What this objective tests
SCS-C02 Infrastructure Security — Key Topics
Choose and configure Security Groups, NACLs, AWS WAF, Network Firewall, and PrivateLink to protect workloads, then verify access with Reachability Analyzer and harden EC2 using SSM Session Manager instead of SSH.
- Choosing security groups versus NACLs for stateful subnet and instance-level filtering
- Configuring AWS Network Firewall, WAF rules and Shield Advanced for edge protection
- Using VPC endpoints, PrivateLink and Gateway Endpoints to keep traffic off the internet
- Hardening EC2 access with Systems Manager Session Manager, key pairs and IMDSv2