Independence Day Deal! Unlock 25% OFF Today – Limited-Time Offer - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon Exam ANS-C01 Topic 5 Question 10 Discussion

Actual exam question for Amazon's ANS-C01 exam
Question #: 10
Topic #: 5
[All ANS-C01 Questions]

A company has deployed Amazon EC2 instances in private subnets in a VPC. The EC2 instances must initiate any requests that leave the VPC, including requests to the company's on-premises data center over an AWS Direct Connect connection. No resources outside the VPC can be allowed to open communications directly to the EC2 instances.

The on-premises data center's customer gateway is configured with a stateful firewall device that filters for incoming and outgoing requests to and from multiple VPCs. In addition, the company wants to use a single IP match rule to allow all the communications from the EC2 instances to its data center from a single IP address.

Which solution will meet these requirements with the LEAST amount of operational overhead?

Show Suggested Answer Hide Answer

Contribute your Thoughts:

Ariel
1 months ago
Option A? Seriously? Who thought that up, the 'Rube Goldberg Solutions' team?
upvoted 0 times
...
Margarett
1 months ago
I'm imagining the on-premises network admin seeing this question and just face-palming. 'You want me to do what now?'
upvoted 0 times
Pearlie
5 days ago
C) Deploy a NAT gateway into a private subnet in the VPC where the EC2 instances are deployed. Specify the NAT gateway type as private. Configure the on-premises firewall to allow connections from the IP address that is assigned to the NAT gateway.
upvoted 0 times
...
Jacki
16 days ago
B) Configure the on-premises firewall to filter all requests from the on-premises network to the EC2 instances. Allow a stateful connection if the EC2 instances in the VPC initiate the traffic.
upvoted 0 times
...
Shizue
25 days ago
A) Create a VPN connection over the Direct Connect connection by using the on-premises firewall. Use the firewall to block all traffic from on premises to AWS. Allow a stateful connection from the EC2 instances to initiate the requests.
upvoted 0 times
...
...
Joanne
2 months ago
As long as the NAT gateway doesn't become a bottleneck, Option C seems like the way to go. It's nice to have a single IP rule to manage on the on-premises firewall.
upvoted 0 times
Gabriele
1 days ago
I think Option C is the most efficient solution with the least operational overhead.
upvoted 0 times
...
Daniela
4 days ago
Yeah, having a single IP rule on the on-premises firewall simplifies management.
upvoted 0 times
...
Shayne
8 days ago
I agree, Option C with the NAT gateway seems like the best choice.
upvoted 0 times
...
Luz
12 days ago
As long as the NAT gateway can handle the traffic, it should work smoothly.
upvoted 0 times
...
Lashandra
18 days ago
Using a single IP rule for all communications is definitely a plus.
upvoted 0 times
...
Santos
23 days ago
I think so too. It simplifies the management of the on-premises firewall.
upvoted 0 times
...
Franchesca
1 months ago
I agree, Option C with the NAT gateway seems like the best choice.
upvoted 0 times
...
...
Dahlia
2 months ago
I'm not sure, but option D could also work. Configuring the on-premises firewall to allow connections from the NAT instance might be simpler.
upvoted 0 times
...
Mica
2 months ago
I'm a bit wary of using a NAT instance instead of a gateway. Instances can be more prone to failure, and the maintenance overhead might be higher. Option C seems cleaner.
upvoted 0 times
Jillian
1 months ago
Yeah, I think option C is the best choice for this scenario.
upvoted 0 times
...
Denise
2 months ago
I agree, using a NAT gateway would be more reliable and have less maintenance overhead.
upvoted 0 times
...
...
Pamela
2 months ago
I agree with Dante. Using a NAT gateway in the VPC seems like the most efficient way to meet the requirements.
upvoted 0 times
...
Dante
2 months ago
I think option C is the best solution.
upvoted 0 times
...
Ryan
2 months ago
I'm not sure, but option D also seems like a viable solution. A NAT instance could work well too.
upvoted 0 times
...
Rolande
2 months ago
I agree with Dominga. Using a NAT gateway in a private subnet seems like the most efficient way to meet the requirements.
upvoted 0 times
...
Dominga
2 months ago
I think option C is the best solution.
upvoted 0 times
...
Jerry
2 months ago
Option C looks like the most straightforward solution. Using a private NAT gateway and configuring the on-premises firewall to allow connections from its IP address should do the trick.
upvoted 0 times
Lazaro
1 months ago
Definitely, it's important to minimize operational overhead while maintaining security.
upvoted 0 times
...
Launa
1 months ago
I think so too. It simplifies the setup and ensures only the necessary connections are allowed.
upvoted 0 times
...
Buck
2 months ago
I agree, it seems like the most efficient way to meet the requirements.
upvoted 0 times
...
Amie
2 months ago
Option C looks like the most straightforward solution. Using a private NAT gateway and configuring the on-premises firewall to allow connections from its IP address should do the trick.
upvoted 0 times
...
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77