Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon Exam SCS-C02 Topic 2 Question 50 Discussion

Actual exam question for Amazon's SCS-C02 exam
Question #: 50
Topic #: 2
[All SCS-C02 Questions]

[Logging and Monitoring]

A company hosts an application on Amazon EC2 instances. The application also uses Amazon S3 and Amazon Simple Queue Service (Amazon SQS). The application is behind an Application Load Balancer (ALB) and scales with AWS Auto Scaling.

The company's security policy requires the use of least privilege access, which has been applied to all existing AWS resources. A security engineer needs to implement private connectivity to AWS services.

Which combination of steps should the security engineer take to meet this requirement? (Select THREE.)

Show Suggested Answer Hide Answer
Suggested Answer: A, C, E

The correct answer is A, C, and E because they provide the most secure and efficient way to implement private connectivity to AWS services. Using interface VPC endpoints for Amazon SQS and gateway VPC endpoints for Amazon S3 allows the application to access these services without using public IP addresses or internet gateways. Modifying the endpoint policies on all VPC endpoints enables the security engineer to specify the SQS and S3 resources that the application uses and restrict access to other resources.

The other options are incorrect because they do not provide private connectivity to AWS services or they introduce unnecessary complexity or cost. Option B is incorrect because AWS Transit Gateway is used to connect multiple VPCs and on-premises networks, not to connect to AWS services. Option D is incorrect because modifying the IAM role applied to the EC2 instances is not sufficient to allow outbound traffic to the interface endpoints. The security group and route table associated with the interface endpoints also need to be configured. Option F is incorrect because AWS Firewall Manager is used to centrally manage firewall rules across multiple accounts and resources, not to connect to AWS services.


Contribute your Thoughts:

Hershel
2 days ago
I remember practicing a question similar to this where we had to choose between interface and gateway endpoints. I think SQS needs an interface endpoint, right?
upvoted 0 times
...
Ramonita
8 days ago
I think using a gateway VPC endpoint for Amazon S3 is definitely one of the steps, but I'm not sure about the others.
upvoted 0 times
...
Stephanie
13 days ago
Modifying the endpoint policies on the VPC endpoints to specify the SQS and S3 resources the application uses is a good idea too. That will help enforce the least privilege access requirement.
upvoted 0 times
...
Leota
18 days ago
The Transit Gateway and Firewall Manager options don't seem relevant to this specific scenario. I think we can safely eliminate those.
upvoted 0 times
...
Kimi
23 days ago
I'm pretty confident that using interface VPC endpoints for Amazon SQS and a gateway VPC endpoint for Amazon S3 are the right approaches here. We'll also need to modify the IAM role to allow outbound traffic to the interface endpoints.
upvoted 0 times
...
Magda
28 days ago
Okay, let's think this through step-by-step. We need to implement private connectivity to the AWS services, and the company's security policy requires least privilege access.
upvoted 0 times
...
Desire
1 month ago
This question seems straightforward, but I want to make sure I understand the requirements correctly before selecting the answers.
upvoted 0 times
...

Save Cancel