SCS-C02 exam dumps

SCS-C02 practice question 210 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 210

Select 3

Your organization is building a secure architecture for a new web application hosted on Amazon EC2 instances behind an Application Load Balancer (ALB). The application handles sensitive user data, and your team must comply with security best practices to protect this data. Which of the following actions should be taken to secure the application? (Select TWO.)

  1. A

    Enable AWS WAF on the Application Load Balancer to block malicious traffic.

  2. B

    Store sensitive user data in an Amazon S3 bucket with public read permissions for easy access.

  3. C

    Use AWS Certificate Manager (ACM) to provision and manage an SSL/TLS certificate for encrypting data in transit.

  4. D

    Grant EC2 instances direct internet access to allow unrestricted outbound traffic for faster updates.

  5. E

    Enable encryption at rest for sensitive data stored in Amazon RDS.

Show answer and explanation

Correct answers: A, C, E

Explanation

Securing a web application involves implementing multiple layers of protection. Enabling AWS WAF on the ALB protects the application from web-based attacks. Using ACM to manage SSL/TLS certificates ensures secure transmission of sensitive data. Additionally, encrypting data at rest in Amazon RDS safeguards data from unauthorized access. Publicly exposing sensitive data or allowing unrestricted internet access to EC2 instances violates security best practices and should be avoided.

  • A. Correct.

    This is correct because enabling AWS WAF on the ALB helps block common web exploits, such as SQL injection or cross-site scripting (XSS), improving security.

  • B. Incorrect.

    This is incorrect. Public read permissions on an S3 bucket containing sensitive data violate security best practices and could lead to data breaches.

  • C. Correct.

    This is correct. Using ACM to manage SSL/TLS certificates ensures secure data transmission by encrypting data in transit between clients and the ALB.

  • D. Incorrect.

    This is incorrect. Granting unrestricted internet access to EC2 instances violates the principle of least privilege and poses a security risk.

  • E. Correct.

    This is correct. Encrypting data at rest in Amazon RDS ensures that sensitive information is protected from unauthorized access at the storage level.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam