Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
AWS logo

AWSCertified Security - Specialty

Domain 3Objective 1

Task 3.1: Design, Implement, and Troubleshoot Security Controls for Network Edge Services SCS-C03 Practice Questions (Page 4)

Part of the Content Domain 3: Infrastructure Security domain, which accounts for 18% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~13–21 in this domain), expect 4–7 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
11concepts
18%of the exam

Questions 16–20

  1. 16foundation · easy

    A company wants to reduce the attack surface of its web application by hiding the origin server's IP address. Which edge security strategy directly supports this goal?

    Select an answer first
  2. 17application · medium

    A gaming company is launching a new multiplayer title globally. The application is served through Amazon CloudFront and the backend is an Application Load Balancer (ALB) in us-east-1. The security team has identified that the game's login endpoint is being targeted by credential-stuffing attacks originating from a specific set of countries where the game is not legally available. The company wants to block these requests at the edge before they reach the ALB. What should the security engineer do to meet these requirements?

    Select an answer first
  3. 18application · medium

    A large e-commerce company is preparing for a major sales event. The security team is concerned about potential DDoS attacks targeting the application, which is served through Amazon CloudFront and an Application Load Balancer (ALB). The company wants to ensure that it has enhanced DDoS protection and can respond quickly to attacks. What should the security engineer do?

    Select an answer first
  4. 19foundation · easy

    A security engineer wants to block requests from a specific country using AWS WAF. Which AWS WAF match type should be used?

    Select an answer first
  5. 20application · medium

    A media streaming company uses Amazon CloudFront to serve video content from an S3 bucket. The company has a compliance requirement to prevent direct access to the S3 bucket and to ensure that all requests to the origin include a specific custom header that only CloudFront can provide. The security engineer needs to configure this without using an Origin Access Identity (OAI). What should the engineer do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.