
AWSCertified Security - Specialty
Domain 1Objective 2
Task 1.2: Design and Implement Logging Solutions SCS-C03 Practice Questions (Page 6)
Part of the Content Domain 1: Detection domain, which accounts for 16% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~11–18 in this domain), expect 4–6 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
18concepts
16%of the exam
Questions 26–30
- 26
What type of information is captured in Route 53 Resolver query logs?
Select an answer first - 27
A security engineer needs to determine which AWS service records API calls made by IAM users and roles in an account. Which log source should be used for this purpose?
Select an answer first - 28
Which configuration file is used by the CloudWatch Logs agent to specify which log files to monitor and which log group to send them to?
Select an answer first - 29
A company wants to aggregate logs from multiple AWS accounts into a single CloudWatch Logs destination for centralized monitoring. Which AWS feature enables this cross-account log aggregation?
Select an answer first - 30
A security analyst wants to capture DNS queries made by resources within a VPC for threat detection. Which AWS log source should be enabled to meet this requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.