A security engineer manages a traditional three-tier web application running on Amazon EC2 instances. The application is facing an increasing number of internet-based attacks. Which actions should the security engineer take to identify known vulnerabilities and reduce the exposed attack surface? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Review security groups to ensure that only required ports are open., Use Amazon Inspector to perform periodic vulnerability assessments on the backend instances..
Why this is the answer
Reviewing security groups to ensure only required ports are open directly reduces the exposed attack surface by limiting network access to the EC2 instances. This minimizes potential entry points for attackers. Using Amazon Inspector to perform periodic vulnerability assessments helps identify known vulnerabilities in the application and its underlying infrastructure, allowing the engineer to patch or mitigate them. This directly addresses the need to identify known vulnerabilities. AWS Certificate Manager (ACM) and Elastic Load Balancing (ELB) for SSL/TLS termination enhance security by encrypting data in transit, but they don't directly identify known vulnerabilities or reduce the exposed attack surface of the EC2 instances themselves. AWS Key Management Service (KMS) is for encryption key management, not for encrypting client-to-server traffic directly, nor does it identify vulnerabilities or reduce the attack surface in this context.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed