
AWSCertified Security - Specialty
Domain 4Objective 2
Task 4.2: Design, Implement, and Troubleshoot Authorization Strategies SCS-C03 Practice Questions (Page 3)
Part of the Content Domain 4: Identity and Access Management domain, which accounts for 20% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~14–23 in this domain), expect 7–12 from this objective — we provide 13 practice questions to prepare you well beyond it. (estimate)
13questions here
3free pages
5concepts
20%of the exam
Questions 11–13
- 11
A security team discovers that an S3 bucket is publicly accessible due to a bucket policy that grants `s3:GetObject` to `*`. Which AWS service can be used to detect this type of unintended access?
Select an answer first - 12
After receiving an IAM Access Analyzer finding that an S3 bucket is shared with an external AWS account, what is the recommended first step to correct the unintended permission?
Select an answer first - 13
A security engineer is investigating an IAM Access Analyzer finding that shows an S3 bucket is accessible from an external AWS account. The engineer wants to determine if the access is intentional and if it should be removed. What should the engineer do first?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to SCS-C03
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.