Skip to content
Tip 2 Cloud

Free study guides, practices test, sample questions

Primary Navigation Menu
Menu
  • Home
  • About us
  • Contact

SCS-C01 (Page 8)

Home » SCS-C01

Which combination of steps should the company take to resolve these security issues?

2026-03-28
By: study aws cloud
In: SCS-C01
With: 2 Comments

A company has a serverless application for internal users deployed on AWS.The application uses AWS Lambda for the front end and for business logic.TheLambda function accesses an Amazon RDS database inside a VPC.The company uses AWS Systems Manager Parameter Store for storing database credentials.A recent security review highlighted the following issues:✑ The Lambda function has internet access.✑ The relational database is publicly accessible.✑ The database credentials are not stored in an encrypted state.Which combination of steps should the company take to resolve these security issues? (Choose three.)Read More →

Which solution meets the company’s current and future logging requirements?

2026-03-28
By: study aws cloud
In: SCS-C01
With: 2 Comments

A company’s on-premises data center forwards DNS logs to a third-party security incident events management (SIEM) solution that alerts on suspicious behavior.The company wants to introduce a similar capability to its AWS accounts that includes automatic remediation.The company expects to double in size within the next few months.Which solution meets the company’s current and future logging requirements?Read More →

Which steps would help achieve this?

2026-03-28
By: study aws cloud
In: SCS-C01
With: 2 Comments

An ecommerce website was down for 1 hour following a DDoS attack.Users were unable to connect to the website during the attack period.The ecommerce company’s security team is worried about future potential attacks and wants to prepare for such events.The company needs to minimize downtime in its response to similar attacks in the future.Which steps would help achieve this? (Choose two.)Read More →

Which combination of steps should the security engineer recommend?

2026-03-28
By: study aws cloud
In: SCS-C01
With: 2 Comments

A company has a VPC with several Amazon EC2 instances behind a NAT gateway.The company’s security policy states that all network traffic must be logged and must include the original source and destination IP addresses.The existing VPC Flow Logs do not include this information.A security engineer needs to recommend a solution.Which combination of steps should the security engineer recommend? (Choose two.)Read More →

Which set of actions should the security team implement to accomplish this?

2026-03-28
By: study aws cloud
In: SCS-C01
With: 2 Comments

A company manages multiple AWS accounts using AWS Organizations.The company’s security team notices that some member accounts are not sending AWSCloudTrail logs to a centralized Amazon S3 logging bucket.The security team wants to ensure there is at least one trail configured for all existing accounts and for any account that is created in the future.Which set of actions should the security team implement to accomplish this?Read More →

What is the first step the security engineer should take?

2026-03-28
By: study aws cloud
In: SCS-C01
With: 2 Comments

A security engineer received an Amazon GuardDuty alert indicating a finding involving the Amazon EC2 instance that hosts the company’s primary website.TheGuardDuty finding received read:UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration.The security engineer confirmed that a malicious actor used API access keys intended for the EC2 instance from a country where the company does not operate.The security engineer needs to deny access to the malicious actor.What is the first step the security engineer should take?Read More →

Which strategies will reduce the attack surface and enhance the security of the containers?

2026-03-27
By: study aws cloud
In: SCS-C01
With: 2 Comments

Developers in an organization have moved from a standard application deployment to containers.The Security Engineer is tasked with ensuring that containers are secure.Which strategies will reduce the attack surface and enhance the security of the containers? (Choose two.)Read More →

Which design will meet the requirements with MINIMUM effort?

2026-03-27
By: study aws cloud
In: SCS-C01
With: 2 Comments

An application outputs logs to a text file.The logs must be continuously monitored for security incidents.Which design will meet the requirements with MINIMUM effort?Read More →

Which of the following is the LEAST permissive solution that will allow the metrics to be delivered?

2026-03-27
By: study aws cloud
In: SCS-C01
With: 2 Comments

An application has been written that publishes custom metrics to Amazon CloudWatch.Recently, IAM changes have been made on the account and the metrics are no longer being reported.Which of the following is the LEAST permissive solution that will allow the metrics to be delivered?Read More →

Which action should the Engineer take based on this situation?

2026-03-27
By: study aws cloud
In: SCS-C01
With: 2 Comments

A Security Engineer received an AWS Abuse Notice listing EC2 instance IDs that are reportedly abusing other hosts.Which action should the Engineer take based on this situation? (Choose three.)Read More →

Posts pagination

Previous 1 … 7 8 9 … 41 Next

Recent Posts

  • Which AWS service provides protection against DDoS attacks for applications that run in the AWS Cloud?
  • Which option ensures that services are not allowed within the production accounts, yet are allowed in separate development accounts within the LEAST administrative overhead?
  • How can the data engineer set up access to meet these requirements?
  • Which service will allow Active Directory users to mount storage as a drive on their desktops?
  • Which solution will meet these requirements in the MOST operationally efficient way?

Categories

  • CLF-C01
  • CLF-C02
  • DBS-C01
  • DOP-C01
  • DOP-C02
  • DVA-C01
  • DVA-C02
  • MLS-C01
  • SAA-C02
  • SAA-C03
  • SAP-C01
  • SAP-C02
  • SCS-C01
  • SOA-C01
  • SOA-C02

© 2026. Tip2Cloud doesn't offer any real exam questions. All questions & answers were supported by AI.