ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 235 - SCS-C01 discussion

Report
Export

A company hosts a popular web application that connects to an Amazon RDS MySQL DB instance running in a private VPC subnet that was created with default ACL settings. The IT Security department has a suspicion that a DDos attack is coming from a suspecting IP. How can you protect the subnets from this attack?

Please select:

A.
Change the Inbound Security Groups to deny access from the suspecting IP
Answers
A.
Change the Inbound Security Groups to deny access from the suspecting IP
B.
Change the Outbound Security Groups to deny access from the suspecting IP
Answers
B.
Change the Outbound Security Groups to deny access from the suspecting IP
C.
Change the Inbound NACL to deny access from the suspecting IP
Answers
C.
Change the Inbound NACL to deny access from the suspecting IP
D.
Change the Outbound NACL to deny access from the suspecting IP
Answers
D.
Change the Outbound NACL to deny access from the suspecting IP
Suggested answer: C

Explanation:

Option A and B are invalid because by default the Security Groups already block traffic. You can use NACL's as an additional security layer for the subnet to deny traffic. Option D is invalid since just changing the Inbound Rules is sufficient The AWS Documentation mentions the following A network access control list (ACLJ is an optional layer of security for your VPC that acts as a firewall for controlling traffic in and out of one or more subnets. You might set up network ACLs with rules similar to your security groups in order to add an additional layer of security to your VPC. The correct answer is: Change the Inbound NACL to deny access from the suspecting IP

asked 16/09/2024
Giorgio Bertocchi
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first