Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 697 discussion

A solutions architect creates a VPC that includes two public subnets and two private subnets. A corporate security mandate requires the solutions architect to launch all Amazon EC2 instances in a private subnet. However, when the solutions architect launches an EC2 instance that runs a web server on ports 80 and 443 in a private subnet, no external internet traffic can connect to the server.

What should the solutions architect do to resolve this issue?

  • A. Attach the EC2 instance to an Auto Scaling group in a private subnet. Ensure that the DNS record for the website resolves to the Auto Scaling group identifier.
  • B. Provision an internet-facing Application Load Balancer (ALB) in a public subnet. Add the EC2 instance to the target group that is associated with the ALEnsure that the DNS record for the website resolves to the ALB.
  • C. Launch a NAT gateway in a private subnet. Update the route table for the private subnets to add a default route to the NAT gateway. Attach a public Elastic IP address to the NAT gateway.
  • D. Ensure that the security group that is attached to the EC2 instance allows HTTP traffic on port 80 and HTTPS traffic on port 443. Ensure that the DNS record for the website resolves to the public IP address of the EC2 instance.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
sandordini
5 months, 3 weeks ago
Selected Answer: B
Not A - Autoscaling Irrelevant B - ALB, route tales for the public subnet with a route to Priv subnet C - "NAT gateway" is "to allow [outbound] internet traffic", but this is about inbound traffic D - Instances are in the private subnet, therefore it wont work from the public.
upvoted 3 times
...
waldirlsantos
6 months ago
Why not "D"?
upvoted 1 times
...
boluwatito
6 months, 1 week ago
Selected Answer: D
nsure that the security group attached to the EC2 instance allows inbound traffic on ports 80 and 443 from the desired sources (e.g., any IP or specific IP ranges). This allows external internet traffic to reach the web server running on the EC2 instance
upvoted 1 times
...
TruthWS
6 months, 3 weeks ago
B - because ALB do it better NAT
upvoted 1 times
...
Cali182
8 months, 1 week ago
Selected Answer: C
Option C from Chatgt
upvoted 1 times
lenotc
6 months, 3 weeks ago
NAT Gateway outbound connections
upvoted 1 times
...
jaswantn
8 months, 1 week ago
NAT Gateway stays in public subnet, not in private subnet. So, C can't be.
upvoted 5 times
...
...
anikolov
8 months, 1 week ago
Selected Answer: B
B: Provision an internet-facing Application Load Balancer (ALB) in a public subnet makes more sense
upvoted 4 times
...
mestule
8 months, 1 week ago
Selected Answer: B
B makes most sense
upvoted 3 times
...
Andy_09
8 months, 1 week ago
Changing to option D
upvoted 1 times
...
Andy_09
8 months, 1 week ago
C should be the correct answer
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...