
AWSCertified Security - Specialty
Domain 6Objective 2
Task 6.2: Implement a Secure and Consistent Deployment Strategy for Cloud Resources SCS-C03 Practice Questions (Page 5)
Part of the Content Domain 6: Security Foundations and Governance domain, which accounts for 14% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~10–16 in this domain), expect 3–5 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
10concepts
14%of the exam
Questions 21–25
- 21
A company is adopting a multi-account strategy and wants to implement a tagging strategy to track costs and ownership. The finance team needs to allocate costs by department and project. The operations team needs to identify the owner of each resource for troubleshooting. What is the MOST effective tagging strategy?
Select an answer first - 22
A company uses AWS Service Catalog to provision standardized EC2 instances for its developers. The company wants to automatically apply tags to all resources provisioned through Service Catalog to track the 'CostCenter' and 'Environment'. What is the MOST efficient way to achieve this?
Select an answer first - 23
A security engineer is implementing a policy-as-code pipeline for CloudFormation deployments. The team uses AWS CloudFormation Stack Sets to deploy to multiple accounts. The security team wants to enforce a rule that prohibits the use of 't2.micro' instances in production accounts. The engineer has written a CloudFormation Guard rule. Where should the rule be enforced to ensure it is applied to all stack set deployments?
Select an answer first - 24
Which of the following is a common practice when using Infrastructure as Code to improve the security of cloud resource deployments?
Select an answer first - 25
A company's central IT team has created a standardized, secure VPC architecture with a bastion host and specific security group rules. They want to allow application teams in different AWS accounts to launch this architecture themselves, but they do not want the teams to modify the underlying resources or create their own non-compliant versions. Which AWS service should the central IT team use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.