nerdexam
Check_Point

156-561 · Question #116

Which of these operations will delete all inbound and outbound rules in a Security Group?

The correct answer is A. Region Lock. Region Lock is the operation that removes all inbound and outbound rules from a Security Group, effectively stripping it of any traffic permissions and leaving it in a locked, rule-less state. This makes it the most disruptive of the lock types - it does not merely restrict…

CloudGuard Network Security in AWS

Question

Which of these operations will delete all inbound and outbound rules in a Security Group?

Options

  • ARegion Lock
  • BRule Lock
  • CFull Protect Lock
  • DPolicy Lock

How the community answered

(44 responses)
  • A
    93% (41)
  • B
    2% (1)
  • D
    5% (2)

Explanation

Region Lock is the operation that removes all inbound and outbound rules from a Security Group, effectively stripping it of any traffic permissions and leaving it in a locked, rule-less state. This makes it the most disruptive of the lock types - it does not merely restrict changes, it actively deletes the existing rule set.

Rule Lock (B) prevents modification of existing rules but does not delete them - it's a change-freeze, not a wipe. Full Protect Lock (C) is a broader resource-level protection that prevents deletion of the Security Group itself, not its rules. Policy Lock (D) restricts policy-level configurations but has no direct effect on individual inbound/outbound rules.

Memory tip: Think of "Region" as the widest scope - a region-level lock doesn't just freeze what's there, it resets the Security Group entirely. If you remember that "Region = Reset," you can distinguish it from the narrower locks (Rule, Full Protect, Policy) that preserve or protect rather than purge.

Topics

#Security Groups#Region Lock#CloudGuard AWS#Firewall Rules

Community Discussion

No community discussion yet for this question.

Full 156-561 Practice