
AWSCertified Security - Specialty
Domain 5Objective 3
Task 5.3: Design and Implement Controls to Protect Confidential Data, Credentials, Secrets, and Cryptographic Key Materials SCS-C03 Practice Questions (Page 2)
Part of the Content Domain 5: Data Protection domain, which accounts for 18% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~13–21 in this domain), expect 4–7 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
14concepts
18%of the exam
Questions 6–10
- 6
What is a common use case for Amazon SNS message data protection?
Select an answer first - 7
How can you rotate an AWS KMS key that uses imported key material?
Select an answer first - 8
A company uses Amazon SNS to publish order notifications. The messages contain customer email addresses and phone numbers, which must be redacted before they are delivered to subscribers. The company wants to implement this without modifying the application code. What should they do?
Select an answer first - 9
A security engineer needs to rotate the imported key material for a customer managed KMS key. The key is used to encrypt data in Amazon S3. The rotation must not change the key ID, and the old key material must be available for decryption of data encrypted with it. What is the correct way to achieve this?
Select an answer first - 10
An application running on an EC2 instance needs to retrieve a database secret from AWS Secrets Manager. Which AWS SDK call should the application use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.