
AWSCertified Security - Specialty
Domain 4Objective 1
Task 4.1: Design, Implement, and Troubleshoot Authentication Strategies SCS-C03 Practice Questions (Page 1)
Part of the Content Domain 4: Identity and Access Management domain, which accounts for 20% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~14–23 in this domain), expect 7–12 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
11concepts
20%of the exam
Questions 1–5
- 1
A company has a mobile application that uses Amazon Cognito identity pools to provide temporary AWS credentials to users. The application recently started using a new identity provider (IdP) for sign-in. Users can authenticate with the new IdP, but they cannot access AWS resources. What should the developer check first?
Select an answer first - 2
A company uses AWS Managed Microsoft AD for authentication. Users report that they can sign in to their workstations but cannot authenticate to AWS services that use the directory. The directory's health status is healthy, and the security group for the directory allows inbound traffic on port 389. What should the administrator check next?
Select an answer first - 3
A user in IAM Identity Center can see an AWS account in the portal but cannot access any resources in that account. The user's permission set is attached to the account and the user is a member of the group that has the permission set assigned. CloudTrail shows an AssumeRole event that succeeded. What should the administrator check next?
Select an answer first - 4
A data analytics team needs to provide a third-party vendor with temporary access to a single CSV file in an S3 bucket. The vendor does not have AWS credentials. The file must be accessible for exactly 30 minutes, and the team wants to avoid creating any IAM users or roles for the vendor. Which solution should the team use?
Select an answer first - 5
A security engineer is troubleshooting an authentication failure for a user who is trying to assume a role in another AWS account. The user has valid credentials in the source account. CloudTrail shows an AssumeRole event with an 'AccessDenied' error. What is the most likely cause of this failure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.