ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 154 - CLF-C02 discussion

Report
Export

A company wants to establish a security layer in its VPC that will act as a firewall to control subnet traffic.

Which AWS service or feature will meet this requirement?

A.
Routing tables
Answers
A.
Routing tables
B.
Network access control lists (network ACLs)
Answers
B.
Network access control lists (network ACLs)
C.
Security groups
Answers
C.
Security groups
D.
Amazon GuardDuty
Answers
D.
Amazon GuardDuty
Suggested answer: C

Explanation:

Security groups are the service or feature that meets the requirement of establishing a security layer in a VPC that will act as a firewall to control subnet traffic. Security groups are stateful firewalls that control the inbound and outbound traffic at the instance level. You can assign one or more security groups to each instance in a VPC, and specify the rules that allow or deny traffic based on the protocol, port, and source or destination. Security groups are associated with network interfaces, and therefore apply to all the instances in the subnets that use those network interfaces. Routing tables are used to direct traffic between subnets and gateways, not to filter traffic. Network ACLs are stateless firewalls that control the inbound and outbound traffic at the subnet level, but they are less granular and more cumbersome to manage than security groups. Amazon GuardDuty is a threat detection service that monitors your AWS account and workloads for malicious or unauthorized activity, not a firewall service.

asked 16/09/2024
Shahir Kazmi
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first