SCS-C02 Threat Detection and Incident Response Practice Question
A company uses Amazon GuardDuty to monitor its AWS environment. The security team has received a GuardDuty finding of type 'Recon:EC2/PortProbeUnprotectedPort'. The finding indicates that an EC2 instance has an open SSH port that is being probed from the internet. The team wants to reduce the attack surface and prevent future probes. Which THREE actions should the team take? (Choose THREE.)
⚠ Common exam trap
Many candidates think suppressing the finding (Option A) is a valid remediation step, but AWS explicitly distinguishes between 'suppression' (hiding alerts) and 'remediation' (fixing the root cause), and the question asks for actions to 'prevent future probes,' not just reduce alert noise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the security group to allow SSH only from specific IP addresses.
Modifying the security group to allow SSH only from specific IP addresses directly restricts inbound traffic to trusted sources, eliminating the open exposure that triggers the GuardDuty 'Recon:EC2/PortProbeUnprotectedPort' finding. This is a fundamental network access control that reduces the attack surface by applying the principle of least privilege at the security group level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Suppress the GuardDuty finding to reduce noise.
Why it's wrong here
Suppressing the GuardDuty finding only removes it from the console and may delay response; it does not remediate the exposed SSH port or any active compromise. GuardDuty findings are intended to trigger investigation and corrective action, so using suppression here would let an attacker maintain access and could allow the finding to recur as continuing activity. Suppression is appropriate only for confirmed false positives or known benign behavior, not as a substitute for security hardening.
- ✓
Modify the security group to allow SSH only from specific IP addresses.
Why this is correct
Restricting the security group source to a specific IP CIDR for port 22 ensures that only authorized administrative workstations can open SSH connections, while all other public access is denied at the network layer. This directly reduces the attack surface because the instance is no longer reachable from the entire internet, and it also preserves the existing instance, its data, and its DNS name. This is a minimal, reversible change that addresses the identified risk without disrupting running workloads.
- ✗
Terminate the EC2 instance and launch a new one.
Why it's wrong here
Terminating the EC2 instance and launching a replacement is unnecessarily disruptive because the underlying issue is a permissive security group rule, not a hardware or OS fault that requires re-provisioning. A replacement would lose the instance's persistent data unless snapshots are taken first, and it would still require the same security group correction to avoid repeating the exposure. The instance should be secured in place by tightening the security group or switching to Session Manager, which is faster and avoids unintended availability and data-loss risks.
- ✓
Move the instance to a private subnet and use a NAT gateway for outbound internet access.
Why this is correct
Moving the instance to a private subnet and routing outbound traffic through a NAT gateway removes its public IP address and makes it unreachable from the internet for SSH, while still allowing it to fetch patches and updates. However, this alone does not provide an inbound management path, so administrators would need a bastion host, a VPN, or AWS Systems Manager Session Manager to access the instance. This is a network-level isolation measure that reduces exposure, but it should be paired with an appropriate secure access mechanism.
- ✓
Use AWS Systems Manager Session Manager to access the instance instead of SSH.
Why this is correct
Using AWS Systems Manager Session Manager for administrative access eliminates the need for port 22 to be open at all, because sessions are established through the SSM agent over an HTTPS connection to the AWS control plane, not via a public-facing SSH listener. With Session Manager, you can remove the permissive SSH ingress rule entirely, and access is controlled by IAM policies, with optional session logging and VPC endpoints for private connectivity. This is the most direct way to remove the exposed SSH attack vector while maintaining full administrative capability.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.