// amazon · scs-c02
amazon

// aws certified security - specialty scs-c02

SCS-C02

Prepare for the AWS Certified Security - Specialty exam with detailed questions and comprehensive study plans designed for security professionals.

307
questions
65
in exam
170m
duration
Choose your mode
at a glance

What you get

PDF US$10.00Sub US$10/mopass 750 (scaled score)

Free practice questions are available without payment; anyone can start practicing at no cost.

access options

PDF bank or platform subscription?

Two separate purchases: a one-time PDF for SCS-C02, or a monthly subscription for online practice and simulators across the platform. A subscription does not include the PDF download.

option / 01 · pdf file

Full question bank PDF

US$10.00· one-time
  • Full question bank as a print-ready PDF
  • Lifetime access to this exam only
  • Domain-tagged questions with explanations
  • Separate from online practice — buy once

option / 02 · subscription

All exams · practice & simulator

US$10.00· per month
  • Practice & exam simulator on every bank
  • All current and future exams included
  • Personal analytics and retention tools
  • Cancel anytime — no per-exam upsells
Subscribe for platform access
sample · 1 of 307Shuffle

See what's in the bank.

Infrastructure Securitymedium

15 votes · last validated recently

A company needs to use HTTPS when connecting to its web applications to meet compliance requirements. These web applications run in Amazon VPC on Amazon EC2 instances behind an Application Load Balancer (ALB). A security engineer wants to ensure that the load balancer will only accept connections over port 443, even if the ALB is mistakenly configured with an HTTP listener.

Which configuration steps should the security engineer take to accomplish this task?
A
Create a security group with a rule that denies inbound connections from 0.0.0.0/0 on port 80. Attach this security group to the ALB to overwrite more permissive rules from the ALB’s default security group.
0%
B
Create a network ACL that denies inbound connections from 0.0.0.0/0 on port 80. Associate the network ACL with the VPC’s internet gateway.
0%
C
Create a network ACL that allows outbound connections to the VPC IP range on port 443 only. Associate the network ACL with the VPC’s internet gateway.
0%
D
Create a security group with a single inbound rule that allows connections from 0.0.0.0/0 on port 443. Ensure this security group is the only one associated with the ALB.
100%
next →
04 · coverage

Exam domains

Incident Response12%
26 q
Logging and Monitoring20%
75 q
Infrastructure Security26%
76 q
Identity and Access Management20%
72 q
Data Protection22%
58 q
community questionsview all →

Questions from the community

Top-voted approved contributions for this exam, reviewed before landing in the bank.

// top community questionsview all →
0.0 · 0 reviews

What candidates say

no reviews yet

related

You may also like

More exams based on your interests.

Loading...

307 questions

PDF US$10.00 one-time·Sub US$10/mo

Practice