A company is using Amazon Route 53 Resolver for its hybrid DNS infrastructure. The company has set up Route 53 Resolver forwarding rules for authoritative domains that are hosted on on-premises DNS servers.A new security mandate requires the company to implement a solution to log and query DNS traffic that goes to the on-premises DNS servers. The logs must show details of the source IP address of the instance from which the query originated. The logs also must show the DNS name that was requested in Route 53 Resolver.Which solution will meet these requirements?
Answer(s): C
A security engineer is configuring account-based access control (ABAC) to allow only specific principals to put objects into an Amazon S3 bucket. The principals already have access to Amazon S3.The security engineer needs to configure a bucket policy that allows principals to put objects into the S3 bucket only if the value of the Team tag on the object matches the value of the Team tag that is associated with the principal. During testing, the security engineer notices that a principal can still put objects into the S3 bucket when the tag values do not match.Which combination of factors are causing the PutObject operation to succeed when the tag values are different? (Choose two.)
Answer(s): A,C
A company is hosting multiple applications within a single VPC in its AWS account. The applications are running behind an Application Load Balancer that is associated with an AWS WAF web ACL. The company's security team has identified that multiple port scans are originating from a specific range of IP addresses on the internet.A security engineer needs to deny access from the offending IP addresses.Which solution will meet these requirements?
Answer(s): A
A company has contracted with a third party to audit several AWS accounts. To enable the audit, cross-account IAM roles have been created in each account targeted for audit. The auditor is having trouble accessing some of the accounts.Which of the following may be causing this problem? (Choose three.)
Answer(s): A,C,F
Post your Comments and Discuss Amazon SCS-C02 exam with other Community members:
Mohammed Haque Commented on March 03, 2025 very useful site for exam prep UNITED STATES
Kevin Commented on January 03, 2025 Yo, just copped the full SCS-C02 material, and bro, it’s a lifesaver! AWS security is no joke, but this makes it way easier to get. If you’re tryna pass, don’t sleep on this, cuz it’s solid! UNITED STATES
Mosawar Commented on January 03, 2025 Passed this exam. Valid exam dumps. EUROPEAN UNION
Ahmad Commented on January 03, 2025 This test is hard. But questions in premium version is good and valid. Has screenshots from real exam scenarios. UNITED ARAB EMIRATES
Our website is free, but we have to fight against bots and content theft. We're sorry for the inconvenience caused by these security measures. You can access the rest of the SCS-C02 content, but please register or login to continue.