🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

An enterprise operates several AWS accounts in a single AWS Organization. To reduce its external attack surface, the security team must guarantee that no new EC2 instance can ever be launched with an automatically assigned public IPv4 address in any development account. Which AWS control provides the most effective preventative safeguard for this requirement?

  • Activate VPC Flow Logs and CloudWatch alarms to detect and alert on traffic from instances with public IP addresses in development VPCs.

  • Attach a Service Control Policy in AWS Organizations that denies ec2:RunInstances when the request's ec2:AssociatePublicIpAddress condition equals true for the development accounts.

  • Enable Amazon GuardDuty and configure an EventBridge rule to automatically stop any instance that acquires a public IP address.

  • Create an AWS Config managed rule that detects EC2 instances with public IP addresses and generates compliance alerts.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot