SCS-C02 Infrastructure Security Practice Question
Which THREE are AWS best practices for securing an Amazon EC2 instance? (Choose three.)
⚠ Common exam trap
Test-takers frequently think instance metadata is a secure place to store credentials because it is convenient, but AWS explicitly warns against this due to the risk of exposure through SSRF or other instance-level vulnerabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use security groups to control inbound and outbound traffic.
Option C is correct because security groups act as stateful virtual firewalls at the instance/ENI level, and AWS best practice is to allow only the specific inbound ports (e.g., 22/443) and restrict outbound traffic needed by the workload rather than permitting all traffic. Option D is correct because disabling password-based SSH authentication and using SSH key pairs (or EC2 Instance Connect/SSM Session Manager) removes the risk of brute-force credential attacks and aligns with AWS guidance for Linux instance access. Option E is correct because AWS Systems Manager Patch Manager automates scanning and installation of OS and application security patches via patch baselines and maintenance windows, which is the recommended way to keep EC2 instances patched at scale. Option A is wrong because instance metadata is readable from the instance (and potentially via SSRF) and is not a secure secret store; credentials should go in AWS Secrets Manager or Systems Manager Parameter Store. Option B is wrong because launching in the default VPC is not a security best practice; AWS recommends custom VPCs with segmented subnets, least-privilege routing, and controlled internet exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store database credentials in instance metadata for easy retrieval.
Why it's wrong here
Instance metadata is readable by any process or SSRF on the instance, so credentials placed there are exposed rather than protected. Metadata suits retrieving the instance role's temporary credentials; storing static database passwords belongs in AWS Secrets Manager or Parameter Store with restricted access.
- ✗
Launch instances in the default VPC for easier network configuration.
Why it's wrong here
The default VPC ships with permissive routing and a public subnet layout, widening the instance's exposure surface rather than segmenting it. It is tempting because it removes subnet-creation effort, and it would suit throwaway lab instances where isolation is irrelevant, but production hardening requires custom VPCs with private subnets and controlled route tables.
- ✓
Use security groups to control inbound and outbound traffic.
Why this is correct
Security groups provide stateful, instance-level filtering of inbound and outbound traffic, allowing least-privilege rules per workload. This satisfies the EC2 hardening requirement by restricting which ports and sources can reach each instance, unlike subnet-level NACLs alone.
- ✓
Disable password-based authentication and use SSH key pairs instead.
Why this is correct
Disabling password authentication forces SSH to rely on cryptographic key pairs, eliminating brute-force credential guessing against the instance. This satisfies the EC2 access-control best practice by removing a weak, reusable secret from the authentication path.
- ✓
Regularly apply security patches using AWS Systems Manager Patch Manager.
Why this is correct
Patch Manager automates OS and application patching across EC2 fleets via SSM documents and maintenance windows, removing manual patch drift. This directly satisfies the best-practice requirement to remediate known vulnerabilities promptly, a core control for hardening instances against exploitation.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.