ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 550 - CLF-C02 discussion

Report
Export

Which of the following services can be used to block network traffic to an instance? (Select TWO.)

A.
Security groups
Answers
A.
Security groups
B.
Amazon Virtual Private Cloud (Amazon VPC) flow logs
Answers
B.
Amazon Virtual Private Cloud (Amazon VPC) flow logs
C.
Network ACLs
Answers
C.
Network ACLs
D.
Amazon CloudWatch
Answers
D.
Amazon CloudWatch
E.
AWS CloudTrail
Answers
E.
AWS CloudTrail
Suggested answer: A, C

Explanation:

Security groups and network ACLs are two AWS services that can be used to block network traffic to an instance. Security groups are virtual firewalls that control the inbound and outbound traffic for your instances at the instance level. You can specify which protocols, ports, and source or destination IP addresses are allowed or denied for each instance.Security groups are stateful, which means that they automatically allow return traffic for any allowed inbound or outbound traffic123. Network ACLs are virtual firewalls that control the inbound and outbound traffic for your subnets at the subnet level. You can create rules to allow or deny traffic based on protocols, ports, and source or destination IP addresses.Network ACLs are stateless, which means that you have to explicitly allow return traffic for any allowed inbound or outbound traffic456.Reference:1:Security groups for your VPC - Amazon Virtual Private Cloud,2:Security Groups for Your VPC - Amazon Elastic Compute Cloud,3:AWS Security Groups: Everything You Need to Know,4:Network ACLs - Amazon Virtual Private Cloud,5:Control traffic to subnets using network ACLs - Amazon Virtual Private Cloud,6:AWS Network ACLs: Everything You Need to Know

asked 16/09/2024
Harri Jaakkonen
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first