ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 258 - SCS-C01 discussion

Report
Export

Your company has defined a number of EC2 Instances over a period of 6 months. They want to know if any of the security groups allow unrestricted access to a resource. What is the best option to accomplish this requirement? Please select:

A.
Use AWS Inspector to inspect all the security Groups
Answers
A.
Use AWS Inspector to inspect all the security Groups
B.
Use the AWS Trusted Advisor to see which security groups have compromised access.
Answers
B.
Use the AWS Trusted Advisor to see which security groups have compromised access.
C.
Use AWS Config to see which security groups have compromised access.
Answers
C.
Use AWS Config to see which security groups have compromised access.
D.
Use the AWS CLI to query the security groups and then filter for the rules which have unrestricted accessd
Answers
D.
Use the AWS CLI to query the security groups and then filter for the rules which have unrestricted accessd
Suggested answer: B

Explanation:

The AWS Trusted Advisor can check security groups for rules that allow unrestricted access to a resource. Unrestricted access increases opportunities for malicious activity (hacking, denial-ofservice attacks, loss of data). If you go to AWS Trusted Advisor, you can see the details

Option A is invalid because AWS Inspector is used to detect security vulnerabilities in instances and not for security groups.

Option C is invalid because this can be used to detect changes in security groups but not show you security groups that have compromised access.

Option Dis partially valid but would just be a maintenance overhead

For more information on the AWS Trusted Advisor, please visit the below URL:

https://aws.amazon.com/premiumsupport/trustedadvisor/best-practices;The correct answer is: Use the AWS Trusted Advisor to see which security groups have compromisedaccess. Submit your Feedback/Queries to our Experts

asked 16/09/2024
Juan Carlos Yepez
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first