SCS-C02 Infrastructure Security • Set 9
SCS-C02 Infrastructure Security Practice Test 9 — 15 questions with explanations. Free, no signup.
A company has a VPC with a public subnet and a private subnet. The public subnet contains a NAT gateway and a bastion host. The private subnet contains a web server that needs to be patched via the internet. The security engineer has configured the route tables: the public subnet route table has a default route to the Internet Gateway, and the private subnet route table has a default route to the NAT gateway. The web server can successfully initiate outbound connections to the internet to download patches. However, the security team notices that the web server is also receiving inbound connections from the internet on port 80. The web server's security group allows inbound HTTP from 0.0.0.0/0. What should the engineer do to prevent inbound internet traffic while still allowing outbound patching?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.