nerdexam
Amazon

SCS-C03 · Question #102

A public subnet contains two Amazon EC2 instances. The subnet has a custom network ACL. A security engineer is designing a solution to improve the subnet security. The solution must allow outbound tra

Sign in or unlock SCS-C03 to reveal the answer and full explanation for question #102. The question stem and answer options stay visible for context.

Submitted by manish99· Mar 6, 2026Infrastructure Security

Question

A public subnet contains two Amazon EC2 instances. The subnet has a custom network ACL. A security engineer is designing a solution to improve the subnet security. The solution must allow outbound traffic to an internet service that uses TLS through port 443. The solution also must deny inbound traffic that is destined for MySQL port 3306. Which network ACL rule set meets these requirements?

Options

  • AUse inbound rule 100 to allow traffic on TCP port 443. Use inbound rule 200 to deny traffic on
  • BUse inbound rule 100 to deny traffic on TCP port 3306. Use inbound rule 200 to allow traffic on
  • CUse inbound rule 100 to allow traffic on TCP port range 1024-65535. Use inbound rule 200 to
  • DUse inbound rule 100 to deny traffic on TCP port 3306. Use inbound rule 200 to allow traffic on

Unlock SCS-C03 to see the answer

You've previewed enough free SCS-C03 questions. Unlock SCS-C03 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#network ACL#stateless rules#ephemeral ports#port filtering
Full SCS-C03 Practice