AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

An operations engineer is defining security for a newly deployed three-tier web application in a single VPC. The application tier EC2 instances reside in private subnets and receive traffic exclusively from an internal Application Load Balancer. The engineer must permit only the load balancer to initiate HTTPS connections to the instances, even when the load balancer scales. How should the security group for the application tier be configured?

  • Add an inbound rule that allows TCP 443 with the source set to the load balancer's subnet CIDR ranges.

  • Attach the load balancer's security group to the application EC2 instances instead of creating a separate security group.

  • Add an inbound rule that allows TCP 443 with the source set to the security group ID of the Application Load Balancer.

  • Create a network ACL for the private subnets that allows inbound TCP 443 from 0.0.0.0/0.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot