Medium1 markMultiple Choice
Domain 1.2: Security ControlsSecurityNetworkingNetwork Firewall

AWS SAP-C02 · Question 72 · Domain 1.2: Security Controls

A company is designing a secure network architecture. They have a VPC with public and private subnets. EC2 instances in the private subnets need to download patches from the internet. The security team requires that all outbound traffic be inspected for malware and that access to specific domains can be blocked. Which combination of services should be used? (Select TWO)

Answer options:

A.

Deploy a NAT Gateway in the public subnet.

B.

Deploy an Internet Gateway in the private subnet.

C.

Deploy AWS Network Firewall and route traffic from the private subnets through it.

D.

Use AWS WAF to inspect the outbound traffic.

E.

Configure Security Groups to block specific domains.

F.

Use Amazon GuardDuty to block the traffic.

How to approach this question

Combine internet access with outbound inspection.

Full Answer

To provide internet access to private subnets, a NAT Gateway is required. To inspect that outbound traffic for malware and block domains, AWS Network Firewall must be deployed in the routing path.

Common mistakes

Thinking WAF can inspect outbound traffic.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 7

75 questions · hints · full answers · grading

More questions from this exam