exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 536 discussion

Exam question from Amazon's AWS-SysOps
Question #: 536
Topic #: 1
[All AWS-SysOps Questions]

An Amazon EC2 instance is in a private subnet. To SSH to the instance, it is required to use a bastion host that has an IP address of 10.0.0.5. SSH logs on the
EC2 instance in the private subnet show that connections are being made over SSH from several other IP addresses. The EC2 instance currently has the following inbound security group rules applied:

Protocol: TCP -

Port: 22 -

Source: 10.0.0.5/32 -

Protocol: TCP -

Port: 22 -

Source: sg-xxxxxxxx -

Protocol: TCP -

Port: 389 -

Source: 0.0.0.0/0 -
What is the MOST likely reason that another IP addresses is able to SSH to the EC2 instance?

  • A. The rule with 0.0.0.0/0 means SSH is open for any client to connect
  • B. The rule with /32 is not limiting to a single IP address
  • C. Any instance belonging to sg-xxxxxxxx is allowed to connect
  • D. There is an outbound rule allowing SSH traffic
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dkp
Highly Voted 7 months ago
Source: 0.0.0.0/0 port is allowed for 389. For ssh port used is 22. So the ans should be C.
upvoted 13 times
karmaah
6 months, 4 weeks ago
You are right.
upvoted 5 times
...
...
mukeshs
Highly Voted 7 months, 1 week ago
Answer should be C. There are other IP's in the security group that are also able to connect.
upvoted 10 times
omar_bahrain
7 months, 1 week ago
how about this "Warning If you use 0.0.0.0/0, you enable all IPv4 addresses to access your instance using SSH"!!!!
upvoted 4 times
...
...
TroyMcLure
Most Recent 5 months, 4 weeks ago
Correct Answer: C
upvoted 1 times
...
fqnn
6 months ago
I would say C SSH is port 22, I don't see how D. is the answer.
upvoted 1 times
fqnn
5 months, 4 weeks ago
Sorry for typo, I meant I don't see how A. is the answer
upvoted 1 times
...
...
a_w_s
6 months ago
C is teh good answer!
upvoted 2 times
...
ezat
6 months, 2 weeks ago
C is the answer
upvoted 2 times
...
sen12
6 months, 2 weeks ago
The question is about SSH and with the rule in option C which can allow all the IP's through port 22 (ssh) is the culprit.
upvoted 2 times
...
saumenP
7 months ago
C is correct
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago