exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 254 discussion

A company is reviewing a recent migration of a three-tier application to a VPC. The security team discovers that the principle of least privilege is not being applied to Amazon EC2 security group ingress and egress rules between the application tiers.

What should a solutions architect do to correct this issue?

  • A. Create security group rules using the instance ID as the source or destination.
  • B. Create security group rules using the security group ID as the source or destination.
  • C. Create security group rules using the VPC CIDR blocks as the source or destination.
  • D. Create security group rules using the subnet CIDR blocks as the source or destination.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Aninina
Highly Voted 1 year, 5 months ago
Selected Answer: B
B. Create security group rules using the security group ID as the source or destination. This way, the security team can ensure that the least privileged access is given to the application tiers by allowing only the necessary communication between the security groups. For example, the web tier security group should only allow incoming traffic from the load balancer security group and outgoing traffic to the application tier security group. This approach provides a more granular and secure way to control traffic between the different tiers of the application and also allows for easy modification of access if needed. It's also worth noting that it's good practice to minimize the number of open ports and protocols, and use security groups as a first line of defense, in addition to network access control lists (ACLs) to control traffic between subnets.
upvoted 13 times
...
Wael216
Highly Voted 1 year, 3 months ago
Selected Answer: B
By using security group IDs, the ingress and egress rules can be restricted to only allow traffic from the necessary source or destination, and to deny all other traffic. This ensures that only the minimum required traffic is allowed between the application tiers. Option A is not the best choice because using the instance ID as the source or destination would allow traffic from any instance with that ID, which may not be limited to the specific application tier. Option C is also not the best choice because using VPC CIDR blocks would allow traffic from any IP address within the VPC, which may not be limited to the specific application tier. Option D is not the best choice because using subnet CIDR blocks would allow traffic from any IP address within the subnet, which may not be limited to the specific application tier.
upvoted 9 times
...
Guru4Cloud
Most Recent 9 months, 2 weeks ago
Selected Answer: B
Create security group rules using the security group ID as the source or destination. This way, the security team can ensure that the least privileged access is given to the application tiers by allowing only the necessary communication between the security groups. For example, the web tier security group should only allow incoming traffic from the load balancer security group and outgoing traffic to the application tier security group. This approach provides a more granular and secure way to control traffic between the different tiers of the application and also allows for easy modification of access if needed. It's also worth noting that it's good practice to minimize the number of open ports and protocols, and use security groups as a first line of defense, in addition to network access control lists (ACLs) to control traffic between subnets.
upvoted 2 times
...
cookieMr
12 months ago
Selected Answer: B
A. would limit the traffic based on specific instances, which may not be the most suitable solution for applying the principle of least privilege between application tiers. B. By using security group IDs in the rules, you can precisely control the traffic between application tiers, allowing only the necessary communication and adhering to the principle of least privilege. C. would apply broad rules based on the entire VPC CIDR blocks, which may not provide the necessary level of granularity required for secure communication between specific application tiers. D. would limit the traffic based on subnet CIDR blocks, which may not be sufficient for ensuring proper security between application tiers. In summary, using security group IDs (Option B) is the recommended approach as it allows for precise control of traffic between application tiers, aligning with the principle of least privilege.
upvoted 6 times
foha2012
5 months ago
with option A. How would you use instance ID in security group inbound rules ?
upvoted 2 times
...
...
Bmarodi
1 year ago
Selected Answer: B
I vote for option B.
upvoted 2 times
...
LuckyAro
1 year, 5 months ago
Selected Answer: B
. Create security group rules using the security group ID as the source or destination
upvoted 2 times
...
techhb
1 year, 5 months ago
Security Group Rulesapply to instances https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/security-group-rules.html
upvoted 2 times
...
mhmt4438
1 year, 5 months ago
Selected Answer: B
Correct answer is B
upvoted 3 times
...
bamishr
1 year, 5 months ago
Selected Answer: B
https://www.examtopics.com/discussions/amazon/view/46463-exam-aws-certified-solutions-architect-associate-saa-c02/
upvoted 2 times
...
Morinator
1 year, 5 months ago
Selected Answer: B
B right https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/security-group-rules.html
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago