5.0 Data Protection SCS-C03 Practice Quiz
108 exam-style questions covering 18% of the SCS-C03 exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the AWS Certified Security Specialty practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
A public ALB must reject clients that use obsolete TLS versions while preserving HTTPS for modern browsers. What should the security engineer configure?
- A. An ELB security policy that permits only approved TLS versions and ciphers
- B. An S3 Lifecycle rule on access logs
- C. An IAM password policy for application users
- D. EBS encryption on the load balancer targets only
ELB security policies define the TLS protocol and cipher suites used by HTTPS listeners.
A company wants end users to know they are connecting to the intended public application domain. What data-in-transit control is required?
- A. A trusted public certificate on the HTTPS endpoint that matches the application domain
- B. A private AMI hardened with CIS settings
- C. An SQS dead-letter queue for failed events
- D. A KMS key alias that matches the DNS name
A valid certificate lets clients authenticate the endpoint and establish an encrypted session.
A compliance requirement states that all connections to an Amazon RDS database must use TLS. What should be implemented?
- A. Use public subnets for the database
- B. Require SSL or TLS at the database layer and distribute the correct trust bundle to clients
- C. Enable S3 Object Lock on database exports only
- D. Increase the database backup retention period
Database-side TLS enforcement and trusted certificates ensure clients establish encrypted database sessions.
An ALB listener supports TLS, but scanners report weak ciphers. What should be changed?
- A. Rotate the application database password
- B. Select a stronger ELB security policy that removes the weak cipher suites
- C. Add more target group health checks
- D. Enable EFS lifecycle policies
The listener's security policy controls which cipher suites the ALB offers during TLS negotiation.
A private application must consume an AWS service without traversing the public internet. What should be configured?
- A. A public NAT gateway route to every service
- B. A VPC endpoint with appropriate endpoint policy and private DNS settings
- C. An open security group on the application
- D. A bucket lifecycle policy
VPC endpoints provide private connectivity to supported AWS services and can be scoped by policy.
A CloudFront distribution serves an API. The company requires viewers to use HTTPS and origins to receive encrypted traffic. What configuration satisfies this?
- A. Use a wider cache TTL for API responses
- B. Store API logs in an encrypted bucket only
- C. Set viewer protocol policy to redirect or require HTTPS and use HTTPS-only origin protocol policy
- D. Use an IAM permissions boundary on the distribution owner
CloudFront can enforce HTTPS from viewers and use encrypted connections to origins.
An application sends customer data to an external partner API. The security team requires encryption and server identity validation. What should the client verify?
- A. Only the HTTP response body length
- B. Only the local instance profile name
- C. The partner endpoint certificate chain and hostname during TLS negotiation
- D. Only the S3 storage class of archived payloads
Client-side certificate validation prevents encrypted connections to an untrusted or impersonated endpoint.
A private API endpoint must be accessible only with TLS 1.2 or later. Which control should be selected?
- A. Enable DynamoDB point-in-time recovery
- B. Use a NAT gateway for inbound API traffic
- C. Change the API stage description
- D. Configure the API's custom domain or fronting load balancer with an approved TLS security policy
The TLS policy on the serving endpoint determines which client protocol versions are accepted.
Key Terms in This Domain
- AWS Resource Access Manager: Securely shares AWS resources across accounts and OUs
- AWS Systems Manager: Operations management and automated remediation across resources
- AWS IAM: Identity and access management for users, groups, and roles
- Resource-based policy: Policy attached directly to a resource (S3 bucket, KMS key, role) granting cross-account access
- AWS Verified Access: Zero-trust access to internal apps without a VPN, evaluating identity and device
- AWS PrivateLink: Private connectivity to AWS and SaaS services via interface VPC endpoints
- VPC interface endpoint: PrivateLink endpoint into AWS services without traversing the public internet
- Network Access Analyzer: Identifies unintended network paths to or from resources
- Amazon EMR: Managed Hadoop/Spark; supports inter-node encryption and Lake Formation integration
- AWS KMS: Managed encryption keys with policy-based access control and CloudTrail audit
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/aws-security-specialty/data-protection/
<a href="https://quizbuffet.com/aws-security-specialty/data-protection/">AWS Security Specialty Data Protection practice quiz on QuizBuffet</a>
Other SCS-C03 Domains
- 1.0 Detection
- 2.0 Incident Response
- 3.0 Infrastructure Security
- 4.0 Identity and Access Management
- 6.0 Security Foundations and Governance
← Back to SCS-C03 practice test overview
Questions are written against the published SCS-C03 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.