Courseiva

CCNA Infrastructure Security Questions

75 of 245 questions · Page 3/4 · Infrastructure Security · Answers revealed

151
MCQeasy

A company has a security group rule that allows inbound traffic from 0.0.0.0/0 on port 22. The security engineer wants to restrict SSH access to only the company's public IP range (203.0.113.0/24). What is the correct way to update the security group rule?

A.Remove the existing inbound rule and do not add any new rule; SSH access will be denied by default.
B.Modify the existing inbound rule to change the source from 0.0.0.0/0 to 203.0.113.0/24.
C.Add a new inbound rule with source 203.0.113.0/24 and the security group will automatically deny all other traffic.
D.Change the outbound rules to restrict traffic.
AnswerB

Modifying the existing rule's source CIDR from 0.0.0.0/0 to 203.0.113.0/24 is the minimal, precise change: the rule continues to allow TCP/22 only from the company's IP range. Security group rules are stateful and evaluated as a union, so editing the existing rule ensures no separate overly permissive rule remains. This directly satisfies the requirement to allow SSH only from the company IP while preserving connectivity for authorized administrators.

Why this answer

Option B is correct because modifying the existing inbound rule to change the source from 0.0.0.0/0 to 203.0.113.0/24 directly restricts SSH access to the company's public IP range. Security groups are stateful and allow you to edit rules in place, so this is the simplest and most accurate method.

Exam trap

The trap here is assuming that adding a new rule with a narrower CIDR will override the existing broader rule, but security groups are allow-only and all rules are evaluated together, so the broader rule must be removed or modified.

How to eliminate wrong answers

Option A is wrong because removing the rule without adding a new one would block all SSH access, not just restrict it to the company's range. Option C is wrong because adding a new rule does not automatically deny other traffic; security groups are allow-only, so the existing 0.0.0.0/0 rule would still permit all SSH access. Option D is wrong because outbound rules control outbound traffic, not inbound SSH access; changing outbound rules would not restrict inbound SSH.

152
MCQmedium

A company is using AWS CloudTrail to monitor API activity in their account. They have enabled CloudTrail in all regions and are logging to an S3 bucket. The security team wants to ensure that log files are not tampered with after delivery. They enable CloudTrail log file integrity validation. Which additional step must be taken to verify the integrity of the log files?

A.Enable S3 versioning on the log bucket.
B.Configure the S3 bucket to use server-side encryption with AWS KMS.
C.Enable S3 Object Lock on the log bucket.
D.Use the AWS CLI to run the validate-logs command against the log files.
AnswerD

Run the AWS CLI command `aws cloudtrail validate-logs --trail-arn ... --start-time ... --end-time ...` to validate CloudTrail log file integrity. The command downloads the signed digest files, verifies their digital signatures using CloudTrail's public key, and then compares the SHA-256 hash of each log file against the hash recorded in the digest, detecting any modification, deletion, or insertion. This is the only option that cryptographically verifies log integrity and is purpose-built for exactly this scenario.

Why this answer

CloudTrail log file integrity validation uses digital signatures (SHA-256 hashing and signing with a private key). To verify integrity, you must use the AWS CLI command 'aws cloudtrail validate-logs' or download the public key and verify manually. Option A (enable S3 versioning) helps protect against accidental deletion or overwriting but does not verify integrity.

Option B (use KMS to encrypt logs) protects confidentiality only. Option C (use S3 Object Lock) prevents deletion or modification but does not provide tamper detection or integrity verification.

153
MCQmedium

A company is using Amazon EC2 instances in a VPC with a security group that allows inbound SSH from 0.0.0.0/0. A security engineer needs to restrict SSH access to only the company's public IP range (203.0.113.0/24) while maintaining all other existing rules. What is the MOST efficient way to accomplish this?

A.Disable SSH and use AWS Systems Manager Session Manager to connect to instances.
B.Create a network ACL with an inbound rule allowing SSH from 203.0.113.0/24 and deny all other traffic.
C.Modify the existing security group rule to change the source from 0.0.0.0/0 to 203.0.113.0/24.
D.Create a new security group rule allowing SSH from 203.0.113.0/24 and keep the existing rule.
AnswerC

Modifying the existing rule is the correct action because security group inbound rules are evaluated as an allow list, and changing the source to 203.0.113.0/24 removes the wildcard entry while authorizing only the specified IP range. The update is an in-place edit, so no duplicate rule remains and the stateful security group automatically permits the return traffic for established SSH sessions. The existing rule should be changed rather than appended because any remaining 0.0.0.0/0 rule would continue to allow all source IPs.

Why this answer

Modifying the existing security group rule's source from 0.0.0.0/0 to 203.0.113.0/24 directly restricts inbound SSH to the company's public IP range without affecting any other rules. Security groups are stateful and rule changes apply immediately, making this the most efficient approach as it requires only a single edit to the existing rule.

Exam trap

The trap here is that candidates may think adding a more specific allow rule overrides a broader allow rule, but security groups use an allow-list model where all rules are additive, so the original 0.0.0.0/0 rule must be removed or modified to actually restrict access.

How to eliminate wrong answers

Option A is wrong because disabling SSH and using AWS Systems Manager Session Manager is an alternative solution, not the most efficient way to restrict SSH access while maintaining existing rules; it changes the access method entirely and may not meet the requirement to restrict SSH specifically. Option B is wrong because network ACLs are stateless and operate at the subnet level, not the instance level; modifying a network ACL would affect all instances in the subnet and require separate inbound and outbound rules for return traffic, making it less efficient and not a direct replacement for a security group rule. Option D is wrong because adding a new security group rule allowing SSH from 203.0.113.0/24 while keeping the existing rule with 0.0.0.0/0 would still allow SSH from all IPs, as security group rules are evaluated as a logical OR; the existing permissive rule would remain in effect, failing to restrict access.

154
MCQmedium

A security engineer is designing a web application that will run on EC2 instances behind an Application Load Balancer (ALB). The application must be protected from common web exploits like SQL injection and cross-site scripting. Which AWS service should be used to provide this protection?

A.AWS WAF
B.Network ACLs
C.Security Groups
D.AWS Shield Advanced
AnswerA

AWS WAF integrates directly with the Application Load Balancer, inspecting HTTP requests against rule groups that block SQL injection and cross-site scripting patterns before traffic reaches the EC2 instances. This satisfies the stem's requirement for protection from common web exploits at the ALB layer, filtering malicious payloads inline.

Why this answer

AWS WAF is a Layer 7 web application firewall that inspects HTTP/HTTPS requests and can block common exploits like SQL injection and cross-site scripting using managed rule groups (e.g., AWSManagedRulesCommonRuleSet, SQLiRuleSet, XSSRuleSet). It integrates natively with ALB, CloudFront, and API Gateway, making it the correct choice for protecting an ALB-fronted web app.

Exam trap

The trap is confusing DDoS protection (Shield) or network-layer filtering (NACLs, Security Groups) with application-layer exploit protection (WAF); only WAF inspects HTTP payloads.

How to eliminate wrong answers

Option B is wrong because Network ACLs are stateless Layer 3/4 filters that only allow or deny based on IP, port, and protocol — they cannot inspect HTTP payloads for SQLi or XSS patterns. Option C is wrong because Security Groups are stateful Layer 3/4 firewalls attached to ENIs; they control which ports and IPs can reach the instance but have no application-layer inspection capability. Option D is wrong because AWS Shield Advanced provides DDoS protection (Layer 3/4 and some Layer 7 volumetric mitigation) but does not perform signature-based inspection for SQLi or XSS.

155
MCQeasy

A company has a VPC with public and private subnets. The private subnets need to access the internet for software updates. Which component should be added to the VPC to enable this?

A.Internet gateway
B.VPN connection
C.VPC peering connection
D.NAT gateway
AnswerD

A NAT gateway sits in the public subnet with an Elastic IP and performs source NAT, letting private-subnet instances initiate outbound internet traffic for updates while blocking unsolicited inbound connections. This satisfies the requirement to give private subnets internet access without exposing them.

Why this answer

A NAT gateway allows instances in private subnets to initiate outbound internet traffic while preventing inbound traffic from the internet. It is placed in a public subnet and uses an Elastic IP, and private subnet route tables point to it for 0.0.0.0/0.

Exam trap

The trap is confusing NAT gateway with internet gateway; candidates may think private subnets can use an internet gateway directly, but that would require them to be public and have public IPs.

How to eliminate wrong answers

Option A is wrong because an internet gateway enables bidirectional internet access for public subnets; private subnets cannot use it directly without becoming public. Option B is wrong because a VPN connection connects to on-premises networks, not the internet. Option C is wrong because VPC peering connects two VPCs, not to the internet.

156
MCQmedium

A company uses AWS Direct Connect to connect its on-premises data center to AWS. The company has a VPC with public and private subnets. The security team wants to ensure that all traffic between on-premises and the VPC goes through a set of security appliances (firewalls) deployed in the VPC. The appliances are in separate subnets. Currently, traffic is routed directly via the virtual private gateway. What is the MOST secure and scalable way to force traffic through the security appliances?

A.Place the security appliances in a public subnet and route traffic through a NAT gateway.
B.Create a transit gateway and attach the Direct Connect virtual interface to it. Then route traffic through the appliance subnets.
C.Deploy a Gateway Load Balancer and create Gateway Load Balancer endpoints in each subnet. Update the route tables to point to the endpoints.
D.Set up a VPN connection from on-premises to the VPC and route traffic through the appliance subnets.
AnswerC

A Gateway Load Balancer (GWLB) transparently intercepts traffic using Gateway Load Balancer endpoints, which are VPC endpoints that can be designated as route-table targets. After you deploy the GWLB in one VPC and the security appliances in target groups, you create endpoints in each subnet and update those subnets' route tables to point the Direct Connect prefix or default route to the endpoints. The GWLB then encapsulates traffic using the GENEVE protocol and distributes flows across the appliance fleet, enabling scaling, health checks, and automatic failover while keeping the appliances transparent to the source and destination. This is the standard pattern for inserting a horizontal fleet of third-party security appliances inline for inspection of Direct Connect traffic.

Why this answer

Using a Gateway Load Balancer with Gateway Load Balancer endpoints in each subnet allows transparent traffic inspection and scaling. Option A is wrong because a NAT gateway only handles outbound traffic, not bidirectional inspection. Option B is wrong because a transit gateway does not force traffic through appliances; additional routing and appliance VPCs are needed.

Option D is wrong because a VPN connection does not inherently route through VPC appliances; it would require custom routing.

157
MCQhard

A security engineer notices that an EC2 instance in a private subnet can reach the internet, even though there is no NAT gateway or instance in the route table. What is the most likely cause?

A.An internet gateway is attached to the VPC and a default route points to it.
B.A VPC endpoint for S3 is configured.
C.A NAT gateway is configured in a different availability zone.
D.An egress-only internet gateway is used for IPv6 traffic.
AnswerD

An egress-only internet gateway (EIGW) is a special gateway that enables outbound IPv6 connectivity from a VPC to the internet while blocking any inbound IPv6 traffic. It is the IPv6 counterpart to a NAT gateway, designed for private subnets that need to initiate internet requests without being connetionally reachable. The presence of a route for ::/0 pointing to the EIGW in the private subnet's route table exactly produces the observed outbound-only behavior.

Why this answer

An egress-only internet gateway (EIGW) allows outbound-only IPv6 traffic from instances in a private subnet to the internet, but it does not permit inbound connections initiated from the internet. Since the question states there is no NAT gateway or instance, and the instance can reach the internet, the most likely cause is that the VPC uses IPv6 and an EIGW is configured with a default route (::/0) pointing to it. This enables outbound internet access without a NAT device, matching the described scenario.

Exam trap

The trap here is that candidates often assume internet access from a private subnet always requires a NAT gateway or instance, overlooking the fact that egress-only internet gateways provide outbound-only IPv6 internet access without any NAT device.

How to eliminate wrong answers

Option A is wrong because an internet gateway (IGW) attached to a VPC with a default route (0.0.0.0/0) pointing to it would provide internet access only to instances in public subnets (those with a route to the IGW and a public IP), not to instances in a private subnet. Option B is wrong because a VPC endpoint for S3 provides private connectivity to S3 only, not general internet access. Option C is wrong because a NAT gateway configured in a different availability zone would still appear in the route table of the private subnet’s route table (as a default route pointing to the NAT gateway ID) to provide internet access; the question explicitly states there is no NAT gateway or instance in the route table, so this cannot be the cause.

158
MCQeasy

A security engineer is configuring a new VPC with public and private subnets. The application servers in the private subnet need to download patches from the internet. Which component is required?

A.VPC endpoint
B.Direct Connect
C.Internet gateway
D.NAT gateway
AnswerD

A NAT gateway is a managed AWS service that enables instances in a private subnet to initiate outbound connections to the internet (e.g., for software updates or API calls) while preventing unsolicited inbound connections. It is deployed in a public subnet with an Elastic IP address, and the private subnet's route table sends non-local traffic to the NAT gateway's network interface. This exactly matches the requirement to provide outbound internet access for private subnet instances without exposing them to inbound traffic.

Why this answer

A NAT gateway is required to allow instances in a private subnet to initiate outbound traffic to the internet (e.g., to download patches) while preventing the internet from initiating inbound connections to those instances. The NAT gateway resides in a public subnet with an attached Internet Gateway, and it translates the private IP addresses of the application servers to the NAT gateway's Elastic IP address for outbound traffic.

Exam trap

The trap here is that candidates often confuse a NAT gateway with an Internet Gateway, mistakenly thinking an Internet Gateway can be attached directly to a private subnet, but an Internet Gateway only works with resources that have public IP addresses, whereas a NAT gateway enables outbound internet access for private instances without public IPs.

How to eliminate wrong answers

Option A is wrong because a VPC endpoint (e.g., Gateway or Interface endpoint) provides private connectivity to AWS services (like S3 or DynamoDB) without traversing the internet, but it does not provide general internet access for downloading patches from arbitrary internet hosts. Option B is wrong because Direct Connect establishes a dedicated private network connection from on-premises to AWS, but it does not inherently provide internet access; it would require additional routing and an internet gateway to reach the public internet. Option C is wrong because an Internet Gateway alone enables bidirectional communication between the VPC and the internet, but it cannot be directly attached to a private subnet; instances in a private subnet without a public IP cannot use an Internet Gateway for outbound-only traffic.

159
MCQhard

A company runs a multi-tier web application on AWS. The web tier uses an Application Load Balancer (ALB) in a public subnet, and the application tier runs on EC2 instances in private subnets. The security team recently ran a vulnerability scan and found that the application instances are accessible from the internet on port 8080. The EC2 instances have a security group that allows inbound traffic on port 8080 from the ALB's security group only. However, the ALB's security group allows inbound traffic on port 8080 from 0.0.0.0/0. The architecture also includes a NAT Gateway for outbound internet access from private subnets. The security engineer needs to ensure that only the ALB can communicate with the application instances on port 8080, and that the application instances cannot be directly accessed from the internet. What should the security engineer do?

A.Change the EC2 instance security group to allow inbound traffic on port 8080 from 0.0.0.0/0, and rely on the subnet network ACL to block traffic.
B.Add a rule to the EC2 security group that denies inbound traffic from 0.0.0.0/0 on port 8080.
C.Modify the ALB security group to remove the inbound rule for port 8080 from 0.0.0.0/0, and configure the ALB listener to forward traffic from port 80/443 to port 8080 on the target group.
D.Place the EC2 instances in a public subnet and use a network ACL to block inbound traffic on port 8080 from the internet.
AnswerC

This is the correct solution because it eliminates the unintended public exposure of port 8080 while still enabling the ALB to forward client traffic to the instances on that port. The ALB security group should only permit inbound HTTP/HTTPS on ports 80 and 443, and the ALB listener should be configured with a forward action to the target group on port 8080. Instance security groups should then independently restrict port 8080 to only accept traffic from the ALB security group, preserving a defense-in-depth architecture where instances are not directly internet-reachable.

Why this answer

The ALB security group should only allow inbound traffic on the listener ports (80/443) from the internet, not port 8080. The ALB listener then forwards to the target group on port 8080, and the EC2 security group already restricts 8080 to the ALB's security group. Removing the 0.0.0.0/0 rule on 8080 from the ALB SG closes the exposure while preserving the ALB-to-instance path.

Exam trap

SCS-C02 often tests the misconception that security groups support deny rules or that NACLs can substitute for SG least privilege — candidates must remember SGs are allow-only and that the fix is removing the overly permissive inbound rule, not adding a deny.

How to eliminate wrong answers

Option A is wrong because opening 8080 to 0.0.0.0/0 on the instances and relying on NACLs inverts the security model and exposes instances directly. Option B is wrong because security groups are allow-only — you cannot create explicit deny rules, so a 'deny 0.0.0.0/0' rule is not possible. Option D is wrong because moving instances to a public subnet increases exposure and NACLs are stateless and coarse, not a substitute for SG-based least privilege.

160
MCQmedium

A company has an AWS Lambda function that needs to access an Amazon RDS database. The database is in a private subnet. Which configuration will allow the Lambda function to securely access the database without traversing the internet?

A.Create a VPC peering connection between the Lambda VPC and the RDS VPC.
B.Place the Lambda function in a public subnet and use a NAT gateway to access the RDS database.
C.Configure the Lambda function to run in the same VPC as the RDS database, in the same private subnet.
D.Use a VPC endpoint for Lambda to connect to the RDS database.
AnswerC

Attaching the Lambda function to the VPC and placing it in the same private subnet as the RDS instance allows the function's elastic network interface to communicate directly with the database over private IP addresses. This satisfies the security group rules—Lambda can use its own security group to allow inbound traffic to RDS on the database port. There is no need for internet access or NAT, and the connection remains within the private network. This is the recommended AWS pattern for Lambda plus RDS in the same VPC.

