Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
AWS logo

AWSCertified Security - Specialty

Domain 4Objective 1

Task 4.1: Design, Implement, and Troubleshoot Authentication Strategies SCS-C03 Practice Questions (Page 4)

Part of the Content Domain 4: Identity and Access Management domain, which accounts for 20% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~14–23 in this domain), expect 7–12 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
11concepts
20%of the exam

Questions 16–20

  1. 16foundation · easy

    A developer is building a mobile application that needs to allow users to sign up and sign in using email and password, and also allow them to sign in with social identity providers like Facebook. Which Amazon Cognito component should be used to manage the user sign-up and sign-in process?

    Select an answer first
  2. 17foundation · easy

    An application uses Amazon Cognito user pools for authentication. After a user signs in successfully, the application needs to access AWS resources such as an S3 bucket. Which Cognito component should be used to exchange the user's authentication token for temporary AWS credentials?

    Select an answer first
  3. 18foundation · easy

    A security engineer is designing a central authentication solution for a company's workforce. The company wants to use AWS IAM Identity Center to manage access to multiple AWS accounts and business applications. Which component of IAM Identity Center defines the level of access that a user or group receives when assigned to an AWS account?

    Select an answer first
  4. 19foundation · easy

    A company wants to allow its employees to authenticate to AWS using their existing corporate Active Directory credentials. Which AWS service can be used to establish a trust relationship between the corporate IdP and AWS IAM for federated access?

    Select an answer first
  5. 20application · medium

    A company runs a batch processing application on Amazon EC2 instances. The application needs to read from an S3 bucket and write to a DynamoDB table. The security team wants to avoid storing long-term credentials on the instances. Which authentication strategy should the company implement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.