ANS-C01 exam dumps

ANS-C01 practice question 436 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 436

Select 2

Your organization requires that all traffic between your VPC and an on-premises data center be encrypted and compliant with strict security standards. You have set up a Site-to-Site VPN connection between AWS and the data center. However, the security team has raised concerns about ensuring that only approved IP address ranges are allowed to communicate over this VPN. Which combination of steps should you take to meet these requirements?

  1. A

    Configure a Network ACL on the VPC subnets to allow traffic only from the approved IP address ranges.

  2. B

    Use VPN route filtering to ensure that only approved IP address ranges are advertised to the on-premises network.

  3. C

    Enable AWS Firewall Manager to automatically block unapproved traffic over the VPN connection.

  4. D

    Use Security Groups to allow only approved IP address ranges to access resources within the VPC.

  5. E

    Configure a CloudWatch alarm to monitor traffic from unapproved IP address ranges over the VPN.

Show answer and explanation

Correct answers: B, D

Explanation

To meet the security and compliance requirements, you need to restrict traffic to only approved IP address ranges over the VPN connection. VPN route filtering ensures that only approved routes are advertised or accepted, while Security Groups provide the necessary fine-grained control over which IP ranges can access resources within the VPC. These solutions together ensure that traffic is compliant and secure.

  • A. Incorrect.

    Network ACLs are stateless and apply at the subnet level, but they do not provide the granularity needed to filter traffic specifically over the VPN connection.

  • B. Correct.

    VPN route filtering allows you to control the routes that are advertised or accepted, restricting traffic to approved IP address ranges and ensuring compliance.

  • C. Incorrect.

    AWS Firewall Manager is a centralized management tool for AWS WAF and Security Groups, but it does not directly control traffic over a VPN connection.

  • D. Correct.

    Security Groups are stateful and provide fine-grained control over inbound and outbound traffic to resources within the VPC, allowing you to restrict access to approved IP address ranges.

  • E. Incorrect.

    CloudWatch alarms are useful for monitoring traffic but do not actively block or filter traffic, so they would not meet the requirement to enforce security.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam