SCS-C02 exam dumps

SCS-C02 practice question 213 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 213

Select 2

Your company has deployed a web application hosted on Amazon EC2 instances in a VPC. These instances are behind an Application Load Balancer (ALB). The application needs to allow inbound traffic only from specific IP ranges while ensuring no unintended access is allowed. Additionally, to comply with company policy, you must ensure that any changes to security rules for inbound and outbound traffic are logged. Which combination of approaches should you use to secure the environment?

  1. A

    Use security groups associated with the EC2 instances to allow inbound traffic only from the specific IP ranges

  2. B

    Use a network ACL to block all inbound traffic and only allow the specific IP ranges to pass through

  3. C

    Enable AWS CloudTrail logs to monitor changes made to the security group and network ACL configurations

  4. D

    Use AWS Network Firewall to block all traffic except from the specific IP ranges at the VPC level

  5. E

    Attach a WAF (Web Application Firewall) to the ALB to block traffic from unwanted IP ranges

Show answer and explanation

Correct answers: A, C

Explanation

To secure the environment, security groups should be used to allow traffic only from the specific IP ranges, as they provide stateful and granular control. AWS CloudTrail should be enabled to log any changes to the security rules for compliance purposes. While network ACLs and AWS Network Firewall could be used, they are not necessary or as efficient for this specific scenario, and WAF is not designed for managing IP-based access control.

  • A. Correct.

    Correct: Security groups are stateful and allow fine-grained control over inbound and outbound traffic to EC2 instances. They are ideal for allowing traffic from specific IP ranges.

  • B. Incorrect.

    Incorrect: While network ACLs can filter traffic, they are stateless and less flexible compared to security groups for this scenario. Security groups are the preferred mechanism for EC2 instance traffic control.

  • C. Correct.

    Correct: AWS CloudTrail can log changes to security rules, providing an audit trail to meet compliance requirements.

  • D. Incorrect.

    Incorrect: AWS Network Firewall is not necessary here because the requirement is limited to controlling traffic to the EC2 instances, which can be effectively managed using security groups.

  • E. Incorrect.

    Incorrect: AWS WAF is designed for protecting web applications against specific threats like SQL injection or cross-site scripting, not for managing traffic from specific IP ranges in this use case.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam