Courseiva

CCNA Infrastructure Security Questions

75 of 245 questions · Page 1/4 · Infrastructure Security topic · Answers revealed

1
MCQeasy

Which AWS service can be used to centrally manage VPC security groups and network ACLs across multiple accounts in AWS Organizations?

A.AWS Firewall Manager
B.AWS Shield
C.AWS Config
D.AWS WAF
AnswerA

AWS Firewall Manager is the service designed to centrally configure and administer VPC security rules across accounts in an AWS Organization. It lets you create security group policies and network ACL policies that are automatically applied to new and existing VPC resources, enforcing a consistent security posture. This central management capability directly matches the scenario of managing VPC security centrally.

Why this answer

AWS Firewall Manager is the correct service because it provides centralized management of security groups and network ACLs across multiple accounts within AWS Organizations. It allows you to define common security rules and apply them automatically to new and existing accounts, ensuring consistent enforcement of VPC security policies without manual per-account configuration.

Exam trap

The trap here is that candidates confuse AWS Firewall Manager with AWS WAF or AWS Shield, assuming any 'firewall' or 'security' service can manage VPC-level constructs, but only Firewall Manager provides centralized cross-account management of security groups and NACLs.

How to eliminate wrong answers

Option B is wrong because AWS Shield is a managed Distributed Denial of Service (DDoS) protection service, not a tool for managing security groups or network ACLs. Option C is wrong because AWS Config is a service for evaluating and auditing resource compliance against rules, but it does not centrally manage or enforce security group or NACL policies across accounts. Option D is wrong because AWS WAF is a web application firewall that protects HTTP/HTTPS endpoints from common web exploits, and it does not manage VPC-level security groups or network ACLs.

2
Multi-Selecthard

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The security team wants to allow only HTTP and HTTPS traffic from the internet to the ALB, and only HTTP traffic from the ALB to the EC2 instances. Which THREE security group configurations are required? (Choose three.)

Select 3 answers
A.ALB security group: inbound rule allowing HTTP from 0.0.0.0/0.
B.EC2 security group: inbound rule allowing HTTP from 0.0.0.0/0.
C.EC2 security group: inbound rule allowing HTTP from ALB security group.
D.EC2 security group: inbound rule allowing HTTPS from ALB security group.
E.ALB security group: inbound rule allowing HTTPS from 0.0.0.0/0.
AnswersA, C, E

The ALB is the public entry point for the web application, so its security group must permit inbound HTTP from any IPv4 address. Allowing 0.0.0.0/0 on port 80 is required for clients on the internet to reach the load balancer. The ALB then forwards requests to the EC2 instances, whose own security group controls traffic from the ALB only.

Why this answer

The ALB must accept HTTP traffic from the internet (0.0.0.0/0) to serve web requests. This inbound rule allows the ALB to listen on port 80 for unencrypted HTTP traffic, which is a standard requirement for a public-facing web application. Without this rule, HTTP requests from clients would be dropped by the ALB's security group.

Exam trap

The trap here is that candidates often mistakenly add an HTTPS inbound rule to the EC2 security group (option D) or allow direct internet access to the instances (option B), failing to recognize that the ALB should handle HTTPS termination and only forward HTTP to the backend.

3
MCQhard

A security engineer is reviewing an IAM policy attached to a user. The policy is intended to allow all EC2 actions except deleting volumes in the Production environment. However, the user reports being able to delete volumes that are tagged with Environment=Production. What is the reason for this behavior?

A.The policy is not attached to the correct IAM entity.
B.The Deny statement should use iam:ResourceTag instead of ec2:ResourceTag.
C.The condition in the Deny statement uses StringNotEquals, which denies deletion for non-Production volumes, not Production volumes.
D.The Allow statement uses a wildcard for the action, which overrides the Deny statement.
AnswerC

The StringNotEquals operator evaluates to true when the volume's tag value is anything other than Production, so the Deny applies only to non-Production volumes. Production-tagged volumes fail the negative condition and are therefore allowed by the Deny statement to be deleted. If the goal is to protect Production volumes from deletion, the policy should use StringEquals with the value Production so that only matching volumes are denied.

Why this answer

The Deny statement uses the StringNotEquals condition operator with ec2:ResourceTag/Environment=Production. This means the Deny applies when the tag value is NOT equal to Production, so it denies deletion for non-Production volumes but allows deletion for Production volumes. To deny deletion of Production volumes, the policy should use StringEquals instead of StringNotEquals.

Exam trap

The trap here is that candidates often confuse StringNotEquals with StringEquals, assuming that StringNotEquals will deny the specified tag value, when in fact it denies all other values, allowing the intended target to pass through.

How to eliminate wrong answers

Option A is wrong because the policy is attached to the user, and the user can perform other EC2 actions, so the attachment is correct; the issue is the logic in the policy itself. Option B is wrong because ec2:ResourceTag is the correct condition key for EC2 resource tags; iam:ResourceTag is used for IAM resources, not EC2. Option D is wrong because in IAM policy evaluation, an explicit Deny always overrides any Allow, regardless of wildcards; the problem is that the Deny condition does not match the Production volumes.

4
MCQhard

A company uses AWS Shield Advanced to protect its web application from DDoS attacks. The security team wants to receive real-time notifications when a DDoS attack is detected. Which configuration should be used?

A.Use Amazon CloudWatch Events to trigger an AWS Lambda function that sends an Amazon SNS notification when a Shield Advanced event occurs.
B.Enable VPC Flow Logs and create a CloudWatch alarm for high traffic volume.
C.Subscribe an SNS topic to Shield Advanced notifications directly.
D.Enable AWS CloudTrail and create a metric filter for DDoS events.
AnswerA

Shield Advanced is integrated natively with Amazon CloudWatch Events (now Amazon EventBridge), publishing real-time events such as DDoSDetected, AwsShibboleth, and AwsServiceEventNotification. Rather than polling or manual monitoring, you create a CloudWatch Events rule that matches these Shield event types and sets an AWS Lambda function as its target; the Lambda function then formats the event detail and publishes a message to an Amazon SNS topic, enabling timely notifications to your incident-response team. This pattern is the documented, reliable way to automate responses to Shield Advanced findings because it puts the filtering and routing logic in the event bus, not in the notification channel itself.

Why this answer

AWS Shield Advanced integrates with Amazon CloudWatch Events (now Amazon EventBridge) to emit events when DDoS attacks are detected. The standard pattern is to create an EventBridge rule that matches Shield Advanced events and triggers a Lambda function, which then publishes to an SNS topic for real-time notification. This is the documented, supported mechanism for proactive DDoS alerting.

Exam trap

SCS-C02 often tests the misconception that Shield Advanced can publish directly to SNS or that CloudTrail/VPC Flow Logs can detect DDoS events, when EventBridge is the required integration point.

How to eliminate wrong answers

Option B is wrong because VPC Flow Logs capture IP traffic metadata but do not detect or identify DDoS attacks; a high-traffic alarm is a crude proxy that generates false positives and misses attack signatures. Option C is wrong because Shield Advanced does not natively publish directly to SNS topics; it emits events to EventBridge, which must be routed. Option D is wrong because CloudTrail records API activity, not DDoS attack events; metric filters on CloudTrail cannot detect network-layer attacks.

5
MCQhard

A company uses AWS WAF to protect its web application from common web exploits. The security team wants to block requests that contain SQL injection or cross-site scripting (XSS) in the query string. Which rule type should be used?

A.Custom regex pattern set
B.Managed rule group for SQL injection and XSS
C.Rate-based rule
D.Geographic match rule
AnswerB

AWS WAF managed rule groups such as AWSManagedRulesSQLiRuleSet and AWSManagedRulesCommonRuleSet are purpose-built to detect SQL injection (SQLi) and cross-site scripting (XSS) using context-aware inspection that decodes and normalizes the request. Unlike simple regex matching, these rule groups apply heuristic and signature-based analysis that catches encoded payloads, comment obfuscation, and case variations, and AWS continuously updates them to address new evasion techniques, making them the appropriate, low-maintenance solution for this threat.

Why this answer

AWS WAF managed rule groups, such as the AWS-AWSManagedRulesSQLiRuleSet and AWS-AWSManagedRulesXSSRuleSet, are pre-configured to inspect query strings for SQL injection and cross-site scripting (XSS) patterns. Using a managed rule group is the most efficient and accurate approach because it leverages AWS's continuously updated threat signatures, reducing false positives and administrative overhead compared to custom rules.

Exam trap

The trap here is that candidates may think custom regex rules are necessary for precise control, but AWS WAF managed rule groups are specifically designed to handle SQL injection and XSS with higher accuracy and lower maintenance, making them the recommended choice for this use case.

How to eliminate wrong answers

Option A is wrong because custom regex pattern sets require manual definition of patterns for SQL injection and XSS, which is error-prone, difficult to maintain, and may miss obfuscated attack vectors that managed rules handle. Option C is wrong because rate-based rules are designed to block excessive request rates (e.g., DDoS) and do not inspect query string content for SQLi or XSS. Option D is wrong because geographic match rules filter traffic based on the requester's country or region, not on the content of the query string.

6
MCQhard

A company has a security group that allows inbound SSH from a specific IP range. A security engineer notices that the security group rule is not being applied to a newly launched EC2 instance. What is the most likely cause?

A.The new EC2 instance was not launched with the correct security group
B.The security group is using the default VPC security group
C.The security group is configured as stateless
D.The network ACL is blocking SSH traffic to the subnet
AnswerA

If the new instance was launched without appending the security group that contains the SSH rule, or was attached to a different security group, the rule never applies to that instance. Security group membership is determined at launch time for the primary ENI, and editing rules on the intended group only affects instances that are actually associated with it. To resolve this, you must attach the correct security group to the running instance or relaunch with the right group selected.

Why this answer

The most likely cause is that the new EC2 instance was not launched with the correct security group. Security groups act as virtual firewalls for instances, and an instance can only be associated with security groups at launch time. If the engineer launched the instance without explicitly selecting the security group that allows inbound SSH from the specific IP range, the instance would default to the VPC's default security group, which typically does not have the same custom SSH rule.

This is a common operational oversight when automating or manually launching instances.

Exam trap

The trap here is that candidates often confuse security group statefulness with network ACL statelessness, or assume that a security group rule applies automatically to all instances in a VPC, when in fact each instance must be explicitly associated with the correct security group at launch.

How to eliminate wrong answers

Option B is wrong because using the default VPC security group is a symptom of not selecting the correct security group, not a separate cause; the default group itself can be modified to allow SSH, but the question states the rule is not being applied, implying the instance is associated with a group lacking that rule. Option C is wrong because security groups are stateful by design (they automatically allow return traffic), and the stateless/stateful distinction applies to network ACLs, not security groups; a stateless security group does not exist in AWS. Option D is wrong because network ACLs operate at the subnet level and can block SSH, but the question specifies that the security group rule is not being applied, which points to a misconfiguration at the instance-level firewall (security group), not the subnet-level ACL; additionally, network ACLs are stateless and would affect all instances in the subnet, not just the newly launched one.

7
Drag & Dropmedium

Drag and drop the steps to set up AWS Certificate Manager (ACM) for a custom domain in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

ACM certificate requires request, DNS validation, issuance, association, and automatic renewal.

8
MCQeasy

A security engineer needs to audit all changes to AWS resources in an account. Which AWS service should be enabled?

A.Amazon Inspector
B.AWS CloudTrail
C.AWS Config
D.Amazon GuardDuty
AnswerB

AWS CloudTrail records every AWS API call as an event, capturing the identity of the caller, the source IP address, the request parameters, and the response elements. For an audit of all resource changes, CloudTrail is the authoritative source because nearly every modification to an AWS resource is implemented through a management-plane API call that gets logged.

Why this answer

AWS CloudTrail is the correct service because it records API activity and changes to AWS resources as events, providing an audit log of who made what change, when, and from where. This directly meets the requirement to audit all changes, as every AWS API call (e.g., CreateInstance, ModifySecurityGroup) is captured in a CloudTrail event history or delivered to an S3 bucket for long-term analysis.

Exam trap

The trap here is that candidates confuse AWS Config's configuration tracking (which shows what changed) with CloudTrail's API audit trail (which shows who changed it and how), leading them to pick AWS Config when the question explicitly asks for auditing all changes, which requires the API-level logging only CloudTrail provides.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability assessment service that scans EC2 instances and container images for software vulnerabilities and unintended network exposure, not a change audit service. Option C is wrong because AWS Config evaluates resource configurations against desired rules and tracks configuration changes over time, but it does not capture who made the change or the API call details—it focuses on resource state, not the API audit trail. Option D is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events for malicious activity, not a service that audits all resource changes.

9
MCQmedium

A company is using AWS CloudTrail to log API calls. The security team needs to ensure that log files are not tampered with and can be used to verify integrity. Which feature should be enabled?

A.Enable MFA delete on the log bucket.
B.Enable log file integrity validation in CloudTrail.
C.Enable server-side encryption with AWS KMS on the log bucket.
D.Enable S3 versioning on the log bucket.
AnswerB

CloudTrail log file integrity validation employs a SHA-256 hash chain to detect any modification, deletion, or forgery of log files. CloudTrail periodically creates signed digest files that list the hash of every log file delivered in that period along with the hash of the previous digest, and each digest is signed with a private key held by AWS. You can verify the signature using the publicly available key and recompute hashes to confirm the logs have not been altered, which directly addresses the need to ensure the API call history is trustworthy and tamper-evident.

Why this answer

CloudTrail log file integrity validation uses a hash chain (SHA-256) to create a digest file that proves log files have not been modified, deleted, or tampered with since delivery. This feature allows you to verify that CloudTrail log files have remained unchanged, meeting the security team's requirement for integrity verification.

Exam trap

The trap here is that candidates often confuse data protection features (encryption, versioning, MFA delete) with integrity verification, which specifically requires cryptographic hash validation to detect tampering.

How to eliminate wrong answers

Option A is wrong because MFA delete on the S3 bucket protects against accidental or unauthorized deletion of objects, but does not provide cryptographic verification of log file integrity. Option C is wrong because server-side encryption with AWS KMS protects data at rest from unauthorized access, but does not provide a mechanism to detect tampering or verify that log files have not been altered. Option D is wrong because S3 versioning preserves previous versions of objects to protect against overwrites and deletions, but does not offer cryptographic proof of file integrity or tamper detection.

10
MCQmedium

A company hosts a web application on EC2 instances behind an Application Load Balancer. The security team wants to ensure that only traffic from the ALB can reach the EC2 instances. Which configuration should be applied?

A.Configure the instances' security group to allow traffic from the ALB's security group.
B.Configure the instances' security group to allow traffic from the client's source IP addresses.
C.Configure a network ACL on the subnet to allow traffic from the ALB's private IP addresses.
D.Assign an IAM role to the instances that allows traffic only from the ALB.
AnswerA

Referencing the ALB's security group as the source in the instances' inbound rule allows traffic only from ENIs belonging to that group, and it tracks ALB IP changes automatically. This satisfies the requirement that only ALB traffic reaches the instances.

Why this answer

Security groups support referencing other security groups as a source. By configuring the EC2 instances' security group to allow inbound traffic from the ALB's security group, only traffic originating from the ALB (which uses the ALB's security group) is permitted. This ensures that traffic from any other source, including direct internet traffic, is blocked at the instance level.

Exam trap

The trap here is that candidates often confuse network ACLs (stateless, IP-based) with security groups (stateful, group-based) and mistakenly choose option C, not realizing that security group referencing is the correct and more secure method for this scenario.

How to eliminate wrong answers

Option B is wrong because allowing traffic from client source IP addresses would permit direct access to the EC2 instances, bypassing the ALB and defeating the purpose of restricting traffic to only the ALB. Option C is wrong because network ACLs are stateless and operate at the subnet level; they cannot reference security groups and would require manual management of ALB private IP addresses, which can change over time. Option D is wrong because IAM roles control API-level permissions for AWS services, not network traffic; they cannot filter or allow inbound traffic to EC2 instances.

11
MCQeasy

A company wants to encrypt data at rest for an Amazon S3 bucket. Which action should be taken?

A.Use client-side encryption before uploading objects.
B.Enable default encryption on the S3 bucket.
C.Enable SSL/TLS for the bucket.
D.Use AWS CloudHSM to encrypt the bucket.
AnswerB

Enabling default encryption on the S3 bucket automatically applies server-side encryption to every object written to it. You can choose SSE-S3 (AES-256) or SSE-KMS (with a customer managed CMK), and S3 encrypts objects at rest without any client-side changes. Any PUT request that omits encryption headers receives the bucket's default encryption, ensuring a consistent security posture for all stored data.

Why this answer

Enabling default encryption on the S3 bucket ensures that all objects stored in the bucket are automatically encrypted at rest using server-side encryption (SSE-S3, SSE-KMS, or SSE-C). This meets the requirement for encrypting data at rest without requiring any client-side changes, as the encryption is applied by S3 upon write.

