exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 83 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 83
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A company has multiple VPCs in their account that are peered, as shown in the diagram. A Security Engineer wants to perform penetration tests of the Amazon
EC2 instances in all three VPCs.
How can this be accomplished? (Choose two.)

  • A. Deploy a pre-authorized scanning engine from the AWS Marketplace into VPC B, and use it to scan instances in all three VPCs. Do not complete the penetration test request form.
  • B. Deploy a pre-authorized scanning engine from the Marketplace into each VPC, and scan instances in each VPC from the scanning engine in that VPC. Do not complete the penetration test request form.
  • C. Create a VPN connection from the data center to VPC A. Use an on-premises scanning engine to scan the instances in all three VPCs. Complete the penetration test request form for all three VPCs.
  • D. Create a VPN connection from the data center to each of the three VPCs. Use an on-premises scanning engine to scan the instances in each VPC. Do not complete the penetration test request form.
  • E. Create a VPN connection from the data center to each of the three VPCs. Use an on-premises scanning engine to scan the instances in each VPC. Complete the penetration test request form for all three VPCs.
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
josellama2000
Highly Voted 3 years, 8 months ago
B & D are correct. A is incorrect. Transitive Peering is not supported. B cant access C. C is incorrect. Edge to Edge routing is not supported E is incorrect. you dont need / cant to complete the penetration test request form edge-to-edge routing in a cloud For example, you have a corporate network connected to one Amazon VPC (A). That VPC is also connected to another VPC (B). Routing from your corporate network through VPC A to reach VPC B is an example of edge to edge routing (and it's not allowed).
upvoted 44 times
ugreenhost
3 years, 8 months ago
D? dont need to complete the penetration test form??
upvoted 1 times
...
exams
3 years, 8 months ago
Agree.. B &D are correct
upvoted 3 times
...
EricJason
3 years, 8 months ago
why you don't need to raise the pen test request in D?
upvoted 1 times
EricJason
3 years, 8 months ago
ah.. sorry just realized pen test to EC2 doesn't need a pre-approval. so B D should be right. https://aws.amazon.com/security/penetration-testing/
upvoted 7 times
...
...
...
Raj1510
Highly Voted 3 years, 7 months ago
AWS Permitted Services for security assessments or penetration tests against their AWS infrastructure without prior approval for 8 services, listed as “Permitted Services.” Amazon EC2 instances, NAT Gateways, and Elastic Load Balancers Amazon RDS Amazon CloudFront Amazon Aurora Amazon API Gateways AWS Lambda and Lambda Edge functions Amazon Lightsail resources Amazon Elastic Beanstalk environments https://aws.amazon.com/security/penetration-testing/ so , C and E : Ruled out A : No transitive peering supported via VPC B and D correct
upvoted 15 times
...
Raphaello
Most Recent 1 year, 3 months ago
Selected Answer: BD
BD are the correct answers here. D cause you do not need to submit any request for pen tests against EC2. https://aws.amazon.com/security/penetration-testing
upvoted 1 times
...
Raphaello
1 year, 3 months ago
Selected Answer: BD
BD are the correct answers here. D cause you do not need to submit any request for pen tests against EC2. https://aws.amazon.com/security/penetration-testing
upvoted 1 times
...
brpjp
1 year, 5 months ago
Given answers are correct: You must require to complete Penetration Testing request to perform any pen test on EC2 instances or VPCs. Only for AWS authorized partner - pentest permission is not required. Also, as per ChatGPT Edge-to-Edge Routing: VPC peering enables communication between VPCs as if they are on the same network. This includes edge-to-edge routing, allowing traffic to flow directly between the peered VPCs.
upvoted 1 times
...
sprial02
1 year, 9 months ago
Since VPC A is connected to B and C as a peer, you can perform the penetration test by connecting to the VPN on your premises, and you must complete the penetration test form. I think it's C and E.
upvoted 1 times
sprial02
1 year, 9 months ago
By the way, the meaning of pcx-12121212 is vpc peering, which means that VPC A communicates with B, C, and so on. So I think C,E is correct!
upvoted 1 times
...
