ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 153 - SAP-C02 discussion

Report
Export

A company runs an application on a fleet of Amazon EC2 instances that are in private subnets behind an internet-facing Application Load Balancer (ALB). The ALB is the origin for an Amazon CloudFront distribution. An AWS WAF web ACL that contains various AWS managed rules is associated with the CloudFront distribution.

The company needs a solution that will prevent internet traffic from directly accessing the ALB.

Which solution will meet these requirements with the LEAST operational overhead?

A.
Create a new web ACL that contains the same rules that the existing web ACL contains. Associate the new web ACL with the ALB.
Answers
A.
Create a new web ACL that contains the same rules that the existing web ACL contains. Associate the new web ACL with the ALB.
B.
Associate the existing web ACL with the ALB.
Answers
B.
Associate the existing web ACL with the ALB.
C.
Add a security group rule to the ALB to allow traffic from the AWS managed prefix list for CloudFront only.
Answers
C.
Add a security group rule to the ALB to allow traffic from the AWS managed prefix list for CloudFront only.
D.
Add a security group rule to the ALB to allow only the various CloudFront IP address ranges.
Answers
D.
Add a security group rule to the ALB to allow only the various CloudFront IP address ranges.
Suggested answer: C

Explanation:

https://aws.amazon.com/about-aws/whats-new/2022/02/amazon-cloudfront-managed-prefix-list/

asked 16/09/2024
Angelo Gulisano
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first