exam questions

Exam ANS-C00 All Questions

View all questions & answers for the ANS-C00 exam

Exam ANS-C00 topic 1 question 13 discussion

Exam question from Amazon's ANS-C00
Question #: 13
Topic #: 1
[All ANS-C00 Questions]

You are deploying an EC2 instance in a private subnet that requires access to the Internet. One of the requirements for this solution is to restrict access to only particular URLs on a whitelist. In addition to the whitelisted URLs, the instances should be able to access any Amazon S3 bucket in the same region via any URL.
Which of the following solutions should you deploy? (Choose two.)

  • A. Include s3.amazonaws.com in the whitelist.
  • B. Create a VPC endpoint for S3.
  • C. Run Squid proxy on a NAT instance.
  • D. Deploy a NAT gateway into your VPC.
  • E. Utilize a security group to restrict access.
Show Suggested Answer Hide Answer
Suggested Answer: BC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Steve2314
Highly Voted 3 years, 2 months ago
It should be BC. VPC endpoint would provide S3 access and Squid proxy on a NAT instance can be used to restrict access to particular URLs.
upvoted 25 times
certificatores
3 years, 1 month ago
B C for sure. this use-case is mentioned several times in original study guide book
upvoted 1 times
...
...
PavanKushwah123
Most Recent 1 year, 11 months ago
Correct Answer CD
upvoted 1 times
...
TonyGe
2 years ago
BC. we have deployed same architecture :)
upvoted 1 times
...
Brum
2 years ago
Selected Answer: BC
NAT Gateway does not allow create a whitelist, so a proxy (squid) is necessary here. in order to access S3 in the "same region", a VPC endpoint (Gateway endpoint). So, BC are the correct answers
upvoted 2 times
...
quixo
2 years, 5 months ago
Selected Answer: BC
answer is BC
upvoted 1 times
...
kopper2019
2 years, 9 months ago
B and C, but so far an AWS firewall should do it
upvoted 1 times
...
AshishBravo
3 years, 1 month ago
BC. Squid proxy on a NAT instance can be used to restrict access to particular URLs. VPC endpoint Gateway would provide S3 access.
upvoted 1 times
...
Huntkey
3 years, 1 month ago
BC. A is wrong because it says accessing S3 through any URLs. Potentially, you could create a DNS record of any name and point to the S3. In that case, it will be dropped.
upvoted 1 times
...
iafro
3 years, 1 month ago
How/why would you run a nat instance and a nat gateway?
upvoted 1 times
...
ChauPhan
3 years, 1 month ago
B,C for me
upvoted 1 times
...
cardiryh
3 years, 1 month ago
Band C for me
upvoted 2 times
...
inf
3 years, 1 month ago
Answer: B,C A - incorrect - missing region: s3.<region>.amazonaws.com B - correct - EC2->VPC Endpoint->S3 bucket (S3 endpoints can access buckets in specified region only. https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints-s3.html) C - correct - EC2->NAT Instance->Squid Proxy+Whitelists/Blacklists->Internet->Allowed sites/URLs D - incorrect - doesn't enable whitelisting, but allows all internet access E - incorrect - doesn't enable whitelisting on URLs, also can't deny anything (use NACLs) - both require code to constantly update allow, allow/deny rules
upvoted 4 times
Kentik
3 years, 1 month ago
just FYI, the s3 region comes before s3.amazonaws.com
upvoted 1 times
...
...
SuperD
3 years, 1 month ago
B and D
upvoted 1 times
...
2aldous
3 years, 2 months ago
B and D "The instance requite access to internet"
upvoted 1 times
Lapiro
3 years, 1 month ago
remember question said, EC2 Instance is in a private subnet.
upvoted 1 times
...
...
Johnny_Green
3 years, 2 months ago
B, C are the correct answers. https://aws.amazon.com/blogs/security/how-to-add-dns-filtering-to-your-nat-instance-with-squid/
upvoted 1 times
...
JRFerre
3 years, 2 months ago
Correct ans for me C & D C - squid proxy permit connections to whitelisted domains that you define. https://aws.amazon.com/blogs/security/how-to-set-up-an-outbound-vpc-proxy-with-domain-whitelisting-and-content-filtering/ D-Instance is in a private subnet and requires access to the interent.
upvoted 1 times
MaikM
3 years, 1 month ago
Squid Proxy gives access to the internet. No need for NAT gateway.
upvoted 1 times
...
...
backfringe
3 years, 2 months ago
it's B & C
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago