SCS-C03 Exam Question 21

A company allows users to download its mobile app onto their phones. The app is MQTT based and connects to AWS IoT Core to subscribe to specific client-related topics. Recently, the company discovered that some malicious attackers have been trying to get a Trojan horse onto legitimate mobile phones. The Trojan horse poses as the authentic application and uses a client ID with injected special characters to gain access to topics outside the client ' s privilege scope.
Which combination of actions should the company take to prevent this threat? (Select TWO.)
  • SCS-C03 Exam Question 22

    A company finds that one of its Amazon EC2 instances suddenly has a high CPU usage. The company does not know whether the EC2 instance is compromised or whether the operating system is performing background cleanup.
    Which combination of steps should a security engineer take before investigating the issue? (Select THREE.)
  • SCS-C03 Exam Question 23

    A company ' s web application is hosted on Amazon EC2 instances running behind an Application Load Balancer (ALB) in an Auto Scaling group. An AWS WAF web ACL is associated with the ALB. AWS CloudTrail is enabled and stores logs in Amazon S3 and Amazon CloudWatch Logs.
    The operations team has observed some EC2 instances reboot at random. After rebooting, all access logs on the instances have been deleted. During an investigation, the operations team found that each reboot happened just after a PHP error occurred on the new-user-creation.php file. The operations team needs to view log information to determine if the company is being attacked.
    Which set of actions will identify the suspect attacker ' s IP address for future occurrences?
  • SCS-C03 Exam Question 24

    AWS Config cannot deliver configuration snapshots to Amazon S3.
    Which TWO actions will remediate this issue?
  • SCS-C03 Exam Question 25

    A security engineer needs to implement AWS IAM Identity Center with an external identity provider (IdP).
    Select and order the correct steps from the following list to meet this requirement. Select each step one time or not at all. (Select and order THREE.)
    . Configure the external IdP as the identity source in IAM Identity Center.
    . Create an IAM role that has a trust policy that specifies the IdP ' s API endpoint.
    . Enable automatic provisioning in IAM Identity Center settings.
    . Enable automatic provisioning in the external IdP.
    . Obtain the SAML metadata from IAM Identity Center.
    . Obtain the SAML metadata from the external IdP.