
AWSCertified CloudOps Engineer - Associate
Domain 4Objective 1
Task 4.1: Implement and Manage Security and Compliance Tools and Policies. SOA-C03 Practice Questions (Page 7)
Part of the Content Domain 4: Security and Compliance domain, which makes up ~17% of our current practice bank. AWS does not publish an official question count, but from its 130-minute exam (~50–85 total, ~9–14 in this domain), expect 5–7 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
16concepts
Questions 31–35
- 31
A company uses Microsoft Entra ID (Azure AD) as its identity provider. Employees need to access AWS accounts in the organization using their Entra ID credentials. The security team wants to use IAM Identity Center for SSO. What should they configure in IAM Identity Center?
Select an answer first - 32
A security team needs to investigate a suspicious API call that occurred in the past week. Where can they find the details of that API call?
Select an answer first - 33
An application running on an EC2 instance needs to read from an S3 bucket and write to a DynamoDB table. The security team wants to avoid storing long-term credentials on the instance. Which approach should they use?
Select an answer first - 34
Which AWS service allows you to centrally manage multiple AWS accounts, consolidate billing, and apply policies across all accounts?
Select an answer first - 35
Which element of an IAM policy allows you to restrict access based on conditions such as the user's IP address, the time of day, or whether MFA is present?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “SOA-C03” is a trademark of its owner, used for identification only.