ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 196 - SCS-C01 discussion

Report
Export

A Systems Engineer is troubleshooting the connectivity of a test environment that includes a virtual security appliance deployed inline. In addition to using the virtual security appliance, the Development team wants to use security groups and network ACLs to accomplish various security requirements in the environment.

What configuration is necessary to allow the virtual security appliance to route the traffic?

A.
Disable network ACLs.
Answers
A.
Disable network ACLs.
B.
Configure the security appliance's elastic network interface for promiscuous mode.
Answers
B.
Configure the security appliance's elastic network interface for promiscuous mode.
C.
Disable the Network Source/Destination check on the security appliance's elastic network interface
Answers
C.
Disable the Network Source/Destination check on the security appliance's elastic network interface
D.
Place the security appliance in the public subnet with the internet gateway
Answers
D.
Place the security appliance in the public subnet with the internet gateway
Suggested answer: C

Explanation:

Each EC2 instance performs source/destination checks by default. This means that the instance must be the source or destination of any traffic it sends or receives. In this case virtual security appliance instance must be able to send and receive traffic when the source or destination is not itself.

Therefore, you must disable source/destination checks on the NAT instance."

asked 16/09/2024
Pablo Hilario
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first