exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 672 discussion

Exam question from Amazon's AWS-SysOps
Question #: 672
Topic #: 1
[All AWS-SysOps Questions]

An application is running on multiple EC2 instances. As part of an initiative to improve overall infrastructure security, the EC2 instances were moved to a private subnet. However, since moving, the EC2 instances have not been able to automatically update, and a SysOps Administrator has not been able to SSH into them remotely.
Which two actions could the Administrator take to securely resolve these issues? (Choose two.)

  • A. Set up a bastion host in a public subnet, and configure security groups and route tables accordingly.
  • B. Set up a bastion host in the private subnet, and configure security groups accordingly.
  • C. Configure a load balancer in a public subnet, and configure the route tables accordingly.
  • D. Set up a NAT gateway in a public subnet, and change the private subnet route tables accordingly.
  • E. Set up a NAT gateway in a private subnet, and ensure that the route tables are configured accordingly.
Show Suggested Answer Hide Answer
Suggested Answer: AD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
saumenP
Highly Voted 2 years, 1 month ago
NAT gateway always attached to Public subnet, not private. AD should be correct
upvoted 23 times
...
jxhyxxclyp
Highly Voted 2 years, 1 month ago
why not ad
upvoted 11 times
...
Akinwaleo
Most Recent 5 months, 3 weeks ago
According to the chat GPT answer is A and D Configure NAT Gateway: The SysOps Administrator can set up a NAT Gateway in a public subnet to route traffic from the private subnet to the internet. This will enable EC2 instances to automatically update themselves and access the internet securely. Configure a Bastion Host: A Bastion Host can be used to allow remote access to EC2 instances in a private subnet. The SysOps Administrator can set up a Bastion Host in a public subnet, which acts as a jump server to access EC2 instances in the private subnet. The Bastion Host can be configured with a secure SSH connection
upvoted 1 times
...
Cyril_the_Squirl
1 year, 12 months ago
B and E are correct. A is wrong. Bastion host lbs belong in the public subnet and have access in the private subnet. This the whole point of bastion hosts. B. Is correct. C is wrong and just a silly option. D is wrong, you already have IGW in public subnet giving internet access to your entire VPC, you use NAT gateway in private subnet with IGW as its default route. E is correct, route tables must reflect that 0.0.0.0/0 traffic is forwarded to IGW.
upvoted 1 times
crazydev
1 year, 7 months ago
Please read the question again. Also, I'm afraid you need to clear your concepts. A is correct and applicable. D is correct and applicable. A and D are the right answers.
upvoted 1 times
...
...
RicardoD
2 years ago
A | D are the answers You should add a bastion host (A) on the public subnet, so you can log into it and then get access to the DB, then add a NAT gateway (D) so the server can send responses to internet
upvoted 2 times
...
abhishek_m_86
2 years ago
A. Set up a bastion host in a public subnet, and configure security groups and route tables accordingly. D. Set up a NAT gateway in a public subnet, and change the private subnet route tables accordingly. Seem correct
upvoted 2 times
...
Chirantan
2 years ago
A & D as bots nat gateway and bastion host are in public subnet
upvoted 1 times
...
kiev
2 years ago
A and D. Note Nat Gateway is associated with the private subnet but it is placed in the public subnet.
upvoted 1 times
...
jackdryan
2 years ago
I'll go with A,D
upvoted 1 times
...
MFDOOM
2 years ago
> A & D
upvoted 1 times
...
gilbertlelancelo
2 years ago
A. Set up a bastion host in a public subnet, and configure security groups and route tables accordingly. D. Set up a NAT gateway in a public subnet, and change the private subnet route tables accordingly. Correct answer A & D.
upvoted 1 times
...
waterzhong
2 years ago
A and D are the right answers. Both Bastion host and NAT gateway should be placed in a public subnet. "Bastion hosts are "instances that sit within your public subnet and are typically accessed using SSH or RDP". For those who were thinking of E as a good answer: "Use a NAT gateway in a public VPC subnet to enable outbound internet traffic from instances in a private subnet."
upvoted 5 times
...
shammous
2 years ago
A and D are the right answers. Both Bastion host and NAT gateway should be placed in a public subnet. "Bastion hosts are "instances that sit within your public subnet and are typically accessed using SSH or RDP". For those who were thinking of E as a good answer: "Use a NAT gateway in a public VPC subnet to enable outbound internet traffic from instances in a private subnet."
upvoted 1 times
...
KhatriRocks
2 years ago
AD is the ans
upvoted 1 times
...
khan11
2 years ago
A AND E
upvoted 1 times
proxyolism
2 years ago
actually I thought AD is the answer, but it is not. I was also knew that NAT gateway must attached to private subnet, but it was wrong. https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html as from AWS reference, NAT gateway must attached to public subnet for connect to internet as outbound traffic from private subnet. As above, right answer is AD indeed.
upvoted 1 times
proxyolism
2 years ago
sorry for mistypes. I thought AE first and indeed answer is AD
upvoted 1 times
...
...
...
MrKhan
2 years ago
A and D are valid answers.
upvoted 2 times
...
pkboy78
2 years, 1 month ago
Nevermind it is A and D. Subnet associated with nat gateway is classified as a public subnet with outbound internet connection.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago