1answer.
Ask question
Login Signup
Ask question
All categories
  • English
  • Mathematics
  • Social Studies
  • Business
  • History
  • Health
  • Geography
  • Biology
  • Physics
  • Chemistry
  • Computers and Technology
  • Arts
  • World Languages
  • Spanish
  • French
  • German
  • Advanced Placement (AP)
  • SAT
  • Medicine
  • Law
  • Engineering
taurus [48]
3 years ago
12

A security review has flagged this architecture as vulnerable, and a Security Engineer has been asked to make this design more s

ecure. The company has a short deadline and a second VPN connection to the Aurora account is not possible.
How can a Security Engineer securely set up the bastion host?
A. Move the bastion host to the VPC and VPN connectivity. Create a VPC peering relationship between the bastion host VPC and Aurora VPC.
B. Create a SSH port forwarding tunnel on the Developer's workstation to the bastion host to ensure that only authorized SSH clients can access the bastion host.
C. Move the bastion host to the VPC with VPN connectivity. Create a cross-account trust relationship between the bastion VPC and Aurora VPC, and update the Aurora security group for the relationship.
D. Create an AWS Direct Connect connection between the corporate network and the Aurora account, and adjust the Aurora security group for this connection.

Physics
1 answer:
dybincka [34]3 years ago
6 0

Answer:

Complete Question:

A company has two AWS accounts, each containing one VPC. The first VPC has a VPN connection with its corporate network. The second VPC, without a VPN, hosts an Amazon Aurora database cluster in private subnets. Developers manage the Aurora database from a bastion host in a public subnet as shown in the image.

A security review has flagged this architecture as vulnerable, and a Security Engineer has been asked to make this design more secure. The company has a short deadline and a second VPN connection to the Aurora account is not possible.

How can a Security Engineer securely set up the bastion host?

A. Move the bastion host to the VPC and VPN connectivity. Create a VPC peering relationship between the bastion host VPC and Aurora VPC.

B. Create a SSH port forwarding tunnel on the Developer's workstation to the bastion host to ensure that only authorized SSH clients can access the bastion host.

C. Move the bastion host to the VPC with VPN connectivity. Create a cross-account trust relationship between the bastion VPC and Aurora VPC, and update the Aurora security group for the relationship.

D. Create an AWS Direct Connect connection between the corporate network and the Aurora account, and adjust the Aurora security group for this connection.

Answer:

B. Create an SSH port forwarding tunnel on the Developer's workstation to the bastion host to ensure that only authorized SSH clients can access the bastion host.

Explanation:

To gain a better understanding of why the option selected in the answer to the question let first explain some terms.

AWS:

According to techtarget,

AWS (Amazon Web Services) is a comprehensive, evolving cloud computing platform provided by Amazon that includes a mixture of (1) infrastructure as a service (IaaS),(2) platform as a service (PaaS) and (3)packaged software as a service (SaaS) offerings.

An AWS account is a container for your AWS resources

A bastion host is a server whose purpose is to provide access to a private network from an external network, such as the Internet. Because of its exposure to potential attacks, a bastion host must minimize the chances of penetration to the private network.

SSH port forwarding, or TCP/IP connection tunneling, is a process whereby a TCP/IP connection that would otherwise be insecure is tunneled through a secure SSH(Secure Shell (SSH) is a cryptographic network protocol for operating network services securely over an unsecured network.) link, thus protecting the tunneled connection from network attacks.

So the Bastion protects the private network while the SSH prevent unauthorized access to the bastion

You might be interested in
Scientist who first proposed the theory that the continents drifted is __________
Aloiza [94]

Answer:

Alfred Wegener

Explanation:

Alfred Wegener is a german meteorologist who proposed the theory that the continents drifted, and he presented it to the German Geological Society on January 1912.

4 0
3 years ago
If we warm a volume of air, it expands. Does it then follow that if we expand a volume of air, it warms? Explain.
Ivahew [28]

Answer:

nope don't think so

Explanation:

the heat causes the molecules to move faster therefore expanding in watever it the air is in

3 0
3 years ago
Read 2 more answers
A 60 N force is applied over a distance of 15 m. How much work was done?
GuDViN [60]

Answer:

900J

Explanation:

w =f×s

60×15

=900J

thus the k.e of the body is 900j

3 0
2 years ago
Which geologic feature most likely be represented by contour lines drawn far apart from one another?
andrey2020 [161]

Answer;

A plain

Explanation;

A contour line connects points of the same elevation. Contour lines are usually curves. Closed contours represent hills.

Contour lines can not cross since they represent different elevations. A contour interval is the difference in elevation between one contour and an adjacent contour.

5 0
3 years ago
John is hiking and notices a small stream of water flowing down the side of the mountain. What part of the water cycle is John o
Alexus [3.1K]

Answer: Runofff

Explanation: because it said that it is going down the side of the mountain

3 0
2 years ago
Other questions:
  • A 40% pressure drop across an oil filter screen indicates that?
    9·1 answer
  • The temperature of 4.29 mol of an ideal diatomic gas is increased by 27.1 ˚C without the pressure of the gas changing. The molec
    5·1 answer
  • During Cardiovascular Excercise, what do the heart and lungs do?
    10·1 answer
  • 4.) An apartment building is on fire and a guy is trapped on the fire escape ladder. There is a
    5·1 answer
  • Choose the statement about nuclear fusion that is always correct? A) Very little energy is released in fusion processes. B) Due
    7·2 answers
  • A car traveling at 22 m/s comes to an abrupt halt in 0.1 second when it hits a tree. What is the deceleration in meters per seco
    12·1 answer
  • Light is incident on an air-water interface at an angle of 30 degree to the normal. What angle does the refracted ray make with
    11·1 answer
  • Tyler wants to learn about the types of insects in the soil near his house. Which would be a benefit of carrying out a descripti
    12·1 answer
  • In order for generators to work, this type of
    15·2 answers
  • What part of the atom takes up most of the atoms space?
    10·2 answers
Add answer
Login
Not registered? Fast signup
Signup
Login Signup
Ask question!