SAP-C02 exam dumps

SAP-C02 practice question 396 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 396

Select 4

A company is hosting a multi-tier application on AWS. The application uses Amazon EC2 instances in private subnets for the back-end and stores sensitive customer data in Amazon RDS. The front-end is hosted on Amazon Elastic Load Balancer (ELB) in public subnets. The security team has identified potential vulnerabilities in the current architecture, including unrestricted internet access for EC2 instances and weak database credentials. Which actions should the Solutions Architect take to improve the security of this architecture?

  1. A

    Implement a NAT Gateway in the public subnet to allow EC2 instances to access the internet securely for updates.

  2. B

    Enable AWS Secrets Manager to store and rotate database credentials automatically.

  3. C

    Add a security group rule to allow all inbound traffic to the EC2 instances for easier connectivity.

  4. D

    Configure an Application Load Balancer (ALB) to use HTTPS and enforce SSL/TLS encryption for front-end traffic.

  5. E

    Enable Amazon GuardDuty to monitor and detect malicious activity across the AWS environment.

Show answer and explanation

Correct answers: A, B, D, E

Explanation

To improve the security of the architecture, it is necessary to address specific vulnerabilities such as unrestricted internet access and weak credential management. Implementing a NAT Gateway ensures EC2 instances can securely access the internet. Using AWS Secrets Manager enhances credential security by automatically managing and rotating sensitive data. Enforcing HTTPS on the ALB protects front-end communications, and enabling Amazon GuardDuty provides advanced monitoring to detect and respond to threats. Allowing all inbound traffic to EC2 instances, however, is a security risk and should never be done.

  • A. Correct.

    Correct. A NAT Gateway allows EC2 instances in private subnets to securely access the internet for updates without exposing them directly to the internet.

  • B. Correct.

    Correct. AWS Secrets Manager enhances security by securely storing and automatically rotating database credentials, reducing the risk of credential exposure.

  • C. Incorrect.

    Incorrect. Allowing all inbound traffic to EC2 instances is a significant security risk and violates AWS security best practices.

  • D. Correct.

    Correct. Configuring an ALB to enforce HTTPS ensures front-end traffic is encrypted, protecting sensitive information in transit.

  • E. Correct.

    Correct. Amazon GuardDuty provides continuous security monitoring and threat detection for the AWS environment, improving overall security.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam