Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-440 Exam - Topic 2 Question 18 Discussion

A cloud engineer is setting up a new set of nodes in the AWS EKS cluster to manage database integration with Mongo Atlas. The engineer set up security to Mongo but now wants to ensure that the nodes are also secure on the network side. Which feature in AWS should the engineer use?
B) security groups
A) EC2 Trust Lock
D) key pairs
C) tagging

Cisco 300-440 Exam - Topic 2 Question 18 Discussion

Actual exam question for Cisco's 300-440 exam
Question #: 18
Topic #: 2
[All 300-440 Questions]

A cloud engineer is setting up a new set of nodes in the AWS EKS cluster to manage database integration with Mongo Atlas. The engineer set up security to Mongo but now wants to ensure that the nodes are also secure on the network side. Which feature in AWS should the engineer use?

Show Suggested Answer Hide Answer
Suggested Answer: B

Security groups are a feature in AWS that allow you to control the inbound and outbound traffic to your instances. They act as a virtual firewall that can filter the traffic based on the source, destination, protocol, and port. You can assign one or more security groups to your instances, and each security group can have multiple rules. Security groups are stateful, meaning that they automatically allow the response traffic for any allowed inbound traffic, and vice versa. Security groups are essential for securing your nodes in the AWS EKS cluster, as they can prevent unauthorized access to your Mongo Atlas database or other resources. You can also use security groups to isolate your nodes from other instances in the same VPC or subnet, or to allow communication between nodes in different clusters or regions.Reference:=

AWS Security Groups

Security Groups for Your VPC

Security Groups for Your Amazon EC2 Instances

Security Groups for Your Amazon EKS Cluster


Contribute your Thoughts:

0/2000 characters
Rosio
2 months ago
True, but Security Groups are more flexible for EKS nodes.
upvoted 0 times
...
Sherrell
2 months ago
What about Network ACLs? They add another layer of security.
upvoted 0 times
...
Latanya
2 months ago
Definitely! Security Groups control inbound and outbound traffic.
upvoted 0 times
...
Richelle
4 months ago
I think they should use Security Groups.
upvoted 0 times
...
Johnson
4 months ago
I think they should consider using AWS WAF too.
upvoted 0 times
...
Delsie
4 months ago
Surprised they didn't mention VPCs for isolation!
upvoted 0 times
...
Therese
4 months ago
What about Network ACLs? Aren't they also important?
upvoted 0 times
...
Man
5 months ago
Totally agree, Security Groups are essential!
upvoted 0 times
...
Stephaine
5 months ago
They should use AWS Security Groups for network security.
upvoted 0 times
...
Amber
5 months ago
AWS Network Firewall is the feature the engineer needs to secure the network.
upvoted 0 times
...
Celestina
5 months ago
AWS Network Firewall is the way to go for network security in this scenario.
upvoted 0 times
...
Myrtie
5 months ago
I'd go with AWS Network Firewall to secure the network for the EKS cluster.
upvoted 0 times
...
Ruthann
5 months ago
AWS Network Firewall is the feature the engineer should use.
upvoted 0 times
...
Tyra
6 months ago
I believe the best option would be to use AWS PrivateLink to securely connect to Mongo Atlas without exposing the nodes to the public internet.
upvoted 0 times
...
Starr
6 months ago
I practiced a similar question about securing nodes in EKS, and I think VPC Peering might be involved, but I'm not confident about that.
upvoted 0 times
...
Launa
7 months ago
I'm not entirely sure, but I remember something about Network ACLs being important for network security in AWS. Could that be relevant here?
upvoted 0 times
...
Agustin
7 months ago
I think the engineer should consider using Security Groups to control inbound and outbound traffic for the nodes. That sounds familiar from my studies.
upvoted 0 times
...
Stevie
7 months ago
Hmm, not 100% sure on this one. I'd want to review the AWS documentation on EKS networking and security to make sure I fully understand the options available. Probably a good idea to jot down a few key points before answering.
upvoted 0 times
...
Herminia
7 months ago
I've worked with EKS and Mongo Atlas before, so this feels pretty straightforward to me. I'd recommend looking into Amazon VPC and the security features it provides to lock down the network access to those EKS nodes.
upvoted 0 times
...
Glendora
7 months ago
Okay, for this one I'd probably focus on looking at the AWS networking services that can help secure the EKS nodes. Things like VPC, security groups, and network ACLs seem like they could be relevant here.
upvoted 0 times
...
Eden
7 months ago
Hmm, this seems like it could be a tricky one. I'd want to make sure I understand the specific networking requirements for integrating Mongo Atlas with EKS. Might need to do some research on best practices there.
upvoted 0 times
...
Belen
8 months ago
I think I'd start by reviewing the AWS security features that are relevant for EKS clusters and network security. Maybe look into things like security groups, network ACLs, or VPC peering.
upvoted 0 times
Iluminada
1 month ago
Don't forget about VPC peering! It can help with secure communication between VPCs.
upvoted 0 times
...
Dusti
2 months ago
Yeah, security groups are great! Network ACLs can add another layer too.
upvoted 0 times
...
Truman
2 months ago
Have you checked out security groups yet? They're essential for controlling access.
upvoted 0 times
...
...

Save Cancel