Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
AWS logo

AWSCertified Security - Specialty

Domain 2Objective 2

Task 2.2: Respond to Security Events SCS-C03 Practice Questions (Page 3)

Part of the Content Domain 2: Incident Response domain, which accounts for 14% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~10–16 in this domain), expect 5–8 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
7concepts
14%of the exam

Questions 11–15

  1. 11expert · hard

    A security engineer receives a GuardDuty finding that an EC2 instance is performing port scanning. The instance is part of a legacy application that cannot be stopped, and the security team is unsure if the finding is a false positive. The engineer needs to validate the finding and contain the threat if real, without disrupting the application. Which approach should the engineer take?

    Select an answer first
  2. 12application · medium

    A company's security team has identified a compromised EC2 instance that is communicating with a malicious server. The instance is in a private subnet and is accessed via a bastion host. The team needs to contain the threat while preserving the instance for forensic analysis. Which action should the team take?

    Select an answer first
  3. 13application · medium

    A security analyst is investigating a potential brute-force attack on an application. The analyst has CloudTrail logs, VPC Flow Logs, and application logs stored in S3. The analyst needs to correlate failed login attempts with network traffic to identify the source IPs. Which approach should the analyst use?

    Select an answer first
  4. 14foundation · easy

    A security analyst is conducting a root cause analysis and needs to understand the sequence of events that led to a security incident. Which method is commonly used to trace the timeline of events?

    Select an answer first
  5. 15foundation · easy

    A security team wants to search and analyze application logs stored in CloudWatch Logs to find error patterns related to a security incident. Which CloudWatch feature should they use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.