1.0 Detection SCS-C03 Practice Quiz
96 exam-style questions covering 16% of the SCS-C03 exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the AWS Certified Security Specialty practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
A payment API handles cardholder-adjacent metadata and is exposed through API Gateway and Lambda. The security team needs near-real-time detection of suspicious access patterns and failed authorization. Which monitoring requirement should be prioritized?
- A. Capture API access logs, Lambda application errors, authentication outcomes, and security findings with alerting on abnormal patterns
- B. Collect only monthly cost reports for the API account
- C. Rely only on Lambda deployment package checksums
- D. Monitor only successful HTTP 200 responses
The workload includes an internet-facing API and sensitive transaction context, so monitoring must cover request activity, application failures, authentication behavior, and security findings together.
A workload processes confidential documents and stores them in S3. The team must detect accidental exposure and sensitive data placement. What monitoring requirement is most relevant?
- A. Monitor S3 public access changes, object-level activity where required, and Amazon Macie findings
- B. Track only CPU utilization of unrelated EC2 instances
- C. Use only Route 53 health checks for the bucket name
- D. Monitor only container image vulnerability scans
Confidential document monitoring should include exposure detection, object access visibility, and sensitive data discovery.
A batch analytics workload runs once per night in a private subnet and reads encrypted S3 data. The business asks for security monitoring without high-volume debug logs. Which approach fits the workload?
- A. Enable verbose application debug logging forever for every record processed
- B. Monitor job success, data access events for sensitive buckets, key access, and exception logs with targeted retention
- C. Monitor only public web request metrics
- D. Disable all data access logging because the subnet is private
The workload is scheduled and data-sensitive, so monitoring should focus on execution outcome, protected data access, KMS usage, and meaningful failures rather than continuous debug noise.
A security operations team is onboarding a new workload. Which question best helps define detection requirements?
- A. Which dashboard color does the application team prefer?
- B. Which assets, identities, data, entry points, and failure modes are most important to protect?
- C. How many unused subnets exist in the account?
- D. Which service has the shortest name in the architecture?
Detection design starts by identifying what matters, how it can be accessed, and which failure or attack paths must be visible.
A VPC workload has strict egress requirements. The team wants monitoring for unexpected outbound connections. Which strategy is appropriate?
- A. Monitor only AWS Billing console logins
- B. Collect VPC Flow Logs and inspect egress patterns with alerts for unauthorized destinations
- C. Collect only application feature flag changes
- D. Rely only on subnet names that include private
Flow logs provide network metadata that can reveal unexpected outbound paths and destinations.
A multi-account organization has workloads with different criticality. The security team wants to set alert thresholds. What should drive the monitoring requirements?
- A. The alphabetical order of account names
- B. The number of dashboards a team already has
- C. Workload risk, data sensitivity, exposure, recovery objectives, and ownership model
- D. A single identical threshold for every resource type in every account
Monitoring requirements should reflect business impact and threat exposure so alerting is aligned to the actual risk of each workload.
A workload uses generative AI features through Amazon Bedrock and stores prompts and outputs. The security team must monitor for abuse while limiting sensitive logging. What is the best monitoring requirement?
- A. Log every prompt and response in plaintext forever
- B. Monitor only EC2 disk metrics because AI workloads always run on instances
- C. Capture policy-relevant invocation metadata, guardrail outcomes, access events, and redacted application logs
- D. Ignore model access events if the application has authentication
Generative AI monitoring should include who invoked the model, which controls acted, and safe diagnostic context without storing unnecessary sensitive prompt content.
A public application uses CloudFront, AWS WAF, and an ALB. The team needs to detect credential stuffing and layer 7 attacks. Which monitoring signals matter most?
- A. Only EBS volume throughput on backend instances
- B. Only CloudFormation stack output values
- C. Only successful deployment events from the pipeline
- D. AWS WAF logs, CloudFront access logs, ALB request metrics, and authentication failure patterns
Credential stuffing and layer 7 attacks are visible through edge, web firewall, load balancer, and identity-related request patterns.
Key Terms in This Domain
- Amazon CloudWatch: Metrics, alarms, dashboards, and logs for AWS resources and applications
- Amazon Security Lake: Centralizes security data from AWS and third-party sources in OCSF format
- Amazon CodeGuru Security: Static code analysis for security vulnerabilities and secrets in source code
- AWS Config: Tracks resource configuration history and evaluates compliance rules
- Amazon EMR: Managed Hadoop/Spark; supports inter-node encryption and Lake Formation integration
- SSM Parameter Store: Hierarchical configuration and secret storage with KMS encryption
- Amazon GuardDuty: Threat detection from CloudTrail, VPC Flow Logs, DNS, EKS, S3, and runtime telemetry
- AWS Security Hub: Aggregates and prioritizes findings across AWS security services
- Amazon Detective: Investigates security findings with linked behavioral graphs
- AWS CloudTrail: API call logging for governance, compliance, and incident investigation
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/aws-security-specialty/detection/
<a href="https://quizbuffet.com/aws-security-specialty/detection/">AWS Security Specialty Detection practice quiz on QuizBuffet</a>
Other SCS-C03 Domains
- 2.0 Incident Response
- 3.0 Infrastructure Security
- 4.0 Identity and Access Management
- 5.0 Data Protection
- 6.0 Security Foundations and Governance
← Back to SCS-C03 practice test overview
Questions are written against the published SCS-C03 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.