SCS-C02 exam dumps

SCS-C02 practice question 267 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 267

Select 2

Your company has deployed a three-tier web application in AWS. You are tasked with verifying the network reachability between an EC2 instance in the application tier and an RDS database in the database tier. Additionally, you must ensure the security posture of the EC2 instance against known vulnerabilities. Which combination of AWS services should you use to achieve this?

  1. A

    Use VPC Reachability Analyzer to verify the network reachability between the EC2 instance and the RDS database.

  2. B

    Use Amazon Inspector to scan the EC2 instance for vulnerabilities and security issues.

  3. C

    Use AWS Trusted Advisor to assess the reachability between the EC2 instance and the RDS database.

  4. D

    Use AWS Config to validate the security group rules for the EC2 instance.

  5. E

    Use Network Access Analyzer to confirm compliance of the EC2 instance's network path.

Show answer and explanation

Correct answers: A, B

Explanation

To verify network reachability between the EC2 instance and the RDS database, VPC Reachability Analyzer is the ideal tool because it simulates network paths and identifies potential connectivity issues. To ensure the security posture of the EC2 instance, Amazon Inspector is used to scan for known vulnerabilities and compliance misconfigurations. Together, these services address both network reachability and security concerns effectively.

  • A. Correct.

    Correct. VPC Reachability Analyzer is specifically designed to analyze and verify network reachability between two resources, such as an EC2 instance and an RDS database.

  • B. Correct.

    Correct. Amazon Inspector is a service used to identify vulnerabilities and security issues in EC2 instances and other supported resources.

  • C. Incorrect.

    Incorrect. While AWS Trusted Advisor provides recommendations for cost optimization, security, and performance, it does not analyze detailed network reachability.

  • D. Incorrect.

    Incorrect. AWS Config tracks configuration changes and compliance of resources but does not directly analyze network reachability or vulnerabilities.

  • E. Incorrect.

    Incorrect. Network Access Analyzer is suitable for compliance checks on network paths but is not designed for specific reachability analysis or vulnerability scanning.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam