5.0 Data Protection SCS-C03 Practice Quiz

108 exam-style questions covering 18% of the SCS-C03 exam. Instant feedback on every answer, progress tracking, no signup required.

This domain is part of the AWS Certified Security Specialty practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.

Sample Questions

A public ALB must reject clients that use obsolete TLS versions while preserving HTTPS for modern browsers. What should the security engineer configure?
  • A. An ELB security policy that permits only approved TLS versions and ciphers
  • B. An S3 Lifecycle rule on access logs
  • C. An IAM password policy for application users
  • D. EBS encryption on the load balancer targets only

ELB security policies define the TLS protocol and cipher suites used by HTTPS listeners.

A company wants end users to know they are connecting to the intended public application domain. What data-in-transit control is required?
  • A. A trusted public certificate on the HTTPS endpoint that matches the application domain
  • B. A private AMI hardened with CIS settings
  • C. An SQS dead-letter queue for failed events
  • D. A KMS key alias that matches the DNS name

A valid certificate lets clients authenticate the endpoint and establish an encrypted session.

A compliance requirement states that all connections to an Amazon RDS database must use TLS. What should be implemented?
  • A. Use public subnets for the database
  • B. Require SSL or TLS at the database layer and distribute the correct trust bundle to clients
  • C. Enable S3 Object Lock on database exports only
  • D. Increase the database backup retention period

Database-side TLS enforcement and trusted certificates ensure clients establish encrypted database sessions.

An ALB listener supports TLS, but scanners report weak ciphers. What should be changed?
  • A. Rotate the application database password
  • B. Select a stronger ELB security policy that removes the weak cipher suites
  • C. Add more target group health checks
  • D. Enable EFS lifecycle policies

The listener's security policy controls which cipher suites the ALB offers during TLS negotiation.

A private application must consume an AWS service without traversing the public internet. What should be configured?
  • A. A public NAT gateway route to every service
  • B. A VPC endpoint with appropriate endpoint policy and private DNS settings
  • C. An open security group on the application
  • D. A bucket lifecycle policy

VPC endpoints provide private connectivity to supported AWS services and can be scoped by policy.

A CloudFront distribution serves an API. The company requires viewers to use HTTPS and origins to receive encrypted traffic. What configuration satisfies this?
  • A. Use a wider cache TTL for API responses
  • B. Store API logs in an encrypted bucket only
  • C. Set viewer protocol policy to redirect or require HTTPS and use HTTPS-only origin protocol policy
  • D. Use an IAM permissions boundary on the distribution owner

CloudFront can enforce HTTPS from viewers and use encrypted connections to origins.

An application sends customer data to an external partner API. The security team requires encryption and server identity validation. What should the client verify?
  • A. Only the HTTP response body length
  • B. Only the local instance profile name
  • C. The partner endpoint certificate chain and hostname during TLS negotiation
  • D. Only the S3 storage class of archived payloads

Client-side certificate validation prevents encrypted connections to an untrusted or impersonated endpoint.

A private API endpoint must be accessible only with TLS 1.2 or later. Which control should be selected?
  • A. Enable DynamoDB point-in-time recovery
  • B. Use a NAT gateway for inbound API traffic
  • C. Change the API stage description
  • D. Configure the API's custom domain or fronting load balancer with an approved TLS security policy

The TLS policy on the serving endpoint determines which client protocol versions are accepted.

Key Terms in This Domain

Link to this quiz

Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:

https://quizbuffet.com/aws-security-specialty/data-protection/

<a href="https://quizbuffet.com/aws-security-specialty/data-protection/">AWS Security Specialty Data Protection practice quiz on QuizBuffet</a>

Other SCS-C03 Domains

← Back to SCS-C03 practice test overview

Questions are written against the published SCS-C03 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.