...
sandromechi
1 year, 10 months ago
Selected Answer: BD
Think: A - Incorrect because cross peering is not supported B - CORRECT - because it is technical possible (there are a clue here) C - Incorrect - Due to the same reason of A. D - CORRECT - Because it's technical possible (It connects with clue from B) E - Incorrect - Despite the fact of it's technical possible, it doesn't connect with B. Why? Once we don't have to complete the request form (as maentioned on B), we can assume that pen test doesn't include command&control comands. So, between D and E, we can securely choose D based on B. That is it for me!
upvoted 1 times
...
OCHT
1 year, 11 months ago
Selected Answer: BE
AWS does allow penetration testing of its services, but it requires users to request permission via a penetration testing form before conducting such tests to ensure the safety and integrity of its services. For penetration testing, AWS customers can deploy pre-authorized scanning engines from AWS Marketplace, but these should be deployed into each VPC because VPC peering connections are not transitive. Option B suggests using a scanning engine from the AWS Marketplace in each VPC, allowing for targeted scanning within each environment. This approach would not require the completion of a penetration testing request form, as these Marketplace solutions are pre-approved for such use. Option E suggests setting up a VPN connection from the on-premises data center to each VPC, which would then use an on-premises scanning engine to carry out the penetration testing. This approach requires the completion of the penetration testing request form because it involves an external, potentially non-approved, scanning engine.
upvoted 1 times
...
phadidi
2 years, 3 months ago
If A mentioned VPC A instead of VPC B, could it be a correct answer? In other words, could VPC A, being able to reach out to VPC B and VPC C, be able to complete the scanning process? I think that would be useful to know in day-to-day experience with AWS.
upvoted 2 times
...
hubekpeter
2 years, 5 months ago
Selected Answer: BD
You don't need to submit pen test request form for EC2s anymore. - https://aws.amazon.com/security/penetration-testing/ And you can't use transitive peering. Therefore B&D.
upvoted 1 times
...
sakibmas
2 years, 6 months ago
Selected Answer: BD
Customer Service Policy for Penetration Testing Permitted Services Amazon EC2 instances, NAT Gateways, and Elastic Load Balancers Amazon RDS Amazon CloudFront Amazon Aurora Amazon API Gateways AWS Fargate AWS Lambda and Lambda Edge functions Amazon Lightsail resources Amazon Elastic Beanstalk environments Prohibited Activities DNS zone walking via Amazon Route 53 Hosted Zones Denial of Service (DoS), Distributed Denial of Service (DDoS), Simulated DoS, Simulated DDoS (These are subject to the DDoS Simulation Testing policy) Port flooding Protocol flooding Request flooding (login request flooding, API request flooding)
upvoted 1 times
...
sapien45
2 years, 8 months ago
Selected Answer: BD
AWS Permitted Services for security assessments or penetration tests against their AWS infrastructure without prior approval for 8 services, listed as “Permitted Services.” Amazon EC2 instances, NAT Gateways, and Elastic Load Balancers https://aws.amazon.com/security/penetration-testing/ No transitive peering supported via VPC peering
upvoted 2 times
...
dcasabona
2 years, 10 months ago
Selected Answer: BD
B and D in my option.
upvoted 1 times
...
abdullah78658
2 years, 10 months ago
Selected Answer: BD
ARE CORRECT, NO NEED FOR REQUEST
upvoted 1 times
...
ceros399
3 years, 2 months ago
Selected Answer: BD
B and D: as you don't need to submit a pen-test request for EC2 instances!
upvoted 1 times
...
Radhaghosh
3 years, 4 months ago
For EC2 Pen test you don't need a request to be placed. Again VPC peering doesn't support edge routing and transitive peering. This left B & D as correct options
upvoted 1 times
...
sanjaym
3 years, 6 months ago
Ans: BD 100%
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...