Soru

Zorluk: OrtaAWS Network Services

An organization is hosting a web application on several Amazon EC2 instances within a public subnet of a Virtual Private Cloud (VPC). The security administrator must configure a stateful network firewall rule at the instance level to permit inbound traffic on port 443 (HTTPS) from any IP address. Which AWS networking component should the administrator modify to meet this requirement?

  1. Security GroupCevap
  2. B
    Network Access Control List (Network ACL)
  3. C
    AWS Transit Gateway
  4. D
    IAM Role

Cevap

Security Group
A security group is the correct component because it operates at the instance level and provides stateful traffic filtering, allowing return traffic automatically without requiring an outbound rule.

Adım Adım Çözüm

1
Analyze the requirement for a firewall rule that is stateful and operates at the instance level.
Identify that the component must apply to individual instances (not subnets) and automatically allow return traffic (stateful).
Filtering at the instance level requires instance-level firewalls, and stateful behavior means return traffic does not need explicit rules.
2
Evaluate the options to find which AWS service or configuration meets these characteristics.
A security group acts at the instance level and is stateful. A Network ACL acts at the subnet level and is stateless.
This distinguishes between the two primary firewall features in an Amazon VPC.

Anahtar Kavram

VPC Security Groups vs Network ACLs
Tahmini Süre:1m 0s
Bu soruyu puanla