For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 7Question 25
    Medium1 markMultiple Choice
    Domain 1.2: Security ControlsSecurityNetwork FirewallNetworking

    AWS SAP-C02 · Question 25 · Domain 1.2: Security Controls

    A company has a multi-tier application running on AWS. The web tier is in a public subnet, and the application and database tiers are in private subnets. The application tier needs to download software updates from the internet. The security team requires that the application tier's outbound internet access be restricted to only the specific domains of the software vendors. How can this be achieved?

    Answer options:

    A.

    Use a NAT Gateway and configure Security Groups on the application instances to allow outbound traffic only to the vendor domains.

    B.

    Deploy an AWS Network Firewall in the VPC. Configure stateful rules with domain list filtering to allow access only to the vendor domains. Route application tier internet traffic through the firewall.

    C.

    Configure a VPC Endpoint for the software vendor's domains.

    D.

    Use AWS WAF on an Application Load Balancer to filter outbound requests.

    How to approach this question

    Identify the service that provides outbound domain filtering.

    Full Answer

    B.Deploy an AWS Network Firewall in the VPC. Configure stateful rules with domain list filtering to allow access only to the vendor domains. Route application tier internet traffic through the firewall.✓ Correct
    Deploy an AWS Network Firewall in the VPC. Configure stateful rules with domain list filtering to allow access only to the vendor domains. Route application tier internet traffic through the firewall.
    AWS Network Firewall provides stateful inspection and domain name filtering for outbound traffic, allowing you to restrict access to specific URLs/domains.

    Common mistakes

    Believing Security Groups can use domain names.
    Question 24All questionsQuestion 26

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 7

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A global enterprise is designing a multi-region network architecture connecting 50 AWS accounts a...HardQ02A company is migrating its hybrid network to AWS. They have two 10 Gbps AWS Direct Connect connec...HardQ03An enterprise has 100 AWS accounts in AWS Organizations. The security team mandates that all Amaz...MediumQ04A financial company requires that all EBS volumes, S3 buckets, and RDS databases be encrypted usi...EasyQ05An enterprise is designing a disaster recovery strategy for a critical application running on Ama...Hard
    View all 75 questions →