makeporngreatagain.pro
yeahporn.top
hd xxx

Virtual Private Cloud Quiz

80,336

A company hosts a popular web application that connects to an Amazon RDS MySQL DB instance running in a private VPC subnet created with default ACL settings. The web servers must be accessible only to customers on an SSL connection and the database should only be accessible to web servers in a public subnet. As an architect, which of the following would you not recommend for such an architecture?

A. Create a separate web server and database server security group.

B. Ensurethe web server security group allows HTTPS port 443 inbound traffic fromanywhere (0.0.0.0/0) and apply it to the web servers.

C. Ensurethe web server security group allows MySQL port 3306 inbound traffic fromanywhere (0.0.0.0/0) and apply it to the web servers.

D. Ensurethe DB server security group allows MySQL port 3306 inbound and specify thesource as the web server security group.

C. Change the security groups for the cluster.
The question is describing a scenario where it has been instructed that the database servers should only be accessible to web servers in the public subnet.You have been asked which one of the following is not a recommended architecture based on the scenario.The answer is option C. “Ensure the web server security group allows MySQL port 3306 inbound traffic from anywhere (0.0.0.0/0) and apply it to the web servers.”Here in this Option C, we are allowing all the incoming traffic from the internet to the database port which is not acceptable as per the architecture.​A similar setup is given in AWSDocumentation:
1) To ensure that traffic can flow into your web server from anywhere on secure traffic, you need to allow inbound security at 443
2) You need to then ensure that traffic can flow from the database server to the web server via the database security group.The below snapshot from AWS Documentation shows the rules tables for the security groups which relate to the same requirements as the question.
For more information on this use case scenario, please visit the following URL
https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_Scenario2.html
The requirement in the question states that the database servers should only be accessible to web servers in the public subnet.
The answer option C – “Ensure the web server security group allows MySQL port 3306 inbound traffic from anywhere (0.0.0.0/0) and apply it to the web servers.” is not a recommended architecture for the above scenario. Here, we allow all the incoming traffic from the Internet to the database port which is not acceptable as per the architecture.

Leave A Reply

Your email address will not be published.

baseofporn.com https://www.opoptube.com
Ads Blocker Image Powered by Code Help Pro

Ads Blocker Detected!!!

We have detected that you are using extensions to block ads. Please support us by disabling these ads blocker.