SOA-C02 exam dumps

SOA-C02 practice question 236 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 236

Select 2

You are tasked with designing a VPC in AWS for a web application. The application requires public access to its web servers and secure database access. You create two subnets: one public subnet for the web servers and one private subnet for the database. What steps must you take to ensure proper connectivity for the application?

  1. A

    Attach an internet gateway to the VPC and update the public subnet's route table to route traffic to the internet gateway.

  2. B

    Create a NAT gateway in the private subnet for the database to access the internet.

  3. C

    Configure a security group for the web servers to allow inbound HTTP and HTTPS traffic from any IP address.

  4. D

    Update the private subnet's network ACL to explicitly allow HTTP and HTTPS traffic inbound from the internet.

  5. E

    Create a route in the private subnet's route table that directs all traffic (0.0.0.0/0) to the internet gateway.

Show answer and explanation

Correct answers: A, C

Explanation

To allow public access to the web servers, the public subnet needs an internet gateway attached to the VPC and an updated route table. Additionally, the web server's security group must allow inbound HTTP and HTTPS traffic. The database in the private subnet does not require outbound internet access or routes to the internet gateway, and network ACLs are not responsible for managing HTTP/HTTPS traffic in this scenario.

  • A. Correct.

    Correct. An internet gateway is required for public subnets to enable internet access, and the public subnet's route table must have a route to the internet gateway.

  • B. Incorrect.

    Incorrect. A NAT gateway is not required in the private subnet since the database does not need outbound internet access in this scenario.

  • C. Correct.

    Correct. Security groups for the web servers in the public subnet must allow inbound HTTP and HTTPS traffic to enable external access to the application.

  • D. Incorrect.

    Incorrect. Network ACLs are stateless and should not be configured to allow inbound HTTP and HTTPS traffic directly from the internet. This is handled by the security group.

  • E. Incorrect.

    Incorrect. Private subnets should not have a route to the internet gateway. They typically use a NAT gateway or remain isolated for security purposes.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam