exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C02 exam

Exam AWS Certified Solutions Architect - Associate SAA-C02 topic 1 question 77 discussion

A solutions architect is designing a web application that will run on Amazon EC2 instances behind an Application Load Balancer (ALB). The company strictly requires that the application be resilient against malicious internet activity and attacks, and protect against new common vulnerabilities and exposures.
What should the solutions architect recommend?

  • A. Leverage Amazon CloudFront with the ALB endpoint as the origin.
  • B. Deploy an appropriate managed rule for AWS WAF and associate it with the ALB.
  • C. Subscribe to AWS Shield Advanced and ensure common vulnerabilities and exposures are blocked.
  • D. Configure network ACLs and security groups to allow only ports 80 and 443 to access the EC2 instances.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
CloudSharma
Highly Voted 3 years, 7 months ago
i think B
upvoted 47 times
MIU
3 years, 7 months ago
I think this is "C". Because WAF is included in "AWS Shield Advanced". And it is required different types of attacks.
upvoted 4 times
...
Hitesha
3 years, 7 months ago
AWS WAF is included with AWS Shield Advanced at no extra cost. Check the link: https://docs.aws.amazon.com/waf/latest/developerguide/ddos-overview.html Hence answer is C
upvoted 25 times
PhilMultiCloud
3 years, 6 months ago
I think B cause C is too expensive and normally it´s more focus on DDos attacks, regular WAF already protects against the attacks mentioned...
upvoted 3 times
PhilMultiCloud
3 years, 6 months ago
AWS WAF provides Managed Rules which are pre-configured rules to protect applications common threats like application vulnerabilities like OWASP, bots, or Common Vulnerabilities and Exposures (CVE).
upvoted 2 times
PhilMultiCloud
3 years, 6 months ago
answer is B
upvoted 2 times
...
...
naveenagurjara
2 years, 10 months ago
Cost effective not mentioned.
upvoted 1 times
...
...
...
aguy9
3 years, 6 months ago
I think the answer is C because “AWS Shield Advanced includes AWS WAF at no additional cost” https://aws.amazon.com/shield/?whats-new-cards.sort-by=item.additionalFields.postDateTime&whats-new-cards.sort-order=desc
upvoted 3 times
PhilMultiCloud
3 years, 6 months ago
it´s B, C is for DDos AWS WAF provides Managed Rules which are pre-configured rules to protect applications common threats like application vulnerabilities like OWASP, bots, or Common Vulnerabilities and Exposures (CVE).
upvoted 1 times
...
...
SandyIndia
3 years, 6 months ago
B is correct Keyword is Designing a web application behind an (ALB). WAF works at HTTP Layer 7 (ALB) AWS Shield works at Layer 3 & 4 (NLB)
upvoted 21 times
cachac
3 years, 6 months ago
"AWS Shield Advanced includes intelligent DDoS attack detection and mitigation for not only for network layer (layer 3) and transport layer (layer 4) attacks, but also for application layer (layer 7) attacks." https://docs.aws.amazon.com/waf/latest/developerguide/ddos-overview.html
upvoted 12 times
...
naveenagurjara
2 years, 10 months ago
Requires both... so go for AWS SHield advanced and you get WAF free bundled.
upvoted 1 times
...
...
...
robbyqk
Highly Voted 3 years, 7 months ago
it a B good answer. B. Deploy an appropriate managed rule for AWS WAF and associate it with the ALB. WAF have this options for solutions. https://aws.amazon.com/waf/features/ Web traffic filtering AWS WAF lets you create rules to filter web traffic based on conditions that include IP addresses, HTTP headers and body, or custom URIs. This gives you an additional layer of protection from web attacks that attempt to exploit vulnerabilities in custom or third party web applications. In addition, AWS WAF makes it easy to create rules that block common web exploits like SQL injection and cross site scripting. AWS WAF allows you to create a centralized set of rules that you can deploy across multiple websites. This means that in an environment with many websites and web applications you can create a single set of rules that you can reuse across applications rather than recreating that rule on every application you want to protect.
upvoted 13 times
Alouch47
3 years, 7 months ago
The correct answer is C. WAF only doesn't cover the whole requirement : "resilient against malicious internet activity and attacks" = AWS Shield "protect against new common vulnerabilities and exposures" = AWS WAF So answer is WAF+Shield = Shield Advanced : AWS Shield Advanced includes AWS WAF in its priced subscription (Shield Standard doesn't) Answer is C
upvoted 21 times
PhilMultiCloud
3 years, 6 months ago
it´s B, C is for DDos AWS WAF provides Managed Rules which are pre-configured rules to protect applications common threats like application vulnerabilities like OWASP, bots, or Common Vulnerabilities and Exposures (CVE).
upvoted 2 times
...
...
...
Uzbekistan
Most Recent 1 year, 2 months ago
Selected Answer: B
AWS WAF (Web Application Firewall): It helps protect web applications from common web exploits that could affect application availability, compromise security, or consume excessive resources. By deploying AWS WAF with managed rules, you can block known attack patterns and vulnerabilities, including those identified as common vulnerabilities and exposures (CVEs). Application Load Balancer (ALB): Since the web application will run on EC2 instances behind an ALB, associating AWS WAF with the ALB allows you to inspect and filter incoming traffic before it reaches the instances. This provides an additional layer of protection against malicious activity.
upvoted 1 times
...
slackbot
1 year, 10 months ago
Selected Answer: B
ppl continue to play around a single word. if so - why use Shield when the question did not say Shields Advanced?! if a single word for you makes sense to drop WAF, then a single word for me says to drop Shield, because basic shield does not include WAF, and Shields protects against layer4 attacks, which is NOT what the question is asking B
upvoted 1 times
...
BECAUSE
1 year, 11 months ago
Selected Answer: C
C is the answer
upvoted 1 times
...
test_devops_aws
2 years, 2 months ago
Selected Answer: C
" If you’re prone to frequent DDoS attacks, consider purchasing Shield Advanced"
upvoted 1 times
...
jw1806
2 years, 7 months ago
Selected Answer: B
Needs WAF for ALB, not shield
upvoted 1 times
...
cloudfever
2 years, 8 months ago
Selected Answer: B
B is the right answer
upvoted 2 times
...
Fyssy
2 years, 8 months ago
Selected Answer: B
While AWS WAF is a firewall that can protect you from multiple types of attacks and provide various options for whitelisting, AWS Shield is a single-purpose service. AWS Shield is a managed Distributed Denial of Service (DDoS) protection tool for your AWS-based applications
upvoted 2 times
...
archimate
2 years, 9 months ago
This is a dumb question. check this out:https://aliceandbob.company/services/continuous-improvement/managed-perimeter-protection/ my understanding is , if you have more funding, than Shield, if no, go with WAF the mini.
upvoted 1 times
...
cloud_collector
2 years, 9 months ago
Selected Answer: B
AWS WAF is a firewall that can protect you from multiple types of attacks and provide various options for whitelisting, AWS Shield is a single-purpose service. AWS Shield is a managed Distributed Denial of Service (DDoS) protection tool for your AWS-based applications
upvoted 1 times
cloud_collector
2 years, 9 months ago
With Managed Rules for AWS WAF, you can quickly get started and protect your web application or APIs against common threats. You can select from many rule types, such as ones that address issues like the Open Web Application Security Project (OWASP) Top 10 security risks, threats specific to Content Management Systems (CMS), or emerging Common Vulnerabilities and Exposures (CVE). https://aws.amazon.com/waf/
upvoted 1 times
...
...
naveenagurjara
2 years, 10 months ago
Selected Answer: C
AWS Shield Advanced includes WAF for free. So the solution warrants both Shield and WAF measures.
upvoted 1 times
...
examJack
3 years, 1 month ago
Selected Answer: C
AWS Shield Advanced capabilities and options A AWS Shield Advanced subscription includes the following capabilities and options. These supplement the DDoS detection and mitigation capabilities that you already receive with AWS. * AWS WAF integration * Automatic application layer DDoS mitigation * Health-based detection * Protection groups * Enhanced visibility into DDoS events and attacks * Centralized management of Shield Advanced protections by AWS Firewall Manager * AWS Shield Response Team (SRT) * Proactive engagement * Cost protection opportunities https://docs.aws.amazon.com/waf/latest/developerguide/ddos-advanced-summary-capabilities.html
upvoted 1 times
...
zehnminuten
3 years, 1 month ago
Selected Answer: C
C is correct. See comment from Alouch47.
upvoted 1 times
...
SimoneP
3 years, 3 months ago
Selected Answer: C
ANS C my 2 cents : "high premium on the application's resilience to hostile internet activities and assaults" --> Shields Advanced (WAF included)
upvoted 4 times
Didi31
3 years, 1 month ago
Exactly. People are missing the memo.
upvoted 1 times
...
...
FF11
3 years, 4 months ago
Selected Answer: B
B is good.
upvoted 1 times
...
Spacer
3 years, 4 months ago
Should be C. Because the question mentioned ALB that implicit it’s a layer 7 DDoS attack. So shield is a better option here.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago