Amazon Web Services Amazon AWS Certified Advanced Networking - Specialty ANS-C01 Question # 11 Topic 2 Discussion

Amazon Web Services Amazon AWS Certified Advanced Networking - Specialty ANS-C01 Question # 11 Topic 2 Discussion

ANS-C01 Exam Topic 2 Question 11 Discussion:
Question #: 11
Topic #: 2

A company runs a workload in a single VPC on AWS. The company’s architecture contains several interface VPC endpoints for AWS services, including Amazon CloudWatch Logs and AWS Key Management Service (AWS KMS). The endpoints are configured to use a shared security group. The security group is not used for any other workloads or resources.

After a security review of the environment, the company determined that the shared security group is more permissive than necessary. The company wants to make the rules associated with the security group more restrictive. The changes to the security group rules must not prevent the resources in the VPC from using AWS services through interface VPC endpoints. The changes must prevent unnecessary access.

The security group currently uses the following rules:

• Inbound - Rule 1

Protocol: TCP

Port: 443

Source: 0.0.0.0/0

• Inbound - Rule 2

Protocol: TCP

Port: 443

Source: VPC CIDR

• Outbound - Rule 1

Protocol: All

Port: All

Destination: 0.0.0.0/0

Which rule or rules should the company remove to meet with these requirements?


A.

Outbound - Rule 2


B.

Inbound - Rule 1 and Outbound - Rule 1


C.

Inbound - Rule 2 and Outbound - Rule 1


D.

Outbound - Rule 1


Get Premium ANS-C01 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.