1answer.
Ask question
Login Signup
Ask question
All categories
  • English
  • Mathematics
  • Social Studies
  • Business
  • History
  • Health
  • Geography
  • Biology
  • Physics
  • Chemistry
  • Computers and Technology
  • Arts
  • World Languages
  • Spanish
  • French
  • German
  • Advanced Placement (AP)
  • SAT
  • Medicine
  • Law
  • Engineering
taurus [48]
3 years ago
12

A security review has flagged this architecture as vulnerable, and a Security Engineer has been asked to make this design more s

ecure. The company has a short deadline and a second VPN connection to the Aurora account is not possible.
How can a Security Engineer securely set up the bastion host?
A. Move the bastion host to the VPC and VPN connectivity. Create a VPC peering relationship between the bastion host VPC and Aurora VPC.
B. Create a SSH port forwarding tunnel on the Developer's workstation to the bastion host to ensure that only authorized SSH clients can access the bastion host.
C. Move the bastion host to the VPC with VPN connectivity. Create a cross-account trust relationship between the bastion VPC and Aurora VPC, and update the Aurora security group for the relationship.
D. Create an AWS Direct Connect connection between the corporate network and the Aurora account, and adjust the Aurora security group for this connection.

Physics
1 answer:
dybincka [34]3 years ago
6 0

Answer:

Complete Question:

A company has two AWS accounts, each containing one VPC. The first VPC has a VPN connection with its corporate network. The second VPC, without a VPN, hosts an Amazon Aurora database cluster in private subnets. Developers manage the Aurora database from a bastion host in a public subnet as shown in the image.

A security review has flagged this architecture as vulnerable, and a Security Engineer has been asked to make this design more secure. The company has a short deadline and a second VPN connection to the Aurora account is not possible.

How can a Security Engineer securely set up the bastion host?

A. Move the bastion host to the VPC and VPN connectivity. Create a VPC peering relationship between the bastion host VPC and Aurora VPC.

B. Create a SSH port forwarding tunnel on the Developer's workstation to the bastion host to ensure that only authorized SSH clients can access the bastion host.

C. Move the bastion host to the VPC with VPN connectivity. Create a cross-account trust relationship between the bastion VPC and Aurora VPC, and update the Aurora security group for the relationship.

D. Create an AWS Direct Connect connection between the corporate network and the Aurora account, and adjust the Aurora security group for this connection.

Answer:

B. Create an SSH port forwarding tunnel on the Developer's workstation to the bastion host to ensure that only authorized SSH clients can access the bastion host.

Explanation:

To gain a better understanding of why the option selected in the answer to the question let first explain some terms.

AWS:

According to techtarget,

AWS (Amazon Web Services) is a comprehensive, evolving cloud computing platform provided by Amazon that includes a mixture of (1) infrastructure as a service (IaaS),(2) platform as a service (PaaS) and (3)packaged software as a service (SaaS) offerings.

An AWS account is a container for your AWS resources

A bastion host is a server whose purpose is to provide access to a private network from an external network, such as the Internet. Because of its exposure to potential attacks, a bastion host must minimize the chances of penetration to the private network.

SSH port forwarding, or TCP/IP connection tunneling, is a process whereby a TCP/IP connection that would otherwise be insecure is tunneled through a secure SSH(Secure Shell (SSH) is a cryptographic network protocol for operating network services securely over an unsecured network.) link, thus protecting the tunneled connection from network attacks.

So the Bastion protects the private network while the SSH prevent unauthorized access to the bastion

You might be interested in
suppose an electrically charged ruler transfers some of its charge by contact to a tiny plastic sphere. will the ruler and the s
poizon [28]

Answer:

Here ball and rod will repel each other as they are of similar charges

Explanation:

As we know that the two charges attract or repel each other by electrostatic force

This force is given as

F = \frac{kq_1q_2}{r^2}

so we know if two charges are similar in nature then they will repel each other and if the two charges are opposite in nature then they will attract each other

So here when rod touch the ball then it transfer its charge to the ball and due to similar charges in ball and rod they both repel each other

5 0
3 years ago
If something is a good conductor, what type of insulator is it?
nlexa [21]

4. a poor insulator

If rest other things are kept constant or unchanged then a good conductor can be termed as a poor insulator.

8 0
1 year ago
Read 2 more answers
Which formula is used to find fluctuation of the shape of body
Sladkaya [172]

Answer:

varn=n1+1ehvkT–1

Explanation:

This is Einstein's equation.

5 0
3 years ago
Two parakeets sit on a swing with their combined center of mass 10.0 cm below the pivot. At what frequency do they swing?
Oksanka [162]

Answer:

1.58 Hz

Explanation:

The frequency of the simple pendulum is given by

f = 1/T

 = 1/2π√g/l  

In this problem, I = 10.0 cm = 0.1 m  

f = 1/2π√9.8/0.1

=  1.58 Hz

7 0
3 years ago
g In 1920, Stern and Gerlach performed an experiment that first demonstrated Group of answer choices energy quantization. space
anyanavicka [17]

Answer:

B. space quantization.

Explanation:

In 1921, Otto Stern developed the idea behind this experiment, while Walther Gerlach performed the actual experiment in 1922. The Ster-Gerlach experiment provides prove to the fact that the spatial orientation of angular momentum is quantized. To demonstrate the experiment, silver atoms were made to travel through a magnetic field path.

Before they hit the screen(usually a glass slide), they were deflected because of their non-zero magnetic moment. There was an expected result for this experiment, but the actual observation on the glass slide was a continuous distribution of the silver atoms that actually hit the glass. This experiment was useful in proving that in all atomic-scale systems, there was a quantization of angular momentum.

4 0
3 years ago
Other questions:
  • What are the products in the photosynthesis equation?
    14·2 answers
  • The distance traveled by an object can be modeled by the equation d = ut + 0.5at2 where d = distance, u = initial velocity, t =
    11·1 answer
  • When one of the two planes of vibration of a light wave is blocked, the resulting wave is called
    15·2 answers
  • Terrence connects several lightbulbs in a parallel circuit. Electricity flows through the circuit, and all the bulbs light up. 
    9·1 answer
  • un avión aterriza en la superficie de un portaaviones a 50 m/s y se detiene por completo en 120 metros, ¿cuál es la aceleración
    7·1 answer
  • 7. A 600g brick weighs 6N in the air. If the brick displaces 2N of water when it is
    11·1 answer
  • Suppose that scientists observe violent gas eruptions on a planet with an acceleration due to gravity of 3.9 m/s2. The jets thro
    15·1 answer
  • An object moving with a speed of 35 m/a and has a kinetic energy of 1500j, what is the mass of the object
    10·1 answer
  • can you suggest improvement that can be made towards the design of siphon so that the transfer of liquid is much higher.​
    13·1 answer
  • Mass is the amount of matter in an object what describes the amount of space the object takes up?
    10·1 answer
Add answer
Login
Not registered? Fast signup
Signup
Login Signup
Ask question!