Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A security engineer needs to ensure that an EC2 instance can only be accessed using SSH key pairs, not passwords. Which configuration is required?

⚠ Common exam trap

A common mix-up: candidates confuse network-level controls (security groups) or IAM permissions with OS-level authentication settings, assuming AWS services can enforce SSH password policies when only the instance's SSH daemon configuration can do so.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set 'PasswordAuthentication no' in /etc/ssh/sshd_config on the EC2 instance

SSH password authentication is controlled by the `PasswordAuthentication` directive in `/etc/ssh/sshd_config`. Setting it to `no` disables password-based logins, forcing users to authenticate using SSH key pairs (public-key cryptography). This is the standard, OS-level method to enforce key-only SSH access on an EC2 instance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use EC2 Instance Connect instead of SSH

    Why it's wrong here

    EC2 Instance Connect replaces the user's manual SSH key handling by generating a temporary key and pushing it to the instance through a service, but it does not modify the sshd configuration or disable password-based authentication. If PasswordAuthentication remains enabled, an attacker could still brute-force or log in with a password, so using EC2 Instance Connect does not 'ensure' key-only access. It is an alternative access mechanism, not a security control that enforces a specific authentication policy on the target instance.

  • ✓

    Set 'PasswordAuthentication no' in /etc/ssh/sshd_config on the EC2 instance

    Why this is correct

    Forcing key-based authentication on an EC2 instance requires disabling password logins at the OpenSSH daemon level by setting 'PasswordAuthentication no' in /etc/ssh/sshd_config and restarting sshd. This directly changes how the SSH server validates users: public key cryptography becomes the only accepted method, and password prompts are no longer offered. Because sshd reads this configuration on startup, the setting takes effect for all SSH connections, making it a true enforcement mechanism rather than a workflow convenience.

  • ✗

    Attach an IAM role to the instance that denies password-based access

    Why it's wrong here

    An IAM role attached to an EC2 instance delivers temporary AWS credentials through the instance metadata service, which govern only AWS API calls such as S3, DynamoDB, or EC2 actions. These credentials are never consulted by the OpenSSH server when processing a login attempt, because SSH authentication occurs locally in the guest OS using /etc/passwd, shadow files, or PAM. A policy that 'denies password-based access' would not translate to sshd; the SSH daemon does not interpret IAM policies and would continue to accept passwords as configured.

  • ✗

    Configure the security group to allow SSH only from specific IP addresses

    Why it's wrong here

    Security groups are stateful VPC-level firewalls that permit or deny traffic based on IP addresses, ports, and protocols, but they cannot inspect the SSH handshake or the authentication payload. Even if SSH traffic is restricted to a trusted source IP, the instance's sshd will still accept any valid password from that IP unless password authentication is explicitly disabled. Thus, this approach narrows the attack surface but does not enforce the requested key-only authentication policy on the EC2 instance itself.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.