Courseiva

CCNA Infrastructure Security Questions

75 of 245 questions · Page 2/4 · Infrastructure Security topic · Answers revealed

76
MCQmedium

A security engineer is designing a network architecture for a three-tier web application. The web tier must be accessible from the internet, but the application and database tiers must not. Which VPC configuration should be used?

A.Place web and app tiers in public subnets, database in private subnet.
B.Place web tier in public subnets, app and database tiers in private subnets.
C.Place all tiers in private subnets and use a VPN for external access.
D.Place all tiers in public subnets with security groups restricting access.
AnswerB

This standard three-tier design places only the web tier in public subnets with a route to an internet gateway so it can serve external users. The app and database tiers are in private subnets with no internet gateway route, preventing direct inbound connections from the internet; the app tier receives traffic from the web tier through an internal load balancer or security group rules, and the database is isolated to app-tier-only access. This minimizes the attack surface and is the correct pattern for a public-facing web application.

Why this answer

It places the web tier in public subnets with an internet gateway for direct internet access, while the application and database tiers reside in private subnets with no direct internet route. This ensures that only the web tier is exposed, and the app and database tiers can only be reached through the web tier via internal routing, aligning with the principle of least privilege for a three-tier architecture.

Exam trap

The trap here is that candidates often confuse security groups with subnet routing, assuming that restrictive security groups alone can prevent internet access even when the subnet is public, but the route table's default route to an internet gateway still allows inbound traffic from the internet.

How to eliminate wrong answers

Option A is wrong because placing the app tier in a public subnet exposes it to the internet, violating the requirement that only the web tier be accessible from the internet. Option C is wrong because using a VPN for external access would require all traffic to go through the VPN, which is unnecessary and adds complexity; the web tier is meant to be publicly accessible without VPN. Option D is wrong because placing all tiers in public subnets, even with security groups, still exposes the app and database tiers to potential internet-facing risks, as security groups alone do not prevent direct internet access from the subnet's route table.

77
MCQhard

A company is deploying a web application on EC2 instances behind an Application Load Balancer. The security team requires that all traffic between the ALB and the EC2 instances be encrypted. Which configuration should the engineer implement?

A.Configure the ALB listener with HTTP protocol and the target group with HTTP protocol, then use a security group to restrict traffic.
B.Configure the ALB listener with HTTPS protocol and the target group with HTTP protocol.
C.Configure the ALB listener with TCP protocol and the target group with TCP protocol, then install SSL certificates on the EC2 instances.
D.Configure the ALB listener with HTTPS protocol and the target group with HTTPS protocol, and install SSL certificates on the EC2 instances.
AnswerD

End-to-end encryption requires TLS on both hops: an HTTPS listener terminates client TLS, while an HTTPS target group re-encrypts traffic to the instances. Installing certificates on the EC2 instances lets them present them, satisfying the requirement that ALB-to-instance traffic is encrypted.

Why this answer

It ensures end-to-end encryption between the ALB and EC2 instances. The ALB listener uses HTTPS to terminate client SSL/TLS, and the target group uses HTTPS to re-encrypt traffic to the instances, requiring SSL certificates on the EC2 instances to decrypt and re-encrypt. This satisfies the security requirement that all traffic between the ALB and EC2 instances be encrypted.

Exam trap

The trap here is that candidates often assume HTTPS on the listener alone is sufficient, overlooking that the target group protocol must also be HTTPS to encrypt traffic between the ALB and instances, not just between clients and the ALB.

How to eliminate wrong answers

Option A is wrong because using HTTP on both the listener and target group means traffic is in plaintext, violating the encryption requirement. Option B is wrong because while the listener uses HTTPS, the target group uses HTTP, so traffic between the ALB and EC2 instances is unencrypted, which does not meet the requirement. Option C is wrong because TCP protocol at the listener and target group does not provide application-layer encryption; SSL certificates on EC2 instances alone do not encrypt traffic without HTTPS configuration on the target group.

78
MCQeasy

A company wants to allow its developers to SSH into EC2 instances only from the corporate network IP range (203.0.113.0/24). Which configuration should be used to enforce this restriction?

A.Configure a network ACL on the subnet to allow inbound SSH from the corporate range and deny all other inbound traffic.
B.Use AWS Systems Manager Session Manager to connect to instances instead of SSH.
C.Add an IAM policy that allows `ec2:RunInstances` only if the request includes the corporate IP.
D.Add a security group rule that allows inbound SSH (port 22) from the corporate IP range.
AnswerD

Adding a security group rule to allow inbound SSH (port 22) only from the corporate IP range is the correct solution because security groups are stateful and act at the instance's network interface level. This rule denies all other inbound SSH traffic by default, since security groups have an implicit deny-all inbound rule, and because it is stateful, return traffic for allowed connections (e.g., ephemeral ports) is automatically permitted. This directly restricts SSH to the corporate range without requiring separate outbound rules, making it the appropriate mechanism for this use case.

Why this answer

A security group rule can restrict inbound SSH to the specific IP range. Security groups act as a virtual firewall for EC2 instances, and by adding a rule that allows inbound SSH only from the corporate IP range (203.0.113.0/24), all other inbound traffic on port 22 is implicitly denied. Option A is incorrect because network ACLs are stateless and apply at the subnet level, not the instance level, and the question asks for a configuration to enforce SSH restriction on EC2 instances.

Option B is incorrect because AWS Systems Manager Session Manager does not use SSH; it provides browser-based shell access without inbound ports. Option C is incorrect because IAM policies control permissions for API actions, not network traffic.

79
MCQeasy

A company is using an Application Load Balancer (ALB) to distribute traffic to a set of EC2 instances in private subnets. The security team wants to ensure that only traffic from the ALB can reach the EC2 instances. Which security group configuration should be applied to the EC2 instances?

A.Allow inbound HTTP/HTTPS from the security group attached to the ALB.
B.Configure the network ACL to allow traffic from the ALB's private IP addresses.
C.Allow inbound HTTP/HTTPS from 0.0.0.0/0.
D.Allow inbound HTTP/HTTPS from the VPC CIDR block.
AnswerA

Referencing the ALB's security group as the source is a security group-to-security group rule: it dynamically matches any IP address associated with an elastic network interface that belongs to that ALB security group. This means EC2 instances behind the ALB accept traffic only from the ALB's ENIs, even as the ALB scales and its private IPs change. The rule is stateful, so return traffic flows automatically, and no internet CIDR is ever exposed. This is the AWS-recommended pattern for placing an ALB in front of a web tier.

Why this answer

Referencing the security group of the Application Load Balancer as the source in the inbound rule ensures that only traffic coming from the ALB can reach the EC2 instances. Option B is incorrect because network ACLs are stateless and cannot reference security groups; they also operate at the subnet level, not at the instance level. Option C is incorrect because allowing traffic from 0.0.0.0/0 would expose the instances to the internet.

Option D is incorrect because allowing traffic from the VPC CIDR would permit any instance in the VPC to access the EC2 instances, not just the ALB.

80
Multi-Selecthard

A security engineer is designing a network architecture in AWS. The engineer needs to ensure that all outbound traffic from a VPC goes through a centrally managed NAT device for logging and filtering. The VPC has multiple private subnets. Which TWO steps are required to accomplish this? (Choose TWO.)

Select 2 answers
A.Deploy an HTTP forward proxy in the public subnet.
B.Create a route table for the private subnets with a default route (0.0.0.0/0) pointing to the NAT device.
C.Set up a transit gateway and attach the VPC to it.
D.Create a gateway endpoint for Amazon S3.
E.Place the NAT device in a public subnet with a route to an internet gateway.
AnswersB, E

Private subnets lack a route to the internet, so their route tables must direct 0.0.0.0/0 to the central NAT device's elastic network interface. This satisfies the requirement that all outbound traffic traverses the NAT for logging and filtering.

Why this answer

Option B is correct because the private subnets' route table must have a default route (0.0.0.0/0) whose target is the central NAT device (e.g., a NAT instance or NAT Gateway), which forces all outbound traffic to be sent to that device for logging and filtering instead of going directly to an internet gateway. Option E is correct because the NAT device itself must reside in a public subnet and have a route to an internet gateway so it can forward the private subnets' traffic to the internet while performing the required logging and filtering. Option A is not required because an HTTP forward proxy is an application-layer solution and is not the mechanism that routes VPC subnet traffic to a NAT device; the question asks for the routing/placement steps.

Option C is unnecessary because a transit gateway is used to interconnect VPCs or on-premises networks, not to route a single VPC's outbound traffic through a NAT device. Option D is incorrect because a gateway endpoint for Amazon S3 only provides private access to S3 and does not handle general outbound internet traffic through a NAT device.

Exam trap

SCS-C02 often tests the confusion between a NAT gateway (which requires a public subnet and IGW route) and a transit gateway or VPC endpoint, tricking candidates into selecting connectivity services that do not provide NAT.

81
MCQmedium

A company has an Amazon S3 bucket that stores sensitive data. The security team wants to ensure that all access to the bucket is made only via HTTPS. Which policy should be used?

A.Enable CloudFront with HTTPS-only viewer protocol policy.
B.Use a VPC endpoint for S3 with a bucket policy that restricts access to the VPC endpoint.
C.Enable 'Block public access' on the bucket.
D.Add a bucket policy that denies access when aws:SecureTransport is false.
AnswerD

A bucket policy that explicitly denies requests when aws:SecureTransport equals false is correct because aws:SecureTransport is a global IAM condition key that is true for HTTPS and false for HTTP. Using a Bool condition with a Deny effect overrides any other allow statement in the policy, so every S3 operation, including from authorized IAM principals, must arrive over TLS. This is the standard way to enforce HTTPS at the S3 API level, and it cannot be bypassed by accessing the bucket directly.

Why this answer

The condition `aws:SecureTransport` evaluates to `false` when the request is made over HTTP instead of HTTPS. By adding a bucket policy that denies all S3 actions when `aws:SecureTransport` is `false`, the company enforces HTTPS-only access at the policy level, regardless of how the request originates.

Exam trap

The trap here is that candidates often confuse network-level controls (like VPC endpoints or CloudFront) with transport-level encryption enforcement, mistakenly thinking they guarantee HTTPS when they only control the network path or the viewer-to-edge segment.

How to eliminate wrong answers

Option A is wrong because enabling CloudFront with an HTTPS-only viewer protocol policy only enforces HTTPS between viewers and CloudFront, not between CloudFront and the S3 origin; the S3 bucket itself could still be accessed directly via HTTP. Option B is wrong because a VPC endpoint for S3 with a bucket policy restricting access to the VPC endpoint controls network path but does not enforce HTTPS; requests over the VPC endpoint can still use HTTP. Option C is wrong because enabling 'Block public access' prevents public access but does not enforce HTTPS; authenticated users or applications could still make HTTP requests.

82
Multi-Selecthard

A company needs to enforce that all Amazon S3 buckets are encrypted at rest. Which TWO actions should be taken? (Choose two.)

Select 2 answers
A.Enable AWS CloudTrail to log S3 API calls.
B.Use bucket policies to deny write operations without encryption.
C.Enable default encryption on each S3 bucket.
D.Create a KMS key and apply it to all buckets.
E.Use a service control policy (SCP) to deny the s3:PutBucketPublicAccessBlock action.
AnswersB, C

Bucket policies that deny s3:PutObject unless the request includes encryption headers block unencrypted uploads at the authorisation layer, enforcing encryption at rest for every write. This satisfies the requirement to prevent plaintext objects from being stored.

Why this answer

Option B is correct because a bucket policy with a Deny effect on s3:PutObject when the request lacks the s3:x-amz-server-side-encryption header (or uses an unapproved algorithm) actively blocks unencrypted uploads, enforcing encryption at rest at the object level. Option C is correct because enabling default encryption (SSE-S3 or SSE-KMS) on each bucket ensures any object PUT without explicit encryption headers is automatically encrypted at rest. Option A is incorrect because CloudTrail only records API activity for auditing; it does not enforce encryption.

Option D is incorrect because creating a KMS key alone does not apply it to buckets or enforce encryption; the key must be referenced in bucket policies or default encryption settings. Option E is incorrect because denying s3:PutBucketPublicAccessBlock addresses public access blocking, not encryption at rest.

Exam trap

Candidates often mistake SCPs or public access blocking as mechanisms to enforce encryption at rest. However, only default encryption and bucket policies with condition keys like s3:x-amz-server-side-encryption directly enforce encryption at rest.

83
Multi-Selecthard

A company has a VPC with public and private subnets. An EC2 instance in a private subnet needs to download patches from the internet. Which combination of components provides a highly available, managed solution? (Select TWO.)

Select 2 answers
A.Add a route to the private subnet's route table pointing 0.0.0.0/0 to the NAT gateway.
B.Launch a NAT instance in a public subnet.
C.Create a VPC endpoint for Amazon S3.
D.Create a NAT gateway in each Availability Zone.
E.Attach an internet gateway to the VPC.
AnswersA, D

Adding a route to the private subnet's route table with destination 0.0.0.0/0 and target the NAT gateway is the precise mechanism that enables outbound internet access from private instances. The NAT gateway itself resides in a public subnet and relies on its own route to the internet gateway, but private subnets require this explicit route to direct traffic to the NAT gateway. Without this route, private instances have no path to the internet, making this the correct action to satisfy the requirement.

Why this answer

A NAT gateway enables outbound internet access for instances in a private subnet while preventing inbound connections from the internet. It is a managed AWS service that automatically scales and is highly available within a single Availability Zone. By adding a route for 0.0.0.0/0 to the NAT gateway in the private subnet's route table, traffic destined for the internet is forwarded to the NAT gateway, which then uses an internet gateway to reach the internet.

Exam trap

The trap here is that candidates often think a single NAT gateway is sufficient for high availability, but AWS requires one NAT gateway per Availability Zone to survive an AZ failure, and they may also confuse a VPC endpoint for S3 as a general internet access solution.

84
MCQeasy

A company has a VPC with a public subnet and a private subnet. An EC2 instance in the private subnet needs to download patches from the internet. Which AWS service should be used to allow this without assigning a public IP address to the instance?

A.Internet Gateway
B.VPC Endpoint
D.VPN Connection
AnswerC

A NAT Gateway is a fully managed AWS service that enables instances in a private subnet to initiate outbound connections to the internet while preventing unsolicited inbound connections. It sits in a public subnet, uses an Elastic IP for source NAT, and forwards traffic through the Internet Gateway. Because it preserves the flow state, return traffic from the internet is translated back to the private instance, but no external host can directly initiate a session into the private subnet.

Why this answer

A NAT Gateway is the correct service because it allows instances in a private subnet to initiate outbound connections to the internet (e.g., to download patches) while remaining unreachable from the internet and without needing a public IP. The NAT Gateway resides in a public subnet, has an Elastic IP, and performs source NAT (SNAT) on traffic from the private subnet, translating the private source IP to its own public IP. This satisfies the requirement of outbound-only internet access without exposing the instance.

Exam trap

The trap is assuming a VPC Endpoint provides internet access — candidates conflate private connectivity to AWS services with general internet egress, but only a NAT Gateway (or NAT instance) enables outbound internet for private subnets without public IPs.

How to eliminate wrong answers

Option A is wrong because an Internet Gateway provides bidirectional internet connectivity and requires the instance to have a public IP or Elastic IP and a route in a public subnet — it does not enable private-subnet instances to reach the internet without a public IP. Option B is wrong because a VPC Endpoint (Interface or Gateway) provides private connectivity to specific AWS services (e.g., S3, DynamoDB, SSM) over the AWS backbone, not general internet access for downloading patches from arbitrary external repositories. Option D is wrong because a VPN Connection links your on-premises network to the VPC; it does not provide internet egress for private-subnet instances unless you route through on-premises, which is not the intended solution and adds complexity.

85
MCQhard

A company uses AWS Transit Gateway to connect multiple VPCs and on-premises networks. The security team wants to inspect all traffic between VPCs using a third-party firewall appliance. Which architecture should be used?

A.Set up AWS Direct Connect and route all traffic through the on-premises firewall.
B.Use Transit Gateway with appliance mode and route tables to direct traffic through a firewall appliance in a central VPC.
C.Create VPC peering connections between each VPC and the firewall VPC.
D.Configure network ACLs in each VPC to block traffic unless it comes from the firewall.
AnswerB

Transit Gateway with appliance mode enables asymmetric routing support, allowing a gateway route table to forward traffic from source VPCs to the central inspection VPC, while the firewall appliance then routes return traffic back through the same appliance, ensuring both directions are inspected. By using separate route tables associated with each VPC attachment, you can force all inter-VPC and outbound traffic through the firewall appliance, which scales horizontally and keeps security inspection centralized.

Why this answer

Transit Gateway with appliance mode enables the firewall appliance in a central VPC to receive traffic from all attached VPCs with symmetric routing, ensuring that both forward and return traffic flows through the same appliance. By configuring route tables to direct inter-VPC traffic to the firewall appliance's elastic network interface (ENI), the security team can inspect all traffic without requiring complex peering or on-premises backhauling.

