ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 539 - DOP-C01 discussion

Report
Export

Which of these configuration or deployment practices is a security risk for RDS?

A.
Storing SQL function code in plaintext
Answers
A.
Storing SQL function code in plaintext
B.
Non-Multi-AZ RDS instance
Answers
B.
Non-Multi-AZ RDS instance
C.
Having RDS and EC2 instances exist in the same subnet
Answers
C.
Having RDS and EC2 instances exist in the same subnet
D.
RDS in a public subnet
Answers
D.
RDS in a public subnet
Suggested answer: D

Explanation:

Making RDS accessible to the public internet in a public subnet poses a security risk, by making your database directly addressable and spammable. DB instances deployed within a VPC can be configured to be accessible from the Internet or from EC2 instances outside the VPC. If a VPC security group specifies a port access such as TCP port 22, you would not be able to access the DB instance because the firewall for the DB instance provides access only via the IP addresses specified by the DB security groups the instance is a member of and the port defined when the DB instance was created.

Reference: http://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Overview.RDSSecurityGroups.html

asked 16/09/2024
Mohamed Isaaq
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first