
AWSCertified Security - Specialty
Domain 3Objective 2
Task 3.2: Design, Implement, and Troubleshoot Security Controls for Compute Workloads SCS-C03 Practice Questions (Page 9)
Part of the Content Domain 3: Infrastructure Security domain, which accounts for 18% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~13–21 in this domain), expect 4–7 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
17concepts
18%of the exam
Questions 41–45
- 41
A company has deployed a mix of Amazon EC2 instances, Amazon ECS clusters, and AWS Lambda functions. The security team is concerned about detecting malicious activity and anomalous behavior at the runtime level, such as cryptocurrency mining or unusual network connections from these workloads. Which service should they enable to get this visibility?
Select an answer first - 42
Which AWS service provides runtime monitoring for EC2, ECS, and Lambda to detect threats and anomalous behavior?
Select an answer first - 43
A company wants to implement a comprehensive security scanning strategy in their CI/CD pipeline. They have a mix of Java applications and infrastructure as code (IaC) written in AWS CloudFormation. They want to catch security issues in both the application code and the IaC templates before deployment. They also want to get automated remediation suggestions. Which combination of AWS services should they use?
Select an answer first - 44
A company needs to build a new AMI that includes a specific security agent that must be installed and configured. The agent requires a license file that is stored in AWS Secrets Manager. The security team wants the AMI build process to be fully automated and to fail if the agent is not installed correctly. They also want to test the AMI by launching an instance and running a validation script. Which EC2 Image Builder feature should they use to meet these requirements?
Select an answer first - 45
A company wants to integrate security scanning into their CI/CD pipeline to identify vulnerabilities in their application code and infrastructure as code (IaC) templates before deployment. They want to catch issues like SQL injection, insecure dependencies, and overly permissive IAM policies. Which combination of AWS services should they use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.