ExamGecko
Question list
Search
Search

Related questions











Question 865 - CLF-C01 discussion

Report
Export

A company provides Amazon Workspaces to its remote employees. The company wants to prevent employees from using their virtual desktops to visit specific websites that are known to be malicious.

Which AWS service should the company use to meet this requirement?

A.
AWS Shield Advanced
Answers
A.
AWS Shield Advanced
B.
Amazon Route 53
Answers
B.
Amazon Route 53
C.
Amazon GuardDuty
Answers
C.
Amazon GuardDuty
D.
AWS Network Firewall
Answers
D.
AWS Network Firewall
Suggested answer: D

Explanation:

Explanation:

https://aws.amazon.com/blogs/desktop-and-application-streaming/filtering-internet-traffic-fromamazon-workspaces/

AWS Network Firewall extends protection beyond SG- and NACL-levels by protecting at the route level and offering stateless and stateful rules from layers 3 through 7 in the OSI Model. It uses the certificate fully qualified domain name (FQDN) or Server Name Indication (SNI) to determine if a website is allowed for HTTPS traffic. This is a commonly requested security requirement. Reviewing these design examples of AWS Network Firewall will accelerate your migration to Amazon WorkSpaces. AWS Network Firewall is a managed service, with no infrastructure to manage or patch you can simplify operational excellence. Native settings for advanced filtering (including domain name), and network traffic inspection can alert and block traffic related to malware. It also has layer 7 intrusion prevent system (IPS) rules, and the ability to apply TLS fingerprinting to prevent a spoofed IP or FQDN.

asked 16/09/2024
Giuseppina Mancinelli
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first