Courseiva
Network Security, Compliance and GovernanceeasyMultiple SelectObjective-mapped

ANS-C01 Network Security, Compliance and Governance Practice Question

Which TWO of the following are best practices for securing a VPC?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use multiple Availability Zones for redundancy.

(Use multiple Availability Zones) is correct because it provides redundancy and improves availability, which is a key security best practice by ensuring fault tolerance. Option D (Restrict inbound SSH access to specific IP ranges) is correct as it minimizes the attack surface by limiting administrative access to authorized IPs only. Option A is wrong: VPC Flow Logs capture IP traffic information but do not block traffic; they are used for monitoring and analysis, not as a security control. Option C is wrong: placing databases in public subnets exposes them to the internet, increasing risk; they should be in private subnets with controlled access. Option E is wrong: the default VPC security group allows all inbound traffic, which is overly permissive; custom security groups should be used to implement least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable VPC Flow Logs on all subnets to block malicious traffic.

    Why it's wrong here

    Flow logs only capture metadata, do not block.

  • Use multiple Availability Zones for redundancy.

    Why this is correct

    Improves availability and fault tolerance.

  • Place database instances in public subnets for easier management.

    Why it's wrong here

    Databases should be in private subnets.

  • Restrict inbound SSH access to specific IP ranges.

    Why this is correct

    Least privilege principle.

  • Use the default VPC security group for all instances.

    Why it's wrong here

    Default security group is too permissive.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This ANS-C01 question is part of Courseiva's 1,621-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.