ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 44 - SCS-C01 discussion

Report
Export


A Security Engineer has been asked to troubleshoot inbound connectivity to a web server. This single web server is not receiving inbound connections from the internet, whereas all other web servers are functioning properly. The architecture includes network ACLs, security groups, and a virtual security appliance. In addition, the Development team has implemented Application Load Balancers (ALBs) to distribute the load across all web servers. It is a requirement that traffic between the web servers and the internet flow through the virtual security appliance. The Security Engineer has verified the following:

A.
The rule set in the Security Groups is correct
Answers
A.
The rule set in the Security Groups is correct
B.
The rule set in the network ACLs is correct
Answers
B.
The rule set in the network ACLs is correct
C.
The rule set in the virtual appliance is correctWhich of the following are other valid items to troubleshoot in this scenario? (Choose two.)
Answers
C.
The rule set in the virtual appliance is correctWhich of the following are other valid items to troubleshoot in this scenario? (Choose two.)
D.
Verify that the 0.0.0.0/0 route in the route table for the web server subnet points to a NAT gateway.
Answers
D.
Verify that the 0.0.0.0/0 route in the route table for the web server subnet points to a NAT gateway.
E.
Verify which Security Group is applied to the particular web server’s elastic network interface (ENI).
Answers
E.
Verify which Security Group is applied to the particular web server’s elastic network interface (ENI).
F.
Verify that the 0.0.0.0/0 route in the route table for the web server subnet points to the virtual security appliance.
Answers
F.
Verify that the 0.0.0.0/0 route in the route table for the web server subnet points to the virtual security appliance.
G.
Verify the registered targets in the ALB.
Answers
G.
Verify the registered targets in the ALB.
H.
Verify that the 0.0.0.0/0 route in the public subnet points to a NAT gateway.
Answers
H.
Verify that the 0.0.0.0/0 route in the public subnet points to a NAT gateway.
Suggested answer: C, D

Explanation:

https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-eni.html

asked 16/09/2024
Marcin Golec
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first