exam questions

Exam AWS Certified Cloud Practitioner All Questions

View all questions & answers for the AWS Certified Cloud Practitioner exam

Exam AWS Certified Cloud Practitioner topic 1 question 171 discussion

Exam question from Amazon's AWS Certified Cloud Practitioner
Question #: 171
Topic #: 1
[All AWS Certified Cloud Practitioner Questions]

A company has multiple applications and is now building a new multi-tier application. The company will host the new application on Amazon EC2 instances. The company wants the network routing and traffic between the various applications to follow the security principle of least privilege.
Which AWS service or feature should the company use to enforce this principle?

  • A. Security groups
  • B. AWS Shield
  • C. AWS Global Accelerator
  • D. AWS Direct Connect gateway
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
JackFish
Highly Voted 2 years, 4 months ago
Selected Answer: A
A – Security groups control the traffic that is allowed to reach and leave the resources that it is associated with. AWS Shield is for DDoS protection. AWS Global Accelerator is for global reach. AWS Direct Connect is a cloud service that links your network directly to AWS to deliver consistent, low-latency performance.
upvoted 23 times
...
Kaal97
Most Recent 2 weeks, 6 days ago
Selected Answer: A
A. Security groups
upvoted 1 times
...
nhanmv92
1 year ago
Selected Answer: A
A. Security groups. Security groups are stateful firewalls that control inbound and outbound traffic at the instance level. By defining rules in security groups, you can control the traffic to your Amazon EC2 instances based on protocols, ports, and source/destination IP addresses. Security groups follow the principle of least privilege, allowing you to restrict traffic only to what is necessary for the application.
upvoted 2 times
...
Pranava_GCP
1 year, 6 months ago
Selected Answer: A
A. Security groups "A security group acts as a virtual firewall for your EC2 instances to control incoming and outgoing traffic. Inbound rules control the incoming traffic to your instance, and outbound rules control the outgoing traffic from your instance. When you launch an instance, you can specify one or more security groups. If you don't specify a security group, Amazon EC2 uses the default security group for the VPC. You can add rules to each security group that allow traffic to or from its associated instances. You can modify the rules for a security group at any time. New and modified rules are automatically applied to all instances that are associated with the security group. When Amazon EC2 decides whether to allow traffic to reach an instance, it evaluates all of the rules from all of the security groups that are associated with the instance." https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-security-groups.html
upvoted 1 times
...
man5484
1 year, 6 months ago
Selected Answer: A
Security groups are virtual firewalls that control inbound and outbound traffic at the instance level. They act as a first line of defense by allowing you to specify the protocols, ports, and source IP ranges that are allowed to access your instances. By configuring security groups appropriately, you can restrict network traffic to only what is necessary for the applications to communicate with each other, following the principle of least privilege. Security groups provide granular control over traffic at the instance level and can be easily configured and managed through the AWS Management Console, CLI, or SDKs. You can define specific rules to allow or deny traffic based on various criteria such as IP addresses, port numbers, and protocols.
upvoted 1 times
...
Vishal_Gupta
1 year, 10 months ago
Keyword here is EC2 instance. Security Gateway acts as a firewall for EC2 instances
upvoted 1 times
...
Saif93
2 years ago
Selected Answer: A
A is the answer.
upvoted 1 times
...
nder
2 years, 2 months ago
Selected Answer: A
Security groups act as a firewall at the INSTANCE level
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago