Courseiva

CCNA Infrastructure Security Questions

20 of 245 questions · Page 4/4 · Infrastructure Security · Answers revealed

226
Multi-Selecthard

Which THREE are AWS best practices for securing an Amazon EC2 instance? (Choose three.)

Select 3 answers
A.Store database credentials in instance metadata for easy retrieval.
B.Launch instances in the default VPC for easier network configuration.
C.Use security groups to control inbound and outbound traffic.
D.Disable password-based authentication and use SSH key pairs instead.
E.Regularly apply security patches using AWS Systems Manager Patch Manager.
AnswersC, D, E

Security groups provide stateful, instance-level filtering of inbound and outbound traffic, allowing least-privilege rules per workload. This satisfies the EC2 hardening requirement by restricting which ports and sources can reach each instance, unlike subnet-level NACLs alone.

Why this answer

Option C is correct because security groups act as stateful virtual firewalls at the instance/ENI level, and AWS best practice is to allow only the specific inbound ports (e.g., 22/443) and restrict outbound traffic needed by the workload rather than permitting all traffic. Option D is correct because disabling password-based SSH authentication and using SSH key pairs (or EC2 Instance Connect/SSM Session Manager) removes the risk of brute-force credential attacks and aligns with AWS guidance for Linux instance access. Option E is correct because AWS Systems Manager Patch Manager automates scanning and installation of OS and application security patches via patch baselines and maintenance windows, which is the recommended way to keep EC2 instances patched at scale.

Option A is wrong because instance metadata is readable from the instance (and potentially via SSRF) and is not a secure secret store; credentials should go in AWS Secrets Manager or Systems Manager Parameter Store. Option B is wrong because launching in the default VPC is not a security best practice; AWS recommends custom VPCs with segmented subnets, least-privilege routing, and controlled internet exposure.

Exam trap

The trap here is that candidates may think instance metadata is a secure place to store credentials because it is convenient, but AWS explicitly warns against this due to the risk of exposure through SSRF or other instance-level vulnerabilities.

227
MCQeasy

A company wants to restrict access to an Amazon S3 bucket so that only objects uploaded with server-side encryption using AWS KMS (SSE-KMS) are allowed. Which bucket policy condition key should be used?

A.s3:x-amz-server-side-encryption-customer-key
B.s3:x-amz-server-side-encryption-aws-kms-key-id
C.kms:EncryptionContext
D.s3:x-amz-server-side-encryption
AnswerD

The s3:x-amz-server-side-encryption condition key only verifies that server-side encryption was requested or applied, typically checking the value such as AES256 or aws:kms, but it does not identify which AWS KMS key was used. This condition can ensure that objects are encrypted, but it cannot distinguish between different KMS keys, so it is insufficient for restricting access to objects encrypted with a specific KMS key. The requirement specifically calls for enforcing a particular KMS key, which requires a more granular condition key like s3:x-amz-server-side-encryption-aws-kms-key-id.

Why this answer

To enforce that all objects uploaded to an S3 bucket use SSE-KMS, you should use the bucket policy condition key `s3:x-amz-server-side-encryption` and set its value to `aws:kms`. This ensures the encryption header is `aws:kms` without requiring a specific KMS key. The key `s3:x-amz-server-side-encryption-aws-kms-key-id` is used only when you need to require a particular KMS key ARN.

Exam trap

Candidates often confuse the generic encryption condition key with the specific KMS key ID condition key. For restricting to any SSE-KMS, use `s3:x-amz-server-side-encryption` with value `aws:kms`. To restrict to a specific KMS key, use `s3:x-amz-server-side-encryption-aws-kms-key-id`.

How to eliminate wrong answers

Option A is wrong because `s3:x-amz-server-side-encryption-customer-key` is used to enforce server-side encryption with customer-provided encryption keys (SSE-C), not SSE-KMS. Option C is wrong because `kms:EncryptionContext` is a condition key for KMS API actions (like Encrypt or Decrypt) and is not used in S3 bucket policies to enforce encryption type on uploads. Option D is wrong because `s3:x-amz-server-side-encryption` only checks whether the `x-amz-server-side-encryption` header is present (e.g., 'AES256' for SSE-S3 or 'aws:kms' for SSE-KMS), but it cannot enforce that a specific KMS key ID is used, which is required to restrict to SSE-KMS only.

228
MCQhard

A company deploys an AWS Lambda function inside a VPC to read from an Amazon RDS for PostgreSQL database in a private subnet. The function also needs to write logs to CloudWatch Logs and store objects in Amazon S3. The security team wants to eliminate the need for a NAT gateway while still allowing the function to reach both AWS services. Which combination of actions should the engineer take?