Why this answer

Placing the Lambda function in the same VPC and the same private subnet as the RDS database allows the Lambda function to communicate with the database directly over the AWS network using private IP addresses. This configuration ensures traffic does not traverse the internet, and it leverages VPC routing and security groups for access control. Lambda functions must be configured with VPC settings to access resources in private subnets, and when both are in the same subnet, no additional gateways or peering are required.

Exam trap

The trap here is that candidates often assume Lambda functions always run inside a VPC by default, but in reality, Lambda runs in an AWS-managed VPC unless explicitly configured with VPC settings, and they mistakenly think VPC endpoints can be used for any AWS service, including RDS, when in fact RDS does not support VPC interface endpoints for database connections.

How to eliminate wrong answers

Option A is wrong because VPC peering connects two separate VPCs, but Lambda functions run within a VPC only when explicitly configured; the default Lambda execution environment is outside any VPC, so peering does not apply unless the Lambda is already in a VPC. Option B is wrong because placing the Lambda function in a public subnet and using a NAT gateway would still route traffic through the internet (via the NAT gateway) to reach the RDS database in a private subnet, which is unnecessary and less secure; direct VPC placement avoids internet traversal. Option D is wrong because VPC endpoints are used for connecting to AWS services like S3 or DynamoDB via PrivateLink, not for connecting to an RDS database; RDS does not support VPC interface endpoints for database connections.

161
MCQeasy

A company uses AWS Systems Manager Session Manager to manage EC2 instances without opening inbound ports. Which IAM policy is required for an EC2 instance to allow Session Manager to connect?

A.AmazonSSMFullAccess
B.AmazonEC2FullAccess
C.AdministratorAccess
D.AmazonSSMManagedInstanceCore
AnswerD

AmazonSSMManagedInstanceCore is the AWS-managed policy specifically designed for EC2 instances that need to be managed through Systems Manager and Session Manager. It includes the required actions such as ssm:UpdateInstanceInformation, ssmmessages:CreateControlChannel, ssmmessages:CreateDataChannel, and s3:GetObject for patch retrieval, while excluding unrelated administrative permissions. Applying this policy to an instance role is the recommended least-privilege approach, ensuring the SSM agent can communicate with the control plane without opening the instance to broader AWS management capabilities.

Why this answer

The AmazonSSMManagedInstanceCore policy grants the minimum permissions required for an EC2 instance to communicate with the Systems Manager service via the SSM Agent, including sending heartbeats, receiving commands, and establishing Session Manager connections. Session Manager does not require inbound ports; it relies on the instance initiating outbound HTTPS connections (port 443) to the SSM endpoints, so the instance needs only the permissions in this managed policy to function as a managed node.

Exam trap

The trap here is that candidates often pick AmazonSSMFullAccess (Option A) because it sounds like it covers all SSM needs, but they fail to distinguish between the permissions needed for the instance role (which only needs to act as a managed node) versus the permissions needed for an administrator user who manages SSM features.

How to eliminate wrong answers

Option A is wrong because AmazonSSMFullAccess is an AWS-managed policy intended for IAM users or roles that need full administrative access to Systems Manager actions (e.g., creating documents, running automations), not for the EC2 instance role; it grants overly broad permissions that are unnecessary and violate least privilege for the instance. Option B is wrong because AmazonEC2FullAccess provides full access to EC2 resources (e.g., launching instances, modifying security groups) but does not include the specific SSM actions (ssm:UpdateInstanceInformation, ssm:SendCommand, etc.) required for the SSM Agent to register and communicate with Session Manager. Option C is wrong because AdministratorAccess grants full access to all AWS services and resources, which is far beyond the principle of least privilege and is never recommended for an EC2 instance role; it would work technically but is a security anti-pattern that the exam expects you to reject in favor of the minimal policy.

162
MCQhard

A company is designing a hybrid cloud architecture with an AWS Direct Connect connection. The company wants to ensure that traffic to and from the VPC goes through the Direct Connect connection and not over the internet. Which configuration should be used?

A.Create a VPC Endpoint for each AWS service.
B.Set up a VPN connection over the internet as a backup.
C.Attach a Virtual Private Gateway to the VPC and update the route tables to point to the Direct Connect virtual interface.
D.Configure the Direct Connect connection and assign public IPs to instances.
AnswerC

Forcing traffic through Direct Connect requires a Virtual Private Gateway (VGW) attached to the VPC and a private virtual interface (VIF) connecting the Direct Connect connection to that VGW. Once the VGW is attached, you update each subnet's route table with a static route pointing to the on-premises CIDR via the VGW, and you must also enable route propagation from the VGW so that routes are advertised. This ensures that any packet bound for the on-premises network is sent to the VGW and then over the Direct Connect private VIF, bypassing the internet entirely.

Why this answer

A Virtual Private Gateway (VGW) is the AWS-side anchor for an AWS Direct Connect private virtual interface (VIF). By attaching the VGW to the VPC and updating the VPC route tables to point the destination CIDR (e.g., the on-premises network) to the Direct Connect VIF, all traffic between the VPC and the on-premises network is forced through the Direct Connect link, bypassing the internet entirely.

Exam trap

The trap here is that candidates often confuse VPC Endpoints (which provide private access to AWS services) with the mechanism needed to route general VPC-to-on-premises traffic through Direct Connect, leading them to select Option A instead of understanding that a VGW and proper route table entries are required.

How to eliminate wrong answers

Option A is wrong because VPC Endpoints allow private access to specific AWS services (e.g., S3, DynamoDB) without traversing the internet, but they do not route general VPC traffic (e.g., to on-premises networks) through Direct Connect; they are service-specific, not a replacement for a VGW. Option B is wrong because a VPN backup over the internet would still allow traffic to potentially egress via the internet if the Direct Connect link fails, and the question explicitly requires traffic to go through Direct Connect, not over the internet; a VPN is a backup path, not a mechanism to enforce Direct Connect usage. Option D is wrong because assigning public IPs to instances would actually encourage traffic to route over the internet (via the IGW), defeating the requirement to keep traffic off the internet; Direct Connect does not require public IPs for private VIF traffic.

163
MCQmedium

A company uses AWS CloudFormation to deploy infrastructure. A security engineer needs to ensure that all CloudFormation stacks use a specific AWS KMS key for encrypting resources that support encryption. Which approach should be used?

A.Use a CloudFormation template that includes the KMS key ID as a hardcoded value.
B.Use a CloudFormation parameter to accept the KMS key ID and validate it with a rule.
C.Use AWS CloudFormation StackSets with a service-managed permission model to deploy stacks from a centrally managed template that includes the KMS key.
D.Use an AWS Organizations service control policy (SCP) to deny all CloudFormation actions unless a specific KMS key is used.
AnswerC

AWS CloudFormation StackSets with a service-managed permission model centralizes template management in the management account, and the StackSets service automatically creates and manages IAM roles in every target account within the AWS Organization, so end users cannot alter the template or the KMS key reference during deployment. Stack instances are deployed with identical configuration, and updates are controlled by the administrator, ensuring the approved KMS key is consistently used across all accounts. This is an enforceable control because the template content is immutable to users in target accounts, and StackSets provides auditable, repeatable deployments through the Organizations integration.

Why this answer

AWS CloudFormation StackSets with a service-managed permission model allow you to deploy a centrally managed template across multiple accounts and regions from a single administrator account. By hardcoding the KMS key ID directly in the template (or referencing a stack-set parameter that is locked down), you enforce that all stack instances use the specified KMS key for encryption-enabled resources, ensuring consistent compliance without relying on individual user input.

Exam trap

The trap here is that candidates often confuse SCPs with resource-level enforcement, not realizing that SCPs cannot evaluate the specific values of CloudFormation template parameters or resource properties, only the API actions themselves.

How to eliminate wrong answers

Option A is wrong because hardcoding the KMS key ID in a CloudFormation template reduces flexibility and security—anyone with access to the template can see the key ID, and it prevents reuse across environments without manual edits. Option B is wrong because a CloudFormation parameter with a validation rule only checks the format or allowed values of the input; it does not enforce that the key is actually used by resources in the stack, and users can still supply a different key ID that passes validation. Option D is wrong because an SCP cannot inspect the specific KMS key ID used within a CloudFormation resource property; SCPs operate at the API action level (e.g., denying `cloudformation:CreateStack`) and cannot conditionally allow actions based on the value of a template parameter or resource property.

164
MCQmedium

A company has an Amazon S3 bucket that stores sensitive data. The security team needs to ensure that all access to the bucket is encrypted in transit. Which condition should be added to the bucket policy?

A.aws:SecureTransport
B.aws:SourceIp
C.s3:x-amz-server-side-encryption
D.aws:UserAgent
AnswerA

The aws:SecureTransport condition key is a global IAM condition that evaluates to true only when the request to S3 was made over HTTPS/TLS. By including it in a bucket policy with a Deny effect, you can reject any HTTP request, thereby enforcing encryption in transit for all S3 API operations. This condition directly addresses the requirement that sensitive data not be transmitted in plaintext.

Why this answer

The `aws:SecureTransport` condition key in an S3 bucket policy enforces that all requests to the bucket must be made over HTTPS (TLS). When set to `false`, any HTTP request is denied, ensuring data is encrypted in transit. This directly addresses the security team's requirement to encrypt all access to the bucket during transmission.

Exam trap

The trap here is that candidates confuse encryption in transit (HTTPS/TLS) with encryption at rest (server-side encryption), leading them to select `s3:x-amz-server-side-encryption` instead of `aws:SecureTransport`.

How to eliminate wrong answers

Option B is wrong because `aws:SourceIp` restricts access based on the requester's IP address, not the encryption of the connection; it does not enforce HTTPS. Option C is wrong because `s3:x-amz-server-side-encryption` controls server-side encryption at rest (e.g., SSE-S3, SSE-KMS), not encryption in transit over the network. Option D is wrong because `aws:UserAgent` filters requests based on the user agent string of the client application, which has no bearing on whether the transport layer is encrypted.

165
MCQmedium

A security engineer is designing a VPC with a public subnet and a private subnet. The private subnet will host a database instance that should only be accessible from the application instances in the public subnet. The application instances use an Auto Scaling group. Which configuration ensures that only the application instances can access the database?

A.Allow inbound database port from the security group attached to the application instances in the public subnet.
B.Allow inbound database port from 0.0.0.0/0 in the database security group.
C.Configure a network ACL on the private subnet to allow the database port from the public subnet CIDR.
D.Allow inbound database port from the public subnet CIDR block in the database security group.
AnswerA

Referencing the application instances' security group as the source makes the rule follow the Auto Scaling group automatically, so only those instances can reach the database port. This satisfies the constraint that access be limited to the application tier despite changing instance IPs.

Why this answer

Referencing the application instances' security group as the source in the database security group's inbound rule allows only instances that carry that security group to connect. Because the Auto Scaling group applies the same security group to all instances, this dynamically permits all current and future application instances without hardcoding CIDRs. This is the only option that restricts access to the application instances specifically.

Exam trap

SCS-C02 often tests the misconception that subnet CIDR-based rules are equivalent to security group references — candidates pick the CIDR option, missing that only SG referencing restricts access to the specific instances.

How to eliminate wrong answers

Option B is wrong because allowing 0.0.0.0/0 opens the database to the entire internet, violating the least-privilege requirement. Option C is wrong because network ACLs are stateless and subnet-level; allowing the public subnet CIDR would permit any host in that subnet, not just the application instances, and NACLs cannot reference security groups. Option D is wrong because allowing the public subnet CIDR permits any resource in that subnet — including future unrelated instances — rather than only the application instances identified by their security group.

166
MCQmedium

A company uses AWS Systems Manager Session Manager to manage EC2 instances. The security team wants to ensure that all SSH sessions are logged and that commands are recorded. What should be configured?

A.Enable session logging in the Session Manager preferences to send logs to Amazon S3 and CloudWatch Logs
B.Configure the security group to allow inbound SSH from the Session Manager service
C.Enable AWS CloudTrail to log Systems Manager API calls
D.Create an IAM policy that allows ssm:StartSession and attach it to the instance role
AnswerA

Enabling session logging in Session Manager preferences is the correct approach because it captures the actual interactive session stream—every keystroke, command, and output—and delivers it to centralized destinations such as Amazon S3 and CloudWatch Logs. This configuration is applied at the Systems Manager account level and can enforce audit trails for all sessions, including the ability to search and alert on command history. Without this, there is no native way to retroactively review the commands executed inside a session, making it essential for compliance and forensic requirements.

Why this answer

Session Manager preferences allow logging session activity to Amazon S3 and CloudWatch Logs, which records all commands run during SSH sessions. Option B is incorrect because security groups control network access, not logging. Option C is incorrect because CloudTrail logs API calls to Systems Manager, not the commands executed within a session.

Option D is incorrect because an IAM policy only controls permissions to start sessions, not the logging of session activity.

167
MCQhard

A security engineer is designing a network segmentation strategy for a VPC that hosts sensitive data. The engineer needs to ensure that EC2 instances in a private subnet can communicate with an RDS database in a different private subnet, but cannot communicate with any other resources in the same VPC. Which configuration should be used?

A.Create a VPC peering connection between the subnets.
B.Configure security groups for the EC2 instances that only allow outbound traffic to the RDS security group, and RDS security group allows inbound from the EC2 security group.
C.Assign the same security group to both the EC2 instances and the RDS database.
D.Use network ACLs with deny rules for all traffic except between the two subnets.
AnswerB

Security groups act as stateful, instance-level firewalls, and AWS allows one security group to reference another as a source or destination in its rules. By configuring the EC2 security group's outbound rule to destination the RDS security group, and the RDS security group's inbound rule to source the EC2 security group, the two sets of instances can communicate only with each other, without hard-coding IP addresses. Because security groups default to deny-all and automatically allow return traffic, this pattern creates a minimal-privilege channel between the application tier and the database tier, and it self-maintains when instances are replaced or auto-scaled since the rule references the group, not individual instance IPs.

Why this answer

Security groups act as a virtual firewall at the instance level, allowing stateful traffic filtering. By configuring the EC2 security group to allow outbound traffic only to the RDS security group (using the security group ID as the destination), and the RDS security group to allow inbound traffic only from the EC2 security group, you create a precise, bidirectional allowlist. This ensures that EC2 instances can communicate exclusively with the RDS database, blocking all other traffic within the VPC without relying on IP addresses or subnet CIDRs.

Exam trap

The trap here is that candidates often confuse security groups with network ACLs or assume that VPC peering or shared security groups are sufficient for fine-grained segmentation, overlooking that security group referencing provides the precise, resource-level isolation required for this scenario.

How to eliminate wrong answers

Option A is wrong because VPC peering connects entire VPCs, not subnets, and would allow all traffic between the peered VPCs, not restrict communication to specific resources. Option C is wrong because assigning the same security group to both EC2 and RDS would allow all traffic between any instances using that group, including unintended communication between multiple EC2 instances or other resources, violating the requirement to restrict communication solely to the EC2-RDS pair. Option D is wrong because network ACLs are stateless and operate at the subnet level, requiring explicit allow rules for both inbound and outbound traffic; using deny rules for all traffic except between the two subnets would be complex, error-prone, and still allow any instance in those subnets to communicate, not just the specific EC2 and RDS instances.

168
MCQmedium

A company uses an AWS Network Firewall to inspect traffic between subnets in a VPC. The security team wants to ensure that all traffic from the web tier to the database tier passes through the firewall. The web servers are in subnet A, and the database servers are in subnet B. What routing configuration is required?

A.Add a route in the route table associated with subnet A that sends all traffic to the firewall endpoint.
B.Add a route in the route table for subnet A with destination subnet B CIDR and target the firewall endpoint. Add a similar route in subnet B's route table with destination subnet A CIDR and target the firewall endpoint.
C.Add a route in the route table associated with subnet B that sends all traffic to the firewall endpoint.
D.Associate both subnets with the same route table and add a route to the firewall endpoint for all traffic.
AnswerB

This is the correct approach because it creates symmetric, purpose-built route entries. The route in subnet A's table with destination subnet B CIDR targets the firewall endpoint so outbound cross-tier traffic is inspected, and the mirrored route in subnet B's table with destination subnet A CIDR ensures replies also traverse the firewall for stateful inspection. All other traffic keeps its normal path, minimizing blast radius and cost. This pair of specific CIDR-based routes guarantees that both directions of the subnet-A-to-subnet-B conversation pass through the firewall endpoint, satisfying the requirement.

Why this answer

AWS Network Firewall is a stateful, managed firewall that inspects traffic only when that traffic is explicitly routed to its firewall endpoint. To inspect east-west traffic between subnet A (web tier) and subnet B (database tier), both directions must be routed through the firewall endpoint. This means adding a route in subnet A's route table for the destination subnet B CIDR pointing to the firewall endpoint, and a reciprocal route in subnet B's route table for the destination subnet A CIDR pointing to the firewall endpoint.

This ensures that traffic from A to B and B to A is symmetrically inspected, which is required for stateful inspection to work correctly.

Exam trap

SCS-C02 often tests the misconception that routing traffic in only one direction is sufficient for stateful inspection, or that a single route table can serve multiple subnets with different routing needs.

How to eliminate wrong answers

Option A is wrong because it only routes traffic from subnet A to the firewall endpoint, leaving return traffic from subnet B to subnet A uninspected and potentially breaking stateful flow symmetry. Option C is wrong because it only routes traffic from subnet B to the firewall endpoint, missing the outbound direction from the web tier. Option D is wrong because associating both subnets with the same route table does not automatically route traffic between them through the firewall; a single route table cannot have overlapping CIDR routes that distinguish traffic based on source subnet, and AWS route tables are per-subnet, not per-source, so this would not achieve bidirectional inspection.

169
MCQmedium

A company is using AWS CloudFormation to deploy infrastructure. Which method ensures that sensitive data, such as database passwords, is not exposed in the template or outputs?

A.Use the 'NoEcho' property on the password parameter.
B.Store the password in the template outputs.
C.Hardcode the password in the template and use the 'NoEcho' property.
D.Use a dynamic reference to a Systems Manager Parameter Store parameter.
AnswerD

A dynamic reference to Systems Manager Parameter Store, such as {{resolve:ssm:parameter-name}}, lets CloudFormation retrieve the password securely at deployment time without ever embedding it in the template. The parameter can be stored as a SecureString using AWS KMS encryption, and access can be governed by IAM policies, ensuring only authorized stacks and roles can retrieve the value. This approach separates secrets from infrastructure code, follows least-privilege principles, and provides auditability through Parameter Store and CloudTrail.

Why this answer

Using a dynamic reference to an AWS Systems Manager Parameter Store parameter allows CloudFormation to retrieve the password at stack creation time without embedding it in the template or exposing it in outputs. The password is stored securely in Parameter Store, and CloudFormation resolves the reference dynamically, ensuring the sensitive value never appears in plaintext in the template, stack events, or outputs.

Exam trap

The trap here is that candidates often confuse the 'NoEcho' property with a security control that protects the value from being exposed anywhere, when in reality it only hides the input during parameter entry and does not prevent exposure in the template file, outputs, or logs.

How to eliminate wrong answers

Option A is wrong because the 'NoEcho' property only masks the parameter value in the console or CLI when the user enters it; it does not prevent the value from being stored in the template or from being exposed in stack outputs if the parameter is referenced there. Option B is wrong because storing the password in template outputs explicitly exposes the sensitive data in the Outputs tab of the CloudFormation console and in the DescribeStacks API response, which is the opposite of secure handling. Option C is wrong because hardcoding the password in the template, even with 'NoEcho', still embeds the plaintext value in the template file itself, which can be exposed through version control, logs, or template retrieval; 'NoEcho' only hides it during parameter input, not from the template content.

170
MCQmedium

A company has deployed a multi-tier web application on AWS. The web servers are in a public subnet, and the application servers are in a private subnet. The security team wants to ensure that the application servers cannot initiate outbound connections to the internet. What should the team do?

A.Add a deny rule for all outbound traffic in the network ACL of the private subnet.
B.Modify the security group of the application servers to deny all outbound traffic.
C.Remove the default route (0.0.0.0/0) pointing to an internet gateway or NAT gateway from the private subnet's route table.
D.Attach an egress-only internet gateway to the private subnet.
AnswerC

Removing the default route (0.0.0.0/0) to an internet gateway or NAT gateway from the private subnet's route table eliminates the only path for outbound traffic to reach the internet. Route tables govern where traffic is sent from the subnet; without a default route, any packet destined outside the VPC has no route and is dropped. This does not affect inbound traffic, which is controlled by security groups and network ACLs, making it a precise and effective solution.

Why this answer

Removing the default route (0.0.0.0/0) from the private subnet's route table ensures that any traffic destined for the internet has no valid path, effectively preventing application servers from initiating outbound internet connections. Network ACLs and security groups are stateful or stateless filters but do not control routing; without a route, packets cannot leave the subnet regardless of allow rules. This aligns with the principle of using route tables to enforce network segmentation in a multi-tier architecture.

Exam trap

The trap here is that candidates often confuse security group rules or network ACLs with routing decisions, mistakenly believing that blocking outbound traffic at the firewall level is sufficient, when in fact AWS routes traffic before applying security group or ACL rules, so without a route, no traffic can leave the subnet regardless of allow rules.

How to eliminate wrong answers

Option A is wrong because network ACLs are stateless and apply to both inbound and outbound traffic at the subnet level, but adding a deny rule for all outbound traffic would still allow return traffic for established connections if inbound rules permit it; more importantly, it does not prevent the application servers from initiating connections if a route exists, as the ACL only filters packets that are already routed. Option B is wrong because security groups are stateful and cannot deny outbound traffic; they only support allow rules, and by default all outbound traffic is allowed unless explicitly removed, but removing all outbound rules still permits return traffic for inbound-initiated connections due to statefulness, and the security group does not control routing. Option D is wrong because an egress-only internet gateway is designed for IPv6 traffic to allow outbound-only connections from a private subnet, which would actually enable outbound internet access for IPv6, contrary to the requirement to prevent all outbound internet connections.

171
MCQeasy

A company wants to restrict access to an S3 bucket so that only requests from a specific VPC endpoint are allowed. Which S3 bucket policy condition key should be used?

A.aws:VpcSourceIp
B.aws:SourceVpc
C.aws:SourceVpce
D.aws:SourceIp
AnswerC

The aws:SourceVpce condition key is explicitly designed for VPC endpoints and lets you match the ID of the VPC endpoint through which the request was made, such as vpce-12345678. By placing a StringEquals condition in the bucket policy, you can allow access only when the request arrives via that exact endpoint. This satisfies the requirement to restrict access to a specific VPC endpoint, while all other traffic is implicitly denied.

Why this answer

To restrict access to an S3 bucket so that only requests originating from a specific VPC endpoint are allowed, you must use the `aws:SourceVpce` condition key in the S3 bucket policy. This key evaluates the VPC endpoint ID (e.g., `vpce-1a2b3c4d`) of the request, ensuring that only traffic routed through that specific endpoint is granted access. The `aws:SourceVpc` key is used to restrict access based on the VPC ID, not the endpoint ID, and `aws:SourceIp` and `aws:VpcSourceIp` are not valid condition keys for VPC endpoint-based restrictions.

Exam trap

The trap here is that candidates often confuse `aws:SourceVpc` (which restricts by VPC ID) with `aws:SourceVpce` (which restricts by VPC endpoint ID), leading them to select the wrong condition key when the requirement is specifically to allow only traffic from a particular VPC endpoint.

How to eliminate wrong answers

Option A is wrong because `aws:VpcSourceIp` is not a valid AWS condition key; the correct key for source IP is `aws:SourceIp`, and it does not restrict based on VPC endpoint. Option B is wrong because `aws:SourceVpc` restricts access based on the VPC ID (e.g., `vpc-12345678`), not the specific VPC endpoint ID, so it would allow any traffic from within that VPC, not just through the endpoint. Option D is wrong because `aws:SourceIp` restricts based on the client's IP address, which is not suitable for VPC endpoint-based access control since the endpoint uses private IPs and the condition key cannot enforce endpoint-specific restrictions.

172
Multi-Selectmedium

Which TWO of the following are valid ways to control inbound traffic to an EC2 instance? (Select TWO.)

Select 2 answers
A.Network ACLs
B.IAM policies
C.Amazon CloudWatch alarms
D.AWS Key Management Service (KMS)
E.Security groups
AnswersA, E

Network ACLs are stateless virtual firewalls applied at the subnet boundary. They evaluate inbound and outbound traffic against an ordered set of allow and deny rules based on source/destination IP, port, and protocol, with the first matching rule winning. Because NACLs are stateless, an inbound connection's return packets must be explicitly allowed by a matching outbound rule. This makes them an effective subnet-level control for blocking unwanted inbound traffic before it reaches any instance.

Why this answer

Network ACLs (NACLs) are a valid method to control inbound traffic to an EC2 instance because they act as a stateless firewall at the subnet level. Each NACL rule evaluates inbound traffic based on source IP, protocol, and port, and rules are processed in order from lowest to highest number. Since NACLs are stateless, you must explicitly allow both inbound and outbound traffic for a response to return.

Exam trap

The trap here is that candidates often confuse IAM policies with network-level controls, mistakenly thinking IAM can filter traffic, or they assume CloudWatch alarms can block traffic when they only trigger notifications or auto-scaling actions.

173
MCQhard

A company is designing a VPC with public and private subnets. The application servers in the private subnets need to download patches from the internet. Which architecture provides the highest security while allowing internet access?

A.Place a NAT Gateway in the public subnet and configure the private subnet route table to send 0.0.0.0/0 traffic to the NAT Gateway
B.Create a VPC endpoint for Amazon S3 and route traffic through it
C.Attach an internet gateway to the private subnet and configure the route table to send 0.0.0.0/0 traffic to the internet gateway
D.Place a bastion host in the public subnet and configure the private instances to route internet traffic through it
AnswerA

The NAT Gateway is deployed in a public subnet with an Elastic IP and performs source network address translation for instances in private subnets. Outbound packets are sent to the NAT Gateway via the 0.0.0.0/0 route, and return traffic is delivered back through the same stateful translation. Because private instances lack public IPs and the route table points to the NAT Gateway rather than an internet gateway, unsolicited inbound connections cannot reach them, making this the standard design for outbound-only internet access.

Why this answer

A NAT Gateway in a public subnet allows instances in private subnets to initiate outbound traffic to the internet (e.g., for patch downloads) while preventing any unsolicited inbound traffic from the internet. The private subnet route table sends 0.0.0.0/0 traffic to the NAT Gateway, which then forwards it through the Internet Gateway (IGW) attached to the VPC. This provides the highest security because the private instances remain unreachable from the internet, unlike using an IGW directly or a bastion host for routing.

Exam trap

The trap here is that candidates often confuse a bastion host (for administrative access) with a NAT device (for outbound internet routing), or incorrectly assume that a VPC endpoint can provide general internet access instead of just private connectivity to specific AWS services.

How to eliminate wrong answers

Option B is wrong because a VPC endpoint for Amazon S3 only provides private connectivity to S3, not general internet access for downloading patches from arbitrary internet sources. Option C is wrong because attaching an Internet Gateway directly to a private subnet and routing 0.0.0.0/0 traffic to it would make the subnet effectively public, exposing instances to unsolicited inbound traffic and defeating the purpose of a private subnet. Option D is wrong because a bastion host is designed for secure administrative access (SSH/RDP) to private instances, not for routing general internet traffic; using it as a NAT would create a single point of failure, performance bottleneck, and security risk due to its management plane exposure.

174
MCQhard

A company uses an AWS Transit Gateway to connect multiple VPCs and on-premises networks. A security engineer needs to ensure that traffic between VPCs is inspected by a third-party firewall appliance. Which architecture should be used?

A.Configure security groups on the transit gateway to inspect traffic.
B.Create VPC endpoints for each VPC to route traffic through the firewall.
C.Attach the firewall appliance to a dedicated inspection VPC and route traffic from other VPCs through the inspection VPC using transit gateway route tables.
D.Use network ACLs on the transit gateway to filter traffic.
AnswerC

This is the standard centralized inspection architecture: deploy the firewall appliance in a dedicated inspection VPC and attach that VPC to the transit gateway, then use separate transit gateway route tables to force all traffic from spoke VPCs to route to the inspection VPC before it proceeds to other attachments. The inspection VPC must also have route tables that forward traffic back to the transit gateway toward the final destination, enabling asymmetric return-path handling and stateful inspection. This design works because the transit gateway routes based on its route tables, so the firewall becomes an inline bump-in-the-wire for all inter-VPC traffic while maintaining a single control point.

Why this answer

It uses a dedicated inspection VPC as a central point for traffic inspection. By attaching the third-party firewall appliance to this inspection VPC and manipulating transit gateway route tables, you can force all inter-VPC traffic to be routed through the firewall for inspection. This architecture leverages the transit gateway's ability to route traffic between attachments based on route table entries, enabling centralized security enforcement without modifying individual VPC routing.

Exam trap

The trap here is that candidates often confuse transit gateway capabilities with VPC-level constructs like security groups or network ACLs, assuming they can be applied directly to the transit gateway, when in fact transit gateway traffic inspection requires a separate inspection VPC architecture.

How to eliminate wrong answers

Option A is wrong because security groups are stateful firewalls applied at the instance or elastic network interface level, not on transit gateways; transit gateways do not support security groups. Option B is wrong because VPC endpoints (Gateway Endpoints or Interface Endpoints) are used for private connectivity to AWS services (e.g., S3, DynamoDB) and cannot route general inter-VPC traffic through a third-party firewall. Option D is wrong because network ACLs are stateless firewalls applied at the subnet level, not on transit gateways; transit gateways do not support network ACLs.

175
MCQeasy

A company has a VPC with public and private subnets. The private subnets need to access the internet for software updates. Which AWS service provides a managed, highly available, and scalable solution for this requirement?

A.NAT instance in a public subnet
B.Internet Gateway attached to the VPC
C.NAT Gateway in a public subnet
D.AWS Site-to-Site VPN connection
AnswerC

A NAT Gateway is a fully managed service placed in a public subnet with an Elastic IP, and it automatically scales throughput and is highly available when deployed in multiple Availability Zones. It allows instances in private subnets to initiate outbound internet sessions by translating their private source addresses to the gateway's public address, while preventing inbound connections from the internet. This directly satisfies the need for managed, scalable internet egress for the private workload.

Why this answer

A NAT Gateway is a managed AWS service that provides outbound-only internet access for instances in private subnets. It is highly available within an Availability Zone (AZ) and scales automatically up to 45 Gbps, making it the ideal solution for private subnet internet access without the management overhead of a NAT instance.

Exam trap

The trap here is that candidates often confuse a NAT Gateway with a NAT instance, thinking the instance is more flexible or cheaper, but they overlook the managed, highly available, and scalable nature of the NAT Gateway that directly addresses the requirement without operational overhead.

How to eliminate wrong answers

Option A is wrong because a NAT instance is a single EC2 instance that you must manage, patch, and configure for high availability (e.g., using an Auto Scaling group with a script), and it does not provide the same managed scalability or automatic failover as a NAT Gateway. Option B is wrong because an Internet Gateway (IGW) allows bidirectional traffic; attaching it to a VPC and routing private subnets to it would expose those instances to inbound internet traffic, violating the requirement for private subnets that should only initiate outbound connections. Option D is wrong because an AWS Site-to-Site VPN connects your VPC to an on-premises network over the internet, not to the public internet for software updates; it is designed for hybrid connectivity, not outbound internet access for private subnets.

176
MCQmedium

A company uses an Application Load Balancer (ALB) to distribute traffic to a fleet of EC2 instances in private subnets. The security team wants to ensure that only the ALB can communicate with the EC2 instances. Which security group configuration should be applied to the EC2 instances?

A.Allow inbound HTTP traffic from the EC2 instances' own security group
B.Allow inbound HTTP traffic from 0.0.0.0/0
C.Allow inbound HTTP traffic from the VPC CIDR block
D.Allow inbound HTTP traffic from the ALB's security group
AnswerD

Referencing the ALB's security group as the source means the EC2 instances accept traffic only from ENIs belonging to that group, regardless of IP addresses. This satisfies the stem's constraint that only the ALB may communicate with the instances.

Why this answer

Security groups can reference other security groups as a source, allowing traffic only from resources associated with that security group. By specifying the ALB's security group as the source for inbound HTTP traffic, the EC2 instances will only accept traffic originating from the ALB, effectively restricting all other inbound traffic. This is a best practice for securing backend instances behind a load balancer.

Exam trap

The trap here is that candidates often confuse security group referencing with CIDR-based rules, mistakenly thinking that allowing the VPC CIDR (Option C) is sufficient, but this would allow any resource in the VPC, not just the ALB, to reach the EC2 instances.

How to eliminate wrong answers

Option A is wrong because allowing inbound HTTP traffic from the EC2 instances' own security group would permit traffic between the EC2 instances themselves, not from the ALB, and does not restrict access to the ALB only. Option B is wrong because allowing inbound HTTP traffic from 0.0.0.0/0 would permit traffic from any IP address on the internet, completely bypassing the ALB and exposing the EC2 instances directly. Option C is wrong because allowing inbound HTTP traffic from the VPC CIDR block would permit traffic from any resource within the VPC (including other EC2 instances, NAT gateways, or VPN connections), not exclusively from the ALB.

177
MCQhard

A company has a VPC with a public subnet and a private subnet. They launch an EC2 instance in the private subnet with a default security group that allows all outbound traffic. The instance needs to download files from an S3 bucket in the same region. Which configuration allows this without internet access?

A.Set up an AWS Direct Connect connection to the S3 bucket.
B.Create a VPC gateway endpoint for S3 and add a route to the private subnet's route table.
C.Attach an internet gateway to the VPC and add a route to the private subnet.
D.Create a NAT gateway in the public subnet and add a route to the private subnet's route table.
AnswerB

A VPC gateway endpoint for S3 is a horizontally scaled, highly available service that allows instances in a private subnet to communicate with S3 without traversing the internet or requiring public IP addresses. Adding a route in the private subnet's route table that points the S3 prefix list (e.g., com.amazonaws.region.s3) to the endpoint ID (pl-xxxx) keeps all traffic within the AWS network, ensuring low latency and enhanced security. This is the recommended, cost-effective approach because the gateway endpoint itself is free and there are no data transfer charges for S3 traffic.

Why this answer

A VPC gateway endpoint for S3 allows instances in a private subnet to access S3 without traversing the internet. By adding a route to the private subnet's route table that points to the endpoint, traffic destined for S3 stays within the AWS network. The default security group's outbound rule permits all traffic, so no additional security group changes are needed.

Exam trap

The trap here is that candidates often confuse VPC gateway endpoints with interface endpoints or assume a NAT gateway is required for any outbound traffic, missing that S3 and DynamoDB support gateway endpoints which work directly from private subnets without internet access.

How to eliminate wrong answers

Option A is wrong because AWS Direct Connect is a dedicated network connection from on-premises to AWS, not a solution for VPC-to-S3 access without internet; it adds unnecessary complexity and cost. Option C is wrong because attaching an internet gateway and adding a route to the private subnet would require the instance to have a public IP or a NAT device to reach the internet, and the question explicitly states 'without internet access'. Option D is wrong because a NAT gateway provides outbound internet access for private instances, which contradicts the requirement of no internet access; it also introduces a dependency on a public subnet and an internet gateway.

