SCS-C02 exam dumps

SCS-C02 practice question 12 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 12

Select 3

An organization has deployed several web applications on Amazon EC2 instances behind an Application Load Balancer (ALB). The organization wants to ensure that all HTTP traffic to the applications is encrypted and adheres to compliance requirements. Additionally, they want to restrict certain clients from accessing the applications based on their IP addresses. Which combination of actions should the organization take to meet these requirements?

  1. A

    Configure the ALB to use an HTTPS listener with an SSL/TLS certificate.

  2. B

    Use a Web Application Firewall (WAF) with an ALB to block requests from specific IP addresses.

  3. C

    Enable VPC Flow Logs to monitor incoming traffic and restrict unauthorized IPs.

  4. D

    Redirect all HTTP requests to HTTPS using an ALB listener rule.

  5. E

    Use AWS Shield Advanced to protect against DDoS attacks and restrict IP addresses.

Show answer and explanation

Correct answers: A, B, D

Explanation

To meet the requirements, the organization must ensure traffic is encrypted using HTTPS, which can be achieved by configuring an HTTPS listener on the ALB. To restrict access from specific IP addresses, AWS WAF rules can be applied to block those IPs. Additionally, redirecting HTTP to HTTPS ensures that all traffic to the applications is encrypted. VPC Flow Logs and AWS Shield Advanced are useful for monitoring and DDoS protection but do not directly address the requirements in this scenario.

  • A. Correct.

    Correct: Configuring the ALB to use an HTTPS listener ensures that all traffic is encrypted using SSL/TLS, meeting the compliance requirement for securing communication.

  • B. Correct.

    Correct: AWS WAF can block requests from specific IP addresses, helping to restrict access based on the organization's requirements.

  • C. Incorrect.

    Incorrect: While VPC Flow Logs provide visibility into network traffic, they do not actively restrict or block IP addresses. This is more of a monitoring tool than an enforcement mechanism.

  • D. Correct.

    Correct: Redirecting all HTTP requests to HTTPS ensures that even if users attempt to access the web applications over HTTP, they are securely redirected to HTTPS, maintaining compliance and security.

  • E. Incorrect.

    Incorrect: AWS Shield Advanced primarily focuses on protecting against DDoS attacks and does not provide functionality to restrict specific IP addresses.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam