nerdexam
AmazonAmazon

SCS-C02 · Question #203

SCS-C02 Question #203: Real Exam Question with Answer & Explanation

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #203. The question stem and answer options stay visible for context.

Submitted by haruto_sh· Mar 6, 2026

Question

A company hosts an application on Amazon EC2 instances. The application also uses Amazon S3 and Amazon Simple Queue Service (Amazon SQS). The application is behind an Application Load Balancer (ALB) and scales with AWS Auto Scaling. The company's security policy requires the use of least privilege access, which has been applied to all existing AWS resources. A security engineer needs to implement private connectivity to AWS services. Which combination of steps should the security engineer take to meet this requirement? (Choose three.)

Options

  • AUse an interface VPC endpoint for Amazon SQS
  • BConfigure a connection to Amazon S3 through AWS Transit Gateway.
  • CUse a gateway VPC endpoint for Amazon S3.
  • DModify the IAM role applied to the EC2 instances in the Auto Scaling group to allow outbound
  • EModify the endpoint policies on all VPC endpoints. Specify the SQS and S3 resources that the
  • FConfigure a connection to Amazon S3 through AWS Firewall Manager

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full SCS-C02 PracticeBrowse All SCS-C02 Questions