ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 369 - SCS-C01 discussion

Report
Export

Your company has been using AWS for hosting EC2 Instances for their web and database applications.

They want to have a compliance check to see the following

Whether any ports are left open other than admin ones like SSH and RDP Whether any ports to the database server other than ones from the web server security group are open Which of the following can help achieve this in the easiest way possible. You don't want to carry out an extra configuration changes?

Please select:

A.
AWS Config
Answers
A.
AWS Config
B.
AWS Trusted Advisor
Answers
B.
AWS Trusted Advisor
C.
AWS Inspector D.AWSGuardDuty
Answers
C.
AWS Inspector D.AWSGuardDuty
Suggested answer: B

Explanation:

Trusted Advisor checks for compliance with the following security recommendations:

Limited access to common administrative ports to only a small subset of addresses. This includes ports 22 (SSH), 23 (Telnet) 3389 (RDP), and 5500 (VNQ. Limited access to common database ports. This includes ports 1433 (MSSQL Server), 1434 (MSSQL Monitor), 3306 (MySQL), Oracle (1521) and 5432 (PostgreSQL). Option A is partially correct but then you would need to write custom rules for this. The AWS trusted advisor can give you all o these checks on its dashboard Option C is incorrect. Amazon Inspector needs a software agent to be installed on all EC2 instances that are included in th. assessment target, the security of which you want to evaluate with Amazon Inspector. It monitors the behavior of the EC2 instance on which it is installed, including network, file system, and process activity, and collects a wide set of behavior and configuration data (telemetry), which it then passes to the Amazon Inspector service. Our question's requirement is to choose a choice that is easy to implement. Hence Trusted Advisor is more appropriate for this ) question. Options D is invalid because this service dont provide these details.

For more information on the Trusted Advisor, please visit the following URL

https://aws.amazon.com/premiumsupport/trustedadvisor>The correct answer is: AWS Trusted Advisor Submit your Feedback/Queries to our Experts

asked 16/09/2024
Geetanjali Singh
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first