SCS-C02 exam dumps

SCS-C02 practice question 496 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 496

Select 2

Your company has deployed a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application uses Amazon RDS for its database and stores static content in an S3 bucket. As part of a security review, you are tasked with reducing the attack surface of the application. Which of the following actions should you take to minimize the attack surface? (Select TWO)

  1. A

    Restrict inbound traffic to the EC2 instances to only allow traffic from the ALB using security groups.

  2. B

    Configure a VPC endpoint for the S3 bucket and restrict S3 bucket access to this endpoint.

  3. C

    Enable public access to the Amazon RDS instance to allow remote database management.

  4. D

    Deploy the application in multiple AWS Regions to improve availability.

  5. E

    Disable unused ports and protocols on the EC2 instances' security groups.

Show answer and explanation

Correct answers: A, B

Explanation

Reducing the attack surface involves limiting access points and exposure to potential threats. Allowing only ALB traffic to the EC2 instances and restricting S3 bucket access via a VPC endpoint reduces the number of ways an attacker could exploit the resources. Other options either increase exposure (e.g., enabling public RDS access) or are unrelated to reducing the attack surface in this specific scenario.

  • A. Correct.

    Correct: Restricting inbound traffic to the EC2 instances to only allow traffic from the ALB ensures that only traffic routed through the ALB can reach the application, reducing the attack surface.

  • B. Correct.

    Correct: Configuring a VPC endpoint for the S3 bucket and restricting bucket access to this endpoint ensures that access to the bucket is limited to resources within the VPC, reducing exposure to external attacks.

  • C. Incorrect.

    Incorrect: Enabling public access to the Amazon RDS instance increases the attack surface, as it allows potential attackers to target the database directly.

  • D. Incorrect.

    Incorrect: Deploying the application in multiple regions improves availability but does not directly reduce the attack surface.

  • E. Incorrect.

    Incorrect: Disabling unused ports and protocols on EC2 instances' security groups is a good security practice but is not the most impactful action in this scenario compared to restricting traffic and using VPC endpoints.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam