ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 263 - SOA-C02 discussion

Report
Export

A SysOps administrator receives an alert from Amazon GuardDuty about suspicious network activity on an Amazon EC2 instance. The GuardDuty finding lists a new external IP address as a traffic destination. The SysOps administrator does not recognize the external IP address. The SysOps administrator must block traffic to the external IP address that GuardDuty identified. Which solution will meet this requirement?

A.
Create a new security group to block traffic to the external IP address. Assign the new security group to the EC2 instance.
Answers
A.
Create a new security group to block traffic to the external IP address. Assign the new security group to the EC2 instance.
B.
Use VPC flow logs with Amazon Athena to block traffic to the external IP address.
Answers
B.
Use VPC flow logs with Amazon Athena to block traffic to the external IP address.
C.
Create a network ACL. Add an outbound deny rule for traffic to the external IP address.
Answers
C.
Create a network ACL. Add an outbound deny rule for traffic to the external IP address.
D.
Create a new security group to block traffic to the external IP address. Assign the new security group to the entire VPC.
Answers
D.
Create a new security group to block traffic to the external IP address. Assign the new security group to the entire VPC.
Suggested answer: C

Explanation:

https://docs.aws.amazon.com/vpc/latest/userguide/vpc-network-acls.html

asked 16/09/2024
Ankit Parimi
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first