
AWSCertified Security - Specialty
Domain 5Objective 3
Task 5.3: Design and Implement Controls to Protect Confidential Data, Credentials, Secrets, and Cryptographic Key Materials SCS-C03 Practice Questions (Page 7)
Part of the Content Domain 5: Data Protection domain, which accounts for 18% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~13–21 in this domain), expect 4–7 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
14concepts
18%of the exam
Questions 31–35
- 31
What is the purpose of Amazon SNS message data protection?
Select an answer first - 32
What is the purpose of a key policy in AWS KMS?
Select an answer first - 33
A company operates in two AWS Regions and needs to encrypt data in both Regions using the same KMS key. They want to be able to encrypt in one Region and decrypt in the other. The key must be managed centrally. What is the most appropriate solution?
Select an answer first - 34
What is the benefit of enabling automatic rotation for a secret in AWS Secrets Manager?
Select an answer first - 35
What is an AWS KMS external key store (XKS)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to SCS-C03
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.