ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 170 - SCS-C01 discussion

Report
Export

A company has deployed a custom DNS server in AWS. The Security Engineer wants to ensure that Amazon EC2 instances cannot use the Amazon-provided DNS. How can the Security Engineer block access to the Amazon-provided DNS in the VPC?

A.
Deny access to the Amazon DNS IP within all security groups.
Answers
A.
Deny access to the Amazon DNS IP within all security groups.
B.
Add a rule to all network access control lists that deny access to the Amazon DNS IP.
Answers
B.
Add a rule to all network access control lists that deny access to the Amazon DNS IP.
C.
Add a route to all route tables that black holes traffic to the Amazon DNS IP.
Answers
C.
Add a route to all route tables that black holes traffic to the Amazon DNS IP.
D.
Disable DNS resolution within the VPC configuration.
Answers
D.
Disable DNS resolution within the VPC configuration.
Suggested answer: D

Explanation:

https://docs.aws.amazon.com/vpc/latest/userguide/vpc-dns.html

asked 16/09/2024
Rehan Malik
51 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first