ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
Your company runs several Amazon EC2 instances that engineers must occasionally access for emergency shell troubleshooting. Security logs record thousands of daily failed SSH attempts from public IP addresses, indicating an automated brute-force attack. The team wants to remove this attack surface yet keep on-demand administrative access from any location, without running extra infrastructure or maintaining source IP allow lists. Which solution best satisfies these goals?
Deploy fail2ban on each instance to ban IP addresses that exceed a threshold of failed SSH logins.
Enable AWS WAF on the Application Load Balancer and create a rate-based rule that blocks IP addresses with excessive requests.
Install the AWS Systems Manager agent on the instances, disable inbound TCP 22 in the security group, and use Session Manager for interactive shell access.
Add an AWS Network Firewall endpoint to the VPC and configure intrusion-prevention rules to block repeated SSH login failures.
AWS Systems Manager Session Manager enables administrators to open interactive shells to EC2 instances through the AWS console or CLI. The SSM agent on each instance initiates an outbound HTTPS connection to the Systems Manager service, so no inbound ports-such as TCP 22 for SSH-need to be open. Closing port 22 eliminates the brute-force vector while still allowing ad-hoc access. AWS Network Firewall and fail2ban leave port 22 exposed, and AWS WAF cannot inspect SSH traffic.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS Systems Manager Session Manager?
Open an interactive chat with Bash
Why is it important to close inbound port 22 for EC2 instances?
Open an interactive chat with Bash
How does the AWS Systems Manager agent work to establish secure connections?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .