ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 191 - CLF-C02 discussion

Report
Export

Which task can a company perform by using security groups in the AWS Cloud?

A.
Allow access to an Amazon EC2 instance through only a specific port.
Answers
A.
Allow access to an Amazon EC2 instance through only a specific port.
B.
Deny access to malicious IP addresses at a subnet level.
Answers
B.
Deny access to malicious IP addresses at a subnet level.
C.
Protect data that is cached by Amazon CloudFront.
Answers
C.
Protect data that is cached by Amazon CloudFront.
D.
Apply a stateless firewall to an Amazon EC2 instance.
Answers
D.
Apply a stateless firewall to an Amazon EC2 instance.
Suggested answer: A

Explanation:

Security groups are virtual firewalls that control the inbound and outbound traffic for Amazon EC2 instances. They can be used to allow access to an Amazon EC2 instance through only a specific port, such as port 22 for SSH or port 80 for HTTP. Security groups cannot deny access to malicious IP addresses at a subnet level, as they only allow or deny traffic based on the rules defined by the customer. To block malicious IP addresses, customers can use network ACLs, which are stateless firewalls that can be applied to subnets. Security groups cannot protect data that is cached by Amazon CloudFront, as they only apply to EC2 instances. To protect data that is cached by Amazon CloudFront, customers can use encryption, signed URLs, or signed cookies. Security groups are not stateless firewalls, as they track the state of the traffic and automatically allow the response traffic to flow back to the source. Stateless firewalls do not track the state of the traffic and require rules for both inbound and outbound traffic.

asked 16/09/2024
Christian Gyssels
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first