exam questions

Exam AWS Certified SAP on AWS - Specialty PAS-C01 All Questions

View all questions & answers for the AWS Certified SAP on AWS - Specialty PAS-C01 exam

Exam AWS Certified SAP on AWS - Specialty PAS-C01 topic 1 question 23 discussion

A company is planning to move all its SAP applications to Amazon EC2 instances in a VPC. Recently, the company signed a multiyear contract with a payroll software-as-a-service (SaaS) provider. Integration with the payroll SaaS solution is available only through public web APIs.
Corporate security guidelines state that all outbound traffic must be validated against an allow list. The payroll SaaS provider provides only fully qualified domain name (FQDN) addresses and no IP addresses or IP address ranges. Currently, an on-premises firewall appliance filters FQDNs. The company needs to connect an SAP Process Orchestration (SAP PO) system to the payroll SaaS provider.
What must the company do on AWS to meet these requirements?

  • A. Add an outbound rule to the security group of the SAP PO system to allow the FQDN of the payroll SaaS provider and deny all other outbound traffic.
  • B. Add an outbound rule to the network ACL of the subnet that contains the SAP PO system to allow the FQDN of the payroll SaaS provider and deny all other outbound traffic.
  • C. Add an AWS WAF web ACL to the VPAdd an outbound rule to allow the SAP PO system to connect to the FQDN of the payroll SaaS provider.
  • D. Add an AWS Network Firewall firewall to the VPC. Add an outbound rule to allow the SAP PO system to connect to the FQDN of the payroll SaaS provider.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kaishin0527
1 year, 10 months ago
Selected Answer: D
D: AWS Network Firewall is a managed service that makes it easy to deploy essential network protections for all of your Amazon Virtual Private Clouds (VPCs). The service can be configured to filter traffic based on fully qualified domain names (FQDN), which meets the requirement of the scenario.
upvoted 3 times
...
[Removed]
1 year, 10 months ago
Selected Answer: D
https://docs.aws.amazon.com/network-firewall/latest/developerguide/stateful-rule-groups-domain-names.html
upvoted 1 times
...
easytoo
2 years ago
d-d-d-d-dd--d-d-d-d
upvoted 1 times
...
SMALLAM
2 years, 4 months ago
I think D
upvoted 4 times
...
Grillppl
2 years, 4 months ago
Waf only incoming traffic and no fqdn filtering. Nw fw inbound and outbound filtering and fqdn filtering supported. So it should be D
upvoted 3 times
...
Balki
2 years, 4 months ago
Selected Answer: D
FQDN filtering can be achieved only through Firewall https://aws.amazon.com/blogs/security/use-aws-network-firewall-to-filter-outbound-https-traffic-from-applications-hosted-on-amazon-eks/
upvoted 3 times
...
forexamweb
2 years, 4 months ago
Selected Answer: D
D maybe https://aws.amazon.com/network-firewall/features#Web_filtering
upvoted 3 times
...
kk8s
2 years, 4 months ago
C for me
upvoted 1 times
SONALID
1 year, 8 months ago
web ACL rule cannot have FQDN
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...