exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 86 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 86
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A company runs an application on AWS that needs to be accessed only by employees. Most employees work from the office, but others work remotely or travel.
How can the Security Engineer protect this workload so that only employees can access it?

  • A. Add each employee's home IP address to the security group for the application so that only those users can access the workload.
  • B. Create a virtual gateway for VPN connectivity for each employee, and restrict access to the workload from within the VPC.
  • C. Use a VPN appliance from the AWS Marketplace for users to connect to, and restrict workload access to traffic from that appliance.
  • D. Route all traffic to the workload through AWS WAF. Add each employee's home IP address into an AWS WAF rule, and block all other traffic.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
INASR
Highly Voted 3 years, 7 months ago
C is the only correct answer . They want also remote workers, travellers and not only office users and this is why AWS private gateway is not a solution since it is site-to-site VPN with 2 tunnels. VPN cloud hub is the same as private VPN gateway but multiple site-to-site tunnels , so it is wrong.
upvoted 33 times
sapien45
2 years, 8 months ago
your response albeit correct, does not make any sense. Who mentionned CloudHub ? what is it with the tunnels ? B is incorrect because you cannot create a separate VPN connection for each user Better to have each user connect to the VPN appliance. C
upvoted 2 times
...
...
polo
Highly Voted 3 years, 8 months ago
C is correct I think: https://docs.aws.amazon.com/vpc/latest/userguide/vpn-connections.html check the last column
upvoted 14 times
...
Raphaello
Most Recent 1 year, 3 months ago
Selected Answer: C
C is the best answer, yet it is very poorly written. It give hints to SSL VPN, but a better description to AWS Client VPN (managed service) would've been better. Still..C is the best answer.
upvoted 3 times
...
Nuha_23
1 year, 9 months ago
Selected Answer: C
C is correct You can also choose to use a third-party VPN solution. Use a third-party solution if you require full access and management of the AWS side of the VPN connection. see this link : https://repost.aws/knowledge-center/connect-vpc
upvoted 1 times
...
KRtoptech
1 year, 9 months ago
D; Allow all IP addresses and then use Rate limit on the WAF
upvoted 1 times
...
Sickcnt
1 year, 10 months ago
Selected Answer: C
Network Engineer here Implemented thousands of VPNs so far B is incorrect because for Clint-to-Site VPNs you need an "EC2 Client VPN endpoint" and not a "VPN Private Gateway" (VPN Private gateway is for Site-to-site Ipsec VPN tunnels) That leaves us with Option C
upvoted 5 times
...
sandromechi
1 year, 10 months ago
Selected Answer: B
B is correct because we can create a VPN GW with VPN Clients.
upvoted 1 times
...
pk0619
1 year, 10 months ago
Selected Answer: C
B is absurd
upvoted 1 times
...
OCHT
1 year, 11 months ago
Selected Answer: C
Option A is not a good choice because home IP addresses frequently change, and it would be a significant administrative burden to constantly update security group rules. Option B isn't practical, as creating a virtual gateway for each employee can become cumbersome and difficult to manage, especially for a large number of employees. Option D would be expensive and might not offer the same level of protection and control as a dedicated VPN solution. AWS WAF is more suited to protecting against web exploits rather than managing access control for a large number of users. So, using a VPN appliance from the AWS Marketplace for users to connect to and restricting workload access to traffic from that appliance is the most suitable option.
upvoted 1 times
sandromechi
1 year, 10 months ago
On B, you can choose VPN Clients... It's not about site-to-site VPN.
upvoted 1 times
...
...
ITGURU51
1 year, 11 months ago
C is the only suitable remote access solution.
upvoted 1 times
...
vavofa5697
2 years ago
Selected Answer: C
A. Definitely not suitable since there are employess are travelling and remote B. Creating a virtual gateway for each employee would be a lot of effort and not scalable D. AWS WAF is not suitable since it is for protecting web app The remaining is only C. Use a VPN appliance is the most suitable option
upvoted 1 times
...
ceros399
3 years, 2 months ago
Selected Answer: C
C - is the only offering a connection for authenticated users
upvoted 1 times
...
Radhaghosh
3 years, 3 months ago
C --> Is the correct Answer (as the question mentioned work remotely or travel)
upvoted 1 times
...
sam_live
3 years, 4 months ago
virtual gateway for VPN connectivity for each employee? could someone please explain how's that even a solution in the entire security world, rest alone AWS? A VPN solution is usually between two sites/domains or remote access endpoint VPN for users. The one possibility here is to get a VPN appliance from workplace. The answer should be - C
upvoted 2 times
...
ChauPhan
3 years, 6 months ago
C is correct, others are painful, we don't need to manage each IP address
upvoted 1 times
...
sanjaym
3 years, 6 months ago
Ans: C
upvoted 1 times
...
Paimon
3 years, 6 months ago
Having actually worked through this in real world..........C
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago