nerdexam
Amazon

SCS-C02 · Question #373

Your company has a set of EC2 Instances defined in AWS. They need to ensure that all traffic packets are monitored and inspected for any security threats. How can this be achieved? Choose 2 answers…

The correct answer is A. Use a host based intrusion detection system B. Use a third party firewall installed on a central EC2 instance. If you want to inspect the packets themselves, then you need to use custom based software A diagram representation of this is given in the AWS Security best practices Option C is invalid because VPC Flow logs cannot conduct packet inspection.

Submitted by thandi_sa· Mar 6, 2026Infrastructure Security

Question

Your company has a set of EC2 Instances defined in AWS. They need to ensure that all traffic packets are monitored and inspected for any security threats. How can this be achieved? Choose 2 answers from the options given below

Exhibit

SCS-C02 question #373 exhibit

Options

  • AUse a host based intrusion detection system
  • BUse a third party firewall installed on a central EC2 instance
  • CUse VPC Flow logs
  • DUse Network Access control lists logging

How the community answered

(41 responses)
  • A
    83% (34)
  • C
    12% (5)
  • D
    5% (2)

Explanation

If you want to inspect the packets themselves, then you need to use custom based software A diagram representation of this is given in the AWS Security best practices Option C is invalid because VPC Flow logs cannot conduct packet inspection.

Topics

#host-based IDS#intrusion detection#traffic inspection#network security

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice