Chapter 3
- 4
An internet gateway is not used with a private IP, so this answer is incorrect.
Security groups have all outbound ports open by default, so there is no need to open port 80
specifically.
A private subnet can connect to the internet with the correct configuration.
A correctly configured route table is required for any internet connectivity, so answer 4 is correct.
- 3
A security group does not allow connections to other AWS services such as S3 and RDS by default, so this is incorrect.
Security groups block all inbound traffic by default, so this answer is incorrect.
Security groups do allow all outbound traffic by default, so 3 is the correct answer.
A route table is required for an internet gateway to be used, so this is incorrect.
- 1 and 4
Each subnet can only be deployed in a single AZ, so 1 is a correct answer.
The smallest CIDR block you can allow is /28
, so this is incorrect.
Private subnets connect to...