Exam trap

The trap here is confusing encryption at rest (server-side encryption) with encryption in transit (SSL/TLS), leading candidates to select Option C, which only protects data during transfer, not while stored.

How to eliminate wrong answers

Option A is wrong because client-side encryption encrypts data before upload, which is a valid approach but not the action the question asks for—it requires client-side changes and does not leverage S3's native server-side encryption. Option C is wrong because SSL/TLS encrypts data in transit between the client and S3, not data at rest within the bucket. Option D is wrong because AWS CloudHSM provides hardware security modules for key storage and cryptographic operations, but it does not directly encrypt an S3 bucket; you would need to integrate it with AWS KMS (via custom key store) to use it for S3 server-side encryption, and even then the action is to enable default encryption with SSE-KMS, not to use CloudHSM directly.

12
MCQmedium

A security engineer is configuring a Network ACL for a public subnet that hosts a web server. The web server must accept HTTPS (TCP 443) traffic from the internet and respond. It must also be able to initiate outbound connections to the internet for software updates (HTTPS). What is the MINIMUM set of rules required for the inbound and outbound Network ACL?

A.Inbound: allow TCP 443 from 0.0.0.0/0 and TCP 22 from a management IP; Outbound: allow all traffic to 0.0.0.0/0.
B.Inbound: allow TCP 443 from 0.0.0.0/0; Outbound: allow TCP 443 to a specific software update server IP.
C.Inbound: allow TCP 443 from 0.0.0.0/0; Outbound: allow all traffic to 0.0.0.0/0.
D.Inbound: allow TCP 443 from 0.0.0.0/0; Outbound: allow TCP 1024-65535 to 0.0.0.0/0 (for return traffic) and allow TCP 443 to 0.0.0.0/0 (for updates).
AnswerD

This rule set meets the requirement by allowing inbound HTTPS on 443 for public clients and providing the minimal outbound rules needed for stateful-like behavior in a stateless NACL. The outbound TCP 1024-65535 rule allows responses to return to clients' ephemeral source ports, while the outbound TCP 443 rule permits the instance to fetch software updates. Together they allow required traffic while blocking unnecessary outbound communication, aligning with least privilege and the scenario's goal.

Why this answer

Network ACLs are stateless, meaning they require explicit rules for both inbound and outbound traffic. For the web server to accept HTTPS requests from the internet, an inbound rule allowing TCP 443 from 0.0.0.0/0 is needed. For the server to respond to those requests, an outbound rule allowing ephemeral ports (TCP 1024-65535) to 0.0.0.0/0 is required to handle return traffic.

Additionally, to allow the server to initiate outbound HTTPS connections for software updates, a separate outbound rule allowing TCP 443 to 0.0.0.0/0 is necessary.

Exam trap

The trap here is that candidates often forget that Network ACLs are stateless and assume that allowing inbound HTTPS automatically permits the return traffic, leading them to choose option C instead of the more precise option D that includes ephemeral port rules.

How to eliminate wrong answers

Option A is wrong because it includes an unnecessary inbound rule for SSH (TCP 22) that is not required by the question, and it does not explicitly allow outbound ephemeral ports for return traffic, which is essential for stateless NACLs. Option B is wrong because it restricts outbound traffic to a specific software update server IP, which is not the minimum set; the question requires the ability to initiate outbound connections to the internet, not a specific IP, and it also omits the outbound ephemeral port rule for return traffic. Option C is wrong because while it allows all outbound traffic, it does not include the specific outbound rule for TCP 443 to 0.0.0.0/0 for software updates; the 'allow all' rule would work, but the question asks for the minimum set, and option C is overly permissive and not the most restrictive correct answer.

13
MCQeasy

A company wants to use AWS WAF to protect its web application from common web exploits. Which AWS service must be integrated with AWS WAF to provide this protection?

A.Security Groups
B.Application Load Balancer or Amazon CloudFront
C.Amazon Route 53
D.Network ACLs
AnswerB

AWS WAF is a managed Layer 7 web application firewall that you attach by associating a web access control list (ACL) with a supported resource, specifically an Application Load Balancer for regional HTTP/S requests or Amazon CloudFront for edge-based delivery. An ALB terminates HTTP/HTTPS and forwards requests to targets, giving WAF a point to inspect URI, headers, and body; CloudFront provides the same inspection at CloudFront edge locations before origin processing. This is the supported integration path, along with API Gateway and App Runner, so the correct target is an ALB or CloudFront.

Why this answer

AWS WAF is a web application firewall that inspects HTTP/HTTPS traffic at Layer 7. It must be integrated with a service that can terminate HTTP/HTTPS connections and forward the traffic to WAF for inspection. Both Application Load Balancer (ALB) and Amazon CloudFront support this integration, allowing WAF to filter requests based on rules such as SQL injection or cross-site scripting.

Security Groups and Network ACLs operate at the network and transport layers (Layers 3/4) and cannot provide Layer 7 inspection.

Exam trap

The trap here is that candidates often confuse network-layer controls (Security Groups, NACLs) with application-layer protection, assuming any firewall can be used with WAF, but only ALB and CloudFront provide the necessary Layer 7 integration for AWS WAF.

How to eliminate wrong answers

Option A is wrong because Security Groups act as a virtual firewall for EC2 instances at the instance level, operating at Layer 3/4 (IP and port) and cannot inspect HTTP/HTTPS payloads or integrate with AWS WAF. Option C is wrong because Amazon Route 53 is a DNS service that resolves domain names to IP addresses and does not handle HTTP traffic or provide a point for WAF rule evaluation. Option D is wrong because Network ACLs are stateless Layer 3/4 filters applied at the subnet level, which cannot perform Layer 7 inspection or be associated with AWS WAF.

14
Multi-Selectmedium

A security engineer is tasked with securing an Amazon RDS for MySQL database. The database must be accessible only from a specific set of EC2 instances. Which THREE steps should the engineer take?

Select 3 answers
A.Disable encryption at rest to improve performance.
B.Enable encryption at rest for the RDS instance.
C.Launch the RDS instance in a private subnet.
D.Create a security group that allows inbound traffic on port 3306 from the EC2 instances' security group.
E.Associate the RDS instance with a public subnet for easier access.
AnswersB, C, D

Enabling encryption at rest protects the database by encrypting data files in the underlying block storage, along with automated backups, snapshots, and read replicas, using an AWS KMS customer master key (AES-256). This satisfies compliance requirements such as PCI DSS or HIPAA and defends against theft of physical storage or unauthorized access to snapshots. Must be configured at instance creation time; to encrypt an existing unencrypted instance, you have to create an encrypted snapshot and restore from it.

Why this answer

Enabling encryption at rest for the RDS instance ensures that data stored on the underlying storage is encrypted using AWS Key Management Service (KMS). This is a security best practice for protecting sensitive data at rest, and it does not conflict with the requirement to restrict network access. Encryption at rest is independent of network access controls and is essential for compliance with many security frameworks.

Exam trap

The trap here is that candidates may focus solely on network-level controls (security groups and subnets) and overlook encryption at rest as a required security step, or they may incorrectly believe that encryption at rest degrades performance significantly for MySQL workloads.

15
MCQeasy

A company wants to block traffic from a specific IP address range from accessing an Application Load Balancer (ALB). Which AWS feature should be used?

A.Network ACL
B.Security Group for the ALB
C.Route53
D.AWS WAF
AnswerD

AWS WAF is the correct service because it attaches as a web access control list (web ACL) directly to the Application Load Balancer. You can create an IP set match rule to block the specific IPv4 or IPv6 address before the request reaches the ALB, and WAF inspects each HTTP/HTTPS request at Layer 7. It also offers managed rules, rate-based rules, and geo-matching for more granular traffic control, and its integration is a one-click attachment to ALBs.

Why this answer

AWS WAF is the correct feature to block traffic from a specific IP address range from accessing an Application Load Balancer. WAF integrates directly with ALB and allows you to create rules based on IP addresses, which can be used to allow or block requests. Network ACLs and security groups operate at the network layer and are not specific to ALB traffic inspection.

Exam trap

SCS-C02 often tests the difference between security groups, NACLs, and WAF, and candidates may incorrectly choose security groups because they think they can block IPs, but security groups only allow.

How to eliminate wrong answers

Option A is wrong because Network ACLs are stateless and operate at the subnet level, not directly on the ALB; they can block IP ranges but are not the recommended way to filter traffic for an ALB and lack application-layer awareness. Option B is wrong because Security Groups for the ALB control inbound traffic to the ALB but only support allow rules, not explicit deny rules for specific IP ranges; you cannot block a specific IP range with a security group. Option C is wrong because Route53 is a DNS service and cannot block traffic based on IP addresses; it can be used for DNS-based filtering but not for blocking traffic to an ALB.

16
MCQhard

A security engineer is configuring AWS WAF to protect an Application Load Balancer (ALB) from SQL injection attacks. The engineer must ensure that only requests with a specific header are allowed and that SQL injection attempts are blocked. Which combination of AWS WAF components should the engineer use?

A.A web ACL with a rule that blocks requests missing the required header, and a rule that uses the SQL injection match condition to block malicious requests.
B.A web ACL with a rule that allows requests with the header and a rule that uses the SQL injection match condition to count malicious requests.
C.A web ACL with a rule that blocks requests missing the header, and a rule that uses a regex pattern set to block SQL injection attempts.
D.A web ACL with a rate-based rule to limit requests and a rule that uses the SQL injection match condition to block malicious requests.
AnswerA

AWS WAF web ACLs contain rules that can inspect headers and use match conditions like SQL injection. A rule to block requests missing the header enforces the header requirement, and a SQL injection match condition blocks malicious payloads. Both can be combined in a single web ACL associated with the ALB.

Why this answer

AWS WAF web ACLs can contain multiple rules. To enforce a required header, a rule that blocks requests missing that header is needed. To block SQL injection, the built-in SQL injection match condition is the appropriate choice.

Combining these two rules in a web ACL associated with the ALB meets both requirements.

Exam trap

The trap here is confusing count and block actions, or assuming that a rate-based rule or regex pattern set can replace the dedicated SQL injection match condition and header check.

17
MCQhard

A company uses AWS Direct Connect to connect its on-premises data center to a VPC. The security team wants to encrypt all traffic between on-premises and the VPC. Which solution should be used?

A.Enable encryption on the Direct Connect virtual interface
B.Use VPC Peering with encryption
C.Set up an IPsec VPN over the Direct Connect connection
D.Configure TLS on all applications
AnswerC

Yes—this is the standard pattern when you need encryption over Direct Connect. You can deploy a site-to-site VPN on a public virtual interface, or terminate a software VPN on an EC2 instance behind a private VIF, so IPsec encapsulates the IP packets and secures the entire path while still benefiting from Direct Connect's bandwidth and latency. IPsec provides authenticity, integrity, and confidentiality for all traffic, making it the appropriate answer for the stated requirement.

Why this answer

Direct Connect does not natively encrypt traffic; it provides a private, low-latency connection but the data traverses it in cleartext. By establishing an IPsec VPN tunnel over the Direct Connect link (often called a 'Direct Connect VPN' or using a virtual private gateway with a VPN attachment), you encrypt all traffic between on-premises and the VPC at the network layer, meeting the security team's requirement for encryption.

Exam trap

The trap here is that candidates assume Direct Connect inherently provides encryption because it is a private connection, but AWS explicitly states that Direct Connect does not encrypt traffic, and the correct approach is to overlay an IPsec VPN tunnel.

How to eliminate wrong answers

Option A is wrong because Direct Connect virtual interfaces (private, public, or transit) do not support native encryption; they operate at Layer 2/3 without any built-in encryption mechanism. Option B is wrong because VPC Peering does not provide encryption; it is a Layer 3 connection that routes traffic over the AWS backbone without encryption, and it cannot be used to connect an on-premises data center to a VPC. Option D is wrong because configuring TLS on all applications only encrypts application-layer traffic for specific protocols (e.g., HTTPS), leaving other traffic (e.g., SSH, database connections, or custom protocols) unencrypted and does not provide a comprehensive network-layer encryption solution.

18
MCQeasy

A security engineer needs to ensure that an EC2 instance can only be accessed using SSH key pairs, not passwords. Which configuration is required?

A.Use EC2 Instance Connect instead of SSH
B.Set 'PasswordAuthentication no' in /etc/ssh/sshd_config on the EC2 instance
C.Attach an IAM role to the instance that denies password-based access
D.Configure the security group to allow SSH only from specific IP addresses
AnswerB

Forcing key-based authentication on an EC2 instance requires disabling password logins at the OpenSSH daemon level by setting 'PasswordAuthentication no' in /etc/ssh/sshd_config and restarting sshd. This directly changes how the SSH server validates users: public key cryptography becomes the only accepted method, and password prompts are no longer offered. Because sshd reads this configuration on startup, the setting takes effect for all SSH connections, making it a true enforcement mechanism rather than a workflow convenience.

Why this answer

SSH password authentication is controlled by the `PasswordAuthentication` directive in `/etc/ssh/sshd_config`. Setting it to `no` disables password-based logins, forcing users to authenticate using SSH key pairs (public-key cryptography). This is the standard, OS-level method to enforce key-only SSH access on an EC2 instance.

Exam trap

The trap here is that candidates confuse network-level controls (security groups) or IAM permissions with OS-level authentication settings, assuming AWS services can enforce SSH password policies when only the instance's SSH daemon configuration can do so.

How to eliminate wrong answers

Option A is wrong because EC2 Instance Connect is a service that uses SSH keys (or AWS-provided keys) to connect, but it does not disable password authentication on the instance; it merely provides an alternative connection method. Option C is wrong because IAM roles control AWS API-level permissions (e.g., starting/stopping instances) and cannot enforce OS-level SSH authentication settings like password vs. key-based login. Option D is wrong because security group rules restrict network access by source IP, not the authentication method; they do not prevent password-based SSH logins if the instance allows them.

19
MCQeasy

A company wants to securely store and manage SSL/TLS certificates for use with CloudFront. Which AWS service should be used?

A.AWS Identity and Access Management (IAM)
B.AWS Key Management Service (AWS KMS)
C.AWS Certificate Manager (ACM)
D.AWS CloudHSM
AnswerC

AWS Certificate Manager provisions SSL/TLS certificates for public and private domains, handles domain validation via DNS or email, and automatically renews eligible certificates before expiry. It natively deploys the certificate to integrated AWS services such as Application Load Balancers, CloudFront, and API Gateway, eliminating manual installation and tracking. Because the private key is generated in and protected by AWS-managed hardware, ACM is the correct service for the stated requirement to securely store and manage SSL/TLS certificates.

Why this answer

AWS Certificate Manager (ACM) is the correct service because it is specifically designed to provision, manage, and deploy public and private SSL/TLS certificates for use with AWS services like CloudFront. ACM integrates directly with CloudFront to automatically renew certificates before expiration, eliminating manual renewal overhead. It also handles the complex certificate chain and private key management securely, ensuring HTTPS termination at CloudFront edge locations.

Exam trap

The trap here is that candidates often confuse AWS KMS or IAM Server Certificate Store as viable options for CloudFront, but ACM is the only service that provides automatic renewal and native integration with CloudFront, and certificates must be in us-east-1.

How to eliminate wrong answers

Option A is wrong because AWS Identity and Access Management (IAM) is a service for managing user identities, permissions, and access control, not for storing or managing SSL/TLS certificates; while IAM can store server certificates for use with Elastic Load Balancers (ELBs) via the IAM Server Certificate Store, it does not support CloudFront and lacks automatic renewal features. Option B is wrong because AWS Key Management Service (AWS KMS) is a managed service for creating and controlling encryption keys used to encrypt data at rest, not for managing SSL/TLS certificates; KMS does not handle certificate issuance, renewal, or integration with CloudFront. Option D is wrong because AWS CloudHSM provides dedicated hardware security modules (HSMs) for cryptographic key storage and operations, but it is not designed for SSL/TLS certificate lifecycle management; using CloudHSM for certificates would require custom development and manual renewal, and it does not natively integrate with CloudFront.

20
MCQeasy

A security engineer needs to ensure that all Amazon EBS volumes attached to EC2 instances in a production account are encrypted at rest. The engineer wants to enforce this requirement automatically and prevent the creation of unencrypted volumes. Which action should the engineer take?

A.Attach a bucket policy to the EBS service that requires encryption.
B.Enable EBS encryption by default in the AWS Region.
C.Create an IAM policy that denies the ec2:CreateVolume action unless the encrypted parameter is true.
D.Use AWS Config to monitor for unencrypted volumes and automatically delete them.
AnswerB

Enabling EBS encryption by default ensures that all new EBS volumes created in the Region are automatically encrypted using the default KMS key for EBS encryption. This enforces encryption at rest without requiring manual intervention for each volume. It also prevents the creation of unencrypted volumes, meeting the requirement.

Why this answer

Enabling EBS encryption by default in the Region ensures that all new EBS volumes are automatically encrypted at rest. This is a simple, effective way to enforce encryption and prevent the creation of unencrypted volumes. It applies to all new volumes regardless of how they are created, providing a robust control.

