nerdexam
AmazonAmazon

PAS-C01 · Question #132

PAS-C01 Question #132: Real Exam Question with Answer & Explanation

Sign in or unlock PAS-C01 to reveal the answer and full explanation for question #132. The question stem and answer options stay visible for context.

Design of SAP Workloads on AWS

Question

A company is planning to move all its SAP applications to Amazon EC2 instances in a VPC. Recently, the company signed a multiyear contract with a payroll software-as-a-service (SaaS) provider. Integration with the payroll SaaS solution is available only through public web APIs. Corporate security guidelines state that all outbound traffic must be validated against an allow list. The payroll SaaS provider provides only fully qualified domain name (FQDN) addresses and no IP addresses or IP address ranges. Currently, an on-premises firewall appliance filters FQDNs. The company needs to connect an SAP Process Orchestration (SAP PO) system to the payroll SaaS provider. What must the company do on AWS to meet these requirements?

Options

  • AAdd an outbound rule to the security group of the SAP PO system to allow the FQDN of the payroll
  • BAdd an outbound rule to the network ACL of the subnet that contains the SAP PO system to allow
  • CAdd an AWS WAF web ACL to the VPAdd an outbound rule to allow the SAP PO system to
  • DAdd an AWS Network Firewall firewall to the VPC. Add an outbound rule to allow the SAP PO

Unlock PAS-C01 to see the answer

You've previewed enough free PAS-C01 questions. Unlock PAS-C01 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#AWS Network Firewall#FQDN filtering#Egress control#VPC Security
Full PAS-C01 PracticeBrowse All PAS-C01 Questions