ANS-C01 exam dumps

ANS-C01 practice question 11 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 11

Select 2

Your company operates a multi-tier web application hosted on AWS. The application has a public-facing web tier in an Auto Scaling group behind an Application Load Balancer (ALB) and a private database tier on Amazon RDS. You need to ensure that the web tier can securely communicate with the database tier while adhering to the principle of least privilege. Which of the following actions should you take to accomplish this?

  1. A

    Configure a security group for the database tier to allow inbound traffic only from the web tier's security group.

  2. B

    Attach an IAM role to the EC2 instances in the web tier, granting access to the database.

  3. C

    Set up a Network ACL that allows all outbound traffic from the web tier's subnet to the database tier's subnet.

  4. D

    Use VPC peering to enable communication between the web tier and the database tier.

  5. E

    Enable inbound rules in the database tier's security group to allow traffic from the web tier's subnet CIDR range.

Show answer and explanation

Correct answers: A, C

Explanation

To ensure secure communication between the web tier and the database tier in a multi-tier architecture, you should use a combination of security groups and Network ACLs. Configuring the database tier's security group to allow inbound traffic only from the web tier's security group ensures the principle of least privilege. Additionally, setting up a Network ACL to permit outbound traffic from the web tier's subnet to the database tier's subnet adds an extra layer of security. Using IAM roles, VPC peering, or broad CIDR-based rules does not meet the requirements as effectively.

  • A. Correct.

    This is correct. Configuring the database tier's security group to allow inbound traffic only from the web tier's security group ensures secure communication while following the principle of least privilege.

  • B. Incorrect.

    This is incorrect. IAM roles are used for granting permissions to access AWS services, not for controlling network traffic between instances.

  • C. Correct.

    This is correct. A Network ACL that allows outbound traffic from the web tier's subnet to the database tier's subnet ensures communication while providing an additional layer of security.

  • D. Incorrect.

    This is incorrect. VPC peering is unnecessary in this scenario because both tiers are within the same VPC.

  • E. Incorrect.

    This is incorrect. Allowing traffic from the web tier's subnet CIDR range is less secure than restricting access to the specific security group of the web tier.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam