SAP-C02 exam dumps

SAP-C02 practice question 56 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 56

Select 3

An organization is hosting a web application in a VPC. The web application consists of an Application Load Balancer (ALB) in the public subnet and EC2 instances in a private subnet. The architecture also includes a NAT Gateway in another public subnet for outbound internet access from the private subnet. The security team has reported that unauthorized IP addresses are attempting to access the application. As an AWS Solutions Architect, which actions can you take to restrict access to the application only from specific trusted IP ranges?

  1. A

    Update the security group attached to the ALB to allow inbound traffic only from the trusted IP ranges.

  2. B

    Modify the route table of the public subnet hosting the ALB to block traffic from unauthorized IP ranges.

  3. C

    Use a network ACL associated with the public subnet hosting the ALB to explicitly deny traffic from unauthorized IP ranges.

  4. D

    Update the security group attached to the private EC2 instances to allow traffic only from the ALB.

  5. E

    Use a WAF (Web Application Firewall) associated with the ALB to restrict access to the trusted IP ranges.

Show answer and explanation

Correct answers: A, C, E

Explanation

To restrict access to the web application from specific trusted IP ranges, you can use a combination of security groups, network ACLs, and AWS WAF. The security group attached to the ALB can restrict inbound traffic based on IP ranges. Network ACLs provide an additional layer of subnet-level access control by denying traffic from unauthorized IP ranges. AWS WAF, when integrated with the ALB, allows for fine-grained control over web traffic, including IP-based restrictions. Route tables are for traffic routing and do not provide traffic filtering capabilities, and restricting the EC2 instance security group alone does not protect the ALB.

  • A. Correct.

    Correct. Security groups operate at the instance or resource level and can be used to restrict inbound traffic to the ALB based on trusted IP ranges.

  • B. Incorrect.

    Incorrect. Route tables are used for defining the traffic routing rules within a VPC and cannot block or allow traffic based on IP addresses.

  • C. Correct.

    Correct. Network ACLs operate at the subnet level and can be used to explicitly deny traffic from unauthorized IP ranges.

  • D. Incorrect.

    Incorrect. While security groups attached to EC2 instances can restrict traffic, this would not address the access control issue for the ALB, which is the primary entry point for the application.

  • E. Correct.

    Correct. AWS WAF can be used with an ALB to enforce IP-based access control rules, allowing or blocking traffic from specific IP ranges.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam