Skip to content
BytePatterns

SCS-C03 · Domain 3: Infrastructure Security · 18% of the exam

Task 3.3: Design and troubleshoot network security controls

Deciding which packets may pass: security groups, network ACLs and Network Firewall, encrypted hybrid links with VPN, Direct Connect and MACsec, Verified Access, segmentation of north/south and east/west traffic, and finding network paths nobody needs.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

Instances in private subnets may make outbound HTTPS calls only to three partner domains and to *.amazonaws.com. The partners' IP addresses change often. All egress already passes through AWS Network Firewall. What should the security team configure?

  1. ASecurity group outbound rules that allow port 443 to the partners' current IP ranges
  2. BA network ACL on the private subnets that denies all outbound traffic except port 443
  3. CA Route 53 Resolver DNS Firewall rule that blocks a list of known malicious domains
  4. DA Network Firewall stateful domain list rule group in allow list mode
Show the answer and why
  • ASecurity group outbound rules that allow port 443 to the partners' current IP ranges

    Incorrect

    Security groups match addresses, not domain names, so the rules would break whenever the partners' addresses change.

  • BA network ACL on the private subnets that denies all outbound traffic except port 443

    Incorrect

    A network ACL cannot tell one HTTPS destination from another by name; it would still allow every HTTPS site.

  • CA Route 53 Resolver DNS Firewall rule that blocks a list of known malicious domains

    Incorrect

    A block list of bad domains leaves every other domain reachable, which is the opposite of an allow list.

  • DA Network Firewall stateful domain list rule group in allow list mode

    Correct

    Domain list rule groups match the TLS SNI or HTTP host name, not IP addresses, so an allow list keeps working when addresses change.

Egress filtering by name belongs in Network Firewall's domain lists. Since SNI and host headers can be forged, add IP-based rules where the risk warrants it.

Question 2 · choose 1

A company has a 100 Gbps dedicated AWS Direct Connect connection. A new regulation requires that all traffic between the company's router and AWS on that link is encrypted, without lowering usable throughput to the bandwidth of individual IPsec tunnels. The company's router supports MACsec. What should the company do?

  1. ARun AWS Site-to-Site VPN tunnels over the Direct Connect connection and aggregate them with ECMP
  2. BRequire TLS in every application that uses the link
  3. CReplace the connection with a hosted connection from a Direct Connect partner and turn on MACsec
  4. DTurn on MACsec on the dedicated connection with a CKN/CAK pair configured on both ends
Show the answer and why
  • ARun AWS Site-to-Site VPN tunnels over the Direct Connect connection and aggregate them with ECMP

    Incorrect

    Each VPN tunnel has a fixed bandwidth limit of a few Gbps at most, so many tunnels would be needed and throughput would still be limited per flow.

  • BRequire TLS in every application that uses the link

    Incorrect

    Application TLS protects only the applications that use it, not all traffic on the link.

  • CReplace the connection with a hosted connection from a Direct Connect partner and turn on MACsec

    Incorrect

    MACsec is not supported on hosted connections.

  • DTurn on MACsec on the dedicated connection with a CKN/CAK pair configured on both ends

    Correct

    MACsec gives layer 2 encryption between the company's router and the Direct Connect device and is supported on 10, 100 and 400 Gbps dedicated connections.

High-throughput, link-level encryption on Direct Connect is MACsec on a dedicated connection; IPsec VPN is the option when MACsec is not available.

Question 3 · choose 1

An auditor asks the security team to show that no resource in the cardholder data VPC can be reached from any internet gateway, and to list any network path that would allow it. The team must check the configuration without sending traffic and must name the requirement once rather than test each pair of resources. Which tool should the team use?

  1. AVPC Reachability Analyzer analyses between resources
  2. BVPC flow logs for the cardholder data VPC, queried with Athena
  3. CNetwork Access Analyzer with a Network Access Scope
  4. DThe Trusted Advisor check for unrestricted security group ports
Show the answer and why
  • AVPC Reachability Analyzer analyses between resources

    Incorrect

    Reachability Analyzer tests one source and one destination at a time, so every pair would need its own analysis.

