Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon Exam ANS-C01 Topic 1 Question 25 Discussion

Actual exam question for Amazon's ANS-C01 exam
Question #: 25
Topic #: 1
[All ANS-C01 Questions]

A company is deploying a new stateless web application on AWS. The web application will run on Amazon EC2 instances in private subnets behind an Application Load Balancer. The EC2 instances are in an Auto Scaling group. The web application has a stateful management application for administration that will run on EC2 instances that are in a separate Auto Scaling group.

The company wants to access the management application by using the same URL as the web application, with a path prefix of /management. The protocol, hostname, and port number must be the same for the web application and the management application. Access to the management application must be restricted to the company's on-premises IP address space. An SSL/TLS certificate from AWS Certificate Manager (ACM) will protect the web application.

Which combination of steps should a network engineer take to meet these requirements? (Select TWO.)

Show Suggested Answer Hide Answer

Contribute your Thoughts:

Eun
13 hours ago
I'm not sure, but I think option B could also be a valid choice.
upvoted 0 times
...
Alba
13 hours ago
C looks interesting, but I'm not a fan of relying on the X-Forwarded-For header for IP verification. That could be easily spoofed.
upvoted 0 times
...
Lashandra
2 days ago
I agree with Alishia. Those steps seem to meet all the requirements.
upvoted 0 times
...
Glennis
5 days ago
I'm not sure about B. Modifying the default rule to handle the management app doesn't seem as clean as having a dedicated rule for it.
upvoted 0 times
...
Alishia
6 days ago
I think the correct steps are A and C.
upvoted 0 times
...
Johnna
6 days ago
Hmm, I think option A is the way to go. Separating the management application into its own target group and using path-based routing to restrict access to the on-premises IP space seems like a solid approach.
upvoted 0 times
...

Save Cancel