Security Group Flashcards

1
Q

What types of rules can be created?

A

Allow-based

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Default settings for new security group

A

Do not allow any inbound traffic while still allowing all types of outbound traffic to pass through

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does it mean when we say security groups are stateful?

A

If you send a request from your instance, the response traffic for that request is allowed to flow in regardless of inbound rules
Responses to allowed inbound traffic are allowed to flow out regardless of outbound rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which address should you use to allow communication between VPC instances?

A

Private IP, nnot their public IP or Elastic IP address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are security groups associated with?

A

Network interfaces, not the instances themselves
When you change the security group of an instance, you ate changing the security groups associated with its network interface

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Does a newly created network interface have a security group associated with it?

A

Yes, it’s associated with the default security group for the VPC unless you specify a different one

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What ate network interfaces and security groups bound to?

A

The VPC they are launched in
They cannot be used for other VPCs
However, security groups belonging to a different VPC can be referenced as the origin and destination of a security group rule of peered VPCs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

At what layer do network ACLs operate?

A

They operate on the subnet layer which means they protect the whole subnet rather than individual instances

How well did you know this?
1
Not at all
2
3
4
5
Perfectly