PAS-C01 · Question #94
A company decides to deploy SAP non-production systems on AWS by using the standard installation model in a single Availability Zone. The company will use Amazon Elastic File System (Amazon EFS) to…
The correct answer is A. Configure the security groups that are associated with the EFS file systems to allow inbound E. Configure the security groups that are associated with the EC2 instances to allow outbound. Mounting Amazon EFS requires NFS traffic on TCP port 2049 to flow from the EC2 instance to the EFS mount target. Two security group rules are needed to create this path: (1) The EFS mount target's security group must allow inbound traffic on port 2049 from the EC2 instances'…
Question
A company decides to deploy SAP non-production systems on AWS by using the standard installation model in a single Availability Zone. The company will use Amazon Elastic File System (Amazon EFS) to host SAP file systems such as /sapmnt and /usr/sap/trans. The company launches the required Amazon EC2 instances to host these systems. However, the company cannot mount the EFS file systems to the respective EC2 instances. An SAP engineer needs to adjust the security groups that are assigned to the EC2 instances and EFS file systems to allow traffic between the EC2 instances and the EFS file systems. Which combination of steps should the SAP engineer take to meet these requirements? (Choose two.)
Options
- AConfigure the security groups that are associated with the EFS file systems to allow inbound
- BConfigure the security groups that are associated with the EFS file systems to allow outbound
- CConfigure the security groups that are associated with the EFS file systems to allow outbound
- DConfigure the security groups that are associated with the EC2 instances to allow inbound access
- EConfigure the security groups that are associated with the EC2 instances to allow outbound
How the community answered
(21 responses)- A81% (17)
- B5% (1)
- C10% (2)
- D5% (1)
Explanation
Mounting Amazon EFS requires NFS traffic on TCP port 2049 to flow from the EC2 instance to the EFS mount target. Two security group rules are needed to create this path: (1) The EFS mount target's security group must allow inbound traffic on port 2049 from the EC2 instances' security group (Option A) - this permits NFS requests to reach EFS. (2) The EC2 instances' security group must allow outbound traffic on port 2049 to the EFS security group (Option E) - this permits the instances to initiate NFS connections. Option B (outbound from EFS) is unnecessary because EFS responses use stateful connection tracking; the return traffic is automatically allowed. Option C is similarly redundant. Option D (inbound to EC2 from EFS) addresses NFS responses, which are handled automatically by stateful security groups and do not require an explicit inbound rule.
Topics
Community Discussion
No community discussion yet for this question.