
AWSCertified Security - Specialty
Domain 1Objective 2
Task 1.2: Design and Implement Logging Solutions SCS-C03 Practice Questions (Page 5)
Part of the Content Domain 1: Detection domain, which accounts for 16% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
18concepts
16%of the exam
Questions 21–25
- 21
Which AWS service provides query logs that capture DNS queries made by resources within a VPC?
Select an answer first - 22
Which tool is commonly used to visualize and explore log data stored in Amazon OpenSearch Service?
Select an answer first - 23
A security engineer is designing a logging strategy for a new application that will be deployed on EC2 instances in a VPC. The application will use an Application Load Balancer (ALB) and an Amazon RDS database. The security team needs to detect unauthorized access attempts and monitor network traffic. Which log sources should the engineer enable?
Select an answer first - 24
A security analyst is investigating a potential brute-force attack on an EC2 instance. VPC Flow Logs and CloudWatch Logs are enabled. The analyst needs to identify the source IP addresses that attempted to connect to port 22 and failed. Which CloudWatch Logs Insights query would BEST identify these IP addresses?
Select an answer first - 25
A security team suspects that an attacker is using DNS tunneling to exfiltrate data from a VPC. They need to enable logging to capture DNS queries and analyze them for suspicious patterns. Which log source should they enable?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.