Home › Forums › AWS › AWS Certified Advanced Networking – Specialty › Timed Mode Bonus Set 3 Question: Answer might need an update!
-
Timed Mode Bonus Set 3 Question: Answer might need an update!
JR-TutorialsDojo updated 6 days, 19 hours ago
2 Members
·
2
Posts
-
A company has deployed several applications in a VPC using Auto Scaling groups. Each Amazon EC2 instance hosts a different application and is dynamically assigned an IP address as the Auto Scaling group launches or terminates instances based on traffic demand. The company uses AWS Network Firewall to monitor and filter outgoing traffic for these EC2 instances.
The company needs to ensure that the Network Firewall stateful rule group always has the most up-to-date list of IP addresses for the instances in the Auto Scaling groups, without requiring manual intervention whenever new instances are launched or terminated.
Which solution will ensure the stateful rule group remains up-to-date with the least operational overhead?
Why can’t the answer be Group instance by application name which is managed by the Tags?
https://aws.amazon.com/about-aws/whats-new/2023/02/aws-network-firewall-tag-based-resource-groups/
-
Hello saig1991
Thanks for bringing this to our attention. You’re correct that AWS Network Firewall supports tag‑based resource groups for IP set references.
We will make the necessary updates, which should be reflected on the portal soon.
Regards,
JR @ Tutorials Dojo
Log in to reply.