Which THREE are AWS best practices for securing an Amazon EC2 instance? (Choose three.)
Security groups provide stateful, instance-level filtering of inbound and outbound traffic, allowing least-privilege rules per workload. This satisfies the EC2 hardening requirement by restricting which ports and sources can reach each instance, unlike subnet-level NACLs alone.
Why this answer
Option C is correct because security groups act as stateful virtual firewalls at the instance/ENI level, and AWS best practice is to allow only the specific inbound ports (e.g., 22/443) and restrict outbound traffic needed by the workload rather than permitting all traffic. Option D is correct because disabling password-based SSH authentication and using SSH key pairs (or EC2 Instance Connect/SSM Session Manager) removes the risk of brute-force credential attacks and aligns with AWS guidance for Linux instance access. Option E is correct because AWS Systems Manager Patch Manager automates scanning and installation of OS and application security patches via patch baselines and maintenance windows, which is the recommended way to keep EC2 instances patched at scale.
Option A is wrong because instance metadata is readable from the instance (and potentially via SSRF) and is not a secure secret store; credentials should go in AWS Secrets Manager or Systems Manager Parameter Store. Option B is wrong because launching in the default VPC is not a security best practice; AWS recommends custom VPCs with segmented subnets, least-privilege routing, and controlled internet exposure.
Exam trap
The trap here is that candidates may think instance metadata is a secure place to store credentials because it is convenient, but AWS explicitly warns against this due to the risk of exposure through SSRF or other instance-level vulnerabilities.