exam questions

Exam AWS Certified Cloud Practitioner All Questions

View all questions & answers for the AWS Certified Cloud Practitioner exam

Exam AWS Certified Cloud Practitioner topic 1 question 50 discussion

Exam question from Amazon's AWS Certified Cloud Practitioner
Question #: 50
Topic #: 1
[All AWS Certified Cloud Practitioner Questions]

A company recently deployed an Amazon RDS instance in its VPC. The company needs to implement a stateful firewall to limit traffic to the private corporate network.
Which AWS service or feature should the company use to limit network traffic directly to its RDS instance?

  • A. Network ACLs
  • B. Security groups
  • C. AWS WAF
  • D. Amazon GuardDuty
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
HaslinaF
Highly Voted 2 years, 3 months ago
stateless-Netwrok ACL stateful ; security group
upvoted 62 times
...
V_a_r_u_n
Highly Voted 2 years, 1 month ago
Selected Answer: B
AWS WAF is a web application firewall that lets you monitor the HTTP(S) requests that are forwarded to your protected web application resources. You can protect the following resource types: Amazon CloudFront distribution Amazon API Gateway REST API Application Load Balancer AWS AppSync GraphQL API Amazon Cognito user pool
upvoted 16 times
...
Dipa_2910
Most Recent 4 days ago
Selected Answer: B
Option B - Security groups . security groups are statefull firewall
upvoted 1 times
...
Dipa_2910
4 days, 22 hours ago
Selected Answer: B
security groups are statefull firewall NACL are stateless
upvoted 1 times
...
sonaljain
1 month, 1 week ago
Selected Answer: B
Security groups
upvoted 1 times
...
Drashti51
7 months, 1 week ago
Selected Answer: B
Amazon RDS security groups enable you to manage network access to your Amazon RDS instances. With security groups, you specify sets of IP addresses using CIDR notation, and only network traffic originating from these addresses is recognized by your Amazon RDS instance. Although they function in a similar way, Amazon RDS security groups are different from Amazon EC2 security groups. It is possible to add an EC2 security group to your RDS security group. Any EC2 instances that are members of the EC2 security group are then able to access the RDS instances that are members of the RDS security group.
upvoted 3 times
...
PearlR
11 months ago
It is SECURITY GROUPS.. it could have been WAF but WAF is staeless
upvoted 2 times
...
Reidy
1 year ago
Selected Answer: B
B. Security groups
upvoted 1 times
...
med_dernoun
1 year, 3 months ago
Selected Answer: A
NACL that is working on the subnet level
upvoted 1 times
...
backslash_cc
1 year, 4 months ago
Selected Answer: B
WAF is stateless. The question asks for a statefull service, hence Security Groups.
upvoted 2 times
...
Yuval711
1 year, 5 months ago
Selected Answer: B
According to this article: https://aws.amazon.com/blogs/database/applying-best-practices-for-securing-sensitive-data-in-amazon-rds/ Both WAS and SG are recommended but since the word "stateful" was used.... I'm gonna go with Security Groups
upvoted 2 times
...
Soumya198725
1 year, 6 months ago
Stateful firewall mentioned means Security group
upvoted 1 times
...
Tarasharma
1 year, 6 months ago
wy is the admin gicign wrong answer ?
upvoted 1 times
...
Hayden001
1 year, 6 months ago
B is correct
upvoted 1 times
...
sri073
1 year, 6 months ago
Selected Answer: B
stateful firewall--security group
upvoted 1 times
...
tuan_nn
1 year, 7 months ago
Selected Answer: B
B is correct
upvoted 1 times
...
man5484
1 year, 7 months ago
Selected Answer: B
Security groups are a fundamental feature of AWS that act as stateful firewalls for controlling inbound and outbound traffic at the instance level. They provide granular control over traffic by allowing or denying specific protocols, ports, and IP ranges. To limit network traffic to the Amazon RDS instance, the company can configure the associated security group to only allow inbound connections from the private corporate network. By specifying the appropriate rules, the company can restrict access to the RDS instance to only the necessary IP addresses or IP ranges.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago