exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 60 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 60
Topic #: 1
[All AWS Certified Security - Specialty Questions]

Which of the following minimizes the potential attack surface for applications?

  • A. Use security groups to provide stateful firewalls for Amazon EC2 instances at the hypervisor level.
  • B. Use network ACLs to provide stateful firewalls at the VPC level to prevent access to any specific AWS resource.
  • C. Use AWS Direct Connect for secure trusted connections between EC2 instances within private subnets.
  • D. Design network security in a single layer within the perimeter network (also known as DMZ, demilitarized zone, and screened subnet) to facilitate quicker responses to threats.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AnNguyen
Highly Voted 3 years, 2 months ago
Answer is A B: NACL is stateless C: Direct Connect connect AWS and on-premise, not in private subnet D: Should be multi-layer, not single-layer
upvoted 48 times
...
cloudguy365
Highly Voted 3 years, 2 months ago
D is the right Answer, SG apply on ENI not on hypervisor level.
upvoted 19 times
DahMac
3 years, 1 month ago
minimize attack surface, not respond to attack. A does that, not D.
upvoted 5 times
dfranco76
3 years, 1 month ago
Correct answer A. From Devjava post: From https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf Always use security groups: They provide stateful firewalls for Amazon EC2 instances at the hypervisor level. You can apply multiple security groups to a single instance, and to a single ENI.
upvoted 7 times
...
...
...
Raphaello
Most Recent 10 months, 1 week ago
Selected Answer: A
Answer A is the best bullsh!t answer to a bullsh!t question.
upvoted 1 times
...
ITGURU51
1 year, 6 months ago
The answer is A because the best practice is to use security groups over NACL's whenever possible. Furthermore, security groups reduce the attack surface at the hypervisor level.
upvoted 1 times
...
Ell89
1 year, 9 months ago
Selected Answer: A
A - NACLs arent stateful
upvoted 2 times
...
Nan001
1 year, 10 months ago
Selected Answer: A
I thought B, after reading again, NACLs are stateless. Confused between A and D. But ChatGPT response is: Use security groups to provide stateful firewalls for Amazon EC2 instances at the hypervisor level.
upvoted 2 times
...
Molkaka
1 year, 11 months ago
Selected Answer: A
https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf Best practices for network security in the AWS cloud include the following: • Always use security groups: They provide stateful firewalls for Amazon EC2 instances at the hypervisor level. You can apply multiple security groups to a single instance, and to a single ENI.
upvoted 4 times
...
GaniGaniGani
1 year, 11 months ago
Selected Answer: A
ANSWER A
upvoted 2 times
...
sky_top_onestart
2 years ago
Selected Answer: D
A is incorrect, the ec2 location is a private network, not a surface. B is incorrect, Netwok ACL is stateless C is incoreect, 'AWS Direct Connect' is no surface.
upvoted 1 times
...
hubekpeter
2 years ago
Selected Answer: D
A is nonsense. They are using XEN hypervisor, i don't think they're setting firewall on a hypervisor level but maybe I'm wrong. They probably do use openvswitch as a SDN layer which is running in linux userspace !!! https://wiki.xenproject.org/wiki/Xen_Networking
upvoted 1 times
...
sakibmas
2 years, 1 month ago
Selected Answer: A
Always use security groups: They provide stateful firewalls for Amazon EC2 instances at the hypervisor level. You can apply multiple security groups to a single instance, and to a single ENI. Reference: https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf
upvoted 2 times
...
arae
2 years, 2 months ago
Answer A The b answer is just wrong because NACL is stateless
upvoted 1 times
...
sapien45
2 years, 4 months ago
Selected Answer: A
Always use security groups: They provide stateful firewalls for Amazon EC2 instances at the hypervisor level. You can apply multiple security groups to a single instance, and to a single ENI.
upvoted 3 times
...
ryuhei
2 years, 5 months ago
Selected Answer: D
Answer:D!!!
upvoted 2 times
...
TigerInTheCloud
2 years, 8 months ago
Selected Answer: A
Copied AnNguyen's explanation for being able to vote. Answer is A B: NACL is stateless C: Direct Connect connect AWS and on-premise, not in among private subnets D: Should be multi-layer, not single-layer
upvoted 2 times
...
ceros399
2 years, 8 months ago
Selected Answer: A
A - Is clear, you reduce the attack surface, reducing number of exposed ports
upvoted 3 times
...
Radhaghosh
2 years, 10 months ago
NACL is not Stateful --> Answer is A
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago