{"id":217,"date":"2021-01-10T10:30:16","date_gmt":"2021-01-10T10:27:50","guid":{"rendered":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/aws-certified-security-specialty-scs-c01-question208\/"},"modified":"2021-01-10T10:30:36","modified_gmt":"2021-01-10T10:30:36","slug":"aws-certified-security-specialty-scs-c01-question208","status":"publish","type":"post","link":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/aws-certified-security-specialty-scs-c01-question208\/","title":{"rendered":"AWS Certified Security &#8211; Specialty SCS-C01 &#8211; Question208"},"content":{"rendered":"<div class=\"question\">A company wants to deploy an application in a private VPC that will not be connected to the internet. The company\u2019s security team will not allow bastion hosts or methods using SSH to log in to Amazon EC2 instances. The application team plans to use AWS Systems Manager Session Manager to connect to and manage the EC2 instances.<br \/>\nWhich combination of steps should the security team take? (Choose three.) <br \/><strong><br \/>A.<\/strong> Make sure the Systems Manager Agent is installed and running on all EC2 instances inside the VPC. <br \/><strong>B.<\/strong> Ensure the IAM role attached to the EC2 instances in the VPC allows access to Systems Manager. <br \/><strong>C.<\/strong> Create an SCP that prevents the creation of SSH key pairs. <br \/><strong>D.<\/strong> Launch a NAT gateway in the VPC. Update the routing policies to forward traffic to this NAT gateway. <br \/><strong>E.<\/strong> Ensure proper VPC endpoints are in place for Systems Manager and Amazon EC2. <br \/><strong>F.<\/strong> Ensure the VPC has a transit gateway attachment. Update the routing policies to forward traffic to this transit gateway.<\/div>\n<p><\/p>\n<style> .hidden-div{ display:none } <\/style>\n<p>\t\t\t\t\t\t\t<button onclick=\"getElementById('hidden-div').style.display = 'block'\"> Show Answer <\/button> <button onclick=\"getElementById('hidden-div').style.display = 'none'\">Hide Answer<\/button><\/p>\n<div class=\"hidden-div\" id=\"hidden-div\"><span style=\"\"><\/p>\n<div class=\"answer\">Correct Answer: <strong>ABE<\/strong><\/div>\n<p><strong>Explanation:<\/strong> <\/p>\n<div class=\"explanation\">\nReference: <a href=\"https:\/\/aws.amazon.com\/blogs\/mt\/replacing-a-bastion-host-with-amazon-ec2-systems-manager\/\" title=\"External link\" rel=\"nofollow noopener\" target=\"_blank\">https:\/\/aws.amazon.com\/blogs\/mt\/replacing-a-bastion-host-with-amazo&#8230;<\/a><\/div>\n<p><\/strong><\/span> <\/div>\n","protected":false},"excerpt":{"rendered":"<p>A company wants to deploy an application in a private VPC that will not be connected to the internet. The company\u2019s security team will not allow bastion hosts or methods using SSH to log in to Amazon EC2 instances. The application team plans to use AWS Systems Manager Session Manager to connect to and manage [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3,210],"class_list":["post-217","post","type-post","status-publish","format-standard","hentry","category-aws-certified-security-specialty-scs-c01","tag-aws-certified-security-specialty-scs-c01","tag-question-208"],"_links":{"self":[{"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/posts\/217","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/comments?post=217"}],"version-history":[{"count":1,"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/posts\/217\/revisions"}],"predecessor-version":[{"id":269,"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/posts\/217\/revisions\/269"}],"wp:attachment":[{"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/media?parent=217"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/categories?post=217"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/exampracticetests.com\/aws\/Security-Specialty_SCS-C01\/wp-json\/wp\/v2\/tags?post=217"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}