PassDrill Free practice questions with explanations that actually teach.

AWS-SAA · ec2 · Q005 · easy

A security team wants to reduce the risk of an application vulnerability being exploited to steal an EC2 instance's IAM role credentials via the instance metadata service. Which configuration change most directly mitigates this specific risk?

  1. Require IMDSv2 by setting the instance metadata options' HttpTokens parameter to required
  2. Replace the instance's shared tenancy with a Dedicated Host
  3. Enable detailed CloudWatch monitoring on the instance
  4. Move the instance into a cluster placement group