AWS Certified Advanced Networking – Specialty ANS-C00 – Question296

You are managing a VPC with 4 AZs. There is a load balancer managing the public accessibility to your servers. You have a secondary ENI with a private IPv4 address on an instance that is serving public web traffic. Your server communicates over private addresses to a database in another subnet. Security is a major concern for your company and whitelisting is in effect.
You have to bring the web server down for maintenance, what two things should you do? (Choose two.)

A.
Reboot the instance.
B. Move the ENI from one server to the other.
C. Associate the new ENI with the database security group.
D. Configure a secondary ENI on the standby instance.

Correct Answer: CD

Explanation:

Explanation:
You must configure a secondary ENI on the standby instance with an IP address that can access the data subnet. This may require modification of the security group for the database.