Exam trap

The trap here is thinking that IAM policies or AWS Config are the primary enforcement mechanisms, when the simplest and most direct method is enabling encryption by default.

21
MCQmedium

A company is designing a VPC for a three-tier web application that must be accessible from the internet only via HTTPS. The web servers must be able to initiate outbound connections to the internet for software updates, but the database servers must have no direct internet access. Which architecture meets these requirements?

A.Web servers in private subnets, database servers in public subnets, both behind an Application Load Balancer
B.Web servers in public subnets, database servers in private subnets with a route to a NAT Gateway in a public subnet
C.Web servers in private subnets with a route to a NAT Gateway, database servers in private subnets with no route to the NAT Gateway, both behind an Application Load Balancer in public subnets
D.Web servers in public subnets with Elastic IPs, database servers in private subnets with a route to an internet gateway
AnswerC

This architecture correctly places the web servers in private subnets with a 0.0.0.0/0 route to a NAT gateway in public subnets, so the web servers can download patches and updates but cannot be directly reached from the internet. The database servers are in separate private subnets with no route to the NAT gateway or to an internet gateway, giving them no internet path at all—protecting against both inbound attacks and outbound data exfiltration. The internet-facing Application Load Balancer resides in public subnets, accepts HTTPS traffic on port 443, terminates TLS, and forwards requests to the web servers over private IPs, while the web servers communicate with the database over the VPC internal network only.

Why this answer

Web servers in private subnets behind an Application Load Balancer (ALB) in public subnets can receive internet traffic via the ALB, and they can initiate outbound internet connections via a NAT Gateway. Database servers in private subnets with no route to the NAT Gateway have no internet access, meeting the requirement. This architecture isolates the database tier while allowing web tier outbound updates.

Exam trap

SCS-C02 often tests the misconception that private subnets always have no internet access, when in fact a private subnet with a route to a NAT Gateway allows outbound internet, which may violate strict isolation requirements for database tiers.

How to eliminate wrong answers

Option A is wrong because database servers in public subnets would have direct internet access, violating the requirement. Option B is wrong because web servers in public subnets would be directly accessible from the internet, and the database servers would have a route to a NAT Gateway, giving them outbound internet access, which is not allowed. Option D is wrong because web servers in public subnets with Elastic IPs are directly accessible, and database servers with a route to an internet gateway would have internet access, violating the requirement.

22
Multi-Selecthard

Which THREE of the following are best practices for securing an Amazon RDS database instance? (Select THREE.)

Select 3 answers
A.Enable encryption at rest using AWS KMS
B.Place the RDS instance in a private subnet
C.Use strong passwords and rotate them regularly
D.Enable public accessibility for ease of management
E.Use the default database port
AnswersA, B, C

RDS encryption at rest uses AWS KMS envelope encryption, where a customer master key (CMK) encrypts the data keys that encrypt your database storage, automated backups, snapshots, and read replicas. If the underlying EBS volumes are compromised, the encrypted data remains unreadable without KMS key access, and you also get a compliance benefit. Note that you must enable encryption at launch because you cannot encrypt an existing unencrypted RDS instance in place.

Why this answer

Enabling encryption at rest using AWS KMS ensures that the underlying storage for the RDS instance, automated backups, read replicas, and snapshots are encrypted using AES-256. This protects data at rest from unauthorized physical access or storage media theft, and is a fundamental security best practice for compliance frameworks like PCI DSS and HIPAA.

Exam trap

The trap here is that candidates often confuse 'public accessibility' with necessary management access, but AWS explicitly recommends placing RDS in a private subnet and using a bastion host or AWS Systems Manager Session Manager for secure administrative access, not a public IP.

23
MCQhard

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The ALB is configured to terminate SSL/TLS and forward traffic to the instances over HTTP. The security team wants to ensure that the instances only accept traffic from the ALB, not from any other source. How can this be achieved?

A.Configure the instance security group to allow HTTP traffic only from the VPC CIDR block.
B.Configure the instance security group to allow HTTP traffic only from the ALB's security group.
C.Configure the network ACL on the instance's subnet to allow HTTP traffic only from the ALB's private IP address.
D.Configure the instance security group to allow HTTP traffic only from the subnet CIDR block where the ALB resides.
AnswerB

Referencing the ALB's security group as the source in the instance security group rule limits inbound HTTP to traffic originating from the elastic network interfaces that actually belong to the ALB nodes. This SG-to-SG association follows the ALB as it scales or replaces its ENIs across Availability Zones, because any ENI that is a member of the ALB security group is automatically allowed. It is the recommended, least-privilege approach for placing an EC2 instance behind an Application Load Balancer.

Why this answer

Referencing the ALB's security group in the instance security group rule allows traffic only from the ALB, regardless of the ALB's IP address changes. This leverages AWS security group referencing, which is a managed and scalable way to restrict traffic to a specific source security group. The ALB's security group acts as a logical identifier, ensuring that only traffic forwarded by the ALB reaches the instances.

Exam trap

The trap here is that candidates often confuse security group referencing with IP-based rules, mistakenly thinking that using the ALB's subnet CIDR or VPC CIDR is sufficient, when in fact those approaches allow traffic from any resource in those ranges, not just the ALB.

How to eliminate wrong answers

Option A is wrong because allowing HTTP traffic from the entire VPC CIDR block would permit any resource within the VPC (including compromised instances or unauthorized services) to directly access the instances, bypassing the ALB. Option C is wrong because network ACLs are stateless and operate at the subnet level, not the instance level; they cannot restrict traffic based on the ALB's private IP address reliably since ALB IPs can change, and they would require managing both inbound and outbound rules, which is less secure and more complex than security group referencing. Option D is wrong because allowing traffic from the subnet CIDR block where the ALB resides would permit any resource in that subnet (including other instances or services) to access the instances, not just the ALB itself.

24
MCQhard

A company has a multi-account AWS environment using AWS Organizations. The security team wants to centrally manage VPC security group rules across all accounts. Which solution should be used?

A.Use AWS Firewall Manager to define security group policies and enforce them across accounts.
B.Use AWS Organizations Service Control Policies to restrict security group modifications.
C.Use AWS Config rules to automatically remediate non-compliant security groups.
D.Use AWS Network Firewall to inspect traffic and block unauthorized connections.
AnswerA

AWS Firewall Manager is the correct service for centrally managing security group rules across all accounts in an AWS Organization. You can create a security group policy that defines baseline ingress/egress rules, and Firewall Manager automatically applies that policy to compliant and non-compliant resources in every member account, including new accounts added later. This is proactive enforcement, not just detection, and it also supports audit policies that continuously check and report security group drift.

Why this answer

AWS Firewall Manager is the correct choice because it provides centralized management of security group rules across multiple accounts in an AWS Organization. It allows the security team to define a common security group policy and automatically enforce it across all member accounts, ensuring consistent security posture without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Config's detection and remediation capabilities with centralized enforcement, not realizing that Config operates per-account and lacks the multi-account policy management that Firewall Manager provides.

How to eliminate wrong answers

Option B is wrong because AWS Organizations Service Control Policies (SCPs) are used to restrict permissions at the account level, not to manage or enforce specific security group rules; they can prevent modifications but cannot define or apply the rules themselves. Option C is wrong because AWS Config rules can detect non-compliant security groups and trigger remediation actions, but they do not provide centralized enforcement across accounts; each account must have its own Config setup and remediation logic. Option D is wrong because AWS Network Firewall is a managed firewall service that inspects network traffic at the VPC level, not a tool for managing security group rules; it operates at layers 3-7 and cannot define or enforce security group configurations.

25
Multi-Selecteasy

A Security Engineer is designing a secure VPC architecture. Which THREE components are essential for creating a public subnet that can host a web server accessible from the internet?

Select 3 answers
A.VPN connection to on-premises
B.Route table with a default route (0.0.0.0/0) pointing to the IGW
C.Security group allowing inbound HTTP/HTTPS from 0.0.0.0/0
E.Internet Gateway (IGW)
AnswersB, C, E

A route table entry for 0.0.0.0/0 targeting the Internet Gateway (IGW) is the core routing mechanism that makes a subnet public. Without this default route, the IGW exists but traffic from the subnet cannot reach it; the VPC's implicit local route only handles VPC-internal traffic. This route is required for the web server to receive inbound HTTP/HTTPS from the internet and to send responses back, making it a mandatory component of a public subnet design.

Why this answer

A public subnet requires a route table that directs traffic destined for 0.0.0.0/0 to an Internet Gateway (IGW). Without this default route, instances in the subnet cannot send or receive traffic from the internet, even if they have public IP addresses. The IGW acts as the target for this route, enabling bidirectional communication between the VPC and the internet.

Exam trap

The trap here is that candidates often confuse a NAT Gateway with an Internet Gateway, mistakenly thinking a NAT Gateway can provide inbound internet access to a public subnet, when in fact it only supports outbound traffic from private subnets.

26
MCQhard

Refer to the exhibit. A security engineer runs the describe-instances command for an EC2 instance. The instance has a public IP address. The security group "allow-ssh-http" has inbound rules that allow SSH from 0.0.0.0/0 and HTTP from 0.0.0.0/0. The engineer wants to block SSH access from the internet while keeping HTTP access. Which change should be made?

A.Remove the inbound rule that allows SSH from 0.0.0.0/0 from the security group.
B.Add a network ACL rule to deny SSH inbound from 0.0.0.0/0.
C.Disassociate the public IP address from the instance.
D.Modify the security group to add a deny rule for SSH from 0.0.0.0/0.
AnswerA

The security group acts as a stateful, allow-only firewall at the instance level. Removing the inbound SSH rule for 0.0.0.0/0 immediately denies all internet SSH traffic while leaving the HTTP rule intact. Since security groups contain no explicit deny rules, the absence of an allow rule is what blocks the connection. This is the precise, least-disruptive change because it only restricts SSH and does not affect HTTP reachability.

Why this answer

Security groups are stateful and support only allow rules; removing the inbound SSH rule from the security group effectively blocks SSH access from the internet (0.0.0.0/0) while the HTTP rule remains, allowing HTTP traffic. Since the instance already has a public IP address, removing the SSH rule is the simplest and most direct way to achieve the goal without affecting other traffic.

Exam trap

Candidates may incorrectly think security groups support deny rules (like network ACLs) or that adding a network ACL deny rule is the best solution. While a NACL deny rule can block SSH at the subnet level, it affects all instances in the subnet. Security groups are allow-only and provide instance-level control, so the correct action is to remove the SSH allow rule from the security group.

How to eliminate wrong answers

Option B is wrong because network ACLs are stateless and require both inbound and outbound rules to be explicitly configured; adding a deny rule for SSH inbound would still require a corresponding outbound rule to allow return traffic, and it would not override the security group's allow rule for SSH, which would still permit the traffic. Option C is wrong because disassociating the public IP address would block all internet access (including HTTP), not just SSH, which violates the requirement to keep HTTP access. Option D is wrong because security groups do not support deny rules; they only support allow rules, so you cannot add a deny rule for SSH; you must remove the allow rule instead.

27
MCQeasy

A company wants to allow an EC2 instance to access a DynamoDB table without traversing the internet. Which AWS feature should be used?

A.VPC Peering
B.ClassicLink
D.VPC Gateway Endpoint for DynamoDB
AnswerD

A VPC Gateway Endpoint for DynamoDB is a logical gateway object added to the VPC route table, allowing instances to reach DynamoDB via AWS's private network without attaching an internet gateway or NAT device. It works by adding an entry to the route table that points DynamoDB's prefix list to the endpoint, and it supports IAM policies on the endpoint itself to restrict access. This is the recommended, private, and cost-effective solution for an EC2 instance to access DynamoDB securely and is the correct answer.

Why this answer

A VPC Gateway Endpoint for DynamoDB allows EC2 instances within a VPC to access DynamoDB without traversing the internet. It uses AWS PrivateLink to route traffic through the AWS network, ensuring low latency and enhanced security by keeping traffic within the AWS backbone.

Exam trap

The trap here is that candidates often confuse Gateway Endpoints with Interface Endpoints (for services like S3 or DynamoDB) or mistakenly think VPC Peering or NAT Gateway can provide private access to DynamoDB, but only Gateway Endpoints support DynamoDB without internet traversal.

How to eliminate wrong answers

Option A is wrong because VPC Peering connects two VPCs to enable communication between them, but it does not provide a direct, internet-free path to DynamoDB; DynamoDB is a managed service outside the VPC. Option B is wrong because ClassicLink allows EC2 instances in a classic network to communicate with a VPC, but it does not apply to DynamoDB access and is deprecated. Option C is wrong because a NAT Gateway enables outbound internet access for private subnets, but it forces traffic to traverse the internet, violating the requirement to avoid internet traversal.

28
MCQhard

A company uses AWS Direct Connect to connect its on-premises data center to AWS. The connection is set up with a private VIF to a VPC using a virtual private gateway. The security team wants to encrypt all traffic between on-premises and the VPC. Which solution should be implemented?

A.Configure TLS on the applications
B.Set up an IPsec VPN over the Direct Connect private VIF
C.Use a site-to-site VPN over the internet instead of Direct Connect
D.Enable encryption on the Direct Connect private VIF
AnswerB

Setting up an IPsec VPN over the Direct Connect private VIF encapsulates all IP traffic between your on-premises network and the VPC, providing network-layer confidentiality and integrity while still using the private, low-latency Direct Connect path. IPsec operates at Layer 3, so it secures every protocol and service traversing the link, not just specific applications, and it is the standard way to add encryption because Direct Connect does not encrypt traffic natively. The VPN tunnel rides inside the private VIF, so you retain the dedicated bandwidth and avoid the public internet.

Why this answer

Direct Connect private VIFs do not natively encrypt traffic; they provide a private, dedicated network connection but the data traverses it in cleartext. By establishing an IPsec VPN tunnel over the private VIF, you encrypt all traffic between the on-premises network and the VPC, meeting the security team's requirement for encryption while still leveraging the low latency and reliability of Direct Connect.

Exam trap

The trap here is that candidates assume Direct Connect private VIFs are inherently encrypted because they are 'private,' but AWS explicitly states that Direct Connect does not provide encryption—you must add IPsec yourself.

How to eliminate wrong answers

Option A is wrong because TLS encrypts only application-layer traffic (e.g., HTTPS), not all IP traffic between the data center and VPC; it would require application-level changes and does not protect non-HTTP protocols. Option C is wrong because using a site-to-site VPN over the internet introduces internet-based latency, jitter, and potential reliability issues, and it abandons the dedicated Direct Connect link, which is already in place for performance and compliance reasons. Option D is wrong because Direct Connect private VIFs do not support native encryption; there is no toggle or feature to 'enable encryption' on a VIF—encryption must be added via an overlay like IPsec.

29
MCQeasy

A company wants to block SSH access (port 22) to all EC2 instances from the internet, but allow SSH from a specific management VPN IP range (10.0.0.0/16). Which configuration should be used?

A.Configure a security group to allow inbound SSH from 10.0.0.0/16 only.
B.Use an IAM policy to restrict SSH access to the management IP range.
C.Configure a network ACL to allow inbound SSH from 10.0.0.0/16 and deny from 0.0.0.0/0.
D.Configure a security group to allow inbound SSH from 0.0.0.0/0 and deny from 10.0.0.0/16.
AnswerA

A security group acts as a stateful instance-level firewall with an implicit deny-all for inbound traffic, so configuring a rule that allows inbound TCP port 22 from only 10.0.0.0/16 satisfies the requirement. Because security groups only contain permissive rules, any SSH connection sourced outside that CIDR is automatically blocked by the default deny, without needing an explicit deny. This approach also automatically allows return traffic for established sessions due to statefulness, so no separate outbound rule is required.

Why this answer

Security groups are stateful firewalls that control inbound and outbound traffic at the instance level. By configuring a security group to allow inbound SSH (port 22) only from the management VPN IP range (10.0.0.0/16), all other inbound traffic on port 22 is implicitly denied because security groups operate on a default-deny principle. This meets the requirement to block SSH from the internet while permitting access from the specified internal range.

Exam trap

The trap here is that candidates often confuse the stateless nature of network ACLs with the stateful behavior of security groups, leading them to choose a network ACL solution (Option C) without considering the need for explicit outbound rules, or they incorrectly think security groups can deny specific IP ranges (Option D).

How to eliminate wrong answers

Option B is wrong because IAM policies control permissions for AWS API actions (e.g., ec2:AuthorizeSecurityGroupIngress), not network traffic at the packet level; they cannot filter SSH connections to EC2 instances. Option C is wrong because network ACLs are stateless and require explicit inbound and outbound rules; allowing inbound SSH from 10.0.0.0/16 and denying from 0.0.0.0/0 would work for inbound traffic, but the outbound return traffic must also be explicitly allowed, and the question asks for a configuration that blocks SSH from the internet—security groups are the simpler, correct choice for instance-level control. Option D is wrong because security groups only support allow rules; you cannot explicitly deny traffic from a specific IP range within a security group, and allowing from 0.0.0.0/0 would permit SSH from the internet, which contradicts the requirement.

30
Multi-Selecteasy

A company wants to restrict access to an S3 bucket so that only traffic from a specific VPC can download objects. Which combination of actions should the company take? (Choose TWO.)

Select 2 answers
A.Attach an Internet gateway to the VPC and route traffic through it.
B.Attach a security group to the S3 bucket.
C.Create an S3 bucket policy that allows access only from the VPC using the aws:SourceVpc condition.
D.Create a NAT gateway in the VPC for outbound traffic.
E.Create a VPC endpoint for Amazon S3 in the VPC.
AnswersC, E

Create a bucket policy whose Principal is the intended IAM role or account and add a Condition using the aws:SourceVpc key set to the VPC ID. This allows requests only when they originate from that exact VPC, so traffic from any other VPC or the public internet is blocked. To make this work, requests must arrive through a VPC endpoint for S3, because the aws:SourceVpc condition key is populated only for traffic that uses an endpoint.

Why this answer

To restrict access to an S3 bucket so that only traffic from a specific VPC can download objects, the correct combination is to create an S3 bucket policy that uses the aws:SourceVpc condition (Option C) and create a VPC endpoint for Amazon S3 in the VPC (Option E). The bucket policy with aws:SourceVpc ensures that only requests originating from the specified VPC are allowed, while the VPC endpoint enables private connectivity between the VPC and S3 without traversing the internet. Option A (Internet gateway) would make the VPC publicly accessible and is not required for private access.

Option B (NAT gateway) is used for outbound internet access from private subnets, not for restricting access to S3. Option D (security group) cannot be attached to an S3 bucket; security groups apply to EC2 instances or other resources, not to S3.

31
MCQhard

Refer to the exhibit. A security engineer runs the iptables command on an EC2 instance in a VPC. The instance has a security group that allows all outbound traffic and inbound SSH from 0.0.0.0/0, HTTP from 0.0.0.0/0, and HTTPS from 0.0.0.0/0. A user from IP 203.0.113.5 tries to connect to the instance over HTTP. What will happen?

A.The connection succeeds because the security group allows HTTP.
B.The connection succeeds because iptables allows HTTP from anywhere.
C.The connection is dropped by iptables.
D.The connection is dropped by the security group.
AnswerC

When the HTTP packet from the public client reaches the instance, the security group already allows it, so it is not rejected at the VPC edge. In the INPUT chain, the ACCEPT rule for 10.0.0.0/16 does not match because the source IP is outside that range, and the subsequent DROP rule or default policy DROP terminates the packet. This drop happens inside the instance OS, not in the security group.

Why this answer

The iptables command shown in the exhibit (not provided here but implied to have a default DROP or REJECT policy on the INPUT chain, or a specific rule that drops HTTP traffic) overrides the security group's permissive rules. Security groups act as a virtual firewall at the instance level, but iptables operates within the instance's OS kernel netfilter framework and is evaluated after the security group. Since iptables drops the HTTP connection, the packet is discarded before reaching the application, regardless of the security group allowing HTTP from 0.0.0.0/0.

Exam trap

The trap here is that candidates assume security groups are the only firewall layer and forget that iptables rules within the instance can override them, leading them to incorrectly choose option A or B.

How to eliminate wrong answers

Option A is wrong because the security group allows HTTP, but iptables rules are evaluated after the security group and can override its permissions; the connection is dropped by iptables. Option B is wrong because iptables does not allow HTTP from anywhere; the exhibit's iptables configuration (implied) drops HTTP traffic, so the connection fails. Option D is wrong because the security group allows HTTP from 0.0.0.0/0, so it does not drop the connection; the drop occurs due to iptables.

32
MCQhard

A security engineer is investigating a potential breach. The engineer notices that an EC2 instance's security group allows inbound SSH (port 22) from 0.0.0.0/0. The instance is in a public subnet and has a public IP address. However, the engineer finds that SSH access is only possible from a specific IP address. What is the most likely explanation?

A.The network ACL allows inbound SSH from 0.0.0.0/0
B.The security group rule is being overridden by a more restrictive security group attached to the same instance
C.The security group rule is being evaluated but the instance's operating system firewall is blocking SSH
D.The network ACL denies inbound SSH from all IPs except the specific IP
AnswerD

Network ACLs are stateless and can explicitly deny traffic. If the NACL denies SSH from all IPs except the specific one, it would override the permissive security group rule, explaining why only that IP can connect.

Why this answer

Security groups in AWS are stateful and allow-only — they cannot deny traffic. If a security group permits SSH from 0.0.0.0/0 but access is restricted to one IP, the restriction must come from a stateless network ACL, which supports both allow and deny rules and is evaluated before the security group. A network ACL that denies SSH from all sources except the specific IP would produce exactly this observed behavior.

This is the only option that explains a restriction despite a permissive security group.

Exam trap

SCS-C02 often tests the misconception that security groups can deny traffic or that multiple security groups override each other, when in fact security groups are allow-only and additive — only NACLs can deny.

How to eliminate wrong answers

Option A is wrong because a network ACL allowing SSH from 0.0.0.0/0 would permit, not restrict, traffic — it cannot explain why only one IP can connect. Option B is wrong because security groups are additive and allow-only; a more restrictive security group attached to the same instance cannot override a permissive rule, it can only add more allows. Option C is wrong because while an OS-level firewall could block SSH, the question asks for the most likely explanation given the AWS-native controls described, and a network ACL deny is the canonical AWS mechanism that produces this pattern; an OS firewall is possible but less likely and not the best answer.

33
MCQmedium

A security engineer is troubleshooting connectivity issues between two EC2 instances in the same VPC but different subnets. Both instances have security groups that allow all traffic from each other's security group. However, traffic is still blocked. What is the most likely cause?

A.The instances are in different VPCs.
B.The network ACL for one or both subnets is blocking the traffic.
C.The route tables do not have a route between the subnets.
D.VPC Flow Logs are not enabled.
AnswerB

Network ACLs are stateless filters applied at the subnet boundary and are evaluated before Security Groups. A custom network ACL with an explicit deny rule, or with an inbound allow rule that lacks a matching outbound ephemeral-port allow rule, will drop traffic even when Security Groups permit it. Since stateful Security Groups do not validate the complete bidirectional flow, a misconfigured network ACL remains a common cause of unexplained communication failures between instances.

Why this answer

The most likely cause is that the network ACL (NACL) for one or both subnets is blocking the traffic. Security groups are stateful and allow traffic based on rules, but NACLs are stateless and require explicit inbound and outbound rules for traffic to flow. Even if security groups permit all traffic between the instances, a NACL denying the traffic (e.g., by having a default deny rule or missing ephemeral port ranges) will block it.

Since the instances are in different subnets, the NACL associated with each subnet must allow the traffic in both directions.

Exam trap

The trap here is that candidates often assume security groups alone control all traffic and overlook the stateless nature of network ACLs, especially when instances are in different subnets where NACLs apply at the subnet boundary.

How to eliminate wrong answers

Option A is wrong because the question states both instances are in the same VPC, so being in different VPCs is not applicable. Option C is wrong because route tables in a VPC automatically have a local route that enables communication between subnets within the same VPC, so no additional route is needed. Option D is wrong because VPC Flow Logs are a monitoring feature that logs traffic metadata but do not affect traffic flow; they cannot block or allow traffic.

34
Multi-Selectmedium

A company uses AWS CloudFormation to deploy infrastructure. The security team wants to ensure that all S3 buckets created by CloudFormation have encryption enabled by default. Which TWO approaches can achieve this?

Select 2 answers
A.Create an AWS Config rule that checks for S3 bucket encryption and auto-remediates
B.Enable S3 Block Public Access at the account level
C.Attach a service control policy (SCP) to the root OU that denies S3 bucket creation without encryption
D.Attach an IAM role to the CloudFormation service that grants permissions to encrypt buckets
E.Use a CloudFormation stack policy to deny creation of S3 buckets without encryption
AnswersA, C

The AWS Config managed rule s3-bucket-server-side-encryption-enabled evaluates every S3 bucket against your encryption policy and marks those without default encryption as non-compliant. By attaching an automatic remediation action, Config invokes an SSM Automation document that runs PutBucketEncryption on the non-compliant bucket, bringing it into compliance without manual intervention. This detects buckets that CloudFormation created without encryption and repairs them, making it an effective retrospective and continuous control.

Why this answer

An AWS Config rule can check that S3 buckets have encryption enabled and automatically remediate any non-compliant buckets. Option C is correct because a service control policy (SCP) can be attached to the root OU to deny the creation of S3 buckets without encryption, using a condition on the s3:x-amz-server-side-encryption header. Option B is incorrect because S3 Block Public Access does not enforce encryption.

Option D is incorrect because attaching an IAM role to CloudFormation only grants permissions but does not enforce encryption. Option E is incorrect because CloudFormation stack policies only protect existing resources from updates and cannot enforce conditions on bucket creation.

35
MCQmedium

Refer to the exhibit. A security engineer runs the CLI command and receives the output shown. The engineer expects to see flow logs for a specific subnet, but the output shows the resource ID as a VPC. What is the most likely reason?

A.The flow log is not active; it shows ACTIVE, so that's not the issue.
B.The flow log is configured to deliver to CloudWatch, but the log group name is incorrect.
C.The IAM role does not have permissions to deliver logs for subnets.
D.The flow log was created at the VPC level, not at the subnet level.
AnswerD

The resource ID in the flow log output is prefixed with "vpc-", which indicates the flow log was created at the VPC level rather than at the subnet level. As a result, the flow log captures all traffic in the VPC, and the query is not filtering for the specific subnet due to the resource scope. To see subnet-specific flow logs, you must create a separate flow log with the subnet ID as the resource ID.

Why this answer

The output shows the resource ID as a VPC (vpc-xxxx), but the security engineer expected to see flow logs for a specific subnet. This indicates that the flow log was created at the VPC level, not at the subnet level. In AWS, VPC Flow Logs can be created at the VPC, subnet, or network interface level, and the resource ID in the flow log output reflects the level at which the log was configured.

Since the engineer expected subnet-level logs, the most likely reason is that the flow log was created for the entire VPC instead of the specific subnet.

Exam trap

The trap here is that candidates may assume the flow log is misconfigured due to permissions or delivery settings, when the real issue is the scope at which the flow log was created—a common confusion between VPC-level and subnet-level flow logs.

How to eliminate wrong answers

Option A is wrong because the flow log is indeed active (ACTIVE status), so inactivity is not the issue. Option B is wrong because the log group name being incorrect would not cause the resource ID to show a VPC instead of a subnet; it would affect log delivery but not the resource identifier in the output. Option C is wrong because IAM role permissions for delivering logs to CloudWatch are not related to the level (VPC vs. subnet) at which the flow log is created; permissions issues would prevent log delivery entirely, not change the resource ID shown.

36
MCQhard

A security engineer notices that an Amazon EC2 instance has a security group that allows inbound SSH (port 22) from 0.0.0.0/0. The instance is a bastion host. What is a more secure alternative to this configuration?

A.Change the SSH port to a non-standard port to avoid automated attacks.
B.Restrict the inbound SSH rule to a single IP address from the corporate network.
C.Replace the security group rule with a network ACL that allows SSH from 0.0.0.0/0.
D.Remove the inbound SSH rule and use AWS Systems Manager Session Manager to access the instance.
AnswerD

Removing the inbound SSH rule and using AWS Systems Manager Session Manager closes the port 22 listener entirely, so the instance is not reachable over SSH from the network. Session Manager authenticates the user through IAM, authorizes actions with IAM policies, and sends the interactive shell session over an encrypted channel initiated by the SSM Agent. Sessions can be audited and recorded via S3 or CloudWatch Logs, and you can use a VPC endpoint so traffic never traverses an open internet-facing port. This avoids the need for SSH key management and eliminates brute-force exposure.

Why this answer

AWS Systems Manager Session Manager provides secure, auditable, and keyless shell access to EC2 instances without opening any inbound ports. It uses the AWS Systems Manager agent to initiate an outbound connection to the AWS SSM endpoint over HTTPS (port 443), eliminating the need for a bastion host or any inbound SSH rule. This approach also integrates with AWS Identity and Access Management (IAM) for fine-grained access control and AWS CloudTrail for full session logging.

Exam trap

The trap here is that candidates often think restricting SSH to a single IP (Option B) is the most secure approach, but the exam tests the concept of eliminating inbound access entirely through agent-based outbound-only solutions like Session Manager, which is a key principle of the AWS Well-Architected Framework's security pillar.

How to eliminate wrong answers

Option A is wrong because changing the SSH port to a non-standard port only obscures the service from automated scans but does not prevent targeted attacks or port scanning; it violates security by obscurity principles and is not a secure alternative. Option B is wrong because restricting the inbound SSH rule to a single corporate IP address still leaves the bastion host exposed to SSH vulnerabilities, requires maintaining a bastion host, and does not eliminate the attack surface of an open SSH port. Option C is wrong because replacing the security group rule with a network ACL that allows SSH from 0.0.0.0/0 is actually less secure—network ACLs are stateless and do not provide the same stateful filtering as security groups, and they still expose the instance to inbound SSH traffic from the entire internet.

37
MCQmedium

A security engineer is designing a VPC with public and private subnets in two Availability Zones. The company requires that all outbound traffic from private subnets to the internet must go through a single, centrally managed NAT gateway. Which combination of resources and route table entries should be used?

A.A single NAT gateway in a public subnet, and a default route (0.0.0.0/0) in each private subnet route table pointing to that NAT gateway.
B.A single NAT gateway in a private subnet, and a default route in each private subnet pointing to the NAT gateway.
C.One NAT gateway per private subnet, each with a route to an internet gateway.
D.One NAT gateway per Availability Zone, with routes to the internet gateway.
AnswerA

A NAT gateway must reside in a public subnet with an internet gateway as the next-hop for 0.0.0.0/0 so it can perform source NAT for outbound traffic. Placing a single NAT gateway there and adding a 0.0.0.0/0 route in every private subnet route table pointing to that gateway ID centralizes internet egress while keeping instances private. This is the standard minimal design, though it is a single point of failure if that availability zone goes down.

Why this answer

A single NAT gateway placed in a public subnet (with an Internet Gateway route) can be used by multiple private subnets across different Availability Zones. Each private subnet's route table must have a default route (0.0.0.0/0) pointing to the NAT Gateway's elastic network interface (ENI) or NAT Gateway ID, ensuring all outbound traffic from private instances is source-NATed through that single, centrally managed device.

Exam trap

The trap here is that candidates often assume a NAT gateway must be in a private subnet because it handles private traffic, but AWS requires NAT gateways to be in a public subnet with an IGW route to function correctly.

How to eliminate wrong answers

Option B is wrong because a NAT gateway must reside in a public subnet (with a route to an Internet Gateway) to translate private IPs and reach the internet; placing it in a private subnet would block outbound traffic as the NAT gateway itself would have no internet path. Option C is wrong because it violates the requirement for a single, centrally managed NAT gateway; using one NAT gateway per private subnet would create multiple egress points and increase cost and management overhead. Option D is wrong because it also violates the single-NAT requirement; deploying one NAT gateway per Availability Zone creates multiple egress points and is typically used for high availability, not central management.

38
MCQmedium

Refer to the exhibit. A security engineer is investigating a potential unauthorized VPC creation. What does the evidence suggest?

A.The user admin created two VPCs, but one was deleted shortly after creation.
B.The CloudTrail log is incomplete; both VPCs exist.
C.Both VPCs were created successfully and still exist.
D.The user admin only created one VPC; the second event is a duplicate.
AnswerA

Each CreateVpc API call in CloudTrail is recorded with a distinct event ID and returns a unique VPC ID. The current describe-vpcs output shows only one VPC, so one of the two created VPC IDs is absent. That absence indicates a DeleteVpc call (or another deletion mechanism) removed the VPC after creation; CloudTrail's management events would capture that deletion, confirming the lifecycle.

Why this answer

The CloudTrail log shows two CreateVpc events by user admin. One VPC exists (vpc-12345678), but the other (vpc-87654321) does not exist, indicating that it was deleted after creation. This could indicate malicious activity where a VPC was created and then deleted to cover tracks.

39
Multi-Selecteasy

A security engineer needs to protect an S3 bucket that contains sensitive data. Which two methods should the engineer use?

Select 2 answers
A.Use Amazon CloudFront to serve the content.
B.Enable VPC Flow Logs on the bucket.
C.Apply an S3 bucket policy that restricts access to specific IAM users or roles.
D.Use IAM policies to grant permissions to users and roles.
E.Enable S3 object ACLs.
AnswersC, D

An S3 bucket policy is a resource-based policy attached directly to the bucket, and it can specify which IAM users or roles are permitted to perform actions such as s3:GetObject or s3:PutObject. Since the policy is evaluated against the principal, action, resource, and conditions, it can restrict access to only specific AWS identities while denying all other principals. This is a native, effective way to protect the bucket and is the recommended resource-based control for enforcing such restrictions.

