AmazonAmazon Security Specialty SCS-C02 ·EN ·Updated 24 Jul 2026

A security engineer at a large enterprise manages a data processing application used by 1,500 subsidiary companies. The parent company and all subsidiaries use AWS. The application listens on TCP port 443 and runs on Amazon EC2 behind a Network Load Balancer (NLB). For compliance, the application must be accessible only to subsidiaries and must not be exposed to the public internet. The engineer has received the public and private CIDR ranges for each subsidiary. Which solution should the engineer implement to enforce these access restrictions?

Choose an answer

Tap an option to check your answer.

Pass your exam — without the endless answer hunt

Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.

Pass your exam faster No card needed
✓ Verified by ExamRoll editorial · Updated 24 July 2026 · Source: official academy
All-in-one access

One subscription. Every exam.

Every plan unlocks unlimited answer search, practice tests, AI explanations, and the full resource library — in 20+ languages.

Monthly
24.87
Just €0.83/day
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

Best value
12 months
179.87
Just €0.49/daySave 40%
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

✓ Free plan included · ✓ Cancel anytime · ✓ All plans unlock the full product