1answer.
Ask question
Login Signup
Ask question
All categories
  • English
  • Mathematics
  • Social Studies
  • Business
  • History
  • Health
  • Geography
  • Biology
  • Physics
  • Chemistry
  • Computers and Technology
  • Arts
  • World Languages
  • Spanish
  • French
  • German
  • Advanced Placement (AP)
  • SAT
  • Medicine
  • Law
  • Engineering
taurus [48]
3 years ago
12

A security review has flagged this architecture as vulnerable, and a Security Engineer has been asked to make this design more s

ecure. The company has a short deadline and a second VPN connection to the Aurora account is not possible.
How can a Security Engineer securely set up the bastion host?
A. Move the bastion host to the VPC and VPN connectivity. Create a VPC peering relationship between the bastion host VPC and Aurora VPC.
B. Create a SSH port forwarding tunnel on the Developer's workstation to the bastion host to ensure that only authorized SSH clients can access the bastion host.
C. Move the bastion host to the VPC with VPN connectivity. Create a cross-account trust relationship between the bastion VPC and Aurora VPC, and update the Aurora security group for the relationship.
D. Create an AWS Direct Connect connection between the corporate network and the Aurora account, and adjust the Aurora security group for this connection.

Physics
1 answer:
dybincka [34]3 years ago
6 0

Answer:

Complete Question:

A company has two AWS accounts, each containing one VPC. The first VPC has a VPN connection with its corporate network. The second VPC, without a VPN, hosts an Amazon Aurora database cluster in private subnets. Developers manage the Aurora database from a bastion host in a public subnet as shown in the image.

A security review has flagged this architecture as vulnerable, and a Security Engineer has been asked to make this design more secure. The company has a short deadline and a second VPN connection to the Aurora account is not possible.

How can a Security Engineer securely set up the bastion host?

A. Move the bastion host to the VPC and VPN connectivity. Create a VPC peering relationship between the bastion host VPC and Aurora VPC.

B. Create a SSH port forwarding tunnel on the Developer's workstation to the bastion host to ensure that only authorized SSH clients can access the bastion host.

C. Move the bastion host to the VPC with VPN connectivity. Create a cross-account trust relationship between the bastion VPC and Aurora VPC, and update the Aurora security group for the relationship.

D. Create an AWS Direct Connect connection between the corporate network and the Aurora account, and adjust the Aurora security group for this connection.

Answer:

B. Create an SSH port forwarding tunnel on the Developer's workstation to the bastion host to ensure that only authorized SSH clients can access the bastion host.

Explanation:

To gain a better understanding of why the option selected in the answer to the question let first explain some terms.

AWS:

According to techtarget,

AWS (Amazon Web Services) is a comprehensive, evolving cloud computing platform provided by Amazon that includes a mixture of (1) infrastructure as a service (IaaS),(2) platform as a service (PaaS) and (3)packaged software as a service (SaaS) offerings.

An AWS account is a container for your AWS resources

A bastion host is a server whose purpose is to provide access to a private network from an external network, such as the Internet. Because of its exposure to potential attacks, a bastion host must minimize the chances of penetration to the private network.

SSH port forwarding, or TCP/IP connection tunneling, is a process whereby a TCP/IP connection that would otherwise be insecure is tunneled through a secure SSH(Secure Shell (SSH) is a cryptographic network protocol for operating network services securely over an unsecured network.) link, thus protecting the tunneled connection from network attacks.

So the Bastion protects the private network while the SSH prevent unauthorized access to the bastion

You might be interested in
If the relative density of a liquid is 0.34 what is the density of the liquid​
Elina [12.6K]

Answer:

<h2>3338.98 kg/m³</h2>

Explanation:

The formula for calculating the relative density of a substance is expressed as

Relative density of a liquid = Density of the liquid /density of water

Given relative density of a liquid = 0.34

Density of water 997kg/m³

Substituting into the formula we have;

Density of the liquid = Relative density of a liquid * density of water

Density of the liquid = 0.34 * 997

Density of the liquid = 3338.98 kg/m³

7 0
3 years ago
Is Heredity nature or nurture?
Luden [163]
The answer is nature
8 0
3 years ago
Read 2 more answers
This famous scientist conducted experiments that led to the development of the Plum Pudding atomic model.
s344n2d4d5 [400]
J.J. Thomson discovered the electron, leading to the Plum Pudding model
5 0
3 years ago
Read 2 more answers
Can classical physics be used to accurately describe a satellite moving at a speed of 7500 m/s? explain why or why not.
gogolik [260]

The classical physics works on the Newton's laws of motion. It is applicable on heavenly bodies which are governed by the gravitational force. On the other hand, Quantum Physics is applicable for very low mass and sized bodies like electron, protons etc. The classical physics would accurately describe the motion of satellite moving with speed 7500 m/s using the following formula:

r=\frac {GM}{v^{2}}

where G is the gravitational constant, M is the mass of the planet and v is the orbital speed. Then radius of the orbit can be described by this formula.

3 0
3 years ago
Why does magnet 5 float above magnet 4
4vir4ik [10]
Because the same sides(N and N, or S and S) are facing each other in magnet 4 and 5. Also in magnet 2 and 3.
8 0
3 years ago
Other questions:
  • A 15-kg ball is tossed up into the air. The ball is 2 meters off the ground traveling 4 m/s. What is the potential energy? A. 29
    13·1 answer
  • What two organelles should be labeled that WOULD NOT be found in an animal cell?
    7·1 answer
  • If cells are placed in a hypertonic solution containing a solute to which the membrane is impermeable what could happena)cells w
    12·1 answer
  • If an object suspended by a scale shows a weight of 3 N in air, and 2 N when submerged in water, the buoyant force on the submer
    15·1 answer
  • Blood takes about 1.65 s to pass through a 2.00 mm long capillary. If the diameter of the capillary is 5.00 μm and the pressure
    5·1 answer
  • Why do mass numbers have a trailing decimal? use the following words describe for credit isotopes protons neutrons electrons in
    5·1 answer
  • A point charge with a charge q1 = 2.30 μC is held stationary at the origin. A second point charge with a charge q2 = -5.00 μC mo
    15·2 answers
  • Choose the correct statement below about the interaction between magnets, magnetic materials and charges.
    10·1 answer
  • Two satellites A and B orbit the Earth in the same plane. Their masses are 5 m and 7 m, respectively, and their radii 4 r and 7
    5·1 answer
  • Which of the following is not an example of work?
    7·1 answer
Add answer
Login
Not registered? Fast signup
Signup
Login Signup
Ask question!