exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 385 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 385
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A company has deployed servers on Amazon EC2 instances in a VPC. External vendors access these servers over the internet. Recently, the company deployed a new application on EC2 instances in a new CIDR range. The company needs to make the application available to the vendors.

A security engineer verified that the associated security groups and network ACLs are allowing the required ports in the inbound diction. However, the vendors cannot connect to the application.

Which solution will provide the vendors access to the application?

  • A. Modify the security group that is associated with the EC2 instances to have the same outbound rules as inbound rules.
  • B. Modify the network ACL that is associated with the CIDR range to allow outbound traffic to ephemeral ports.
  • C. Modify the inbound rules on the internet gateway to allow the required ports.
  • D. Modify the network ACL that is associated with the CIDR range to have the same outbound rules as inbound rules.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Toptip
1 year, 11 months ago
Selected Answer: B
B is correct
upvoted 1 times
...
XaviL
2 years, 3 months ago
B is correct, always on ephemeral port range. I understand that this change not apply to IG, the change was on EC2s
upvoted 1 times
...
Nocky24
2 years, 4 months ago
Selected Answer: B
B definitely.
upvoted 1 times
...
Leonardocp33
2 years, 4 months ago
Selected Answer: B
B for sure
upvoted 1 times
...
tainh
2 years, 5 months ago
Selected Answer: B
B is correct Need allow outbound traffic for new CIDR back with ephemeral port range
upvoted 3 times
...
AdamWest
2 years, 5 months ago
Selected Answer: B
Answer B
upvoted 2 times
...
D2
2 years, 5 months ago
Answer B
upvoted 1 times
...
Isaias
2 years, 5 months ago
Selected Answer: B
B, ACL outbound neet to permit epheral ports to return traffic
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago