The Web Application Development team is worried about malicious activity from 200 random IP addresses. Which action will ensure security and scalability from this type of threat?
A.
Use inbound security group rules to block the IP addresses.
B.
Use inbound network ACL rules to block the IP addresses.
C.
Use AWS WAF to block the IP addresses.
D.
Write iptables rules on the instance to block the IP addresses.
The answer is C
NACL cant be cant be an option here due to the fact that its current quota is 20 rules per NACL including implicit deny rule. However you can have 200 NACLs per VPC.
b is not an answer as there is a limit on the number of rules per ACL and we don't know if these ip's are even in the same range. C is the right answer
20/40 rules peR ACL
https://www.totalcloud.io/blog/5-not-to-ignore-best-practices-for-aws-nacls-network-access-control-lists#:~:text=%E2%80%93%20There%20is%20a%20default%20limit,ACLs%20per%20VPC%20is%20200.
Ans is C
"Random" IPs so you cannot scalably put rules in NACLs, also not best practice for AWS to have that large amount of NACLs.
"AWS WAF, which functions like a typical web application firewall, but with the added reliability and scalability that comes with being an AWS-managed service."
It's C all day long https://aws.amazon.com/blogs/security/how-to-use-aws-waf-to-filter-incoming-traffic-from-embargoed-countries/ and https://docs.aws.amazon.com/waf/latest/developerguide/classic-tutorials-4xx-blocking.html
This section is not available anymore. Please use the main Exam Page.ANS-C00 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
clark
Highly Voted 3 years, 8 months agoPavanKushwah123
Most Recent 2 years, 5 months agoMohamedSherif1
3 years, 1 month agokopper2019
3 years, 3 months agoAzureDP900
3 years, 4 months agoceros399
3 years, 5 months agoNSF2
3 years, 7 months agoScunningham99
3 years, 7 months agoandyo
3 years, 7 months agoBillyC
3 years, 7 months agoRonanh
3 years, 7 months agotonna86
3 years, 8 months agoaviz
3 years, 8 months agokab
3 years, 8 months agomachlo1
3 years, 8 months agoHazemYousry
3 years, 8 months ago