SCS-C02 Infrastructure Security Practice Question
A company uses AWS Systems Manager Session Manager to provide SSH access to EC2 instances without needing to open inbound ports. The security team wants to ensure that all session activity is logged and that only authorized users can start sessions. Which combination of actions should be taken? (Choose TWO.)
⚠ Common exam trap
Candidates may think that VPC Flow Logs or security groups are needed for Session Manager, but Session Manager is designed to avoid inbound ports and uses IAM and CloudTrail for access control and logging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable AWS CloudTrail to log StartSession API calls.
Option B is correct because Session Manager records session activity through the StartSession API, and enabling AWS CloudTrail captures those API calls for auditing who started sessions and when. Option D is correct because IAM policies scoping the ssm:StartSession action to specific users or roles enforce authorization, ensuring only approved principals can initiate sessions. Option A is incorrect because Session Manager does not rely on SSH key pairs; it uses the SSM Agent and IAM credentials, so requiring SSH keys does not meet the logging or authorization goal. Option C is incorrect because VPC Flow Logs capture IP traffic metadata, not the session-level activity or API authorization events the team needs. Option E is incorrect because Session Manager is designed to avoid inbound ports and security groups restricting inbound traffic to Session Manager endpoints is neither required nor how access control is enforced.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the EC2 instances to require SSH key pairs for authentication.
Why it's wrong here
Requiring SSH key pairs is ineffective for Session Manager because the SSM agent authenticates to AWS using IAM credentials, not SSH keys. Even if you enable SSH tunneling through Session Manager, the keys only protect the tunneled connection, not the StartSession API call itself, so they provide no audit trail of session initiation.
- ✓
Enable AWS CloudTrail to log StartSession API calls.
Why this is correct
CloudTrail is the correct choice because it records StartSession API calls as management events, capturing the IAM principal, source IP, and timestamp of each session request. This gives you a detective control to answer who initiated a session and when, which is essential for security auditing and alerting on unusual activity.
- ✗
Enable VPC Flow Logs to monitor network traffic.
Why it's wrong here
VPC Flow Logs are unrelated to API-level session auditing; they capture network traffic metadata such as source/destination IPs, ports, and packet counts at the VPC or subnet level. Session Manager traffic over VPC endpoints would only show connection-level details, not the user identity or the fact that a session was started via the SSM API.
- ✓
Create IAM policies that allow the ssm:StartSession action only for specific users or roles.
Why this is correct
Creating IAM policies that allow ssm:StartSession only for specific users or roles is a critical preventive control. You can further scope with conditions like ssm:resourceTag to limit which instances a user can access, and combine with aws:PrincipalTag for fine-grained access, but this alone does not log session activity; it must be paired with CloudTrail or session data logging for a complete audit trail.
- ✗
Use security groups to restrict inbound traffic to the Session Manager endpoints.
Why it's wrong here
Security groups do not govern Session Manager authorization because the SSM agent initiates an outbound-TLS connection to AWS, and inbound rules on the instance are not consulted for user access. Even when using VPC endpoints for Session Manager, access is controlled by IAM policies and VPC endpoint policies, not by the instance's security group, which only filters network traffic to the instance.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.