exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C02 exam

Exam AWS Certified Solutions Architect - Associate SAA-C02 topic 1 question 363 discussion

A company is reviewing a recent migration of a three-tier application to a VPC. The security team discovers that the principle of least privilege is not being applied to Amazon EC2 security group ingress and egress rules between the application tiers.
What should a solutions architect do to correct this issue?

  • A. Create security group rules using the instance ID as the source or destination.
  • B. Create security group rules using the security group ID as the source or destination.
  • C. Create security group rules using the VPC CIDR blocks as the source or destination.
  • D. Create security group rules using the subnet CIDR blocks as the source or destination.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dmscountera
Highly Voted 3 years, 7 months ago
B. Create security group rules using the security group ID as the source or destination. SG nesting
upvoted 23 times
...
jkwek
Highly Voted 3 years, 7 months ago
Answer is B. https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/security-group-rules.html
upvoted 10 times
lc76262
3 years, 7 months ago
Thanks for the very helpful link that proves B is the answer.
upvoted 2 times
...
...
cloud_collector
Most Recent 2 years, 9 months ago
B The ID of a security group (referred to here as the specified security group). For example, the current security group, a security group from the same VPC, or a security group for a peered VPC. This allows traffic based on the private IP addresses of the resources associated with the specified security group. This does not add rules from the specified security group to the current security group. https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/security-group-rules.html
upvoted 1 times
...
Ln312
3 years, 6 months ago
B In fact, A is more secure, as SG may be added to other EC2s, not only instances in application tiers. But if these application tiers work with ASG, A will be a trouble. So Ans should be B
upvoted 4 times
...
spydii
3 years, 6 months ago
Are these dumps even worth it?
upvoted 4 times
lummy
3 years, 6 months ago
they are actually worth it, but the answers given are not
upvoted 5 times
...
...
Always_Wanting_Stuff
3 years, 7 months ago
I am guessing that we reference the security ID so that the security group rules are aggregated and therefore follow the rules of least privilege?
upvoted 1 times
...
lovelyone
3 years, 7 months ago
(Inbound rules only) The source of the traffic and the destination port or port range. The source can be another security group, an IPv4 or IPv6 CIDR block, a single IPv4 or IPv6 address, or a prefix list ID. so its B & D
upvoted 1 times
...
lovelyone
3 years, 7 months ago
AWS Security Group can't be nested; they can contain only users, not other groups. AWS Security Group has no default group that automatically includes all users in the AWS account. If you want to have a group like that, you need to create it and assign each new user to it. Anser is A
upvoted 1 times
...
syu31svc
3 years, 7 months ago
"principle of least privilege" Answer is B; security group of instances to another from tier to tier
upvoted 6 times
...
MunzerR
3 years, 7 months ago
B...always preferer SG ID over Instance ID
upvoted 5 times
...
waqas
3 years, 7 months ago
Yes its B.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago