable security policy that specifies the TLS version and cipher suites for client connections?
Select an answer first - 18
A data science team uses Amazon SageMaker AI to train a model on a large dataset. The security team requires that data transferred between the SageMaker training instances and the S3 bucket be encrypted in transit. What should the security engineer configure?
Select an answer first - 19
In SageMaker AI, which setting controls encryption of data in transit between training instances?
Select an answer first - 20
Which AWS service provides secure access to applications without requiring a traditional VPN connection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.