SCS-C02 Infrastructure Security Practice Question
Exhibit
Which THREE actions will improve the security of an Amazon EKS cluster?
A security engineer is reviewing the security of an Amazon EKS cluster. The cluster is used to run containerized applications. Which three actions should the engineer take to improve the security of the cluster?
⚠ Common exam trap
Watch out — candidates often confuse using the default VPC as a 'safe' choice because it is pre-configured, but it lacks the isolation and security group controls needed for production workloads, making Option B a common distractor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restrict access to the cluster using AWS IAM authentication for kubectl.
Restricting access to the cluster using AWS IAM authentication for kubectl is correct because it integrates with AWS IAM to manage user and role permissions, ensuring that only authorized principals can interact with the EKS cluster. This replaces the default, less secure static token or certificate-based authentication with a robust, auditable identity federation. By mapping IAM roles to Kubernetes RBAC, you enforce least-privilege access and prevent unauthorized API calls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Restrict access to the cluster using AWS IAM authentication for kubectl.
Why this is correct
Restricting kubectl access through AWS IAM authentication is correct because it integrates IAM identities with Kubernetes RBAC, allowing precise mapping of IAM users and roles to cluster permissions. This avoids shared static credentials and ensures that only authenticated AWS principals with an explicit RBAC role can execute kubectl commands against the EKS cluster.
- ✗
Use the default VPC for the cluster.
Why it's wrong here
Using the default VPC is incorrect because it typically uses public subnets and permissive network ACLs that expose cluster control plane resources unnecessarily. The default VPC also lacks private subnet isolation, encryption patterns, and centralized network control that a well-designed custom VPC provides for production EKS workloads.
- ✓
Configure the cluster API server endpoint to be private.
Why this is correct
Setting the Kubernetes API server endpoint to private is correct because it removes internet accessibility and restricts all management traffic to within the VPC and peered networks. Combined with the cluster's private endpoint setting, kubectl traffic travels only over the AWS network, significantly reducing exposure to denial-of-service attacks and unauthorized API access.
- ✗
Grant the cluster-admin role to all developers.
Why it's wrong here
Granting cluster-admin to every developer is wrong because it violates least privilege and grants full control over the entire cluster, including all namespaces, secrets, and RBAC policies. Developers typically require only namespace-scoped permissions, and over-privileged accounts increase the blast radius if credentials are compromised or misused.
- ✓
Enable audit logging for the cluster.
Why this is correct
Enabling audit logging for the EKS cluster is correct because it sends Kubernetes API activity to CloudWatch Logs, capturing who performed which actions and when. This detective control is essential for monitoring, threat detection, and compliance forensics, and should be paired with alerting on suspicious API calls.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.