1. You have a EC2 instance in your VPC with IPV4 addresses and you need to initiate outbound connections to the internet but prevent unsolicited inbound connections from the internet. What would you use?
a) VGW
b) Egress-Only Internet Gateways
c) EC2 instance with Elastic IP
d) NAT device
-----------------------------------------------------------------------------------------------------------------------
2. connections to the internet but prevent unsolicited inbound connections from the internet. What would you use?
a. NAT device
b. VGW
c. Egress-Only Internet Gateways
d. EC2 instance with Elastic IP
------------------------------------------------------------------------------------------------------------------------
3. You have a Site-to-Site VPN connection consists of a virtual private gateway attached to your VPC at Amazon side. What device you should have at the Corporate data Center side?
a) Customer Gateway
b) Virtual Private Gateway
c) NAT Gateway
d) Bastion Host
--------------------------------------------------------------------------------------------------------------------------
4. You need a highly available, scalable technology that enables you to privately connect your VPC to supported AWS services, services hosted by other AWS accounts and supported AWS Marketplace partner services. What technology you would use?
a) AWS PrivateLink
b) AWS Direct Connect
c) AWS Site-to-Site VPN
d) AWS IPSec
--------------------------------------------------------------------------------------------------------------------------
5. You are designing a multi-tier website, with the web servers which need internet access and the database servers need to be accessed only from web servers. What subnet mechanism you would use?
a) Webservers in public subnet, database servers in private subnet
b) Both in private subnets with webserver instances access internet via NAT gateway
c) Both in public subnets with databse servers has non default security groups
d) Database servers in default subnet and webservers in public subnet
--------------------------------------------------------------------------------------------------------------------------
6. A network address translation (NAT) gateway should reside in private subnet.
a) True
b) False
---------------------------------------------------------------------------------------------------------------------------
7. The instances assigned to a security group can be in different subnets.
a) True
b) False
----------------------------------------------------------------------------------------------------------------------------
8. Which security mechanism in VPC corresponds to the type of role an instance plays?
a. Network ACL
b. Security Group
c. private Subnet
d. Route Table
--------------------------------------------------------------------------------------------------------------------------
9. Security groups act as a firewall for associated Amazon EC2 instances, controlling both inbound and outbound traffic at the instance level.
a) False
b) True
--------------------------------------------------------------------------------------------------------------------------
10. Network access control lists act as a firewall for associated subnets, controlling both inbound and outbound traffic at the subnet level.
a) True
b) False
---------------------------------------------------------------------------------------------------------------------------
11. You need to monitor the accepted and rejected IP traffic going to and from your instances. What AWS tool would use?
a. Cloudwatch
b. CloudTrail
c. VPC Flow Log
d. Elastic Search
---------------------------------------------------------------------------------------------------------------------------
12. Security Group is Stateful because return traffic is automatically allowed, regardless of any rules.
a) True
b) False
----------------------------------------------------------------------------------------------------------------------------
13. Network ACL is StateLess because return traffic must be explicitly allowed by rules.
a) True
b) False
-----------------------------------------------------------------------------------------------------------------------------
14. Which of the following process rules in number order when deciding whether to allow traffic?
a. Network ACL
b. Security group
c. Both
d. None
------------------------------------------------------------------------------------------------------------------------------
15) Suppose Internet Traffic is coming to a EC2 instance. Choose the order in which following security/routing mechanisms are applied?
a. Internet gateway, Routing Table, Network ACL, Security Group
a. Internet gateway, Routing Table, Security Group, Network ACL
a. Network ACL,Internet gateway, Routing Table, Security Group
a. Internet gateway, Network ACL, Security Group,Routing Table
---------------------------------------------------------------------------------------------------------------------------------
a) VGW
b) Egress-Only Internet Gateways
c) EC2 instance with Elastic IP
d) NAT device
-----------------------------------------------------------------------------------------------------------------------
2. connections to the internet but prevent unsolicited inbound connections from the internet. What would you use?
a. NAT device
b. VGW
c. Egress-Only Internet Gateways
d. EC2 instance with Elastic IP
------------------------------------------------------------------------------------------------------------------------
3. You have a Site-to-Site VPN connection consists of a virtual private gateway attached to your VPC at Amazon side. What device you should have at the Corporate data Center side?
a) Customer Gateway
b) Virtual Private Gateway
c) NAT Gateway
d) Bastion Host
--------------------------------------------------------------------------------------------------------------------------
4. You need a highly available, scalable technology that enables you to privately connect your VPC to supported AWS services, services hosted by other AWS accounts and supported AWS Marketplace partner services. What technology you would use?
a) AWS PrivateLink
b) AWS Direct Connect
c) AWS Site-to-Site VPN
d) AWS IPSec
--------------------------------------------------------------------------------------------------------------------------
5. You are designing a multi-tier website, with the web servers which need internet access and the database servers need to be accessed only from web servers. What subnet mechanism you would use?
a) Webservers in public subnet, database servers in private subnet
b) Both in private subnets with webserver instances access internet via NAT gateway
c) Both in public subnets with databse servers has non default security groups
d) Database servers in default subnet and webservers in public subnet
--------------------------------------------------------------------------------------------------------------------------
6. A network address translation (NAT) gateway should reside in private subnet.
a) True
b) False
---------------------------------------------------------------------------------------------------------------------------
7. The instances assigned to a security group can be in different subnets.
a) True
b) False
----------------------------------------------------------------------------------------------------------------------------
8. Which security mechanism in VPC corresponds to the type of role an instance plays?
a. Network ACL
b. Security Group
c. private Subnet
d. Route Table
--------------------------------------------------------------------------------------------------------------------------
9. Security groups act as a firewall for associated Amazon EC2 instances, controlling both inbound and outbound traffic at the instance level.
a) False
b) True
--------------------------------------------------------------------------------------------------------------------------
10. Network access control lists act as a firewall for associated subnets, controlling both inbound and outbound traffic at the subnet level.
a) True
b) False
---------------------------------------------------------------------------------------------------------------------------
11. You need to monitor the accepted and rejected IP traffic going to and from your instances. What AWS tool would use?
a. Cloudwatch
b. CloudTrail
c. VPC Flow Log
d. Elastic Search
---------------------------------------------------------------------------------------------------------------------------
12. Security Group is Stateful because return traffic is automatically allowed, regardless of any rules.
a) True
b) False
----------------------------------------------------------------------------------------------------------------------------
13. Network ACL is StateLess because return traffic must be explicitly allowed by rules.
a) True
b) False
-----------------------------------------------------------------------------------------------------------------------------
14. Which of the following process rules in number order when deciding whether to allow traffic?
a. Network ACL
b. Security group
c. Both
d. None
------------------------------------------------------------------------------------------------------------------------------
15) Suppose Internet Traffic is coming to a EC2 instance. Choose the order in which following security/routing mechanisms are applied?
a. Internet gateway, Routing Table, Network ACL, Security Group
a. Internet gateway, Routing Table, Security Group, Network ACL
a. Network ACL,Internet gateway, Routing Table, Security Group
a. Internet gateway, Network ACL, Security Group,Routing Table
---------------------------------------------------------------------------------------------------------------------------------