AWS Certified Security - Specialty SCS-C02 Exam QuestionsBrowse all questions from this exam

AWS Certified Security - Specialty SCS-C02 Exam - Question 95


The security engineer is managing a traditional three-tier web application that is running on Amazon EC2 instances. The application has become the target of increasing numbers of malicious attacks from the internet.

What steps should the security engineer take to check for known vulnerabilities and limit the attack surface? (Choose two.)

Show Answer
Correct Answer: BD

To check for known vulnerabilities, the security engineer should use Amazon Inspector, which is designed to periodically scan instances for vulnerabilities and compliance. To limit the attack surface, the engineer should review the application security groups to ensure that only the necessary ports are open, thereby minimizing the potential entry points for attacks.

Discussion

5 comments
Sign in to comment
AgboolaKunOptions: BD
Nov 27, 2024

Security groups for reducing the attack surface, Amazon Inspector to scan for and mitigate known vulnerabilities

oioiOptions: BD
Nov 24, 2024

correct

[Removed]Options: BD
Nov 25, 2024

B D. Moderator, please correct the default answers

AameeOptions: BD
Nov 26, 2024

B and D , self-explanatory..

c6ed25aOptions: BD
Mar 23, 2025

Security group and inspector is good answer