Exam trap

The trap here is that candidates may assume VPC peering or network ACLs can achieve transitive traffic inspection, but they fail to recognize that only Transit Gateway with appliance mode provides the necessary symmetric routing and transitive routing capabilities for centralized firewall inspection.

How to eliminate wrong answers

Option A is wrong because routing all traffic through an on-premises firewall via AWS Direct Connect introduces unnecessary latency, bandwidth costs, and dependency on the on-premises network, which is not a native AWS architecture for VPC-to-VPC inspection. Option C is wrong because VPC peering does not support transitive routing; each peering connection is a one-to-one relationship, so traffic between two VPCs would not automatically flow through a third-party firewall VPC unless complex routing and additional appliances are manually configured, making it unscalable. Option D is wrong because network ACLs are stateless and operate at the subnet level, not at the traffic inspection layer; they cannot force traffic through a firewall appliance or provide deep packet inspection, and blocking traffic based on source IP alone is insufficient for security policy enforcement.

86
Multi-Selecthard

A security engineer needs to enable VPC Flow Logs to capture traffic metadata. Which THREE components are required to create a VPC Flow Log?

Select 3 answers
A.A CloudWatch Logs log group to publish the flow logs.
B.A VPC, subnet, or network interface to monitor.
C.An S3 bucket to store the flow logs.
D.An Amazon Kinesis Data Firehose delivery stream.
E.An IAM role that grants permissions to publish logs.
AnswersA, B, E

When the delivery target for VPC Flow Logs is CloudWatch Logs, the log group is the container that receives and stores the published flow log records. It must exist in the same Region as the monitored VPC, and VPC Flow Logs automatically creates a log stream for each elastic network interface. Without this log group (or permission to create it), you cannot complete CloudWatch Logs delivery.

Why this answer

A CloudWatch Logs log group is required because VPC Flow Logs publish traffic metadata to CloudWatch Logs as the default destination. The flow logs are stored as log streams within the specified log group, enabling querying and monitoring via CloudWatch Logs Insights. Without a log group, there is no destination for the flow log records to be sent to.

Exam trap

The trap here is that candidates often assume S3 is mandatory because it is a common storage service, but VPC Flow Logs require either CloudWatch Logs or S3 as a destination, and the question specifies the three required components, making S3 optional and thus incorrect.

87
MCQmedium

A security engineer is designing a network architecture for a web application that must be highly available and secure. The application uses an Application Load Balancer (ALB) in front of EC2 instances. Which architecture meets these requirements?

A.Place both the ALB and EC2 instances in private subnets across two Availability Zones.
B.Place the ALB in private subnets and EC2 instances in public subnets across two Availability Zones.
C.Place the ALB in public subnets and EC2 instances in private subnets across two Availability Zones.
D.Place both the ALB and EC2 instances in public subnets across two Availability Zones.
AnswerC

This is the correct architecture: the internet-facing ALB resides in public subnets, where it has public IP addresses and a route through the internet gateway to accept client traffic, while the EC2 instances are placed in private subnets with no public IPs or direct internet ingress. The ALB terminates HTTP/HTTPS traffic and forwards requests to instances over private IP addresses using target groups; security groups on the instances should only allow traffic from the ALB security group. This design keeps instances isolated from direct internet access while still providing high availability across two Availability Zones.

Why this answer

The correct architecture places the ALB in public subnets so it can receive internet traffic, while EC2 instances reside in private subnets for enhanced security. The ALB acts as a reverse proxy, terminating client connections and forwarding requests to the instances over private IPs, which prevents direct internet access to the instances. Deploying across two Availability Zones ensures high availability by surviving an AZ failure.

Exam trap

The trap here is that candidates often assume both components must be in the same subnet type for simplicity, but the correct design intentionally separates public-facing and private resources to enforce security boundaries.

How to eliminate wrong answers

Option A is wrong because placing both the ALB and EC2 instances in private subnets would block internet traffic from reaching the ALB, making the web application inaccessible from the internet. Option B is wrong because placing EC2 instances in public subnets exposes them directly to the internet, bypassing the security benefits of the ALB and increasing the attack surface. Option D is wrong because placing both the ALB and EC2 instances in public subnets exposes the instances to inbound internet traffic, defeating the purpose of using an ALB for security and potentially violating compliance requirements.

88
Multi-Selectmedium

A company wants to ensure that all Amazon S3 bucket policies comply with a security baseline that prohibits public read access. Which TWO methods can be used to detect non-compliant buckets? (Choose TWO.)

Select 2 answers
A.Enable AWS CloudTrail to monitor GetPublicAccessBlock calls.
B.Use IAM Access Analyzer to review bucket policies for public access.
C.Use Amazon Inspector to scan bucket policies.
D.Use AWS Config with the s3-bucket-public-read-prohibited managed rule.
E.Use AWS Trusted Advisor to check S3 bucket permissions.
AnswersB, D

IAM Access Analyzer is the correct tool here because it uses automated reasoning to analyze resource-based policies, including S3 bucket policies, and generates findings for any policy that grants access to principals outside your AWS account or organization. It specifically flags 'public' access when a bucket policy allows anonymous access (Principal: "*"), and it also surfaces cross-account access with detailed context about the external principal, actions, and resource. This allows you to review every bucket policy systematically and remediate unintended public exposure, making it a comprehensive policy-review solution.

Why this answer

IAM Access Analyzer reviews resource policies to identify resources shared with an external entity. For S3 buckets, it can analyze bucket policies and detect if they grant public read access (i.e., access to 'Principal': '*'). This directly identifies non-compliant buckets against the security baseline that prohibits public read access.

Exam trap

The trap here is that candidates may confuse AWS Trusted Advisor's 'S3 Bucket Permissions' check (which only flags buckets with open ACLs or bucket policies that allow 'Everyone' access) with a comprehensive detection of all public read access, but it does not catch all bucket policy configurations that grant public read access (e.g., via a principal like 'CanonicalUser' or a specific AWS account).

89
MCQmedium

A security engineer needs to ensure that all traffic between two EC2 instances in different subnets is encrypted in transit. What is the most secure and efficient solution?

A.Configure network ACLs to allow traffic
B.Use VPC Peering
C.Set up an IPsec VPN between the instances
D.Configure security groups to allow traffic
AnswerC

An IPsec VPN creates an encrypted tunnel between the configured endpoints (here, the instances), typically using ESP in tunnel or transport mode to encrypt IP payloads and, when needed, the original IP header. It also provides mutual authentication, integrity checking, and anti-replay protection, ensuring all traffic between the instances is confidential and tamper-evident. This is the only option that actively encrypts the traffic itself.

Why this answer

An IPsec VPN between the two EC2 instances provides end-to-end encryption of all traffic at the network layer, regardless of the application protocol. This ensures that data in transit between the instances is encrypted using IPsec (ESP/AH), which is the most secure and efficient solution for encrypting traffic between two specific instances in different subnets without relying on the underlying network infrastructure.

Exam trap

The trap here is that candidates often confuse network-layer connectivity solutions (like VPC Peering or security groups) with encryption mechanisms, assuming that routing traffic through AWS's private network or allowing traffic via security groups inherently encrypts the data, when in fact neither provides encryption in transit.

How to eliminate wrong answers

Option A is wrong because network ACLs are stateless firewall rules that filter traffic based on IP addresses, ports, and protocols, but they do not provide any encryption of traffic in transit. Option B is wrong because VPC Peering connects two VPCs at the network layer using the AWS global network, but it does not encrypt traffic between instances; traffic is routed over the AWS backbone but remains unencrypted unless additional encryption (e.g., IPsec) is applied. Option D is wrong because security groups act as stateful virtual firewalls that control inbound and outbound traffic at the instance level, but they do not encrypt any data; they only permit or deny traffic based on rules.

90
MCQmedium

A company has a web application running on EC2 instances behind an Application Load Balancer (ALB). The application uses a custom header X-Auth-Token to authenticate requests. The security team wants to use AWS WAF to block requests that do not contain this header or contain an invalid token. The WAF is associated with the ALB. The team creates a rule with a match condition that checks for the presence of the X-Auth-Token header and a regex pattern for the token value. However, the rule is not blocking any requests. What is the most likely cause?

A.AWS WAF is not supported for Application Load Balancers; it only supports CloudFront.
B.AWS WAF cannot inspect custom headers; it can only inspect standard HTTP headers.
C.The regex pattern for the token is too complex for AWS WAF to process.
D.There is an allow rule with a higher priority that allows all requests before the block rule is evaluated.
AnswerD

AWS WAF evaluates rules in ascending priority order, where lower numeric priority values are evaluated first. If a higher-priority allow rule (e.g., priority 0) matches all requests and is set to 'Allow', the web ACL immediately stops evaluating remaining rules, so a lower-priority block rule (e.g., priority 1) is never reached. The presence of such a broad allow rule fully explains why requests are not blocked, even when the block rule itself is properly configured.

Why this answer

AWS WAF evaluates rules in priority order, and the first rule that matches determines the action. If an allow rule with a lower number (higher priority) matches all requests, the block rule is never evaluated. Therefore, the most likely cause is that an allow rule with higher priority is permitting all traffic before the block rule can inspect the header.

Exam trap

SCS-C02 often tests the misconception that AWS WAF cannot inspect custom headers or that rule order doesn't matter; candidates must remember that rule priority and action determine whether a block rule is ever reached.

How to eliminate wrong answers

Option A is wrong because AWS WAF is supported on Application Load Balancers, not just CloudFront. Option B is wrong because AWS WAF can inspect custom headers; it supports all HTTP headers including custom ones. Option C is wrong because AWS WAF regex patterns have limits but complexity is rarely the cause of no blocking; the service would return an error if the pattern were invalid.

91
MCQmedium

A security engineer needs to ensure that an Amazon S3 bucket blocks all public access. Which S3 block public access settings should be enabled?

A.Block public access to buckets and objects granted through new public bucket policies
B.Block public access to buckets and objects granted through new access control lists (ACLs)
C.Block public access to buckets and objects granted through any access control lists (ACLs)
D.Block all public access
AnswerD

This option enables all four S3 Block Public Access settings: BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, and RestrictPublicBuckets. BlockPublicAcls stops new public ACLs, IgnorePublicAcls causes existing public ACLs to be disregarded, BlockPublicPolicy prevents adding new public bucket policies, and RestrictPublicBuckets limits how existing public policies are used. Together they close both ACL-based and bucket-policy-based pathways for anonymous or public access, making this the correct choice to ensure the bucket is not publicly accessible.

Why this answer

The 'Block all public access' setting in Amazon S3 is a single toggle that simultaneously enables all four individual block public access settings, ensuring that no public access is allowed through any mechanism—bucket policies, ACLs, or otherwise. This is the only setting that comprehensively blocks all public access to the S3 bucket and its objects, as required by the security engineer's goal.

Exam trap

The trap here is that candidates may think enabling individual settings (like blocking new bucket policies or new ACLs) is sufficient, but they overlook that existing policies or ACLs could still allow public access, and only 'Block all public access' guarantees complete closure of all public access vectors.

How to eliminate wrong answers

Option A is wrong because it only blocks public access granted through new public bucket policies, leaving existing policies and ACLs (both new and existing) as potential vectors for public access. Option B is wrong because it only blocks public access granted through new ACLs, while existing ACLs and bucket policies could still allow public access. Option C is wrong because it blocks public access through any ACLs (both new and existing) but does not block public access granted through bucket policies, which is a separate and common mechanism for granting public access.

92
MCQmedium

A company has a VPC with a CIDR block of 10.0.0.0/16. The company wants to connect this VPC to an on-premises network that uses the CIDR block 10.0.0.0/8. The company has set up an AWS Site-to-Site VPN connection. After configuration, the on-premises network cannot reach resources in the VPC, and the VPC cannot reach on-premises resources. What is the most likely cause of the connectivity issue?

A.The VPC route table does not have a route for the on-premises CIDR block pointing to the virtual private gateway.
B.The security group attached to the VPC resources does not allow traffic from the on-premises CIDR block.
C.The VPN connection is using dynamic routing (BGP) instead of static routing, which is required for overlapping CIDRs.
D.The on-premises network CIDR block overlaps with the VPC CIDR block, causing routing conflicts.
AnswerD

The on-premises network uses 10.0.0.0/8, which includes the VPC CIDR 10.0.0.0/16. This overlap creates conflicting routes: traffic destined for 10.0.0.0/16 could be routed locally within the VPC or to the VPN, causing ambiguity and failure. Overlapping CIDRs are a common cause of hybrid connectivity issues and must be resolved by re-addressing one side.

Why this answer

The on-premises network CIDR 10.0.0.0/8 overlaps with the VPC CIDR 10.0.0.0/16. This overlap causes routing conflicts because the same IP range exists on both sides of the VPN. Traffic cannot be correctly routed, leading to connectivity failure.

The solution is to re-address either the VPC or the on-premises network to eliminate the overlap.

Exam trap

The trap here is assuming that a missing route or security group rule is the cause, when the fundamental issue is overlapping CIDR blocks that make routing impossible.

93
MCQeasy

A company wants to allow a user to assume a role in another AWS account to access resources. Which AWS service should be used to create and manage the trust relationship between the accounts?

A.IAM roles with a trust policy that allows the external account.
B.AWS Security Token Service (STS) to generate tokens.
C.IAM users in the source account with cross-account permissions.
D.AWS Organizations service control policies.
AnswerA

IAM roles are the native AWS mechanism for cross-account access: the role's trust policy explicitly names the external account (or its users/roles) as a principal, and the permission policy grants the specific actions the role can perform. When the external user assumes the role, AWS verifies that the trust policy allows the request and then issues temporary credentials scoped to the role's permissions, making this the correct and secure way to enable the cross-account assumption.

Why this answer

IAM roles with a trust policy that explicitly allows the external AWS account to assume the role is the correct mechanism for establishing a cross-account trust relationship. The trust policy defines which principal (the external account) is allowed to assume the role, and the permissions policy attached to the role controls what actions the assumed role can perform. This is the foundational AWS service for delegating access across accounts.

Exam trap

The trap here is that candidates confuse the mechanism for establishing trust (IAM role trust policy) with the mechanism for obtaining credentials (STS), leading them to select STS as the answer despite it being a downstream step.

How to eliminate wrong answers

Option B is wrong because AWS Security Token Service (STS) is used to generate temporary security credentials (tokens) after a trust relationship is established, not to create or manage the trust relationship itself. Option C is wrong because IAM users are identities within a single account; granting cross-account permissions to an IAM user would require creating a role in the target account and allowing the user to assume it, not directly managing the trust relationship. Option D is wrong because AWS Organizations service control policies (SCPs) are used to centrally manage permissions across accounts in an organization, but they do not create or manage trust relationships for role assumption between accounts.

94
MCQeasy

A company wants to restrict access to an Amazon S3 bucket so that only users from a specific AWS account can upload objects. Which policy mechanism should be used?

A.Create a bucket policy with a condition that checks the aws:SourceAccount condition key.
B.Attach an IAM policy to the bucket that denies access to all users except those from the allowed account.
C.Generate a pre-signed URL for each upload request.
D.Configure the bucket ACL to grant access only to the allowed account's canonical user ID.
AnswerA

A bucket policy with an aws:SourceAccount condition key evaluates the account ID of the IAM principal that signs the request and is enforced by S3 when the bucket is accessed. This condition is evaluated against the requester's account number, allowing you to allow or deny access based on that account without specifying individual user ARNs. It is the recommended approach because it uses a resource-based policy that directly supports condition keys, and it ensures all requests from unintended accounts are rejected.

Why this answer

A bucket policy with the `aws:SourceAccount` condition key allows you to restrict access to a specific AWS account. When users from the allowed account upload objects, the condition evaluates the source account ID, ensuring only requests originating from that account are permitted. This is the recommended approach for cross-account access control in S3, as it directly enforces the account-level restriction at the bucket policy level.

Exam trap

The trap here is that candidates confuse IAM policies with resource-based policies, thinking an IAM policy can be attached to an S3 bucket, or they mistakenly believe bucket ACLs or pre-signed URLs can enforce account-level restrictions.

How to eliminate wrong answers

Option B is wrong because IAM policies are attached to IAM users, groups, or roles, not directly to S3 buckets; you cannot attach an IAM policy to a bucket. Option C is wrong because pre-signed URLs grant temporary access to specific objects for any user with the URL, regardless of AWS account, and do not restrict uploads to a specific account. Option D is wrong because bucket ACLs are legacy and do not support account-level restrictions based on AWS account IDs; they use canonical user IDs, which are not the same as AWS account IDs and are less flexible for cross-account control.

95
MCQmedium

A security engineer sees the above security group configuration for an EC2 instance. The instance hosts a web application that should only be accessible from the internal network (10.0.0.0/8) over HTTPS, and SSH should not be open to the internet. What is the security issue with this configuration?

A.The outbound rule allows all traffic to all destinations.
B.The inbound HTTPS rule is too permissive.
C.The inbound SSH rule is too permissive.
D.There is no security issue; the configuration is correct.
AnswerA

The outbound rule is defined as allowing all traffic to 0.0.0.0/0, meaning any instance associated with this security group can initiate connections to any IP address on any port. This violates the principle of least privilege because if an attacker compromises the instance, they could use it as a pivot to exfiltrate sensitive data or launch outbound attacks. Even though inbound HTTPS may also be overly broad, the outbound any-any rule is a critical misconfiguration because it provides no egress filtering or restrictions to required services.

Why this answer

The outbound rule allowing all traffic to all destinations (0.0.0.0/0) violates the principle of least privilege. While the inbound rules restrict HTTPS to the internal network (10.0.0.0/8) and SSH is not open to the internet, the outbound rule permits any instance in the security group to initiate connections to any IP address and port, including malicious external hosts. This could allow data exfiltration or outbound attacks, which is a security issue even if inbound access is properly restricted.

Exam trap

The trap here is that candidates focus solely on inbound rules (HTTPS and SSH) and overlook the outbound rule, assuming that stateful security groups automatically handle outbound traffic safely, but AWS explicitly tests that outbound rules must also be restricted to follow least privilege.

How to eliminate wrong answers

Option B is wrong because the inbound HTTPS rule is correctly scoped to the internal network (10.0.0.0/8), which aligns with the requirement that the web application should only be accessible from the internal network. Option C is wrong because the inbound SSH rule is not open to the internet (0.0.0.0/0) in the provided configuration; it is restricted to the internal network (10.0.0.0/8), so it is not too permissive. Option D is wrong because the outbound rule is overly permissive, creating a security risk that makes the configuration incorrect.

96
Multi-Selecteasy

Which TWO AWS services are designed to provide DDoS protection? (Choose 2.)

Select 2 answers
A.VPC Flow Logs
B.AWS CloudTrail
C.AWS Config
D.AWS WAF
E.AWS Shield Standard
AnswersD, E

AWS WAF is a web application firewall that protects at Layer 7 by inspecting HTTP(S) requests and filtering malicious traffic before it reaches your application. You can use rate-based rules to limit the number of requests from a given IP address, block known attacker IP sets, and mitigate HTTP floods, SQL injection, or cross-site scripting attempts. This directly addresses application-layer DDoS attacks, which consume application resources by sending large volumes of web requests, and it is a core component for ongoing protection of web-facing workloads.

Why this answer

AWS WAF (Option D) is a web application firewall that helps protect web applications from common web exploits that could affect application availability, compromise security, or consume excessive resources. It integrates with Amazon CloudFront, Application Load Balancer, and API Gateway to filter and monitor HTTP(S) requests, providing protection against layer 7 DDoS attacks such as SQL injection and cross-site scripting.

Exam trap

The trap here is that candidates may confuse monitoring or auditing services (VPC Flow Logs, CloudTrail, Config) with active security controls, but only AWS Shield and AWS WAF provide direct DDoS mitigation capabilities.

97
Multi-Selectmedium

A security engineer is designing a VPC with public and private subnets. The private subnets will host databases that should not have direct internet access. Which three components are required to provide outbound internet access for these databases? (Choose THREE.)

Select 3 answers
A.AWS WAF attached to the NAT gateway.
B.An internet gateway attached to the VPC.
C.Route tables in the private subnets with a default route (0.0.0.0/0) pointing to the NAT gateway.
D.A VPC gateway endpoint for S3.
E.A NAT gateway in a public subnet.
AnswersB, C, E

The internet gateway provides the VPC's path to the internet and is required for the NAT gateway to reach external destinations. Without it attached to the VPC, the NAT gateway cannot forward private-subnet traffic outbound, so the stem's outbound access fails.

Why this answer

Option B is correct because an internet gateway (IGW) attached to the VPC is the fundamental component that enables any communication between the VPC and the internet; the NAT gateway itself requires an IGW to forward traffic outbound. Option E is correct because a NAT gateway must be deployed in a public subnet (one whose route table points to the IGW) so it can translate private subnet traffic to the internet while preventing inbound connections to the databases. Option C is correct because the private subnet route tables must contain a default route (0.0.0.0/0) targeting the NAT gateway, which is how the databases' outbound packets are directed to the NAT for translation.

Option A is not required because AWS WAF is a layer 7 web application firewall that protects web applications and does not enable or provide outbound internet access. Option D is not required because a VPC gateway endpoint for S3 only provides private connectivity to Amazon S3 and does not provide general outbound internet access.

Exam trap

The trap here is that candidates often think a NAT gateway alone provides internet access, forgetting that the NAT gateway must be placed in a public subnet with a route to an internet gateway, and that the private subnet’s default route must point to the NAT gateway, not the IGW.

98
MCQmedium

A company uses AWS CloudFormation to deploy infrastructure. A security requirement states that no security group should allow inbound SSH access from 0.0.0.0/0. What is the best way to enforce this policy?

A.Create an IAM policy that denies the ec2:AuthorizeSecurityGroupIngress action if the CIDR is 0.0.0.0/0.
B.Use AWS Config with a managed rule to detect and automatically remediate non-compliant security groups.
C.Add an AWS::IAM::Policy resource in the CloudFormation template to deny the rule.
D.Use a service control policy (SCP) that denies the CreateStack action if the template contains SSH from 0.0.0.0/0.
AnswerB

AWS Config can continuously monitor security group configurations using the managed rule 'vpc-sg-open-only-to-authorized-ports', which flags security groups that allow unrestricted inbound access. When the rule detects a non-compliant security group, you can attach an automatic remediation action using an AWS Systems Manager Automation document such as AWS-RevokeSecurityGroupIngress. This removes the offending SSH 0.0.0.0/0 rule without requiring manual intervention, and AWS Config tracks compliance status in the dashboard.

Why this answer

AWS Config with a managed rule (e.g., 'restricted-ssh') can continuously evaluate security group configurations against the policy and automatically remediate non-compliant rules using AWS Systems Manager Automation. This provides detective and corrective enforcement without blocking legitimate administrative actions, unlike IAM or SCP approaches that would prevent necessary changes or fail to detect existing non-compliant resources.

Exam trap

The trap here is that candidates often choose an IAM-based deny policy (Option A) thinking it prevents the action entirely, but they overlook that AWS Config with remediation is the only option that both detects and automatically fixes existing non-compliant security groups, which is the core requirement of 'enforcing' the policy.

How to eliminate wrong answers

Option A is wrong because denying ec2:AuthorizeSecurityGroupIngress only prevents new inbound SSH rules from being added but does not detect or remediate existing non-compliant security groups that were created before the policy was applied. Option C is wrong because adding an AWS::IAM::Policy resource inside a CloudFormation template only affects the stack's execution role and cannot retroactively enforce rules on security groups already deployed or created outside that template. Option D is wrong because an SCP denying CreateStack based on template content cannot inspect the actual security group rules after stack creation, and it would block all stack creation attempts even if the SSH rule is later removed or modified.

99
MCQhard

A company uses AWS Organizations to manage multiple accounts. The security team must enforce that all Amazon S3 buckets across all accounts are encrypted with AWS KMS. The team has enabled S3 default encryption for new buckets, but existing buckets may not be encrypted. They need to automatically remediate any non-compliant buckets. The team has AWS Config and AWS Lambda available. What is the MOST operationally efficient solution?

A.Manually review all buckets using the S3 console and enable encryption for those that are not encrypted.
B.Write a script that runs daily on an EC2 instance to list all buckets and enable encryption on any that are not encrypted.
C.Use AWS Config with the s3-bucket-server-side-encryption-enabled rule and configure an AWS Systems Manager Automation document to remediate non-compliant buckets.
D.Use AWS Trusted Advisor to check for unencrypted buckets and send an SNS notification to the security team to manually remediate.
AnswerC

AWS Config continuously evaluates each S3 bucket against the s3-bucket-server-side-encryption-enabled managed rule and, upon detecting non-compliance, can immediately trigger an AWS Systems Manager Automation document to apply default encryption automatically. This creates a closed-loop, serverless remediation pipeline that is real-time, fully audited (via Config compliance history and SSM Automation execution logs), and scalable across accounts through Organization-level conformance packs. It is the only option that provides both continuous detection and automatic remediation without manual effort or infrastructure management.

Why this answer

Use AWS Config with the s3-bucket-server-side-encryption-enabled rule to detect non-compliant S3 buckets. Then configure an automatic remediation action using an AWS Systems Manager Automation document to enable encryption on those buckets. This approach is serverless, automated, and operationally efficient as it does not require manual intervention or separate compute resources.

100
MCQhard

A security engineer is reviewing the following IAM policy attached to an S3 bucket: { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": "*", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::example-bucket/*", "Condition": { "IpAddress": { "aws:SourceIp": "10.0.0.0/8" } } } ] } The bucket contains sensitive data and should only be accessible from the corporate network (CIDR 10.0.0.0/8). However, the engineer is concerned that this policy might not be effective. What is the primary security concern with this policy?

A.The bucket policy does not include a Deny statement for requests outside the IP range, so the default allow might still permit access from other IPs.
B.The policy grants public access to the bucket because the Principal is "*", allowing anyone from the specified IP range to access objects.
C.The condition key aws:SourceIp only evaluates the IP address of the client, but if the request comes through a proxy, the IP might not match.
D.The policy uses s3:GetObject but does not include s3:ListBucket, so users cannot see the object list, but they can guess object keys.
AnswerB

The policy sets Principal to '*' in a bucket policy, which means every principal—including unauthenticated anonymous users—is included in the scope of the statement. The condition on aws:SourceIp narrows the network source to a specific IP CIDR, but it does not require any AWS credentials, identity, or account relationship. As a result, any person or service whose traffic originates from that IP range can read objects in the bucket, making the bucket effectively public to that entire network.

Why this answer

The bucket policy uses `"Principal": "*"` combined with `"Effect": "Allow"`, which explicitly grants public access to anyone who meets the condition. While the condition restricts access to the `10.0.0.0/8` IP range, the policy itself is still a public bucket policy — it allows any authenticated or unauthenticated user from that IP range to read objects. This violates the principle of least privilege and exposes sensitive data to any user on the corporate network, not just authorized IAM roles or users.

Exam trap

The trap here is that candidates focus on the IP restriction condition and assume it makes the policy secure, overlooking the fact that `"Principal": "*"` still makes the bucket publicly accessible to any user within that IP range, which is a direct violation of AWS shared responsibility and least privilege principles.

How to eliminate wrong answers

Option A is wrong because the default behavior of IAM and S3 bucket policies is to deny all access unless explicitly allowed; there is no 'default allow' that would permit requests outside the IP range — the policy simply does not grant access to IPs outside `10.0.0.0/8`, so they are implicitly denied. Option C is wrong because the `aws:SourceIp` condition key correctly evaluates the source IP of the request, and while proxies can alter the perceived IP, the condition still works as intended for direct requests; the concern about proxy IPs is a valid operational consideration but not the primary security flaw of this policy. Option D is wrong because the lack of `s3:ListBucket` does not create a security vulnerability — it only prevents listing objects, which is a separate access control concern, and the policy's primary issue is granting public access to sensitive data.

101
Multi-Selecthard

A company is migrating a legacy application to AWS. The application requires two-way communication between the web servers and the database servers using TCP port 3306. The security team wants to follow the principle of least privilege. Which TWO actions should be taken to secure the traffic?

Select 2 answers
A.Create a security group for the web servers that allows outbound traffic on port 3306 to the database security group.
B.Create a security group for the database servers that allows inbound traffic on port 3306 from the web subnet CIDR.
C.Place the database servers in a public subnet for easier connectivity.
D.Configure the network ACL for the database subnet to allow inbound traffic on port 3306 from the web subnet CIDR.
E.Create a security group for the database servers that allows inbound traffic on port 3306 from the web security group ID.
AnswersA, E

This is correct because security groups are stateful: when the web server initiates a TCP connection to the database on port 3306, the corresponding return traffic is automatically allowed back into the web server without an explicit inbound rule. By setting the destination to the database security group ID rather than an IP range, the rule dynamically applies to every instance currently associated with that security group, which simplifies management if the database fleet scales or changes. This outbound rule scopes traffic to the specific database tier and avoids opening port 3306 to the whole VPC.

Why this answer

Security groups are stateful, so allowing outbound traffic on port 3306 from the web servers to the database security group automatically permits the corresponding return traffic. This adheres to the principle of least privilege by specifying the destination as the database security group ID rather than a broad CIDR range, ensuring only the intended web servers can initiate the connection.

Exam trap

The trap here is that candidates often confuse security groups (stateful, instance-level) with network ACLs (stateless, subnet-level) and incorrectly assume that a subnet CIDR-based rule in a security group is equivalent to using a security group ID, when in fact the latter provides stricter least-privilege control by limiting access to only the specific instances in the web security group.

102
MCQhard

A company has a VPC with public and private subnets. The private sub host Amazon RDS instances. To allow the RDS instances to access the internet for software updates without exposing them to inbound internet traffic, what should be configured?

A.Use a VPN connection to an on-premises network that has internet access.
B.Set up a VPC peering connection to a VPC with internet access.
C.Create a NAT gateway in a public subnet and add a route to the NAT gateway in the private subnet route table.
D.Attach an internet gateway to the private subnet route table.
AnswerC

A NAT gateway deployed in a public subnet with an associated elastic IP provides outbound internet connectivity for instances in private subnets. You must add a default route (0.0.0.0/0) in the private subnet's route table pointing to the NAT gateway's interface or ID, ensuring instances can initiate outbound connections while remaining inaccessible from the internet.

Why this answer

A NAT gateway in a public subnet allows instances in private subnets to initiate outbound traffic to the internet (e.g., for software updates) while preventing any unsolicited inbound connections from the internet. Adding a route in the private subnet's route table that points 0.0.0.0/0 to the NAT gateway enables this outbound-only internet access for the RDS instances.

Exam trap

The trap here is that candidates often confuse a NAT gateway with an internet gateway, mistakenly thinking an internet gateway can be attached to a private subnet, or they overlook that a NAT gateway must be placed in a public subnet with an internet gateway attached to that subnet's route table to function correctly.

How to eliminate wrong answers

Option A is wrong because a VPN connection to an on-premises network with internet access would route traffic through the on-premises network, adding latency and complexity, and is not the standard AWS solution for outbound-only internet access from private subnets. Option B is wrong because VPC peering does not provide internet access; it only enables private connectivity between VPCs, and the peered VPC would need its own internet gateway and NAT gateway to provide internet access, making this an indirect and unnecessarily complex solution. Option D is wrong because attaching an internet gateway to a private subnet route table would expose the RDS instances to inbound internet traffic, violating the requirement to prevent inbound exposure, and internet gateways are designed for public subnets, not private ones.

103
MCQeasy

A company wants to restrict access to an S3 bucket so that only traffic from a specific VPC can read objects. Which security mechanism should be used?

A.Use an S3 bucket policy with a condition that restricts access to the VPC endpoint ID.
B.Assign an IAM role to the S3 bucket.
C.Attach a security group to the S3 bucket.
D.Configure a network ACL on the VPC subnet to allow traffic to S3.
AnswerA

A bucket policy can use the aws:SourceVpce condition key to restrict access to a specific VPC endpoint. This allows only traffic that arrives through the corresponding gateway or interface endpoint to reach the bucket, while all other sources, including the public internet, are denied. This resource-based control is the correct way to enforce VPC-only access to an S3 bucket.

Why this answer

An S3 bucket policy can include a condition that restricts access to traffic originating from a specific VPC endpoint. By using the `aws:SourceVpce` condition key, the policy ensures that only requests coming through the specified VPC endpoint (interface or gateway) are allowed to read objects, effectively locking down access to the VPC.

Exam trap

The trap here is that candidates often confuse network-level controls (security groups, NACLs) with resource-based policies, mistakenly thinking they can apply security groups or NACLs to S3 buckets, when in fact S3 only supports bucket policies and IAM policies for access control.

How to eliminate wrong answers

Option B is wrong because IAM roles are assigned to principals (users, services) to grant permissions, not to S3 buckets; buckets themselves cannot assume roles. Option C is wrong because security groups are network-level firewalls for EC2 instances and other AWS resources, but S3 buckets are not network interfaces and cannot have security groups attached. Option D is wrong because network ACLs control traffic at the subnet level and cannot restrict access to a specific S3 bucket; they also cannot enforce bucket-level conditions like VPC endpoint IDs.

104
MCQeasy

A security engineer needs to ensure that all data stored in an Amazon S3 bucket is encrypted at rest. The bucket must use server-side encryption with a key managed by the customer (SSE-C). What must the engineer include in the PUT request to enforce this?

A.x-amz-server-side-encryption-customer-algorithm and x-amz-server-side-encryption-customer-key
B.x-amz-server-side-encryption: AES256
C.x-amz-server-side-encryption: aws:kms
D.x-amz-server-side-encryption-bucket-key-enabled: true
AnswerA

These two headers are mandatory for SSE-C, where the customer supplies the raw 256-bit AES key in each request rather than letting AWS hold key material. x-amz-server-side-encryption-customer-algorithm must be set to AES256, and x-amz-server-side-encryption-customer-key must contain the base64-encoded key, typically accompanied by x-amz-server-side-encryption-customer-key-MD5 to verify integrity. AWS discards the key after encrypting the object and stores only a salted HMAC for later validation, so you must re-supply these headers on every PUT, GET, HEAD, or range read.

Why this answer

SSE-C requires the client to provide both the encryption algorithm and the encryption key in the PUT request headers. The `x-amz-server-side-encryption-customer-algorithm` header must be set to `AES256`, and the `x-amz-server-side-encryption-customer-key` header must contain the base64-encoded 256-bit key. Without these headers, S3 will not apply customer-provided encryption keys, and the object will not be encrypted with SSE-C.

Exam trap

The trap here is that candidates confuse the `x-amz-server-side-encryption` header (used for SSE-S3 and SSE-KMS) with the SSE-C-specific headers, leading them to pick Option B or C, which do not allow customer-provided keys.

How to eliminate wrong answers

Option B is wrong because `x-amz-server-side-encryption: AES256` specifies SSE-S3, where AWS manages the key, not the customer. Option C is wrong because `x-amz-server-side-encryption: aws:kms` specifies SSE-KMS, which uses AWS KMS keys, not customer-provided keys. Option D is wrong because `x-amz-server-side-encryption-bucket-key-enabled: true` enables S3 Bucket Keys for SSE-KMS, reducing KMS API calls, but does not enforce SSE-C or provide customer-managed keys.

105
MCQmedium

A security engineer is tasked with implementing network segmentation for a multi-tier application. The web tier must be accessible from the internet, but the application tier must only be accessible from the web tier. The database tier must only be accessible from the application tier. All tiers are in the same VPC. Which design meets these requirements?

A.Create a security group for each tier. Configure inbound rules to allow traffic only from the preceding tier's security group.
B.Use a single security group for all instances and use IAM policies to restrict access.
C.Place each tier in separate subnets and use network ACLs with CIDR blocks to allow traffic between tiers.
D.Place all instances in public subnets and restrict access using security groups.
AnswerA

Security group chaining gives tier-specific, stateful filtering without hard-coding IP addresses. Define a separate security group for the web, app, and database tiers, then set inbound rules on the app SG that allow traffic from the web SG (on the app port) and on the database SG that allow traffic from the app SG. Because the source is an SG ID, any instance associated with the preceding tier automatically has access, and newly launched instances in that tier are included without updating CIDR rules. This enforces least-privilege east-west traffic isolation.

Why this answer

Security groups can reference other security groups as sources in inbound rules, allowing granular traffic control between tiers without CIDR blocks. This approach allows the web tier security group to allow inbound from the internet, the app tier security group to allow inbound only from the web tier security group, and the database tier security group to allow inbound only from the app tier security group. Option B is incorrect because IAM policies control user permissions, not network traffic.

Option C is incorrect because network ACLs with CIDR blocks are less specific and do not scale well, and placing tiers in separate subnets is not necessary. Option D is incorrect because placing all instances in public subnets unnecessarily exposes them to the internet, increasing security risk.

106
MCQhard

A company wants to deploy a web application that must be accessible over HTTPS only. The application runs behind an Application Load Balancer (ALB). The security team wants to enforce HTTP Strict Transport Security (HSTS) to prevent downgrade attacks. Which configuration achieves this?

A.Use AWS CloudFront with a custom header that enforces HSTS
B.Configure the ALB to redirect HTTP traffic to HTTPS and have the application set the Strict-Transport-Security header in the response
C.Configure the ALB listener to use HTTPS only and set a custom header via a listener rule
D.Enable HSTS on the ALB via the AWS Management Console
AnswerB

This is the correct architecture because it separates transport security into two complementary layers: the ALB listener uses a redirect action to convert any plain HTTP request to HTTPS, forcing TLS for every attempt, and the application returns the Strict-Transport-Security header in its response, which instructs browsers to automatically use HTTPS for the domain for the specified duration. ALB does not natively generate HSTS headers, so the application must supply it after a successful TLS connection. This satisfies both the immediate encryption requirement and the long-term HSTS enforcement.

Why this answer

HSTS is enforced by the web application sending the `Strict-Transport-Security` header in HTTPS responses. By configuring the ALB to redirect HTTP to HTTPS, all traffic is forced over TLS, and the application can then set the HSTS header to instruct browsers to always use HTTPS for future requests. The ALB itself does not natively set HSTS headers; this must be done at the application layer.

Exam trap

The trap here is that candidates assume HSTS can be configured directly on the ALB (like a security policy or listener rule), when in fact it must be implemented at the application layer by setting the response header, and the ALB only handles traffic redirection.

How to eliminate wrong answers

Option A is wrong because AWS CloudFront can forward or add custom headers, but it does not natively enforce HSTS; the `Strict-Transport-Security` header must still be set by the origin (the application) or via a CloudFront Function/Lambda@Edge, and simply using a custom header does not implement HSTS correctly. Option C is wrong because ALB listener rules can only modify or insert headers for requests, not for responses; HSTS requires the header to be present in the HTTP response from the target, not in the request. Option D is wrong because the ALB does not have a built-in HSTS feature or setting in the AWS Management Console; HSTS is an application-layer header and cannot be enabled directly on the load balancer.

107
MCQeasy

A company is using AWS WAF to protect its Application Load Balancer (ALB). The security team wants to block requests that do not contain a valid API key in the HTTP header 'X-API-Key'. Which WAF rule type should be used?

A.String match condition
B.Regex pattern set
C.Rate-based rule
D.IP set
AnswerB

A regex pattern set lets you define a regular expression that describes the structural format of valid API keys, such as a required prefix followed by a specific number of alphanumeric characters. In a WAF rule, you can use the 'not' operator to inspect the API key header and block any request whose key does not match this pattern, providing centralized pattern-based validation at the edge. This directly addresses the requirement to reject invalid API keys.

Why this answer

A regex pattern set rule is the correct choice because it allows you to define a regular expression pattern that matches the expected format of valid API keys in the 'X-API-Key' header. AWS WAF regex pattern sets can be used in a rule to inspect the header value and block requests that do not match the pattern, providing flexible and precise validation beyond simple string matching.

Exam trap

The trap here is that candidates often confuse string match conditions with regex pattern sets, assuming that a simple 'contains' or 'starts with' string match is sufficient for validating structured data like API keys, when in fact regex provides the necessary pattern flexibility.

How to eliminate wrong answers

Option A is wrong because a string match condition can only check for exact or substring matches, not complex patterns like varying alphanumeric formats or specific character sequences typical of API keys. Option C is wrong because a rate-based rule is designed to block IPs based on request rate thresholds, not to inspect header content for a valid API key. Option D is wrong because an IP set rule blocks or allows traffic based on source IP addresses, not on the presence or validity of an API key in a header.

108
MCQhard

A financial services company runs a critical application on Amazon EC2 instances in a VPC. The application processes sensitive financial data and must meet strict compliance requirements. The security team recently discovered that an EC2 instance was compromised due to an unpatched vulnerability. The attacker used the instance's IAM role to access an S3 bucket containing customer data and exfiltrated the data. The security team needs to prevent such incidents in the future. They have implemented the following controls: - All EC2 instances are launched in private subnets. - The IAM roles used by EC2 instances follow the principle of least privilege. - Security groups restrict inbound and outbound traffic. - AWS Systems Manager Patch Manager is used to patch instances. - AWS CloudTrail is enabled and logs are sent to a centralized S3 bucket. - Amazon GuardDuty is enabled. Despite these controls, the team is concerned about the blast radius if an instance is compromised again. Which additional measure would MOST effectively limit the blast radius of a compromised EC2 instance?

A.Enable VPC Flow Logs to monitor traffic to S3.
B.Use S3 VPC Endpoints with a bucket policy that only allows access from the VPC endpoint, and use Systems Manager Session Manager instead of SSH.
C.Deploy AWS WAF in front of the S3 bucket.
D.Create an AWS Config rule to detect S3 access from EC2 instances.
AnswerB

Creating an S3 VPC endpoint and attaching a bucket policy that denies all access unless the request originates from that endpoint confines S3 traffic to the AWS internal network, removing exposure to the public internet. This, combined with replacing SSH with AWS Systems Manager Session Manager, eliminates inbound SSH ports and relies on IAM-based, auditable session access instead of static keys. Together, these controls shrink the attack surface and provide preventive, policy-enforced protection against both network-level exfiltration and credential compromise.

Why this answer

Using an S3 VPC endpoint with a bucket policy that restricts access exclusively to that endpoint ensures that compromised EC2 instances can only reach S3 through the VPC endpoint, preventing data exfiltration over the internet. Additionally, replacing SSH with Systems Manager Session Manager eliminates the need for open inbound SSH ports and provides fine-grained access control through IAM, reducing the attack surface and blast radius.

Exam trap

The trap here is that candidates may choose VPC Flow Logs (Option A) thinking it provides active protection, but it is only a monitoring tool that does not reduce the blast radius; the key is to implement network-level and access-level restrictions that prevent data exfiltration even if an instance is compromised.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs only provide visibility into traffic patterns and do not actively limit the blast radius or prevent data exfiltration. Option C is wrong because AWS WAF is a web application firewall designed to protect web-facing resources like ALB or CloudFront, not S3 buckets directly; it cannot restrict access from EC2 instances to S3. Option D is wrong because an AWS Config rule is a detective control that can detect non-compliant access after it occurs, but it does not proactively limit the blast radius or prevent exfiltration in real time.

109
MCQmedium

A company has a security group that allows inbound SSH from 0.0.0.0/0. The security team wants to restrict access to only the company's public IP range 203.0.113.0/24. What change should be made?

A.Add a network ACL rule to deny SSH from 0.0.0.0/0.
B.Modify the inbound SSH rule in the security group to source 203.0.113.0/24.
C.Add a network ACL rule to allow SSH from 203.0.113.0/24.
D.Remove the inbound SSH rule from the security group.
AnswerB

Modifying the inbound SSH rule's source from 0.0.0.0/0 to 203.0.113.0/24 is the precise fix because security groups are stateful and support only allow rules. Every IP outside that CIDR will be implicitly denied by the security group's default-deny behavior, while the company's addresses remain permitted. This change directly aligns the security group with the requirement and requires no extra outbound rule because stateful filtering automatically allows the return traffic.

Why this answer

Security groups are stateful and act as a virtual firewall for instances. To restrict inbound SSH access from 0.0.0.0/0 to only the company's public IP range, you must modify the existing inbound rule's source CIDR from 0.0.0.0/0 to 203.0.113.0/24. This change directly updates the allowed source IP range, and since security groups evaluate all rules before making a decision, the more specific allowed range will take effect without needing additional rules.

Exam trap

The trap here is that candidates often confuse the stateless behavior of network ACLs with the stateful behavior of security groups, leading them to incorrectly believe that adding a deny rule in a network ACL can override a security group's allow rule for the same traffic.

How to eliminate wrong answers

Option A is wrong because network ACLs are stateless and operate at the subnet level, not at the instance level; adding a deny rule in a network ACL would not override the security group's allow rule for SSH, and it would also require an explicit allow rule for return traffic due to statelessness. Option C is wrong because adding a network ACL rule to allow SSH from 203.0.113.0/24 does not change the security group's existing inbound SSH rule that allows 0.0.0.0/0, so SSH from any IP would still be permitted by the security group. Option D is wrong because removing the inbound SSH rule entirely would block all SSH access, including from the company's intended IP range, which is not the desired outcome.

110
Multi-Selectmedium

A security engineer is designing a secure VPC architecture. Which THREE components should be used to implement defense in depth? (Choose three.)

Select 3 answers
A.VPN connection
B.Internet gateway
C.Security groups
D.Network ACLs
E.VPC Flow Logs
AnswersC, D, E

Instance-level firewall.

Why this answer

Security groups (C) are stateful virtual firewalls that control inbound and outbound traffic at the instance level. They operate at the network interface (ENI) level, allowing only explicitly permitted traffic and automatically allowing return traffic for permitted sessions. This provides a critical layer of host-level defense within the VPC.

Exam trap

The trap here is that candidates often confuse connectivity components (VPN, Internet gateway) with security controls, or they overlook that VPC Flow Logs are a detective control (not preventive) but still a valid part of defense in depth, leading them to select A or B instead of the correct trio of security groups, network ACLs, and VPC Flow Logs.

111
MCQmedium

A company has an AWS Direct Connect connection to its on-premises data center. The security team wants to ensure that traffic between the VPC and the data center is encrypted. Which solution should they use?

A.Set up an IPsec VPN connection over the Direct Connect virtual interface.
B.Enable encryption on the Direct Connect virtual interface.
C.Use AWS Site-to-Site VPN over the internet.
D.Use VPC Peering to connect the VPC to the data center.
AnswerA

A Direct Connect virtual interface provides a dedicated, low-latency network path, but it does not encrypt traffic on its own. By configuring an IPsec VPN session over that virtual interface, you can encapsulate all packets in an encrypted tunnel between the on-premises edge and the AWS VPN endpoint, meeting compliance requirements while retaining Direct Connect's performance and reliability benefits.

Why this answer

AWS Direct Connect does not encrypt traffic by default. To encrypt, you can use an IPsec VPN over the Direct Connect virtual interface (option A). Option B is incorrect because Direct Connect does not support native encryption on the virtual interface; encryption must be added via IPsec or application-level encryption.

Option C is not optimal because the requirement specifies using the existing Direct Connect connection, not internet-based VPN. Option D is incorrect because VPC Peering connects VPCs within AWS, not an on-premises data center, and does not provide encryption.

112
Multi-Selectmedium

A company is designing a network architecture for a critical application that must be highly available and secure. Which TWO actions should be taken to ensure high availability of the network infrastructure?

Select 2 answers
A.Deploy resources across multiple Availability Zones.
B.Use Elastic IP addresses for failover between instances.
C.Use a single internet gateway for the VPC.
D.Use a single Availability Zone for all resources to reduce complexity.
E.Place all instances in a public subnet for easy access.
AnswersA, B

Distributing workloads across multiple Availability Zones within a Region makes an entire data-center failure survivable because each AZ runs on independent power, cooling, and physical networking. If one AZ degrades or goes offline, healthy copies of the workload in other AZs continue to serve traffic, giving the design a failure domain with no single point of failure. This is the foundational pattern for mission-critical architecture on AWS and is more effective than any single-instance or IP-level technique.

Why this answer

Deploying resources across multiple Availability Zones (AZs) ensures that if one AZ experiences a failure (e.g., power outage, network disruption), the application can continue serving traffic from another AZ. This is the foundational principle of high availability in AWS, as each AZ is isolated but connected via low-latency links, allowing for fault tolerance without single points of failure.

Exam trap

The trap here is that candidates often confuse high availability with disaster recovery or assume that using a single internet gateway or Elastic IP addresses alone provides sufficient fault tolerance, when in fact the core requirement is geographic redundancy across Availability Zones.

113
MCQmedium

An application running on EC2 instances needs to access an S3 bucket. The Security Engineer wants to ensure that the EC2 instances do not have access keys and that the access is restricted to only the required bucket. What is the most secure way to provide this access?

A.Generate an access key for an IAM user with permissions to the S3 bucket and store it in the EC2 instance.
B.Create an S3 bucket policy that allows the EC2 instance's public IP address to access the bucket.
C.Create an IAM role with a policy that allows access to the specific S3 bucket, and attach the role to the EC2 instance profile.
D.Use the root user's access keys to configure the application.
AnswerC

Creating an IAM role with a narrowly scoped policy and attaching it as the instance profile lets the EC2 instance securely obtain temporary credentials from AWS STS through the instance metadata service, with no keys embedded in the AMI or stored on disk. These credentials are rotated automatically and are valid only for a short duration, reducing the blast radius of any credentials leak. The policy can restrict actions to the specific S3 bucket (for example, s3:GetObject and s3:ListBucket), and the role's trust policy allows the EC2 service to assume it, ensuring the instance operates with least privilege and a clear audit trail in CloudTrail.

Why this answer

It uses an IAM role attached to an EC2 instance profile, which allows the instance to obtain temporary security credentials from AWS STS (Security Token Service) without storing any long-term access keys. The role's policy can be scoped to grant access only to the specific S3 bucket, ensuring least privilege. This approach eliminates the risk of key exposure and is the AWS-recommended best practice for granting EC2 instances access to AWS services.

Exam trap

The trap here is that candidates may think storing access keys on the instance (Option A) is acceptable if the keys are scoped, but the exam emphasizes that any long-term credential on an instance is a security risk, and the IAM role mechanism is the only secure, AWS-native way to avoid hardcoded keys.

How to eliminate wrong answers

Option A is wrong because storing an access key on the EC2 instance introduces a long-term credential that can be compromised if the instance is breached, violating the principle of not embedding keys in code or instances. Option B is wrong because restricting access by public IP address is insecure (IPs can change, be spoofed, or shared) and does not authenticate the instance; S3 bucket policies based on IPs are not a secure identity-based access control method. Option D is wrong because using the root user's access keys violates AWS security best practices (root keys should never be used for programmatic access) and grants unrestricted, overly permissive access to all AWS resources, not just the required bucket.

