Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Advanced Networking - Specialty ANS-C01 All Questions

View all questions & answers for the AWS Certified Advanced Networking - Specialty ANS-C01 exam

Exam AWS Certified Advanced Networking - Specialty ANS-C01 topic 1 question 125 discussion

A company plans to run a computationally intensive data processing application on AWS. The data is highly sensitive. The VPC must have no direct internet access, and the company has applied strict network security to control access.

Data scientists will transfer data from the company's on-premises data center to the instances by using an AWS Site-to-Site VPN connection. The on-premises data center uses the network range 172.31.0.0/20 and will use the network range 172.31.16.0/20 in the application VPC.

The data scientists report that they can start new instances of the application but that they cannot transfer any data from the on-premises data center. A network engineer enables VPC flow logs and sends a ping to one of the instances to test reachability. The flow logs show the following:



The network engineer must recommend a solution that will give the data scientists the ability to transfer data from the on-premises data center.

Which solution will meet these requirements?

  • A. Modify the security group for the application. Add an inbound rule to allow traffic from the on-premises data center network range to the application.
  • B. Modify the network ACLs for the VPC subnet. Add an inbound rule to allow traffic from the on-premises data center network range to the VPC subnet range.
  • C. Modify the network ACLs for the VPC subnet. Add an outbound rule to allow traffic from the VPC subnet range to the on-premises data center network range.
  • D. Modify the security group for the application. Add an outbound rule to allow traffic from the application to the on-premises data center network range.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Newbies
5 months, 3 weeks ago
Ans is A - B:Modifying the outbound ACL wouldn't address the inability to initiate data transfer from the on-premises side.
upvoted 1 times
Newbies
5 months, 3 weeks ago
Sorry D is the answer
upvoted 1 times
...
...
Marfee400704
7 months, 1 week ago
I think that it's correct answer is C according to SPOTO products.
upvoted 1 times
...
GaryQian
7 months, 1 week ago
Selected Answer: C
Only ACL can add rules for CIDER range. And the reject happen from AWS to On-prem so it is outbound issue
upvoted 3 times
...
Arad
10 months, 2 weeks ago
Selected Answer: C
Obviously C.
upvoted 1 times
...
Neo00
1 year, 2 months ago
Selected Answer: C
C. Return traffic was blocked by NACL, outbound should be allowed
upvoted 3 times
...
tcp22
1 year, 3 months ago
C for sure
upvoted 2 times
...
RVD
1 year, 3 months ago
Selected Answer: C
issue with Outbound NACL
upvoted 3 times
...
Balasmaniam
1 year, 3 months ago
Selected Answer: C
NACL rejects outbound
upvoted 1 times
...
papercuts23
1 year, 3 months ago
Selected Answer: C
Agreed. Outbound is reject.
upvoted 1 times
...
takecoffe
1 year, 3 months ago
Selected Answer: C
yeah outbound is rules needs to added
upvoted 1 times
...
demoras
1 year, 3 months ago
Selected Answer: C
Answer should be C
upvoted 1 times
...
Awadhesh
1 year, 3 months ago
Answer should be C
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...