AmazonAmazon Security Specialty SCS-C02 ·EN ·Updated 24 Jul 2026

A security engineer is building an Amazon EC2 isolation procedure for incident response. The goal is to block all inbound and outbound traffic to a target instance except access by the forensics team. Each instance has its own security group, and multiple instances share the same subnet. During testing, the engineer opens an SSH session to the target, then removes existing security group rules and adds rules to allow the forensics team on port 22. The existing SSH session remains active, although ICMP to the public IP is blocked. What should the engineer do to fully isolate the instance?

Choose an answer

Tap an option to check your answer.

Pass your exam — without the endless answer hunt

Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.

Pass your exam faster No card needed
✓ Verified by ExamRoll editorial · Updated 24 July 2026 · Source: official academy
All-in-one access

One subscription. Every exam.

Every plan unlocks unlimited answer search, practice tests, AI explanations, and the full resource library — in 20+ languages.

Monthly
24.87
Just €0.83/day
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

Best value
12 months
179.87
Just €0.49/daySave 40%
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

✓ Free plan included · ✓ Cancel anytime · ✓ All plans unlock the full product