Important Amazon SCS-C02 Exam Questions
Amazon AWS Certified Security - Specialty (old) SCS-C02 Exam
Attempt the Amazon Specialty practice test and solve real exam-like SCS-C02 questions to prepare efficiently and increase your chances of success. Our Amazon SCS-C02 practice questions match the actual AWS Certified Security - Specialty (old) exam format, helping you enhance confidence and improve performance. With our SCS-C02 practice exam software, you can analyze your performance, identify weak areas, and work on them effectively to boost your final Amazon Specialty exam score.
| Vendor: | Amazon |
|---|---|
| Exam Name: | AWS Certified Security - Specialty (old) |
| Registration Code: | SCS-C02 |
| Related Certification: | Amazon Specialty Certification |
| Exam Audience: | AWS Amazon Security Engineers and Security Architects, |
Total Questions
467
Last Updated
04-07-2026
Exam Duration
170 MINUTES
Upgrade to Premium
GET FULL PDFQuestion: 1
[Identity and Access Management]
A security engineer is implementing a solution to allow users to seamlessly encrypt Amazon S3 objects without having to touch the keys directly. The solution must be highlyscalable without requiring continual management. Additionally, the organization must be able to immediately delete the encryption keys.
Which solution meets these requirements?
Question: 2
[Infrastructure Security]
A company that uses AWS Organizations wants to see AWS Security Hub findings for many AWS accounts and AWS Regions. Some of the accounts are in the company's organization, and some accounts are in organizations that the company manages for customers. Although the company can see findings in the Security Hub administrator account for accounts in the company's organization, there are no findings from accounts in other organizations.
Which combination of steps should the company take to see findings from accounts that are outside the organization that includes the Security Hub administrator account? (Select TWO.)
Question: 3
[Logging and Monitoring]
A security engineer is implementing a logging solution for a company's AWS environment. The security engineer has configured an AWS CloudTrail trail in the company's AWS account. The logs are stored in an Amazon S3 bucket for a third-party service provider to monitor. The service provider has a designated 1AM role to access the S3 bucket.
The company requires all logs to be encrypted at rest with a customer managed key. The security engineer uses AWS Key Management Service (AWS KMS) lo create the customer managed key and key policy. The security engineer also configures CloudTrail to use the key to encrypt the trail.
When the security engineer implements this configuration, the service provider no longer can read the logs.
What should the security engineer do to allow the service provider to read the logs?
Question: 4
[Data Protection]
A company has multiple Amazon S3 buckets encrypted with customer-managed CMKs Due to regulatory requirements the keys must be rotated every year. The company's Security Engineer has enabled automatic key rotation for the CMKs; however the company wants to verity that the rotation has occurred.
What should the Security Engineer do to accomplish this?
Question: 5
[Identity and Access Management]
A company is evaluating the use of AWS Systems Manager Session Manager to gam access to the company's Amazon EC2 instances. However, until the company implements the change, the company must protect the key file for the EC2 instances from read and write operations by any other users.
When a security administrator tries to connect to a critical EC2 Linux instance during an emergency, the security administrator receives the following error. "Error Unprotected private key file - Permissions for' ssh/my_private_key pern' are too open".
Which command should the security administrator use to modify the private key Me permissions to resolve this error?
Other Amazon Certification Exams
AWS Certified Solutions Architect - Professional Exam
AWS Certified AI Practitioner
AWS Certified Generative AI Developer - Professional
AWS Certified Solutions Architect - Associate
AWS Certified Security - Specialty
AWS Certified DevOps Engineer - Professional Exam