Question 1 of 30
A company is planning to set up a multi-tier application architecture within an Amazon VPC. They want to ensure that their web servers can communicate with the application servers while restricting direct access to the database servers from the internet. The company has defined the following CIDR blocks for their VPC: 10.0.0.0/16 for the VPC, 10.0.1.0/24 for the web tier, 10.0.2.0/24 for the application tier, and 10.0.3.0/24 for the database tier. Which of the following configurations would best achieve the desired security and communication requirements?
Create a security group for the web tier that allows inbound traffic from the internet on port 80 and 443, and allows outbound traffic to the application tier on all ports. Create a security group for the application tier that allows inbound traffic from the web tier on all ports and allows outbound traffic to the database tier on port 3306. Finally, create a security group for the database tier that allows inbound traffic only from the application tier on port 3306.
Create a security group for the web tier that allows inbound traffic from the application tier on all ports and allows outbound traffic to the internet on port 80 and 443. Create a security group for the application tier that allows inbound traffic from the web tier on port 80 and 443 and allows outbound traffic to the database tier on all ports. Create a security group for the database tier that allows inbound traffic from the internet on port 3306.
Create a security group for the web tier that allows inbound traffic from the internet on port 80 and 443, and allows outbound traffic to the application tier on port 80. Create a security group for the application tier that allows inbound traffic from the web tier on port 80 and allows outbound traffic to the database tier on port 3306. Create a security group for the database tier that allows inbound traffic from the application tier on all ports.
Create a security group for the web tier that allows inbound traffic from the internet on port 80 and 443, and allows outbound traffic to the application tier on port 80. Create a security group for the application tier that allows inbound traffic from the web tier on all ports and allows outbound traffic to the database tier on port 3306. Create a security group for the database tier that allows inbound traffic from the internet on port 3306.

Preparing for Amazon SOA-C02 AWS Certified SysOps Administrator – Associate (SOA-C02)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free