AWS Certified Security - Specialty
Validates expertise in securing workloads and architectures on AWS. Covers threat detection and incident response, security logging and monitoring, infrastructure security, identity and access management, data protection, and management and security governance. Requires five or more years of IT security experience with at least two years of hands-on AWS security experience, demonstrating proficiency in implementing security controls, managing security operations, and understanding specialized data classifications and AWS data protection mechanisms.
Sample questions
A free preview of 15 source-grounded questions from this exam — answers and explanations included.
- Q1Infrastructure Securitymedium
A platform team is designing edge protection for a public web application and must summarize which AWS resource types AWS WAF web ACLs can attach to, before resource policy authoring begins. Per the AWS WAF Developer Guide, which option matches?
- A.You can protect Amazon CloudFront, Amazon API Gateway, Application Load Balancer, AWS AppSync, Amazon Cognito, AWS App Runner, AWS Amplify, Amazon CloudWatch, and AWS Verified Access resources with AWS WAF web ACLs.Correct answer
- B.AWS WAF web ACLs can attach only to Amazon CloudFront distributions and never to Application Load Balancers, API Gateway, AppSync, Cognito, App Runner, Amplify, or Verified Access resources in any AWS Region of any account.
- C.AWS WAF web ACLs can attach only to Application Load Balancers and never to Amazon CloudFront, API Gateway, AppSync, Cognito, App Runner, Amplify, or Verified Access resources, so non-ALB workloads need a different L7 protection layer entirely.
Sources
Questions are grounded in 150 references from official and authoritative materials.