You have just come from your Chief Information Security Officer's (CISO) office with the instructions to provide an audit report of all AWS network rules used by the organization's Amazon EC2 instances. You have discovered that a single Describe-Security-Groups API call will return all of an account's security groups and rules within a region. You create the following pseudo-code to create the required report: - Parse "aws ec2 describe-security-groups" output - For each security group - Create report of ingress and egress rules Which two additional pieces of logic should you include to meet the CISO's requirements? (Choose two.)
A) Parse security groups in each region.
B) Parse security groups in each Availability Zone and region.
C) Evaluate VPC network access control lists.
D) Evaluate AWS CloudTrail logs.
E) Evaluate Elastic Load Balancing access control lists.
F) Parse CloudFront access control lists.
Correct Answer:
Verified
Q299: You have an application consisting of a
Q300: Your organization has decided to implement a
Q301: You run operations for a company that
Q302: You have an ASP.NET web application running
Q303: A web application is being actively developed
Q305: Which deployment method, when using AWS Auto
Q306: Your social media marketing application has a
Q307: For AWS Auto Scaling, what is the
Q308: When thinking of AWS Elastic Beanstalk's model,
Q309: You are hired as the new head
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents