Answers
Here are the answers to this chapter’s questions:
- The principle of least privilege asserts that a system should be granted the minimum levels of access necessary to perform its tasks. In the context of route tables in a VPC, this principle implies that if a subnet does not require certain connectivity (for example, internet communication or access to external networks), it should not possess a route to an IGW, NAT gateway, or an external network.
- Using separate VPCs for different environments provides an additional layer of isolation and reduces the risk of potential cross-contamination between environments. It also allows for more granular control over permissions and security controls for each environment based on their specific needs.
- A bastion host acts as a proxy to control access to other EC2 instances, reducing the attack surface by only exposing the bastion host to the internet. However, the security of the bastion host depends largely on your...