exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 783 discussion

Exam question from Amazon's AWS-SysOps
Question #: 783
Topic #: 1
[All AWS-SysOps Questions]

A VPC is connected to a company data center by a VPN. An Amazon EC2 instance with the IP address 172.31.16.139 is within a private subnet of the VPC. A
SysOps Administrator issued a ping command to the EC2 instance from an on-premises computer with the IP address 203.0.113.12 and did not receive an acknowledgment. VPC Flow Logs were enabled and showed the following:

What action will resolve the issue?

  • A. Modify the EC2 security group rules to allow inbound traffic from the on-premises computer
  • B. Modify the EC2 security group rules to allow outbound traffic to the on-premises computer
  • C. Modify the VPC network ACL rules to allow inbound traffic from the on-premises computer
  • D. Modify the VPC network ACL rules to allow outbound traffic to the on-premises computer
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
doofenshmirtz
6 months, 1 week ago
ok i get it its D
upvoted 1 times
...
gulu73
1 year, 2 months ago
Selected Answer: D
D is the answer
upvoted 1 times
...
Bunchie
1 year, 9 months ago
D is Correct. Th ping is from 203.0.113.12 to 172.31.16.13 9: The security group's inbound rules allow ICMP traffic, but the outbound rules do not allow ICMP traffic. Because security groups are stateful, the response ping from your instance is allowed. The network ACL permits inbound ICMP traffic but does not permit outbound ICMP traffic. Network ACLs are stateless, then the response ping is dropped.
upvoted 1 times
...
[Removed]
1 year, 11 months ago
[sampleXML/xmlfile-413 1.png] contains - 2 123456789010 eni-1234abcd 3.104.75.244 172.31.10.10 0 0 1 4 336 1432917027 1432917142 ACCEPT OK 2 123456789010 eni-1234abcd 172.31.10.10 3.104.75.244 0 0 1 4 336 1432917094 1432917142 REJECT OK
upvoted 1 times
[Removed]
1 year, 11 months ago
only IPs are different
upvoted 1 times
...
...
ahaffar
2 years, 5 months ago
All the ansears are incorrect If your network ACL permits outbound ICMP traffic, the flow log displays two ACCEPT records (one for the originating ping and one for the response ping). If your security group denies inbound ICMP traffic, the flow log displays a single REJECT record, because the traffic was not permitted to reach your instance. https://docs.aws.amazon.com/vpc/latest/userguide/flow-logs-records-examples.html#flow-log-example-security-groups this is a repeated Q and ICMP is blocked by default https://docs.aws.amazon.com/vpc/latest/userguide/flow-logs-records-examples.html#flow-log-example-security-groups
upvoted 1 times
wahlbergusa
2 years, 5 months ago
Answer is D. Read RicardoD' s summary below. It is simple enough.
upvoted 2 times
...
...
TroyMcLure
2 years, 6 months ago
Correct Answer: D
upvoted 3 times
...
alexsandroe
2 years, 6 months ago
D. Modify the VPC network ACL rules to allow outbound traffic to the on-premises computer
upvoted 1 times
...
RicardoD
2 years, 6 months ago
D is the answer SG is stateful, so no need to set outbound NACL is stateless, so what comes in, will not be allowed to come out automatically, hence you need to declare it
upvoted 1 times
...
thirusk
2 years, 6 months ago
D - Allow outbound using NACL
upvoted 2 times
...
Azaad78
2 years, 7 months ago
D- this a NACL problem because they are stateless. SGs are stateful so any allowed in traffic is allowed response out and visa versa.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago