Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Alibaba Cloud Certified Professional: Cloud Architect CAP-C01 Question # 3 Topic 1 Discussion

Alibaba Cloud Certified Professional: Cloud Architect CAP-C01 Question # 3 Topic 1 Discussion

CAP-C01 Exam Topic 1 Question 3 Discussion:
Question #: 3
Topic #: 1

A Cloud Architect is designing a two-tiered architecture that includes a public vSwitch and a database vSwitch. The web servers in the public vSwitch must be open to the Internet on port 443. The ApsaraDB RDS for MySQL instance in the database vSwitch must be accessible only to the web servers on port 3306.

Which combination of actions should the Cloud Architect take to meet these requirements? (Correct answers: 2)


A.

Create a security group for the RDS instance. Add a rule to allow traffic from the web servers ' security group on port 3306.


B.

Create a security group for the RDS instance. Add a rule to allow traffic from the public vSwitch CIDR block on port 3306.


C.

Create a network ACL for the public vSwitch. Add a rule to deny outbound traffic to 0.0.0.0/0 on port 3306.


D.

Create a security group for the RDS instance. Add a rule to deny all traffic except traffic from the web servers ' security group on port 3306.


E.

Create a security group for the web servers in the public vSwitch. Add a rule to allow traffic from 0.0.0.0/0 on port 443.


Get Premium CAP-C01 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.