SCS-C02 · Question #118
A company has deployed servers on Amazon EC2 instances in a VPC. External vendors access these servers over the internet. Recently, the company deployed a new application on EC2 instances in a new…
The correct answer is B. Modify the network ACL that is associated with the CIDR range to allow outbound traffic to. You must allow the ephemeral ports in the outbound NACL for the CIDR range.
Question
A company has deployed servers on Amazon EC2 instances in a VPC. External vendors access these servers over the internet. Recently, the company deployed a new application on EC2 instances in a new CIDR range. The company needs to make the application available to the vendors. A security engineer verified that the associated security groups and network ACLs are allowing the required ports in the inbound direction. However, the vendors cannot connect to the application. Which solution will provide the vendors access to the application?
Options
- AModify the security group that is associated with the EC2 instances to have the same outbound
- BModify the network ACL that is associated with the CIDR range to allow outbound traffic to
- CModify the inbound rules on the internet gateway to allow the required ports.
- DModify the network ACL that is associated with the CIDR range to have the same outbound rules
How the community answered
(29 responses)- A3% (1)
- B86% (25)
- C7% (2)
- D3% (1)
Explanation
You must allow the ephemeral ports in the outbound NACL for the CIDR range.
Topics
Community Discussion
No community discussion yet for this question.