SCS-C02 exam dumps

SCS-C02 practice question 232 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 232

Select 3

Your company is deploying an application on Amazon EC2 instances within an Auto Scaling group behind an Application Load Balancer (ALB). The application's compliance requirements mandate that all traffic to and from the instances must be encrypted. Additionally, access to the instances must be restricted to specific administrators via SSH. Which combination of measures should you implement to meet these requirements?

  1. A

    Configure the Application Load Balancer to use HTTPS listeners with an SSL/TLS certificate.

  2. B

    Enable Instance Connect for SSH access to the EC2 instances and restrict access via IAM policies.

  3. C

    Use a security group to allow inbound traffic to the EC2 instances only on port 443 from the ALB.

  4. D

    Install an SSL/TLS certificate directly on each EC2 instance to terminate HTTPS traffic.

  5. E

    Create a bastion host in a public subnet to manage SSH access to the EC2 instances.

Show answer and explanation

Correct answers: A, C, E

Explanation

To meet the requirements, you must ensure all traffic is encrypted and restrict administrative access to the EC2 instances. Configuring the ALB with HTTPS listeners enforces encryption for external traffic. Restricting inbound traffic on the instances to only port 443 from the ALB ensures secure communication. Lastly, using a bastion host facilitates controlled SSH access for administrators. Instance Connect and installing SSL/TLS certificates directly on instances are either insufficient or unnecessarily complex solutions in this scenario.

  • A. Correct.

    Correct: Configuring the Application Load Balancer to use HTTPS listeners with an SSL/TLS certificate ensures that all traffic to the ALB is encrypted.

  • B. Incorrect.

    Incorrect: While Instance Connect can help manage SSH access, it does not align with the requirement to restrict access to specific administrators using security controls.

  • C. Correct.

    Correct: Using a security group to allow inbound traffic only on port 443 from the ALB ensures that EC2 instances accept traffic only from the ALB and no other sources.

  • D. Incorrect.

    Incorrect: Installing an SSL/TLS certificate directly on each EC2 instance adds unnecessary complexity since the ALB already handles HTTPS termination.

  • E. Correct.

    Correct: Using a bastion host in a public subnet allows administrators to securely SSH into the instances while keeping the instances themselves in private subnets, meeting the access restriction requirement.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam