AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium

A company wants to conduct authorized penetration testing against its EC2 instances and Application Load Balancer to validate its security posture. According to AWS's customer policies, what must the company do before starting the test?

  1. APurchase AWS Shield Advanced, which is a mandatory prerequisite for any penetration testing
  2. BNothing; AWS permits penetration testing on most owned services without prior approval for commonly tested services
  3. CObtain written approval from every third-party vendor whose software is hosted on the instances
  4. DSubmit a request and wait for AWS Support to personally perform the test on their behalf
Show answer & explanation

Correct answer: B. Nothing; AWS permits penetration testing on most owned services without prior approval for commonly tested services

AWS has published a policy that allows customers to perform penetration testing against their own AWS resources for a defined list of commonly tested services (including EC2 instances, NAT gateways, and ELBs) without prior approval, as long as testing complies with AWS's Acceptable Use Policy and does not target prohibited activities like DDoS simulation. There is no requirement for AWS Support to personally run the test, third-party vendor approval, or Shield Advanced purchase.

Why the other options are wrong

  • A. Shield Advanced is unrelated and not a prerequisite for penetration testing permissions.
  • C. Third-party vendor approval is not an AWS requirement for infrastructure penetration testing.
  • D. AWS does not perform the test on the customer's behalf; the customer runs it themselves.

AWS Penetration Testing Policy

AWS allows customers to conduct penetration tests against their own resources for a list of commonly tested services without prior approval, subject to the Acceptable Use Policy.

  • No prior approval needed for permitted services (EC2, ELB, NAT gateways, etc.)
  • Prohibited actions include DNS zone walking and DDoS simulation
  • Some services still require special permission requests

Memory trick: Test freely on your own house, but follow AWS's house rules

More Security and Compliance questions