Suggested Answer:AB🗳️
You must allow traffic through the NACL and through the Security Group to access the instance. If there is not an Outbound allow setup in the NACL, you may need to set that, but an outbound rule for Security Group 1 is not necessary as security groups are stateful.
AB. C does not "need to be configured". By default, new security groups start with only an outbound rule that allows all traffic to leave the instances. You must add rules to enable any inbound traffic or to restrict the outbound traffic. https://docs.aws.amazon.com/vpc/latest/userguide/VPC_SecurityGroups.html#CreatingSecurityGroups
C is a correct answer and A is the best answer between remaining three answers.
When allowing traffic on NACL one must remember to allow returning traffic on ports 1024 to 65535. (NACL is not state full)
AC. Can someone explain why C is not correct? Since SG are stateful, you cannot deny the incoming traffic but we can allow which is by creating outbound rule.. I may be wrong but happy to correct
C is not correct because it is not necessary. Security Groups are statefull, so returning traffic will be automatically allowed.
upvoted 5 times
...
...
This section is not available anymore. Please use the main Exam Page.ANS-C00 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
ChauPhan
Highly Voted 3 years, 7 months agobp339
Most Recent 3 years, 2 months agocidd04
3 years, 7 months agoJamesTR
3 years, 8 months agoVEV
3 years, 8 months agoptpho
3 years, 7 months agoJamesTR
3 years, 8 months ago