A.Create a gateway endpoint for Amazon S3 and a gateway endpoint for CloudWatch Logs, then associate both with the function's route tables.
B.Create interface endpoints for both Amazon S3 and CloudWatch Logs, and enable private DNS so the function resolves the service names to the endpoint addresses.
C.Create gateway endpoints for Amazon S3 and interface endpoints for CloudWatch Logs, associate them with the function's subnets, and attach a security group to the interface endpoints that allows HTTPS from the function's security group.
D.Attach an internet gateway to the VPC and update the function's route table to direct 0.0.0.0/0 to the internet gateway, then rely on the function's security group to restrict egress.
AnswerC

Gateway endpoints for S3 and interface endpoints for CloudWatch Logs keep that traffic on the AWS network, so no NAT gateway is needed. Interface endpoints use elastic network interfaces with security groups, so permitting HTTPS from the Lambda function's security group is required for the logs path to succeed.

Why this answer

Gateway endpoints serve Amazon S3 without hourly charges, while interface endpoints powered by AWS PrivateLink serve CloudWatch Logs. Because interface endpoints are elastic network interfaces, the endpoint's security group must allow inbound HTTPS from the Lambda function's security group, and private DNS resolution lets the SDK reach the service names transparently.

Exam trap

The trap here is assuming that a gateway endpoint can be created for any AWS service, when gateway endpoints exist only for Amazon S3 and DynamoDB.

229
Multi-Selecthard

Which THREE measures can be taken to secure a VPC's network boundary? (Choose three.)

Select 3 answers
A.Attach an S3 bucket policy to restrict access to the bucket.
B.Use security groups to control inbound and outbound traffic at the instance level.
C.Attach an internet gateway to the VPC.
D.Use network ACLs to add an additional layer of stateless filtering at the subnet level.
E.Enable VPC Flow Logs to capture and analyze traffic metadata.
AnswersB, D, E

Security groups act as a stateful virtual firewall attached to Elastic Network Interfaces, allowing you to define allow rules for inbound and outbound traffic. Stateful means return traffic is automatically permitted for an allowed request, and you can only specify allow rules—there is no explicit deny—so managing per-instance traffic at the protocol, port, and source/destination CIDR is the core instance-level measure. This is a foundational VPC security control that directly filters traffic before it reaches an instance.

Why this answer

Option B is correct because security groups act as stateful virtual firewalls at the instance/ENI level, allowing you to permit only specific inbound and outbound traffic, which directly hardens the VPC boundary. Option D is correct because network ACLs provide stateless subnet-level filtering with allow and deny rules, adding a second layer of defense that complements security groups. Option E is correct because VPC Flow Logs capture IP traffic metadata to CloudWatch Logs or S3, enabling detection and analysis of suspicious or unauthorized traffic crossing the VPC boundary.

Option A is not correct here because an S3 bucket policy secures access to an S3 bucket, not the VPC network boundary. Option C is not correct because attaching an internet gateway enables connectivity to the internet rather than restricting or securing the boundary.

Exam trap

The trap here is confusing network security controls (security groups, network ACLs, VPC Flow Logs) with resource-level policies (S3 bucket policies) or connectivity components (internet gateway), leading candidates to select options that do not directly secure the VPC's network boundary.

230
MCQeasy

A company wants to provide temporary, limited-privilege credentials to users so they can access AWS resources from mobile applications. Which AWS service should the company use?

A.AWS Security Token Service (STS)
B.AWS Single Sign-On (SSO)
C.AWS Identity and Access Management (IAM) users
D.Amazon Cognito user pools
AnswerA

AWS Security Token Service (STS) is the correct service because it explicitly issues temporary, limited-privilege credentials—typically an access key ID, a secret access key, and a session token—with configurable durations (15 minutes to 12 hours). For a mobile app that needs scoped permissions without embedding permanent keys, STS operations like AssumeRole or GetFederationToken are the direct mechanism, and the returned credentials are automatically expired, reducing risk of long-term exposure.

Why this answer

AWS Security Token Service (STS) is the correct service because it enables the generation of temporary, limited-privilege credentials (access key, secret key, and session token) that can be used to access AWS resources. These credentials are ideal for mobile applications where long-term keys are a security risk, as they can be scoped with an IAM role and have a configurable expiration (default 1 hour, max 36 hours). STS supports the AWS Signature Version 4 signing process and can be called via the AssumeRole or GetFederationToken APIs to provide federated access.

Exam trap

The trap here is that candidates confuse Amazon Cognito user pools (which handle authentication and user management) with identity pools (which use STS to grant AWS credentials), leading them to select Cognito user pools instead of STS as the direct service for temporary credentials.

How to eliminate wrong answers

Option B (AWS Single Sign-On) is wrong because it is a centralized authentication service for workforce users accessing multiple AWS accounts or business applications, not designed to issue temporary credentials for mobile app users. Option C (IAM users) is wrong because IAM users have long-term static credentials (access key and secret key) that are not temporary and pose a higher security risk if exposed in mobile applications. Option D (Amazon Cognito user pools) is wrong because user pools are a user directory and authentication provider for mobile apps, but they do not directly issue AWS credentials; instead, they integrate with identity pools (which use STS) to grant temporary AWS access.

231
MCQmedium

A company uses Amazon CloudFront with an Application Load Balancer (ALB) as the origin. The security team wants to restrict access to the ALB so that it only accepts traffic from CloudFront. Which configuration should be used?

A.Configure the ALB to be internal and place it in a VPC with a CloudFront VPC origin.
B.Configure the ALB to require a specific header 'X-CloudFront-Origin' and reject requests without it.
C.Configure the ALB to use an IAM role that allows only CloudFront to invoke the ALB.
D.Configure the ALB security group to allow inbound traffic only from the CloudFront origin IP ranges published by AWS.
AnswerD

This is the correct and recommended approach: AWS publishes the complete set of CloudFront IP addresses used to fetch content from origins in the ip-ranges.json file, with a specific service indicator (CLOUDFRONT_ORIGIN_FACING). By adding a security group rule that allows inbound TCP 80/443 only from those CIDR blocks, the ALB will refuse connections from any other public IP, including direct internet clients that bypass CloudFront. You can implement this effectively using a managed prefix list that AWS keeps updated, or by periodically refreshing your security group rules from the published ranges.

Why this answer

CloudFront publishes a list of its origin-facing IP address ranges, and you can restrict the ALB's security group to allow inbound traffic only from those ranges. This ensures that only CloudFront can reach the ALB directly, preventing bypass attacks. AWS provides these IP ranges in the ip-ranges.json file, which can be used to automate security group updates.

Exam trap

The trap here is that candidates often confuse CloudFront's viewer-facing IP ranges with its origin-facing IP ranges, or they assume that a custom header (like 'X-CloudFront-Origin') is a built-in CloudFront feature, when in fact AWS recommends using security group restrictions as the primary defense.

How to eliminate wrong answers

Option A is wrong because CloudFront cannot use a VPC origin with an internal ALB; CloudFront origins must be publicly accessible over the internet, and internal ALBs are not reachable from CloudFront. Option B is wrong because there is no standard 'X-CloudFront-Origin' header; while you can use a custom header like 'X-Origin-Verify' to authenticate requests, this is not a built-in CloudFront feature and relies on a shared secret, which is less secure than network-layer restriction. Option C is wrong because IAM roles are used for API-level authorization (e.g., invoking Lambda functions), not for network traffic control to an ALB; ALBs do not evaluate IAM roles for incoming HTTP requests.

232
MCQeasy

A company wants to ensure that all data sent to an S3 bucket is encrypted in transit. Which policy statement should be added to the bucket policy?

A.Allow if aws:SecureTransport is false
B.Deny unless aws:SecureTransport is false
C.Allow if aws:SecureTransport is true
D.Deny if aws:SecureTransport is false
AnswerD

This is the correct pattern because it explicitly denies every request where aws:SecureTransport is false, i.e., plaintext HTTP, while leaving HTTPS requests unaffected and able to be allowed by other statements. An explicit Deny always overrides any Allow, so even a broad bucket policy cannot accidentally permit insecure HTTP traffic. This is the standard, recommended way to enforce TLS for S3 data in transit.

Why this answer

The correct answer is D: Deny if aws:SecureTransport is false. The aws:SecureTransport condition key evaluates to true when the request is made over HTTPS (TLS) and false when made over HTTP. To enforce encryption in transit, you must explicitly deny requests where aws:SecureTransport is false, ensuring that any unencrypted HTTP request is rejected.

This is the standard pattern for S3 bucket policies to enforce TLS-only access.

Exam trap

SCS-C02 often tests the difference between Allow and Deny effects and the logical inversion of condition keys, so candidates may mistakenly choose an Allow statement with aws:SecureTransport true, not realizing that an explicit Deny is required to block insecure requests when other allows exist.

How to eliminate wrong answers

Option A is wrong because it allows requests when aws:SecureTransport is false, which means it permits unencrypted HTTP traffic, directly contradicting the goal. Option B is wrong because it denies requests when aws:SecureTransport is false, but the condition is inverted: it would deny secure HTTPS requests and allow insecure HTTP requests, which is the opposite of what is needed. Option C is wrong because it only allows requests when aws:SecureTransport is true, but it does not explicitly deny insecure requests; if there are other allow statements in the bucket policy, HTTP requests could still be permitted.

An explicit deny is required to guarantee enforcement.

233
Multi-Selecteasy

A company wants to use AWS CloudTrail to log all API calls in an AWS account. The security engineer needs to ensure that the logs are encrypted at rest and are accessible only to authorized personnel. Which THREE steps should the engineer take? (Choose THREE.)

Select 3 answers
A.Enable MFA delete on the S3 bucket.
B.Enable server-side encryption on the S3 bucket that stores CloudTrail logs.
C.Attach a service control policy (SCP) to the root account.
D.Create an IAM policy that grants access to the S3 bucket only to specific users or roles.
E.Configure the S3 bucket policy to require encrypted connections (aws:SecureTransport).
AnswersB, D, E

Enabling server-side encryption on the S3 bucket that stores CloudTrail logs ensures that every delivered log object is encrypted at rest, either with SSE-S3 using Amazon-managed keys or with SSE-KMS using a customer-managed key. This directly protects the audit trail from being read by anyone who obtains the underlying storage, and it is a core requirement for compliance frameworks that mandate encrypted audit data. CloudTrail supports SSE-KMS through its own integration, allowing you to control the encryption key separately from the bucket.

Why this answer

Option B is correct because enabling server-side encryption (SSE-S3, SSE-KMS, or SSE-C) on the S3 bucket that stores CloudTrail logs ensures the log objects are encrypted at rest, satisfying the encryption requirement. Option D is correct because an IAM policy scoped to specific users or roles enforces least-privilege access, ensuring only authorized personnel can read the CloudTrail log objects. Option E is correct because a bucket policy condition requiring aws:SecureTransport=true denies any non-TLS (HTTP) requests, protecting logs in transit and preventing unencrypted access.

Option A does not belong because MFA delete protects against accidental or malicious deletion of objects but does not provide encryption at rest or restrict read access to authorized personnel. Option C does not belong because an SCP attached to the root account only sets permission guardrails for accounts in an organization and does not encrypt CloudTrail logs or grant/restrict access to the specific S3 bucket.

Exam trap

SCS-C02 often tests the difference between encryption at rest, encryption in transit, and access control — candidates incorrectly pick MFA Delete or SCPs thinking they provide confidentiality of log data.

234
MCQhard

A security engineer needs to ensure that all data in transit between an Application Load Balancer (ALB) and EC2 instances is encrypted. What configuration is required?

A.Configure the security group to allow traffic on port 443.
B.Configure the ALB listener with HTTPS protocol.
C.Configure the ALB to terminate TLS connections.
D.Configure the target group to use HTTPS protocol.
AnswerD

Setting the target group protocol to HTTPS instructs the ALB to establish a new TLS session with each registered EC2 target rather than forwarding plaintext HTTP. This encrypts the second segment of the request path, so combined with an HTTPS listener the data is encrypted end to end. It directly addresses the missing encryption between the load balancer and the instances, making it the correct action.

Why this answer

Encryption in transit between an ALB and its targets is controlled by the target group protocol, not the listener. Setting the target group to HTTPS makes the ALB initiate TLS connections to the EC2 instances, encrypting the backend leg. The listener protocol only governs the client-to-ALB leg.

Exam trap

The trap is assuming that configuring the ALB listener for HTTPS automatically encrypts the backend leg — candidates forget that the target group protocol is a separate setting that controls ALB-to-instance encryption.

How to eliminate wrong answers

Option A is wrong because security groups control network reachability (ports and sources), not encryption; allowing port 443 does not force TLS between the ALB and targets. Option B is wrong because configuring the ALB listener with HTTPS only encrypts traffic from the client to the ALB; the ALB still communicates with targets using whatever protocol the target group specifies. Option C is wrong because terminating TLS at the ALB means the ALB decrypts client traffic and then forwards it — if the target group is HTTP, the backend leg is plaintext, which is the opposite of what is required.

Option D is correct because the target group protocol setting is what determines whether the ALB re-encrypts traffic to the instances.

235
MCQeasy

A company uses AWS Organizations with multiple accounts. The security team wants to enforce that all Amazon S3 buckets across the organization have server-side encryption (SSE-S3 or SSE-KMS) enabled. Which approach should be used to enforce this policy?

A.Create an S3 bucket policy in each account to deny access to unencrypted buckets.
B.Use AWS Config rules to detect buckets without encryption and send alerts.
C.Create an IAM role in each account that requires encryption when creating buckets.
D.Create a service control policy (SCP) that denies s3:CreateBucket if the bucket does not have encryption enabled.
AnswerD

An SCP in AWS Organizations can apply a deny to s3:CreateBucket for every principal in the organization by using the condition key s3:x-amz-server-side-encryption to require an encryption header such as AES256 or aws:kms. Because service control policies are evaluated before any IAM policy and apply across the root, OU, or account level, they act as a centrally managed preventive control that blocks the creation of unencrypted buckets in all member accounts. With the correct condition, any request that omits or misconfigures the encryption parameter will be denied, meeting the company's objective.

Why this answer

Service Control Policies (SCPs) in AWS Organizations allow you to centrally deny API actions across all accounts. By creating an SCP that denies `s3:CreateBucket` unless the request includes encryption parameters (SSE-S3 or SSE-KMS), you enforce encryption at the point of bucket creation, preventing non-compliant buckets from ever being created. This is the only approach that proactively enforces the policy across the entire organization, rather than relying on detection or per-account configurations.

Exam trap

The trap here is that candidates often confuse detective controls (like AWS Config) with preventive controls (like SCPs), or assume that bucket policies or IAM roles can enforce encryption at creation time, when only SCPs can centrally deny the API call across an entire organization.

How to eliminate wrong answers

Option A is wrong because S3 bucket policies control access to existing buckets, not the creation of buckets; they cannot prevent an unencrypted bucket from being created. Option B is wrong because AWS Config rules are detective, not preventive; they can alert on non-compliant buckets but do not enforce encryption at creation time. Option C is wrong because IAM roles are per-account and cannot enforce a policy across all accounts in an organization; additionally, IAM roles control who can create buckets but do not enforce encryption requirements on the bucket itself.

236
Multi-Selecteasy

A company uses AWS Systems Manager Session Manager to provide SSH access to EC2 instances without needing to open inbound ports. The security team wants to ensure that all session activity is logged and that only authorized users can start sessions. Which combination of actions should be taken? (Choose TWO.)

Select 2 answers
A.Configure the EC2 instances to require SSH key pairs for authentication.
B.Enable AWS CloudTrail to log StartSession API calls.
C.Enable VPC Flow Logs to monitor network traffic.
D.Create IAM policies that allow the ssm:StartSession action only for specific users or roles.
E.Use security groups to restrict inbound traffic to the Session Manager endpoints.
AnswersB, D

CloudTrail is the correct choice because it records StartSession API calls as management events, capturing the IAM principal, source IP, and timestamp of each session request. This gives you a detective control to answer who initiated a session and when, which is essential for security auditing and alerting on unusual activity.

Why this answer

Option B is correct because Session Manager records session activity through the StartSession API, and enabling AWS CloudTrail captures those API calls for auditing who started sessions and when. Option D is correct because IAM policies scoping the ssm:StartSession action to specific users or roles enforce authorization, ensuring only approved principals can initiate sessions. Option A is incorrect because Session Manager does not rely on SSH key pairs; it uses the SSM Agent and IAM credentials, so requiring SSH keys does not meet the logging or authorization goal.

Option C is incorrect because VPC Flow Logs capture IP traffic metadata, not the session-level activity or API authorization events the team needs. Option E is incorrect because Session Manager is designed to avoid inbound ports and security groups restricting inbound traffic to Session Manager endpoints is neither required nor how access control is enforced.

Exam trap

Candidates may think that VPC Flow Logs or security groups are needed for Session Manager, but Session Manager is designed to avoid inbound ports and uses IAM and CloudTrail for access control and logging.

237
MCQhard

Refer to the exhibit. A security engineer is reviewing this CloudFormation template. What security risk is present in this configuration?

A.The template does not associate the security group with the instance, so the instance has no security group.
B.HTTP access is allowed from all IP addresses (0.0.0.0/0) which is a security risk.
C.SSH access is allowed from a large internal CIDR block (10.0.0.0/8) which could expose the instance to unnecessary internal threats.
D.The template uses SecurityGroups property instead of SecurityGroupIds, which is deprecated.
AnswerC

The 10.0.0.0/8 CIDR block is the entire RFC1918 Class A private address space, covering every possible 10.x.x.x network used by VPCs and internal environments. Opening SSH to this range allows any compromised host in that vast address space to attempt to connect to the instance, which is an unnecessary and overly permissive ingress rule. Best practice is to scope SSH to a specific management CIDR or single IP to maintain least privilege.

Why this answer

Allowing SSH (TCP port 22) from the entire 10.0.0.0/8 CIDR block is overly permissive. This range encompasses all RFC 1918 private addresses in the 10.x.x.x space, which could include many internal subnets, VPNs, or peered VPCs that do not require administrative access. Unnecessarily broad internal access increases the attack surface and violates the principle of least privilege.

Exam trap

The trap here is that candidates often focus on the obvious risk of opening SSH to 0.0.0.0/0, but the question tests whether they recognize that an overly broad internal CIDR (10.0.0.0/8) is also a significant security risk, especially when SSH is involved.

How to eliminate wrong answers

Option A is wrong because the SecurityGroups property in the AWS::EC2::Instance resource directly associates the security group by name or reference; the instance will have the specified security group attached. Option B is wrong because the template does not define any HTTP (port 80) ingress rule; the security group only allows SSH (port 22) and ICMP, so HTTP from 0.0.0.0/0 is not present. Option D is wrong because SecurityGroups is a valid property for EC2 instances in CloudFormation and is not deprecated; SecurityGroupIds is used when referencing security groups by ID, but both are supported.

238
MCQhard

A company wants to audit all API calls made to Amazon S3 within a specific AWS account. Which combination of services should be used to meet this requirement?

A.AWS CloudTrail and Amazon CloudWatch Logs.
B.Amazon Inspector and Amazon CloudWatch Logs.
C.Amazon GuardDuty and Amazon CloudWatch Logs.
D.AWS Config and Amazon CloudWatch Logs.
AnswerA

Amazon CloudTrail is the authoritative source for S3 API activity, capturing both management events (e.g., CreateBucket, DeleteBucket) and, when enabled, data events for object-level actions such as PutObject, GetObject, and DeleteObject. By delivering those CloudTrail logs to Amazon CloudWatch Logs, you can create metric filters and alarms for real-time monitoring of API calls, making this the correct combination for a complete S3 audit trail.

Why this answer

AWS CloudTrail is the service that records all API calls made to Amazon S3 (and other AWS services) within an AWS account, capturing details such as the identity of the caller, the time of the call, the source IP address, and the request parameters. By delivering these logs to Amazon CloudWatch Logs, you can monitor, search, and set alarms on the API activity in real time, enabling comprehensive auditing of S3 operations.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks configuration changes) with CloudTrail (which tracks API calls), leading them to select Option D, but only CloudTrail provides the detailed audit trail of API activity required for this use case.

How to eliminate wrong answers

Option B is wrong because Amazon Inspector is a vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, not a service that records API calls. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes logs (like VPC Flow Logs and DNS logs) for malicious activity, but it does not itself capture or audit API calls to S3. Option D is wrong because AWS Config is a service that evaluates resource configurations against desired policies and tracks configuration changes, not API call history.

239
MCQmedium

A security engineer is configuring a VPC flow log to detect unusual traffic patterns. The engineer notices that some traffic between two EC2 instances in the same VPC appears in the flow logs as NODATA records, and other connections appear as REJECT records. The engineer must determine what each record type indicates before building detections. Which statement correctly describes the difference?

A.NODATA indicates that a security group blocked the traffic, while REJECT indicates that a network ACL blocked the traffic.
B.NODATA indicates that no traffic matched the flow log record during the aggregation interval, while REJECT indicates that traffic was present but was blocked by a security group or network ACL.
C.NODATA indicates that traffic was rejected by an AWS WAF rule, while REJECT indicates that traffic was allowed by a security group.
D.NODATA indicates that the flow log was disabled for the resource, while REJECT indicates that the destination port was unreachable.
AnswerB

NODATA means the capture window closed with no matching packets, which is common for flows that are logging only accepted or only rejected traffic. REJECT means packets were observed but denied by a security group, network ACL, or similar control, so the connection attempt is visible in the record.

Why this answer

VPC flow logs emit ACCEPT, REJECT, and NODATA records. A REJECT record means packets were seen but denied, typically by a security group or network ACL, while NODATA means the aggregation interval elapsed with no matching packets captured, which is useful for confirming that a monitored flow simply never occurred.

Exam trap

The trap here is reading NODATA as evidence of a blocked connection, when it actually only indicates that no matching traffic was observed in the interval.

240
MCQmedium

A company wants to restrict access to an S3 bucket so that only requests from a specific VPC Endpoint are allowed. Which policy element should be used in the bucket policy?

A.aws:SourceVpc
B.aws:VpcSourceIp
C.aws:SourceIp
D.aws:SourceVpce
AnswerD

The aws:SourceVpce condition key is the correct way to restrict an S3 bucket to requests that came through a specific VPC endpoint. You write it in the bucket policy's Condition block using StringEquals and set the value to the full VPC endpoint ID, such as vpce-0abcdef123456789. Because this key is present in the request context only when the request traffic actually travels through the specified VPC endpoint, it gives the most precise endpoint-level control among the listed options.

Why this answer

The aws:SourceVpce condition key is the correct choice because it specifically evaluates the VPC endpoint ID (e.g., vpce-12345678) that the request traversed to reach S3. When you attach a bucket policy that denies all traffic except requests originating from a particular VPC endpoint, you use a Condition block with StringEquals on aws:SourceVpce to match that endpoint ID. This is the only key that directly identifies the endpoint itself, making it the precise tool for restricting access to a specific VPC endpoint.

Exam trap

SCS-C02 often tests the confusion between aws:SourceVpc (VPC ID) and aws:SourceVpce (VPC endpoint ID), causing candidates to pick the VPC-level key when the question specifically asks for endpoint-level restriction.

How to eliminate wrong answers

Option A is wrong because aws:SourceVpc evaluates the VPC ID (e.g., vpc-abc123) from which the request originated, not the VPC endpoint ID; it cannot distinguish between multiple endpoints in the same VPC. Option B is wrong because aws:VpcSourceIp is not a valid AWS condition key—it does not exist in IAM policy evaluation. Option C is wrong because aws:SourceIp checks the public or private IP address of the requester, which is not reliable for VPC endpoint traffic since the source IP may be a private address that is not unique to the endpoint and can be spoofed or shared.

241
MCQmedium

A security team needs to audit all changes to security group rules across multiple AWS accounts in an organization. Which combination of services should be used to meet this requirement?

A.Amazon CloudWatch Logs and AWS CloudTrail.
B.Amazon GuardDuty and AWS Security Hub.
C.AWS Trusted Advisor and AWS Config.
D.AWS Config and AWS CloudTrail.
AnswerD

AWS Config continuously records the configuration state of security groups, including each ingress and egress rule change, and can deliver configuration-history timelines and compliance snapshots. AWS CloudTrail captures the API actions that initiate those changes, logging the principal, user agent, and request parameters for every management event. Together they provide both the 'what' (configuration state via Config) and the 'who/when/how' (API activity via CloudTrail), enabling a complete audit trail of security group changes. For example, when a rule is removed, Config shows the new state while CloudTrail reveals the identity of the caller.

Why this answer

AWS Config continuously records changes to resource configurations, including security group rules, and can evaluate them against desired configurations. AWS CloudTrail captures API activity, so it logs the actual API calls that modify security groups (e.g., AuthorizeSecurityGroupIngress). Together, Config provides the configuration change history and CloudTrail provides the who, what, when, and from where for each change.

This combination is the standard AWS approach for auditing security group modifications across multiple accounts, especially when centralized via AWS Organizations and a delegated administrator.

Exam trap

SCS-C02 often tests the misconception that AWS Config alone can provide a full audit trail of who made changes, when in fact CloudTrail is required to capture the API-level identity and request details.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs is for storing and analyzing log data (e.g., from applications or flow logs), not for recording resource configuration changes; CloudTrail alone records API calls but does not provide a configuration timeline or compliance evaluation of security group rules. Option B is wrong because GuardDuty is a threat detection service that identifies malicious activity, and Security Hub aggregates and prioritizes findings; neither records configuration changes or provides a full audit trail of security group rule modifications. Option C is wrong because Trusted Advisor offers best-practice checks and recommendations, not a detailed configuration change history, and AWS Config alone (without CloudTrail) lacks the API-level audit trail of who made each change.

242
MCQeasy

A company is using AWS Shield Advanced to protect its web application against DDoS attacks. Which additional AWS service can be used to automatically mitigate application layer attacks?

A.AWS Network Firewall
B.Amazon GuardDuty
C.AWS Firewall Manager
D.AWS WAF
AnswerD

AWS WAF is a web application firewall that monitors and filters HTTP(S) requests based on conditions like IP reputation, country, URI, and SQL injection signatures. When integrated with AWS Shield Advanced, it provides the primary mechanism for application layer (L7) DDoS mitigation—enabling you to add rate-based rules and block anomalous traffic before it reaches the origin. This direct, request-level inspection makes it the correct option for protecting a web application.

Why this answer

AWS WAF is the correct choice because it integrates directly with AWS Shield Advanced to provide application-layer (Layer 7) DDoS mitigation. Shield Advanced handles network and transport layer attacks, while AWS WAF uses web access control lists (ACLs) to inspect HTTP/HTTPS traffic and block malicious requests such as SQL injection or cross-site scripting, which are common application-layer attack vectors.

Exam trap

The trap here is that candidates often confuse AWS WAF with AWS Network Firewall or Firewall Manager, mistakenly believing that any firewall service can handle application-layer attacks, but only AWS WAF provides Layer 7 inspection and mitigation for HTTP/HTTPS traffic.

How to eliminate wrong answers

Option A is wrong because AWS Network Firewall operates at Layers 3 and 4 (network and transport) and does not inspect or filter application-layer HTTP/HTTPS payloads, making it unsuitable for mitigating application-layer DDoS attacks. Option B is wrong because Amazon GuardDuty is a threat detection service that identifies malicious activity via logs and network metadata, but it does not actively block or mitigate traffic at the application layer. Option C is wrong because AWS Firewall Manager is a policy management tool that centrally configures rules across multiple accounts and resources, but it does not itself perform application-layer traffic inspection or mitigation.

243
MCQhard

A company has a VPC with a public subnet and a private subnet. An EC2 instance in the private subnet needs to download patches from the internet. The company wants to minimize costs and avoid NAT Gateway or NAT Instance charges. Which solution should be used?

A.Deploy a proxy instance in a public subnet and configure the private instance to use the proxy.
B.Use an egress-only internet gateway for the private subnet.
C.Attach an internet gateway to the VPC and add a route to the private subnet route table pointing to the internet gateway.
D.Create a VPC Gateway Endpoint for S3 and configure the instance to download patches from S3.
AnswerD

A VPC Gateway Endpoint for S3 uses the AWS-managed prefix list (com.amazonaws.<region>.s3) as a route-table target in the private subnet, so traffic to S3 stays on the AWS backbone and never leaves the VPC. Instances do not need public IPs, NAT, or an internet gateway, and gateway endpoints do not incur hourly charges. Configuring the route table and endpoint policy enables the private instance to download patches from selected S3 buckets securely without altering the instance's public/private status.

Why this answer

A VPC Gateway Endpoint for S3 allows private subnet resources to access S3 over the AWS network without traversing the internet, avoiding NAT Gateway or NAT Instance charges. The patches can be stored in an S3 bucket and downloaded by the EC2 instance using the endpoint, which uses AWS PrivateLink and does not require an internet gateway or public IP.

Exam trap

The trap here is that candidates often assume a private subnet must use a NAT Gateway or NAT Instance for any internet-bound traffic, overlooking that VPC Gateway Endpoints provide free, private access to specific AWS services like S3, which can satisfy the requirement without incurring additional costs.

