Network ACLs and Security Groups Flashcards

1
Q

To how many NACLs can a subnet be associated?

A

One

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Amazon recommends NACL rule #s be created in increments of what?

A

100

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

To how many VPCs can a NACL be associated

A

1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the default rules for a custom NACL?

A

Inbound: Deny All
Outbound: Deny All

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is an ephemeral port?

A

A short lives port for IP communications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

For what purpose do we worry about ephemeral ports?

A

They are needed for outbound communication in reply to a request, so the range of ports must be allowed in the outbound rules.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What outbound port range Allow rule gives you the greatest flexibility for expansion?

A

1024 - 65536

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How are NACL rules evaluated?

A

Numerical order, from lowest to highest. For example, two conflicting rules will be resolved based on which has a lower rule number.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How long must you wait for a NACL rule to take effect?

A

Immediate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What type of traffic does the VPCs default NACL allow?

A

Inbound: Allow All
Outbound: Allow All

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Does a VPC automatically come with a NACL?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

True or False: A NACL is limited to association with one subnet?

A

False: While one subnet may be associated to one NACL. one NACL may be associated with many subnets.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

In the following NACL ruleset, will 80 be allowed, or denied?

100: 80 Deny
200: 80 Allow

A

Denied because the rule number is lower.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

True or False: NACLs are stateful, meaning AWS will remember the source and destination requests?

A

False. NACLs are stateless, so inbound and outbound rules must exist for round-trip traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

To block specific IP addresses, would you use security groups, or a NACL?

A

NACL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly