exam questions

Exam AWS Certified Solutions Architect - Professional All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional exam

Exam AWS Certified Solutions Architect - Professional topic 1 question 939 discussion

A company wants to use Amazon WorkSpaces in combination with thin client devices to replace aging desktops. Employees use the desktops to access applications that work with clinical trial data. Corporate security policy states that access to the applications must be restricted to only company branch office locations. The company is considering adding an additional branch office in the next 6 months.
Which solution meets these requirements with the MOST operational efficiency?

  • A. Create an IP access control group rule with the list of public addresses from the branch offices. Associate the IP access control group with the WorkSpaces directory.
  • B. Use AWS Firewall Manner to create a web ACL rule with an IPSet with the list of public addresses from the branch office locations. Associate the web ACL with the WorkSpaces directory.
  • C. Use AWS Certificate Manager (ACM) to issue trusted device certificates to the machines deployed in the branch office locations. Enable restricted access on the WorkSpaces directory.
  • D. Create a custom WorkSpace image with Windows Firewall configured to restrict access to the public addresses of the branch offices. Use the image to deploy the WorkSpaces.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
gnandam
Highly Voted 2 years, 8 months ago
A - Amazon WorkSpaces allows you to control which IP addresses your WorkSpaces can be accessed from. By using IP address-based control groups, you can define and manage groups of trusted IP addresses, and only allow users to access their WorkSpaces when they're connected to a trusted network. An IP access control group acts as a virtual firewall that controls the IP addresses from which users are allowed to access their WorkSpaces. To specify the CIDR address ranges, add rules to your IP access control group, and then associate the group with your directory. You can associate each IP access control group with one or more directories. You can create up to 100 IP access control groups per Region per AWS account. However, you can only associate up to 25 IP access control groups with a single directory. C - is not MOST operational efficiency
upvoted 6 times
...
skywalker
Highly Voted 2 years, 8 months ago
Selected Answer: A
A - https://docs.aws.amazon.com/workspaces/latest/adminguide/amazon-workspaces-ip-access-control-groups.html
upvoted 5 times
...
breathingcloud
Most Recent 2 years, 7 months ago
trusted device cert model won't support Linux it works with only Windows and MAC. So lean towards A https://aws.amazon.com/blogs/security/how-to-secure-your-amazon-workspaces-for-external-users/
upvoted 2 times
...
akash_it
2 years, 8 months ago
Selected Answer: A
A is correct
upvoted 3 times
...
Biden
2 years, 8 months ago
Selected Answer: C
Cant be A since desktops wudnt have public IPs. Trusted Certs can be used: https://docs.aws.amazon.com/workspaces/latest/adminguide/trusted-devices.html
upvoted 2 times
astalavista1
2 years, 8 months ago
But the branch will have a Public IP, not the desktops. Public IP for the branch and private IP for workspace, no ?
upvoted 4 times
...
joancarles
2 years, 8 months ago
It is not possible to export public certificates whether they are ACM-issued or imported. https://docs.aws.amazon.com/acm/latest/userguide/sdk-export.html So it's A
upvoted 1 times
...
rsn
1 year, 9 months ago
I support C https://docs.aws.amazon.com/workspaces/latest/adminguide/certificate-based-authentication.html
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...