AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

A company runs a two-tier web app in one VPC. An internet-facing ALB in public subnets listens on TCP 443 and forwards to EC2 instances in private subnets. Security group SG-ALB allows TCP 443 from 0.0.0.0/0. Security group SG-App also allows TCP 443 from 0.0.0.0/0. An audit requires SG-App to accept traffic only from the ALB. What is the most operationally efficient change?

  • Add an outbound rule to SG-ALB that allows TCP 443 to SG-App and remove the inbound rule from SG-App.

  • Replace the inbound rule in SG-App to allow TCP 443 from the security group SG-ALB.

  • Replace the inbound rule in SG-App to allow TCP 443 from the private subnet CIDR ranges that host the ALB's network interfaces.

  • Replace the inbound rule in SG-App to allow TCP 443 from the public subnet CIDR ranges that host the ALB.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot