ANS-C01 exam dumps

ANS-C01 practice question 449 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 449

Select 3

You are designing a highly secure architecture for an application that involves communication between an Amazon EC2 instance and an Amazon RDS database. The application also needs to securely handle API requests from external users. Which combination of mechanisms should you implement to secure the application flows?

  1. A

    Use Security Groups to restrict inbound and outbound traffic for both EC2 and RDS.

  2. B

    Enable VPC Flow Logs to monitor and control traffic between EC2 and RDS.

  3. C

    Use HTTPS for API communications to encrypt data in transit.

  4. D

    Enable IAM database authentication for the RDS instance.

  5. E

    Use a NAT Gateway to route traffic between EC2 and RDS for added security.

Show answer and explanation

Correct answers: A, C, D

Explanation

To secure application flows, you should use Security Groups to control traffic between EC2 and RDS, enforce HTTPS for encrypted API communications, and enable IAM database authentication for secure access to the RDS instance. VPC Flow Logs and NAT Gateway are not directly relevant mechanisms for securing these specific flows.

  • A. Correct.

    Correct: Security Groups act as virtual firewalls to control inbound and outbound traffic, providing a critical layer of security for both EC2 and RDS.

  • B. Incorrect.

    Incorrect: VPC Flow Logs are useful for monitoring traffic but do not directly enforce security or restrict traffic.

  • C. Correct.

    Correct: HTTPS ensures that API communications are encrypted, preventing data interception during transit.

  • D. Correct.

    Correct: Enabling IAM database authentication for RDS eliminates the need for static database credentials, enhancing security.

  • E. Incorrect.

    Incorrect: A NAT Gateway is used to allow private instances to access the internet, not for securing traffic between EC2 and RDS.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam