Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 470 discussion

A company wants to use Amazon WorkSpaces in combination with thin client devices to replace aging desktops. Employees use the desktops to access applications that work with Clinical trial data. Corporate security policy states that access to the applications must be restricted to only company branch office locations. The company is considering adding an additional branch office in the next 6 months.

Which solution meets these requirements with the MOST operational efficiency?

  • A. Create an IP access control group rule with the list of public addresses from the branch offices. Associate the IP access control group with the WorkSpaces directory.
  • B. Use AWS Firewall Manager to create a web ACL rule with an IPSet with the list of public addresses from the branch office locations. Associate the web ACL with the WorkSpaces directory.
  • C. Use AWS Certificate Manager (ACM) to issue trusted device certificates to the machines deployed in the branch office locations. Enable restricted access on the WorkSpaces directory.
  • D. Create a custom WorkSpace image with Windows Firewall configured to restrict access to the public addresses of the branch offices. Use the image to deploy the WorkSpaces.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
backbencher2022
3 weeks ago
Selected Answer: A
A is correct. B is incorrect because WAF web ACLs don't work with Amazon Workspaces. A web access control list (web ACL) gives you fine-grained control over all of the HTTP(S) web requests that your protected resource responds to. You can protect Amazon CloudFront, Amazon API Gateway, Application Load Balancer, AWS AppSync, Amazon Cognito, AWS App Runner, and AWS Verified Access resources. https://docs.aws.amazon.com/waf/latest/developerguide/web-acl.html
upvoted 1 times
...
trungtd
3 months ago
Selected Answer: A
This is not usecase of AWS Firewall Manager and web ACL, and A work
upvoted 2 times
...
iulian0585
3 months, 2 weeks ago
Selected Answer: A
B. AWS Firewall Manager and web ACL: While this could work, it is generally used for managing rules across multiple AWS accounts and resources, which might be an overcomplication for this specific use case. It is more complex to set up and manage compared to IP access control groups.
upvoted 1 times
...
red_panda
4 months ago
Selected Answer: B
From an operational simplicity point of view (which is what is required) it is clearly B. It is much easier to manage IPs with Firewall manager than in a custom way, which by the way remains vague. For me, the correct answer is B.
upvoted 1 times
neta1o
1 month ago
A would be done once for the entire WorkSpaces directory so it would be easy to manage and done centrally. https://docs.aws.amazon.com/workspaces/latest/adminguide/amazon-workspaces-ip-access-control-groups.html#associate-ip-access-control-group
upvoted 1 times
...
...
titi_r
4 months, 3 weeks ago
Selected Answer: A
Answer: A From the AWS Console: "Create an IP access control group that you can add to a WorkSpaces Directory. Users will only be able to access WorkSpaces from these IP addresses."
upvoted 2 times
...
tushar321
5 months ago
A https://docs.aws.amazon.com/workspaces/latest/adminguide/amazon-workspaces-ip-access-control-groups.html
upvoted 3 times
...
BrijMohan08
5 months, 1 week ago
Selected Answer: B
Using AWS Firewall Manager to create a web ACL rule with an IPSet containing the list of public addresses from the branch office locations and associating it with the WorkSpaces directory is the most operationally efficient solution. AWS Firewall Manager allows you to centrally manage and apply web access control lists (web ACLs) across multiple AWS resources, including WorkSpaces. This approach ensures that the access control policy is consistently applied across the WorkSpaces environment, and it can be easily updated as the company adds a new branch office location in the next 6 months.
upvoted 1 times
...
leliodesouza
5 months, 1 week ago
Selected Answer: B
According to ChatGPT: "Among these options, option B, using AWS Firewall Manager to create a web ACL rule with an IPSet, offers the most operational efficiency. It allows for centralized management of access control rules across multiple WorkSpaces and easily scales to accommodate future changes, such as adding a new branch office. Additionally, it aligns with the company's security policy by restricting access based on IP addresses. Therefore, option B is the best choice."
upvoted 1 times
...
pangchn
5 months, 3 weeks ago
Selected Answer: A
A https://docs.aws.amazon.com/workspaces/latest/adminguide/amazon-workspaces-ip-access-control-groups.html
upvoted 4 times
...
AWSPro1234
5 months, 3 weeks ago
Selected Answer: A
Correct answer is A.
upvoted 1 times
...
ahmadraufsyahputra
5 months, 4 weeks ago
correct answer A , need to add ip public for the branch offices to restrict access from branch offices only
upvoted 1 times
...
Dgix
5 months, 4 weeks ago
Selected Answer: A
A is the correct answer. It is the most operationally efficient as it uses IP access control groups.
upvoted 4 times
...
oayoade
5 months, 4 weeks ago
Selected Answer: A
Trust me
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...