Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon Exam SAA-C03 Topic 3 Question 60 Discussion

Actual exam question for Amazon's SAA-C03 exam
Question #: 60
Topic #: 3
[All SAA-C03 Questions]

[Design Secure Architectures]

A company is designing a web application with an internet-facing Application Load Balancer (ALB).

The company needs the ALB to receive HTTPS web traffic from the public internet. The ALB must send only HTTPS traffic to the web application servers hosted on the Amazon EC2 instances on port 443. The ALB must perform a health check of the web application servers over HTTPS on port 8443.

Which combination of configurations of the security group that is associated with the ALB will meet these requirements? (Select THREE.)

Show Suggested Answer Hide Answer
Suggested Answer: A, C, E

Option A:The ALB must accept HTTPS traffic from the public internet. Allowing inbound traffic on port 443 from 0.0.0.0/0 enables this functionality.

Option C:The ALB must forward HTTPS traffic to the web application servers on port 443. Outbound traffic for port 443 must be allowed for this communication.

Option E:The ALB must perform health checks on the web application servers over HTTPS on port 8443. Outbound traffic for port 8443 must be allowed for this purpose.

Option B:Allowing all outbound traffic is overly permissive and does not align with the specific requirements.

Option D and F:Inbound traffic to the ALB from the web application instances is unnecessary because the flow of traffic is from the ALB to the web application instances, not vice versa.

AWS Documentation Reference:

Application Load Balancer Security Groups

Health Checks for ALBs


Contribute your Thoughts:

Caprice
2 days ago
I agree with Dallas. We also need to allow HTTPS outbound traffic to the web application instances for port 443.
upvoted 0 times
...
Dortha
3 days ago
I agree with Mozelle's analysis. This is a straightforward security group configuration for an ALB with HTTPS requirements.
upvoted 0 times
...
Dallas
4 days ago
I think we should allow HTTPS inbound traffic from 0.0.0.0/0 for port 443.
upvoted 0 times
...
Mozelle
7 days ago
A, C, and E are the correct answers. The ALB needs to allow HTTPS inbound traffic from the public internet on port 443, send HTTPS traffic to the web application servers on port 443, and allow HTTPS outbound traffic to the web application instances for the health check on port 8443.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77