Hello. I was doing some of the free AWS test questions and I came up about Pen testing and im not sure which is the correct answer.

The question said something like "An AWS customer did pen testing on their own web app on an EC2 and was later contacted by AWS for violating the AWS Acceptable Use Policy" . How can the customer perform the test without violating the policy?

A. Submit pen test request
B. Exclude port 80 , 443
C. Run test against instances with Inspector installed

D. Deploy test client to same VPC as the app

None of these seem right. You dont need to do A anymore, you dont need to exclude ports. C doesnt seem necessary as well as D. Any thoughts on this?

Stephen I believe you meant to answer this in another thread lol. Im guessing the correct answer was you need to ask for permissions then since it was only a recent change?

