SCS-C03 · Question #114
A company runs an application on a fleet of Amazon EC2 instances. The company can remove instances from the fleet without risk to the application. All EC2 instances use the same security group named P
Sign in or unlock SCS-C03 to reveal the answer and full explanation for question #114. The question stem and answer options stay visible for context.
Question
A company runs an application on a fleet of Amazon EC2 instances. The company can remove instances from the fleet without risk to the application. All EC2 instances use the same security group named ProdFleet. Amazon GuardDuty and AWS Config are active in the company's AWS account. A security engineer needs to provide a solution that will prevent an EC2 instance from sending outbound traffic if GuardDuty generates a cryptocurrency finding event. The security engineer creates a new security group named Isolate that contains no outbound rules. The security engineer configures an AWS Lambda function to remove an EC2 instance from the ProdFleet security group and add it to the Isolate security group. Which additional step will meet this requirement?
Options
- AConfigure GuardDuty to directly invoke the Lambda function if GuardDuty generates a
- BConfigure an AWS Config rule that invokes the Lambda function if a CryptoCurrency:EC2/*
- CConfigure an Amazon EventBridge rule that invokes the Lambda function if GuardDuty generates
- DConfigure an Amazon EventBridge rule that invokes the Lambda function if AWS Config detects a
Unlock SCS-C03 to see the answer
You've previewed enough free SCS-C03 questions. Unlock SCS-C03 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.