1answer.
Ask question
Login Signup
Ask question
All categories
  • English
  • Mathematics
  • Social Studies
  • Business
  • History
  • Health
  • Geography
  • Biology
  • Physics
  • Chemistry
  • Computers and Technology
  • Arts
  • World Languages
  • Spanish
  • French
  • German
  • Advanced Placement (AP)
  • SAT
  • Medicine
  • Law
  • Engineering
taurus [48]
3 years ago
12

A security review has flagged this architecture as vulnerable, and a Security Engineer has been asked to make this design more s

ecure. The company has a short deadline and a second VPN connection to the Aurora account is not possible.
How can a Security Engineer securely set up the bastion host?
A. Move the bastion host to the VPC and VPN connectivity. Create a VPC peering relationship between the bastion host VPC and Aurora VPC.
B. Create a SSH port forwarding tunnel on the Developer's workstation to the bastion host to ensure that only authorized SSH clients can access the bastion host.
C. Move the bastion host to the VPC with VPN connectivity. Create a cross-account trust relationship between the bastion VPC and Aurora VPC, and update the Aurora security group for the relationship.
D. Create an AWS Direct Connect connection between the corporate network and the Aurora account, and adjust the Aurora security group for this connection.

Physics
1 answer:
dybincka [34]3 years ago
6 0

Answer:

Complete Question:

A company has two AWS accounts, each containing one VPC. The first VPC has a VPN connection with its corporate network. The second VPC, without a VPN, hosts an Amazon Aurora database cluster in private subnets. Developers manage the Aurora database from a bastion host in a public subnet as shown in the image.

A security review has flagged this architecture as vulnerable, and a Security Engineer has been asked to make this design more secure. The company has a short deadline and a second VPN connection to the Aurora account is not possible.

How can a Security Engineer securely set up the bastion host?

A. Move the bastion host to the VPC and VPN connectivity. Create a VPC peering relationship between the bastion host VPC and Aurora VPC.

B. Create a SSH port forwarding tunnel on the Developer's workstation to the bastion host to ensure that only authorized SSH clients can access the bastion host.

C. Move the bastion host to the VPC with VPN connectivity. Create a cross-account trust relationship between the bastion VPC and Aurora VPC, and update the Aurora security group for the relationship.

D. Create an AWS Direct Connect connection between the corporate network and the Aurora account, and adjust the Aurora security group for this connection.

Answer:

B. Create an SSH port forwarding tunnel on the Developer's workstation to the bastion host to ensure that only authorized SSH clients can access the bastion host.

Explanation:

To gain a better understanding of why the option selected in the answer to the question let first explain some terms.

AWS:

According to techtarget,

AWS (Amazon Web Services) is a comprehensive, evolving cloud computing platform provided by Amazon that includes a mixture of (1) infrastructure as a service (IaaS),(2) platform as a service (PaaS) and (3)packaged software as a service (SaaS) offerings.

An AWS account is a container for your AWS resources

A bastion host is a server whose purpose is to provide access to a private network from an external network, such as the Internet. Because of its exposure to potential attacks, a bastion host must minimize the chances of penetration to the private network.

SSH port forwarding, or TCP/IP connection tunneling, is a process whereby a TCP/IP connection that would otherwise be insecure is tunneled through a secure SSH(Secure Shell (SSH) is a cryptographic network protocol for operating network services securely over an unsecured network.) link, thus protecting the tunneled connection from network attacks.

So the Bastion protects the private network while the SSH prevent unauthorized access to the bastion

You might be interested in
HELP PLZZZZZZ
ValentinkaMS [17]

Hi there!

We know that:

U (Potential energy) = mgh

We are given the potential energy, so we can rearrange to solve for h (height):

U/mg = h

g = 9.81 m/s²

m = 30 g ⇒ 0.03 kg

0.062/(0.03 · 9.81) = 0.211 m

8 0
2 years ago
How Is budding different from fertilization
tiny-mole [99]
<span>Artificial fertilizers are made chemically. They emphasize three main</span>
5 0
2 years ago
(URGENT 75 points)You are given two same party balloons (one filled with helium and the
skad [1K]

\frac{100}{0.214+-0.006} = 454.55 g/cm3

I'm not too sure since the graduated cylinder was missing and I really don't know how to do it then. But give this a shot. Are you sure it wasn't a graduated cylinder, because I have no idea what that means

5 0
3 years ago
A type of energy work that utilizes touch and visualization
nydimaria [60]
It would be the <span>Energy Therapies Reiki that is a common type of work wherein it makes use of touch and visualisation. In addition, this kind of therapy has its primary goal just to lessen stress and furthermore promotes relaxation. The technique is said to be making use of a "life force energy."</span>
7 0
3 years ago
An 8.0 cm object is 40.0 cm from a concave mirror that has a focal length of 10.0 cm. Its image is 16.0 cm in front of the mirro
svet-max [94.6K]
 We can rearrange the mirror equation before plugging our values in. 
1/p = 1/f - 1/q. 
1/p = 1/10cm - 1/40cm
1/p = 4/40cm - 1/40cm = 3/40cm
40cm=3p  <-- cross multiplication
13.33cm = p

Now that we have the value of p, we can plug it into the magnification equation.

M=-16/13.33=1.2
1.2=h'/8cm
9.6=h'

So the height of the image produced by the mirror is 9.6cm.
6 0
2 years ago
Other questions:
  • At what frequency f, in hertz, would you have to move the comb up and down to produce red light, of wavelength 600 nm
    9·1 answer
  • The total amount of energy in a closed system stays the same. t/f
    8·1 answer
  • A glider of mass 0.240 kg is on a frictionless, horizontal track, attached to a horizontal spring of force constant 6.00 N/m. In
    14·1 answer
  • (b) A 0.13−kg baseball thrown at 100 mph has a momentum of 5.9 kg · m/s. If the uncertainty in measuring the mass is 1.0 × 10−7
    6·1 answer
  • Brianna weighs 425 N. She climbs a flight of stairs to a height of 8 m. It takes her 6 seconds.
    6·1 answer
  • 100 POINTS.
    15·1 answer
  • Three of your friends are all sitting g on one end of a seesaw. The combined weight is 275 N. The length from the fulcrum to you
    12·1 answer
  • The work done to lift a 3kg mass to a<br> height of 10 m is
    7·1 answer
  • Can two objects exert a force on each other without touching? example
    5·1 answer
  • Si dos aparatos eléctricos que tienen diferente potencia funcionan durante el mismo tiempo, ¿ cual transformara mayor cantidad d
    10·1 answer
Add answer
Login
Not registered? Fast signup
Signup
Login Signup
Ask question!