SCS-C02 exam dumps

SCS-C02 practice question 265 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 265

Select 3

Your organization has set up a multi-tier application in AWS, consisting of a public-facing web tier in a public subnet and a private application tier in a private subnet. Users have reported that they are unable to access the application. As a security engineer, you need to analyze the network reachability issue. Which combination of actions should you take to identify and resolve the problem?

  1. A

    Use the VPC Reachability Analyzer to check if there is a valid network path between the public-facing web tier and the private application tier.

  2. B

    Run Amazon Inspector on the instances in the private application tier to identify network misconfigurations related to security group rules.

  3. C

    Check the security group rules for both the public-facing web tier and the private application tier to ensure they allow the necessary traffic.

  4. D

    Use the VPC Reachability Analyzer to verify if the route tables for the public and private subnets are correctly configured.

  5. E

    Inspect the Network ACLs associated with both the public and private subnets to confirm they are not blocking traffic.

Show answer and explanation

Correct answers: A, C, D

Explanation

In this scenario, diagnosing the network reachability issue involves verifying the network path between the components (using VPC Reachability Analyzer), ensuring security group rules permit the required traffic, and checking route table configurations. These tools and steps are specific to AWS's networking and security features and align with best practices for analyzing reachability issues.

  • A. Correct.

    Using the VPC Reachability Analyzer can help determine whether there is a valid network path between the public-facing web tier and the private application tier. This is a key step in diagnosing connectivity issues.

  • B. Incorrect.

    Amazon Inspector is primarily used to identify vulnerabilities and deviations from security best practices, such as unpatched software, rather than diagnosing network reachability issues.

  • C. Correct.

    Checking the security group rules is crucial to ensure that the necessary inbound and outbound traffic is allowed for both the web tier and the application tier.

  • D. Correct.

    The VPC Reachability Analyzer can also be used to verify the configuration of route tables, which are essential for establishing proper routing between subnets.

  • E. Incorrect.

    While inspecting Network ACLs is a good security practice, it is not the primary tool for diagnosing this specific network reachability issue.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam