ANS-C01 exam dumps

ANS-C01 practice question 106 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 106

Single answer

Your company is hosting a multi-tier web application on AWS. The application is deployed across public and private subnets in a VPC. To ensure secure access to the private subnets, a bastion host is deployed in the public subnet. Recently, the security team has raised concerns about unauthorized access to the bastion host. To address this, you need to implement a solution that restricts access to the bastion host based on originating IP addresses. What is the most appropriate configuration to meet this requirement?

  1. A

    Configure a security group on the bastion host to only allow SSH access from specific IP addresses.

  2. B

    Use Network ACLs to block all traffic except SSH from specific IP addresses to the bastion host.

  3. C

    Implement AWS WAF on the bastion host to filter traffic based on IP addresses.

  4. D

    Deploy an additional NAT gateway to filter traffic based on IP addresses before it reaches the bastion host.

Show answer and explanation

Correct answer: A

Explanation

To secure a bastion host, the most efficient and appropriate solution is to use a security group. Security groups are designed to control instance-level access and can be configured to allow only SSH traffic from specific IP ranges. This provides a robust method to restrict unauthorized access while maintaining flexibility and ease of management.

  • A. Correct.

    Correct: Security groups are stateful firewalls and are the most appropriate way to restrict access to the bastion host based on specific IP addresses. They can be configured to allow SSH traffic only from trusted IP ranges.

  • B. Incorrect.

    Incorrect: While Network ACLs can filter traffic at the subnet level, they are stateless and less flexible compared to security groups. Security groups are more suitable for instance-level access control.

  • C. Incorrect.

    Incorrect: AWS WAF is designed for web application traffic and is not applicable for managing SSH access to a bastion host.

  • D. Incorrect.

    Incorrect: NAT gateways are used for providing internet access to resources in private subnets and cannot filter traffic based on IP addresses before it reaches the bastion host.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam