Courseiva
Infrastructure Security →easyMultiple Select

SCS-C02 Infrastructure Security Practice Question

A company uses AWS Systems Manager Session Manager to provide SSH access to EC2 instances without needing to open inbound ports. The security team wants to ensure that all session activity is logged and that only authorized users can start sessions. Which combination of actions should be taken? (Choose TWO.)

⚠ Common exam trap

Candidates may think that VPC Flow Logs or security groups are needed for Session Manager, but Session Manager is designed to avoid inbound ports and uses IAM and CloudTrail for access control and logging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable AWS CloudTrail to log StartSession API calls.

Option B is correct because Session Manager records session activity through the StartSession API, and enabling AWS CloudTrail captures those API calls for auditing who started sessions and when. Option D is correct because IAM policies scoping the ssm:StartSession action to specific users or roles enforce authorization, ensuring only approved principals can initiate sessions. Option A is incorrect because Session Manager does not rely on SSH key pairs; it uses the SSM Agent and IAM credentials, so requiring SSH keys does not meet the logging or authorization goal. Option C is incorrect because VPC Flow Logs capture IP traffic metadata, not the session-level activity or API authorization events the team needs. Option E is incorrect because Session Manager is designed to avoid inbound ports and security groups restricting inbound traffic to Session Manager endpoints is neither required nor how access control is enforced.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the EC2 instances to require SSH key pairs for authentication.

    Why it's wrong here

    Requiring SSH key pairs is ineffective for Session Manager because the SSM agent authenticates to AWS using IAM credentials, not SSH keys. Even if you enable SSH tunneling through Session Manager, the keys only protect the tunneled connection, not the StartSession API call itself, so they provide no audit trail of session initiation.

  • ✓

    Enable AWS CloudTrail to log StartSession API calls.

    Why this is correct

    CloudTrail is the correct choice because it records StartSession API calls as management events, capturing the IAM principal, source IP, and timestamp of each session request. This gives you a detective control to answer who initiated a session and when, which is essential for security auditing and alerting on unusual activity.

  • ✗

    Enable VPC Flow Logs to monitor network traffic.

    Why it's wrong here

    VPC Flow Logs are unrelated to API-level session auditing; they capture network traffic metadata such as source/destination IPs, ports, and packet counts at the VPC or subnet level. Session Manager traffic over VPC endpoints would only show connection-level details, not the user identity or the fact that a session was started via the SSM API.

  • ✓

    Create IAM policies that allow the ssm:StartSession action only for specific users or roles.

    Why this is correct

    Creating IAM policies that allow ssm:StartSession only for specific users or roles is a critical preventive control. You can further scope with conditions like ssm:resourceTag to limit which instances a user can access, and combine with aws:PrincipalTag for fine-grained access, but this alone does not log session activity; it must be paired with CloudTrail or session data logging for a complete audit trail.

  • ✗

    Use security groups to restrict inbound traffic to the Session Manager endpoints.

    Why it's wrong here

    Security groups do not govern Session Manager authorization because the SSM agent initiates an outbound-TLS connection to AWS, and inbound rules on the instance are not consulted for user access. Even when using VPC endpoints for Session Manager, access is controlled by IAM policies and VPC endpoint policies, not by the instance's security group, which only filters network traffic to the instance.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.