exam questions

Exam AWS Certified Cloud Practitioner CLF-C02 All Questions

View all questions & answers for the AWS Certified Cloud Practitioner CLF-C02 exam

Exam AWS Certified Cloud Practitioner CLF-C02 topic 1 question 59 discussion

Which of the following services can be used to block network traffic to an instance? (Choose two.)

  • A. Security groups
  • B. Amazon Virtual Private Cloud (Amazon VPC) flow logs
  • C. Network ACLs
  • D. Amazon CloudWatch
  • E. AWS CloudTrail
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TheFivePips
Highly Voted 1 year, 3 months ago
Selected Answer: AC
Security groups: Act as a virtual firewall for instances, controlling inbound and outbound traffic. They are associated with instances and operate at the instance level. You can configure security group rules to allow or deny traffic based on IP addresses, port ranges, and protocols. Network ACLs: Are an additional layer of security for your VPC. They operate at the subnet level and are stateless, meaning they evaluate rules for inbound and outbound traffic separately. Network ACLs can be used to allow or deny traffic based on IP addresses, port ranges, and protocols. Amazon Virtual Private Cloud (Amazon VPC) flow logs: Capture information about the IP traffic going to and from network interfaces in a VPC. While they provide visibility into network traffic, they don't block or control traffic. Amazon CloudWatch: A monitoring service that collects and tracks metrics, logs, and events from various AWS resources. It is not used for blocking network traffic to an instance. AWS CloudTrail: Provides a record of actions taken by users, roles, or services within an AWS account. It does not block network traffic but helps in auditing and tracking API calls.
upvoted 7 times
...
felixlugo06
Highly Voted 1 year, 6 months ago
A. Security groups C. Network ACLs Security groups are stateful firewalls that control inbound and outbound traffic at the instance level. You can configure security groups to allow or deny specific types of network traffic to and from your instances. Network ACLs (Access Control Lists) are stateless firewalls that control traffic at the subnet level. Network ACLs define rules to allow or deny traffic based on source and destination IP addresses, ports, and protocols.
upvoted 7 times
...
Sir_Kay
Most Recent 2 months ago
Selected Answer: AC
oth Security groups and Network ACLs are used to control and block network traffic to and from Amazon EC2 instances.
upvoted 1 times
...
Amin_013
3 months, 4 weeks ago
Selected Answer: AC
A. Security groups C. Network ACLs
upvoted 1 times
...
SrikanthNL
4 months, 2 weeks ago
Selected Answer: AC
Security Groups is just an ALLOW List, How can you block a traffic using Security group? Well whatever is not mentioned in security group is not allowed by Default :) Tricky huh
upvoted 1 times
...
GPFT
8 months, 1 week ago
Selected Answer: AC
a and c is ok
upvoted 1 times
...
Ruffyit
1 year, 2 months ago
A. Security groups C. Network ACLs Security groups are stateful firewalls that control inbound and outbound traffic at the instance level. You can configure security groups to allow or deny specific types of network traffic to and from your instances. Network ACLs (Access Control Lists) are stateless firewalls that control traffic at the subnet level. Network ACLs define rules to allow or deny traffic based on source and destination IP addresses, ports, and protocols.
upvoted 1 times
...
rankocertified
1 year, 5 months ago
Selected Answer: AC
A is obvious: it is applied at instance level and controls traffic at instance level. C is a bit tricky: NACL is applied at subnet level but it controls traffic based on source & destination. Here you can set a rule set for the instance both "in" (destination) and "out" (source)
upvoted 1 times
...
lunamuller
1 year, 5 months ago
Selected Answer: AC
Answers AC are Correct.
upvoted 1 times
...
ezeadnah
1 year, 6 months ago
Selected Answer: AC
A: Security group limits access to the instance C: blocks network access on the subnet level
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago