Câu 51: AWS Certified Security - Specialty(Old)
A Security Administrator at a university is configuring a fleet of Amazon EC2 instances. The EC2 instances are shared among students, and non-root SSH access is allowed. The Administrator is concerned about students attacking other AWS account resources by using the EC2 instance metadata service. What can the Administ…
Nội dung câu hỏi
A Security Administrator at a university is configuring a fleet of Amazon EC2 instances. The EC2 instances are shared among students, and non-root SSH access is allowed. The Administrator is concerned about students attacking other AWS account resources by using the EC2 instance metadata service. What can the Administrator do to protect against this potential attack?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Disable the EC2 instance metadata service.
- B. Log all student SSH interactive session activity.
- C. Implement iptables-based restrictions on the instances. — đáp án hiện tại
- D. Install the Amazon Inspector agent on the instances.
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.