Security and Compliance
441 questions
Question 441Question →
A financial services firm is deploying a trade processing application on Amazon EC2 instances within a private subnet. The system architecture requires separating instance-level traffic control from subnet-level boundaries. Which of the following statements accurately describe how the administrator should configure Security Groups and Network Access Control Lists (Network ACLs) for this environment? (Select TWO.)
Select all that apply
Security groups are stateful, meaning return traffic is automatically allowed, and they are applied at the instance level.
Network ACLs are stateless, meaning separate inbound and outbound rules are required to allow traffic, and they are applied at the subnet level.
Network ACLs are stateful, meaning they automatically track connection state and allow return traffic at the subnet level.
AWS is responsible for managing security group rules and Network ACL rules on behalf of the customer under the Shared Responsibility Model.
Amazon Inspector should be configured to analyze VPC Flow Logs for intelligent threat detection and block malicious traffic at the subnet level.
PreviousPage 23 / 23