Why this answer

Option C is correct because an S3 bucket policy is a resource-based policy attached directly to the bucket that can explicitly allow or deny access based on principals (specific IAM users, roles, or accounts), conditions such as source VPC endpoint or IP range, and actions, making it the primary tool for restricting who can reach sensitive objects. Option D is correct because IAM policies are identity-based policies attached to users, groups, or roles that define which S3 actions (for example s3:GetObject, s3:PutObject) those identities may perform on the bucket and its objects; combined with the bucket policy, they enforce least-privilege access. Option A is not correct because CloudFront is a content-delivery service that can front an S3 bucket for performance or OAC-based access, but it does not by itself protect the bucket's data or restrict direct S3 access.

Option B is not correct because VPC Flow Logs capture IP traffic metadata for network interfaces in a VPC and have no relationship to S3 bucket access control. Option E is not correct because S3 object ACLs are legacy access-control lists that grant only coarse read/write permissions to individual objects and are not the recommended mechanism for restricting sensitive bucket data to specific IAM principals.

Exam trap

The trap here is that candidates often confuse resource-based policies (bucket policies) with identity-based policies (IAM policies) and may think only one is sufficient, but the question asks for two methods, and both C and D are correct because they work together to enforce least-privilege access.

40
MCQmedium

A security engineer manages a fleet of Amazon EC2 instances in a VPC. The instances must be able to reach the internet for software updates, but they must not be directly reachable from the internet. The VPC has a private subnet with a route to a NAT gateway in a public subnet. The engineer notices that instances in the private subnet cannot reach the internet, and the NAT gateway's CloudWatch metrics show zero active connections. Which of the following is the MOST likely cause?

A.The security group on the instances does not allow outbound traffic to the NAT gateway.
B.The private subnet's route table does not have a route to the NAT gateway.
C.The NAT gateway is not associated with an Elastic IP address.
D.The network ACL on the private subnet is blocking outbound traffic to the NAT gateway.
AnswerB

For a private subnet to use a NAT gateway, its route table must have a route with destination 0.0.0.0/0 pointing to the NAT gateway. If that route is missing or misconfigured, instances cannot send traffic to the NAT gateway, resulting in zero active connections. This is the most likely cause given the symptoms.

Why this answer

The NAT gateway's zero active connections indicate that traffic from the private instances is not reaching it. The most common reason is a missing or incorrect route in the private subnet's route table directing internet-bound traffic to the NAT gateway. Without that route, instances have no path to the NAT gateway, so they cannot access the internet.

Exam trap

The trap here is assuming that a NAT gateway automatically enables internet access for private subnets without verifying the route table configuration.

41
Multi-Selectmedium

A company is using AWS CloudTrail to log API calls. The security team wants to ensure that the logs are protected from unauthorized access and deletion. Which TWO actions should be taken?

Select 2 answers
A.Enable server-side encryption using AWS KMS (SSE-KMS) on the S3 bucket.
B.Use S3 bucket ACLs to restrict access.
C.Enable CloudTrail log file validation.
D.Enable S3 Versioning on the bucket.
E.Enable multi-factor authentication (MFA) for CloudTrail.
AnswersA, C

Server-side encryption with AWS KMS (SSE-KMS) encrypts CloudTrail log objects at rest using envelope encryption with a customer-managed CMK, ensuring that the API activity data is unreadable to unauthorized parties. CloudTrail integrates natively with SSE-KMS, and you can configure the bucket to use a KMS key for all delivered logs, which also provides an additional layer of protection for sensitive information such as user credentials or IP addresses. This is the correct choice because it directly addresses the confidentiality of the logs, a fundamental security requirement.

Why this answer

Enabling server-side encryption using AWS KMS (SSE-KMS) on the S3 bucket that stores CloudTrail logs ensures that the log files are encrypted at rest, protecting them from unauthorized access. This encryption uses envelope encryption with a customer-managed or AWS-managed KMS key, providing an additional layer of access control via KMS key policies and IAM policies. Option C is correct because CloudTrail log file validation creates a signed digest file for each log file, allowing you to verify that the logs have not been tampered with, deleted, or modified after delivery.

This uses SHA-256 hashing and digital signing with the private key of AWS, ensuring integrity and authenticity of the log files.

Exam trap

The trap here is that candidates often confuse 'protecting logs from deletion' with 'preventing deletion' and incorrectly choose S3 Versioning (Option D) as a security control, when in fact versioning only helps recover from accidental deletion, not prevent malicious deletion by an authorized user.

42
MCQmedium

A company uses AWS CloudFormation to deploy infrastructure. The security team wants to ensure that no sensitive data, such as database passwords, is exposed in plaintext in the CloudFormation templates. What is the MOST secure way to handle secrets?

A.Use AWS KMS to encrypt the secrets and include the ciphertext in the template.
B.Use AWS Systems Manager Parameter Store or AWS Secrets Manager with dynamic references in the template.
C.Store the secrets in an encrypted S3 bucket and include the S3 URL in the template.
D.Pass the secrets as plaintext parameters to the stack at launch time.
AnswerB

Using CloudFormation dynamic references to AWS Systems Manager Parameter Store or AWS Secrets Manager lets the service fetch the secret value at stack create/update time, so the actual secret never appears in the template, AWS CloudFormation API calls, or stack logs. With a parameter reference like 'ssm-secure:MyParameter' or a secretsmanager reference, CloudFormation passes the resolved value directly to the resource while the template retains only the reference. This aligns with least-privilege access and supports rotation, because you can attach a version to the reference and rotate the backing secret without editing the template.

Why this answer

AWS Systems Manager Parameter Store and AWS Secrets Manager support dynamic references in CloudFormation templates, allowing you to reference secret values without exposing them in plaintext. CloudFormation resolves these references at deployment time, retrieving the actual secret value from the secure store, and never stores the secret in the template or stack metadata. This approach ensures secrets are managed, rotated, and audited centrally, adhering to security best practices.

Exam trap

The trap here is that candidates may think encrypting the secret with KMS (Option A) or storing it in an encrypted S3 bucket (Option C) is sufficient, but they overlook that the encrypted data or reference URL is still exposed in the template, and the decryption key or bucket access must be managed separately, which is less secure than using a dedicated secrets service with dynamic references.

How to eliminate wrong answers

Option A is wrong because including ciphertext in the template still exposes the encrypted secret in the template itself, and you would need to manage the KMS key and decryption logic separately, which is less secure and more complex than using a native secrets service. Option C is wrong because storing secrets in an encrypted S3 bucket and including the S3 URL in the template still exposes the URL (and potentially the bucket name) in plaintext, and the template would need IAM permissions to access the bucket, increasing the attack surface. Option D is wrong because passing secrets as plaintext parameters at launch time means the secret value is visible in the CloudFormation console, API logs (AWS CloudTrail), and any automation scripts, violating the requirement to avoid plaintext exposure.

43
Multi-Selectmedium

Which TWO actions are valid ways to restrict access to an Amazon S3 bucket using a bucket policy? (Choose two.)

Select 2 answers
A.Use the aws:SourceIp condition key to allow access only from a specific IP range.
B.Use the iam:RoleName condition key to allow access only from a specific IAM role.
C.Use the aws:Referer condition key to allow access only from a specific HTTP referer.
D.Use the aws:SourceVpce condition key to allow access only from a specific VPC.
E.Use the kms:EncryptionContext condition key to require that objects are encrypted with a specific KMS key.
AnswersA, C

The aws:SourceIp condition key is a global condition key that can be used in an S3 bucket policy's Condition block with the IpAddress operator to allow access only from a specific public IP range, such as a corporate egress CIDR. This is valid because S3 evaluates the requester's IP address for most API calls, though it does not apply when the request is made through a VPC endpoint, in which case the source IP is from the endpoint itself.

Why this answer

The `aws:SourceIp` condition key in an S3 bucket policy allows you to restrict access based on the requester's IP address. This is a standard AWS IAM condition that evaluates the source IP of the request, enabling you to permit or deny access from a specific CIDR range. It is commonly used to limit S3 bucket access to a corporate network or a known set of public IPs.

Exam trap

The SCS-C02 exam often tests the distinction between `aws:SourceVpce` (for VPC endpoints) and `aws:SourceVpc` (for VPC-level restrictions), and candidates mistakenly choose `aws:SourceVpce` when the question asks for VPC-wide access control.

44
MCQmedium

A security engineer runs the above AWS CLI command. The engineer notices that the security group has no outbound rules. What is the implication of this configuration?

A.The EC2 instances in this security group cannot initiate outbound connections
B.The EC2 instances cannot receive inbound HTTP traffic
C.The security group allows all outbound traffic by default
D.Outbound traffic is allowed because security groups are stateful
AnswerA

Security groups are stateful and allow all outbound traffic by default; removing every outbound rule leaves no permit, so instances cannot initiate connections. Return traffic for inbound-initiated flows still passes, but new outbound sessions are blocked.

Why this answer

Security groups are stateful and, by default, allow all outbound traffic; however, if outbound rules are explicitly removed, the group has no rule permitting egress, so instances cannot initiate outbound connections. Return traffic for allowed inbound connections is still permitted due to statefulness, but new outbound-initiated flows are blocked. Thus the correct implication is that outbound connections cannot be initiated.

Exam trap

The trap is assuming statefulness means outbound is always allowed — statefulness only covers return traffic for established flows, not new outbound-initiated connections when no egress rule exists.

How to eliminate wrong answers

Option B is wrong because inbound HTTP traffic is governed by inbound rules, not the absence of outbound rules; the scenario says nothing about inbound being blocked. Option C is wrong because while security groups allow all outbound by default, the question states outbound rules were removed, so the default no longer applies. Option D is wrong because statefulness only permits return traffic for established inbound flows; it does not permit new outbound-initiated connections when no outbound rule allows them.

45
MCQhard

A company has a VPC with a public subnet and a private subnet. The public subnet hosts a NAT instance (Amazon Linux) that provides internet access to instances in the private subnet. The security team notices that the NAT instance is receiving high inbound traffic on port 22 from an external IP address. The team wants to block this traffic at the network layer without affecting other traffic. What is the most effective solution?

A.Move the NAT instance to a private subnet and use a NAT gateway instead.
B.Modify the security group attached to the NAT instance to block inbound SSH from the specific IP.
C.Use AWS WAF to block the IP address.
D.Add a network ACL rule on the public subnet to deny inbound traffic from the specific IP on port 22.
AnswerD

A network ACL is a stateless, subnet-level firewall that supports explicit DENY rules with numeric precedence, allowing you to block traffic from a specific source IP on a specific port. Adding a deny rule for that IP and port 22 on the public subnet's NACL will be evaluated before traffic reaches the NAT instance, while still permitting all other inbound traffic. This is the correct approach because NACLs operate at the VPC edge and support the granular, deny-based filtering that security groups cannot provide.

Why this answer

A network ACL (NACL) operates at the subnet level (layer 3/4) and is stateless, meaning it can explicitly deny inbound traffic from a specific IP on port 22 before it reaches the NAT instance. This blocks the traffic at the network layer without affecting other traffic, as NACLs evaluate rules in order and deny rules override allow rules for the specified traffic. Unlike security groups, NACLs do not require the traffic to first reach the instance, making them ideal for blocking unwanted traffic at the subnet boundary.

Exam trap

The trap here is that candidates often choose security groups (Option B) because they are familiar with them, but the question explicitly requires blocking at the network layer, and NACLs are the correct layer 3/4 subnet-level control, while security groups are instance-level and stateful, making them unsuitable for this specific requirement.

How to eliminate wrong answers

Option A is wrong because moving the NAT instance to a private subnet and using a NAT gateway does not block the inbound SSH traffic; it only changes the architecture and still leaves the NAT instance (or gateway) exposed to the same traffic if the subnet's route table or ACLs are not updated. Option B is wrong because modifying the security group attached to the NAT instance to block inbound SSH from the specific IP would work at the instance level, but security groups are stateful and operate at the instance level, not the network layer; the traffic would still reach the instance's network interface before being evaluated, and the question specifically asks to block at the network layer. Option C is wrong because AWS WAF is a web application firewall that operates at layer 7 (application layer) and is designed to protect web applications (e.g., ALB, CloudFront), not to block SSH traffic at the network layer; it cannot filter SSH traffic on port 22.

46
MCQhard

A company runs a critical application on EC2 instances behind an Application Load Balancer. The security team suspects that a DDoS attack is targeting the application. Which AWS service can be used to absorb and mitigate the attack at the network layer before traffic reaches the ALB?

A.AWS WAF
B.AWS Identity and Access Management (IAM)
C.Network ACLs
D.AWS Shield Advanced
AnswerD

AWS Shield Advanced is the purpose-built DDoS mitigation service that protects at the network and transport layers (Layers 3 and 4), covering SYN floods, UDP reflection attacks, and other high-volume floods against EC2 instances and associated Elastic IPs. It provides always-on detection, automatic inline mitigation, and access to the AWS DDoS Response Team (DRT) for rapid manual intervention in complex attacks. For a critical EC2 application, Shield Advanced is the correct choice because it is designed to maintain availability when incoming attack traffic saturates the network path, and it offers cost protection against scaling charges triggered by attacks.

Why this answer

AWS Shield Advanced provides enhanced protections against larger and more sophisticated DDoS attacks, including network-layer (Layer 3/4) attacks such as UDP floods, SYN floods, and reflection attacks. It integrates directly with Application Load Balancers to absorb and mitigate malicious traffic before it reaches the ALB, ensuring the application remains available. This makes it the correct choice for mitigating a DDoS attack at the network layer.

Exam trap

The trap here is that candidates often confuse AWS WAF (Layer 7) with network-layer protection, or assume that Network ACLs can handle DDoS attacks, but only AWS Shield Advanced provides dedicated, scalable mitigation for Layer 3/4 attacks at the network perimeter.

How to eliminate wrong answers

Option A is wrong because AWS WAF operates at Layer 7 (application layer) and is designed to filter HTTP/HTTPS requests based on rules like SQL injection or cross-site scripting, not to absorb network-layer DDoS attacks. Option B is wrong because AWS Identity and Access Management (IAM) is a service for managing user permissions and access control, not for mitigating DDoS attacks. Option C is wrong because Network ACLs are stateless firewall rules that filter traffic at the subnet level, but they cannot absorb or scale to mitigate large volumetric DDoS attacks; they are also not designed for attack mitigation and can be overwhelmed by high-volume traffic.

47
MCQmedium

A company wants to securely store secrets used by an application running on EC2 instances. The secrets include database credentials and API keys. What is the MOST secure and manageable approach?

A.Store the secrets in the EC2 instance user data and retrieve them from the metadata service.
B.Embed the secrets in the application code and encrypt the code with a KMS key.
C.Use AWS Secrets Manager and attach an IAM role to the EC2 instance with permission to access the secrets.
D.Use AWS Systems Manager Parameter Store with a SecureString parameter and reference it in the application code.
AnswerC

Correct. AWS Secrets Manager integrates with IAM roles for EC2 instances, providing fine-grained access control, automatic secret rotation, and auditing. This is the most secure and manageable approach for storing database credentials and API keys.

Why this answer

AWS Secrets Manager is purpose-built for storing, rotating, and retrieving secrets such as database credentials and API keys. Attaching an IAM role to the EC2 instance allows the application to retrieve secrets securely without hardcoding credentials, and Secrets Manager supports automatic rotation, auditing via CloudTrail, and fine-grained access control. This is the most secure and manageable approach.

Exam trap

The trap is choosing Parameter Store SecureString because it is also secure and cheaper; however, the question emphasizes 'most secure and manageable,' and Secrets Manager's native rotation and management features make it the better answer.

How to eliminate wrong answers

Option A is wrong because user data and the metadata service are not secure for secrets — user data is visible in the console and metadata can be accessed by any process on the instance, and there is no rotation or auditing. Option B is wrong because embedding secrets in code (even encrypted) is an anti-pattern; secrets become part of the deployment artifact and are hard to rotate. Option D is wrong because while Parameter Store SecureString is secure, it lacks native rotation and is less feature-rich for secret management compared to Secrets Manager; the question asks for the MOST secure and manageable, and Secrets Manager with IAM role is the best fit.

48
MCQeasy

A security engineer needs to ensure that an Amazon RDS database instance is not accessible from the internet. Which configuration step will achieve this?

A.Deploy the DB instance in a multi-AZ configuration.
B.Set the DB instance to be publicly accessible and restrict security group inbound rules.
C.Set the DB instance to be not publicly accessible and place it in a private subnet.
D.Use the default VPC security group for the DB instance.
AnswerC

Marking the DB instance as not publicly accessible prevents RDS from assigning any public IP address, and placing it in a private subnet with no route to an internet gateway ensures no inbound traffic can reach it from the internet. The database will only be reachable through its private IP address within the VPC, and clients must connect via resources in the same VPC, a VPN, or a bastion host. This configuration is the AWS best practice for database isolation.

Why this answer

Setting a DB instance to be not publicly accessible ensures that it does not receive a public IP address, and placing it in a private subnet (one without a route to an internet gateway) prevents any direct inbound or outbound traffic from the internet. This combination guarantees that the RDS instance is isolated from the public internet, aligning with the security requirement.

Exam trap

The trap here is that candidates often assume security group rules alone can fully control internet access, overlooking the critical distinction between public and private IP assignment and subnet routing that determines actual internet reachability.

How to eliminate wrong answers

Option A is wrong because deploying in a multi-AZ configuration provides high availability and failover support, but does not affect network accessibility; the DB instance can still be publicly accessible if configured otherwise. Option B is wrong because setting the DB instance to be publicly accessible assigns a public IP address, and while restricting security group inbound rules can limit traffic, the instance itself remains reachable from the internet, violating the requirement. Option D is wrong because using the default VPC security group does not inherently prevent internet access; the default security group typically allows all outbound traffic and may have permissive inbound rules, and the instance could still be publicly accessible if placed in a public subnet.

49
Multi-Selectmedium

Which TWO actions can be taken to improve the security of an Amazon RDS for MySQL database instance? (Choose TWO.)

Select 2 answers
A.Place the RDS instance in a private subnet and restrict inbound traffic to the application security group.
B.Disable automated backups to reduce storage costs.
C.Enable Multi-AZ deployment for fault tolerance.
D.Assign a public IP address to the RDS instance for easier access from the internet.
E.Enable encryption at rest using AWS KMS.
AnswersA, E

Placing the RDS instance in a private subnet removes any route to an internet gateway, so it cannot be reached directly from the internet. Restricting inbound rules to the application's security group enforces least-privilege access, permitting only the application tier on the MySQL port.

Why this answer

Option A is correct because placing the RDS for MySQL instance in a private subnet removes it from direct internet reachability, and restricting inbound traffic to only the application's security group enforces least-privilege network access at the database port (3306 for MySQL). Option E is correct because enabling encryption at rest with AWS KMS protects the underlying storage, automated backups, read replicas, and snapshots, so data cannot be read if the storage media is compromised. Option B is incorrect because disabling automated backups reduces recoverability and does not improve security.

Option C is incorrect because Multi-AZ is a high-availability/fault-tolerance feature, not a security control. Option D is incorrect because assigning a public IP address exposes the database to the internet and increases the attack surface.

Exam trap

The trap here is that candidates often confuse high availability (Multi-AZ) or cost-saving measures (disabling backups) with security controls, when in fact they do not address confidentiality, integrity, or access control.

50
MCQmedium

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The security team requires that all traffic between the ALB and EC2 instances be encrypted. Which configuration ensures this requirement is met?

A.Use an HTTPS listener on the ALB and configure the target group with HTTPS.
B.Use a TCP listener on the ALB and a TCP target group.
C.Configure security group inbound rules to allow only HTTPS traffic.
D.Use an HTTP listener on the ALB and HTTP on the target group.
AnswerA

Configuring the ALB listener for HTTPS encrypts client-to-ALB traffic, and setting the target group protocol to HTTPS makes the ALB re-encrypt traffic to the EC2 instances. This end-to-end TLS configuration satisfies the requirement that ALB-to-instance traffic be encrypted.

Why this answer

It ensures end-to-end encryption between the ALB and EC2 instances. By configuring an HTTPS listener on the ALB, traffic from clients to the ALB is encrypted. Then, by setting the target group protocol to HTTPS, the ALB re-encrypts the traffic before forwarding it to the EC2 instances, fulfilling the security team's requirement that all traffic between the ALB and EC2 instances be encrypted.

Exam trap

The trap here is that candidates assume an HTTPS listener alone encrypts all traffic end-to-end, forgetting that the ALB-to-instance leg must also use HTTPS; otherwise, traffic between the ALB and EC2 instances is in plaintext.

How to eliminate wrong answers

Option B is wrong because a TCP listener and TCP target group operate at Layer 4 and do not provide encryption; they forward raw TCP traffic without TLS/SSL termination or re-encryption. Option C is wrong because security group inbound rules only control access at the network level (allowing or denying traffic based on port/protocol) and do not encrypt traffic; encryption is a function of the protocol (HTTPS/TLS), not security group rules. Option D is wrong because using HTTP on both the listener and target group means traffic is transmitted in plaintext at every hop, with no encryption between the ALB and EC2 instances.

51
MCQhard

Refer to the exhibit. A security engineer is unable to SSH into an EC2 instance in subnet-12345678. The instance's security group allows inbound SSH from 10.0.0.0/8, and the instance has a public IP. What is the most likely reason for the failure?

A.The security group egress rule is blocking return traffic.
B.The security group inbound rule restricts SSH to the 10.0.0.0/8 range, blocking the engineer's IP.
C.The network ACL's default deny rule (32767) is blocking all inbound traffic.
D.The network ACL inbound rule for SSH is misconfigured, denying all traffic.
AnswerB

The security group inbound rule permits SSH only from sources within the private 10.0.0.0/8 CIDR range, which does not include the security engineer's public IP address. Security groups act as a stateful virtual firewall that filters packets before they reach the instance; if the source IP does not match an allow rule, the packet is silently dropped. This source-restricted SSH rule is the root cause of the connection failure.

Why this answer

The network ACL allows inbound SSH from 0.0.0.0/0, but the security group only allows SSH from 10.0.0.0/8. Since the engineer is connecting from an IP outside that range, the security group blocks the connection.

52
MCQhard

A company is deploying a multi-tier web application on AWS. The application uses an Application Load Balancer (ALB) to distribute traffic to EC2 instances in private subnets. The security team wants to protect the application from common web exploits like SQL injection and cross-site scripting. Which AWS service should be used?

A.AWS WAF.
B.AWS Network Firewall.
C.AWS Shield Advanced.
D.AWS Security Hub.
AnswerA

AWS WAF is a Layer 7 web application firewall that inspects HTTP/HTTPS requests before they reach the web tier. It runs managed rule groups, including AWS Managed Rules for SQL injection and cross-site scripting, and can be deployed on an Application Load Balancer, Amazon CloudFront, or Amazon API Gateway. Because it can parse the request body and headers, it can block malicious signatures while letting legitimate traffic through.

Why this answer

AWS WAF is a web application firewall that helps protect web applications from common web exploits such as SQL injection and cross-site scripting (XSS). It integrates directly with an Application Load Balancer (ALB) to inspect HTTP/HTTPS requests and filter malicious traffic based on customizable rules, including managed rule groups for OWASP Top 10 threats.

Exam trap

The trap here is that candidates often confuse AWS Network Firewall (Layer 3/4 filtering) with a web application firewall, not realizing that SQL injection and XSS require Layer 7 HTTP payload inspection, which only AWS WAF provides.

How to eliminate wrong answers

Option B (AWS Network Firewall) is wrong because it operates at the network layer (Layer 3/4) and stateful inspection, not at the application layer (Layer 7), so it cannot inspect HTTP payloads for SQL injection or XSS. Option C (AWS Shield Advanced) is wrong because it provides DDoS protection against volumetric and state-exhaustion attacks, not application-layer web exploit filtering. Option D (AWS Security Hub) is wrong because it is a centralized security posture management service that aggregates findings from multiple AWS services, not a real-time traffic inspection or filtering service.

53
Multi-Selectmedium

A security engineer is designing a VPC with private and public subnets. Which TWO actions improve network security? (Choose two.)

Select 2 answers
A.Use a single subnet for all resources to simplify network rules.
B.Use security groups to restrict traffic to the database from only the application tier.
C.Place database instances in a public subnet for easier management.
D.Use a NAT gateway in a public subnet for outbound traffic from private subnets.
E.Place an internet gateway in a private subnet.
AnswersB, D

Security groups act as a stateful, instance-level firewall that lets you reference another security group as the source. By placing the database in a private subnet and attaching a security group that allows inbound traffic only from the application tier's security group (not from a CIDR), you ensure that only instances with that specific security group can reach the database. This rule automatically accommodates new instances added to the application tier and blocks all other traffic, including from other subnets or external sources, without exposing the database to the internet.

Why this answer

Security groups act as a stateful virtual firewall at the instance level, allowing you to restrict inbound traffic to the database instances to only the application tier's security group. This ensures that only traffic originating from the application instances can reach the database, effectively implementing a least-privilege security model.

Exam trap

The trap here is that candidates often confuse security groups (stateful, instance-level) with network ACLs (stateless, subnet-level) and may incorrectly think that a single subnet simplifies security, when in fact it eliminates the network segmentation that is critical for defense in depth.

54
MCQeasy

A company wants to ensure that all traffic to an Amazon S3 bucket is encrypted in transit. Which bucket policy condition should be used?

A.aws:SourceVpce
B.aws:SecureTransport
C.s3:x-amz-server-side-encryption
D.aws:SourceIp
AnswerB

The aws:SecureTransport condition key is a boolean context key that indicates whether the request was sent over SSL/TLS: it is true for HTTPS and false for plaintext HTTP. In a bucket policy, you can add a Deny statement with a condition like {"Bool":{"aws:SecureTransport":"false"}} to block all unencrypted requests. This directly ensures that every request to the S3 bucket is encrypted during transit.

Why this answer

The `aws:SecureTransport` condition key checks whether the request was sent using SSL/TLS (i.e., HTTPS). Setting it to `false` in a deny statement ensures that any HTTP request to the S3 bucket is rejected, thereby enforcing encryption in transit. This is the correct condition for the stated requirement.

Exam trap

The trap here is confusing encryption in transit (HTTPS/TLS) with encryption at rest (server-side encryption), leading candidates to incorrectly select `s3:x-amz-server-side-encryption` instead of `aws:SecureTransport`.

How to eliminate wrong answers

Option A is wrong because `aws:SourceVpce` restricts access based on the VPC endpoint ID, which controls network path but does not enforce encryption in transit. Option C is wrong because `s3:x-amz-server-side-encryption` enforces encryption at rest (server-side encryption), not encryption in transit. Option D is wrong because `aws:SourceIp` restricts access based on the client's IP address, which has no bearing on whether the transport layer uses HTTPS.

55
MCQeasy

Which AWS service can be used to create a private network connection between a VPC and an on-premises data center over dedicated physical lines?

A.AWS Transit Gateway
B.AWS Site-to-Site VPN
C.AWS Direct Connect
D.VPC Peering
AnswerC

AWS Direct Connect delivers a dedicated physical Ethernet-based connection from your on-premises data center to AWS Direct Connect locations, bypassing the public internet entirely. This dedicated link provides consistent network performance, lower latency, and can be scaled from 1 to 100 Gbps depending on the port and partner offerings. A direct connection is established via a cross-connect in a Direct Connect facility or through an AWS Direct Connect Partner, and can be divided into multiple virtual interfaces (VLANs) for accessing public and private AWS resources. This precisely matches the requirement of creating a private network connection using dedicated lines.

Why this answer

AWS Direct Connect is the correct service because it establishes a dedicated, private network connection from an on-premises data center to a VPC using physical Ethernet cables routed through an AWS Direct Connect location. This bypasses the public internet entirely, providing consistent latency, higher bandwidth, and a more reliable connection than internet-based options.

Exam trap

The trap here is that candidates confuse AWS Site-to-Site VPN with a dedicated connection, but VPNs always traverse the public internet and do not provide the physical isolation or consistent performance of Direct Connect.

How to eliminate wrong answers

Option A is wrong because AWS Transit Gateway is a network transit hub that interconnects VPCs and on-premises networks, but it does not itself provide the physical dedicated lines; it requires an underlying connection like Direct Connect or VPN to attach to. Option B is wrong because AWS Site-to-Site VPN creates an encrypted tunnel over the public internet, not over dedicated physical lines, so it does not meet the requirement for a private connection over dedicated infrastructure. Option D is wrong because VPC Peering connects two VPCs within AWS using the AWS global network, but it cannot connect to an on-premises data center and does not involve dedicated physical lines.

56
MCQeasy

A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no resources can be created in a specific AWS Region except for the us-east-1 Region. Which policy type should the security team use?

A.IAM permissions boundary
B.IAM policy applied to the root user
C.Resource-based policy
D.Service control policy (SCP)
AnswerD

Service control policies are the correct account-level control because they establish permission guardrails that apply to every IAM principal and the root user in all linked accounts within an AWS Organization. An SCP can deny actions using a condition such as aws:RequestedRegion, effectively preventing users from making API calls in designated Regions across the entire organization. SCPs do not grant permissions themselves; they just set the maximum allowed access, and they do not affect the management account, which is an important nuance when designing Region restrictions.

Why this answer

Service control policies (SCPs) are the correct choice because they allow you to centrally control the maximum available permissions for all accounts in an AWS Organization. By applying an SCP that denies all actions in a specific region (except us-east-1), the security team can enforce a region restriction across all member accounts, regardless of any IAM policies attached to users or roles. SCPs do not grant permissions themselves but act as a guardrail that limits what IAM policies can allow.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies, thinking that a simple IAM policy denying region access can achieve the same result, but SCPs are the only mechanism that can enforce restrictions across all users and roles in multiple accounts within an organization.

How to eliminate wrong answers

Option A is wrong because IAM permissions boundaries set the maximum permissions for an IAM user or role within a single account, but they cannot enforce region restrictions across multiple accounts in an organization. Option B is wrong because an IAM policy applied to the root user only affects the root user of a single account and does not scale to all accounts in the organization; also, AWS recommends against using root user credentials for daily operations. Option C is wrong because resource-based policies are attached to individual resources (e.g., S3 buckets, Lambda functions) and control access to that specific resource, not the ability to create resources in a region across an entire account or organization.

57
MCQmedium

A company has an EC2 instance that needs to access an S3 bucket. The security team wants to use the principle of least privilege. Which method should be used to grant access?

A.Use a security group to allow outbound traffic to S3.
B.Store AWS access keys on the instance and use them in the application.
C.Create an IAM role with an S3 access policy and attach it to the EC2 instance profile.
D.Create a bucket policy that grants access to the EC2 instance ID.
AnswerC

Create an IAM role with a policy allowing the required S3 actions and attach that role to the EC2 instance via an instance profile. The instance then obtains temporary credentials from the instance metadata service, which are automatically rotated and used by the AWS SDK for signing S3 API requests. This is the secure, recommended pattern because it avoids persistent keys and follows least privilege.

Why this answer

It follows the principle of least privilege by using an IAM role with a scoped S3 access policy, which is then attached to the EC2 instance profile. This allows the EC2 instance to obtain temporary security credentials from the AWS STS service, avoiding long-term access keys and ensuring permissions are granted only as needed.

Exam trap

The trap here is that candidates confuse network-level controls (security groups) with IAM authorization, or mistakenly believe that an instance ID can be used as a principal in a bucket policy, which is not supported by AWS IAM.

How to eliminate wrong answers

Option A is wrong because security groups operate at the network layer (stateful firewall) and cannot grant IAM-level permissions to access S3; they control traffic but not authentication or authorization. Option B is wrong because storing long-term AWS access keys on the instance violates the principle of least privilege, increases the risk of credential exposure, and requires manual rotation. Option D is wrong because bucket policies cannot grant access based on an EC2 instance ID; they support principal ARNs (like IAM roles or users) but not instance IDs, and instance IDs are not IAM principals.

58
MCQmedium

A security engineer is designing a multi-tier web application. The application uses an Application Load Balancer (ALB) to distribute traffic to EC2 instances in private subnets. The engineer needs to ensure that the EC2 instances only accept traffic from the ALB and not from any other source. Which security group configuration should the engineer use?

A.Allow inbound HTTP traffic from the ALB's public IP address on the EC2 instances' security group.
B.Allow inbound HTTP traffic from the VPC CIDR range on the EC2 instances' security group.
C.Allow inbound HTTP traffic from the ALB's security group on the EC2 instances' security group.
D.Allow inbound HTTP traffic from 0.0.0.0/0 on the EC2 instances' security group.
AnswerC

This is correct because referencing the ALB's security group as the source limits inbound HTTP to only traffic originating from the ALB's elastic network interfaces. When the ALB forwards requests to the instances, it uses its ENIs as the source IPs, which are associated with the ALB's security group, so such traffic matches the rule. Any other traffic, including direct internet access, is implicitly denied, providing a least-privilege security control.

Why this answer

It uses a security group reference to allow inbound HTTP traffic from the ALB's security group. This ensures that only traffic originating from the ALB (which has that security group attached) can reach the EC2 instances, regardless of the ALB's IP addresses or changes in the VPC CIDR. This is the recommended AWS best practice for securing traffic between an ALB and backend instances.

Exam trap

The trap here is that candidates often think they need to use the ALB's public IP address (Option A) or the VPC CIDR (Option B) as the source, not realizing that security group referencing is the correct and more secure method for allowing traffic from an ALB to backend instances.

