1answer.
Ask question
Login Signup
Ask question
All categories
  • English
  • Mathematics
  • Social Studies
  • Business
  • History
  • Health
  • Geography
  • Biology
  • Physics
  • Chemistry
  • Computers and Technology
  • Arts
  • World Languages
  • Spanish
  • French
  • German
  • Advanced Placement (AP)
  • SAT
  • Medicine
  • Law
  • Engineering
taurus [48]
3 years ago
12

A security review has flagged this architecture as vulnerable, and a Security Engineer has been asked to make this design more s

ecure. The company has a short deadline and a second VPN connection to the Aurora account is not possible.
How can a Security Engineer securely set up the bastion host?
A. Move the bastion host to the VPC and VPN connectivity. Create a VPC peering relationship between the bastion host VPC and Aurora VPC.
B. Create a SSH port forwarding tunnel on the Developer's workstation to the bastion host to ensure that only authorized SSH clients can access the bastion host.
C. Move the bastion host to the VPC with VPN connectivity. Create a cross-account trust relationship between the bastion VPC and Aurora VPC, and update the Aurora security group for the relationship.
D. Create an AWS Direct Connect connection between the corporate network and the Aurora account, and adjust the Aurora security group for this connection.

Physics
1 answer:
dybincka [34]3 years ago
6 0

Answer:

Complete Question:

A company has two AWS accounts, each containing one VPC. The first VPC has a VPN connection with its corporate network. The second VPC, without a VPN, hosts an Amazon Aurora database cluster in private subnets. Developers manage the Aurora database from a bastion host in a public subnet as shown in the image.

A security review has flagged this architecture as vulnerable, and a Security Engineer has been asked to make this design more secure. The company has a short deadline and a second VPN connection to the Aurora account is not possible.

How can a Security Engineer securely set up the bastion host?

A. Move the bastion host to the VPC and VPN connectivity. Create a VPC peering relationship between the bastion host VPC and Aurora VPC.

B. Create a SSH port forwarding tunnel on the Developer's workstation to the bastion host to ensure that only authorized SSH clients can access the bastion host.

C. Move the bastion host to the VPC with VPN connectivity. Create a cross-account trust relationship between the bastion VPC and Aurora VPC, and update the Aurora security group for the relationship.

D. Create an AWS Direct Connect connection between the corporate network and the Aurora account, and adjust the Aurora security group for this connection.

Answer:

B. Create an SSH port forwarding tunnel on the Developer's workstation to the bastion host to ensure that only authorized SSH clients can access the bastion host.

Explanation:

To gain a better understanding of why the option selected in the answer to the question let first explain some terms.

AWS:

According to techtarget,

AWS (Amazon Web Services) is a comprehensive, evolving cloud computing platform provided by Amazon that includes a mixture of (1) infrastructure as a service (IaaS),(2) platform as a service (PaaS) and (3)packaged software as a service (SaaS) offerings.

An AWS account is a container for your AWS resources

A bastion host is a server whose purpose is to provide access to a private network from an external network, such as the Internet. Because of its exposure to potential attacks, a bastion host must minimize the chances of penetration to the private network.

SSH port forwarding, or TCP/IP connection tunneling, is a process whereby a TCP/IP connection that would otherwise be insecure is tunneled through a secure SSH(Secure Shell (SSH) is a cryptographic network protocol for operating network services securely over an unsecured network.) link, thus protecting the tunneled connection from network attacks.

So the Bastion protects the private network while the SSH prevent unauthorized access to the bastion

You might be interested in
You are riding in a vehicle with a coffee cup on the dashboard while traveling 30 km/h. The vehicle makes a sudden stop to avoid
wariber [46]

Answer:

It would move forward.

Explanation:

3 0
3 years ago
You are trying to find out how high you have to pitch a water balloon in order for it to burst when it hits the ground. You disc
FrozenT [24]

Answer:

The balloon hit the ground with velocity -15.34 m/s

Explanation:

<em>Lets explain how to solve the problem</em>

You found that the best height to pitch a water balloon in order for it to

burst when it hits the ground is 12 meters.

We consider that the 12 meters is the maximum height, so the velocity

at this height is zero.

To find the velocity when the balloon hits the ground lets use the rule

<em>v² = u² + 2gh</em>, where v is the final velocity, u is the initial velocity, g is

the acceleration of gravity and h is the height.

u = 0 , h = 12 m , g = 9.8 m/s²

<em>Substitute these values in the equation above</em>

v² = 0 + 2(9.8)(12)

v² = 235.2

<em>Take square root for both sides</em>

v = ± \sqrt{235.2}

The velocity is downward, then it's a negative value

Then v = -15.34 m/s

<em>The balloon hit the ground with velocity -15.34 m/s</em>

6 0
3 years ago
The partial negative charge in a molecule of water occurs because
just olya [345]

the electrons shared between the oxygen and hydrogen atoms spend more time around the oxygen atom nucleus than around the hydrogen atom nucleus

4 0
3 years ago
What kind of energy is stored when you squeeze a mattress
KengaRu [80]

Answer:

elastic energy

Explanation:

hope it helps you

7 0
2 years ago
Read 2 more answers
6) The best way to reduce force in a car wreck when impulse stays the same is to
UkoKoshka [18]

Answer:

c. increase momentum

Explanation:

When cars bounce off each other, or rebound, there is a larger change in momentum and therefore a larger impulse. A larger impulse means that a greater force is experienced by the occupants of the cars. When cars crumple together, there is a smaller change in momentum and therefore a smaller impulse.

3 0
2 years ago
Other questions:
  • A particular field is 111 yards long. Express this length in meters.
    9·2 answers
  • Finish the sentence below with the word that makes the sentence true.
    12·1 answer
  • An air-standard Diesel cycle has a compression ratio of 16 and a cutoff ratio of 2. At the beginning of the compression process,
    13·1 answer
  • Which statement is True ?
    5·2 answers
  • In Speed Study Number 1, we looked at two cars traveling the same distance at different speeds on city streets. Car "A" traveled
    10·1 answer
  • 5.
    15·2 answers
  • If an object has a fast velocity, the dots on a ticker tape diagram will be _____.
    8·2 answers
  • The diagram below shows two bowling balls, A and B, each having a mass of 7.0 kg, placed 2.00 m apart between their centers.
    9·1 answer
  • A 5 kg ball is suspended on one cable. Calculate the tension in the cable
    6·1 answer
  • Which term does this explain?
    14·1 answer
Add answer
Login
Not registered? Fast signup
Signup
Login Signup
Ask question!