ExamGecko
Home / Amazon / SCS-C01 / List of questions
Ask Question

Amazon SCS-C01 Practice Test - Questions Answers, Page 15

Add to Whishlist

List of questions

Question 141

Report Export Collapse

A Security Engineer must enforce the use of only Amazon EC2, Amazon S3, Amazon RDS, Amazon DynamoDB, and AWS STS in specific accounts. What is a scalable and efficient approach to meet this requirement?

Amazon SCS-C01 image Question 141 7259 09162024005923000000

Amazon SCS-C01 image Question 141 7259 09162024005923000000

Amazon SCS-C01 image Question 141 7259 09162024005923000000

Amazon SCS-C01 image Question 141 7259 09162024005923000000

Become a Premium Member for full access
  Unlock Premium Member

Question 142

Report Export Collapse

A company’s database developer has just migrated an Amazon RDS database credential to be stored and managed by AWS Secrets Manager. The developer has also enabled rotation of the credential within the Secrets Manager console and set the rotation to change every 30 days.

After a short period of time, a number of existing applications have failed with authentication errors. What is the MOST likely cause of the authentication errors?

Become a Premium Member for full access
  Unlock Premium Member

Question 143

Report Export Collapse

The Security Engineer is managing a web application that processes highly sensitive personal information. The application runs on Amazon EC2. The application has strict compliance requirements, which instruct that all incoming traffic to the application is protected from common web exploits and that all outgoing traffic from the EC2 instances is restricted to specific whitelisted URLs. Which architecture should the Security Engineer use to meet these requirements?

Become a Premium Member for full access
  Unlock Premium Member

Question 144

Report Export Collapse

A company recently experienced a DDoS attack that prevented its web server from serving content.

The website is static and hosts only HTML, CSS, and PDF files that users download.

Based on the architecture shown in the image, what is the BEST way to protect the site against future attacks while minimizing the ongoing operational overhead?

Amazon SCS-C01 image Question 144 7262 09162024005923000000

Become a Premium Member for full access
  Unlock Premium Member

Question 145

Report Export Collapse

The Information Technology department has stopped using Classic Load Balancers and switched to Application Load Balancers to save costs. After the switch, some users on older devices are no longer able to connect to the website. What is causing this situation?

Become a Premium Member for full access
  Unlock Premium Member

Question 146

Report Export Collapse

A security team is responsible for reviewing AWS API call activity in the cloud environment for security violations. These events must be recorded and retained in a centralized location for both current and future AWS regions. What is the SIMPLEST way to meet these requirements?

Become a Premium Member for full access
  Unlock Premium Member

Question 147

Report Export Collapse

A Security Administrator is performing a log analysis as a result of a suspected AWS account compromise. The Administrator wants to analyze suspicious AWS CloudTrail log files but is overwhelmed by the volume of audit logs being generated.

What approach enables the Administrator to search through the logs MOST efficiently?

Become a Premium Member for full access
  Unlock Premium Member

Question 148

Report Export Collapse

During a recent security audit, it was discovered that multiple teams in a large organization have placed restricted data in multiple Amazon S3 buckets, and the data may have been exposed. The auditor has requested that the organization identify all possible objects that contain personally identifiable information (PII) and then determine whether this information has been accessed. What solution will allow the Security team to complete this request?

Become a Premium Member for full access
  Unlock Premium Member

Question 149

Report Export Collapse

During a recent internal investigation, it was discovered that all API logging was disabled in a production account, and the root user had created new API keys that appear to have been used several times. What could have been done to detect and automatically remediate the incident?

Become a Premium Member for full access
  Unlock Premium Member

Question 150

Report Export Collapse

An application has a requirement to be resilient across not only Availability Zones within the application’s primary region but also be available within another region altogether. Which of the following supports this requirement for AWS resources that are encrypted by AWS KMS?

Become a Premium Member for full access
  Unlock Premium Member
Total 590 questions
Go to page: of 59
Search

Related questions