Uploaded on Jan 7, 2026
The SCS-C03 Exam Guide is a comprehensive resource designed to help you prepare for the AWS Certified Security – Specialty exam. It covers core security concepts, AWS security services, identity and access management, data protection, incident response, logging, and monitoring. With clear explanations, practical examples, and exam-focused insights, this guide helps you build real-world security skills and confidently pass the SCS-C03 certification exam.
SCS-C03 Exam Guide: AWS Certified Security – Specialty Preparation
Amazon
SCS-C03
ExamName: AWS Certified Security - Specialty
Exam Version: 6.0
Questions & Answers Sample PDF
(Preview content before you buy)
Check the full version using the link below.
https://pass2certify.com/exam/scs-c03
Unlock Full Features:
Stay Updated: 90 days of free exam updates
Zero Risk: 30-day money-back policy
Instant Access: Download right after purchase
Always Here: 24/7 customer support team
https://pass2certify.com//exam/scs-c03 Page 1 of 5
Question 1. (Single Select)
An Application team is designing a solution with two applications. The Security team wants the applications'
logs to be captured in two different places, because one of the applications produces logs with sensitive
data.
Which solution meets the requirement with the LEAST risk and effort?
A: Use Amazon CloudWatch Logs to capture all logs, write an AWS Lambda function that parses the log
file, and move sensitive data to a different log.
B: Use Amazon CloudWatch Logs with two log groups, with one for each application, and use an AWS IAM
policy to control access to the log groups, as required.
C: Aggregate logs into one file, then use Amazon CloudWatch Logs, and then design two CloudWatch
metric filters to filter sensitive data from the logs.
D: Add logic to the application that saves sensitive data logs on the Amazon EC2 instances' local storage,
and write a batch script that logs into the Amazon EC2 instances and moves sensitive logs to a secure
location.
Answer: B
Question 2. (Multi Select)
A Security Engineer must set up security group rules for a three-tier application:
- Presentation tier – Accessed by users over the web, protected by the security group presentation-sg
- Logic tier – RESTful API accessed from the presentation tier through HTTPS, protected by the security
group logic-sg
- Data tier – SQL Server database accessed over port 1433 from the logic tier, protected by the security
group data-sg
Which combination of the following security group rules will allow the application to be secure and
functional?
(Select THREE.)
A: presentation-sg: Allow ports 80 and 443 from 0.0.0.0/0
https://pass2certify.com//exam/scs-c03 Page 2 of 5
B: data-sg: Allow port 1433 from presentation-sg
C: data-sg: Allow port 1433 from logic-sg
D: presentation-sg: Allow port 1433 from data-sg
E: logic-sg: Allow port 443 from presentation-sg
F: logic-sg: Allow port 443 from 0.0.0.0/0
Answer: A, C, E
Question 3. (Multi Select)
A company is building a data lake on Amazon S3. The data consists of millions of small files containing
sensitive information.
The Security team has the following requirements for the architecture:
- Data must be encrypted in transit.
- Data must be encrypted at rest.
- The bucket must be private, but if the bucket is accidentally made public, the data must remain
confidential.
Which combination of steps would meet the requirements?
(Select TWO.)
A: Enable AES-256 encryption using server-side encryption with Amazon S3-managed encryption keys
(SSE-S3) on the S3 bucket.
B: Enable default encryption with server-side encryption with AWS KMS-managed keys (SSE-KMS) on the
S3 bucket.
C: Add a bucket policy that includes a deny if a PutObject request does not include aws:SecureTransport.
D: Add a bucket policy with aws:SourceIp to allow uploads and downloads from the corporate intranet only.
E: Enable Amazon Macie to monitor and act on changes to the data lake's S3 bucket.
Answer: B, C
Question 4. (Single Select)
https://pass2certify.com//exam/scs-c03 Page 3 of 5
A Security Engineer must ensure that all API calls are collected across all company accounts, and that they
are preserved online and are instantly available for analysis for 90 days. For compliance reasons, this data
must be restorable for 7 years.
Which steps must be taken to meet the retention needs in a scalable, cost-effective way?
A: Enable AWS CloudTrail logging across all accounts to a centralized Amazon S3 bucket with versioning
enabled. Set a lifecycle policy to move the data to Amazon Glacier daily, and expire the data after 90 days.
B: Enable AWS CloudTrail logging across all accounts to S3 buckets. Set a lifecycle policy to expire the
data in each bucket after 7 years.
C: Enable AWS CloudTrail logging across all accounts to Amazon Glacier. Set a lifecycle policy to expire
the data after 7 years.
D: Enable AWS CloudTrail logging across all accounts to a centralized Amazon S3 bucket. Set a lifecycle
policy to move the data to Amazon Glacier after 90 days, and expire the data after 7 years.
Answer: D
Question 5. (Multi Select)
A company decides to place database hosts in its own VPC, and to set up VPC peering to different VPCs
containing the application and web tiers. The application servers are unable to connect to the database.
Which network troubleshooting steps should be taken to resolve the issue?
(Select TWO.)
A: Check to see if the application servers are in a private subnet or public subnet.
B: Check the route tables for the application server subnets for routes to the VPC peering connection.
C: Check the NACLs for the database subnets for rules that allow traffic from the internet.
D: Check the database security groups for rules that allow traffic from the application servers.
E: Check to see if the database VPC has an internet gateway
Answer: B, D
https://pass2certify.com//exam/scs-c03 Page 4 of 5
Need more info? Check the link below:
https://pass2certify.com/exam/scs-c03
Thanks for Being a Valued Pass2Certify User!
Guaranteed Success Pass Every Exam with Pass2Certify.
Save $15 instantly with promo code
SAVEFAST
Sales: [email protected]
Support: [email protected]
https://pass2certify.com//exam/scs-c03 Page 5 of 5
Comments