ExamGecko
Home / Amazon / SCS-C01 / List of questions
Ask Question

Amazon SCS-C01 Practice Test - Questions Answers, Page 16

Add to Whishlist

List of questions

Question 151

Report Export Collapse

A Security Engineer received an AWS Abuse Notice listing EC2 instance IDs that are reportedly abusing other hosts. Which action should the Engineer take based on this situation? (Choose three.)

Become a Premium Member for full access
  Unlock Premium Member

Question 152

Report Export Collapse

A Security Administrator is configuring an Amazon S3 bucket and must meet the following security requirements:

Encryption in transit

Encryption at rest

Logging of all object retrievals in AWS CloudTrail

Which of the following meet these security requirements? (Choose three.)

Become a Premium Member for full access
  Unlock Premium Member

Question 153

Report Export Collapse

What is the function of the following AWS Key Management Service (KMS) key policy attached to a customer master key (CMK)?

Amazon SCS-C01 image Question 153 7271 09162024005923000000

Become a Premium Member for full access
  Unlock Premium Member

Question 154

Report Export Collapse


A Security Engineer who was reviewing AWS Key Management Service (AWS KMS) key policies found this statement in each key policy in the company AWS account.

Amazon SCS-C01 image Question 154 7272 09162024005923000000

What does the statement allow?

Become a Premium Member for full access
  Unlock Premium Member

Question 155

Report Export Collapse

A Software Engineer wrote a customized reporting service that will run on a fleet of Amazon EC2 instances. The company security policy states that application logs for the reporting service must be centrally collected. What is the MOST efficient way to meet these requirements?

Become a Premium Member for full access
  Unlock Premium Member

Question 156

Report Export Collapse

A Security Engineer is trying to determine whether the encryption keys used in an AWS service are in compliance with certain regulatory standards. Which of the following actions should the Engineer perform to get further guidance?

Become a Premium Member for full access
  Unlock Premium Member

Question 157

Report Export Collapse

An application has been written that publishes custom metrics to Amazon CloudWatch. Recently, IAM changes have been made on the account and the metrics are no longer being reported. Which of the following is the LEAST permissive solution that will allow the metrics to be delivered?

Become a Premium Member for full access
  Unlock Premium Member

Question 158

Report Export Collapse

A Developer’s laptop was stolen. The laptop was not encrypted, and it contained the SSH key used to access multiple Amazon EC2 instances. A Security Engineer has verified that the key has not been used, and has blocked port 22 to all EC2 instances while developing a response plan.

How can the Security Engineer further protect currently running instances?

Become a Premium Member for full access
  Unlock Premium Member

Question 159

Report Export Collapse

An organization has tens of applications deployed on thousands of Amazon EC2 instances. During testing, the Application team needs information to let them know whether the network access control lists (network ACLs) and security groups are working as expected.

How can the Application team’s requirements be met?

Become a Premium Member for full access
  Unlock Premium Member

Question 160

Report Export Collapse

An application outputs logs to a text file. The logs must be continuously monitored for security incidents. Which design will meet the requirements with MINIMUM effort?

Become a Premium Member for full access
  Unlock Premium Member
Total 590 questions
Go to page: of 59
Search

Related questions