114
MCQmedium

A company wants to restrict access to an S3 bucket so that only requests from a specific VPC endpoint are allowed. Which policy element should be used in the S3 bucket policy?

A.aws:Referer
B.aws:SourceVpce
C.aws:SourceVpc
D.aws:SourceIp
AnswerB

aws:SourceVpce is the correct condition key because it restricts access to requests that originate from a specific VPC endpoint, identified by its endpoint ID (e.g., vpce-1a2b3c4d). In an S3 bucket policy, you can use this condition key with an explicit Allow statement and the endpoint ID as the value to ensure that only traffic flowing through that particular endpoint can access the bucket. This works for both gateway-gateway and interface VPC endpoints for S3, making it the precise mechanism to limit access to exactly one endpoint.

Why this answer

To restrict access to an S3 bucket so that only requests originating from a specific VPC endpoint are allowed, the `aws:SourceVpce` condition key must be used in the S3 bucket policy. This key checks the VPC endpoint ID (e.g., `vpce-1a2b3c4d`) from which the request originated, ensuring that only traffic through that specific endpoint is permitted. Using `aws:SourceVpc` would allow any endpoint within the VPC, not a specific one, and `aws:SourceIp` or `aws:Referer` are irrelevant for VPC endpoint-based access control.

Exam trap

The trap here is that candidates often confuse `aws:SourceVpc` with `aws:SourceVpce`, mistakenly thinking that restricting to a VPC is sufficient, but the question explicitly requires restricting to a specific VPC endpoint, not just any endpoint in the VPC.

How to eliminate wrong answers

Option A is wrong because `aws:Referer` is used to restrict access based on the HTTP Referer header, typically for preventing hotlinking from unauthorized websites, not for VPC endpoint-based access. Option C is wrong because `aws:SourceVpc` restricts access to requests coming from any VPC endpoint within a specified VPC, not a single specific endpoint, which does not meet the requirement of restricting to a specific VPC endpoint. Option D is wrong because `aws:SourceIp` restricts access based on the source IP address of the request, which is not applicable when traffic comes through a VPC endpoint (the source IP is the endpoint's private IP, not the original client IP).

115
Multi-Selectmedium

Which TWO actions should a security engineer take to protect an Amazon EC2 instance from unauthorized access? (Choose two.)

Select 2 answers
A.Place the instance in a public subnet and rely solely on security groups.
B.Disable termination protection so the instance can be easily terminated if compromised.
C.Configure security groups to allow only necessary inbound traffic.
D.Place the instance in a private subnet and use a bastion host for administrative access.
E.Enable detailed billing to monitor instance usage.
AnswersC, D

Security groups act as a stateful virtual firewall, evaluating inbound traffic and allowing only the rules you explicitly define. By restricting inbound traffic to only necessary ports and source IP ranges, you minimize the attack surface and block unused services from being probed. This least-privilege approach is a fundamental security control that should be applied in addition to network segmentation, not as a substitute for it.

Why this answer

Security groups act as a virtual firewall for EC2 instances, controlling inbound and outbound traffic at the instance level. By configuring security groups to allow only necessary inbound traffic (Option C), you follow the principle of least privilege, reducing the attack surface. This is a fundamental security best practice for protecting EC2 instances from unauthorized access.

Exam trap

The trap here is that candidates often think placing an instance in a public subnet with security groups is sufficient, but the exam expects you to recognize that a private subnet with a bastion host is a more secure architecture for administrative access.

116
MCQhard

A company is designing a network architecture for a multi-tier web application. The application consists of a public-facing ALB, web servers in private subnets, and an RDS database in isolated subnets. The security team requires that the web servers have no direct internet access. Which VPC configuration meets this requirement?

A.Public subnets with an Internet Gateway.
B.Isolated subnets with no route to the internet.
C.Private subnets with a NAT Gateway in a public subnet.
D.Private subnets with a VPN connection to the corporate network.
AnswerC

Private subnets with a NAT Gateway in a public subnet provide a controlled outbound-only internet path. The private subnets' route table sends 0.0.0.0/0 to the NAT Gateway, which holds an Elastic IP and translates traffic, while inbound connections from the internet are still impossible. This allows instances to fetch updates and call external services without being directly exposed, making it the recommended multi-tier architecture pattern.

Why this answer

Placing web servers in private subnets with a NAT Gateway in a public subnet allows them to initiate outbound connections to the internet (e.g., for software updates) while preventing any inbound internet traffic from reaching them directly. The NAT Gateway translates private IPs to the public IP of the gateway, and the private subnets' route table points 0.0.0.0/0 to the NAT Gateway, not an Internet Gateway, ensuring no direct internet access.

Exam trap

The trap here is that candidates often confuse 'no direct internet access' with 'no internet access at all,' leading them to choose isolated subnets (Option B) instead of recognizing that private subnets with a NAT Gateway allow outbound-only internet access, which satisfies the requirement.

How to eliminate wrong answers

Option A is wrong because public subnets with an Internet Gateway would give the web servers direct internet access via their public IPs, violating the requirement for no direct internet access. Option B is wrong because isolated subnets with no route to the internet would prevent the web servers from initiating any outbound internet traffic (e.g., for patches or updates), which is often needed for operational tasks, and the requirement only prohibits direct internet access, not all internet access. Option D is wrong because a VPN connection to the corporate network provides private connectivity to an on-premises network, not internet access, and does not address the requirement to prevent direct internet access—it is irrelevant to the internet access control.

117
MCQhard

A company wants to allow cross-account access to an S3 bucket. The bucket owner (Account A) wants to grant read-only access to users in Account B. Which combination of policies is required?

A.A bucket ACL in Account A granting READ access to Account B
B.A bucket policy in Account A granting s3:GetObject to Account B and an IAM policy in Account B allowing s3:GetObject
C.An IAM policy in Account A that allows s3:GetObject
D.An IAM role in Account B that grants s3:GetObject to Account A
AnswerB

Cross-account access is an AND operation: the bucket policy in Account A must explicitly allow the principal (the root user or a specific IAM principal in Account B) to call s3:GetObject, and the IAM identity in Account B must have an attached identity-based policy that also permits s3:GetObject. If either policy denies or lacks the permission, the request fails, because both the resource-based policy (in the owning account) and the identity-based policy (in the accessing account) must grant the action. This pattern is the standard way to grant direct cross-account access to an S3 object while keeping the resource owner in control.

Why this answer

Cross-account S3 access requires two-sided permission: the bucket owner (Account A) must grant access via a bucket policy that allows Account B's principal to perform s3:GetObject, and the IAM user or role in Account B must also have an IAM policy allowing s3:GetObject. Both are evaluated, and the request is allowed only if both sides permit it.

Exam trap

SCS-C02 often tests the misconception that a bucket policy alone is sufficient for cross-account access, ignoring the requirement for an identity-based policy in the caller's account.

How to eliminate wrong answers

Option A is wrong because S3 bucket ACLs are legacy and cannot grant cross-account access to IAM principals in another account in the way a bucket policy can; ACLs also do not support condition keys or fine-grained actions like s3:GetObject. Option C is wrong because an IAM policy in Account A applies only to principals within Account A, not to users in Account B, so it cannot grant cross-account access. Option D is wrong because an IAM role in Account B granting access to Account A reverses the direction — it would let Account A assume a role in Account B, not let Account B read Account A's bucket.

118
MCQhard

Refer to the exhibit. A user from IP 10.1.2.3 attempts to download an object from my-secret-bucket using HTTP (not HTTPS). What will be the outcome?

A.Success, because the Allow statement is evaluated first.
B.Failure, because the user's IP is not in the allowed range.
C.Success, because the user's IP is within the allowed range.
D.Failure, because the Deny statement blocks HTTP requests.
AnswerD

This is the correct outcome because AWS IAM uses an explicit deny override model: if any applicable policy contains a Deny statement that matches the request, access is denied even if an Allow statement also matches. Here, the request is sent over HTTP, so the Deny condition on aws:SecureTransport (e.g., "aws:SecureTransport": "false") is triggered, blocking the request. The user's IP being within the allowed range is irrelevant because the Deny statement takes unconditional precedence.

Why this answer

The Deny statement with condition aws:SecureTransport=false will block HTTP requests. Even though the IP matches the allow rule, the explicit Deny overrides the Allow.

119
Multi-Selecthard

A company is using AWS Direct Connect with a private virtual interface (VIF) to connect its on-premises network to a VPC. The security team wants to encrypt traffic over the Direct Connect connection. Which TWO options can be used? (Choose TWO.)

Select 2 answers
A.Use AWS KMS to encrypt the traffic.
B.Use AWS Certificate Manager to issue certificates for the connection.
C.Enable MACsec on the Direct Connect connection.
D.Use SSL/TLS to encrypt the traffic between on-premises and AWS.
E.Establish an IPsec VPN tunnel over the Direct Connect connection.
AnswersC, E

MACsec operates at layer 2, providing hop-by-hop encryption on the dedicated Direct Connect link between the customer router and the AWS device. It encrypts traffic traversing the connection itself, satisfying the requirement without overlaying an IPsec tunnel.

Why this answer

Option C is correct because AWS Direct Connect supports MACsec (IEEE 802.1AE) on dedicated connections at 10 Gbps and 100 Gbps, providing point-to-point Layer 2 encryption between the on-premises router and the AWS Direct Connect location. Option E is correct because you can run an IPsec VPN over the private VIF (or a transit VIF) on top of Direct Connect, which encrypts traffic end-to-end at Layer 3 between the on-premises VPN device and the AWS VPN endpoint. Option A is incorrect because AWS KMS is a key management service for encrypting data at rest, not for encrypting network traffic in transit over Direct Connect.

Option B is incorrect because ACM issues and manages TLS certificates for AWS-integrated services, not for encrypting a Direct Connect link. Option D is incorrect because generic SSL/TLS is not a supported mechanism for encrypting the Direct Connect private VIF transport itself; encryption must come from MACsec or an IPsec VPN.

Exam trap

The trap here is that candidates often assume encryption must happen at higher layers (like SSL/TLS) or through a separate service (like KMS), but the exam tests knowledge of Layer 2 encryption (MACsec) and Layer 3 encryption (IPsec over Direct Connect) as the two valid methods to encrypt traffic over a Direct Connect connection.

120
MCQhard

Refer to the exhibit. A security engineer attaches this bucket policy to an S3 bucket. A user from IP address 203.0.113.10 tries to download an object using HTTP (not HTTPS). What will happen?

A.The request is allowed because the IP address matches the allow statement.
B.The request is denied because the IP is not in the allowed range.
C.The request is denied because HTTP is used.
D.The request is allowed because the user is using a valid IP.
AnswerC

The bucket policy includes an explicit deny statement that blocks any request where the transport protocol is HTTP, typically via a condition such as `aws:SecureTransport: false`. Since the request in question uses HTTP, that deny condition is met, and an explicit deny always overrides any allow statement in the policy. As a result, even a request from an otherwise permitted IP address is denied because of the insecure protocol.

Why this answer

The bucket policy includes a condition that denies access when the request uses HTTP (aws:SecureTransport equals false). Even though the IP address 203.0.113.10 matches the allowed IP range in the policy, the explicit deny for HTTP requests overrides the allow. Since the user is using HTTP, the request is denied.

Exam trap

The trap here is that candidates see the IP address matches the allow statement and assume the request is allowed, overlooking the explicit deny for HTTP that overrides the allow due to AWS IAM policy evaluation logic.

How to eliminate wrong answers

Option A is wrong because the policy contains an explicit deny condition for HTTP requests that overrides the IP-based allow statement, so matching the IP does not guarantee access. Option B is wrong because the IP address 203.0.113.10 is within the allowed IP range specified in the policy (203.0.113.0/24), so the denial is not due to IP mismatch. Option D is wrong because the request is denied due to the use of HTTP, not because the IP is invalid; the IP is valid but the protocol condition triggers the deny.

121
MCQhard

A security engineer is configuring a VPC for a highly sensitive application. The VPC must not have a route to the internet, but the application needs to periodically download security patches from a specific domain (patches.example.com). Which solution meets these requirements with minimal operational overhead?

A.Launch a proxy server in a public subnet and configure the application to use the proxy.
B.Use a VPC endpoint for Amazon S3 and DynamoDB to download patches.
C.Create a VPC interface endpoint for AWS Systems Manager and use Systems Manager Patch Manager to apply patches.
D.Deploy a NAT gateway in a public subnet and add a route to the NAT gateway for the private subnet.
AnswerB

A VPC endpoint for Amazon S3 (a gateway endpoint) allows resources in private subnets to access S3 using private IP addresses with traffic staying entirely within the AWS network, without any internet gateway, NAT device, or VPN connection. Since patches are stored in S3 buckets, the application can retrieve patch files directly over the endpoint, and an endpoint for DynamoDB can handle patch metadata or state tables. This satisfies the no-internet-route requirement while enabling secure patch downloads.

Why this answer

It uses VPC endpoints for Amazon S3 (and optionally DynamoDB) to provide private connectivity to AWS services without requiring an internet gateway. By storing the security patches in an S3 bucket with a custom domain alias (e.g., patches.example.com), the application can download patches through the VPC endpoint, meeting the requirement of no internet route and minimizing operational overhead. Options A and D require an internet gateway, which creates a route to the internet.

Option C does not provide access to an external domain like patches.example.com.

Exam trap

Candidates may assume that AWS Systems Manager Patch Manager can download patches from any external domain via VPC endpoints, but SSM endpoints only provide private access to AWS services, not arbitrary external domains. The correct approach is to store patches in an AWS service like S3 and use a VPC endpoint.

How to eliminate wrong answers

Option A is wrong because launching a proxy server in a public subnet requires the VPC to have an internet gateway and a route to the internet, which violates the requirement that the VPC must not have a route to the internet. Option B is wrong because VPC endpoints for Amazon S3 and DynamoDB are designed for accessing those specific AWS services, not for downloading patches from an external domain like patches.example.com; they cannot route traffic to arbitrary internet destinations. Option D is wrong because deploying a NAT gateway in a public subnet requires the VPC to have an internet gateway attached to the public subnet, which again creates a route to the internet, directly contradicting the requirement.

122
MCQmedium

A company uses AWS Organizations with multiple accounts. The security team needs to enforce that all Amazon S3 buckets across the organization are configured to block public access. Which solution should be used to centrally enforce this requirement?

A.Enable AWS Trusted Advisor to automatically remediate public buckets.
B.Use a service control policy (SCP) to deny the s3:PutBucketPublicAccessBlock action at the organization root.
C.Create an IAM role in each account that denies the s3:PutBucketPublicAccessBlock action.
D.Apply a bucket policy to each bucket that blocks public access.
AnswerB

An SCP applied at the organization root in AWS Organizations is an identity-policy boundary that affects every principal, including the root user, in every member account. By explicitly denying the s3:PutBucketPublicAccessBlock action, users cannot create, change, or delete S3 Block Public Access settings, effectively preventing all accounts from removing public-access protections. This is the only option that gives a centrally manageable, organization-wide preventive control.

Why this answer

Service control policies (SCPs) in AWS Organizations allow you to centrally control the maximum available permissions for all accounts within the organization. By denying the s3:PutBucketPublicAccessBlock action at the organization root, you prevent any account from disabling or modifying the public access block settings on any S3 bucket, thereby enforcing the security team's requirement across all accounts. This approach works because SCPs are applied at the organization level and override any IAM or bucket-level permissions that would otherwise allow the action.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies or bucket policies, thinking that a bucket policy or an IAM role can centrally enforce a deny across all accounts, but only SCPs operate at the organization level and apply to all principals in the member accounts.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor can only detect public buckets and provide recommendations, but it cannot automatically remediate them without additional custom automation (e.g., using AWS Config rules with auto-remediation), and it is not a central enforcement mechanism. Option C is wrong because creating an IAM role in each account that denies the action does not prevent users or services from using other IAM roles or direct IAM user permissions to call s3:PutBucketPublicAccessBlock; SCPs are the only way to enforce a deny across all principals in an account. Option D is wrong because applying a bucket policy to each bucket that blocks public access is a per-bucket manual or scripted approach that does not prevent future buckets from being created without the policy, nor does it centrally enforce the requirement across all existing and new buckets.

123
MCQeasy

A security engineer is configuring a VPC with public and private subnets. The engineer needs to allow instances in the private subnet to download software updates from the internet. Which component should be added to the VPC?

A.VPN connection to on-premises.
B.VPC endpoint for Amazon S3.
C.Bastion host in a public subnet.
D.NAT gateway in a public subnet.
AnswerD

A NAT gateway in a public subnet is correct because it enables instances in private subnets to initiate outbound IPv4 traffic to the internet, such as software updates or API calls, while preventing unsolicited inbound connections from reaching them. The NAT gateway resides in a public subnet with an Elastic IP and uses the internet gateway to reach external networks, while private subnet route tables direct 0.0.0.0/0 traffic to the NAT gateway. It is fully managed, scales automatically, and does not require patch management—unlike a NAT instance.

