nerdexam
AmazonAmazon

ANS-C01 · Question #69

ANS-C01 Question #69: Real Exam Question with Answer & Explanation

Sign in or unlock ANS-C01 to reveal the answer and full explanation for question #69. The question stem and answer options stay visible for context.

Submitted by carlos_mx· Mar 6, 2026Infrastructure Security

Question

Your security team implements a host-based firewall on all of your Amazon Elastic Compute Cloud (EC2) instances to block all outgoing traffic. Exceptions must be requested for each specific requirement. Until you request a new rule, you cannot access the instance metadata service. Which firewall rule should you request to be added to your instances to allow instance metadata access?

Options

  • AInbound; Protocol tcp; Source [Instance's EIP]; Destination 169.254.169.254
  • BInbound; Protocol tcp; Destination 169.254.169.254; Destination port 80
  • COutbound; Protocol tcp; Destination 169.254.169.254; Destination port 80
  • DOutbound; Protocol tcp; Destination 169.254.169.254; Destination port 443

Unlock ANS-C01 to see the answer

You've previewed enough free ANS-C01 questions. Unlock ANS-C01 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#EC2 instance metadata#host firewall rules#outbound connectivity
Full ANS-C01 PracticeBrowse All ANS-C01 Questions