178
MCQeasy

A company is deploying a web application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The instances are in a private subnet. How should the security group for the EC2 instances be configured?

A.Allow inbound HTTP/HTTPS from the internet gateway.
B.Allow inbound HTTP/HTTPS from the security group of the ALB.
C.Allow inbound HTTP/HTTPS from 0.0.0.0/0.
D.Allow inbound HTTP/HTTPS from the VPC CIDR.
AnswerB

Referencing the ALB's security group as the source in the EC2 instance's security group inbound rule is the recommended, least-privilege approach for a private-subnet web tier. This creates a security-group-to-security-group dependency: the rule dynamically allows traffic from any network interface that is associated with the ALB's security group, regardless of the ALB's IP addresses or how they change over time. Because the ALB terminates the client connection and opens a new connection to the instance, the source IP of those connections is the ALB's private IP (or its ENI), which is covered by the ALB's security group association. This rule also ensures that no other resource in the VPC or on-premises can reach the instances directly, preserving the private subnet's isolation and forcing all traffic through the ALB.

Why this answer

The EC2 instances are in a private subnet and should only accept traffic from the ALB, not directly from the internet. By referencing the ALB's security group as the source, you ensure that only traffic that has passed through the ALB can reach the instances, maintaining a secure architecture. This follows the principle of least privilege and prevents bypassing the load balancer.

Exam trap

The trap here is that candidates often confuse the source for security group rules, thinking they should use the internet gateway or VPC CIDR, when the correct approach is to reference the ALB's security group to enforce traffic flow through the load balancer.

How to eliminate wrong answers

Option A is wrong because the internet gateway is a network routing component, not a security group source; security groups cannot reference an internet gateway. Option C is wrong because allowing 0.0.0.0/0 would permit direct inbound traffic from the internet, which defeats the purpose of placing instances in a private subnet and bypasses the ALB. Option D is wrong because allowing the VPC CIDR would permit traffic from any resource within the VPC, including potentially compromised instances, rather than restricting traffic to only the ALB.

179
MCQeasy

Which of the following is a best practice for securing an AWS account root user?

A.Create access keys for the root user and use them for API calls.
B.Enable multi-factor authentication (MFA) and avoid using the root user.
C.Use the root user for daily administrative tasks.
D.Share the root user password with the IT team for emergency access.
AnswerB

Enabling MFA on the root account adds a second authentication factor that protects account-level actions such as changing the account email or closing the account, which cannot be performed by IAM users. Avoiding the root user for routine operations means you create IAM administrative users or roles with least privilege, ensuring every action is attributable and auditable. The combination dramatically reduces the risk of root credential misuse.

Why this answer

The AWS root user has unrestricted access to all AWS resources and services, making it a high-value target. Enabling multi-factor authentication (MFA) adds an extra layer of security beyond the password, and AWS best practices dictate that the root user should only be used for a limited set of tasks (e.g., changing account settings) and never for daily operations. This minimizes the attack surface and reduces the risk of compromise.

Exam trap

The trap here is that candidates may think the root user is necessary for daily administration or that sharing credentials is acceptable for emergencies, but AWS explicitly prohibits these practices in favor of IAM roles and MFA-protected root user access only for account-level changes.

How to eliminate wrong answers

Option A is wrong because creating access keys for the root user violates AWS security best practices; root user access keys provide unrestricted, permanent credentials that cannot be rotated or scoped down, and AWS recommends never using them for API calls. Option C is wrong because using the root user for daily administrative tasks exposes the account to unnecessary risk; instead, AWS Identity and Access Management (IAM) users with appropriate permissions should be used for routine operations. Option D is wrong because sharing the root user password with the IT team undermines accountability and security; AWS recommends using IAM roles or a secure password management system for emergency access, not distributing the root password.

180
MCQeasy

A company is using AWS Systems Manager Session Manager to provide secure shell access to EC2 instances without opening inbound ports. Which of the following is a requirement for this setup?

A.The EC2 instance must have an IAM role that allows SSM actions.
B.The EC2 instance must be in a public subnet.
C.The EC2 instance must have a public IP address.
D.The security group must allow inbound SSH from 0.0.0.0/0.
AnswerA

The SSM Agent on the EC2 instance requires an IAM instance role that grants the necessary Systems Manager permissions, such as the managed policy AmazonSSMManagedInstanceCore. This role provides temporary credentials that the agent uses to authenticate to the Systems Manager control plane and to open the bidirectional websocket channel required for Session Manager. Without these IAM permissions, even a technically healthy instance will be unable to register with Systems Manager or start a session.

Why this answer

AWS Systems Manager Session Manager establishes a secure shell connection to EC2 instances without requiring inbound ports. The EC2 instance must have an IAM role attached that includes the AWS managed policy AmazonSSMManagedInstanceCore, which grants permissions for the SSM agent to communicate with the Systems Manager service. This IAM role is essential because the SSM agent uses AWS credentials from the instance metadata to authenticate and establish a bidirectional control channel via HTTPS (port 443) to the Systems Manager endpoint, not through traditional SSH.

Exam trap

The trap here is that candidates assume Session Manager requires inbound network access (like SSH) or public IPs, but the key requirement is the IAM role that grants the SSM agent permission to communicate with the AWS Systems Manager service via outbound-only HTTPS connections.

How to eliminate wrong answers

Option B is wrong because the EC2 instance does not need to be in a public subnet; Session Manager works with instances in private subnets as long as they have outbound internet access (via NAT gateway or VPC endpoints) to reach the Systems Manager endpoints. Option C is wrong because the instance does not require a public IP address; Session Manager uses the SSM agent to initiate an outbound connection to AWS, so the instance can be fully private with no public IP. Option D is wrong because Session Manager explicitly avoids opening inbound SSH ports; the security group does not need to allow inbound SSH from 0.0.0.0/0, and in fact, a best practice is to block all inbound SSH traffic when using Session Manager.

181
MCQmedium

A company needs to securely store database credentials used by a Lambda function. The credentials must be automatically rotated. Which service should be used?

A.AWS Identity and Access Management (IAM)
B.AWS Key Management Service (KMS)
C.AWS Systems Manager Parameter Store
D.AWS Secrets Manager
AnswerD

Secrets Manager is the purpose-built service for storing sensitive data like database credentials, API keys, and passwords. It provides native automatic rotation using a configurable Lambda function and integrates with RDS, Redshift, and DocumentDB for out-of-the-box rotation. Secrets Manager also maintains versions and enforces fine-grained IAM policies, so it is the correct choice when credentials must be rotated automatically and safely.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to securely store, manage, and automatically rotate database credentials and other secrets throughout their lifecycle. It natively supports automatic rotation for Amazon RDS, Redshift, and DocumentDB databases without requiring custom code, and it integrates directly with Lambda via the AWS SDK to retrieve secrets on demand.

Exam trap

The trap here is that candidates often confuse Parameter Store's SecureString parameter (which can store encrypted secrets) with Secrets Manager's automatic rotation feature, overlooking that Parameter Store does not natively rotate secrets.

How to eliminate wrong answers

Option A is wrong because IAM is an access management service for controlling permissions to AWS resources, not a secrets storage service; it cannot store or rotate database credentials. Option B is wrong because KMS is a key management service for creating and controlling encryption keys, not for storing or rotating secrets like database credentials. Option C is wrong because Systems Manager Parameter Store can store secrets as SecureString parameters but lacks built-in automatic rotation capabilities; it requires custom solutions or integration with Secrets Manager to achieve rotation.

182
MCQeasy

A company uses Amazon S3 to store sensitive data. The security team wants to ensure that all objects are encrypted at rest. Which feature should they enable on the S3 bucket?

A.Versioning
B.Server access logging
C.Cross-Region Replication
D.Default encryption
AnswerD

Default encryption automatically applies server-side encryption (SSE-S3, SSE-KMS, or SSE-C) to every new object written to the bucket. This is the correct remediation because it guarantees that all future uploads are encrypted at rest, establishing a consistent security baseline. It is a direct control that addresses the requirement to protect sensitive data, and it can be further enforced with a bucket policy denying unencrypted uploads. Note that default encryption does not encrypt existing objects, so those must be handled separately.

Why this answer

S3 Default Encryption (now called Default Bucket Encryption) automatically encrypts every object uploaded to the bucket using either SSE-S3 or SSE-KMS, without requiring the uploader to specify encryption headers. Enabling it on the bucket ensures all objects are encrypted at rest by default, satisfying the security team's requirement. It is the only option that directly enforces encryption at rest for all objects.

Exam trap

SCS-C02 often tests the difference between features that sound security-related (logging, versioning, replication) and the one that actually enforces encryption at rest — candidates frequently pick Server Access Logging or Versioning as a security control when the question asks specifically about encryption.

How to eliminate wrong answers

Option A is wrong because Versioning only preserves multiple versions of objects — it has no encryption capability and does not enforce encryption at rest. Option B is wrong because Server Access Logging records requests made to the bucket for auditing purposes; it does not encrypt data. Option C is wrong because Cross-Region Replication copies objects to another bucket in a different region for durability or latency, but it does not enforce encryption at rest on the source bucket.

183
MCQhard

A company is using AWS Organizations to manage multiple accounts. The security team wants to ensure that all accounts have AWS CloudTrail enabled in all regions. Which approach should be used?

A.Create an SCP that requires CloudTrail to be enabled.
B.Enable CloudTrail in each account using a cross-account IAM role.
C.Use AWS Config rules to detect non-compliant accounts and automatically enable CloudTrail.
D.Enable AWS CloudTrail from the master account as an organization trail.
AnswerD

An organization trail, created from the management (master) account of AWS Organizations, automatically applies to every account within the organization and is centrally managed as a single trail. CloudTrail delivers log files for the management account and all member accounts to the same S3 bucket, and member accounts cannot stop or modify the trail, preserving a reliable audit baseline. This is the intended, native way to enable CloudTrail across an organization, and it fulfills the requirement with no per-account setup.

Why this answer

AWS Organizations allows you to create an organization trail from the management account that automatically applies to all member accounts and all regions. This ensures CloudTrail is enabled across the entire organization without requiring per-account configuration, and it centralizes log delivery to a single Amazon S3 bucket for auditing.

Exam trap

The SCS-C02 exam often tests the misconception that SCPs can enforce positive actions (like enabling a service), when in reality SCPs only provide preventive controls (denying actions) and cannot proactively configure resources.

How to eliminate wrong answers

Option A is wrong because SCPs can only deny or allow actions (e.g., prevent disabling CloudTrail), but they cannot enforce enabling a service; they are not proactive configuration tools. Option B is wrong because using a cross-account IAM role to enable CloudTrail in each account is manual, error-prone, and does not scale; it also fails to enforce compliance automatically across all regions. Option C is wrong because AWS Config rules can detect non-compliance but cannot automatically enable CloudTrail; remediation actions require additional automation (e.g., AWS Systems Manager Automation), and Config itself is not a provisioning tool.

184
MCQeasy

A startup is building a web application on AWS. They have an Application Load Balancer (ALB) in front of EC2 instances in an Auto Scaling group. They want to protect the application from common web exploits like SQL injection and cross-site scripting. They also need to allow only traffic from certain geographic regions. Which AWS service should they use to achieve these requirements?

A.AWS WAF
B.AWS Shield Advanced
C.Security groups on the ALB
D.Network ACLs on the ALB subnets
AnswerA

AWS WAF is the correct service because it operates at Layer 7 and can inspect every HTTP(S) request forwarded to the ALB, allowing you to block SQL injection, cross-site scripting, and other application-layer attacks via managed or custom rules. It also supports geo-match and rate-based rules, which are essential for a web-facing application. By associating a WAF web ACL directly with the ALB, traffic is filtered before reaching the application, giving you granular control over the actual request content.

Why this answer

AWS WAF is a web application firewall that protects against common web exploits like SQL injection and cross-site scripting. It also allows you to create geo-match conditions to allow or block traffic based on geographic regions, meeting both requirements.

Exam trap

SCS-C02 often tests the distinction between WAF and Shield, and candidates might think Shield Advanced provides WAF capabilities, but it's primarily for DDoS; also, they might confuse security groups with WAF for application-layer protection.

How to eliminate wrong answers

Option B is wrong because AWS Shield Advanced provides DDoS protection, not web exploit protection like SQL injection or XSS, and does not offer geographic traffic filtering. Option C is wrong because security groups on the ALB control IP/port-based access, not web exploits or geographic filtering. Option D is wrong because network ACLs on subnets are stateless and control IP/port traffic, not application-layer attacks or geo-blocking.

185
MCQhard

A company is running a critical web application on EC2 instances behind an Application Load Balancer (ALB) in a VPC. The application serves traffic on port 443. The security team has implemented a security group for the ALB that allows inbound HTTPS from 0.0.0.0/0. The EC2 instances are in a private subnet with a security group that allows inbound traffic from the ALB security group on port 8080. The application works correctly. However, the security team wants to add an additional layer of defense by implementing a web application firewall (WAF) to block common web exploits. The team also wants to ensure that only traffic from the company's corporate IP range (203.0.113.0/24) can access the application for administrative purposes on a separate path. The team has enabled AWS WAF on the ALB and associated a web ACL. They have also created a rule to allow traffic from the corporate IP range and block all other traffic. After deploying these changes, external users (not from corporate IP) cannot access the application at all. The company wants external users to be able to access the main application, but only corporate IPs should access the admin path. What should the security engineer do to fix the issue?

A.Configure the security group of the ALB to allow only corporate IPs.
B.Create two separate ALBs, one for admin traffic and one for main traffic.
C.Remove the WAF rule that blocks all non-corporate traffic and rely on security groups.
D.Modify the WAF rule to allow traffic from the corporate IP range on the admin path and allow all traffic on the main application path.
AnswerD

Modify the WAF web ACL rule so it permits requests from the corporate IP range when the URI path is /admin*, while allowing all other traffic to the main application path without restriction. This can be implemented as a rule with a condition combining the IP set source match and a string pattern match for the admin path, with an appropriate action to block non-matching admin requests. This preserves the public availability of the main application and maintains a tight security boundary on administrative endpoints.

Why this answer

The correct action is to modify the WAF rule to allow traffic from corporate IPs on the admin path and allow all other traffic on the main application path. Currently, the WAF rule blocks all non-corporate traffic, which prevents external users from accessing the main application. By creating separate conditions for the admin path (corporate IPs only) and the main path (allow all), the security team can achieve the desired access control.

Option A is incorrect because it would block external users at the security group level. Option B is unnecessary and adds complexity. Option C removes the WAF protection entirely.

Therefore, option D is the correct solution.

186
MCQeasy

A company is designing a security group for a web application that must receive HTTPS traffic from the internet and send traffic to a backend database. The backend database is an Amazon RDS MySQL instance. What is the best practice for configuring the security groups?

A.Web server SG: inbound HTTPS from 0.0.0.0/0. Database SG: inbound MySQL from web server SG.
B.Web server SG: inbound HTTPS from 0.0.0.0/0, outbound to database SG on port 3306. Database SG: inbound MySQL from web server CIDR block.
C.Web server SG: inbound HTTPS from 0.0.0.0/0, outbound all traffic. Database SG: inbound MySQL from 0.0.0.0/0.
D.Web server SG: inbound HTTPS from 0.0.0.0/0, inbound MySQL from database SG. Database SG: outbound MySQL to web server SG.
AnswerA

This configuration is correct because it applies the principle of least privilege: the web server security group only opens HTTPS to the internet, while the database security group restricts MySQL access to only the web server security group via a security group reference. Security group references are dynamic, so any instance attached to the web server SG is automatically allowed, even as the fleet scales, without needing to update CIDR ranges. This also prevents any other source—including other VPCs or subnets—from reaching the database directly.

Why this answer

The best practice is to allow inbound HTTPS from the internet to the web server security group, and then allow inbound MySQL on the database security group referencing the web server security group as the source. This creates a tight, identity-based trust relationship between tiers without hardcoding CIDR ranges.

Exam trap

SCS-C02 often tests security group referencing versus CIDR blocks, and candidates frequently choose CIDR-based rules or open database ports to 0.0.0.0/0, missing that security group references provide tighter, identity-based control.

How to eliminate wrong answers

Option B is wrong because it uses a CIDR block for the database inbound rule instead of referencing the web server security group, which is less precise and can break if IPs change. Option C is wrong because allowing MySQL from 0.0.0.0/0 exposes the database to the entire internet, a severe security risk. Option D is wrong because it reverses the direction — the web server should not accept inbound MySQL from the database, and the database should not initiate outbound MySQL to the web server.

187
MCQhard

A security engineer is designing a multi-tier web application on AWS. The web tier must be accessible from the internet, but the application tier should be accessible only from the web tier. The database tier should be accessible only from the application tier. Which combination of security groups provides the MOST secure configuration?

A.Web SG: allow HTTP/HTTPS from 0.0.0.0/0. App SG: allow HTTP from Web SG CIDR. DB SG: allow MySQL from App SG CIDR.
B.Web SG: allow HTTP/HTTPS from 0.0.0.0/0. App SG: allow all traffic from Web SG. DB SG: allow MySQL from App SG.
C.Web SG: allow HTTP/HTTPS from 0.0.0.0/0. App SG: allow HTTP from Web SG security group ID. DB SG: allow MySQL from 10.0.0.0/24.
D.Web SG: allow HTTP/HTTPS from 0.0.0.0/0. App SG: allow HTTP from Web SG security group ID. DB SG: allow MySQL from App SG security group ID.
AnswerD

Referencing security group IDs as sources enforces tier-to-tier traffic only, so the app tier accepts HTTP solely from the web tier and the database accepts MySQL solely from the app tier. This satisfies the least-privilege constraint without CIDR-based exposure.

Why this answer

It uses security group IDs as the source for inbound rules, which allows traffic only from instances associated with the specified security group, regardless of their IP addresses. This provides a dynamic and secure way to control traffic between tiers, as security group IDs are resolved at the instance level and automatically adapt to changes in instance membership. By contrast, using CIDR blocks (as in options A and C) is less secure because it relies on static IP ranges that may not accurately reflect the actual instances in the web or app tiers, and option B is overly permissive by allowing all traffic from the web SG.

Exam trap

The trap here is that candidates often choose CIDR-based rules (options A or C) because they seem simpler, but they fail to recognize that security group IDs provide a more secure and dynamic way to enforce tier-to-tier access, especially in environments with elastic IPs or auto-scaling.

How to eliminate wrong answers

Option A is wrong because it uses CIDR blocks (Web SG CIDR) instead of security group IDs, which is less secure as CIDR blocks can be broader than necessary and do not automatically update when instances change IPs. Option B is wrong because it allows all traffic from the Web SG to the App SG, which is overly permissive and violates the principle of least privilege by permitting unnecessary protocols beyond HTTP. Option C is wrong because it uses a static CIDR block (10.0.0.0/24) for the database tier, which does not restrict access solely to the app tier instances and may allow other resources in that subnet to reach the database.

188
MCQmedium

A company wants to store audit logs for a minimum of 7 years to meet compliance requirements. The logs are stored in Amazon S3. Which action should be taken to ensure logs are not deleted before 7 years?

A.Enable MFA Delete on the bucket.
B.Configure an S3 Lifecycle policy to transition objects to Glacier after 7 years.
C.Enable S3 Versioning to preserve all versions of objects.
D.Enable S3 Object Lock in Compliance mode with a 7-year retention period on the bucket.
AnswerD

S3 Object Lock in Compliance mode gives each object a write-once-read-many (WORM) retention period, and once a 7-year retention is applied, no user, including the AWS account root user, can delete or overwrite that object version until the period expires. Because Compliance mode is irrevocable for the locked object, even an admin with full permissions cannot shorten the retention or remove the lock. This directly enforces the seven-year audit-log requirement at the S3 API level.

Why this answer

S3 Object Lock in Compliance mode prevents any user, including the root account, from deleting or overwriting an object version until the retention period expires. Setting a 7-year retention period on the bucket enforces the compliance requirement at the object level and cannot be bypassed, which is exactly what is needed to guarantee logs are not deleted before 7 years.

Exam trap

SCS-C02 often tests whether candidates confuse versioning or MFA Delete with true immutability, leading them to pick options that preserve data but do not legally prevent deletion before the retention period.

How to eliminate wrong answers

Option A is wrong because MFA Delete only requires additional authentication for delete operations; it does not prevent an authorized user with MFA from deleting objects before 7 years. Option B is wrong because a lifecycle transition to Glacier after 7 years does not prevent deletion; lifecycle policies manage storage class, not immutability. Option C is wrong because S3 Versioning preserves versions but does not prevent deletion of the current version or the entire object; a user can still delete all versions.

189
Multi-Selecthard

A company runs a two-tier application in a VPC. The web tier runs on EC2 instances in a public subnet behind an Application Load Balancer. The database tier runs on Amazon RDS for MySQL in two private subnets. A security engineer must harden the database tier so that only the web tier can reach the database on port 3306, and so that the database instances are not reachable from the internet under any circumstances. (Choose two.)

Select 2 answers
A.Attach an Elastic IP address to each RDS instance and restrict the security group to the web tier's public addresses.
B.Enable public accessibility on the RDS instances and rely on the security group to block unauthorized sources.
C.Configure the RDS subnet group to use only private subnets that have no route to an internet gateway.
D.Attach a security group to the RDS instances that allows inbound TCP 3306 only from the web tier's security group.
E.Create a network ACL on the private subnets that allows inbound TCP 3306 from 0.0.0.0/0 and denies all other inbound traffic.
AnswersC, D

Placing the database in private subnets with no route to an internet gateway removes any path to or from the internet, which directly satisfies the requirement that the database never be internet-reachable. Route table design, not just security groups, is what guarantees the absence of that path.

Why this answer

Restricting port 3306 by referencing the web tier's security group enforces identity-based access, while keeping the database in private subnets without an internet gateway route removes any possible internet path. Together they satisfy both the least-privilege and the no-internet-exposure requirements without relying on address-based rules.

Exam trap

The trap here is treating a security group rule as sufficient protection while leaving the database in a subnet that still has a route to an internet gateway or public accessibility enabled.

190
Multi-Selecthard

A security engineer is reviewing the security of an Amazon EKS cluster. The cluster is used to run containerized applications. Which three actions should the engineer take to improve the security of the cluster?

Select 3 answers
A.Restrict access to the cluster using AWS IAM authentication for kubectl.
B.Use the default VPC for the cluster.
C.Configure the cluster API server endpoint to be private.
D.Grant the cluster-admin role to all developers.
E.Enable audit logging for the cluster.
AnswersA, C, E

Restricting kubectl access through AWS IAM authentication is correct because it integrates IAM identities with Kubernetes RBAC, allowing precise mapping of IAM users and roles to cluster permissions. This avoids shared static credentials and ensures that only authenticated AWS principals with an explicit RBAC role can execute kubectl commands against the EKS cluster.

Why this answer

Restricting access to the cluster using AWS IAM authentication for kubectl is correct because it integrates with AWS IAM to manage user and role permissions, ensuring that only authorized principals can interact with the EKS cluster. This replaces the default, less secure static token or certificate-based authentication with a robust, auditable identity federation. By mapping IAM roles to Kubernetes RBAC, you enforce least-privilege access and prevent unauthorized API calls.

Exam trap

The trap here is that candidates often confuse using the default VPC as a 'safe' choice because it is pre-configured, but it lacks the isolation and security group controls needed for production workloads, making Option B a common distractor.

191
MCQmedium

Refer to the exhibit. The bucket policy allows access from a specific IP range and denies access over HTTP. A user from IP 198.51.100.5 makes a GET request over HTTPS. What will happen?

A.Denied because of the explicit Deny statement.
B.Allowed because the request is over HTTPS.
C.Allowed because the Deny condition is not satisfied.
D.Denied because no explicit allow matches the request.
AnswerD

The explicit Deny statement is skipped because the request uses HTTPS and thereby satisfies the secure-transport condition, but that only removes a blocking rule. The sole Allow statement, however, is conditioned on the request's source IP being in the specified allowed range, and this request's source IP does not fall within that range. Since the request does not match the condition of any Allow statement, no explicit allow applies, and AWS IAM falls back to the default implicit deny. The request is denied for exactly that reason: no explicit allow matches it.

Why this answer

In AWS S3 bucket policies, an explicit Deny always overrides any Allow, but the request must first match a Deny condition. Here, the Deny condition applies to HTTP requests, but the request is HTTPS, so the Deny does not apply. However, the bucket policy only allows access from a specific IP range, and the user's IP (198.51.100.5) is not within that allowed range.

Since no explicit Allow matches the request, the default implicit Deny applies, resulting in access being denied.

Exam trap

The trap here is that candidates often assume that because the Deny condition is not triggered (due to HTTPS), the request must be allowed, overlooking the fact that the request still fails the IP-based Allow condition, leading to an implicit Deny.

How to eliminate wrong answers

Option A is wrong because the explicit Deny statement only denies access over HTTP, and this request is over HTTPS, so the Deny condition is not satisfied. Option B is wrong because while the request is over HTTPS, it does not satisfy the IP range condition in the Allow statement, so it is not allowed. Option C is wrong because the Deny condition is not satisfied, but the request still fails due to the lack of an explicit Allow matching the IP address, leading to an implicit Deny.

192
MCQmedium

A company is designing a VPC with public and private subnets. The web servers in the public subnets must be accessible from the internet on port 443, but the database servers in the private subnets should only be accessible from the web servers on port 3306. Which combination of security group rules and network ACL rules should be used to meet these requirements with the least administrative overhead?

A.Use security groups for all tiers; add an inbound rule to the database security group allowing traffic from the web security group on port 3306.
B.Use security groups for all tiers; add an inbound rule to the web security group allowing internet traffic on port 443, and add an outbound rule to the web security group allowing traffic to the database security group on port 3306.
C.Use security groups for the web tier and network ACLs for the database tier; add an inbound rule to the database network ACL allowing traffic from the web subnet CIDR on port 3306.
D.Use security groups for the web tier and network ACLs for the database tier; add an inbound rule to the database network ACL allowing all traffic from the web security group.
AnswerA

Security groups are stateful and support referencing other security groups as a source, allowing an inbound rule on the database security group to permit traffic only from instances associated with the web security group on port 3306. This removes the need to track instance IP addresses or rely on broad CIDR ranges, and it automatically scales with the web tier's launch or termination. Because security groups are stateful, return traffic from the database to the web tier is implicitly allowed, reducing operational overhead while maintaining least-privilege access.

Why this answer

Security groups are stateful and support referencing other security groups as a source, which allows you to permit traffic from the web security group to the database security group on port 3306 without needing to specify IP addresses. This approach minimizes administrative overhead as security group rules are automatically applied to all instances associated with the group, and changes propagate without updating network ACLs or CIDR ranges. The web security group can have an inbound rule allowing HTTPS (port 443) from the internet (0.0.0.0/0), while the database security group only allows inbound MySQL/Aurora (port 3306) from the web security group, meeting the access requirements precisely.

Exam trap

The trap here is that candidates often confuse the stateful nature of security groups with the stateless nature of network ACLs, leading them to incorrectly add outbound rules (Option B) or choose network ACLs (Options C and D) when security group references provide a simpler, more scalable solution.

How to eliminate wrong answers

Option B is wrong because it adds an outbound rule to the web security group for traffic to the database security group on port 3306, but security groups are stateful—if the inbound rule on the database security group allows traffic from the web security group, the return traffic is automatically permitted, making the outbound rule redundant and not the primary mechanism to restrict database access. Option C is wrong because it uses a network ACL for the database tier, which is stateless and requires separate inbound and outbound rules, increasing administrative overhead; additionally, referencing a subnet CIDR instead of a security group is less flexible and does not automatically adapt to changes in the web tier. Option D is wrong because network ACLs do not support referencing security groups as a source or destination—they only support CIDR blocks, IP addresses, or service prefixes, so the rule 'allowing all traffic from the web security group' is invalid and would not work.

193
MCQmedium

A company is using AWS WAF to protect a web application behind an Application Load Balancer. The Security Engineer wants to block requests that contain SQL injection attacks. Which action should the Engineer take?

A.Enable AWS Shield Advanced to automatically block SQL injection attacks.
B.Create a WAF rule with a SQL injection match condition and set the action to block.
C.Use Amazon GuardDuty to detect and block SQL injection attempts.
D.Configure the security group of the EC2 instances to block traffic containing SQL injection patterns.
AnswerB

AWS WAF's SQL injection match condition inspects HTTP request components—such as the URI, query string, body, cookies, and headers—for known malicious SQL patterns using transformations like URL decode and lowercasing to evade bypass attempts. Setting the rule action to Block causes the AWS WAF web ACL to terminate matching requests before they reach the protected resource, which is exactly the correct mechanism for preventing SQL injection attacks at the application layer.

Why this answer

AWS WAF is the native service for filtering web traffic to Application Load Balancers, and it includes a managed rule set specifically for SQL injection (SQLi) detection. By creating a custom WAF rule with a SQL injection match condition and setting the action to 'Block', the Engineer directly instructs WAF to inspect incoming requests for SQLi patterns and drop matching traffic before it reaches the ALB. This is the correct, service-native approach for blocking SQL injection attacks at the application layer.

Exam trap

The trap here is that candidates confuse AWS Shield Advanced (a DDoS service) with WAF (a web application firewall), or assume that network-layer controls like security groups can inspect application-layer payloads, when in fact only WAF can perform content inspection for SQL injection.

How to eliminate wrong answers

Option A is wrong because AWS Shield Advanced provides DDoS protection and does not have native SQL injection detection capabilities; it can work with WAF but cannot independently block SQLi. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events for malicious activity, but it does not inspect HTTP request payloads for SQL injection patterns and cannot block traffic in real-time at the ALB. Option D is wrong because security groups operate at the network layer (Layer 3/4) and cannot inspect application-layer payloads for SQL injection patterns; they only filter based on IP addresses, ports, and protocols.

194
MCQeasy

A company is using AWS Key Management Service (KMS) to encrypt data at rest in Amazon S3. The security team wants to ensure that only a specific IAM role can decrypt the data. Which KMS policy element should be used?

A.Principal
B.Resource
C.Action
D.Effect
AnswerA

The Principal element in a KMS key policy identifies the IAM role, user, service, or account that is explicitly granted permission to use the key. For example, the ARN of an IAM role is placed here so that role can call kms:Encrypt or kms:Decrypt. Since the question asks who can use the key, Principal is the correct answer.

Why this answer

(Principal) is correct because in a KMS key policy, the Principal element specifies which IAM users, roles, or AWS services are allowed to perform actions on the key. By setting the Principal to the specific IAM role's ARN, only that role can decrypt the data, enforcing the security team's requirement.

Exam trap

The trap here is that candidates often confuse the Principal element with the Resource element, thinking Resource controls who can use the key, when in fact Resource identifies the key itself and Principal identifies the entity allowed to act on it.

How to eliminate wrong answers

Option B (Resource) is wrong because the Resource element in a KMS key policy identifies the key itself (e.g., the key ARN), not the entity allowed to use it; it does not restrict which IAM role can decrypt. Option C (Action) is wrong because the Action element defines the cryptographic operations (like kms:Decrypt) that are allowed, but it does not specify who can perform them. Option D (Effect) is wrong because the Effect element only sets whether the policy statement allows or denies access (e.g., 'Allow' or 'Deny'), but it does not identify the specific IAM role permitted to decrypt.

195
MCQmedium

A security engineer is reviewing the SQS queue policy shown in the exhibit. The queue is subscribed to an SNS topic in the same account. The security team has a requirement that only the SNS topic should be allowed to send messages to the queue. What is the issue with this policy?

A.The second statement allows any principal in the 10.0.0.0/8 range to receive messages from the queue.
B.The policy does not specify a principal, so it will not work.
C.The aws:SourceArn condition uses ArnLike which is deprecated.
D.The aws:SourceIp condition cannot be used with SQS queue policies.
AnswerA

The second statement grants ReceiveMessage to Principal '*' but limits the request to the 10.0.0.0/8 network via aws:SourceIp. That condition only restricts the caller's IP address; it does not restrict which IAM principal or account can call, so any authenticated principal originating from that CIDR may receive messages. Production should scope the principal to a specific account or IAM role, or add aws:SourceArn if the intent is to allow only a single source service.

Why this answer

The second statement in the SQS queue policy allows any principal in the 10.0.0.0/8 IP range to receive messages from the queue, which violates the security requirement that only the SNS topic should be allowed to send messages. The policy should restrict the `sqs:SendMessage` action to the SNS topic using a condition like `aws:SourceArn` and should not include a broad `Effect: Allow` for `sqs:ReceiveMessage` without restricting the principal or source.

Exam trap

The trap here is that candidates may focus on the `aws:SourceArn` condition or the lack of a principal, overlooking the fact that the second statement grants broad receive access to any IP in the 10.0.0.0/8 range, which violates the requirement to restrict message sending to only the SNS topic.

How to eliminate wrong answers

Option B is wrong because SQS queue policies can work without specifying a principal if the policy is attached to the queue itself, and the `Principal` element can be omitted or set to `*` to allow all principals, but the issue here is not the absence of a principal. Option C is wrong because `ArnLike` is not deprecated; it is a valid condition operator used for pattern matching on ARNs, and the `aws:SourceArn` condition is commonly used with `ArnLike` to restrict access to specific resources. Option D is wrong because `aws:SourceIp` can be used with SQS queue policies to restrict access based on IP addresses, but it is not the issue here; the problem is the overly permissive second statement.

196
MCQhard

A company is deploying a multi-tier web application across multiple Availability Zones. The application includes a web tier, application tier, and database tier. The security team requires that the web tier can communicate with the application tier only on port 8080, and the application tier can communicate with the database tier only on port 3306. Which security group configuration should be used?

A.In the application tier security group, allow inbound from the web tier security group on port 8080. In the database tier security group, allow inbound from the application tier security group on port 3306.
B.In the database tier security group, allow inbound from the application tier's CIDR block on port 3306.
C.In the application tier security group, allow inbound from the web tier's CIDR block on port 8080.
D.In the web tier security group, allow outbound to 0.0.0.0/0 on port 8080.
AnswerA

This is correct because security group references create a logical firewall between tiers that is independent of IP addresses. The application tier security group only accepts HTTP traffic originating from resources that are members of the web tier security group, and the database tier security group only accepts MySQL traffic from members of the application tier security group. AWS resolves the referenced security group to the private IPs of its associated instances at the time the traffic is evaluated, so scaling events and IP changes do not require rule updates.

Why this answer

Referencing security groups as sources (security group referencing) is the AWS-recommended, least-privilege approach for tiered applications. The application tier SG allows inbound on 8080 only from the web tier SG, and the database tier SG allows inbound on 3306 only from the application tier SG. This ensures traffic is permitted based on the identity of the source instances, not on IP ranges, and it scales automatically as instances are added or removed.

Exam trap

SCS-C02 often tests whether candidates know security groups can reference other security groups, so they default to CIDR-based rules and lose least-privilege points.

How to eliminate wrong answers

Option B is wrong because using the application tier's CIDR block is less secure and brittle — it permits any resource in that subnet, not just the application instances, and breaks if IPs change. Option C is wrong because using the web tier's CIDR block similarly allows any host in that subnet, violating least privilege, and it does not restrict to the web tier's actual instances. Option D is wrong because allowing outbound to 0.0.0.0/0 on port 8080 from the web tier does not control inbound access to the application tier and is overly permissive; security groups are stateful, so outbound rules are not the mechanism for restricting tier-to-tier inbound traffic.

197
MCQeasy

A company is using AWS CloudTrail to log API calls. The security team wants to ensure that log files are not modified after they are created. Which feature should they enable?

A.Server-side encryption with AWS KMS
B.Log file integrity validation
C.S3 Object Lock
D.CloudWatch Logs integration
AnswerB

Log file integrity validation is a CloudTrail feature that uses SHA-256 hashing and digital signatures to build a hash chain across log and digest files. CloudTrail periodically delivers a signed digest file that includes the hash of every log file delivered during that period and the hash of the previous digest. If anyone modifies or deletes a log after delivery, the hash stored in the next digest will not match, and the validation command will flag the discrepancy. This is the only option here that provides direct, detection-based integrity assurance for CloudTrail logs.

Why this answer

CloudTrail log file integrity validation uses SHA-256 hashing and RSA digital signatures to create digest files that let you verify log files have not been altered or deleted after delivery. It is the native CloudTrail feature designed specifically for tamper detection.

Exam trap

SCS-C02 often tests the confusion between encryption (confidentiality) and integrity validation (tamper detection) — candidates must not assume KMS encryption prevents log modification.

How to eliminate wrong answers

Option A is wrong because KMS server-side encryption protects confidentiality at rest but does not detect or prevent post-creation modification — an attacker with KMS access could still alter logs. Option C is wrong because S3 Object Lock provides WORM protection but is an S3 feature, not a CloudTrail integrity mechanism, and requires enabling on the bucket separately; it prevents deletion/overwrite but does not provide cryptographic verification of log integrity. Option D is wrong because CloudWatch Logs integration streams events for monitoring but does not validate the integrity of delivered CloudTrail log files.

198
MCQhard

A company has a multi-account AWS environment using AWS Organizations. The security team needs to enforce that all new S3 buckets created in any account in the organization are encrypted with a specific KMS key. Which approach should be used?

A.Set up AWS Config rules to detect non-compliant buckets
B.Apply a Service Control Policy (SCP) that denies s3:CreateBucket unless encryption is configured
C.Create an IAM role that requires encryption and attach it to all users
D.Use an S3 bucket policy with a condition for encryption
AnswerB

SCPs can deny actions based on conditions, enforcing encryption at creation time.

Why this answer

Service Control Policies (SCPs) in AWS Organizations can centrally deny the creation of S3 buckets unless specific encryption conditions are met. By using an SCP with a condition that requires `s3:x-amz-server-side-encryption-aws-kms-key-id` to match the specific KMS key ARN, the security team can enforce encryption at the organizational level, preventing any account from creating non-compliant buckets regardless of IAM permissions.

Exam trap

The trap here is that candidates often confuse detective controls (AWS Config) with preventive controls (SCPs), or mistakenly think S3 bucket policies can govern bucket creation, when in fact bucket policies only apply to operations on existing buckets.

How to eliminate wrong answers

Option A is wrong because AWS Config rules are detective, not preventive; they can detect non-compliant buckets after creation but cannot block the creation itself, leaving a window of non-compliance. Option C is wrong because IAM roles attached to users do not enforce encryption on S3 bucket creation across all accounts in the organization; users can still create buckets without encryption if they have direct S3 permissions or use other roles, and IAM roles cannot override permissions granted by other policies. Option D is wrong because S3 bucket policies are resource-based and apply only to existing buckets, not to the creation of new buckets; they cannot prevent a bucket from being created without encryption.

199
MCQhard

Refer to the exhibit. A security engineer applies this S3 bucket policy to an S3 bucket. The bucket contains sensitive data. What is the effect of this policy?

A.It allows anonymous users to upload objects.
B.It denies PutObject requests that are not using HTTPS.
C.It denies all PutObject requests to the bucket.
D.It enforces that all objects must be encrypted at rest.
AnswerB

With the condition key aws:SecureTransport set to false, the Deny effect triggers only when the request travels over plain HTTP. Since the Action is limited to s3:PutObject, only object uploads are blocked; other operations remain unaffected. The result is that any PUT request without TLS is rejected, effectively mandating HTTPS for uploads to the bucket while still allowing secure uploads to proceed.

Why this answer

The bucket policy uses a Deny effect with a condition on 'aws:SecureTransport' set to false, which blocks any PutObject request made over plain HTTP. Requests over HTTPS satisfy the condition (SecureTransport = true), so they are not denied by this statement. This is the standard pattern for enforcing encryption in transit for S3 uploads.

Exam trap

SCS-C02 often tests the confusion between encryption in transit (SecureTransport/HTTPS) and encryption at rest (SSE headers), so candidates pick the at-rest encryption option when the policy actually enforces TLS.

How to eliminate wrong answers

Option A is wrong because the policy explicitly denies requests, not allows anonymous uploads; there is no Allow statement granting public access. Option C is wrong because the Deny only applies when SecureTransport is false — HTTPS PutObject requests are permitted, so it does not deny all uploads. Option D is wrong because the policy conditions on transport security (HTTPS), not on encryption at rest; enforcing at-rest encryption requires conditions on 's3:x-amz-server-side-encryption'.

200
MCQhard

A security engineer reviews the above IAM policy attached to an IAM user. The user reports that they cannot download objects from the S3 bucket 'example-bucket' when connected from the office network (IP range 10.0.0.0/16). What is the most likely cause?

A.The bucket policy overrides the IAM policy
B.The policy does not allow the s3:GetObject action
C.The source IP condition does not match the user's actual IP address
D.The user is not assuming the correct IAM role
AnswerC

The policy condition uses the aws:SourceIp global condition key and requires the request to originate from 10.0.0.0/16, a private RFC 1918 CIDR range. IAM compares this against the actual source IP recorded in the request, so if the IAM user is connecting from outside that range—for example, from a public internet address—the condition fails. When a condition fails, the Allow statement is skipped and the request is implicitly denied.

Why this answer

The IAM policy includes a `Condition` block using `aws:SourceIp` that restricts allowed IP addresses to the range 10.0.0.0/16. If the user's actual office network IP address falls outside this range (e.g., due to NAT or a different subnet), the condition fails, and the `s3:GetObject` action is denied, even though the user has the necessary permissions in the `Action` field.

Exam trap

The trap here is that candidates may overlook the `Condition` block and assume the policy allows the action because `s3:GetObject` is listed, failing to realize that the source IP condition can override the allow even when the action is explicitly permitted.

How to eliminate wrong answers

Option A is wrong because bucket policies and IAM policies are evaluated together; an explicit deny in either will override an allow, but there is no bucket policy mentioned in the scenario, and the IAM policy itself is the likely cause of denial. Option B is wrong because the policy explicitly includes `s3:GetObject` in the `Action` list, so the action is allowed by the policy statement. Option D is wrong because the policy is directly attached to the IAM user, not requiring role assumption; the user is already operating under the attached policy.

201
Multi-Selecteasy

A company wants to allow only specific IP addresses to access an S3 bucket. Which two methods can achieve this? (Choose TWO.)

Select 2 answers
A.Use an IAM policy with a condition that limits access to specific IP addresses.
B.Configure a network ACL on the subnet that blocks traffic from all but specific IPs.
C.Enable VPC Flow Logs to filter traffic from specific IPs.
D.Attach a security group to the S3 bucket that allows traffic only from specific IPs.
E.Use an S3 bucket policy with a condition that limits access to specific IP addresses.
AnswersA, E

An IAM policy with a condition key such as aws:SourceIp is valid for restricting S3 actions to specific source IP addresses when the request originates from an authenticated principal. This identity-based policy attaches to IAM users, groups, or roles, and the condition is evaluated against the public IP address of the caller's client. It works for requests made over the internet, but note that when traffic comes through a VPC endpoint, aws:SourceIp is not available and aws:VpcSourceIp would be needed instead.

Why this answer

Option A is correct because an IAM policy can include a Condition element using the aws:SourceIp (or aws:SourceIp with NotIpAddress) key to allow or deny requests based on the requester's IP address, effectively restricting access to specific IPs for the identities the policy is attached to. Option E is correct because an S3 bucket policy is a resource-based policy that can also use the aws:SourceIp condition key to allow only specified IP addresses to access the bucket, which is the most direct way to enforce IP restrictions on the bucket itself. Option B is not correct because a network ACL operates at the subnet level and filters traffic by IP/port for resources in a VPC, but it cannot govern access to an S3 bucket endpoint (especially public S3 endpoints) and does not apply to bucket-level authorization.

Option C is not correct because VPC Flow Logs only capture and record IP traffic metadata for monitoring; they do not filter or block traffic. Option D is not correct because security groups are attached to network interfaces (such as EC2 instances) and cannot be attached to an S3 bucket, and S3 does not use security groups for access control.

Exam trap

The trap here is that candidates often confuse network ACLs or security groups with S3 access control, not realizing that S3 is a global service that does not reside within a VPC subnet and cannot have security groups attached.

202
MCQeasy

A company is designing a new AWS account structure using AWS Organizations. The security team wants to restrict the use of specific AWS services across all member accounts. Which feature should they use?

A.AWS Single Sign-On (SSO)
B.AWS CloudTrail
C.AWS Identity and Access Management (IAM) cross-account roles
D.Service control policies (SCPs)
AnswerD

Service control policies (SCPs) are an AWS Organizations feature that specify the maximum permission boundary for all IAM entities in the accounts, OUs, or root to which they are attached. By adding an SCP that denies or allows specific services, you can prevent member-account users and roots from using services outside the approved set, even if they have IAM policies that allow those actions. SCPs inherit down the organizational hierarchy and are evaluated as a top-level guardrail, making them the appropriate tool to restrict how teams use AWS services in a new account structure.

Why this answer

Service control policies (SCPs) are the correct feature because they allow you to centrally restrict which AWS services and actions are permitted across all member accounts in an AWS Organization. SCPs act as a permission guardrail that applies to all IAM users, roles, and root users within the affected accounts, enabling the security team to enforce service restrictions without modifying individual account configurations.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies, thinking IAM cross-account roles can enforce service restrictions, but SCPs are the only mechanism that applies globally across all users and roles in an AWS Organization.

How to eliminate wrong answers

Option A is wrong because AWS Single Sign-On (SSO) is a service for managing user access and authentication across multiple AWS accounts and applications, not for restricting service usage. Option B is wrong because AWS CloudTrail is a logging and monitoring service that records API activity, but it does not enforce or restrict which services can be used. Option C is wrong because IAM cross-account roles allow users in one account to assume roles in another account for access, but they do not provide a centralized mechanism to deny specific services across all accounts.

203
MCQeasy

A company wants to host a static website in an Amazon S3 bucket. The bucket must be private and accessible only through an Amazon CloudFront distribution. Which configuration ensures that CloudFront can access the S3 bucket while blocking direct access via S3 URL?

A.Use CloudFront signed URLs and configure the bucket policy to allow access from CloudFront IP ranges
B.Enable S3 Block Public Access and configure CloudFront to use the bucket as an origin
C.Configure the bucket policy to allow s3:GetObject from the CloudFront service principal
D.Create an Origin Access Control (OAC) and update the bucket policy to allow access only to the CloudFront distribution
AnswerD

Origin Access Control (OAC) is the recommended way to keep an S3 bucket private while allowing only CloudFront to retrieve objects. You create an OAC, associate it with the distribution's origin, and update the bucket policy to permit s3:GetObject for the cloudfront.amazonaws.com principal under a condition like aws:SourceArn that matches your specific distribution. This prevents direct S3 access via the bucket URL, supports SSE-KMS encryption, and works seamlessly with S3 Block Public Access for a least-privilege, secure static website architecture.

Why this answer

Origin Access Control (OAC) is the recommended way to secure an S3 origin for CloudFront. OAC allows CloudFront to sign requests to S3, and the bucket policy can be configured to allow access only from the specific CloudFront distribution using the OAC. This blocks direct access via S3 URL because the bucket policy does not grant public access.

Exam trap

The trap is confusing OAC with OAI or thinking that a bucket policy allowing the CloudFront service principal is enough; the key is that the policy must be tied to the specific distribution via OAC and condition keys.

How to eliminate wrong answers

Option A is wrong because using CloudFront signed URLs is for restricting access to content at the user level, not for securing the origin; also, allowing access from CloudFront IP ranges is not secure because those IPs can change and are shared. Option B is wrong because simply enabling S3 Block Public Access and using the bucket as an origin does not grant CloudFront access; the bucket would remain private and CloudFront would be denied unless you also configure OAC or OAI. Option C is wrong because allowing 's3:GetObject' from the CloudFront service principal alone is not sufficient; you need to specify the specific distribution and use OAC or OAI to authenticate the request.

204
Multi-Selectmedium

A security engineer is configuring a VPC for a three-tier application. The web tier must be accessible from the internet, the application tier must be accessible only from the web tier, and the database tier must be accessible only from the application tier. Which TWO security group configurations should be used? (Choose TWO.)

Select 2 answers
A.Allow inbound SSH from 0.0.0.0/0 on the web tier security group.
B.Allow inbound HTTP/HTTPS from 0.0.0.0/0 on the web tier security group.
C.Allow inbound HTTP/HTTPS from the web tier security group on the database tier security group.
D.Allow inbound HTTP/HTTPS from the web tier security group on the application tier security group.
E.Allow inbound HTTP/HTTPS from the internet on the database tier security group.
AnswersB, D

The web tier is the only component that needs to accept unsolicited traffic from the internet. By allowing HTTP/HTTPS from 0.0.0.0/0, you enable clients to reach the application via the public IP of the load balancer or the web servers. This is a standard and secure configuration because the web tier acts as the entry point that forwards requests to the application tier, and the other tiers remain hidden from direct internet access.

Why this answer

Option B is correct because the web tier is the only tier that must be reachable from the internet, so its security group should permit inbound HTTP (TCP 80) and HTTPS (TCP 443) from 0.0.0.0/0. Option D is correct because the application tier must be accessible only from the web tier, and referencing the web tier's security group as the source in the application tier's inbound rule enforces that tier-to-tier restriction. Option A is wrong because allowing SSH from 0.0.0.0/0 exposes the web tier to unrestricted remote administration and is not required by the scenario.

Option C is wrong because the database tier should accept traffic only from the application tier, not directly from the web tier. Option E is wrong because exposing the database tier to inbound HTTP/HTTPS from the internet violates the requirement that it be accessible only from the application tier.

Exam trap

The trap here is that candidates often confuse the direction of traffic flow and incorrectly apply security group rules to the wrong tier, such as allowing HTTP/HTTPS from the web tier directly to the database tier (Option C) instead of to the application tier, or they mistakenly open unnecessary ports like SSH (Option A) thinking it is needed for management, which violates the principle of least privilege.

205
Multi-Selectmedium

A security engineer is designing a VPC with public and private subnets. The application servers in the private subnets need to access the internet for software updates, but must not be directly reachable from the internet. Which TWO actions satisfy these requirements?

Select 2 answers
A.Configure the private subnet's security group to allow inbound traffic from 0.0.0.0/0.
B.Add a route in the private subnet's route table pointing to the NAT gateway.
C.Attach an internet gateway to the private subnet's route table.
D.Create a VPC gateway endpoint for Amazon S3.
E.Deploy a NAT gateway in a public subnet.
AnswersB, E

A NAT gateway performs source network address translation for outbound traffic, letting private subnet instances initiate internet connections for updates while remaining unreachable inbound. The private route table's 0.0.0.0/0 route to the NAT gateway satisfies both requirements.

Why this answer

Option B is correct because the private subnet's route table must contain a route (typically 0.0.0.0/0) targeting the NAT gateway so that outbound internet-bound traffic from private instances is forwarded through the NAT. Option E is correct because the NAT gateway itself must reside in a public subnet with a route to an internet gateway, allowing it to translate private instances' traffic to the internet while preventing inbound connections to those instances. Together, B and E provide outbound-only internet access for the private application servers.

Option A is wrong because allowing inbound 0.0.0.0/0 on the private subnet's security group would make the servers reachable from the internet, violating the requirement. Option C is wrong because attaching an internet gateway to a private subnet's route table would make the subnet public and expose the instances directly. Option D is wrong because a VPC gateway endpoint for Amazon S3 only provides private access to S3, not general internet access for software updates.

Exam trap

The trap here is that candidates often confuse a NAT gateway with an internet gateway, mistakenly thinking that adding an internet gateway to a private subnet's route table provides outbound-only access, when in fact it enables bidirectional internet connectivity and requires public IPs on the instances.

206
MCQeasy

A company wants to audit all changes to security group rules in their AWS account. Which AWS service should be used to record these changes?

A.Amazon CloudWatch Logs.
B.AWS CloudTrail.
C.VPC Flow Logs.
D.AWS Config.
AnswerB

AWS CloudTrail is the service designed to record AWS API activity, and it captures every security group change as an API event such as AuthorizeSecurityGroupIngress, RevokeSecurityGroupIngress, AuthorizeSecurityGroupEgress, RevokeSecurityGroupEgress, CreateSecurityGroup, or DeleteSecurityGroup. Each event includes the identity of the caller, the source IP address, the request parameters, and the response elements, giving a complete audit trail of who changed what and when. This makes CloudTrail the appropriate service for auditing all changes to security group rules.

Why this answer

AWS CloudTrail is the correct service because it records API calls made to the AWS environment, including changes to security group rules via the EC2 AuthorizeSecurityGroupIngress, RevokeSecurityGroupIngress, AuthorizeSecurityGroupEgress, and RevokeSecurityGroupEgress API actions. These events are captured as management events in CloudTrail, providing a complete audit trail of who made the change, when, from which IP address, and the exact parameters of the rule modification.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks resource configuration state) with CloudTrail (which tracks API activity), leading them to select AWS Config because they think 'audit changes' means monitoring the current state of rules, but the question specifically asks for recording the changes themselves, which requires API-level logging.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs is a service for storing, monitoring, and accessing log files from AWS resources, but it does not natively capture API-level changes to security group rules; it would require custom integration or agent-based logging. Option C is wrong because VPC Flow Logs capture metadata about network traffic (IP addresses, ports, protocols) flowing through ENIs, not the configuration changes to security group rules themselves. Option D is wrong because AWS Config evaluates and records resource configuration changes over time, but it is not the primary service for auditing API calls; CloudTrail is the service that records the API actions that trigger those configuration changes, while AWS Config focuses on the resulting state.

207
MCQmedium

A company has a requirement to log all network traffic flowing through a VPC, including traffic between EC2 instances within the same subnet. Which AWS service should be used?

A.VPC Flow Logs
B.Amazon GuardDuty
C.AWS Config
D.AWS CloudTrail
AnswerA

VPC Flow Logs is the only option that captures network traffic itself. It records flow metadata for every accepted and rejected connection at the VPC, subnet, or elastic network interface (ENI) level, including intra-subnet traffic between instances. The logs contain source/destination addresses, source/destination ports, protocol, packets, bytes, and the connection action, and can be published to CloudWatch Logs or Amazon S3 for analysis. While it captures flow metadata rather than packet payloads, it fully meets a requirement to log all network traffic for audit and troubleshooting.

Why this answer

VPC Flow Logs capture IP traffic information for network interfaces in a VPC, including traffic between EC2 instances within the same subnet, and can be published to CloudWatch Logs or S3. It is the only AWS service listed that provides packet-level metadata for all traffic flowing through VPC network interfaces.

Exam trap

SCS-C02 often tests the confusion between VPC Flow Logs (network traffic metadata), CloudTrail (API activity), and GuardDuty (threat detection), tricking candidates into selecting CloudTrail for network-level logging.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes logs (including VPC Flow Logs) for malicious activity — it does not itself log network traffic. Option C is wrong because AWS Config records resource configuration changes and evaluates compliance against rules; it does not capture network traffic. Option D is wrong because AWS CloudTrail logs API activity (who called which AWS API), not network traffic flowing through a VPC.

208
MCQeasy

A company has an Amazon RDS for MySQL database in a private subnet. The security team wants to ensure that only an application server in the same VPC can connect to the database. Which security group configuration should be used?

A.Inbound rule on the RDS security group: allow MySQL on port 3306 from the VPC's CIDR.
B.Inbound rule on the RDS security group: allow MySQL on port 3306 from the subnet CIDR of the application server.
C.Inbound rule on the RDS security group: allow MySQL on port 3306 from the security group ID of the application server.
D.Inbound rule on the application server's security group: allow outbound MySQL to the RDS security group.
AnswerC

Setting the source of the RDS security group's inbound rule to the application server's security group ID restricts MySQL access to only those instances whose network interfaces are associated with that security group, regardless of their IP addresses. This is the recommended least-privilege pattern because it ties the rule to a logical group of resources rather than a static IP range, so the rule remains valid if the application server's private IP changes. It also prevents any unrelated VPC or subnet resource from reaching the database, as only resources carrying that specific security group are allowed.

Why this answer

Referencing the application server's security group ID as the source in the inbound rule for MySQL (port 3306) on the RDS security group allows traffic only from instances that are members of that security group, regardless of their IP addresses. This is the most secure and precise method, as it automatically adapts to changes in the application server's IP (e.g., after scaling or replacement) and avoids opening the database to the entire subnet or VPC CIDR.

Exam trap

The trap here is that candidates often confuse inbound vs. outbound rules or mistakenly think that allowing a subnet CIDR is equivalent to allowing a specific instance, when in fact security group ID-based rules provide instance-level granularity and are the recommended approach for this use case.

How to eliminate wrong answers

Option A is wrong because allowing the VPC's CIDR on port 3306 would permit any resource in the VPC (including unauthorized instances, Lambda functions in the same VPC, or even compromised hosts) to connect to the database, violating the principle of least privilege. Option B is wrong because allowing the subnet CIDR of the application server still opens the database to all instances in that subnet, not just the specific application server, and does not protect against lateral movement within the subnet. Option D is wrong because it configures an outbound rule on the application server's security group, which controls traffic leaving the application server, not inbound access to the RDS instance; the RDS security group's inbound rules are what enforce which sources can connect to the database.

209
MCQeasy

A company wants to ensure that all data in transit between its EC2 instances and an RDS database is encrypted. The instances and the database are in the same VPC. Which configuration step is necessary to achieve this?

A.Enable encryption at rest for the RDS instance using AWS KMS.
B.Set up a VPN connection between the EC2 instances and the RDS database.
C.Configure the security group for the RDS instance to enforce encryption.
D.Enable SSL/TLS on the RDS instance and configure the EC2 instances to connect using SSL.
AnswerD

Enabling SSL/TLS on the RDS instance makes the database server accept and require encrypted connections, and configuring the EC2 clients to connect with SSL (for example, using sslmode=require or verify-full in PostgreSQL, or useSSL=true in MySQL) encrypts all data in flight between the application and the database. RDS provides server certificates for each region that clients can validate to prevent man-in-the-middle attacks. This directly satisfies the requirement that all data in transit be encrypted.

Why this answer

To encrypt data in transit between EC2 instances and an RDS database within the same VPC, you must enable SSL/TLS on the RDS instance and configure the EC2 instances to connect using SSL. This ensures that the network traffic is encrypted at the transport layer, protecting against eavesdropping or man-in-the-middle attacks. AWS RDS supports SSL/TLS for most database engines, and the client must explicitly request an encrypted connection.

Exam trap

The trap here is that candidates often confuse encryption at rest (Option A) with encryption in transit, or assume that security groups (Option C) can enforce encryption, when in fact they only filter traffic at the network layer.

How to eliminate wrong answers

Option A is wrong because encryption at rest protects data stored on disk, not data in transit over the network. Option B is wrong because a VPN connection is unnecessary and irrelevant when both resources are in the same VPC; VPNs are used for hybrid connectivity, not for intra-VPC traffic encryption. Option C is wrong because security groups are stateful firewalls that control traffic based on IP addresses and ports, not encryption protocols; they cannot enforce or negotiate SSL/TLS encryption.

210
MCQeasy

A company wants to protect its Amazon EC2 instances from distributed denial-of-service (DDoS) attacks at the network layer. Which AWS service should be used?

A.Amazon CloudFront
B.Amazon GuardDuty
C.AWS Shield Advanced
D.AWS WAF
AnswerC

AWS Shield Advanced is purpose-built for DDoS protection, providing enhanced always-on detection and automatic inline mitigation for network-layer (L3/L4) attacks such as SYN floods and UDP reflection. It works by absorbing attack traffic and rerouting it to AWS's global scrubbing infrastructure while maintaining availability of protected resources like EC2 instances. Advanced also adds cost protection (DDoS-induced spikes are charged back as credits), access to the AWS DDoS Response Team (DRT), and integration with AWS WAF for additional Layer 7 defense. This is the service designed to directly protect EC2 from DDoS attacks.

Why this answer

AWS Shield Advanced provides enhanced protections for Amazon EC2 instances against network-layer (Layer 3/4) DDoS attacks, such as SYN floods, UDP reflection attacks, and other volumetric attacks. It includes always-on traffic monitoring, automated mitigation, and access to the DDoS Response Team (DRT) for custom mitigations, making it the correct choice for network-layer DDoS protection.

Exam trap

The trap here is that candidates often confuse AWS WAF (Layer 7) with network-layer DDoS protection, or assume Amazon CloudFront's edge caching alone is sufficient for all DDoS types, but Shield Advanced is the specific service designed for comprehensive network-layer (Layer 3/4) DDoS mitigation.

How to eliminate wrong answers

Option A is wrong because Amazon CloudFront is a content delivery network (CDN) that primarily protects against application-layer (Layer 7) attacks and provides edge-based DDoS mitigation, but it does not offer dedicated network-layer DDoS protection for EC2 instances directly. Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events to identify malicious activity, but it does not actively mitigate or block DDoS attacks at the network layer. Option D is wrong because AWS WAF is a web application firewall that operates at Layer 7 (HTTP/HTTPS) to filter malicious requests like SQL injection or cross-site scripting, and it cannot mitigate network-layer (Layer 3/4) attacks such as SYN floods or UDP amplification.

211
MCQhard

A company's security team wants to detect and block malicious SQL injection attempts against an Application Load Balancer. Which AWS service should be used?

A.AWS WAF
B.Amazon GuardDuty
C.Amazon Inspector
D.AWS Shield Advanced
AnswerA

AWS WAF is a Layer 7 web application firewall that you can associate with an Application Load Balancer to inspect incoming HTTP(S) requests. It uses managed rule groups, such as the AWS Managed Rules for SQL injection (SQLi_RULE), to match request patterns like malicious query strings, bodies, or headers. When a rule matches, WAF can immediately block the request, return a custom response, or count it, providing inline detection and blocking at the ALB. This is exactly what the security team needs for identifying and stopping SQL injection attempts before they reach the application.

Why this answer

AWS WAF is a web application firewall that can be associated with an Application Load Balancer to inspect HTTP/HTTPS requests for malicious patterns, such as SQL injection attempts. It uses managed rule sets (e.g., AWS Managed Rules for SQL injection) to detect and block these attacks in real time, making it the correct choice for this use case.

Exam trap

The trap here is that candidates often confuse GuardDuty's threat detection (which covers network and account-level anomalies) with application-layer attack detection, or assume Shield Advanced's DDoS protection includes web application firewall capabilities.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events for anomalous behavior, but it does not inspect or block application-layer requests like SQL injection at the ALB level. Option C is wrong because Amazon Inspector is a vulnerability assessment service that scans EC2 instances and container images for software vulnerabilities and network exposure, not for detecting or blocking live web application attacks. Option D is wrong because AWS Shield Advanced provides DDoS protection against volumetric and state-exhaustion attacks, but it does not include application-layer inspection for SQL injection payloads.

212
Multi-Selectmedium

Which TWO of the following are valid methods to protect sensitive data in transit between an on-premises data center and AWS? (Select TWO.)

Select 2 answers
A.AWS Transit Gateway
B.AWS Site-to-Site VPN
C.Internet Gateway
D.VPC Peering
E.AWS Direct Connect with IPSec VPN
AnswersB, E

AWS Site-to-Site VPN creates an encrypted IPsec tunnel between your on-premises VPN device and the AWS VPN endpoint, using protocols like IKE and ESP to authenticate and encrypt all traffic traversing the public internet. The VPN tunnels support AES-128 or AES-256 encryption, along with perfect forward secrecy, ensuring confidentiality and data integrity. This native AWS service directly provides secure encryption of data in transit between your network and the VPC, making it a valid method to protect sensitive data.

Why this answer

AWS Site-to-Site VPN (Option B) creates an encrypted tunnel between an on-premises VPN device and a Virtual Private Gateway in AWS, using IPSec to protect data in transit. This ensures confidentiality and integrity of data crossing the public internet, making it a valid method for securing sensitive data between an on-premises data center and AWS.

Exam trap

The trap here is that candidates often assume AWS Transit Gateway or VPC Peering inherently encrypt traffic, but they do not; encryption must be explicitly added via VPN or Direct Connect with IPSec, and the exam tests this distinction between connectivity and encryption.

213
MCQeasy

A company wants to provide temporary security credentials to users accessing AWS resources from a mobile app. Which AWS service should they use?

A.AWS Signer
B.AWS Directory Service
C.Amazon Cognito Identity Pools (Federated Identities)
D.AWS IAM roles for cross-account access
AnswerC

Amazon Cognito Identity Pools are built specifically to trade identity tokens from any public or custom identity provider for temporary, least-privilege AWS credentials. The service assigns an IAM role per authenticated or guest user, and returns credentials with a short expiration that map to permissions defined in that role. This makes them the standard choice for mobile and web apps that need direct AWS API access without embedding long-term keys on devices.

Why this answer

Amazon Cognito Identity Pools (Federated Identities) allow you to create unique identities for your users and federate them with identity providers. With an identity pool, you can obtain temporary, limited-privilege AWS credentials to access other AWS services. This is the correct service for providing temporary security credentials to users accessing AWS resources from a mobile app.

Option A (AWS Signer) is for code signing, not temporary credentials. Option B (AWS Directory Service) is for managing Microsoft Active Directory, not for generating temporary credentials. Option D (AWS IAM roles for cross-account access) is for granting access between AWS accounts, not for mobile app users.

214
MCQhard

A company uses AWS Shield Advanced to protect its web application against DDoS attacks. The application is behind an Application Load Balancer (ALB) with a web application firewall (AWS WAF) in front. The security team notices that some requests are being blocked by AWS WAF, but the source IP addresses are legitimate customers. What step should the team take to minimize false positives?

A.Implement rate-based rules with a count action and use the count data to create custom rules.
B.Switch to using AWS Managed Rules for IP reputation lists.
C.Increase the WAF rate-based rule threshold to allow more requests.
D.Reconfigure the ALB idle timeout to a higher value.
AnswerA

Use a rate-based rule in COUNT mode so WAF evaluates the request rate and increments the relevant counters without blocking traffic. This exposes the per-IP distribution in CloudWatch metrics and sampled requests, letting you determine a burst threshold that separates human usage from automated floods. The count data then informs a custom rule (e.g., with an aggregate key or scope-down statement) that blocks only when the observed rate genuinely exceeds your normal baseline, minimizing false positives.

Why this answer

Rate-based rules with a count action allow the team to monitor request patterns without blocking legitimate traffic. The count action logs matching requests, enabling analysis to create custom rules that accurately distinguish between malicious and legitimate traffic. This approach minimizes false positives by basing rule logic on observed data rather than static thresholds.

Exam trap

SCS-C02 often tests the misconception that increasing thresholds or using managed rules directly solves false positives, but the key is to first monitor with count mode to gather data before making blocking decisions.

How to eliminate wrong answers

Option B is wrong because AWS Managed Rules for IP reputation lists block based on known malicious IPs, but legitimate customers may be falsely flagged if their IPs are misclassified or shared, and this doesn't address the root cause of false positives from rate-based rules. Option C is wrong because simply increasing the rate-based rule threshold may allow more malicious traffic through and doesn't solve the false positive issue for legitimate customers who might still exceed the new threshold. Option D is wrong because ALB idle timeout is unrelated to WAF false positives; it controls connection persistence and has no impact on request blocking decisions.

215
Multi-Selectmedium

A security engineer is designing a VPC with public and private subnets. The private subnets must be able to download software updates from the internet. Which TWO components can provide this functionality without exposing the private instances to inbound internet traffic?

Select 2 answers
A.NAT gateway
B.Internet gateway
C.VPC endpoint
D.Egress-only internet gateway
E.NAT instance
AnswersA, E

A NAT gateway is a fully managed AWS service that performs source network address translation, replacing private IPv4 addresses with its own Elastic IP for outbound internet traffic. Because it is stateful, it automatically drops any unsolicited inbound connections initiated from the internet, so it satisfies the security requirement of blocking inbound while enabling outbound. It also scales automatically and requires no patching or maintenance, making it the recommended choice.

Why this answer

A NAT gateway is a managed AWS service that enables instances in a private subnet to initiate outbound traffic to the internet (e.g., for downloading software updates) while preventing the internet from initiating inbound connections to those instances. It translates the private IP addresses of the instances to the NAT gateway's Elastic IP address, allowing return traffic to be routed back correctly. This meets the requirement of outbound-only internet access without exposing private instances to inbound traffic.

Exam trap

The trap here is that candidates often confuse NAT gateway with internet gateway, assuming both provide outbound-only access, but the internet gateway is bidirectional and would expose private instances to inbound traffic if used directly.

216
MCQeasy

A security engineer is configuring a security group for a web server that should only accept HTTPS traffic from the internet. Which inbound rule should be set?

A.TCP port 3389 from 0.0.0.0/0
B.TCP port 22 from 0.0.0.0/0
C.TCP port 80 from 0.0.0.0/0
D.TCP port 443 from 0.0.0.0/0
AnswerD

Port 443 is HTTPS, the default port for encrypted web traffic using TLS. Because the instance is intended to serve a public website, allowing inbound TCP 443 from 0.0.0.0/0 lets internet clients reach the service securely while security groups remain stateful, automatically permitting return traffic. This rule aligns with the stated requirement and is the correct enablement for a web server receiving secure browser connections.

Why this answer

HTTPS uses TCP port 443, so an inbound security group rule allowing TCP 443 from 0.0.0.0/0 permits HTTPS traffic from any internet source. This is the standard configuration for a public web server that must accept secure web traffic. Security groups are stateful, so return traffic is automatically allowed without an outbound rule.

Exam trap

SCS-C02 often tests port-number recall under time pressure — candidates confuse 443 (HTTPS) with 80 (HTTP) or pick 22/3389 thinking 'secure' means SSH/RDP, when the question specifically asks for HTTPS.

How to eliminate wrong answers

Option A is wrong because TCP 3389 is RDP (Remote Desktop Protocol) for Windows — exposing it to 0.0.0.0/0 is a critical security risk and unrelated to HTTPS. Option B is wrong because TCP 22 is SSH for Linux administration — again a dangerous public exposure and not HTTPS. Option C is wrong because TCP 80 is unencrypted HTTP, not HTTPS; allowing it would permit plaintext web traffic, violating the requirement for HTTPS only.

