Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
AWS logo

AWSCertified Security - Specialty

Domain 4Objective 1

Task 4.1: Design, Implement, and Troubleshoot Authentication Strategies SCS-C03 Practice Questions (Page 7)

Part of the Content Domain 4: Identity and Access Management domain, which accounts for 20% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~14–23 in this domain), expect 7–12 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
11concepts
20%of the exam

Questions 31–32

  1. 31application · medium

    A security engineer is investigating why a user cannot access an S3 bucket after signing in through IAM Identity Center. The user can sign in successfully and can see the AWS account in the portal, but any API call to S3 fails with an AccessDenied error. Which CloudTrail event should the engineer examine first to diagnose the issue?

    Select an answer first
  2. 32foundation · easy

    A developer is troubleshooting a Cognito user pool authentication issue. The user pool has a Lambda trigger that is supposed to add custom claims to the ID token. Which Lambda trigger is responsible for modifying the ID token before it is issued?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to SCS-C03

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.