
AWSCertified Security - Specialty
Domain 2Objective 2
Task 2.2: Respond to Security Events SCS-C03 Practice Questions (Page 4)
Part of the Content Domain 2: Incident Response domain, which accounts for 14% of the SCS-C03 exam. AWS does not publish an official question count, but from its 170-minute exam (~70–115 total, ~10–16 in this domain), expect 5–8 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
7concepts
14%of the exam
Questions 16–20
- 16
A security team wants to automatically move forensic logs from S3 Standard to S3 Glacier after 90 days to reduce storage costs while retaining them for potential investigations. Which S3 feature should be configured to achieve this?
Select an answer first - 17
A security engineer needs to quickly isolate a compromised EC2 instance by blocking all inbound and outbound traffic at the instance level. Which AWS resource should be modified to achieve this?
Select an answer first - 18
A security engineer sees a Security Hub finding that an S3 bucket is publicly accessible. What is the best way to validate this finding?
Select an answer first - 19
During an incident investigation, a security engineer needs to preserve evidence of network traffic to and from a compromised EC2 instance. Which AWS service should be enabled to capture this information as a forensic artifact?
Select an answer first - 20
A company's security team is responding to a potential compromise of a Linux EC2 instance. The team needs to capture the instance's system logs and network connections for forensic analysis. Which action should the team take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SCS-C03” is a trademark of its owner, used for identification only.