AWS SAA-C03 · Question 03 · Domain 1.2: Secure Workloads
A company is designing a VPC for a multi-tier web application. They need to block specific malicious IP addresses from accessing the web servers, while allowing legitimate HTTPS traffic. Which TWO actions should the solutions architect take? (Select TWO.)
Answer options:
Add a deny rule for the malicious IPs in the Security Group.
Add a deny rule for the malicious IPs in the Network ACL.
Add an allow rule for port 443 (HTTPS) in the Security Group.
Configure AWS Shield Standard to block the specific IP addresses.
Use an IAM policy to deny access from the malicious IPs.
65 questions · hints · full answers · grading