Courseiva
Infrastructure Security →hardMultiple Select

SCS-C02 Infrastructure Security Practice Question

Exhibit

Which THREE actions will improve the security of an Amazon EKS cluster?

A security engineer is reviewing the security of an Amazon EKS cluster. The cluster is used to run containerized applications. Which three actions should the engineer take to improve the security of the cluster?

⚠ Common exam trap

Watch out — candidates often confuse using the default VPC as a 'safe' choice because it is pre-configured, but it lacks the isolation and security group controls needed for production workloads, making Option B a common distractor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restrict access to the cluster using AWS IAM authentication for kubectl.

Restricting access to the cluster using AWS IAM authentication for kubectl is correct because it integrates with AWS IAM to manage user and role permissions, ensuring that only authorized principals can interact with the EKS cluster. This replaces the default, less secure static token or certificate-based authentication with a robust, auditable identity federation. By mapping IAM roles to Kubernetes RBAC, you enforce least-privilege access and prevent unauthorized API calls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Restrict access to the cluster using AWS IAM authentication for kubectl.

    Why this is correct

    Restricting kubectl access through AWS IAM authentication is correct because it integrates IAM identities with Kubernetes RBAC, allowing precise mapping of IAM users and roles to cluster permissions. This avoids shared static credentials and ensures that only authenticated AWS principals with an explicit RBAC role can execute kubectl commands against the EKS cluster.

  • ✗

    Use the default VPC for the cluster.

    Why it's wrong here

    Using the default VPC is incorrect because it typically uses public subnets and permissive network ACLs that expose cluster control plane resources unnecessarily. The default VPC also lacks private subnet isolation, encryption patterns, and centralized network control that a well-designed custom VPC provides for production EKS workloads.

  • ✓

    Configure the cluster API server endpoint to be private.

    Why this is correct

    Setting the Kubernetes API server endpoint to private is correct because it removes internet accessibility and restricts all management traffic to within the VPC and peered networks. Combined with the cluster's private endpoint setting, kubectl traffic travels only over the AWS network, significantly reducing exposure to denial-of-service attacks and unauthorized API access.

  • ✗

    Grant the cluster-admin role to all developers.

    Why it's wrong here

    Granting cluster-admin to every developer is wrong because it violates least privilege and grants full control over the entire cluster, including all namespaces, secrets, and RBAC policies. Developers typically require only namespace-scoped permissions, and over-privileged accounts increase the blast radius if credentials are compromised or misused.

  • ✓

    Enable audit logging for the cluster.

    Why this is correct

    Enabling audit logging for the EKS cluster is correct because it sends Kubernetes API activity to CloudWatch Logs, capturing who performed which actions and when. This detective control is essential for monitoring, threat detection, and compliance forensics, and should be paired with alerting on suspicious API calls.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.