SCS-C02 exam dumps

SCS-C02 practice question 264 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 264

Select 2

Your organization is investigating connectivity issues between an Amazon EC2 instance in a private subnet and an external service hosted in another VPC that is connected via a VPC peering connection. As the Security Engineer, you must determine if the issue is related to network reachability. Which combination of AWS tools can you use to analyze the reachability and identify potential misconfigurations?

  1. A

    Use VPC Reachability Analyzer to trace the network path between the EC2 instance and the external service.

  2. B

    Use Amazon Inspector to scan the EC2 instance for potential vulnerabilities affecting connectivity.

  3. C

    Review the security group and network ACL configurations manually.

  4. D

    Use VPC Flow Logs to monitor network traffic between the EC2 instance and the external service.

  5. E

    Use AWS Config to check for compliance of security group rules.

Show answer and explanation

Correct answers: A, D

Explanation

AWS provides tools like VPC Reachability Analyzer and VPC Flow Logs to analyze network connectivity issues. VPC Reachability Analyzer is specifically designed to trace network paths and identify misconfigurations, while VPC Flow Logs help monitor traffic and identify packet drops. Combining these tools allows for an efficient analysis of network reachability. Other options, like Amazon Inspector and AWS Config, serve different purposes and are not suitable for this scenario.

  • A. Correct.

    Correct: VPC Reachability Analyzer can be used to trace the network path between two resources and identify any misconfigurations, such as missing routes or incorrect security group rules, that could block connectivity.

  • B. Incorrect.

    Incorrect: Amazon Inspector is used for identifying security vulnerabilities and compliance issues in EC2 instances, but it does not analyze network reachability.

  • C. Incorrect.

    Incorrect: Reviewing the security group and network ACL configurations manually can help, but it is not an AWS tool or service specifically designed for reachability analysis.

  • D. Correct.

    Correct: VPC Flow Logs can be used to monitor network traffic and verify whether packets are being allowed or denied at various points in the network path.

  • E. Incorrect.

    Incorrect: AWS Config is useful for compliance checks but does not provide a direct analysis of network reachability.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam