Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 100 Topic 11 Discussion

Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 100 Topic 11 Discussion

SCS-C02 Exam Topic 11 Question 100 Discussion:
Question #: 100
Topic #: 11

A company hosts an application on Amazon EC2 instances. The application also uses Amazon S3 and Amazon Simple Queue Service (Amazon SQS). The application is behind an Application Load Balancer (ALB) and scales with AWS Auto Scaling.

The company’s security policy requires the use of least privilege access, which has been applied to all existing AWS resources. A security engineer needs to implement private connectivity to AWS services.

Which combination of steps should the security engineer take to meet this requirement? (Select THREE.)


A.

Use an interface VPC endpoint for Amazon SQS


B.

Configure a connection to Amazon S3 through AWS Transit Gateway.


C.

Use a gateway VPC endpoint for Amazon S3.


D.

Modify the 1AM role applied to the EC2 instances in the Auto Scaling group to allow outbound traffic to the interface endpoints.


E.

Modify the endpoint policies on all VPC endpoints. Specify the SQS and S3 resources that the application uses


F.

Configure a connection to Amazon S3 through AWS Firewall Manager


Get Premium SCS-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.