
AWSCertified Security - Specialty
Domain 3Objective 3
Task 3.3: Design and Troubleshoot Network Security Controls SCS-C03 Practice Questions (Page 2)
Part of the Content Domain 3: Infrastructure Security domain, which accounts for 18% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~13–21 in this domain), expect 4–7 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
8concepts
18%of the exam
Questions 6–10
- 6
A company wants to provide secure access to an internal application without requiring users to connect to a VPN. Which AWS service can be used for this purpose?
Select an answer first - 7
A company needs a dedicated, private, high-bandwidth connection from its on-premises data center to AWS. Which service should be used?
Select an answer first - 8
A security engineer needs to block a specific IP address from reaching all instances in a subnet. Which AWS network security control should be used for this purpose?
Select an answer first - 9
A company uses AWS Network Access Analyzer to validate network segmentation. The engineer runs an analysis and finds an access path from a development subnet to a production subnet. The development subnet should not have access to the production subnet. The engineer reviews the security group rules and finds that the production security group allows inbound traffic from the development security group on port 22. What should the engineer do to remediate the access path?
Select an answer first - 10
A security engineer wants to encrypt traffic at the link layer on a dedicated Direct Connect connection. Which technology should be used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.