How to eliminate wrong answers

Option A is wrong because deploying a proxy instance in a public subnet still requires that proxy to have internet access (via an internet gateway and public IP), and the proxy itself incurs EC2 instance costs, which does not minimize costs compared to using a free VPC Gateway Endpoint. Option B is wrong because an egress-only internet gateway is designed for IPv6 traffic only and does not support IPv4, which is the typical protocol for patch downloads; it also does not eliminate the need for a NAT device for IPv4. Option C is wrong because adding a route to the private subnet route table pointing to an internet gateway is invalid—private subnets require a NAT device (NAT Gateway or NAT Instance) to route traffic to the internet gateway; directly routing to the internet gateway would not work without a public IP on the instance, and it would violate the requirement to avoid NAT charges.

244
MCQeasy

A company wants to allow a developer to launch EC2 instances only in a specific subnet. The developer should not be able to use any other subnet. Which IAM policy action should be used to enforce this?

A.ec2:ModifySubnetAttribute
B.ec2:CreateTags
C.ec2:RunInstances
D.ec2:DescribeSubnets
AnswerC

This is the exact IAM action that authorizes the RunInstances API call, which provisions one or more EC2 instances along with associated root volumes and network interfaces. The action can be scoped with condition keys such as ec2:SubnetId to restrict launches to specific subnets, and it is the only action listed that creates the underlying compute resource. Therefore, this is the correct permission for allowing a developer to launch EC2 instances.

Why this answer

The ec2:RunInstances action is the correct IAM action to control EC2 instance launches. By attaching a condition key such as ec2:SubnetId to the ec2:RunInstances action in an IAM policy, you can restrict the developer to launching instances only in a specific subnet. Other actions like ModifySubnetAttribute, CreateTags, or DescribeSubnets do not govern the launch of new instances.

Exam trap

The trap here is that candidates often confuse read-only actions (like DescribeSubnets) or unrelated actions (like ModifySubnetAttribute) with the actual launch action, mistakenly thinking they can restrict subnet usage via those permissions instead of using ec2:RunInstances with a condition key.

How to eliminate wrong answers

Option A is wrong because ec2:ModifySubnetAttribute modifies subnet settings (e.g., auto-assign public IP) and does not control instance launches. Option B is wrong because ec2:CreateTags only allows tagging resources, not launching instances. Option D is wrong because ec2:DescribeSubnets is a read-only action that lists subnets but does not authorize instance creation.

245
MCQhard

A security engineer is troubleshooting connectivity issues between an Amazon EC2 instance in a VPC and an on-premises server over a Direct Connect virtual interface. The EC2 instance has a security group that allows outbound traffic to the on-premises CIDR block (10.0.0.0/16). The VPC has a route table entry pointing the on-premises CIDR to the virtual private gateway. The on-premises firewall shows that packets are received from the EC2 instance but responses are not reaching the instance. What is the most likely cause?

A.The on-premises router does not have a route pointing the VPC CIDR back to the Direct Connect interface.
B.The network ACL for the subnet is blocking outbound traffic to the on-premises CIDR.
C.The virtual private gateway is not attached to the VPC.
D.The security group does not allow inbound traffic from the on-premises server.
AnswerA

The VPC has a route for the on-premises CIDR pointing to the virtual private gateway, so outbound packets traverse the Direct Connect virtual interface. However, for successful two-way communication, the on-premises router must have a route for the VPC CIDR that points back to the same Direct Connect interface. Because this return route is missing, response packets are either sent to a default route or dropped, so hosts in the VPC see no replies. This is a classic asymmetric routing failure.

Why this answer

The on-premises firewall logs show packets are received from the EC2 instance, but responses are not reaching it. This indicates a routing issue on the on-premises side: the on-premises router must have a route pointing the VPC CIDR back to the Direct Connect interface (virtual interface) for return traffic to be forwarded correctly. Without this return route, the on-premises server sends responses via its default route (likely the internet), which are dropped by the VPC security group or never reach the EC2 instance.

Exam trap

The trap here is that candidates often assume security groups or network ACLs are the cause of asymmetric connectivity issues, but the real problem is the missing return route on the on-premises side, which is a common misconfiguration in hybrid networking scenarios.

How to eliminate wrong answers

Option B is wrong because the network ACL for the subnet is not blocking outbound traffic to the on-premises CIDR; the question states the EC2 instance can send packets (they are received on-premises), so outbound ACL rules are not the issue. Option C is wrong because if the virtual private gateway were not attached to the VPC, the EC2 instance would not be able to send packets to the on-premises CIDR at all (the route table entry would be invalid), yet packets are received on-premises. Option D is wrong because the security group does not need to allow inbound traffic from the on-premises server for the response to reach the EC2 instance; security groups are stateful, so if the outbound traffic is allowed, the return traffic is automatically permitted regardless of inbound rules.

← PreviousPage 4 of 4 · 245 questions total

Ready to test yourself?

Try a timed practice session using only Infrastructure Security questions.