SCS-C02 Infrastructure Security Practice Question
Which TWO actions should a security engineer take to protect an Amazon EC2 instance from unauthorized access? (Choose two.)
⚠ Common exam trap
Test-takers frequently think placing an instance in a public subnet with security groups is sufficient, but the exam expects you to recognize that a private subnet with a bastion host is a more secure architecture for administrative access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure security groups to allow only necessary inbound traffic.
Security groups act as a virtual firewall for EC2 instances, controlling inbound and outbound traffic at the instance level. By configuring security groups to allow only necessary inbound traffic (Option C), you follow the principle of least privilege, reducing the attack surface. This is a fundamental security best practice for protecting EC2 instances from unauthorized access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Place the instance in a public subnet and rely solely on security groups.
Why it's wrong here
Placing the instance in a public subnet directly exposes it to the internet via an internet gateway, making it reachable by anyone who can guess or discover its public IP. Relying solely on security groups is not sufficient because they only filter traffic to that specific instance and do not provide network-level segmentation; any permitted port becomes an attack vector. A more secure design would place the instance in a private subnet with a bastion host for administrative access.
- ✗
Disable termination protection so the instance can be easily terminated if compromised.
Why it's wrong here
Disabling termination protection removes the EC2 attribute that prevents accidental termination through the console or API, which actually increases the risk of losing the instance and its data. This setting does not control who can access the instance or what actions they can perform, so it cannot mitigate unauthorized access or compromise. In fact, keeping termination protection enabled helps preserve the instance for forensic analysis if it is breached.
- ✓
Configure security groups to allow only necessary inbound traffic.
Why this is correct
Security groups act as a stateful virtual firewall, evaluating inbound traffic and allowing only the rules you explicitly define. By restricting inbound traffic to only necessary ports and source IP ranges, you minimize the attack surface and block unused services from being probed. This least-privilege approach is a fundamental security control that should be applied in addition to network segmentation, not as a substitute for it.
- ✓
Place the instance in a private subnet and use a bastion host for administrative access.
Why this is correct
Placing the instance in a private subnet ensures it has no direct route to an internet gateway, so it cannot receive unsolicited inbound traffic from the internet. Administrative access is then provided only through a bastion host in a public subnet, which serves as a single, controlled entry point that can be hardened, monitored, and restricted to specific IPs. This network segmentation is a core defense-in-depth tactic that protects the instance even if security groups are misconfigured.
- ✗
Enable detailed billing to monitor instance usage.
Why it's wrong here
Enabling detailed billing or AWS Cost Explorer provides cost and usage data, not security monitoring or access control. This feature cannot detect unauthorized login attempts, block malicious traffic, or alert on suspicious API activity. To protect an instance, you would instead rely on tools such as CloudTrail, VPC Flow Logs, and GuardDuty for visibility and threat detection.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.