A cloud practitioner needs to configure a network security control that operates at the subnet level of an Amazon VPC to block traffic from a specific IP address. Which AWS service or feature should be used to meet this requirement?
- ASecurity Group
- Network Access Control List (Network ACL)Cevap
- CVPC Peering connection
- DAmazon GuardDuty
Cevap
Network Access Control List (Network ACL)
The correct answer is the Network Access Control List (Network ACL). A Network ACL is a stateless firewall that operates at the subnet boundary of an Amazon VPC. It supports both allow rules and deny rules, which allows a cloud practitioner to explicitly define a rule that blocks inbound or outbound traffic from a specific IP address.
Adım Adım Çözüm
Anahtar Kavram
Subnet-level network security in AWS using Network Access Control Lists (Network ACLs)
Tahmini Süre:45s