AmazonAmazon Security Specialty SCS-C02 ·EN ·Updated 24 Jul 2026

A company runs long-running analytics on data stored in Amazon S3. The jobs run on Amazon EC2 instances in a private subnet with no internet access, using an Auto Scaling group. The EC2 instances and S3 buckets are in the same AWS account and use an S3 gateway VPC endpoint with the default policy. Each instance’s profile role explicitly allows s3:GetObject and s3:PutObject only for the required S3 buckets. The company discovers that one or more instances are compromised and are exfiltrating data to an S3 bucket outside the company’s AWS Organizations organization. A security engineer must stop the exfiltration while keeping the processing jobs operational. Which solution will meet these requirements?

Choose an answer

Tap an option to check your answer.

Pass your exam — without the endless answer hunt

Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.

Pass your exam faster No card needed
✓ Verified by ExamRoll editorial · Updated 24 July 2026 · Source: official academy
All-in-one access

One subscription. Every exam.

Every plan unlocks unlimited answer search, practice tests, AI explanations, and the full resource library — in 20+ languages.

Monthly
24.87
Just €0.83/day
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

Best value
12 months
179.87
Just €0.49/daySave 40%
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

✓ Free plan included · ✓ Cancel anytime · ✓ All plans unlock the full product