Which step should a SecOps engineer implement in order to create a network exposure policy that identifies instances accessible from any untrusted internet sources?
A.
In Policy Section-> Add Policy-> Config type -> Define Policy details Like Name,Severity-> Configure RQL query "config from network where source.network = UNTRUST INTERNET and dest.resource.type = 'Instance' and dest.cloud.type = 'AWS' " -> define compliance standard -> Define recommendation for remediation & save.
B.
In Policy Section-> Add Policy-> Network type -> Define Policy details Like Name,Severity-> Configure RQL query "network from vpc.flow_record where source.publicnetwork IN ( 'Suspicious IPs' , 'Internet IPs' ) and dest.resource IN ( resource where role IN ( 'Instance ) )" -> define compliance standard -> Define recommendation for remediation & save.
C.
In Policy Section-> Add Policy-> Network type -> Define Policy details Like Name,Severity-> Configure RQL query "network from vpc.flow_record where source.publicnetwork IN ( 'Suspicious IPs' , 'Internet IPs') and dest.resource IN ( resource where role IN ( 'Instance ) )" -> define compliance standard -> Define recommendation for remediation & save.
D.
In Policy Section-> Add Policy-> Network type -> Define Policy details Like Name,Severity-> Configure RQL query "config from network where source.network = UNTRUST INTERNET and dest.resource.type = 'Instance' and dest.cloud.type = 'AWS' " -> Define recommendation for remediation & save.
This is a core concept for this certification. The answer has to be C.
upvoted 1 times
...
This section is not available anymore. Please use the main Exam Page.PCCSE Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Duke_CT
1 week ago