Soru

Zorluk: KolayNetwork and Infrastructure Security

A cloud practitioner is designing a database subnet within an Amazon VPC and needs to apply a firewall rule set at the subnet boundary. The configuration must be stateless, requiring both inbound and outbound traffic rules to be explicitly defined. Which AWS service or feature should be implemented to meet this requirement?

  1. A
    Security Groups
  2. Network Access Control Lists (Network ACLs)Cevap
  3. C
    Amazon GuardDuty
  4. D
    AWS Shield Standard

Cevap

Network Access Control Lists (Network ACLs)
Network Access Control Lists (Network ACLs) act as a stateless firewall at the subnet boundary. Because they are stateless, any allowed inbound traffic must also have a corresponding outbound rule to allow return traffic (and vice versa).

Adım Adım Çözüm

1
Analyze the security boundary requirement.
The requirement specifies applying traffic filtering rules at the subnet boundary, which points to a subnet-level control.
This narrows the choices down to subnet-level features rather than instance-level features.
2
Evaluate the statefulness requirement.
The requirement specifies that the firewall must be stateless, meaning that both inbound and outbound rules must be explicitly allowed.
Network Access Control Lists (Network ACLs) are stateless subnet-level firewalls, whereas Security Groups are stateful instance-level firewalls.

Anahtar Kavram

Understanding the stateless and subnet-level characteristics of Network Access Control Lists (Network ACLs)
Tahmini Süre:45s
Bu soruyu puanla