ANS-C01 exam dumps

ANS-C01 practice question 435 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 435

Select 2

An organization is running a multi-tier web application on AWS and needs to ensure that only HTTPS traffic is allowed to the application servers located in private subnets. Additionally, the organization wants to restrict outbound internet access from these servers to only specific domains for compliance purposes. Which combination of network features should you implement to meet these requirements?

  1. A

    Use a Network ACL to allow inbound HTTPS traffic and deny all other traffic to the application servers.

  2. B

    Create a Security Group to allow inbound HTTPS traffic and block all other inbound traffic.

  3. C

    Configure a NAT Gateway with specific route table entries to restrict outbound internet access to approved domains.

  4. D

    Use an AWS WAF (Web Application Firewall) to restrict outbound requests to specific domains.

  5. E

    Deploy an egress-only internet gateway to enforce restrictions on outbound traffic to approved domains.

  6. F

    Use a VPC endpoint with a policy to allow traffic only to approved domains.

Show answer and explanation

Correct answers: B, F

Explanation

To meet the organization's requirements, a Security Group should be used to allow only HTTPS traffic to the application servers, as Security Groups are stateful and provide fine-grained control over inbound and outbound traffic. Additionally, a VPC endpoint with a policy can enforce compliance by restricting outbound traffic to approved domains. Other options, such as Network ACLs, NAT Gateways, AWS WAF, and egress-only internet gateways, are either not suitable for the use case or do not fully meet the stated requirements.

  • A. Incorrect.

    Network ACLs are stateless and operate at the subnet level. While they can restrict traffic, they are less flexible than Security Groups for application-level traffic filtering and do not meet the requirement for restricting traffic to specific domains.

  • B. Correct.

    Security Groups are stateful and operate at the instance level. They are well-suited for allowing only HTTPS traffic to the application servers and blocking all other inbound traffic.

  • C. Incorrect.

    A NAT Gateway is used to allow private subnets to access the internet, but it does not provide the ability to restrict outbound traffic to specific domains.

  • D. Incorrect.

    AWS WAF is used to filter HTTP and HTTPS requests to web applications but is not designed to restrict outbound traffic to specific domains.

  • E. Incorrect.

    An egress-only internet gateway is used for IPv6 traffic and does not provide the required functionality to restrict outbound traffic to specific domains.

  • F. Correct.

    A VPC endpoint with a policy can be configured to restrict traffic to specific domains by allowing access only to approved resources, which satisfies the compliance requirement.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam