exam questions

Exam AWS Certified Cloud Practitioner All Questions

View all questions & answers for the AWS Certified Cloud Practitioner exam

Exam AWS Certified Cloud Practitioner topic 1 question 388 discussion

Exam question from Amazon's AWS Certified Cloud Practitioner
Question #: 388
Topic #: 1
[All AWS Certified Cloud Practitioner Questions]

A company needs to apply security rules to specific Amazon EC2 instances.

Which AWS service or feature provides this functionality?

  • A. AWS WAF
  • B. Network ACLs
  • C. Amazon VPC
  • D. Security groups
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Pranava_GCP
1 year, 9 months ago
Selected Answer: D
D. Security groups "A security group acts as a virtual firewall for your EC2 instances to control incoming and outgoing traffic. Inbound rules control the incoming traffic to your instance, and outbound rules control the outgoing traffic from your instance. When you launch an instance, you can specify one or more security groups. If you don't specify a security group, Amazon EC2 uses the default security group for the VPC. You can add rules to each security group that allow traffic to or from its associated instances. You can modify the rules for a security group at any time. New and modified rules are automatically applied to all instances that are associated with the security group. When Amazon EC2 decides whether to allow traffic to reach an instance, it evaluates all of the rules from all of the security groups that are associated with the instance." https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-security-groups.html
upvoted 3 times
...
OMKAROC
1 year, 10 months ago
Hence "D" is a Right Answer
upvoted 3 times
...
aislin
1 year, 12 months ago
Selected Answer: D
The answer is D. While security groups are a part of Amazon VPC, it is the security group itself that filters traffic. You need to always choose the most specific, correct key.
upvoted 3 times
...
Guru4Cloud
2 years ago
Selected Answer: D
The AWS service or feature that provides functionality to apply security rules to specific Amazon EC2 instances is Security groups (D). Security groups are a fundamental feature of Amazon VPC that acts as a virtual firewall for EC2 instances. They enable you to control inbound and outbound traffic to your EC2 instances by defining rules that specify the allowed traffic's source and destination. Security groups can be applied at the instance level to specific instances or to an entire group of instances that share a common set of security requirements.
upvoted 3 times
...
RajithaR
2 years, 1 month ago
Selected Answer: D
The correct answer is D. Security groups provide the functionality to apply security rules to specific Amazon EC2 instances. Security groups act as virtual firewalls for your instances to control inbound and outbound traffic. You can add rules to a security group that allow traffic to or from its associated instances according to protocols, ports, and source or destination IP addresses.
upvoted 2 times
...
Saif93
2 years, 3 months ago
Selected Answer: D
D is the answer.
upvoted 2 times
...
NotMeAnyWay
2 years, 3 months ago
Selected Answer: D
D. Security groups AWS Security Groups are a feature of Amazon EC2 that allows you to apply security rules to specific instances. A security group acts as a virtual firewall for your instance to control inbound and outbound traffic. You can use security groups to control access to your instances based on IP address, protocol, and port number. A. AWS WAF: AWS WAF is a service that allows you to create web access control lists (ACLs) to control access to your web applications. It is not used to apply security rules to specific EC2 instances. B. Network ACLs: Network ACLs are used to control inbound and outbound traffic to and from a subnet in a VPC. They are not used to apply security rules to specific EC2 instances. C. Amazon VPC: Amazon VPC allows you to create a virtual network in the AWS cloud. You can use it to launch Amazon EC2 instances, RDS DB instances and other resources in a virtual network that you've defined. It does not provide the functionality of applying security rules to specific instances.
upvoted 4 times
...
HW4301
2 years, 3 months ago
D? My rationale is that you create the security rule in the security group 1st and then apply it to the EC2 instance. If the question is applying a security group to a specific instance then the answer would be AWS VPC. Thoughts?
upvoted 2 times
...
Vrush44
2 years, 4 months ago
Selected Answer: D
security groups
upvoted 3 times
...
dark_cherrymon
2 years, 4 months ago
Selected Answer: D
D, not C, c is traffic
upvoted 2 times
...
OvaltineJenkins
2 years, 5 months ago
Its D, you can create security groups and assign to EC2 instances without creating VPCs. The document you're linking is describing VPCs come with a default security group and additonal SGs can be created within that VPC.
upvoted 2 times
...
gabbani72
2 years, 5 months ago
Selected Answer: D
D was right!
upvoted 3 times
...
JA2018
2 years, 5 months ago
Selected Answer: C
updated response, should be C. https://docs.aws.amazon.com/vpc/latest/userguide/VPC_SecurityGroups.html
upvoted 1 times
...
Redes
2 years, 5 months ago
Selected Answer: D
Answer: D
upvoted 3 times
...
SLEON01
2 years, 5 months ago
Selected Answer: D
D, best option
upvoted 3 times
...
JA2018
2 years, 5 months ago
Selected Answer: D
Should be D.. SGs are stateful virtual FWs for assigned EC2 Instances
upvoted 3 times
JA2018
2 years, 5 months ago
Correction, should be C. You can refer to this: https://docs.aws.amazon.com/vpc/latest/userguide/VPC_SecurityGroups.html
upvoted 1 times
...
...
qwerty0911
2 years, 5 months ago
why is not D?
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago