exam questions

Exam AWS Certified Advanced Networking - Specialty ANS-C01 All Questions

View all questions & answers for the AWS Certified Advanced Networking - Specialty ANS-C01 exam

Exam AWS Certified Advanced Networking - Specialty ANS-C01 topic 1 question 194 discussion

A company is using an Amazon CloudFront distribution that is configured with an Application Load Balancer (ALB) as an origin. A network engineer needs to implement a solution that requires all inbound traffic to the ALB to come from CloudFront. The network engineer must implement the solution at the network layer rather than in the application.

Which solution will meet these requirements in the MOST operationally efficient way?

  • A. Add an inbound rule to the ALB's security group to allow the AWS managed prefix list for CloudFront.
  • B. Add an inbound rule to the network ACLs that are associated with the ALB's subnets. Use the AWS managed prefix list for CloudFront as the source in the rule.
  • C. Configure CloudFront to add a custom HTTP header to the requests that CloudFront sends to the ALB.
  • D. Associate an AWS WAF web ACL with the ALB. Configure the AWS WAF rules to allow traffic from the CloudFront IP set. Automatically update the CloudFront IP set by using an AWS Lambda function.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
veyisceylan
Highly Voted 5 months, 3 weeks ago
It is asking a solution at network layer rather than application layer. Therefore it is A in my opinion. A managed prefix list is a set of one or more CIDR blocks. You can use prefix lists to make it easier to configure and maintain your security groups and route tables.
upvoted 6 times
...
woorkim
Most Recent 1 day, 3 hours ago
Selected Answer: A
AWS Managed Prefix List for CloudFront: AWS provides a managed prefix list that includes the IP ranges for CloudFront edge locations. By using this list in the ALB's security group, the network engineer can restrict access to only traffic originating from CloudFront without manually managing IP ranges. Operational Efficiency: This approach is operationally efficient because: The managed prefix list is automatically updated by AWS whenever CloudFront's IP ranges change. Security groups are simple to configure and maintain compared to other options like network ACLs or AWS WAF.
upvoted 1 times
...
Spaurito
1 month, 1 week ago
C - This defines the solution https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/restrict-access-to-load-balancer.html
upvoted 1 times
Spaurito
1 month ago
Have to change my answer to "A". A defined for the network layer requirement.
upvoted 1 times
...
...
[Removed]
3 months, 4 weeks ago
Selected Answer: A
Question explicitly ask for changes at network layer.
upvoted 3 times
...
Akshay0403
4 months, 3 weeks ago
Selected Answer: A
Option A is the most operationally efficient solution as it leverages AWS managed prefix lists, ensuring up-to-date and secure traffic management to the ALB from CloudFront. Security groups provide a straightforward way to enforce network layer restrictions without additional administrative overhead or application changes. This aligns well with the requirement to implement a solution strictly at the network layer.
upvoted 3 times
...
Blitz1
4 months, 4 weeks ago
Selected Answer: A
A because is saying at network layer. https://aws.amazon.com/about-aws/whats-new/2022/02/amazon-cloudfront-managed-prefix-list/
upvoted 2 times
...
rdiaz
6 months ago
Selected Answer: C
cloudfront header and alb condition
upvoted 2 times
...
AXH
6 months, 1 week ago
Voting for C.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago