Soru

Zorluk: OrtaNetwork and Infrastructure Security

An organization is designing the network security architecture for a multi-tier application in an Amazon VPC. The database tier resides in a private subnet, while the web tier is in a public subnet. The security team needs to implement controls to restrict inbound and outbound traffic at both the subnet boundary and the individual Amazon EC2 instance level. Which of the following statements correctly describe the characteristics of Security Groups and Network Access Control Lists (Network ACLs) in this architecture? (Select TWO.)

  1. Security Groups are stateful, meaning if an inbound rule allows traffic to reach a database instance, the outbound response is permitted automatically.Cevap
  2. Network ACLs are stateless, meaning if an inbound rule allows traffic into a subnet, a corresponding outbound rule must be configured to allow the return traffic.Cevap
  3. C
    Network ACLs operate at the EC2 instance level to filter traffic, while Security Groups operate at the subnet level to protect the entire boundary.
  4. D
    AWS is responsible for managing and patching host operating system firewalls on customer-provisioned Amazon EC2 instances under the Shared Responsibility Model.
  5. E
    Amazon GuardDuty acts as an active firewall that can automatically detect and block malicious traffic at the subnet boundary.

Cevap

Security Groups are stateful, so inbound rules automatically permit outbound response traffic, while Network ACLs are stateless, requiring explicit inbound and outbound rules to allow return traffic.
Security Groups are stateful, meaning outbound response traffic is permitted automatically if inbound traffic is allowed. In contrast, Network ACLs are stateless, requiring explicit configuration of both inbound and outbound rules to allow return traffic.

Adım Adım Çözüm

1
Analyze the operational scope of Security Groups and Network ACLs in an Amazon VPC configuration.
Security Groups operate at the instance level (Elastic Network Interface), while Network ACLs operate at the subnet level.
This establishes where each security control is applied within the VPC architecture.
2
Determine the stateful nature of both security controls to evaluate how return traffic is handled.
Security Groups are stateful (automatically allowing return traffic), while Network ACLs are stateless (requiring return rules).
This shows how traffic rules must be configured in both directions for each control.

Anahtar Kavram

Stateful Security Groups vs. Stateless Network ACLs
Tahmini Süre:1m 30s
Bu soruyu puanla