ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
EC2 instances in a private subnet use the Amazon-provided DNS resolver at the VPC-base-plus-2 address. After their default security group is replaced with one that denies all egress unless explicitly allowed, the instances can still reach public IPs over HTTPS but can no longer resolve domain names. Which minimal egress rule should the security engineer add to restore DNS functionality while following the principle of least privilege?
Permit outbound UDP traffic on port 123 to the VPC DNS resolver's IP address only
Permit outbound TCP traffic on port 53 to 0.0.0.0/0
Permit outbound UDP and TCP traffic on port 53 to the VPC DNS resolver's IP address only
Permit outbound UDP traffic on ports 67 and 68 to the VPC DNS resolver's IP address only
DNS queries normally use UDP port 53, but automatically retry over TCP port 53 when responses exceed the UDP size limit. Because AWS security groups are stateful, the engineer needs to allow only the outbound half of the conversation; the return traffic is automatically permitted. Opening both UDP and TCP on port 53-restricted to the single Amazon-provided resolver's IP-restores name resolution and limits exposure. Allowing only TCP 53 would break most queries, while opening UDP 123 (NTP) or ports 67/68 (DHCP) is unrelated to DNS.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why do DNS queries use both UDP and TCP on port 53?
Open an interactive chat with Bash
What is the principle of least privilege, and how does it apply to security groups?
Open an interactive chat with Bash
What role does the VPC DNS resolver play in AWS?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Network and Communication Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .