
aws saa vpc questions
Authored by Huy Tùng Lê
Computers
Professional Development

AI Actions
Add similar questions
Adjust reading levels
Convert to real-world scenario
Translate activity
More...
Content View
Student View
6 questions
Show all answers
1.
MULTIPLE SELECT QUESTION
45 sec • 1 pt
A silicon valley based startup has a two-tier architecture using Amazon EC2 instances for its flagship application. The web servers (listening on port 443), which have been assigned security group A, are in public subnets across two Availability Zones (AZs) and the MSSQL based database instances (listening on port 1433), which have been assigned security group B, are in two private subnets across two Availability Zones (AZs). The DevOps team wants to review the security configurations of the application architecture.
As a solutions architect, which of the following options would you select as the MOST secure configuration? (Select two)
For security group B: Add an inbound rule that allows traffic only from security group A on port 1433
For security group B: Add an inbound rule that allows traffic only from all sources on port 1433
For security group A: Add an inbound rule that allows traffic from all sources on port 443. Add an outbound rule with the destination as security group B on port 1433
For security group B: Add an inbound rule that allows traffic only from security group A on port 443
For security group A: Add an inbound rule that allows traffic from all sources on port 443. Add an outbound rule with the destination as security group B on port 443
2.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
A developer has configured inbound traffic for the relevant ports in both the Security Group of the Amazon EC2 instance as well as the network access control list (network ACL) of the subnet for the Amazon EC2 instance. The developer is, however, unable to connect to the service running on the Amazon EC2 instance.
As a solutions architect, how will you fix this issue?
Network access control list (network ACL) are stateful, so allowing inbound traffic to the necessary ports enables the connection. Security Groups are stateless, so you must allow both inbound and outbound traffic
Rules associated with network access control list (network ACL) should never be modified from command line. An attempt to modify rules from command line blocks the rule and results in an erratic behavior
Security Groups are stateful, so allowing inbound traffic to the necessary ports enables the connection. Network access control list (network ACL) are stateless, so you must allow both inbound and outbound traffic
IAM Role defined in the Security Group is different from the IAM Role that is given access in the network access control list (network ACL)
3.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
A company has many Amazon Virtual Private Cloud (Amazon VPC) in various accounts, that need to be connected in a star network with one another and connected with on-premises networks through AWS Direct Connect.
What do you recommend?
AWS Transit Gateway
AWS PrivateLink
Virtual private gateway (VGW)
VPC Peering Connection
4.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
An engineering lead is designing a VPC with public and private subnets. The VPC and subnets use IPv4 CIDR blocks. There is one public subnet and one private subnet in each of three Availability Zones (AZs) for high availability. An internet gateway is used to provide internet access for the public subnets. The private subnets require access to the internet to allow Amazon EC2 instances to download software updates.
Which of the following options represents the correct solution to set up internet access for the private subnets?
Set up three NAT gateways, one in each private subnet in each AZ. Create a custom route table for each AZ that forwards non-local traffic to the NAT gateway in its AZ
Set up three Internet gateways, one in each private subnet in each AZ. Create a custom route table for each AZ that forwards non-local traffic to the Internet gateway in its AZ
Set up three NAT gateways, one in each public subnet in each AZ. Create a custom route table for each AZ that forwards non-local traffic to the NAT gateway in its AZ
Set up three egress-only internet gateways, one in each public subnet in each AZ. Create a custom route table for each AZ that forwards non-local traffic to the egress-only internet gateway in its AZ
5.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
A company has its application servers in the public subnet that connect to the Amazon RDS instances in the private subnet. For regular maintenance, the Amazon RDS instances need patch fixes that need to be downloaded from the internet.
Considering the company uses only IPv4 addressing and is looking for a fully managed service, which of the following would you suggest as an optimal solution?
Configure an Egress-only internet gateway for the resources in the private subnet of the VPC
Configure the Internet Gateway of the VPC to be accessible to the private subnet resources by changing the route tables
Configure a Network Address Translation instance (NAT instance) in the public subnet of the VPC
Configure a Network Address Translation gateway (NAT gateway) in the public subnet of the VPC
6.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
The DevOps team at an IT company has recently migrated to AWS and they are configuring security groups for their two-tier application with public web servers and private database servers. The team wants to understand the allowed configuration options for an inbound rule for a security group.
As a solutions architect, which of the following would you identify as an INVALID option for setting up such a configuration?
You can use an Internet Gateway ID as the custom source for the inbound rule
You can use a range of IP addresses in CIDR block notation as the custom source for the inbound rule
You can use an IP address as the custom source for the inbound rule
You can use a security group as the custom source for the inbound rule
Access all questions and much more by creating a free account
Create resources
Host any resource
Get auto-graded reports

Continue with Google

Continue with Email

Continue with Classlink

Continue with Clever
or continue with

Microsoft
%20(1).png)
Apple
Others
Already have an account?
Similar Resources on Wayground
11 questions
KidSS Drone Quiz
Quiz
•
Professional Development
10 questions
Asas Microsoft Word 2021
Quiz
•
2nd Grade - Professio...
10 questions
MATLAB variables. Types. Declaration. Operations.
Quiz
•
Professional Development
11 questions
DP 300 Practice
Quiz
•
Professional Development
10 questions
USE OF ICT IN THE LEARNING PROCESS
Quiz
•
Professional Development
11 questions
DECI - M3 - W4 - Round2
Quiz
•
Professional Development
10 questions
python quiz
Quiz
•
6th Grade - Professio...
10 questions
Scratch
Quiz
•
KG - Professional Dev...
Popular Resources on Wayground
15 questions
Fractions on a Number Line
Quiz
•
3rd Grade
10 questions
Probability Practice
Quiz
•
4th Grade
15 questions
Probability on Number LIne
Quiz
•
4th Grade
20 questions
Equivalent Fractions
Quiz
•
3rd Grade
25 questions
Multiplication Facts
Quiz
•
5th Grade
22 questions
fractions
Quiz
•
3rd Grade
6 questions
Appropriate Chromebook Usage
Lesson
•
7th Grade
10 questions
Greek Bases tele and phon
Quiz
•
6th - 8th Grade
Discover more resources for Computers
20 questions
Black History Month Trivia Game #1
Quiz
•
Professional Development
20 questions
90s Cartoons
Quiz
•
Professional Development
12 questions
Mardi Gras Trivia
Quiz
•
Professional Development
7 questions
Copy of G5_U5_L14_22-23
Lesson
•
KG - Professional Dev...
12 questions
Unit 5: Puerto Rico W1
Quiz
•
Professional Development
42 questions
LOTE_SPN2 5WEEK2 Day 4 We They Actividad 3
Quiz
•
Professional Development
15 questions
Balance Equations Hangers
Quiz
•
Professional Development
31 questions
Servsafe Food Manager Practice Test 2021- Part 1
Quiz
•
9th Grade - Professio...