How to eliminate wrong answers

Option A is wrong because the ALB's public IP addresses are dynamic and can change, making this approach unreliable and insecure; also, the ALB's public IPs are not the source IP of traffic reaching the instances (the ALB uses private IPs). Option B is wrong because allowing traffic from the entire VPC CIDR would permit any resource in the VPC (including compromised instances or unauthorized services) to reach the EC2 instances, violating the principle of least privilege. Option D is wrong because allowing traffic from 0.0.0.0/0 would expose the EC2 instances to the internet, defeating the purpose of placing them in private subnets and creating a severe security risk.

59
MCQhard

A company is using AWS Transit Gateway to connect multiple VPCs and on-premises networks. The Security Engineer needs to ensure that traffic between VPCs is inspected by a central network appliance. Which architecture should the Engineer implement?

A.Use Transit Gateway with appliance mode enabled on the attachments to the inspection VPC, and route inter-VPC traffic through the inspection VPC.
B.Use VPC Peering connections between all VPCs and route traffic through the inspection VPC.
C.Place the network appliance in a public subnet of the inspection VPC and use internet gateways for routing.
D.Use Transit Gateway with route tables that point to the network appliance's ENI for all inter-VPC traffic.
AnswerA

Transit Gateway appliance mode on the attachments to the inspection VPC is the correct approach because it enables the Transit Gateway to forward packets to the network appliance even when return traffic would enter through a different attachment or follow a different path. This is critical for stateful appliances that must inspect both directions of a connection. Inter-VPC traffic is routed via TGW route tables to the inspection VPC attachment, and the appliance's ENI is the next hop inside that VPC. Without appliance mode, asymmetric routing could cause the appliance or the Transit Gateway to drop packets.

Why this answer

Enabling appliance mode on the Transit Gateway attachments to the inspection VPC forces the Transit Gateway to preserve the source and destination MAC addresses of packets, ensuring that asymmetric routing does not cause the network appliance to drop traffic. By routing inter-VPC traffic through the inspection VPC, the appliance can inspect all packets, and appliance mode ensures that return traffic is sent back through the same appliance, maintaining stateful inspection.

Exam trap

The trap here is that candidates often assume that simply routing traffic through an inspection VPC via Transit Gateway is sufficient, without understanding that appliance mode is required to prevent asymmetric routing and ensure stateful inspection works correctly.

How to eliminate wrong answers

Option B is wrong because VPC Peering does not support transitive routing; each peering connection is a one-to-one relationship, so traffic cannot be routed through a central inspection VPC without creating a full mesh of connections and complex routing. Option C is wrong because placing the appliance in a public subnet with an internet gateway would expose it to the internet and is not designed for private inter-VPC traffic inspection; internet gateways are for internet-bound traffic, not VPC-to-VPC routing. Option D is wrong because simply pointing route tables to the network appliance's ENI does not enable appliance mode; without appliance mode, the Transit Gateway may perform MAC address rewriting, causing asymmetric routing and stateful inspection failures.

60
MCQmedium

A security engineer needs to restrict outbound traffic from a VPC to only allow HTTPS traffic to specific domains (e.g., api.example.com). The VPC has a NAT gateway in a public subnet. What is the most secure way to implement this restriction?

A.Configure security group egress rules to allow HTTPS to 0.0.0.0/0.
B.Deploy an AWS Network Firewall in the VPC and configure domain filtering rules.
C.Configure network ACL outbound rules to allow HTTPS to the IP addresses of the allowed domains.
D.Create a VPC endpoint for Amazon S3 and route traffic through it.
AnswerB

AWS Network Firewall is a managed, stateful intrusion prevention system that can perform application-layer inspection of outbound traffic, including domain name filtering. It can decrypt TLS traffic via TLS inspection or evaluate the Server Name Indication (SNI) in the handshake to allow or block specific domain names, regardless of the underlying IP address. By deploying Network Firewall in a VPC with a stateful rule group referencing allowed domains, the engineer can enforce the required domain-based restriction accurately.

Why this answer

AWS Network Firewall provides stateful, application-layer inspection that can filter outbound HTTPS traffic based on domain names (SNI/TLS hostnames), not just IP addresses. This allows you to restrict traffic to specific domains like api.example.com even if their IP addresses change, which is more secure and manageable than IP-based rules. Security groups and network ACLs cannot filter by domain name, and VPC endpoints are for specific AWS services, not general HTTPS domains.

Exam trap

The trap here is that candidates assume network ACLs or security groups can filter by domain name, but they operate only at Layers 3 and 4, whereas domain filtering requires Layer 7 inspection provided by AWS Network Firewall.

How to eliminate wrong answers

Option A is wrong because security group egress rules allow traffic to 0.0.0.0/0 for HTTPS, which permits outbound traffic to any destination, failing to restrict to specific domains. Option C is wrong because network ACLs are stateless and can only filter by IP addresses and ports, not domain names; IP addresses for domains like api.example.com can change, making this approach brittle and insecure. Option D is wrong because VPC endpoints are designed for private connectivity to AWS services (e.g., S3, DynamoDB) and cannot be used to restrict outbound HTTPS traffic to arbitrary external domains.

61
MCQhard

A security engineer is troubleshooting connectivity issues from an EC2 instance in a private subnet to an S3 bucket. The instance has a security group allowing outbound HTTPS (443) to 0.0.0.0/0, and the subnet's network ACL allows outbound HTTPS to 0.0.0.0/0. However, requests to S3 are timing out. Which additional configuration is most likely required?

A.Attach an IAM role to the EC2 instance with S3 permissions
B.Modify the security group to allow traffic to the S3 region-specific IP range
C.Add a VPC Gateway Endpoint for S3 and update the route table
D.Configure a TLS termination proxy
AnswerC

A VPC Gateway Endpoint for S3 is the correct fix because it installs a route entry in the private subnet's route table using the S3 prefix list, allowing traffic destined for S3 to traverse AWS's internal network instead of requiring an internet gateway or NAT device. Without this endpoint, an instance in a private subnet has no viable next hop for S3 public IP ranges, so TCP connections time out. Updating the route table to include the endpoint's prefix-list destination completes the configuration.

Why this answer

An EC2 instance in a private subnet has no route to the internet, so it cannot reach S3's public endpoints even though the security group and NACL allow outbound HTTPS. The correct fix is to create a VPC Gateway Endpoint for S3 and add a route in the subnet's route table pointing S3 traffic to the endpoint. This keeps traffic on the AWS private network and avoids the need for a NAT gateway.

Exam trap

The trap is assuming that a permissive security group and NACL are sufficient for outbound connectivity — candidates forget that a private subnet has no route to the internet and that S3 access requires either a NAT gateway or a VPC Gateway Endpoint.

How to eliminate wrong answers

Option A is wrong because an IAM role grants authorization (permission to call S3 APIs) but does not provide network reachability; without a route to S3, the request times out before any IAM evaluation occurs. Option B is wrong because S3 does not have a fixed region-specific IP range that a security group can target reliably — S3 uses a large, changing set of public IPs, and the security group already allows 0.0.0.0/0 on 443, so adding a narrower range would not solve the routing problem. Option D is wrong because a TLS termination proxy addresses encryption offloading, not network path availability; it does not create a route from a private subnet to S3.

62
MCQmedium

A security engineer notices that an EC2 instance in a private subnet is able to make outbound connections to the internet. The instance does not have a public IP, and there is no NAT gateway or instance in the VPC. What is the most likely cause?

A.The VPC has an egress-only internet gateway for IPv6 traffic.
B.The instance has a public IP assigned automatically via Auto-assign Public IP.
C.The instance is using a VPC endpoint (Gateway type) for S3.
D.The subnet's route table has a default route (0.0.0.0/0) pointing to an internet gateway.
AnswerA

An egress-only internet gateway (EIGW) is an IPv6-specific VPC component that enables instances with IPv6 addresses to initiate outbound connectivity to the internet, but it blocks all inbound connections from the internet. Because an EIGW is completely independent of IPv4 addressing, an instance can reside in a private subnet without a public IPv4 address and still reach the internet via a route table entry for ::/0 pointing to the EIGW. In this scenario, the observed internet access is therefore consistent with the VPC having an egress-only internet gateway for IPv6 traffic.

Why this answer

An egress-only internet gateway (EIGW) allows outbound IPv6 traffic from instances in a private subnet without requiring a public IPv4 address or NAT. Since the instance is making outbound connections to the internet and has no public IP or NAT, and the VPC likely has IPv6 enabled, the EIGW is the most plausible cause. Option D is incorrect because a default route to an internet gateway requires the instance to have a public IPv4 address for return traffic, which contradicts the scenario.

Exam trap

The trap here is that candidates assume a private subnet inherently blocks internet access, but the question tests whether they understand that a subnet's route table—not its public/private designation—determines outbound connectivity, and a 0.0.0.0/0 route to an IGW makes it a public subnet regardless of the instance's IP assignment.

How to eliminate wrong answers

Option A is wrong because an egress-only internet gateway (EIGW) only supports IPv6 traffic, and the question does not mention IPv6; it would not enable outbound IPv4 connections. Option B is wrong because the instance does not have a public IP, and Auto-assign Public IP only applies at launch; even if enabled, the instance would have a public IP, contradicting the premise. Option C is wrong because a VPC Gateway Endpoint for S3 only provides private connectivity to S3, not general internet access; it cannot route traffic to arbitrary internet destinations.

63
Multi-Selectmedium

A security engineer is configuring a VPC for a web application. The VPC has public and private subnets. The web servers are in public subnets and the database servers are in private subnets. The engineer wants to ensure that the database servers are not accessible from the internet. Which two actions should the engineer take?

Select 2 answers
A.Place the database instances in a public subnet with a NAT gateway.
B.Assign public IP addresses to the database instances.
C.Ensure the route table for the database subnets does not have a default route to an Internet Gateway.
D.Create a security group for the database instances that allows inbound traffic only from the web servers' security group.
E.Configure a network ACL on the database subnets to deny all inbound traffic.
AnswersC, D

This is correct because omitting a 0.0.0.0/0 route to the internet gateway from the database subnet's route table makes it a private subnet, so unsolicited inbound traffic from the internet has no path to reach the database instances. This routing-layer control ensures that even if a security group rule were overly permissive, the network stack itself would still drop internet-originated packets destined for the database. This is a foundational defense-in-depth measure in VPC design and is required to keep database instances isolated from the public internet.

Why this answer

Removing the default route (0.0.0.0/0) to an Internet Gateway (IGW) from the route table associated with the database subnets ensures that traffic from those subnets cannot reach the internet, and the internet cannot initiate connections to instances in those subnets. This is the fundamental network-level isolation required for private subnets in a VPC.

Exam trap

The trap here is that candidates often confuse network ACLs with security groups, thinking a deny-all NACL is sufficient, but they overlook that NACLs are stateless and would block necessary return traffic, whereas security groups are stateful and automatically allow return traffic for permitted inbound connections.

64
MCQhard

A company has a VPC with a public subnet and a private subnet. An Amazon RDS instance is in the private subnet, and an application server is in the public subnet. The security team needs to allow the application server to connect to the RDS instance on port 3306 (MySQL). Which configuration will meet this requirement securely?

A.Add an inbound rule to the RDS security group that allows traffic from the VPC CIDR on port 3306.
B.Add an inbound rule to the RDS security group that allows traffic from the security group of the application server on port 3306.
C.Add an inbound rule to the RDS security group that allows traffic from the subnet CIDR of the application server on port 3306.
D.Add an inbound rule to the RDS security group that allows traffic from 0.0.0.0/0 on port 3306.
AnswerB

This is the correct approach: referencing the application server's security group (SG) as the source in the RDS inbound rule permits only traffic originating from network interfaces attached to that specific SG. This pattern—often called SG chaining—is dynamically updated if the instance's private IP changes, is not tied to subnet boundaries, and automatically covers any additional instances that later receive the same SG, making it the most precise and maintainable solution.

Why this answer

It uses a security group reference as the source in the inbound rule for the RDS security group. This allows traffic only from the specific application server(s) associated with that security group, regardless of their IP addresses, and automatically scales if the application server is replaced or scaled. This is the most secure and AWS-recommended method for controlling traffic between resources within a VPC.

Exam trap

The trap here is that candidates often confuse security group references with CIDR-based rules, mistakenly thinking that allowing traffic from the subnet CIDR (Option C) is equivalent to allowing traffic from the application server, when in fact it permits any resource in that subnet to connect.

How to eliminate wrong answers

Option A is wrong because allowing traffic from the entire VPC CIDR is overly permissive; any resource in the VPC, including unintended instances or services, could connect to the RDS instance, violating the principle of least privilege. Option C is wrong because allowing traffic from the subnet CIDR of the application server permits any resource launched in that subnet (e.g., other instances or containers) to access the RDS instance, not just the intended application server. Option D is wrong because allowing traffic from 0.0.0.0/0 exposes the RDS instance to the entire internet, which is a severe security risk and contradicts the requirement to keep the RDS instance in a private subnet.

65
MCQmedium

A security engineer is reviewing the security group rules for a web server. The security group currently has the following inbound rules: allow HTTP from 0.0.0.0/0, allow HTTPS from 0.0.0.0/0, and allow SSH from 0.0.0.0/0. Which change should the engineer make to improve security?

A.Remove the HTTP rule and keep only HTTPS.
B.Change the SSH rule to allow from the VPC CIDR only.
C.Change the SSH rule to allow from a specific IP range used by the company's administrators.
D.Add a rule to allow ICMP from 0.0.0.0/0.
AnswerC

This is correct because it follows the principle of least privilege by limiting SSH inbound traffic to the specific IP range (or security group) that represents the company's administrators. By restricting the source to known administrative egress addresses, the attack surface is dramatically reduced and unauthorized internal or external actors cannot initiate SSH connections. For a production web tier, SSH should typically be allowed only from a bastion jump host or a dedicated admin VPN CIDR, not from a broad public range. This ensures that only authenticated, expected users can establish a management session.

Why this answer

Restricting SSH access (TCP port 22) to a specific IP range used by the company's administrators follows the principle of least privilege. The current rule allows SSH from 0.0.0.0/0, which exposes the server to brute-force attacks and unauthorized access from the entire internet. By limiting the source to only trusted administrative IPs, the attack surface is significantly reduced while still allowing necessary remote management.

Exam trap

The trap here is that candidates may think restricting SSH to the VPC CIDR (Option B) is sufficient, but the exam expects you to recognize that the VPC CIDR can include many hosts, and the most secure approach is to limit to the specific administrative IP range, not just the internal network.

How to eliminate wrong answers

Option A is wrong because removing HTTP (port 80) while keeping only HTTPS (port 443) would break access for clients that do not support HTTPS or for redirects, and it does not address the critical SSH exposure; the question asks for a security improvement, not a change to web traffic rules. Option B is wrong because allowing SSH from the VPC CIDR only is too permissive if the VPC CIDR is large (e.g., 10.0.0.0/16) and includes non-administrative instances or subnets, still exposing SSH to potential internal threats; it is better to restrict to a specific IP range used by administrators. Option D is wrong because adding an ICMP (ping) rule from 0.0.0.0/0 increases the attack surface unnecessarily, as ICMP can be used for network reconnaissance and does not improve security for the web server.

66
MCQmedium

A company uses AWS WAF to protect a web application. The security team wants to block requests that contain SQL injection patterns. Which WAF rule type should be used?

A.IP set rule
B.Geographic match rule
C.Rate-based rule
D.SQL injection match rule
AnswerD

An SQL injection match rule in AWS WAF inspects the request components you configure—such as the query string, body, header, or cookie values—for known SQLi signatures like ' OR '1'='1, UNION SELECT, or comment and quote sequences. It uses pattern matching, optionally normalized with rule-specific text transformations to reduce evasive bypasses like URL encoding or case variation. This is the only rule type among the options that performs payload-level content inspection and produces a match based on the actual malicious input in the request, making it the correct choice for detecting SQL injection.

Why this answer

AWS WAF provides a dedicated SQL injection match rule that inspects incoming requests for SQL injection patterns in the URI, query string, or body. This rule uses a set of predefined SQL-like patterns (e.g., 'OR 1=1', 'UNION SELECT') to detect and block malicious input, directly addressing the security team's requirement.

Exam trap

The trap here is that candidates may confuse a rate-based rule (which controls request volume) with a content-based rule (which inspects payloads), leading them to pick Option C instead of the correct SQL injection match rule.

How to eliminate wrong answers

Option A is wrong because an IP set rule matches requests based on source IP addresses, not on content patterns like SQL injection. Option B is wrong because a geographic match rule filters traffic based on the country of origin, not on request payload content. Option C is wrong because a rate-based rule limits the number of requests from a single IP over a time window, which is used for DDoS mitigation, not for detecting SQL injection patterns.

67
MCQeasy

A Security Engineer needs to block SSH traffic (port 22) from the internet to all EC2 instances in a VPC. Which approach is the most secure and scalable?

