exam questions

Exam CV0-003 All Questions

View all questions & answers for the CV0-003 exam

Exam CV0-003 topic 1 question 220 discussion

Actual exam question from CompTIA's CV0-003
Question #: 220
Topic #: 1
[All CV0-003 Questions]

A security team is conducting an audit of the security group configurations for the Linux servers that are hosted in a public IaaS The team identifies the following rule as a potential issue:



A cloud administrator, who is working remotely, logs in to the cloud management console and modifies the rule to set the source to "My IP." Shortly after deploying the rule, an internal developer receives the following error message when attempting to log in to the server using SSH: Network error: Connection timed out. However, the administrator is able to connect successfully to the same server using SSH. Which of the following is the BEST option for both the developer and the administrator to access the server from their locations?

  • A. Modify the outbound rule to allow the company’s external IP address as a source
  • B. Add an inbound rule to use the IP address for the company's main office as a source
  • C. Modify the inbound rule to allow the company’s external IP address as a source
  • D. Delete the inbound rule to allow the company’s external IP address as a source
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
JVen
Highly Voted 1 year, 11 months ago
I feel like this would have to be B, not A. A removes access to one of them, not add access for the remaining person needing it.
upvoted 5 times
...
sweetykaur
Most Recent 1 month, 3 weeks ago
Selected Answer: B
B. Add an inbound rule to use the IP address for the company's main office as a source. Why this works: By adding an inbound rule that allows SSH access from the company's main office IP address, both the administrator (working remotely) and the internal developer (likely working from the office) can securely access the server. This ensures secure access for both parties without overly broad permissions, like allowing all IPs (0.0.0.0/0), which would pose a security risk.
upvoted 1 times
...
Therealjosh
7 months ago
Selected Answer: C
C. Modify the inbound rule to allow the company’s external IP address as a source. Explanation: Currently, the administrator has modified the rule to set the source to "My IP," which means only the administrator's IP address is allowed for inbound connections. This resulted in the internal developer encountering a connection timeout error when attempting to log in via SSH. By modifying the inbound rule to allow the company’s external IP address as a source, both the administrator and the internal developer can access the server from their respective locations. This option ensures that both the administrator and the developer can connect to the server while maintaining the security restriction of allowing access only from the company's external IP address.
upvoted 2 times
...
Sweety_Certified7
7 months, 1 week ago
Selected Answer: B
Since the error occurred after the administrator modified the rule to restrict SSH access to "My IP," it's likely that the developer's IP address is not included in the allowed sources. Since the administrator already has a rule that allows their IP address, an additional inbound rule needs to be added for the developer. Adding an inbound rule with the IP address of the company's main office as the source would ensure that both the developer (who is internal to the organiztion) and the administrator (who is working remotely) can access the server. ANSWER IS NOT C bcoz: Without explicit information about the developer's external IP address, it would be inaccurate to assume that it is the same as the company's external IP address. THE QUESTION DOES NOT STATE that the company's external IP address is the developers address.
upvoted 1 times
...
FasterN8
8 months, 2 weeks ago
Selected Answer: B
B. There are 2 people in different locations. Each one needs an inbound rule to allow their traffic from their different IPs. The admin already has his rule, you need to ADD an inbound rule for the developer (and every other dev and admin at the office).
upvoted 4 times
...
Pongsathorn
1 year, 1 month ago
Selected Answer: C
C. Modify the inbound rule to allow the company’s external IP address as a source is the BEST option for both the developer and the administrator to access the server from their locations. Here's why: The security group rule was initially set to allow SSH traffic from the administrator's current IP address (My IP). When the administrator modifies the rule to set the source to "My IP," it restricts SSH access to only the administrator's IP address. This change caused the developer to be unable to connect. To allow both the developer and the administrator to access the server from their respective locations, the inbound rule should be modified to include the external IP address of the company. This change will permit SSH access from both their locations, maintaining security while allowing authorized access.
upvoted 1 times
FasterN8
8 months, 2 weeks ago
The change will block the remote admin. The developer is at the company location. You need to ADD an inbound rule to cover each use case.
upvoted 2 times
...
Sweety_Certified7
7 months, 1 week ago
Without explicit information about the developer's external IP address, it would be inaccurate to assume that it is the same as the company's external IP address. THE QUESTION DOES NOT STATE that the company's external IP address is the developers address.
upvoted 1 times
...
...
ROCompTIA
1 year, 4 months ago
Selected Answer: C
It's inbound connection
upvoted 2 times
...
maelo
1 year, 6 months ago
Selected Answer: C
The SSH server needs an inbound rule to be accessed, not outbound (A). Agree to concepcionz and mattygster, as earlier test showed the rule working OK in priniciple, but needs tweaking.
upvoted 1 times
Sweety_Certified7
7 months, 1 week ago
Without explicit information about the developer's external IP address, it would be inaccurate to assume that it is the same as the company's external IP address. THE QUESTION DOES NOT STATE that the company's external IP address is the developers address.
upvoted 1 times
...
...
concepcionz
1 year, 7 months ago
Selected Answer: C
Im also going with C as it modifies the existing inbound rule to allow access from the company's external IP address range, which includes both the administrator and the INTERNAL developer's IP addresses.
upvoted 1 times
Sweety_Certified7
7 months, 1 week ago
Without explicit information about the developer's external IP address, it would be inaccurate to assume that it is the same as the company's external IP address. THE QUESTION DOES NOT STATE that the company's external IP address is the developers address.
upvoted 1 times
...
...
mattygster
1 year, 8 months ago
I am leaning to C, the internal Dev is unable to log into the server using SSH, but the Administrator can. So there is a pre-existing rule that works. B would add an additional rule while C would modify the pre-exisiting rule. keep it simple and have only the ACLs you need rather than multiple that overlap and do the same purpose.
upvoted 2 times
Sweety_Certified7
7 months, 1 week ago
Without explicit information about the developer's external IP address, it would be inaccurate to assume that it is the same as the company's external IP address. THE QUESTION DOES NOT STATE that the company's external IP address is the developers address.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago