Soru

Zorluk: OrtaAWS Network Services

A company is establishing a hybrid network environment. They need to securely connect their on-premises data center to a single Virtual Private Cloud (VPC) in AWS, and they also require a firewall mechanism that filters inbound and outbound traffic specifically at the subnet level. Which AWS networking and security components should the company implement to meet these requirements? (Select TWO.)

  1. Network Access Control Lists (Network ACLs)Cevap
  2. AWS Site-to-Site VPNCevap
  3. C
    Security Groups
  4. D
    AWS Transit Gateway
  5. E
    VPC Peering

Cevap

Network Access Control Lists (Network ACLs) and AWS Site-to-Site VPN are the correct components.
The correct options are Network Access Control Lists (Network ACLs) and AWS Site-to-Site VPN. Network ACLs operate at the subnet level to act as a stateless firewall for controlling traffic entering and leaving subnets. AWS Site-to-Site VPN provides a secure and cost-effective way to connect an on-premises data center to a single VPC.

Adım Adım Çözüm

1
Identify the requirement for filtering traffic at the subnet boundary.
Network Access Control Lists (Network ACLs) operate at the subnet level to filter traffic, fulfilling the security requirement.
Security groups, while also firewalls, operate at the instance level rather than the subnet level.
2
Identify the requirement to securely connect the on-premises data center to a single VPC.
AWS Site-to-Site VPN provides a secure IPsec connection between the on-premises network and the VPC.
Other services like AWS Transit Gateway are designed for complex hub-and-spoke architectures connecting multiple VPCs and networks, which is unnecessary for a single VPC connection.

Anahtar Kavram

Filtering subnet traffic using Network ACLs and establishing hybrid connectivity using VPN.
Bu soruyu puanla