Quiz 6 Question 6 of 20

A new citizen services web tier sits behind an Application Load Balancer. Security wants host-level allow rules for HTTPS from the load balancer only, plus subnet-level explicit denies for known malicious CIDRs. How should SG and NACL responsibilities be split?

Select an answer to reveal the explanation.

Motivation