Question 1 · choose 1
Instances in private subnets may make outbound HTTPS calls only to three partner domains and to *.amazonaws.com. The partners' IP addresses change often. All egress already passes through AWS Network Firewall. What should the security team configure?
- ASecurity group outbound rules that allow port 443 to the partners' current IP ranges
- BA network ACL on the private subnets that denies all outbound traffic except port 443
- CA Route 53 Resolver DNS Firewall rule that blocks a list of known malicious domains
- DA Network Firewall stateful domain list rule group in allow list mode
Show the answer and why
ASecurity group outbound rules that allow port 443 to the partners' current IP ranges
Incorrect
Security groups match addresses, not domain names, so the rules would break whenever the partners' addresses change.
BA network ACL on the private subnets that denies all outbound traffic except port 443
Incorrect
A network ACL cannot tell one HTTPS destination from another by name; it would still allow every HTTPS site.
CA Route 53 Resolver DNS Firewall rule that blocks a list of known malicious domains
Incorrect
A block list of bad domains leaves every other domain reachable, which is the opposite of an allow list.
DA Network Firewall stateful domain list rule group in allow list mode
Correct
Domain list rule groups match the TLS SNI or HTTP host name, not IP addresses, so an allow list keeps working when addresses change.
Egress filtering by name belongs in Network Firewall's domain lists. Since SNI and host headers can be forged, add IP-based rules where the risk warrants it.
AWS documentation