ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 7 - ANS-C01 discussion

Report
Export

A network engineer is designing the architecture for a healthcare company's workload that is moving to the AWS Cloud. All data to and from the on-premises environment must be encrypted in transit.

All traffic also must be inspected in the cloud before the traffic is allowed to leave the cloud and travel to the on-premises environment or to the internet.

The company will expose components of the workload to the internet so that patients can reserve appointments. The architecture must secure these components and protect them against DDoS attacks. The architecture also must provide protection against financial liability for services that scale out during a DDoS event.

Which combination of steps should the network engineer take to meet all these requirements for the workload? (Choose three.)

A.
Use Traffic Mirroring to copy all traffic to a fleet of traffic capture appliances.
Answers
A.
Use Traffic Mirroring to copy all traffic to a fleet of traffic capture appliances.
B.
Set up AWS WAF on all network components.
Answers
B.
Set up AWS WAF on all network components.
C.
Configure an AWS Lambda function to create Deny rules in security groups to block malicious IP addresses.
Answers
C.
Configure an AWS Lambda function to create Deny rules in security groups to block malicious IP addresses.
D.
Use AWS Direct Connect with MACsec support for connectivity to the cloud.
Answers
D.
Use AWS Direct Connect with MACsec support for connectivity to the cloud.
E.
Use Gateway Load Balancers to insert third-party firewalls for inline traffic inspection.
Answers
E.
Use Gateway Load Balancers to insert third-party firewalls for inline traffic inspection.
F.
Configure AWS Shield Advanced and ensure that it is configured on all public assets.
Answers
F.
Configure AWS Shield Advanced and ensure that it is configured on all public assets.
Suggested answer: D, E, F

Explanation:

To meet the requirements for the healthcare company’s workload that is moving to the AWS Cloud, the network engineer should take the following steps:

Use AWS Direct Connect with MACsec support for connectivity to the cloud to ensure that all data to and from the on-premises environment is encrypted in transit (Option D).

Use Gateway Load Balancers to insert third-party firewalls for inline traffic inspection to inspect all traffic in the cloud before it is allowed to leave (Option E).

Configure AWS Shield Advanced and ensure that it is configured on all public assets to secure components exposed to the internet against DDoS attacks and provide protection against financial liability for services that scale out during a DDoS event (Option F).

These steps will help ensure that all data is encrypted in transit, all traffic is inspected before leaving the cloud, and components exposed to the internet are secured against DDoS attacks.

asked 16/09/2024
Mike Rachuj
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first