A company is running its application on AWS. Malicious users exploited a recent promotion event and created many fake accounts.
The application currently uses Amazon CloudFront in front of an Amazon API Gateway API. AWS Lambda functions serve the different API endpoints. The GET registration endpoint is behind the path of /store/registration. The URI for submission of the new account details is at /store/newaccount.
A security engineer needs to design a solution that prevents similar exploitations for future promotion events.
Which combination of steps will meet these requirements? (Choose two.)
mnsait
3 weeks, 2 days ago