Why this answer

A NAT gateway placed in a public subnet allows instances in a private subnet to initiate outbound connections to the internet (e.g., to download software updates) while remaining unreachable from the internet. The NAT gateway performs source NAT, translating the private IPs to its own Elastic IP, and returns responses to the originating instances. This is the standard AWS pattern for giving private subnets outbound-only internet access.

Exam trap

SCS-C02 often tests the misconception that a VPC endpoint or bastion host can provide general outbound internet access; candidates must recognize that only a NAT device (gateway or instance) in a public subnet enables private-subnet instances to reach the internet.

How to eliminate wrong answers

Option A is wrong because a VPN connection to on-premises provides connectivity to a corporate network, not to the public internet, and does not enable general internet downloads. Option B is wrong because a VPC endpoint for Amazon S3 only provides private access to S3 (and S3-compatible services), not to arbitrary internet hosts serving software updates. Option C is wrong because a bastion host in a public subnet is used for inbound SSH/RDP administrative access to private instances, not for outbound internet access from private instances.

124
Multi-Selectmedium

A security engineer is designing a VPC with public and private subnets. The VPC will host web servers in public subnets and database servers in private subnets. The web servers need to send traffic to the database servers, and the database servers must not have direct internet access. Which TWO configurations should the engineer implement?

Select 2 answers
A.Use network ACLs to block all inbound traffic to the private subnets.
B.Configure security group rules to allow inbound traffic from the web server security group to the database security group.
C.Do not add a route to an internet gateway in the route table for the private subnets.
D.Attach an internet gateway to the VPC and route the private subnets to it.
E.Add a NAT gateway in the public subnet and route the private subnets to it.
AnswersB, C

The database security group should have an inbound rule that references the web server security group as its source rather than a CIDR block. This allows the web tier to reach the database service on the required port, such as 3306 or 5432, while keeping the database isolated from all other sources. Because security group references are stateful and evaluated dynamically, this rule continues to work as web instances scale or are replaced, and it does not require the database to have a public IP or an internet gateway route.

Why this answer

Security group rules are stateful and can reference other security groups as a source, allowing the web server security group to be specified as the source for inbound traffic to the database security group. This ensures that only traffic originating from the web servers is permitted to reach the database servers, providing a logical, application-layer firewall without exposing the databases to the internet. Option C is correct because omitting a route to an internet gateway from the private subnet's route table ensures that the database servers have no direct path to the internet, satisfying the requirement that they must not have direct internet access.

Exam trap

The trap here is that candidates often confuse the purpose of NAT gateways (outbound-only internet access) with the requirement to block all internet access, leading them to incorrectly select Option E, or they mistakenly think network ACLs are the primary control for traffic between subnets, overlooking the stateful, group-based nature of security groups.

125
MCQhard

An organization has a multi-account AWS environment using AWS Organizations. The security team needs to ensure that no Amazon EC2 instances are launched without an IAM instance profile that includes a specific role. Which preventive control should be implemented?

A.Create an SCP that denies ec2:RunInstances when the condition iam:InstanceProfile is not set to the required profile ARN.
B.Attach an IAM policy to all users that denies ec2:RunInstances unless an instance profile is specified.
C.Create an SCP that denies ec2:RunInstances when the condition ec2:InstanceProfile is not set.
D.Use AWS Config rule ec2-instance-profile-attached to detect non-compliant instances and automatically terminate them.
AnswerA

This SCP is correct because it applies at the organization level to all member accounts and uses the global IAM condition key iam:InstanceProfile to require a specific instance profile ARN. The deny rule blocks any ec2:RunInstances call from any principal—user, role, or service—that does not include the required profile in its parameters. The condition key is evaluated exactly and provides a preventive guardrail that cannot be bypassed by user-specific policy exceptions.

Why this answer

AWS Organizations Service Control Policies (SCPs) can be applied to all accounts in the organization to prevent actions across all principals. By using the `iam:InstanceProfile` condition key with the `ec2:RunInstances` action, the SCP denies the launch of any EC2 instance that does not have the required IAM instance profile attached. This is a preventive control that blocks the action before it occurs, ensuring compliance across the entire multi-account environment.

Exam trap

The trap here is confusing the condition key `iam:InstanceProfile` (which is correct for IAM instance profiles) with `ec2:InstanceProfile` (which does not exist), leading candidates to choose Option C, and also mistaking detective controls like AWS Config for preventive controls, as in Option D.

How to eliminate wrong answers

Option B is wrong because IAM policies attached to users only apply to those specific users and do not prevent actions performed by roles or services (e.g., EC2 Auto Scaling, AWS CloudFormation) that launch instances without an instance profile, making it an incomplete control. Option C is wrong because `ec2:InstanceProfile` is not a valid condition key for the `ec2:RunInstances` action; the correct condition key is `iam:InstanceProfile`, which references the IAM instance profile ARN. Option D is wrong because AWS Config rules are detective controls that only identify non-compliant resources after they are created, not preventive controls that block the action; automatic termination is a reactive measure, not a preventive one.

126
MCQhard

A company is using AWS Transit Gateway to connect multiple VPCs and on-premises networks via VPN. The security team wants to inspect all traffic between VPCs before it reaches its destination. Which architecture should be used?

A.Use a VPN CloudHub to connect VPCs and inspect traffic at the VPN endpoint.
B.Use AWS Direct Connect to connect VPCs and inspect traffic on-premises.
C.Use a Transit Gateway with a central inspection VPC that hosts security appliances and route all inter-VPC traffic through it.
D.Use VPC Peering and configure security groups on each VPC to allow only necessary traffic.
AnswerC

AWS Transit Gateway acts as a hub to connect multiple VPCs and on-premises networks, enabling you to implement a hub-and-spoke routing architecture without VPC peering complexities. By attaching a dedicated inspection VPC to the Transit Gateway and configuring route tables so that all inter-VPC traffic is sent to that inspection VPC as a next hop, security appliances (e.g., Palo Alto, Fortinet) can inspect and filter all traffic. This provides centralized visibility and control over east-west traffic while avoiding the scaling limits and meshed connections of VPC peering.

Why this answer

AWS Transit Gateway can route inter-VPC traffic through a central inspection VPC that hosts security appliances (e.g., firewalls, IDS/IPS). By attaching the Transit Gateway to the inspection VPC and configuring route tables to force all traffic between VPCs to pass through the inspection VPC, the security team can inspect all traffic before it reaches its destination. This architecture provides centralized, scalable traffic inspection without requiring traffic to leave the AWS network.

Exam trap

The trap here is that candidates may confuse VPC Peering (Option D) as a valid inspection method, but it lacks a central inspection point and cannot enforce traffic inspection between VPCs without complex, non-scalable configurations.

How to eliminate wrong answers

Option A is wrong because VPN CloudHub is designed for connecting multiple on-premises sites via VPN, not for inter-VPC traffic inspection; it does not provide a mechanism to route VPC-to-VPC traffic through a central inspection point. Option B is wrong because AWS Direct Connect extends the on-premises network to AWS but does not inherently inspect inter-VPC traffic; routing traffic on-premises for inspection would add latency and egress costs, and it is not a recommended pattern for VPC-to-VPC inspection. Option D is wrong because VPC Peering creates direct, one-to-one connections between VPCs without a central inspection point; security groups can only filter traffic at the instance level, not inspect or redirect traffic between VPCs.

127
MCQmedium

A company's security team discovers that an Amazon EC2 instance has been compromised and is sending outbound traffic to a known malicious IP address. The instance is in a VPC with a security group that allows all outbound traffic. What is the FASTEST way to stop the outbound traffic without affecting other instances?

A.Modify the network ACL of the subnet to deny outbound traffic to the malicious IP.
B.Change the route table of the subnet to route traffic to a blackhole.
C.Terminate the compromised EC2 instance immediately.
D.Modify the security group attached to the instance to revoke all outbound rules.
AnswerD

Security groups are stateful, instance-level firewalls, so modifying the security group attached to the instance to revoke all outbound rules will immediately block the compromised instance's egress traffic without affecting other instances in the subnet. Changes apply instantly to the ENI, and because security groups are scoped to the instance, this provides precise, surgical isolation. This is the fastest way to stop malicious outbound communication while preserving the instance for investigation.

Why this answer

Security groups are stateful and act as a virtual firewall at the instance level. By revoking all outbound rules in the security group attached to the compromised EC2 instance, you immediately block all outbound traffic from that specific instance without affecting any other instances in the VPC. This is the fastest and most targeted action because it requires no changes to subnet-level configurations or instance termination.

Exam trap

The trap here is that candidates often confuse security groups with network ACLs, assuming that a NACL change is faster or more precise, when in fact security groups are instance-level and can be modified instantly without affecting other instances, making them the fastest and most targeted solution.

How to eliminate wrong answers

Option A is wrong because modifying a network ACL (NACL) affects all instances in the subnet, not just the compromised one, and NACLs are stateless, requiring explicit rules for both inbound and outbound traffic, which adds complexity and latency. Option B is wrong because changing the route table to a blackhole would affect all traffic from the subnet, not just the compromised instance, and would disrupt other instances. Option C is wrong because terminating the instance stops all traffic but also destroys the instance and any data on it, which is not the fastest nor the least disruptive method; it also does not allow for forensic analysis.

128
MCQmedium

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The security team wants to protect the application from common web exploits such as SQL injection and cross-site scripting. Which AWS service should they use?

A.AWS Network Firewall
B.AWS WAF
C.AWS Firewall Manager
D.AWS Shield Advanced
AnswerB

AWS WAF is a web application firewall that protects web applications by inspecting HTTP(S) requests and allowing or blocking them based on rules you define. It specifically includes managed rule groups and match conditions for SQL injection and cross-site scripting (XSS), as well as rate-based rules to mitigate abusive traffic. Since the application is running in EC2 behind an Application Load Balancer or Amazon CloudFront, AWS WAF can be attached to those endpoints directly.

Why this answer

AWS WAF is a web application firewall that helps protect web applications from common web exploits like SQL injection and cross-site scripting (XSS). It integrates directly with Application Load Balancers to inspect HTTP/HTTPS requests and block malicious traffic based on customizable rules. This makes it the correct choice for the security team's requirement.

Exam trap

The trap here is that candidates often confuse AWS WAF with AWS Network Firewall, thinking network-layer filtering is sufficient for application-layer threats, but WAF is specifically designed for HTTP/HTTPS inspection at the application layer.

How to eliminate wrong answers

Option A is wrong because AWS Network Firewall is a stateful managed firewall for VPC network traffic, not designed to inspect application-layer payloads like HTTP requests for SQL injection or XSS. Option C is wrong because AWS Firewall Manager is a policy management service that centrally configures and enforces firewall rules across accounts, not a service that directly inspects web traffic for exploits. Option D is wrong because AWS Shield Advanced provides DDoS protection and cost protection against scaling attacks, not application-layer threat detection for SQL injection or XSS.

129
Multi-Selectmedium

A company uses AWS Organizations and wants to restrict the use of specific instance types across all accounts. Which TWO actions should be taken to enforce this restriction?

Select 2 answers
A.Restrict instance types at the VPC level using network ACLs.
B.Use AWS CloudTrail to monitor instance launches and send alerts.
C.Apply a Service Control Policy (SCP) that denies ec2:RunInstances with noncompliant instance types.
D.Create an IAM role that denies launch of noncompliant instances.
E.Use AWS Config rules to detect and automatically stop noncompliant instances.
AnswersC, E

An SCP applied at the root or OU level with a Deny effect for ec2:RunInstances and a StringNotLike/StringNotEquals condition on ec2:InstanceType explicitly blocks noncompliant launches for all principals inside the affected accounts, including IAM users, roles, and the root user. SCPs provide an authoritative guardrail because they are evaluated as a filter on the account's effective permissions and cannot be overridden by a more permissive IAM policy within that account. This gives central governance across the entire AWS Organization, making it the correct preventive control.

Why this answer

Service Control Policies (SCPs) in AWS Organizations allow you to centrally control the maximum available permissions for all accounts in the organization. By applying an SCP that denies ec2:RunInstances when the instance type does not match an allowed list, you can effectively prevent any user or role in any account from launching noncompliant instance types, even if they have full IAM permissions to do so.

Exam trap

The trap here is that candidates often confuse detective controls (like CloudTrail or AWS Config) with preventive controls (like SCPs), or they mistakenly think IAM roles can enforce organization-wide restrictions when they are only scoped to the trust policy of that specific role.

130
Multi-Selecthard

A security engineer is designing a secure VPC architecture for a web application that must be accessible from the internet. The application runs on EC2 instances in private subnets. Which THREE components are required to provide secure internet connectivity?

Select 3 answers
A.Public subnets with routes to the IGW
B.NAT Gateway in a public subnet
C.Virtual Private Gateway (VGW)
D.Transit Gateway
E.Internet Gateway (IGW) attached to the VPC
AnswersA, B, E

A public subnet is defined by having a route table entry with a destination of 0.0.0.0/0 pointing to an Internet Gateway (IGW). This default route enables resources with public IPs to directly send and receive traffic from the internet. While the IGW is the actual gateway, the route in the public subnet is the configuration that makes the subnet public. Therefore, public subnets with routes to the IGW are a critical part of the architecture for internet-facing components.

Why this answer

A is correct because public subnets require routes to the Internet Gateway (IGW) in their route tables to allow traffic from the internet to reach resources in those subnets. For the web application's EC2 instances in private subnets to initiate outbound internet connectivity (e.g., for software updates), a NAT Gateway must be placed in a public subnet with a route to the IGW, and the private subnet's route table must point 0.0.0.0/0 traffic to the NAT Gateway. The IGW attached to the VPC is the foundational component that enables bidirectional internet traffic for the VPC, but it must be explicitly associated with route tables of public subnets.

Exam trap

The trap here is that candidates often confuse the Virtual Private Gateway (VGW) or Transit Gateway as alternatives for internet connectivity, but neither provides NAT or direct internet access; they are designed for hybrid networking and inter-VPC routing, respectively.

131
MCQeasy

A security engineer needs to ensure that all traffic to an EC2 instance in a VPC is inspected by a network firewall appliance. The firewall is deployed in a separate subnet. What is the MOST secure and scalable way to route traffic through the firewall?

A.Configure a NAT gateway in the firewall subnet and route all traffic through it.
B.Use a Gateway Load Balancer with a Gateway Load Balancer endpoint in each subnet.
C.Use an Application Load Balancer in front of the firewall.
D.Create a transit gateway and route traffic through the firewall subnet.
AnswerB

Gateway Load Balancer sits inline at Layers 3 and 4 by encapsulating traffic in GENEVE tunnels, forwarding packets to a fleet of firewall appliances while preserving flow symmetry. A Gateway Load Balancer endpoint is created in each subnet and becomes the next-hop target in VPC route tables, so all traffic entering or leaving those subnets is transparently steered through the firewall fleet. This design also provides health checks and autoscaling for the security appliances.

Why this answer

A Gateway Load Balancer (GWLB) with a Gateway Load Balancer endpoint in each subnet provides transparent, scalable, and highly available traffic inspection. GWLB operates at Layer 3 (IP packets) and uses GENEVE encapsulation to forward traffic to the firewall appliance without modifying the source/destination IP addresses, ensuring all traffic to the EC2 instance is inspected. This architecture scales horizontally by adding more firewall instances behind the GWLB and avoids single points of failure.

Exam trap

The trap here is that candidates often confuse Gateway Load Balancer with a traditional load balancer (ALB/NLB) or assume a NAT gateway can inspect inbound traffic, but GWLB is the only AWS service designed specifically for transparent, scalable, and highly available traffic inspection at the network layer.

How to eliminate wrong answers

Option A is wrong because a NAT gateway is designed for outbound internet traffic from private subnets, not for bidirectional traffic inspection; it cannot route inbound traffic to an EC2 instance through a firewall appliance. Option C is wrong because an Application Load Balancer operates at Layer 7 (HTTP/HTTPS) and cannot inspect non-HTTP traffic or forward raw IP packets, making it unsuitable for network-layer firewall inspection. Option D is wrong because a transit gateway provides connectivity between VPCs and on-premises networks but does not inherently support transparent traffic inspection; routing traffic through a firewall subnet via a transit gateway requires complex manual route table configurations and lacks the built-in health checks and auto-scaling of a GWLB.

132
MCQhard

A company uses AWS Lambda functions that access an Amazon RDS for MySQL database. The Lambda functions are configured with environment variables containing the database credentials. A security audit reveals that the credentials are stored in plaintext in the Lambda configuration. The security team wants to remediate this by using AWS Secrets Manager to store and automatically rotate the credentials. The Lambda functions are invoked frequently, and the team wants to minimize the impact of rotation on running functions. Which solution meets these requirements with the LEAST operational overhead?