A.Add a security group rule to deny inbound traffic on port 22 from 0.0.0.0/0.
B.Add a network ACL rule to deny inbound traffic on port 22 from 0.0.0.0/0 at the subnet level.
C.Add a network ACL rule to allow inbound traffic on port 22 from 0.0.0.0/0 and then add a deny rule for the same traffic.
D.Add a security group rule to block inbound traffic on port 22 from 0.0.0.0/0 at the VPC level.
AnswerB

A network ACL (NACL) is a stateless firewall applied at the subnet level, and it explicitly supports both allow and deny rules. By adding a deny rule for inbound TCP port 22 from 0.0.0.0/0 with a low rule number, you block all SSH traffic from any source from entering the subnet. This is the correct method because security groups cannot provide an explicit deny, and the NACL rule operates at the subnet boundary rather than at individual resources.

Why this answer

Network ACLs (NACLs) are stateless and operate at the subnet level, allowing you to explicitly deny inbound SSH traffic from 0.0.0.0/0. This approach is more secure and scalable than security group rules because NACLs can block traffic before it reaches the instance, and they support explicit deny rules, which security groups do not. Security groups only support allow rules, so you cannot add a deny rule to block SSH traffic; you must omit the allow rule, which is less explicit and can be accidentally overridden.

Exam trap

The trap here is that candidates often confuse security groups with network ACLs, assuming security groups can have explicit deny rules, when in fact only NACLs support deny rules and operate at the subnet level.

How to eliminate wrong answers

Option A is wrong because security groups do not support deny rules; they only support allow rules, so adding a 'deny' rule is syntactically invalid and cannot be implemented. Option C is wrong because NACLs evaluate rules in order by rule number, and an allow rule with a lower number would permit the traffic before a deny rule with a higher number is evaluated, making the deny ineffective; additionally, allowing then denying the same traffic is redundant and not a best practice. Option D is wrong because security groups cannot be applied at the VPC level; they are associated with individual ENIs or instances, not the entire VPC, and they do not support deny rules.

68
MCQmedium

A company has a multi-account AWS environment using AWS Organizations. The security team wants to centrally manage VPC security group rules across all accounts. Which AWS service should they use?

A.AWS Network Firewall
B.AWS Firewall Manager
C.AWS Config
D.Amazon Route 53 Resolver DNS Firewall
AnswerB

AWS Firewall Manager is the designated service for centrally managing VPC security group rules across all accounts and resources within an AWS Organization. It allows administrators to create security group policies, enforce common security group rules, remediate noncompliant rules automatically, and apply consistent protection to new accounts as they join the organization. This directly matches the requirement for central management of security group rules, making it the correct answer.

Why this answer

AWS Firewall Manager is designed to centrally manage security policies across all accounts in an AWS Organization, including VPC security group rules. It allows you to define a security group policy that automatically applies to existing and new resources, ensuring consistent enforcement across the organization. This is the only service among the options that provides centralized, cross-account management of security groups.

Exam trap

SCS-C02 often tests the distinction between services that can audit security groups (AWS Config) and those that can centrally manage and enforce rules (AWS Firewall Manager). Candidates frequently confuse AWS Config's compliance checks with actual enforcement capabilities.

How to eliminate wrong answers

Option A is wrong because AWS Network Firewall is a managed network firewall service that provides traffic filtering at the VPC level, but it does not centrally manage security group rules across accounts. Option C is wrong because AWS Config is a configuration assessment and auditing service that can detect non-compliant security groups but cannot enforce or centrally manage rules across accounts. Option D is wrong because Amazon Route 53 Resolver DNS Firewall filters DNS queries, not VPC security group rules, and it does not provide cross-account management of security groups.

69
MCQmedium

A security engineer needs to ensure that all Amazon S3 buckets in an AWS account have server-side encryption (SSE) enabled. The engineer wants to automatically remediate any bucket that is created without SSE. Which solution should the engineer implement?

A.Use S3 bucket policies to deny access to objects without encryption.
B.Apply an IAM policy that requires SSE for all S3 actions.
C.Use AWS Config with a managed rule (s3-bucket-server-side-encryption-enabled) and an automatic remediation action.
D.Create a service control policy (SCP) that denies creation of buckets without encryption.
AnswerC

AWS Config's managed rule `s3-bucket-server-side-encryption-enabled` continuously evaluates each S3 bucket for the presence of server-side encryption. When a bucket is found non-compliant, an automatic remediation action—typically a Systems Manager Automation document that calls `PutBucketEncryption`—is invoked to enable default encryption on that bucket. This provides a closed loop that both detects drift and corrects it for existing and newly created buckets, making it the only option that satisfies 'ensure all S3 buckets' proactively and reactively.

Why this answer

AWS Config's managed rule s3-bucket-server-side-encryption-enabled continuously evaluates every S3 bucket in the account and flags any that lack default encryption. Pairing it with an automatic remediation action (typically an SSM Automation document such as AWS-EnableS3BucketEncryption) means newly created non-compliant buckets are remediated without human intervention, satisfying the 'automatically remediate' requirement. This is the canonical AWS-native pattern for continuous compliance enforcement on S3.

Exam trap

SCS-C02 often tests the distinction between preventive controls (SCPs, bucket policies, IAM) and detective-plus-remediation controls (AWS Config + SSM Automation) — candidates pick SCPs or bucket policies because they sound like 'enforcement' but they cannot automatically remediate existing resources.

How to eliminate wrong answers

Option A is wrong because an S3 bucket policy can deny unencrypted PUT requests (e.g., via s3:PutObject with a Null condition on s3:x-amz-server-side-encryption), but it does not enable SSE on the bucket itself and does not remediate existing buckets — it only blocks certain writes. Option B is wrong because IAM policies control identity permissions, not bucket-level encryption configuration; IAM cannot force a bucket to have default encryption enabled. Option D is wrong because an SCP can only deny the s3:CreateBucket action or require a condition, but it cannot retroactively enable encryption on existing buckets and does not provide automatic remediation — it merely blocks creation, leaving the account without a compliant bucket.

70
MCQhard

A company is designing a network architecture for a critical application that must meet strict compliance requirements. The application consists of Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The instances need to access an Amazon RDS database in a different VPC. The company wants to minimize exposure to the internet. Which solution should the company use?

A.Use a site-to-site VPN connection between the VPCs.
B.Use a NAT gateway in the database VPC and route traffic through it.
C.Use a VPC Peering connection between the two VPCs.
D.Use an internet gateway and route traffic over the internet with security groups.
AnswerC

A VPC peering connection privately connects two VPCs using AWS's internal backbone, with no traffic traversing the public internet and no need for a public IP address, VPN appliance, or gateway. It creates direct layer-3 route table entries between the VPC CIDRs, and because the relationship is native to AWS, traffic stays isolated from external carriers. For a single application-to-database pair with non-overlapping CIDRs, VPC peering is the simplest and most cost-effective way to establish low-latency private connectivity.

Why this answer

VPC Peering establishes a private, direct network connection between two VPCs using AWS's internal infrastructure, with no exposure to the internet. Traffic stays within the AWS global network, meeting strict compliance requirements for minimizing internet exposure. This allows EC2 instances in the application VPC to communicate with the RDS database in the database VPC securely and with low latency, using private IP addresses.

Exam trap

The trap here is that candidates often confuse VPC Peering with site-to-site VPN, thinking VPN is required for cross-VPC connectivity, but VPC Peering is the correct AWS-native solution for private VPC-to-VPC communication without internet exposure.

How to eliminate wrong answers

Option A is wrong because a site-to-site VPN connection is used to connect an on-premises network to a VPC, not to connect two VPCs within AWS; it would introduce internet exposure (via the VPN tunnel over the public internet) and unnecessary complexity. Option B is wrong because a NAT gateway is designed to allow instances in a private subnet to initiate outbound traffic to the internet, not to enable private communication between two VPCs; routing traffic through a NAT gateway would force traffic over the internet and break the requirement to minimize exposure. Option D is wrong because using an internet gateway and routing traffic over the internet with security groups exposes the traffic to the public internet, violating the compliance requirement to minimize internet exposure; security groups alone cannot prevent the inherent risk of internet-based communication.

71
Multi-Selectmedium

A security engineer is designing a network architecture for a multi-tier application. The web servers must be accessible from the internet, while the application servers must only be accessible from the web servers. Which TWO configurations should be used? (Choose TWO.)

Select 2 answers
A.Configure a NAT gateway in the private subnet for the application servers.
B.Place the web servers in a public subnet with a route to an internet gateway.
C.Use a network ACL on the application subnet to allow inbound traffic from the web subnet's IP range.
D.Place the application servers in a public subnet with a route to an internet gateway.
E.Configure the application servers' security group to allow traffic only from the web servers' security group.
AnswersB, E

A public subnet routes 0.0.0.0/0 to an internet gateway, so web servers can receive inbound internet traffic and respond outbound. This satisfies the requirement that web servers be internet-accessible, while application servers remain in private subnets with no such route.

Why this answer

Option B is correct because placing the web servers in a public subnet with a route to an internet gateway (0.0.0.0/0 → igw-xxxx) is exactly what makes them reachable from the internet, satisfying the requirement that web servers be internet-accessible. Option E is correct because referencing the web servers' security group as the source in the application servers' security group inbound rules enforces that only instances in that web security group can reach the application tier, which is the recommended, identity-based way to restrict access in a multi-tier design. Option A is not needed here: a NAT gateway provides outbound-only internet access for private subnets and does not control inbound access from the web tier, so it does not satisfy the stated requirement.

Option C is not the best fit because network ACLs are stateless subnet-level filters based on CIDR ranges; while they can restrict traffic, they are not the mechanism that ties access to the web servers' identity, and the question asks for the configuration that limits application access to the web servers specifically. Option D is wrong because putting the application servers in a public subnet with an internet gateway route would expose them to the internet, directly violating the requirement that they be reachable only from the web servers.

Exam trap

The trap here is that candidates often confuse network ACLs with security groups, incorrectly assuming that a stateless network ACL with IP-based rules is the correct way to restrict traffic between tiers, when in fact security group references provide a more secure and manageable solution.

72
MCQmedium

A company uses AWS Transit Gateway to connect multiple VPCs and on-premises networks via AWS Site-to-Site VPN. Security engineers need to ensure that traffic between VPCs is inspected by a third-party firewall appliance deployed in a centralized inspection VPC. Which architecture should be used?

A.Use security groups in each VPC to allow only traffic from the firewall appliance's IP.
B.Establish VPC Peering connections between each VPC and the inspection VPC.
C.Configure Network ACLs in each VPC to deny traffic that does not originate from the inspection VPC.
D.Create a central inspection VPC with the firewall appliance. Configure Transit Gateway route tables to route traffic between VPCs through the inspection VPC.
AnswerD

Create a dedicated inspection VPC that hosts a firewall appliance or a Gateway Load Balancer, and use separate Transit Gateway route tables to force inter-VPC traffic through that VPC. For example, associate each spoke VPC attachment with a route table that has a target route pointing to the inspection VPC attachment for all destination CIDRs, while the inspection VPC uses its own route table to reach the final destination VPCs. This design leverages Transit Gateway's transitive routing and supports high availability through multiple firewall instances behind a Gateway Load Balancer. It is a best practice for centralized east-west traffic inspection in a multi-VPC topology.

Why this answer

Transit Gateway route tables can force traffic between VPCs through the inspection VPC by attaching the firewall appliance and using specific routing entries. Option A is incorrect because security groups only control traffic at the instance level and cannot redirect traffic to an inspection appliance. Option B is incorrect because VPC Peering does not support transitive routing, so traffic between two VPCs cannot go through a third VPC.

Option C is incorrect because Network ACLs are stateless and can only filter traffic based on IP/port, not route traffic through an inspection appliance.

73
MCQeasy

A company is using AWS CloudFormation to deploy a web application. The template includes an EC2 instance with a security group that allows inbound HTTP traffic from 0.0.0.0/0. The security team wants to ensure that this security group is never used in production. Which AWS service can automatically remediate this noncompliant configuration?

A.AWS Identity and Access Management (IAM)
B.AWS Config
C.Amazon GuardDuty
D.AWS CloudTrail
AnswerB

AWS Config continuously records each supported resource's configuration history and evaluates that state against customizable rules and conformance packs. When a resource violates a rule, Config can invoke an AWS Systems Manager Automation document to perform auto-remediation, such as restoring security group rules or untagging resources. This combination of continuous evaluation and corrective action is exactly what is needed to enforce the intended deployed state from CloudFormation.

Why this answer

AWS Config is the correct service because it provides managed rules (e.g., 'restricted-ssh' or 'incoming-ssh-disabled') that can evaluate security group configurations against desired compliance. When a noncompliant resource is detected, AWS Config can trigger an automatic remediation action via Systems Manager Automation documents (e.g., AWSConfigRemediation-RevokeUnusedSecurityGroupIngress) to remove the overly permissive inbound rule. This directly addresses the security team's requirement to prevent the use of a security group allowing HTTP traffic from 0.0.0.0/0 in production.

Exam trap

The trap here is that candidates often confuse AWS Config's detective and preventive capabilities with those of GuardDuty or CloudTrail, mistakenly thinking that threat detection or logging services can automatically fix misconfigurations, when only AWS Config with remediation actions can do so.

How to eliminate wrong answers

Option A is wrong because AWS Identity and Access Management (IAM) manages user permissions and access control, not resource configuration compliance or automated remediation of security group rules. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events for malicious activity; it does not evaluate or remediate security group configurations. Option D is wrong because AWS CloudTrail records API calls for auditing and governance, but it cannot automatically remediate noncompliant resources; it only provides logs for manual review or downstream processing.

74
MCQmedium

Refer to the exhibit. A security engineer reviews the AWS WAF web ACL configuration. What is the effect of this configuration?

A.It blocks IPs that send more than 2000 requests and allows requests containing '<script>' in the body.
B.It allows all traffic because the rules are misconfigured.
C.It blocks both SQL injection and XSS attacks.
D.It blocks SQL injection attacks and allows XSS attacks.
AnswerA

The web ACL contains two rules evaluated in order. The first is a rate-based rule with a threshold of 2,000 requests per IP address over the evaluation window; when that limit is exceeded, the Block action immediately terminates the request. Requests that stay below the threshold continue to the second rule, an XSS match rule whose action is set to Allow, so any request with `<script>` in its body is explicitly permitted rather than blocked. The net effect is therefore IP-based volumetric blocking only, with no content-based blocking.

Why this answer

The first rule (SQLiRule) is actually a rate-based rule that blocks IPs exceeding 2000 requests, not SQL injection. The second rule (XSSRule) has an Allow action, which would allow requests containing '<script>' in the body, defeating the purpose of blocking XSS.

75
MCQhard

Refer to the exhibit. A security engineer runs the command above and sees that the flow log status is ACTIVE. However, the engineer notices that no logs are appearing in the CloudWatch log group. What is the most likely cause?

A.The TrafficType is set to ALL, which captures too much data and causes throttling.
B.The IAM role specified in DeliverLogsPermissionArn does not have permissions to PutLogEvents.
C.The flow log is attached to an ENI instead of a subnet.
D.The flow log destination is set to CloudWatch Logs but the log group is encrypted with KMS.
AnswerB

The DeliverLogsPermissionArn role must have a trust policy allowing vpc-flow-logs.amazonaws.com to assume it and an IAM permissions policy granting logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents. Without logs:PutLogEvents, the Flow Logs service cannot append records to the CloudWatch log stream, so the flow log remains in a FAILED state. Adding the missing PutLogEvents permission is the standard fix for this symptom.

Why this answer

The most likely cause is that the IAM role specified in the DeliverLogsPermissionArn does not have the necessary permissions to call PutLogEvents on the CloudWatch Logs log group. Even if the flow log status is ACTIVE, the delivery of log records will silently fail if the role lacks the required logs:PutLogEvents, logs:CreateLogStream, and logs:DescribeLogStreams actions. The ACTIVE status only indicates that the flow log configuration is valid and the service is attempting to deliver logs, not that delivery is succeeding.

Exam trap

The trap here is that candidates assume an ACTIVE status guarantees logs are being delivered, but AWS explicitly documents that ACTIVE only means the configuration is valid, not that delivery is succeeding; the real test is whether the IAM role has the correct permissions to write to CloudWatch Logs.

How to eliminate wrong answers

Option A is wrong because setting TrafficType to ALL captures all accepted and rejected traffic, which can generate large volumes of data, but CloudWatch Logs throttling is based on the log group's throughput limits and the IAM role's permissions, not the TrafficType setting; throttling would produce a different symptom (e.g., logs appearing slowly or with delays) rather than no logs at all. Option C is wrong because attaching a flow log to an ENI is a valid and common configuration; flow logs can be created at the VPC, subnet, or ENI level, and all are supported, so this would not prevent logs from appearing. Option D is wrong because if the log group is encrypted with a KMS key, the IAM role must also have kms:Decrypt and kms:GenerateDataKey permissions on that key; however, the absence of KMS permissions would cause a different error (e.g., 'AccessDenied' in the flow log status or CloudWatch Logs), but the question states the flow log status is ACTIVE, which implies the KMS permissions are likely correct or the log group is not encrypted; the core issue is the missing PutLogEvents permission.

Page 1 of 4 · 245 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Infrastructure Security questions.