Soru

Zorluk: OrtaAWS Network Services

A company is setting up a hybrid network architecture. They need to establish a dedicated, private physical connection between their on-premises data center and AWS that bypasses the public internet. Additionally, they must implement a stateless firewall to control inbound and outbound traffic at the subnet boundary.

Which two AWS networking services or features should the company configure to meet these requirements?

  1. AWS Direct ConnectCevap
  2. Network Access Control Lists (Network ACLs)Cevap
  3. C
    Security Groups
  4. D
    AWS Transit Gateway
  5. E
    VPC Peering

Cevap

The company should select AWS Direct Connect to establish a dedicated, private connection to their on-premises data center, and Network Access Control Lists (Network ACLs) to serve as a stateless firewall at the subnet boundary.
AWS Direct Connect establishes a dedicated, private physical network connection from the customer's on-premises environment to AWS, bypassing the public internet to deliver consistent performance. Network Access Control Lists (Network ACLs) serve as a stateless security layer at the subnet boundary, requiring explicit rules for both inbound and outbound traffic.

Adım Adım Çözüm

1
Analyze the connectivity requirement.
The company needs a dedicated, private physical connection bypassing the public internet. AWS Direct Connect is the service designed for this purpose.
AWS Direct Connect provides a dedicated physical connection to AWS, unlike a VPN which uses the public internet.
2
Analyze the security filtering requirement.
The company needs a stateless firewall to control inbound and outbound traffic at the subnet boundary. Network Access Control Lists (Network ACLs) operate at the subnet level and are stateless.
Network ACLs evaluate traffic at the subnet boundary and are stateless, requiring separate rules for inbound and outbound traffic.

Anahtar Kavram

AWS hybrid connectivity options and VPC network security boundaries.
Bu soruyu puanla