// amazon · aws-certified-security-specialty
amazon

// aws certified security - specialty

AWS-CERTIFIED-SECURITY-SPECIALTY

Master the AWS Certified Security - Specialty exam. Our prep covers IAM, encryption, and network security through realistic, scenario-based practice questions.

502
questions
65
in exam
170m
duration
Choose your mode
at a glance

What you get

PDF US$10.00Sub US$10/mopass 750

Free practice questions are available without payment; anyone can start practicing at no cost.

access options

PDF bank or platform subscription?

Two separate purchases: a one-time PDF for AWS Certified Security - Specialty, or a monthly subscription for online practice and simulators across the platform. A subscription does not include the PDF download.

option / 01 · pdf file

Full question bank PDF

US$10.00· one-time
  • Full question bank as a print-ready PDF
  • Lifetime access to this exam only
  • Domain-tagged questions with explanations
  • Separate from online practice — buy once

option / 02 · subscription

All exams · practice & simulator

US$10.00· per month
  • Practice & exam simulator on every bank
  • All current and future exams included
  • Personal analytics and retention tools
  • Cancel anytime — no per-exam upsells
Subscribe for platform access
sample · 1 of 502Shuffle

See what's in the bank.

Network securitymedium

3 votes · last validated recently

A company's on-premises networks are connected to VPCs using an AWS Direct Connect gateway. The company's on-premises application needs to stream data using an existing Amazon Kinesis Data Firehose delivery stream. The company's security policy requires that data be encrypted in transit using a private network.
How should the company meet these requirements?
A
Create a VPC endpoint for Kinesis Data Firehose. Configure the application to connect to the VPC endpoint.
100%
B
Configure an IAM policy to restrict access to Kinesis Data Firehose using a source IP condition. Configure the application to connect to the existing Firehose delivery stream.
0%
C
Create a new TLS certificate in AWS Certificate Manager (ACM). Create a public-facing Network Load Balancer (NLB) and select the newly created TLS certificate. Configure the NLB to forward all traffic to Kinesis Data Firehose. Configure the application to connect to the NLB.
0%
D
Peer the on-premises network with the Kinesis Data Firehose VPC using Direct Connect. Configure the application to connect to the existing Firehose delivery stream.
0%
next →
04 · coverage

Exam domains

Threat modeling and secure design30%
11 q
Identity and access management (IAM)25%
151 q
Monitoring, logging, and security analytics15%
104 q
Network security15%
121 q
Data encryption10%
115 q
community questionsview all →

Questions from the community

Top-voted approved contributions for this exam, reviewed before landing in the bank.

// top community questionsview all →
0.0 · 0 reviews

What candidates say

no reviews yet

related

You may also like

More exams based on your interests.

Loading...

502 questions

PDF US$10.00 one-time·Sub US$10/mo

Practice