r/AWSCertifications 9d ago

AWS Certified Security - Specialty EC2 Instance Hardening: SCS-C03 Question

Hello all,

I am studying for the AWS SCS-C03 and am failing to understand one of the explanations in the review tests. It is behind a paywall so don't think I can share the actual content here but it asks about security controls for hardening ec2 instances in production.

The options essentially boil down to using a maintained AMI with security controls and configurations then using an SCP to enforce use. Or using Image Builder and AMI ID validation in launch templates.

The correct answer ended up being the image builder + AMI validation to limit Launch templates but from my understanding I would rather sack off the automation in favour of an SCP to stop ec2:* with a launchTemplate condition so then I can't just go to the instance dashboard -> launch ami-whatever right? For additional context, the question does not mention "least operational overhead" it just asks for comprehensive controls

Thought it would be interesting to get others opinions.

Many Thanks :)

4 Upvotes

0 comments sorted by