Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Amazon Web Services AWS Certified Security – Specialty SCS-C03 Question # 23 Topic 3 Discussion

Amazon Web Services AWS Certified Security – Specialty SCS-C03 Question # 23 Topic 3 Discussion

SCS-C03 Exam Topic 3 Question 23 Discussion:
Question #: 23
Topic #: 3

A security engineer has designed a VPC to segment private traffic from public traffic. The VPC includes two Availability Zones. Each Availability Zone contains one public subnet and one private subnet. Three route tables exist: one for the public subnets and one for each private subnet.

The security engineer discovers that all four subnets are routing traffic through the internet gateway that is attached to the VPC.

Which combination of steps should the security engineer take to remediate this scenario? (Select TWO.)


A.

Verify that a NAT gateway has been provisioned in the public subnet in each Availability Zone.


B.

Verify that a NAT gateway has been provisioned in the private subnet in each Availability Zone.


C.

Modify the route tables for the public subnets to add a local route to the VPC CIDR range.


D.

Modify the route tables for the private subnets to route 0.0.0.0/0 to the NAT gateway in the public subnet of the same Availability Zone.


E.

Modify the route tables for the private subnets to route 0.0.0.0/0 to the internet gateway.


Get Premium SCS-C03 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.