
AWSCertified Security - Specialty
Domain 3Objective 1
Task 3.1: Design, Implement, and Troubleshoot Security Controls for Network Edge Services SCS-C03 Practice Questions (Page 1)
Part of the Content Domain 3: Infrastructure Security domain, which accounts for 18% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~13–21 in this domain), expect 4–7 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
11concepts
18%of the exam
Questions 1–5
- 1
What is the primary purpose of rate limiting at the edge?
Select an answer first - 2
A security engineer is designing edge protection for a public web application. The primary threat is a large-scale distributed denial-of-service (DDoS) attack targeting the application's DNS and HTTP endpoints. Which edge security strategy should the engineer select as the FIRST line of defense?
Select an answer first - 3
A security engineer needs to protect a web application from SQL injection attacks using AWS WAF. Which AWS WAF component should be used to define the inspection criteria?
Select an answer first - 4
A security engineer needs to limit the number of requests a single IP address can make to a web application per minute to mitigate a brute-force attack. Which AWS WAF rule type should be used?
Select an answer first - 5
A security engineer wants to add security headers to HTTP responses served by CloudFront. Which CloudFront feature should be used to add these headers?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.