
AWSCertified Security - Specialty
Domain 3Objective 2
Task 3.2: Design, Implement, and Troubleshoot Security Controls for Compute Workloads SCS-C03 Practice Questions (Page 7)
Part of the Content Domain 3: Infrastructure Security domain, which accounts for 18% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~13–21 in this domain), expect 4–7 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
17concepts
18%of the exam
Questions 31–35
- 31
An application running on an EC2 instance needs to read objects from a specific Amazon S3 bucket and write logs to Amazon CloudWatch Logs. The security team mandates that the instance not have any long-term AWS credentials stored on it. How should the instance be configured to meet this requirement?
Select an answer first - 32
Which principle should guide the configuration of execution roles for compute workloads?
Select an answer first - 33
A developer needs temporary SSH access to a specific EC2 instance to debug an application issue. The company requires that access be granted based on IAM permissions and that no long-term SSH keys be stored on the developer's machine. The instance is in a private subnet but can reach the internet through a NAT gateway. What is the most appropriate way to grant this access?
Select an answer first - 34
What is the primary purpose of Amazon Q Developer in a security context?
Select an answer first - 35
How can you continuously validate that EC2 instances are compliant with patch requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.