Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Exam SAA-C03 All Questions
Exam SAA-C03 All Questions

View all questions & answers for the SAA-C03 exam

Amazon Web Services AWS Solutions Architect Associate SAA-C03 Question # 195 Topic 22 Discussion

SAA-C03 Exam Topic 22 Question 195 Discussion:
Question #: 195
Topic #: 22

A solutions architect is designing a two-tiered architecture that includes a public subnet and a database subnet. The web servers in the public subnet must be open to the internet on port 443. TheAmazon RDS for MySQL D6 instance in the database subnet must be accessible only to the web servers on port 3306.

Which combination of steps should the solutions architect take to meet these requirements? (Select TWO.)


A.

Create a network ACL for the public subnet Add a rule to deny outbound traffic to 0 0 0 0/0 on port 3306


B.

Create a security group for the DB instance Add a rule to allow traffic from the public subnet CIDR block on port 3306


C.

Create a security group for the web servers in the public subnet Add a rule to allow traffic from 0 0 0 O'O on port 443


D.

Create a security group for the DB instance Add a rule to allow traffic from the web servers' security group on port 3306


E.

Create a security group for the DB instance Add a rule to deny all traffic except traffic from the web servers' security group on port 3306


Get Premium SAA-C03 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.