Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
AWS logo

AWSCertified Security - Specialty

Domain 5Objective 3

Task 5.3: Design and Implement Controls to Protect Confidential Data, Credentials, Secrets, and Cryptographic Key Materials SCS-C03 Practice Questions (Page 1)

Part of the Content Domain 5: Data Protection domain, which accounts for 18% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~13–21 in this domain), expect 4–7 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
14concepts
18%of the exam

Questions 1–5

  1. 1foundation · easy

    A company wants to automatically rotate the password for a database user every 30 days. Which AWS Secrets Manager feature should be used?

    Select an answer first
  2. 2application · medium

    A company has an AWS KMS customer managed key with imported key material. The security team suspects that the key material has been compromised and wants to invalidate the current key material and replace it with new material. The key is currently in use to encrypt data in Amazon S3. What is the correct procedure to replace the key material?

    Select an answer first
  3. 3foundation · easy

    What is the primary purpose of AWS Secrets Manager?

    Select an answer first
  4. 4foundation · easy

    What is a key difference between rotating an AWS-generated KMS key and an imported KMS key?

    Select an answer first
  5. 5foundation · easy

    What is an alias in AWS KMS?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.