☎  076 959 6407✉  support@quizcrazepro.co.za
Learn. Practice. Build your future.
BlogHelpContact
aws

AWS Certified Security - Specialty SCS-C03 Actual Exam Questions

19 Questions120 Minutes70% Passing Score▣ Updated: Sep 2026

Question 10 of 19

Single answer
CertylQ A security engineer is responding to an incident that is affecting an AWS account.The ID of the account is 1234156789012.The attack created workloads that are distributed across multiple AWS Regions. all affected Regions. However, the attacker also created an AWS KMS key. The key policy on the KMS key explicitly allows IAM principal kms:* permissions. The key was scheduled to be deleted the previous day. However, the key is still enabled and usable.The key has an ARN of arn:aws;kms:us-east-2:123456789012:key/mrk-0bb0212cd9864fdea0dcamzo26efb5670. The security engineer must delete the key as quickly as possible. Which solution will meet this requirement?
ALog in to the account by using the account root user credentials. Re-issue the deletion request for the KMS key with a waiting period of 7 days.
BIdentify the other Regions where the KMS key ID is present and schedule the key for deletion in 7 days. the KMS key with a waiting period of 7 days.
DDisable the KMS key. Re-issue the deletion request for the KMS key in 30 days.
Correct Answer: B

Identify the other Regions where the KMS key ID is present and schedule the key for deletion in 7 days. the KMS key with a waiting period of 7 days.

Explanation

The correct answer is highlighted above. Review the wording carefully, then use the next question to continue building your understanding of AWS certification topics.

About this practice exam

Review 19 AWS questions with answers and explanations. Use the navigation to move through the exam at your own pace.