nerdexam
Amazon

ANS-C01 · Question #291

A company runs a workload in a single VPC on AWS. The company's architecture contains several interface VPC endpoints for AWS services, including Amazon CloudWatch Logs and AWS Key Management Service

Sign in or unlock ANS-C01 to reveal the answer and full explanation for question #291. The question stem and answer options stay visible for context.

Submitted by naveen.iyer· Mar 6, 2026Network Security

Question

A company runs a workload in a single VPC on AWS. The company's architecture contains several interface VPC endpoints for AWS services, including Amazon CloudWatch Logs and AWS Key Management Service (AWS KMS). The endpoints are configured to use a shared security group. The security group is not used for any other workloads or resources. After a security review of the environment, the company determined that the shared security group is more permissive than necessary. The company wants to make the rules associated with the security group more restrictive. The changes to the security group rules must not prevent the resources in the VPC from using AWS services through interface VPC endpoints. The changes must prevent unnecessary access. The security group currently uses the following rules:

Inbound - Rule 1 Protocol: TCP Port: 443 Source: 0.0.0.0/0 Inbound - Rule 2 Protocol: TCP Port: 443 Source: VPC CIDR Outbound - Rule 1 Protocol: All Port: All Destination: 0.0.0.0/0 Which rule or rules should the company remove to meet with these requirements?

Options

  • AOutbound - Rule 2
  • BInbound - Rule 1 and Outbound - Rule 1
  • CInbound - Rule 2 and Outbound - Rule 1
  • DOutbound - Rule 1

Unlock ANS-C01 to see the answer

You've previewed enough free ANS-C01 questions. Unlock ANS-C01 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full ANS-C01 Practice