In order to provide subnet level isolation, you want to force instance-A in one subnet to route through a security appliance, called instance-B, in another subnet.
Moving instance-B to another VPC seems like overkill for just routing traffic. I think I’d lean towards option B, but I’m not entirely confident about the tagging part.
I feel like deleting the system-generated route might cause issues. I think I should create a more specific route instead, but I'm torn between A and C.
This question feels similar to one we practiced about routing through a firewall. I think option A might be the right choice, but I can't recall the tagging details.
Hmm, I'm a bit confused on this one. I know it has something to do with testing controls, but I'm not sure if controlled reprocessing or input validation would also be considered valid answers.
Okay, the key here is that clients on ALS1 are only receiving IPv4 addresses, but we need them to also get IPv6 addresses. The question is asking what action on DSW1 would allow this.
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Alfreda
4 months agoRoyce
4 months agoIlda
4 months agoRuthann
4 months agoRebbecca
5 months agoPatti
5 months agoLeonardo
5 months agoYoko
5 months agoLai
5 months agoEun
5 months agoCharisse
5 months agoEmelda
5 months agoChanel
5 months ago