A.Use AWS KMS to encrypt the environment variables in the Lambda configuration. Enable automatic rotation of the KMS key.
B.Store the credentials in Secrets Manager with automatic rotation enabled. Modify the Lambda functions to retrieve the secret at runtime using the Secrets Manager API and cache the secret using the AWS SDK.
C.Store the credentials in Secrets Manager and pass the secret ARN as an environment variable. Configure the Lambda function to retrieve the secret on each invocation without caching.
D.Store the credentials in AWS Systems Manager Parameter Store as a SecureString parameter with automatic rotation. Modify the Lambda function to read the parameter at runtime.
AnswerB

This approach centralizes secret storage, enables automatic rotation, and uses caching to reduce API calls and latency. The Lambda function retrieves the secret at runtime; caching ensures that frequent invocations do not overwhelm Secrets Manager and that rotated credentials are picked up after cache expiry. This minimizes operational overhead and improves security.

Why this answer

AWS Secrets Manager is designed to store and rotate database credentials automatically. By modifying the Lambda function to retrieve the secret at runtime and caching it, you reduce the number of API calls while ensuring that rotated credentials are eventually used. This approach provides security with minimal operational overhead because Secrets Manager handles rotation without custom code.

Exam trap

The trap here is assuming that encrypting environment variables with KMS is sufficient, but it does not remove the plaintext credentials from the Lambda configuration nor does it rotate them.

133
MCQhard

A company runs a web application on Amazon EC2 behind an Application Load Balancer (ALB). The security team wants to allow only traffic from the ALB to reach the EC2 instances. Which security group configuration should be used?

A.Allow inbound traffic from the ALB's private IP addresses on the EC2 security group.
B.Allow inbound traffic from the VPC CIDR block on the EC2 security group.
C.Allow inbound traffic from the ALB's security group ID on the EC2 security group.
D.Allow inbound HTTP traffic from 0.0.0.0/0 on the EC2 security group.
AnswerC

Referencing the ALB's security group ID as the source makes the EC2 rule follow the load balancer automatically, so only traffic from that ALB is permitted. This is more precise than CIDR ranges, which would also admit any host in the ALB's subnets.

Why this answer

Security groups can reference other security groups by ID. By setting an inbound rule on the EC2 security group that references the ALB's security group ID, only traffic originating from the ALB is allowed. This is the recommended approach as ALB private IP addresses are dynamic and can change, making IP-based rules (Option A) unreliable.

Exam trap

The trap here is that candidates often assume ALBs have fixed private IP addresses and choose Option A, not realizing that ALB IPs are dynamic and that security group referencing is the AWS-recommended method for this pattern.

How to eliminate wrong answers

Option A is wrong because ALBs do not have static private IP addresses; they use elastic network interfaces that can change, making IP-based rules unreliable and requiring constant updates. Option B is wrong because allowing traffic from the entire VPC CIDR block would permit any resource in the VPC (including compromised instances or unauthorized services) to reach the EC2 instances, bypassing the ALB. Option D is wrong because allowing HTTP traffic from 0.0.0.0/0 would expose the EC2 instances directly to the internet, defeating the purpose of using an ALB for traffic control and security.

134
MCQmedium

A security engineer is designing a network ACL for a public subnet containing an Application Load Balancer. The subnet must allow inbound HTTPS traffic from the internet and outbound traffic to the internet for patches. Which inbound rule should be added?

A.Allow TCP port 1024-65535 from 0.0.0.0/0
B.Allow UDP port 443 from 0.0.0.0/0
C.Allow all traffic from 0.0.0.0/0
D.Allow TCP port 443 from 0.0.0.0/0
AnswerD

This is the correct and most restrictive inbound rule for a public HTTPS endpoint because HTTPS is implemented with TLS over TCP and defaults to destination port 443. Allowing TCP 443 from 0.0.0.0/0 enables any internet client to initiate a TCP connection and perform a TLS handshake with the web server. Because NACLs are stateless, you must also configure a separate outbound rule allowing the ephemeral port range (1024–65535) so the server's return traffic can reach that client. Restricting the inbound rule to TCP 443 avoids exposing other ports while still meeting the functional requirement.

Why this answer

HTTPS traffic uses TCP port 443, and the network ACL must explicitly allow inbound TCP traffic on port 443 from the internet (0.0.0.0/0) to reach the Application Load Balancer. Network ACLs are stateless, so each direction requires a separate rule; this inbound rule permits the initial HTTPS connection requests.

Exam trap

The trap here is that candidates may confuse stateless network ACLs with stateful security groups, leading them to think an ephemeral port rule (like option A) is needed for inbound traffic, when in fact the inbound rule must specify the destination port 443 for the initial connection.

How to eliminate wrong answers

Option A is wrong because it allows ephemeral ports (1024-65535) as the destination port, which is used for return traffic, not for inbound HTTPS requests; this rule would not permit the initial connection on port 443. Option B is wrong because HTTPS uses TCP, not UDP; a UDP port 443 rule would not match HTTPS traffic and would be ineffective. Option C is wrong because allowing all traffic is overly permissive and violates the principle of least privilege; it would permit unnecessary protocols and ports, increasing the attack surface.

135
Multi-Selectmedium

A company is considering using AWS Shield Advanced to protect against DDoS attacks. Which three features are included with AWS Shield Advanced? (Choose THREE.)

Select 3 answers
A.Cost protection against DDoS-related scaling charges
B.Dedicated IP addresses for EC2 instances
C.AWS Site-to-Site VPN
D.Integration with AWS WAF for web ACLs
E.24/7 access to the AWS DDoS Response Team (DRT)
AnswersA, D, E

AWS Shield Advanced provides cost protection to help offset charges incurred when protected resources automatically scale in response to a DDoS attack. For example, if a DDoS attack causes an Application Load Balancer to scale out or CloudFront to serve more requests, AWS can issue billing credits for those additional resource usage charges, as long as the resources are protected by Shield Advanced and the attack is detected. This ensures customers are not financially penalized for the very elasticity that keeps their applications resilient during an attack.

Why this answer

AWS Shield Advanced provides cost protection against DDoS-related scaling charges, meaning if your EC2 or ELB instances scale up due to a DDoS attack, AWS will provide credits for the additional resources incurred. This is a key financial safeguard included in the Shield Advanced subscription.

Exam trap

The trap here is that candidates may confuse AWS Shield Advanced with AWS Shield Standard, or assume features like dedicated IPs or VPN are part of the DDoS protection package, when in fact they are separate services with different purposes.

136
MCQeasy

A company wants to encrypt data at rest in an Amazon S3 bucket. Which AWS service can centrally manage the encryption keys?

A.AWS CloudHSM
B.AWS Certificate Manager (ACM)
C.AWS Key Management Service (AWS KMS)
D.AWS Secrets Manager
AnswerC

AWS Key Management Service (AWS KMS) is a fully managed service that centralizes the creation, storage, rotation, and deletion of customer master keys (CMKs). S3 integrates with KMS through server-side encryption (SSE-KMS), where S3 uses a KMS key to encrypt each object's data key automatically and enforces IAM policies on key usage. This gives you centralized control, auditability through CloudTrail, and seamless S3 encryption, making KMS the correct and standard service for encrypting data at rest in S3.

Why this answer

AWS Key Management Service (AWS KMS) is the correct service because it is a fully managed, centralized service that allows you to create, manage, and control the encryption keys used to encrypt data at rest in Amazon S3. S3 integrates directly with KMS via Server-Side Encryption with AWS KMS (SSE-KMS), enabling you to use customer managed keys (CMKs) or AWS managed keys to enforce granular access control and audit key usage through AWS CloudTrail.

Exam trap

The trap here is that candidates often confuse AWS CloudHSM with KMS because both involve encryption keys, but CloudHSM is a hardware-based key storage service that lacks native integration with S3 for centralized key management, whereas KMS is the intended service for SSE-KMS.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides dedicated hardware security modules (HSMs) for generating and storing keys, but it does not centrally manage encryption keys for S3; it requires manual integration and does not offer native S3 encryption key management. Option B is wrong because AWS Certificate Manager (ACM) is designed to provision, manage, and deploy public and private SSL/TLS certificates for network encryption, not for managing encryption keys for data at rest in S3. Option D is wrong because AWS Secrets Manager is used to securely store and rotate secrets such as database credentials and API keys, not to centrally manage encryption keys for S3 server-side encryption.

137
MCQhard

Refer to the exhibit. A security engineer is reviewing this IAM policy attached to a user. The user reports that they are able to stop and start instances, but they cannot terminate instances. However, the engineer notices that there is no explicit deny for termination. Why is the user unable to terminate instances?

A.The policy does not include an explicit Allow for ec2:TerminateInstances.
B.The second statement's Resource is set to '*' but the Action list does not include termination.
C.The first statement's Resource element is too restrictive and does not include the termination API call.
D.The policy has a syntax error that prevents termination from being evaluated.
AnswerA

The policy contains separate Action and Resource elements, and IAM permits an action only when an explicit Allow statement matches that action. Because ec2:TerminateInstances appears nowhere in the first statement's Action list (which grants Start and Stop) or in the second statement's Describe-only list, the action is implicitly denied by IAM's default-deny evaluation. Without an explicit Allow, no other statement or wildcard can rescue it; the request fails with an UnauthorizedOperation error.

Why this answer

IAM policies operate on an explicit allow model. Even though there is no explicit deny for ec2:TerminateInstances, the user is unable to terminate instances because the policy does not include an explicit Allow action for ec2:TerminateInstances. Without an explicit Allow, the default behavior is to deny the action, regardless of whether a deny statement is present.

Exam trap

The trap here is that candidates often assume the absence of an explicit deny means the action is allowed, but AWS IAM defaults to implicit deny for any action not explicitly allowed.

How to eliminate wrong answers

Option B is wrong because the second statement's Resource being set to '*' and the Action list not including termination is irrelevant; the issue is the lack of an explicit Allow for termination, not the resource specification. Option C is wrong because the first statement's Resource element being too restrictive does not prevent termination; the problem is that termination is not allowed at all in the policy. Option D is wrong because there is no syntax error; the policy is syntactically valid but simply does not grant the required permission.

138
MCQeasy

A company has a VPC with multiple subnets. The security team wants to control traffic between subnets using a stateful firewall that can automatically allow return traffic. Which AWS service should be used?

A.Network ACLs
B.AWS Firewall Manager
C.AWS WAF
D.Security groups
AnswerD

Security groups are stateful and are attached to elastic network interfaces (ENIs), automatically permitting return traffic without requiring separate outbound rules for responses. They can be applied consistently across all instances within a subnet to provide effective subnet-wide filtering with connection tracking, which aligns with the security team's need for granular, connection-aware traffic control. Because they operate per-interface and maintain state, they are the correct choice in this scenario.

Why this answer

Security groups act as a stateful virtual firewall for EC2 instances and other resources at the subnet or instance level. They automatically allow return traffic regardless of inbound or outbound rules, which satisfies the requirement for a stateful firewall that controls traffic between subnets.

Exam trap

The trap here is that candidates often confuse Network ACLs with security groups, assuming both are stateful, but Network ACLs are stateless and require explicit bidirectional rules, while security groups automatically handle return traffic.

How to eliminate wrong answers

Option A is wrong because Network ACLs are stateless, meaning they require explicit rules for both inbound and outbound traffic to allow return traffic, which does not meet the stateful requirement. Option B is wrong because AWS Firewall Manager is a centralized policy management service for firewall rules across accounts and resources, not a stateful firewall itself that controls traffic between subnets. Option C is wrong because AWS WAF is a web application firewall that protects against web exploits at the application layer (HTTP/HTTPS), not a stateful network firewall for controlling traffic between subnets.

139
MCQhard

A company has a VPC with public and private subnets. The private subnets need to access the internet for software updates. The security engineer has set up a NAT gateway in a public subnet and updated the route tables accordingly. However, instances in the private subnets cannot reach the internet. The engineer checks the security group for the NAT gateway and finds that it allows all outbound traffic. What is the most likely cause of the issue?

A.The route table for the private subnet does not have a default route (0.0.0.0/0) pointing to the NAT gateway.
B.The NAT gateway does not have an Elastic IP address assigned.
C.The security group for the NAT gateway does not allow inbound traffic from the private subnets.
D.The network ACL for the private subnet does not allow inbound HTTP/HTTPS traffic.
AnswerA

For instances in a private subnet to reach the internet through a NAT gateway, the subnet's route table must have a default route (0.0.0.0/0) with the NAT gateway as the target. If this route is missing, any outbound internet-bound traffic has no valid next hop and is dropped, causing the connectivity failure. After adding this route, ensure the NAT gateway itself is in a public subnet with an associated Elastic IP and that the public subnet's route table points 0.0.0.0/0 to an internet gateway. This is the most direct and common cause when private instances cannot access the internet.

Why this answer

The most likely cause is that the route table for the private subnet does not have a default route (0.0.0.0/0) pointing to the NAT gateway. Without this route, traffic from private instances cannot reach the NAT gateway, and thus cannot access the internet. Option B is incorrect because a NAT gateway must have an Elastic IP assigned during creation, so it would not be missing.

Option C is incorrect because NAT gateways do not have security groups; they are managed by AWS and the security group concept does not apply. Option D is incorrect because network ACLs are stateless and must allow both inbound and outbound traffic, but the issue here is more likely with routing.

Exam trap

The trap is that the engineer focuses on a non-existent security group for the NAT gateway, while the real issue is the missing default route in the private subnet's route table. Candidates may incorrectly assume security groups apply to NAT gateways or overlook the route table configuration.

How to eliminate wrong answers

Option A is wrong because it is actually the most likely cause of the issue—the private subnet's route table must have a default route (0.0.0.0/0) pointing to the NAT gateway for internet access; without it, traffic cannot be directed to the NAT gateway. Option B is wrong because a NAT gateway requires an Elastic IP address to function; if it were missing, the NAT gateway would not be provisioned correctly, but the question states the NAT gateway is set up, implying an EIP is assigned. Option D is wrong because network ACLs are stateless and must allow both inbound and outbound traffic for ephemeral ports; however, the private subnet's network ACL typically allows outbound HTTP/HTTPS by default, and inbound traffic from the internet is not required for instances initiating outbound connections.

140
Multi-Selecthard

A company wants to restrict access to an S3 bucket so that only requests from a specific VPC endpoint are allowed. The bucket policy must deny all requests that do not come from the VPC endpoint. Which TWO statements are true for this configuration?

Select 2 answers
A.Use the aws:SourceIp condition key to restrict IP addresses.
B.Set the Principal to the VPC endpoint ID.
C.Use the aws:SourceVpce condition key in the bucket policy.
D.Set the Effect to Deny and include a condition for the VPC endpoint.
E.Ensure the bucket policy has an explicit Allow for the VPC endpoint.
AnswersC, D

The aws:SourceVpce condition key is the standard and most direct way to restrict S3 bucket access to a single VPC endpoint. By including this condition in a bucket policy statement, you can match the VPC endpoint ID that appears in the request context, ensuring only requests that come through that endpoint are allowed. For example, you can pair an Allow effect for the endpoint's traffic with Principal '*' and the condition 'StringEquals' on aws:SourceVpce, providing fine-grained control.

Why this answer

Option C is correct because the aws:SourceVpce condition key is the specific global condition key that evaluates the VPC endpoint ID (vpce-xxxxxxxx) from which the request originates, allowing the policy to match traffic coming through that endpoint. Option D is correct because to block everything except the endpoint, the statement must use "Effect": "Deny" combined with a condition such as "StringNotEquals": {"aws:SourceVpce": "vpce-12345678"}, which denies any request whose source VPC endpoint does not match the specified one. Option A is not appropriate because aws:SourceIp matches public IP addresses and cannot reliably identify traffic originating from a VPC endpoint, which uses private IPs and is better identified by its endpoint ID.

Option B is incorrect because the Principal element identifies the AWS identity (account, user, or role) making the request, not the VPC endpoint; the endpoint is referenced through the aws:SourceVpce condition key instead. Option E is incorrect because an explicit Allow is not required for this restriction; a Deny with a negated condition is sufficient to block all non-endpoint requests, and adding an Allow would not by itself enforce the restriction.

Exam trap

The trap here is that candidates often confuse the `aws:SourceVpce` condition key with the `aws:SourceIp` key or incorrectly assume that a VPC endpoint can be set as a Principal, leading them to pick Option A or B, while also missing that a Deny-based policy with the condition is the correct pattern rather than an explicit Allow.

141
Multi-Selectmedium

A company is designing a VPC with multiple subnets. The security team wants to ensure that traffic between the application tier and database tier is encrypted in transit. Which TWO actions should be taken?

Select 2 answers
A.Attach an internet gateway to the database subnet
B.Enable encryption on the database connections using TLS/SSL
C.Use security group rules to restrict traffic to the database port
D.Configure the application to use an encrypted protocol when connecting to the database
E.Use VPC Peering to connect the subnets
AnswersB, D

Enabling TLS/SSL on the database connections encrypts the entire session between the application and the database, protecting the data from eavesdropping or tampering while it traverses the network. This is a direct, protocol-level mitigation for the lack of encryption between the application and the database, and it can be enforced at the database server (e.g., requiring SSL/TLS for all client connections) and supported by the client driver. It does not change network routing or access control, but it specifically ensures confidentiality and integrity of the data in transit.

Why this answer

Option B is correct because enabling TLS/SSL on the database connections ensures that the data transmitted between the application tier and database tier is encrypted in transit, protecting it from interception or eavesdropping. Option D is correct because configuring the application to use an encrypted protocol (such as TLS/SSL) when connecting to the database is necessary to actually initiate and negotiate the encrypted session, complementing the database-side encryption. Option A is incorrect because an internet gateway only enables internet connectivity for a subnet and does not encrypt traffic between internal tiers.

Option C is incorrect because security group rules restrict which ports and sources can communicate but do not provide encryption in transit. Option E is incorrect because VPC peering connects subnets or VPCs for routing purposes but does not encrypt the traffic between them.

Exam trap

SCS-C02 often tests the misconception that network-level controls like security groups or VPC peering automatically provide encryption, when in fact encryption in transit requires explicit configuration at both the database and application layers.

142
MCQmedium

A company is running a critical application on EC2 instances behind an Application Load Balancer. The security team wants to ensure that only traffic from the ALB reaches the EC2 instances. How can this be achieved?

A.Use the ALB's private IP address in the EC2 security group.
B.Configure a Network ACL to allow only the ALB's subnet.
C.Reference the ALB's security group in the EC2 security group inbound rule.
D.Use the ALB's public IP address in the EC2 security group.
AnswerC

By using the ALB's security group as the source in the instance's inbound rule, the rule matches traffic from any ENI that has that security group attached. As the ALB scales, its new ENIs are automatically covered because they inherit the same security group, so the rule remains current without manual updates. This creates a precise, security-group-to-security-group boundary that ensures only the ALB can initiate traffic to the instances, which is the recommended pattern.

Why this answer

You can reference the ALB's security group as the source in the EC2 instance's security group inbound rule. This allows traffic only from the ALB, regardless of the ALB's IP addresses (which can change if the ALB scales). The security group reference is resolved dynamically by AWS, ensuring that only traffic originating from the ALB's elastic network interfaces (ENIs) is permitted.

Exam trap

The trap here is that candidates often confuse the stateless nature of Network ACLs with the stateful behavior of security groups, leading them to choose Option B, but NACLs cannot filter based on security group IDs and would allow traffic from any source in the subnet, not just the ALB.

How to eliminate wrong answers

Option A is wrong because the ALB's private IP addresses are not static; they can change when the ALB scales or its subnets are modified, making this approach unreliable and requiring constant updates. Option B is wrong because a Network ACL (NACL) is stateless and operates at the subnet level, not the instance level; it would allow traffic from any source in the ALB's subnet, including non-ALB instances or services, and does not provide the granularity of security group references. Option D is wrong because the ALB's public IP addresses are not used for traffic between the ALB and EC2 instances; that traffic flows over the AWS internal network using private IPs, and public IPs are not reliable or secure for this purpose.

143
Multi-Selecthard

A company wants to enforce encryption in transit for all traffic between its VPC and on-premises data center over AWS Direct Connect. Which TWO configurations can achieve this?

Select 2 answers
A.Use a public virtual interface with Direct Connect and configure an IPsec VPN over it.
B.Use a Site-to-Site VPN connection over the internet.
C.Use a Direct Connect Gateway and configure an IPsec VPN over the private virtual interface.
D.Use a Transit VPC architecture with VPN attachments.
E.Use a private virtual interface with Direct Connect.
AnswersA, C

A Direct Connect public virtual interface links to AWS public services over the dedicated connection, but the traffic on the link itself is unencrypted. By overlaying an IPsec VPN tunnel on that public VIF, you encrypt all traffic while still using the Direct Connect physical link, satisfying both the Direct Connect and encryption-in-transit mandates. This approach is the standard way to add encryption to a Direct Connect connection that also needs access to public AWS endpoints.

Why this answer

A public virtual interface over Direct Connect provides connectivity to public AWS endpoints, and by layering an IPsec VPN on top, you encrypt all traffic between your VPC and on-premises data center. This ensures encryption in transit while leveraging the low latency and reliability of Direct Connect. Option C is correct because a Direct Connect Gateway allows you to connect multiple VPCs to a Direct Connect private virtual interface, and configuring an IPsec VPN over that private virtual interface encrypts traffic end-to-end, meeting the encryption requirement.

Exam trap

The trap here is that candidates often assume a private virtual interface alone provides encryption, but it does not—it only provides a private network path, and encryption must be explicitly added via IPsec or a similar protocol.

144
MCQhard

An organization has a VPC with public and private subnets. A NAT Gateway is deployed in a public subnet to allow instances in private subnets to access the internet. The security team notices that instances in a private subnet can reach the internet, but cannot initiate connections to an on-premises network connected via AWS Direct Connect. The on-premises network advertises a specific route. What is the most likely cause?

A.The security group assigned to the instances does not allow outbound traffic to the on-premises network.
B.The network ACL on the private subnet is blocking inbound traffic from the on-premises network.
C.The private subnet route table has a route for the on-premises CIDR pointing to the NAT Gateway.
D.The internet gateway is not attached to the VPC.
AnswerC

Route tables in the VPC control where each destination CIDR is sent. If the private subnet route table contains a route for the on-premises CIDR pointing to the NAT Gateway, traffic destined for on-premises is sent to the NAT Gateway, which is designed only for internet-bound traffic and cannot forward it across the Direct Connect or virtual private gateway. Because the route to the NAT Gateway overrides the propagated Direct Connect route, the instances cannot reach on-premises resources. This is the correct root cause.

Why this answer

The most likely cause is that the private subnet's route table has a route for the on-premises CIDR pointing to the NAT Gateway instead of the Direct Connect virtual private gateway (VGW) or transit gateway. A NAT Gateway only translates traffic to the internet — it cannot forward traffic to on-premises networks, so the route is misdirected and the connection fails.

Exam trap

SCS-C02 often tests the limitation that NAT Gateway only handles internet-bound traffic, tricking candidates into thinking a NAT route can reach on-premises — the correct next-hop for on-premises is always the VGW or TGW.

How to eliminate wrong answers

Option A is wrong because security groups are stateful and by default allow all outbound traffic; even if outbound were restricted, the symptom would be a timeout on all outbound traffic, not specifically on-premises. Option B is wrong because the issue is outbound initiation from the private subnet, not inbound from on-premises — and NACLs are stateless but the described symptom points to routing, not filtering. Option D is wrong because the instances can already reach the internet, which proves the IGW is attached and functioning.

145
MCQhard

A company has a VPC with multiple subnets across multiple Availability Zones. The security team wants to inspect all traffic between subnets for malicious activity. Which AWS service should be used?

A.VPC Flow Logs
B.AWS Network Firewall
C.AWS WAF
D.Security groups
AnswerB

AWS Network Firewall is the correct choice because it is a managed, stateful firewall that can inspect all traffic crossing subnet boundaries within the VPC, including traffic routed between application tiers or from a transit gateway. It combines stateless rule groups with stateful inspection engines (Suricata-compatible) to detect and block malicious payloads, protocol anomalies, and known threat signatures at wire speed. By forcing traffic through firewall endpoints in each Availability Zone and using route tables, you can enforce intrusion prevention and traffic filtering across the VPC, which aligns directly with the requirement for network-level threat detection and blocking.

Why this answer

AWS Network Firewall is a managed stateful firewall service that can inspect all traffic between subnets within a VPC, including east-west traffic, for malicious activity. It provides deep packet inspection (DPI) at Layers 3–7, supporting Suricata-compatible rules to detect and block threats like malware or intrusion attempts. This makes it the correct choice for the security team's requirement to inspect inter-subnet traffic.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (a logging service) with a security inspection service, or assume security groups can inspect traffic content, when in fact only AWS Network Firewall provides the required deep packet inspection for inter-subnet traffic.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs only capture metadata (source/destination IP, ports, protocol, packet count) and do not perform packet inspection or block malicious traffic; they are a logging tool, not a security enforcement point. Option C is wrong because AWS WAF is designed to protect web applications from common web exploits (e.g., SQL injection, XSS) by inspecting HTTP/HTTPS traffic at the application layer, and it cannot inspect non-web traffic or east-west traffic between subnets. Option D is wrong because security groups act as a virtual stateful firewall at the instance level, controlling inbound and outbound traffic based on allow rules, but they lack deep packet inspection capabilities and cannot detect or block malicious payloads within allowed traffic flows.

146
MCQeasy

A company uses Amazon CloudFront to distribute content from an S3 bucket. The security team wants to ensure that only CloudFront can access the S3 bucket. Which configuration should be used?

A.Set the bucket policy to allow all principals and rely on CloudFront to restrict access.
B.Configure the bucket policy to allow access only from CloudFront's IP addresses.
C.Create an Origin Access Identity (OAI) and grant it read access to the S3 bucket.
D.Use CloudFront trusted signers to restrict access to the S3 bucket.
AnswerC

An Origin Access Identity (OAI) is a dedicated CloudFront user identity that CloudFront uses to authenticate to S3 when fetching objects. By granting the OAI read permission (e.g., s3:GetObject) in the bucket policy and removing public access, the bucket becomes private and only requests authenticated as that OAI can succeed. This ensures direct S3 access by anonymous users is denied while CloudFront can still retrieve and distribute the content.

Why this answer

An Origin Access Identity (OAI) is a special CloudFront user that you can associate with a distribution, and then the S3 bucket policy can grant read access to that OAI, ensuring that only CloudFront can access the bucket. Option A is incorrect because allowing all principals is too permissive. Option B is incorrect because CloudFront IP addresses can change, so this is not a reliable method.

Option D is incorrect because trusted signers are used for signed URLs/cookies to control who can access content, not to restrict origin access.

147
MCQmedium

A company uses AWS CloudFormation to deploy infrastructure. The security team needs to ensure that all CloudFormation stacks include a specific tag with a value that complies with corporate policies. Which AWS service can enforce this requirement?

A.AWS Config
B.AWS Identity and Access Management (IAM)
C.AWS Service Catalog
D.AWS CloudTrail
AnswerC

AWS Service Catalog acts as a governed provisioning layer for CloudFormation templates, allowing administrators to create portfolios of approved products and attach tag options, stack constraints, and IAM roles to those products. When a user provisions a product, Service Catalog automatically applies the configured tag options to the stack and all resources within it, and can reject deployment if required tags are missing. This makes it the only option here that prevents non-compliant infrastructure from being created while still allowing users to deploy via CloudFormation.

Why this answer

AWS Service Catalog allows administrators to create and manage a portfolio of approved products (e.g., CloudFormation templates) with predefined constraints. One such constraint is a tag option, which enforces that every provisioned product (i.e., CloudFormation stack) includes a specific tag key and value, ensuring compliance with corporate policies. This is the only service among the options that can directly enforce mandatory tagging on CloudFormation stacks at provisioning time.

Exam trap

The trap here is that candidates often assume AWS Config can enforce tagging because it can detect and remediate non-compliant tags, but Config is a detective control, not a preventive one, and cannot block stack creation without the required tags.

How to eliminate wrong answers

Option A is wrong because AWS Config can detect and report non-compliant tags on existing resources via rules, but it cannot enforce tagging at the time of stack creation or prevent a stack from being created without the required tag. Option B is wrong because IAM can control who can create stacks via permissions, but it cannot enforce specific tag key-value pairs on the stacks themselves; IAM conditions can check for tags but not enforce their presence during CloudFormation stack creation. Option D is wrong because AWS CloudTrail is an auditing service that records API calls for governance and compliance, but it has no capability to enforce tagging requirements on CloudFormation stacks.

148
MCQhard

A company is designing a shared services VPC architecture with multiple VPCs connected via a transit gateway. The security engineer needs to ensure that all traffic between VPCs is inspected by a centralized firewall appliance deployed in the shared services VPC. What configuration is required?

A.Create VPC peering connections between each VPC and the shared services VPC.
B.Configure transit gateway route tables to route all inter-VPC traffic through the firewall appliance.
C.Use security groups to route traffic through the firewall.
D.Deploy a Gateway Load Balancer (GWLB) in the shared services VPC and register the firewall as a target.
AnswerB

A transit gateway with carefully designed route tables is the standard way to enforce centralized inspection: attach all VPCs to the transit gateway, then configure a route in each spoke VPC's propagation that sends inter-VPC destination CIDRs to the firewall appliance's elastic network interface in the shared services VPC. The firewall inspects and forwards the traffic back to the transit gateway, which delivers it to the destination VPC. This enables deterministic, high-availability routing through the security appliance.

Why this answer

A transit gateway can use separate route tables to control traffic flow. By configuring the transit gateway route tables to point the default route (0.0.0.0/0) or specific inter-VPC CIDR ranges to a network interface of the centralized firewall appliance in the shared services VPC, all traffic between VPCs is forced through the firewall for inspection. This design ensures that the firewall acts as a central inspection point without requiring VPC peering or complex routing.

Exam trap

The trap here is that candidates often confuse the role of a Gateway Load Balancer (GWLB) with routing, assuming that deploying a GWLB alone will automatically route traffic through the firewall, when in fact the transit gateway route tables must be explicitly configured to direct traffic to the GWLB endpoint or the firewall ENI.

How to eliminate wrong answers

Option A is wrong because VPC peering connections do not support transitive routing; each peering connection is a one-to-one link, so traffic between two peered VPCs cannot be routed through a third VPC without additional complex routing and would not force inspection through the firewall. Option C is wrong because security groups are stateful virtual firewalls that control traffic at the instance level based on rules, not routing; they cannot route traffic through a separate appliance or enforce traffic inspection paths. Option D is wrong because a Gateway Load Balancer (GWLB) is used to distribute traffic to a fleet of third-party appliances (e.g., firewalls) for inline inspection, but it does not by itself route inter-VPC traffic through the firewall; the transit gateway route tables must still be configured to direct traffic to the GWLB endpoint, making this an incomplete solution without the correct routing configuration.

149
MCQeasy

A company is designing a multi-tier web application. The web servers must be accessible from the internet, but the application servers must only be accessible from the web servers. Which AWS feature should be used to meet these requirements?

A.Use security groups with rules that allow inbound traffic to the web servers from the internet, and allow inbound traffic to the application servers only from the web server security group.
B.Use a VPC peering connection between the web tier and application tier subnets.
C.Use network ACLs to allow inbound traffic to the web tier from the internet and to the application tier only from the web tier.
D.Use a VPN connection to isolate the application tier from the web tier.
AnswerA

Security groups are stateful, instance-level firewalls that allow you to reference another security group as a source. By creating a web server security group that allows inbound TCP/443 and TCP/80 from 0.0.0.0/0, and an application server security group with an inbound rule whose source is the web server security group ID, traffic is permitted only from the specific EC2 instances associated with that web security group. This precisely satisfies the requirement without exposing the application tier directly to the internet, and it automatically accounts for new web instances that join the group.

Why this answer

Security groups are stateful, instance-level virtual firewalls in AWS. By allowing inbound internet traffic to the web server security group and then allowing inbound traffic to the application server security group only from the web server security group (referencing the SG as the source), you enforce that only web servers can reach application servers. This is the standard AWS pattern for tiered isolation.

Exam trap

SCS-C02 often tests the confusion between security groups (stateful, instance-level, SG references) and network ACLs (stateless, subnet-level, CIDR-only) — the requirement 'only from the web servers' points to SG referencing.

How to eliminate wrong answers

Option B is wrong because VPC peering connects VPCs, not tiers within a VPC — it does not provide the required access control between web and application subnets. Option C is wrong because network ACLs are stateless and subnet-level; while they can filter traffic, they cannot reference security groups as sources, making it harder to express 'only from the web tier' cleanly and requiring separate rules for return traffic. Option D is wrong because a VPN connection is for secure connectivity between on-premises networks and AWS, not for isolating tiers within a VPC.

150
Multi-Selecthard

Which THREE components are required to set up a client VPN for remote access to a VPC? (Choose 3.)

Select 3 answers
A.Client VPN endpoint
B.Virtual Private Gateway
C.Customer Gateway
D.Authorization rule
E.Target network association
AnswersA, D, E

The Client VPN endpoint is the central AWS server component that clients connect to; it is configured with a server certificate, authentication methods (such as mutual TLS, SAML, or Active Directory), and connection parameters like client CIDR ranges and DNS settings. It serves as the termination point for TLS-based VPN sessions and is a required component because without it, there is nothing for remote clients to establish a tunnel with. All other components (like target network associations and authorization rules) are configured on this endpoint.

Why this answer

A Client VPN endpoint is required as the entry point for remote clients to connect to the VPC. It manages authentication, encryption (using TLS 1.2), and routing for client connections. Without this component, there is no VPN server to accept and authenticate client traffic.

Exam trap

The trap here is confusing the components required for a site-to-site VPN (Virtual Private Gateway and Customer Gateway) with those needed for a client-based VPN, leading candidates to incorrectly select B or C instead of the correct client VPN-specific components.

← PreviousPage 2 of 4 · 245 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Infrastructure Security questions.