  • BVPC flow logs for the cardholder data VPC, queried with Athena

    Incorrect

    Flow logs show traffic that actually occurred. They cannot prove that no path exists.

  • CNetwork Access Analyzer with a Network Access Scope

    Correct

    A Network Access Scope states the requirement once, and the analysis lists every potential path that violates it, without sending traffic.

  • DThe Trusted Advisor check for unrestricted security group ports

    Incorrect

    This check flags open security group rules. It does not evaluate whole network paths from internet gateways.

Network Access Analyzer answers "is there any path like this?" for a whole scope; Reachability Analyzer answers "can A reach B?".

Question 4 · choose 1

Web servers in private subnets sit behind an internet-facing Application Load Balancer. A custom network ACL on the web server subnets allows inbound TCP 8080 from the load balancer subnets and allows outbound TCP 443 to 0.0.0.0/0; everything else is denied. The security groups are correct, but every target fails its health checks. What should the team change?

  1. AAdd an inbound rule to the network ACL that allows TCP 1024-65535 from the load balancer subnets
  2. BAdd an outbound rule to the network ACL that allows TCP 8080 to the load balancer subnets
  3. CAdd an outbound rule to the network ACL that allows TCP 1024-65535 to the load balancer subnets
  4. DAllow inbound TCP 8080 from the load balancer's security group on the targets' security group
Show the answer and why
  • AAdd an inbound rule to the network ACL that allows TCP 1024-65535 from the load balancer subnets

    Incorrect

    Inbound requests on 8080 are already allowed; what is blocked is the response leaving the subnet.

  • BAdd an outbound rule to the network ACL that allows TCP 8080 to the load balancer subnets

    Incorrect

    Responses go back to the port the load balancer opened the connection from, not to port 8080.

  • CAdd an outbound rule to the network ACL that allows TCP 1024-65535 to the load balancer subnets

    Correct

    Network ACLs are stateless, so responses need their own rule, and requests from Elastic Load Balancing use source ports 1024-65535.

  • DAllow inbound TCP 8080 from the load balancer's security group on the targets' security group

    Incorrect

    Security groups are stateful and already correct; the network ACL is what drops the responses.

With a stateless network ACL, every allowed request needs a rule for its response on the client's ephemeral ports.

Question 5 · choose 1

Instances in a private subnet need to download IPv4 updates from the internet, but nothing on the internet may start a connection to them. What should the team add?

  1. AA NAT gateway in a public subnet, routed from the private subnet
  2. BElastic IP addresses on each private instance
  3. CAn egress-only internet gateway for the subnet
  4. DA route from the private subnet straight to the internet gateway
Show the answer and why
  • AA NAT gateway in a public subnet, routed from the private subnet

    Correct

    A NAT gateway lets instances reach services outside the VPC while external services cannot start connections to them.

  • BElastic IP addresses on each private instance

    Incorrect

    Public addresses make the instances reachable from the internet.

  • CAn egress-only internet gateway for the subnet

    Incorrect

    Egress-only internet gateways work only for IPv6 traffic.

  • DA route from the private subnet straight to the internet gateway

    Incorrect

    That turns the subnet public.

NAT is for outbound-only IPv4; for IPv6, the equivalent is an egress-only internet gateway.

Question 6 · choose 1

A team associated an IPv6 CIDR block with a VPC. Web servers in a public subnet now have IPv6 addresses, the subnet's route table sends ::/0 to the internet gateway, and the subnet uses the unmodified default network ACL. The web servers' security group has one inbound rule, TCP 443 from 0.0.0.0/0. Clients reach the site over IPv4, but IPv6 connections time out. What should the team change?

  1. AAdd an outbound rule for TCP 1024-65535 to ::/0 in the security group
  2. BAdd IPv6 allow rules for TCP 443 to the subnet's network ACL
  3. CPoint the subnet's ::/0 route to an egress-only internet gateway
  4. DAdd an inbound rule for TCP 443 from ::/0 to the security group
Show the answer and why
  • AAdd an outbound rule for TCP 1024-65535 to ::/0 in the security group

    Incorrect

    Security groups are stateful: responses to allowed inbound traffic leave regardless of the outbound rules.

  • BAdd IPv6 allow rules for TCP 443 to the subnet's network ACL

    Incorrect

    When an IPv6 CIDR block is associated with a VPC, rules that allow IPv6 traffic are added to the unmodified default network ACL automatically.

  • CPoint the subnet's ::/0 route to an egress-only internet gateway

    Incorrect

    An egress-only internet gateway prevents the internet from starting IPv6 connections, so clients still could not connect.

  • DAdd an inbound rule for TCP 443 from ::/0 to the security group

    Correct

    0.0.0.0/0 covers IPv4 addresses only. Each IPv4 rule needs a matching IPv6 rule, such as HTTPS from ::/0.

Turning on IPv6 adds new address space that existing IPv4 rules do not cover. Review inbound security group rules, custom or modified network ACLs and routes for IPv6 one by one.

Question 7 · choose 1

An application in private subnets calls Amazon SQS with the default public Regional endpoint name. The team wants that traffic to stay inside the VPC without changing the application. What should it do?

  1. AAdd a NAT gateway for the private subnets
  2. BAn SQS interface endpoint with private DNS on
  3. CAn SQS gateway endpoint in the route tables
  4. DAn SQS interface endpoint with private DNS off
Show the answer and why
  • AAdd a NAT gateway for the private subnets

    Incorrect

    Traffic would still go to the public endpoint over the internet path.

  • BAn SQS interface endpoint with private DNS on

    Correct

    With private DNS, the default service name resolves to the endpoint's private IP addresses, so existing requests use the endpoint.

  • CAn SQS gateway endpoint in the route tables

    Incorrect

    Gateway endpoints exist for S3 and DynamoDB, not SQS.

  • DAn SQS interface endpoint with private DNS off

    Incorrect

    Without private DNS, the application must use the endpoint-specific name, which is a code change.

Private DNS needs the VPC's DNS hostnames and DNS resolution attributes turned on.

Question 8 · choose 1

Attack traffic arrives from one known IP address. The team wants to block that address for an entire subnet right away. Which control can do this?

  1. AA security group rule that denies the address
  2. BA network ACL deny rule for the address
  3. CA route table entry that drops the address
  4. DAn IAM policy that denies the address
Show the answer and why
  • AA security group rule that denies the address

    Incorrect

    Security groups support allow rules only, not deny rules.

  • BA network ACL deny rule for the address

    Correct

    Network ACLs support deny rules and apply to all traffic entering or leaving the subnet.

  • CA route table entry that drops the address

    Incorrect

    Route tables decide where traffic goes; they do not drop by source.

  • DAn IAM policy that denies the address

    Incorrect

    IAM policies control API access, not network packets.

Give the deny rule a lower rule number than any allow rule that would match the traffic.

Question 9 · choose 1

Web servers and database servers run in an Auto Scaling setup whose IP addresses change often. The databases must accept traffic only from the web servers. How should the database security group rule be written?

  1. AAllow the database port from 0.0.0.0/0
  2. BAllow the database port from today's web server IP addresses
  3. CDeny the database port from all other security groups
  4. DAllow the port from the web servers' security group
Show the answer and why
  • AAllow the database port from 0.0.0.0/0

    Incorrect

    That allows every source.

  • BAllow the database port from today's web server IP addresses

    Incorrect

    The addresses change, so the list would drift.

  • CDeny the database port from all other security groups

    Incorrect

    Security groups support allow rules only.

  • DAllow the port from the web servers' security group

    Correct

    A rule can reference a security group as its source, so it follows the instances in that group whatever their addresses.

Security group referencing keeps tier-to-tier rules correct as instances scale.

Practise domain 3 →Practise all domains →