exam questions

Exam ANS-C00 All Questions

View all questions & answers for the ANS-C00 exam

Exam ANS-C00 topic 1 question 45 discussion

Exam question from Amazon's ANS-C00
Question #: 45
Topic #: 1
[All ANS-C00 Questions]

The Web Application Development team is worried about malicious activity from 200 random IP addresses. Which action will ensure security and scalability from this type of threat?

  • A. Use inbound security group rules to block the IP addresses.
  • B. Use inbound network ACL rules to block the IP addresses.
  • C. Use AWS WAF to block the IP addresses.
  • D. Write iptables rules on the instance to block the IP addresses.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
clark
Highly Voted 3 years, 2 months ago
"C" is the correct answer
upvoted 18 times
...
PavanKushwah123
Most Recent 1 year, 11 months ago
Correct AnswerB
upvoted 1 times
...
MohamedSherif1
2 years, 7 months ago
C is right
upvoted 1 times
...
kopper2019
2 years, 9 months ago
random IPs, WAF then
upvoted 1 times
...
AzureDP900
2 years, 10 months ago
C is right
upvoted 1 times
...
ceros399
2 years, 11 months ago
Selected Answer: C
C; is a feasible answer, he Ips are random so you can't use NACLs nor SGs.
upvoted 2 times
...
NSF2
3 years, 1 month ago
The answer is C NACL cant be cant be an option here due to the fact that its current quota is 20 rules per NACL including implicit deny rule. However you can have 200 NACLs per VPC.
upvoted 2 times
...
Scunningham99
3 years, 1 month ago
b is not an answer as there is a limit on the number of rules per ACL and we don't know if these ip's are even in the same range. C is the right answer 20/40 rules peR ACL https://www.totalcloud.io/blog/5-not-to-ignore-best-practices-for-aws-nacls-network-access-control-lists#:~:text=%E2%80%93%20There%20is%20a%20default%20limit,ACLs%20per%20VPC%20is%20200.
upvoted 1 times
...
andyo
3 years, 1 month ago
Ans is C "Random" IPs so you cannot scalably put rules in NACLs, also not best practice for AWS to have that large amount of NACLs. "AWS WAF, which functions like a typical web application firewall, but with the added reliability and scalability that comes with being an AWS-managed service."
upvoted 2 times
...
BillyC
3 years, 1 month ago
C its correct!
upvoted 1 times
...
Ronanh
3 years, 1 month ago
It's C all day long https://aws.amazon.com/blogs/security/how-to-use-aws-waf-to-filter-incoming-traffic-from-embargoed-countries/ and https://docs.aws.amazon.com/waf/latest/developerguide/classic-tutorials-4xx-blocking.html
upvoted 1 times
...
tonna86
3 years, 2 months ago
maximum 20 rules per NACL, I would go for C
upvoted 4 times
...
aviz
3 years, 2 months ago
It even says scalability,if we use nacl we need to just remove the add a default rule to deny everything.WAF would definetely help to scale
upvoted 3 times
...
kab
3 years, 2 months ago
I think it's B.
upvoted 2 times
machlo1
3 years, 2 months ago
C is correct. This is question from another exams and was verified many times
upvoted 3 times
...
HazemYousry
3 years, 2 months ago
Not possible - random IPs
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago