List of questions
Related questions
Question 316 - SAA-C03 discussion
A solutions architect is designing a two-tiered architecture that includes a public subnet and a database subnet. The web servers in the public subnet must be open to the internet on port 443. The Amazon RDS for MySQL D6 instance in the database subnet must be accessible only to the web servers on port 3306.
Which combination of steps should the solutions architect take to meet these requirements? (Select TWO.)
A.
Create a network ACL for the public subnet Add a rule to deny outbound traffic to 0 0 0 0/0 on port 3306
B.
Create a security group for the DB instance Add a rule to allow traffic from the public subnet CIDR block on port 3306
C.
Create a security group for the web servers in the public subnet Add a rule to allow traffic from 0 0 0 O'O on port 443
D.
Create a security group for the DB instance Add a rule to allow traffic from the web servers' security group on port 3306
E.
Create a security group for the DB instance Add a rule to deny all traffic except traffic from the web servers' security group on port 3306
Your answer:
0 comments
Sorted by
Leave a comment first