ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 241 - SCS-C01 discussion

Report
Export

A company is hosting a website that must be accessible to users for HTTPS traffic. Also port 22 shouldbe open for administrative purposes. The administrator's workstation has a static IP address of203.0.113.1/32. Which of the following security group configurations are the MOST secure but stillfunctional to support these requirements? Choose 2 answers from the options given belowPlease select:

A.
Port 443 coming from 0.0.0.0/0
Answers
A.
Port 443 coming from 0.0.0.0/0
B.
Port 443 coming from 10.0.0.0/16
Answers
B.
Port 443 coming from 10.0.0.0/16
C.
Port 22 coming from 0.0.0.0/0
Answers
C.
Port 22 coming from 0.0.0.0/0
D.
Port 22 coming from 203.0.113.1/32
Answers
D.
Port 22 coming from 203.0.113.1/32
Suggested answer: A, D

Explanation:

Since HTTPS traffic is required for all users on the Internet, Port 443 should be open on all IPaddresses. For port 22, the traffic should be restricted to an internal subnet. Option B is invalid, because this only allow traffic from a particular CIDR block and not from the internet Option C is invalid because allowing port 22 from the internet is a security risk For more information on AWS Security Groups, please visit the following UR

https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/usins-network-secunty.htmllThe correct answers are: Port 443 coming from 0.0.0.0/0, Port 22 coming from 203.0.113.1 /32Submit your Feedback/Queries to our Experts

asked 16/09/2024
Brandy Butman
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first