ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 73 - SAA-C03 discussion

Report
Export

A company recently launched Linux-based application instances on Amazon EC2 in a private subnet and launched a Linux-based bastion host on an Amazon EC2 instance in a public subnet of a VPC A solutions architect needs to connect from the on-premises network, through the company's internet connection to the bastion host and to the application servers The solutions architect must make sure that the security groups of all the EC2 instances will allow that access Which combination of steps should the solutions architect take to meet these requirements? (Select TWO)

A.
Replace the current security group of the bastion host with one that only allows inbound access from the application instances
Answers
A.
Replace the current security group of the bastion host with one that only allows inbound access from the application instances
B.
Replace the current security group of the bastion host with one that only allows inbound access from the internal IP range for the company
Answers
B.
Replace the current security group of the bastion host with one that only allows inbound access from the internal IP range for the company
C.
Replace the current security group of the bastion host with one that only allows inbound access from the external IP range for the company
Answers
C.
Replace the current security group of the bastion host with one that only allows inbound access from the external IP range for the company
D.
Replace the current security group of the application instances with one that allows inbound SSH access from only the private IP address of the bastion host
Answers
D.
Replace the current security group of the application instances with one that allows inbound SSH access from only the private IP address of the bastion host
E.
Replace the current security group of the application instances with one that allows inbound SSH access from only the public IP address of the bastion host
Answers
E.
Replace the current security group of the application instances with one that allows inbound SSH access from only the public IP address of the bastion host
Suggested answer: C, D

Explanation:

https://digitalcloud.training/ssh-into-ec2-in-private-subnet/

asked 16/09/2024
henk Bouman
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first