Soru

Zorluk: OrtaAWS Network Services

A company is hosting a database cluster in a private subnet of an Amazon VPC. The security team requires a firewall solution that operates at the subnet boundary to block specific malicious traffic before it reaches any instances, regardless of their individual configurations. Which AWS feature should the company configure to meet this subnet-level security requirement?

  1. Network Access Control List (Network ACL)Cevap
  2. B
    Security Group
  3. C
    AWS Transit Gateway
  4. D
    AWS Shield Standard

Cevap

Network Access Control List (Network ACL)
The correct answer is Network Access Control List (Network ACL) because it acts as a stateless firewall that controls inbound and outbound traffic at the subnet boundary, applying to all instances inside that subnet.

Adım Adım Çözüm

1
Identify the level of network control required in the scenario.
The scenario specifies a requirement for a firewall that operates at the subnet boundary (subnet-level control).
This helps narrow down the choices between instance-level and subnet-level security features.
2
Evaluate the capabilities of the available network security options.
Network Access Control Lists (NACLs) operate at the subnet level and apply rules to all instances within that subnet, whereas security groups operate at the individual instance level.
Choosing the service that aligns with the subnet boundary requirement satisfies the security team's constraints.

Anahtar Kavram

AWS Network Security at the Subnet Level
Tahmini Süre:1m 0s
Bu soruyu puanla