217
MCQeasy

A company wants to allow an EC2 instance to access an S3 bucket without exposing the instance to the internet. Which AWS service should be used to achieve this?

A.NAT Gateway
B.AWS Site-to-Site VPN
C.Internet Gateway
D.VPC Endpoint (Gateway type) for S3
AnswerD

A gateway VPC endpoint for S3 is the correct solution because it provides private connectivity from the VPC to S3 without requiring an Internet Gateway, NAT Gateway, or public IP address. It is implemented as a route-table entry using a prefix list for S3, directing traffic to the S3 service over the AWS private network. This endpoint does not incur per-hour or data-processing charges, and it keeps traffic entirely within AWS, satisfying both security and cost-efficiency requirements.

Why this answer

A VPC Endpoint (Gateway type) for S3 allows EC2 instances within a VPC to access S3 buckets privately using AWS's internal network, without traversing the internet. This is achieved by adding an endpoint route in the VPC route table that directs S3 traffic to the endpoint, which uses AWS's private infrastructure. It eliminates the need for an internet gateway, NAT gateway, or VPN connection, ensuring the instance remains isolated from the public internet.

Exam trap

The trap here is that candidates often confuse Gateway Endpoints with Interface Endpoints (powered by AWS PrivateLink) and incorrectly assume a NAT Gateway is required for private subnet access, but Gateway Endpoints are specifically designed for S3 and DynamoDB and do not require any additional infrastructure.

How to eliminate wrong answers

Option A is wrong because a NAT Gateway enables outbound internet access for private instances but still routes traffic through the internet, exposing the instance to potential risks and incurring data transfer costs. Option B is wrong because AWS Site-to-Site VPN connects on-premises networks to a VPC over the internet, but it does not provide private access to S3 from within the VPC without internet egress. Option C is wrong because an Internet Gateway allows bidirectional internet traffic, which would expose the EC2 instance to the internet, violating the requirement to keep it isolated.

218
MCQmedium

A company's security engineer is configuring a web application firewall (WAF) to protect a public-facing Application Load Balancer (ALB). The application is vulnerable to SQL injection attacks. Which AWS WAF rule should be used to mitigate this threat?

A.Add a rule to block cross-site scripting (XSS) attacks.
B.Add a rule from the AWS Managed Rules for SQL injection.
C.Add a rate-based rule to limit requests per IP.
D.Add a geographic match rule to block traffic from specific countries.
AnswerB

AWS WAF's AWSManagedRulesSQLiRuleSet is a managed rule group specifically designed to detect and block SQL injection attempts by inspecting request components such as query strings, body, and headers. It uses curated signatures and pattern-matching to catch syntactic SQLi payloads, and you can associate it with your web ACL on the Application Load Balancer, CloudFront, or API Gateway. Enabling this rule directly addresses the reported vulnerability.

Why this answer

AWS WAF includes managed rule groups specifically designed to detect and block SQL injection attacks by inspecting request parameters, URIs, and headers for malicious SQL patterns. This directly addresses the vulnerability described in the scenario, as SQL injection targets the application's database layer through crafted input.

Exam trap

The trap here is that candidates may confuse SQL injection with XSS because both involve input validation, but AWS WAF treats them as distinct managed rule groups with separate inspection logic and signatures.

How to eliminate wrong answers

Option A is wrong because cross-site scripting (XSS) rules target script injection into web pages, not SQL injection into database queries, and the two attack vectors use different payload patterns and inspection points. Option C is wrong because rate-based rules limit request volume per IP to mitigate DDoS or brute-force attacks, but they do not inspect request content for SQL injection signatures. Option D is wrong because geographic match rules block traffic based on country of origin, which is irrelevant to SQL injection payloads that can originate from any location.

219
MCQeasy

A company wants to restrict access to an S3 bucket so that only requests from a specific VPC are allowed. Which policy should be used?

A.Security group assigned to the S3 bucket
B.IAM policy with aws:SourceIp condition
C.S3 bucket policy with aws:SourceVpc condition
D.Network ACL attached to the S3 bucket
AnswerC

An S3 bucket policy with an aws:SourceVpc condition is the correct way to restrict access to requests originating from a specific VPC. This condition evaluates the VPC ID of the requester, which is available when the request comes through a VPC gateway endpoint (service: s3). It is a resource-based policy, meaning it applies directly to the S3 bucket regardless of which IAM principal makes the request, and is a standard pattern for keeping buckets private to a particular VPC.

Why this answer

S3 bucket policies support the `aws:SourceVpc` condition key, which allows you to restrict access to requests originating from a specific VPC. This works by evaluating the VPC ID from which the request was made, using the source VPC information that AWS automatically includes in requests from VPC endpoints. No other mechanism (security groups, IAM source IP conditions, or network ACLs) can directly enforce VPC-level access control on S3.

Exam trap

The trap here is that candidates often confuse network-level controls (security groups, NACLs) with service-level controls (bucket policies) and assume that S3 can be protected like an EC2 instance, when in fact S3 only supports bucket policies and IAM policies for access control.

How to eliminate wrong answers

Option A is wrong because security groups are network-level firewalls for EC2 instances and cannot be assigned to S3 buckets; S3 is a managed service that does not support security group attachments. Option B is wrong because `aws:SourceIp` condition in IAM policies checks the originating IP address, not the VPC, so it cannot restrict access based on VPC membership and would not work for traffic from a VPC endpoint where the source IP is internal. Option D is wrong because network ACLs are stateless firewalls attached to subnets, not to S3 buckets, and they cannot control access to S3 at the bucket level.

220
MCQhard

A Security Engineer is designing a network architecture for a multi-tier application. The web tier must be accessible from the internet, while the application tier should only be accessible from the web tier, and the database tier only from the application tier. All tiers are in the same VPC. Which configuration meets these requirements with minimal administrative overhead?

A.Use network ACLs with inbound rules that reference the prefix list of the previous tier's subnets.
B.Use network ACLs with inbound rules that allow traffic from the previous tier's subnet CIDR.
C.Use security groups with inbound rules that allow traffic from the previous tier's public IP addresses.
D.Use security groups with inbound rules that reference the security group of the previous tier.
AnswerD

Referencing the previous tier's security group as the source in an inbound rule is the correct approach because security groups are stateful and allow logical references to other security groups, not just IP addresses. When you assign an instance to the source security group, it automatically becomes allowed to reach the target tier, even if its IP address changes or new instances are added. This eliminates the need to manage CIDR blocks or public IPs and keeps security policies tightly aligned with architectural tiers. It is the AWS-recommended pattern for multi-tier security group design.

Why this answer

Security groups are stateful and can reference other security groups as a source in inbound rules, allowing traffic from any instance associated with the referenced security group regardless of IP address changes. This creates a logical dependency chain (web SG → app SG → db SG) that enforces the required tier-to-tier access with zero maintenance when instances scale or subnets change. Option D meets the requirement with minimal administrative overhead because security group references automatically adapt to dynamic environments.

Exam trap

The trap here is that candidates confuse network ACLs with security groups, assuming stateless ACLs can use logical references like security group IDs, or they overlook the administrative overhead of managing CIDR-based rules in dynamic architectures.

How to eliminate wrong answers

Option A is wrong because network ACLs are stateless and cannot reference prefix lists of subnets as a source in inbound rules; they only support CIDR blocks, IP ranges, or protocol/port numbers. Option B is wrong because network ACLs require explicit allow and return traffic rules (stateless), and using subnet CIDRs creates administrative overhead when subnets change or scale, plus they cannot dynamically follow instances that move between subnets. Option C is wrong because referencing public IP addresses is fragile (IPs can change with scaling or NAT), violates the principle of using private addressing within a VPC, and adds administrative burden to track and update IPs.

221
MCQhard

A company uses AWS CloudFormation to deploy infrastructure. The security team wants to ensure that all CloudFormation stacks include a specific tag "Environment" with a value of "Production" or "Development". Which approach should be used?

A.Use AWS CloudFormation Guard to validate that the template includes the required tag with allowed values.
B.Apply an IAM policy that requires the tag on all CloudFormation actions.
C.Use AWS Config to detect and automatically remediate non-compliant stacks.
D.Create an SCP to deny CloudFormation stacks that do not have the required tag.
AnswerA

AWS CloudFormation Guard is a policy-as-code engine that parses and evaluates a template's structure before deployment, allowing you to assert that every resource includes a specific tag key with an allowed value. This validation is proactive, occurring in the CI/CD pipeline prior to stack creation, so non-compliant templates are rejected before any infrastructure exists. Guard rules are written in a simple DSL and can be enforced alongside other template checks, making it the only option that directly inspects the template content rather than relying on API request conditions.

Why this answer

AWS CloudFormation Guard (cfn-guard) is a policy-as-code tool that allows you to define rules to validate CloudFormation templates before they are used to create or update stacks. By writing a Guard rule that checks for the 'Environment' tag with allowed values of 'Production' or 'Development', you can enforce this requirement at the template level, preventing non-compliant stacks from being deployed. This approach is proactive, catching violations during the authoring or CI/CD pipeline stage rather than after deployment.

Exam trap

The trap here is that candidates confuse AWS CloudFormation Guard (a pre-deployment validation tool) with AWS Config (a post-deployment compliance service), or mistakenly believe that IAM policies or SCPs can enforce resource-level tags on CloudFormation stacks, when in fact they only control API request parameters.

How to eliminate wrong answers

Option B is wrong because IAM policies control who can perform actions (e.g., CreateStack) but cannot enforce specific tag keys or values on resources created by CloudFormation; IAM conditions like 'aws:RequestTag' only apply to tagging actions on the API call itself, not to tags on the resulting stack resources. Option C is wrong because AWS Config can detect non-compliant stacks after they are created and trigger remediation (e.g., via Systems Manager Automation), but it is reactive and does not prevent the initial deployment of non-compliant stacks. Option D is wrong because Service Control Policies (SCPs) are applied at the AWS Organizations level to restrict permissions for accounts, but they cannot enforce tags on CloudFormation stacks; SCPs can only deny API actions based on request parameters, not validate tags on resources after creation.

222
MCQmedium

Refer to the exhibit. A security engineer runs the above command and sees the security group configuration. Based on the output, which statement is correct?

A.The security group has no outbound rules.
B.The security group allows SSH access from any IP address.
C.The security group allows HTTP traffic from the internet.
D.The security group is associated with multiple EC2 instances.
AnswerC

The rule permits TCP port 80 from 0.0.0.0/0, so any host on the internet can reach the group's instances over unencrypted HTTP. That source range is the axis distinguishing public exposure from a restricted CIDR.

Why this answer

The security group output shows an inbound rule permitting HTTP (TCP port 80) from 0.0.0.0/0, which means any internet source can reach the instance on port 80. That is the definition of allowing HTTP traffic from the internet. The other statements either misread the output or describe attributes (outbound rules, instance associations) that are not determinable from the rule listing alone.

Exam trap

The trap is reading a security group rule listing and inferring properties that are not actually shown — such as outbound rules or instance associations — or confusing the port in the rule (80) with a different service (SSH/22).

How to eliminate wrong answers

Option A is wrong because security groups in AWS are stateful and include a default allow-all outbound rule unless it has been explicitly removed; the exhibit does not show the outbound rules, so claiming there are none is unsupported. Option B is wrong because the rule shown is for port 80 (HTTP), not port 22 (SSH); SSH access from any IP would require a separate inbound rule for TCP/22 from 0.0.0.0/0, which is not present in the output. Option D is wrong because a security group's rule listing does not reveal how many EC2 instances are associated with it; that information comes from the instance's network interface configuration, not the group's rule set.

223
MCQeasy

A company runs a web application on EC2 instances in an Auto Scaling group across two Availability Zones. The instances are behind an Application Load Balancer. The security team wants to ensure that only the ALB can send traffic to the instances. The instances are in a security group named 'app-sg'. Currently, 'app-sg' has an inbound rule allowing HTTP traffic from 0.0.0.0/0. The team wants to restrict access to only the ALB's security group. The ALB is in a security group named 'alb-sg'. Which course of action should the security engineer take to meet the requirement with minimal disruption?

A.Modify the inbound rule of 'app-sg' to allow HTTP traffic from the private IP addresses of the ALB nodes.
B.Modify the inbound rule of 'app-sg' to allow HTTPS traffic from 0.0.0.0/0 and remove the HTTP rule.
C.Modify the inbound rule of 'app-sg' to allow HTTP traffic from the ALB's elastic network interface (ENI).
D.Modify the inbound rule of 'app-sg' to allow HTTP traffic from security group 'alb-sg'.
AnswerD

Setting the source of the app-sg inbound rule to the alb-sg security group creates an identity-based dependency: only traffic originating from network interfaces associated with alb-sg is permitted. This automatically accommodates ALB node IP changes and scale events because AWS resolves the security group relationship in the VPC. It is a best practice for internal load-balanced architectures and is preferred over CIDR/ENI references since it remains valid across AZs and lifecycle changes.

Why this answer

Security groups can reference each other by ID, allowing traffic from any instance associated with the source security group (alb-sg) without needing to know the ALB's IP addresses. This ensures that only the ALB can send HTTP traffic to the EC2 instances, as the rule dynamically applies to all ALB nodes across Availability Zones. It also minimizes disruption because no IP changes are required, and the rule automatically scales with the ALB.

Exam trap

The trap here is that candidates may think they need to use the ALB's private IP addresses or ENI details, but AWS security groups support referencing other security groups by ID, which is the correct and scalable method for this use case.

How to eliminate wrong answers

Option A is wrong because ALB nodes use elastic network interfaces (ENIs) with private IPs that can change during scaling or replacement, making this approach brittle and requiring constant updates; it also violates the principle of using security group references for dynamic environments. Option B is wrong because allowing HTTPS from 0.0.0.0/0 still permits traffic from any source, failing to restrict access to only the ALB, and removing the HTTP rule does not address the requirement. Option C is wrong because referencing an ALB's ENI is not a valid security group rule source; security groups can only reference other security groups or CIDR blocks, not specific ENIs.

224
MCQeasy

A company has an S3 bucket that contains sensitive data. The security team wants to ensure that all access to the bucket is encrypted in transit. Which policy should be attached to the bucket to enforce this?

A.Configure a bucket policy that denies requests that do not include the x-amz-server-side-encryption header.
B.Attach a bucket policy that denies requests when aws:SecureTransport is false.
C.Enable default encryption on the bucket using SSE-S3.
D.Use Amazon CloudFront to serve the content and require HTTPS.
AnswerB

The aws:SecureTransport condition key is a boolean that is true only when the request is made over SSL/TLS. By attaching a bucket policy with a Deny effect when aws:SecureTransport is false, the bucket rejects every HTTP request and only allows HTTPS requests. This enforces encryption in transit for all S3 operations, including direct API calls from any client or SDK, making it the correct solution.

Why this answer

The `aws:SecureTransport` condition key in an S3 bucket policy evaluates whether the request was sent over HTTPS (TLS). By attaching a bucket policy that denies access when `aws:SecureTransport` is false, the security team enforces that all access to the bucket must be encrypted in transit, blocking any HTTP requests.

Exam trap

The trap here is confusing encryption in transit (HTTPS/TLS) with encryption at rest (SSE headers or default encryption), leading candidates to pick options that enforce server-side encryption instead of transport-layer security.

How to eliminate wrong answers

Option A is wrong because the `x-amz-server-side-encryption` header is used to enforce encryption at rest (server-side encryption), not encryption in transit; it does not control whether the connection uses HTTPS. Option C is wrong because enabling default encryption on the bucket (e.g., SSE-S3) only encrypts objects at rest in S3, not the data in transit between the client and S3. Option D is wrong because while CloudFront with HTTPS can enforce encryption in transit for content delivery, it does not apply to direct S3 bucket access via the S3 API or other endpoints; the bucket policy itself must enforce the condition.

225
MCQeasy

A company wants to ensure that all traffic to and from an Amazon RDS instance is encrypted in transit. Which solution should the security engineer implement?

A.Enable encryption at rest using AWS KMS.
B.Configure the database to require SSL/TLS connections and modify clients to connect using SSL.
C.Use an S3 bucket policy to enforce encryption in transit for all S3 traffic.
D.Use an AWS Transit Gateway to route traffic through a central VPC.
AnswerB

RDS natively supports SSL/TLS for encrypting the connection between a client and your database. You must set the database parameter group to require a secure connection (for example, 'require_secure_transport=ON' for MySQL, or use the rds-force-ssl-parameter for PostgreSQL) and then modify your application's connection string to use SSL mode, pointing to the RDS CA certificate. This ensures that all SQL queries, result sets, and authentication data are encrypted in transit, directly satisfying the requirement.

Why this answer

Encrypting data in transit for Amazon RDS requires enabling SSL/TLS on the database instance and configuring client connections to use SSL/TLS. This ensures that all traffic between the client and the RDS instance is encrypted using TLS protocols, protecting against eavesdropping and man-in-the-middle attacks. Amazon RDS supports SSL/TLS for all database engines, and you can enforce SSL connections by setting the 'require_secure_transport' parameter (MySQL) or similar parameters for other engines.

Exam trap

The trap here is that candidates confuse encryption at rest (KMS) with encryption in transit (SSL/TLS), leading them to select Option A, which does not address network traffic encryption.

How to eliminate wrong answers

Option A is wrong because encryption at rest using AWS KMS protects data stored on disk, not data in transit; it does not encrypt network traffic between clients and the RDS instance. Option C is wrong because an S3 bucket policy enforces encryption in transit for S3 traffic only, not for RDS traffic; it is irrelevant to RDS connectivity. Option D is wrong because an AWS Transit Gateway is used to route traffic between VPCs and on-premises networks, not to enforce encryption; it does not provide any encryption of data in transit between clients and RDS.

← PreviousPage 3 of 4 · 245 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Infrastructure Security questions.