
AWSCertified Security - Specialty
Domain 5Objective 3
Task 5.3: Design and Implement Controls to Protect Confidential Data, Credentials, Secrets, and Cryptographic Key Materials SCS-C03 Practice Questions (Page 4)
Part of the Content Domain 5: Data Protection domain, which accounts for 18% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~13–21 in this domain), expect 4–7 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
14concepts
18%of the exam
Questions 16–20
- 16
A security engineer needs a centralized service to store database credentials, API keys, and other secrets, with the ability to control access using IAM policies. Which AWS service is designed for this purpose?
Select an answer first - 17
A security team wants to use a key generated on an on-premises hardware security module (HSM) to encrypt data in AWS. Which AWS KMS feature allows them to use this key material?
Select an answer first - 18
A company is using Amazon CloudWatch Logs to store application logs. The logs contain credit card numbers that must be masked before they are stored. The company wants to automatically redact this sensitive data as it is ingested. What should they do?
Select an answer first - 19
What is a common use case for AWS Private Certificate Authority?
Select an answer first - 20
What is required for an IAM principal to retrieve a secret from AWS Secrets Manager?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.