CloudExamCheap

SCS-C03 Practice Exam: AWS Certified Security - Specialty

139 questions · 170 min timed mode · AWS · Updated 2026

Lock down AWS like you mean it: KMS, IAM deep cuts, detection, incident response, and network security.

What you'll be tested on

Sample SCS-C03 questions

A security engineer is troubleshooting an AWS Lambda function that is named MyLambdaFunction. The function is encountering an error when the function attempts to read the objects in an Amazon S3 bucket that is named DOC-EXAMPLE-BUCKET. The S3 bucket has the following bucket policy: Which change should the security engineer make to the policy to ensure that the Lambda function can read the bucket objects?
  1. Remove the Condition element. Change the Principal element to the following:
  2. Change the Action element to the following:
  3. Change the Resource element to "arn:aws:s3:::DOC-EXAMPLE- BUCKET/*''.
  4. Change the Resource element to "arn:aws:lambda:::function:MyLambdaFunction". Change the Principal element to the following:
Show answerC — Change the Resource element to "arn:aws:s3:::DOC-EXAMPLE- BUCKET/*''.
In an S3 bucket policy, the Resource element must reference S3 resources. Object-level actions such as s3:GetObject apply to objects, so the Resource must be arn:aws:s3:::DOC-EXAMPLE-BUCKET/* rather than the bucket ARN alone. The policy's Resource was misconfigured, and fixing it to the object-level ARN lets the Lambda execution role read the objects. Changing the Principal or removing the Condition (A) or altering the Action (B) does not fix a malformed Resource. Option D is wrong because a bucket policy cannot grant permissions on a Lambda function ARN; Lambda is the principal making the call, not the resource.
An AWS account administrator created an IAM group and applied the following managed policy to require that each individual user authenticate using mul { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "ec2:*", "Resource": "*" }, { "Sid": "BlockAnyAccessUnlessSignedInWithMFA", "Effect": "Deny", "Action": "ec2:*", "Resource": "*", "Condition": { "BoolIfExists": { "aws:MultiFactorAuthPresent": false } } } ] }ti-factor authentication: After implementing the policy, the administrator receives reports that users are unable to perform Amazon EC2 commands using the AWS CLI. What should the administrator do to resolve this problem while still enforcing multi-factor authentication?
  1. Change the value of aws:MultiFactorAuthPresent to true.
  2. Instruct users to run the aws sts get-session-token CLI command and pass the multi-factor authentication --serial-number and - token-code parameters. Use these resulting values to make API/CLI calls.
  3. Implement federated API/CLI access using SAML 2.0, then configure the identity provider to enforce multi-factor authentication.
  4. Create a role and enforce multi-factor authentication in the role trust policy. Instruct users to run the sts assume-role CLI command and pass --serial-number and --token-code parameters. Store the resulting values in environment variables. Add sts:AssumeRole to NotAction in the policy.
Show answerB — Instruct users to run the aws sts get-session-token CLI command and pass the multi-factor authentication --serial-number and - token-code parameters. Use these resulting values to make API/CLI calls.
The Deny statement with the aws:MultiFactorAuthPresent condition blocks API calls that are not MFA-authenticated, and AWS CLI calls made with long-term access keys carry no MFA flag — so every EC2 CLI call is denied. Running aws sts get-session-token with --serial-number and --token-code returns temporary credentials that DO satisfy the MFA condition, restoring CLI access while MFA stays enforced. Setting the condition value to true just hard-codes the same block, SAML federation is unnecessary overhead here, and an MFA role does not help users calling ec2 directly as themselves.
What is the effect of the following AWS Key Management Service (AWS KMS} key policy that is attached to a customer managed key? { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::111122223333:role/ExampleRole" }, "Action": [ "kms:Encrypt", "kms:Decrypt", "kms:GenerateDataKey*", "kms:CreateGrant", "kms:ListGrants" ], "Resource": "*", "Condition": { "StringEquals": { "kms:ViaService": [ "workmail.us-west-2.amazonaws.com", "ses.us-west-2.amazonaws.com" ] } } }
  1. Amazon WorkMail and Amazon Simple Email Service (Amazon SES) have delegated KMS encrypt and decrypt permissions to the ExampleRole principal in the 111122223333 account.
  2. The ExampleRole principal can transparently encrypt and decrypt email exchanges specifically between ExampleRole and AWS.
  3. The customer managed key can be used for encrypting and decrypting only when the principal is ExampleRole and when the request comes from Amazon WorkMail or Amazon Simple Email Service (Amazon SES) in the specified AWS Region.
  4. The key policy allows Amazon WorkMail or Amazon Simple Email Service (Amazon SES) to encrypt or decrypt on behalf of the ExampleRole for any customer managed key in the account.
Show answerC — The customer managed key can be used for encrypting and decrypting only when the principal is ExampleRole and when the request comes from Amazon WorkMail or Amazon Simple Email Service (Amazon SES) in the specified AWS Region.
The key policy grants the ExampleRole principal kms:Encrypt, kms:Decrypt, kms:GenerateDataKey*, kms:CreateGrant, and kms:ListGrants on the customer managed key, so the key can be used for encryption and decryption operations by that role — that is exactly what option C states. The policy never mentions WorkMail or SES, so options naming those services are wrong, and option B is wrong because nothing in a key policy makes encryption transparent to the principal; the role must still call the KMS API.

Access plans

AccessPrice
3 months$8.99$3.99
1 year$14.99$8.99
Lifetime$24.99$14.99
Practice SCS-C03 now →
Free preview inside — try 5 questions before you pay anything.

FAQ

How many practice questions are in this SCS-C03 bank?
139 questions covering the current SCS-C03 AWS Certified Security - Specialty syllabus, every one with the correct answer and an explanation.
How long is the real SCS-C03 exam?
The official SCS-C03 exam gives you 170 minutes. Our timed exam mode uses the same limit so the pace feels familiar.
What does SCS-C03 access cost?
Plans start at $3.99 for 3 months. One payment, no subscription — and far cheaper than retaking the real exam.