SCS-C03 · Question #18
A company runs an internet-accessible application on several Amazon EC2 instances that run Windows Server. The company used an instance profile to configure the EC2 instances. A security team currentl
Sign in or unlock SCS-C03 to reveal the answer and full explanation for question #18. The question stem and answer options stay visible for context.
Question
A company runs an internet-accessible application on several Amazon EC2 instances that run Windows Server. The company used an instance profile to configure the EC2 instances. A security team currently accesses the VPC that hosts the EC2 instances by using an AWS Site-to- Site VPN tunnel from an on-premises office. The security team issues a policy that requires all external access to the VPC to be blocked in the event of a security incident. However, during an incident, the security team must be able to access the EC2 instances to obtain forensic information on the instances. Which solution will meet these requirements?
Options
- AInstall EC2 Instance Connect on the EC2 instances. Update the IAM policy for the IAM role to
- BInstall EC2 Instance Connect on the EC2 instances. Configure the instances to permit access to
- CCreate an EC2 Instance Connect endpoint in the VPC. Configure an appropriate security group to
- DCreate an EC2 Instance Connect endpoint in the VPC. Configure an appropriate security group to
Unlock SCS-C03 to see the answer
You've previewed enough free SCS-C03 questions. Unlock SCS-C03 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.