Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon Exam SCS-C02 Topic 6 Question 31 Discussion

Actual exam question for Amazon's SCS-C02 exam
Question #: 31
Topic #: 6
[All SCS-C02 Questions]

An AWS account that is used for development projects has a VPC that contains two subnets. The first subnet is named public-subnet-1 and has the CIDR block 192.168.1.0/24 assigned. The other subnet is named private-subnet-2 and has the CIDR block 192.168.2.0/24 assigned. Each subnet contains Amazon EC2 instances.

Each subnet is currently using the VPC's default network ACL. The security groups that the EC2 instances in these subnets use have rules that allow traffic between each instance where required. Currently, all network traffic flow is working as expected between the EC2 instances that are using these subnets.

A security engineer creates a new network ACL that is named subnet-2-NACL with default entries. The security engineer immediately configures private-subnet-2 to use the new network ACL and makes no other changes to the infrastructure. The security engineer starts to receive reports that the EC2 instances in public-subnet-1 and public-subnet-2 cannot communicate with each other.

Which combination of steps should the security engineer take to allow the EC2 instances that are running in these two subnets to communicate again? (Select TWO.)

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

Bette
4 days ago
I'm not sure about that. Maybe we should also consider adding an outbound allow rule for 192.168.1.0/24 in the VPC's default network ACL.
upvoted 0 times
...
Willetta
8 days ago
I'm pretty sure the answer is C and E. Why would we need to touch the VPC's default network ACL? That seems like overkill.
upvoted 0 times
...
Justine
9 days ago
The correct answers are C and D. By adding an outbound allow rule for 192.168.2.0/24 in subnet-2-NACL and an inbound allow rule for 192.168.1.0/24 in subnet-2-NACL, the security engineer can restore communication between the EC2 instances in the two subnets.
upvoted 0 times
...
Demetra
13 days ago
I agree with Elin. We also need to add an inbound allow rule for 192.168.1.0/24 in subnet-2-NACL.
upvoted 0 times
...
Elin
15 days ago
I think we should add an outbound allow rule for 192.168.2.0/24 in subnet-2-NACL.
upvoted 0 times
...

Save Cancel