Aws Certified Security Specialty Scs C02 Practice Test - Set 1

Test your knowledge with this Aws Certified Security Specialty Scs C02 mock exam. Get real-world IT questions and prepare for certification success.

AWS Certified Security – Specialty (SCS-C02) - Exam Information

Exam Information

Exam Code

Aws Certified Security Specialty Scs C02

Exam Title

AWS Certified Security – Specialty (SCS-C02)

Vendor

AWS

Difficulty

Advanced

Duration

170 Minutes

Question Format

Multiple Choice

Last Updated

March 10, 2025

The AWS Certified Security – Specialty (SCS-C02) exam validates expertise in securing AWS environments.

Practice Test

Shop Best AWS Certified Security – Specialty (SCS-C02) Resources Worldwide Amazon

1. Which AWS service provides automated security assessments for applications running on AWS?

AWS Shield
AWS Config
Amazon Inspector
AWS WAF

2. What is the primary use case for AWS IAM?

Manage access and permissions
Monitor resource usage
Store data securely
Deploy applications

3. Which AWS service is used for protecting against DDoS attacks?

AWS Shield
AWS WAF
Amazon Inspector
AWS Config

4. What is the purpose of AWS CloudTrail?

Log API calls and account activity
Monitor resource usage
Store data securely
Deploy applications

5. Which AWS service is used for managing encryption keys?

AWS KMS
AWS IAM
AWS Secrets Manager
AWS CloudTrail

6. What is the primary use case for AWS WAF?

Web application firewall
Data warehousing
Load balancing
Monitoring and logging

7. Which AWS service is used for managing secrets and sensitive data?

AWS Secrets Manager
AWS IAM
AWS KMS
AWS CloudTrail

8. What is the purpose of AWS Config?

Track resource configuration changes
Monitor resource usage
Store data securely
Deploy applications

9. Which AWS service is used for monitoring and logging?

Amazon CloudWatch
AWS Config
AWS CloudTrail
AWS X-Ray

10. What is the primary use case for AWS Organizations?

Manage multiple AWS accounts
Monitor resource usage
Store data securely
Deploy applications

11. Which AWS service is used for securing data in transit?

AWS Certificate Manager
AWS KMS
AWS Secrets Manager
AWS CloudTrail

12. What is the purpose of AWS Artifact?

Access compliance reports and agreements
Monitor resource usage
Store data securely
Deploy applications

13. Which AWS service is used for securing S3 buckets?

S3 Bucket Policies
AWS IAM
AWS KMS
AWS CloudTrail

14. What is the primary use case for AWS GuardDuty?

Threat detection
Monitor resource usage
Store data securely
Deploy applications

15. Which AWS service is used for managing security groups?

Amazon VPC
AWS IAM
AWS KMS
AWS CloudTrail

16. What is the purpose of AWS Macie?

Discover and protect sensitive data
Monitor resource usage
Store data securely
Deploy applications

17. Which AWS service is used for securing EC2 instances?

Security Groups
AWS IAM
AWS KMS
AWS CloudTrail

18. What is the primary use case for AWS Firewall Manager?

Centralized firewall management
Monitor resource usage
Store data securely
Deploy applications

19. Which AWS service is used for securing RDS databases?

IAM Database Authentication
AWS IAM
AWS KMS
AWS CloudTrail

20. What is the purpose of AWS Security Hub?

Centralized security and compliance view
Monitor resource usage
Store data securely
Deploy applications

21. Which AWS service provides managed DDoS protection?

AWS Shield
AWS WAF
Amazon Inspector
AWS Config

22. What is the maximum number of IAM roles that can be attached to an EC2 instance?

1
5
10
20

23. Which AWS service is used to centrally manage firewall rules across accounts?

AWS Firewall Manager
AWS WAF
AWS Shield
AWS Config

24. What is the purpose of AWS Key Management Service (KMS)?

To create and control encryption keys
To manage IAM users
To monitor network traffic
To store secrets

25. Which AWS service provides automated security assessments for EC2 instances?

Amazon Inspector
AWS Config
AWS Shield
AWS WAF

26. What is the maximum number of policies that can be attached to an IAM user?

10
20
50
100

27. Which AWS service is used to discover and protect sensitive data?

Amazon Macie
AWS Shield
AWS WAF
AWS Config

28. What is the purpose of AWS Secrets Manager?

To rotate, manage, and retrieve secrets
To manage IAM users
To monitor network traffic
To store encryption keys

29. Which AWS service provides threat detection using machine learning?

Amazon GuardDuty
AWS Shield
AWS WAF
AWS Config

30. What is the maximum number of access keys allowed per IAM user?

2
5
10
20

31. Which AWS service provides a centralized view of security alerts?

AWS Security Hub
AWS Shield
AWS WAF
AWS Config

32. What is the purpose of AWS Certificate Manager?

To provision, manage, and deploy SSL/TLS certificates
To manage IAM users
To monitor network traffic
To store encryption keys

33. Which AWS service provides network security for EC2 instances?

Security Groups
AWS Shield
AWS WAF
AWS Config

34. What is the maximum number of security groups that can be attached to an EC2 instance?

5
10
20
50

35. Which AWS service provides a web application firewall?

AWS WAF
AWS Shield
Amazon Inspector
AWS Config

36. What is the purpose of AWS Organizations SCPs?

To control permissions across multiple AWS accounts
To manage IAM users
To monitor network traffic
To store encryption keys

37. Which AWS service provides compliance monitoring?

AWS Config
AWS Shield
AWS WAF
Amazon Inspector

38. What is the maximum number of rules allowed in a single AWS WAF web ACL?

100
200
500
1000

39. Which AWS service provides database authentication without passwords?

IAM Database Authentication
AWS Shield
AWS WAF
AWS Config

40. What is the purpose of AWS Artifact?

To access compliance reports and agreements
To manage IAM users
To monitor network traffic
To store encryption keys

41. Which AWS service provides network security for VPCs?

Network ACLs
AWS Shield
AWS WAF
AWS Config

42. What is the maximum number of policies that can be attached to an IAM role?

10
20
50
100

43. Which AWS service provides encryption for data at rest?

AWS KMS
AWS Shield
AWS WAF
AWS Config

44. What is the purpose of AWS CloudHSM?

To manage hardware security modules
To manage IAM users
To monitor network traffic
To store encryption keys

45. Which AWS service provides encryption for data in transit?

AWS Certificate Manager
AWS Shield
AWS WAF
AWS Config

46. What is the maximum number of rules allowed in a security group?

50
60
100
200

47. Which AWS service provides encryption for S3 objects?

S3 Encryption
AWS Shield
AWS WAF
AWS Config

48. What is the purpose of AWS Single Sign-On (SSO)?

To manage access to multiple AWS accounts
To manage IAM users
To monitor network traffic
To store encryption keys

49. Which AWS service provides encryption for EBS volumes?

EBS Encryption
AWS Shield
AWS WAF
AWS Config

50. What is the maximum number of rules allowed in a network ACL?

20
40
100
200

51. Which AWS service provides encryption for RDS databases?

RDS Encryption
AWS Shield
AWS WAF
AWS Config

52. What is the purpose of AWS Control Tower?

To set up and govern a secure multi-account AWS environment
To manage IAM users
To monitor network traffic
To store encryption keys

53. Which AWS service provides encryption for DynamoDB tables?

DynamoDB Encryption
AWS Shield
AWS WAF
AWS Config

54. What is the maximum number of AWS accounts that can be managed by AWS Organizations?

1000
5000
10000
20000

55. Which AWS service provides encryption for Lambda functions?

Lambda Encryption
AWS Shield
AWS WAF
AWS Config

56. What is the purpose of AWS Detective?

To analyze security findings
To manage IAM users
To monitor network traffic
To store encryption keys

57. Which AWS service provides encryption for API Gateway?

API Gateway Encryption
AWS Shield
AWS WAF
AWS Config

58. What is the maximum number of AWS Organizations SCPs that can be attached to an account?

5
10
20
50

59. Which AWS service provides encryption for CloudFront distributions?

CloudFront Encryption
AWS Shield
AWS WAF
AWS Config

60. What is the purpose of AWS Audit Manager?

To assess compliance with regulations and standards
To manage IAM users
To monitor network traffic
To store encryption keys

The Aws Certified Security Specialty Scs C02 certification is a globally recognized credential for IT professionals. This practice test helps you prepare by covering key topics like hardware, networking, troubleshooting, and security.

Want more practice? Check out our other mock exams:

© 2025 ITCertRocket.com - Hands-On IT Lab Exercises & Certification Prep. All rights reserved.