ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 345 - SAP-C01 discussion

Report
Export

You are designing a data leak prevention solution for your VPC environment. You want your VPC Instances to be able to access software depots and distributions on the Internet for product updates. The depots and distributions are accessible via third party CDNs by their URLs.

You want to explicitly deny any other outbound connections from your VPC instances to hosts on the internet. Which of the following options would you consider?

A.
Configure a web proxy server in your VPC and enforce URL-based rules for outbound access Remove default routes.
Answers
A.
Configure a web proxy server in your VPC and enforce URL-based rules for outbound access Remove default routes.
B.
Implement security groups and configure outbound rules to only permit traffic to software depots.
Answers
B.
Implement security groups and configure outbound rules to only permit traffic to software depots.
C.
Move all your instances into private VPC subnets remove default routes from all routing tables and add specific routes to the software depots and distributions only.
Answers
C.
Move all your instances into private VPC subnets remove default routes from all routing tables and add specific routes to the software depots and distributions only.
D.
Implement network access control lists to all specific destinations, with an Implicit deny all rule.
Answers
D.
Implement network access control lists to all specific destinations, with an Implicit deny all rule.
Suggested answer: A

Explanation:

Organizations usually implement proxy solutions to provide URL and web content filtering, IDS/IPS, data loss prevention, monitoring, and advanced threat protection. Reference: https://d0.awsstatic.com/awsanswers/ Controlling_VPC_Egress_Traffic.pdf

asked 16/09/2024
Kirk Boothe
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first