AWS SAP-C02 · Question 72 · Domain 1.2: Security Controls
A company is designing a secure network architecture. They have a VPC with public and private subnets. EC2 instances in the private subnets need to download patches from the internet. The security team requires that all outbound traffic be inspected for malware and that access to specific domains can be blocked. Which combination of services should be used? (Select TWO)
Answer options:
Deploy a NAT Gateway in the public subnet.
Deploy an Internet Gateway in the private subnet.
Deploy AWS Network Firewall and route traffic from the private subnets through it.
Use AWS WAF to inspect the outbound traffic.
Configure Security Groups to block specific domains.
Use Amazon GuardDuty to block the traffic.
75 questions · hints · full answers · grading