exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C02 exam

Exam AWS Certified Solutions Architect - Associate SAA-C02 topic 1 question 236 discussion

A company uses Application Load Balancers (ALBs) in different AWS Regions. The ALBs receive inconsistent traffic that can spike and drop throughout the year.
The company's networking team needs to allow the IP addresses of the ALBs in the on-premises firewall to enable connectivity.
Which solution is the MOST scalable with minimal configuration changes?

  • A. Write an AWS Lambda script to get the IP addresses of the ALBs in different Regions. Update the on-premises firewall's rule to allow the IP addresses of the ALBs.
  • B. Migrate all ALBs in different Regions to the Network Load Balancer (NLBs). Update the on-premises firewall's rule to allow the Elastic IP addresses of all the NLBs.
  • C. Launch AWS Global Accelerator. Register the ALBs in different Regions to the accelerator. Update the on-premises firewall's rule to allow static IP addresses associated with the accelerator.
  • D. Launch a Network Load Balancer (NLB) in one Region. Register the private IP addresses of the ALBs in different Regions with the NLB. Update the on- premises firewall's rule to allow the Elastic IP address attached to the NLB.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dzenadcu
Highly Voted 3 years, 6 months ago
C is correct. Use AWS Global Accelerator, get a static IP for whitelisting on firewalls. No need to replace ALBs with NLBs ! "You can associate these addresses to regional AWS resources or endpoints, such as Application Load Balancers, Network Load Balancers,..."
upvoted 26 times
farciarz212
3 years, 4 months ago
what is the cost?
upvoted 1 times
...
...
jy00271070
Highly Voted 3 years, 7 months ago
C is OK
upvoted 25 times
...
Rekhaachu
Most Recent 2 years ago
Can I use AWS Global Accelerator for my on-premises services? A: You can't directly configure on-premises resources as endpoints for your static IP addresses, but you can configure a Network Load Balancer (NLB) in each AWS Region to address your on-premises endpoints.
upvoted 1 times
...
Shane_theNetworkGuy
2 years, 8 months ago
Selected Answer: C
The question says register ALBs IP address which is definitely a typo. I guess they mean NLB. GA is the way to go, no doubt. 1) Traffic is fluctuating 2)Static 3) Global
upvoted 1 times
...
jj22222
3 years, 4 months ago
C looks right
upvoted 1 times
...
Ultron00
3 years, 4 months ago
C is correct!
upvoted 1 times
...
ansarica
3 years, 5 months ago
GA provides static IP which we can bind in the firewall, and GA can be associated with ALB.
upvoted 4 times
...
charlpl
3 years, 5 months ago
D would also be an option, if it was in multiple regions. This is actually also a recommendation by AWS. put an elastic IP NLB in front of your ALB
upvoted 1 times
Spike2020
3 years, 5 months ago
you mean if it was not in multiple region!!!?
upvoted 1 times
...
...
syu31svc
3 years, 6 months ago
Answer is C https://aws.amazon.com/global-accelerator/faqs/: "Associate the static IP addresses provided by AWS Global Accelerator to regional AWS resources or endpoints, such as Network Load Balancers, Application Load Balancers, EC2 Instances, and Elastic IP addresses"
upvoted 6 times
...
KK_uniq
3 years, 6 months ago
When you need static IP think GA
upvoted 11 times
...
Yogi
3 years, 6 months ago
Ans=C. Launch AWS Global Accelerator. Register the ALBs in different Regions to the accelerator. Update the on-premises firewall's rule to allow static IP addresses associated with the accelerator.
upvoted 5 times
...
toto059
3 years, 6 months ago
it is came and answer is C
upvoted 2 times
...
cthunder
3 years, 6 months ago
I think it is C as Global accelerator will provide a static ip which can be used on the Firewall "When you create an Application Load Balancer in the AWS Management Console, you can optionally add an accelerator at the same time. Elastic Load Balancing and Global Accelerator work together to transparently add the accelerator for you. The accelerator is created in your account, with the load balancer as an endpoint.### Using an accelerator provides static IP addresses and improves the availability and performance of your applications.###"
upvoted 3 times
...
kishan729
3 years, 6 months ago
I am going with B. The primary requirement is to get connectivity to the ALBs via on-prem firewall. But for IP we need NLB & hence replace that and configure firewall. Why get global accelerator to get a set of IP? - the functionality of global accelerator is way big that that, which is not part of the requirement here. Also NLB will help with performing better with spikes (which is a mention, but not a requirement)
upvoted 2 times
chronoler
3 years, 6 months ago
Because Global Accelerator is regional service load balancing, NLB does AZ load balancing, the question points to solve load balancing between aws regions.
upvoted 2 times
...
...
anpt
3 years, 6 months ago
CCCCCCCCCCCCCCCCCCC
upvoted 5 times
...
aguy9
3 years, 6 months ago
I think the answer is C because By using AWS Global Accelerator, you can: “Associate the static IP addresses provided by AWS Global Accelerator to regional AWS resources or endpoints, such as Network Load Balancers, Application Load Balancers,” “Corporate proxies can also whitelist your application’s static IP addresses in their firewalls.” https://aws.amazon.com/global-accelerator/faqs/
upvoted 5 times
...
dph0009
3 years, 6 months ago
C is Okay
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago