exam questions

Exam AWS Certified Solutions Architect - Professional All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional exam

Exam AWS Certified Solutions Architect - Professional topic 1 question 60 discussion

You are designing a social media site and are considering how to mitigate distributed denial-of-service (DDoS) attacks.
Which of the below are viable mitigation techniques? (Choose three.)

  • A. Add multiple elastic network interfaces (ENIs) to each EC2 instance to increase the network bandwidth.
  • B. Use dedicated instances to ensure that each instance has the maximum performance possible.
  • C. Use an Amazon CloudFront distribution for both static and dynamic content.
  • D. Use an Elastic Load Balancer with auto scaling groups at the web, app and Amazon Relational Database Service (RDS) tiers
  • E. Add alert Amazon CloudWatch to look for high Network in and CPU utilization.
  • F. Create processes and capabilities to quickly add and remove rules to the instance OS firewall.
Show Suggested Answer Hide Answer
Suggested Answer: CDE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
iliri_i
Highly Voted 3 years, 6 months ago
This is an old question. WAF is not an option. From what is here I choose CEF. D is not right because you cant put an ELB in front of RDS. Also the OS firewall should not be modified on EC2 since that is what Security Groups are for. So, in general I would discard this question as valid but if I had to choose 3 I'd go with CEF
upvoted 10 times
ravisar
3 years, 2 months ago
Yes, I agree. CEF may correct. RDS won't support ELB. We can use L4 or L7 LB in front of RDS instances for horizontal load balancing such as HAProxy or layer 7 SQL-aware load balancer. https://aws.amazon.com/blogs/database/scaling-your-amazon-rds-instance-vertically-and-horizontally/
upvoted 1 times
...
atlasga
2 years, 8 months ago
The only reason I can think of that they list the OS firewall in F is they might mean rules that blacklist malicious IP blocks, which cannot be done with security groups. Then again you shouldn't be letting that traffic even reach your EC2 instances and should instead by relying on other measures to block that traffic.
upvoted 1 times
...
...
amministrazione
Most Recent 8 months, 3 weeks ago
C. Use an Amazon CloudFront distribution for both static and dynamic content. D. Use an Elastic Load Balancer with auto scaling groups at the web, app and Amazon Relational Database Service (RDS) tiers E. Add alert Amazon CloudWatch to look for high Network in and CPU utilization.
upvoted 1 times
...
SkyZeroZx
1 year, 10 months ago
Selected Answer: CEF
Yes, I agree. CEF may correct. RDS won't support ELB.
upvoted 1 times
...
TigerInTheCloud
2 years, 4 months ago
Selected Answer: CDE
A, B Surely C, E + D is good. but ELB is not for RDS, there are other ways to scale RDS F, Sounds good, but what do you try to block or allow? CDE is my choice
upvoted 1 times
...
icanfly
2 years, 7 months ago
Selected Answer: CEF
My answer is CEF
upvoted 1 times
...
hilft
2 years, 9 months ago
DEF seems the option without WAF and shield. ABC are meant for performace
upvoted 1 times
...
cldy
3 years, 4 months ago
C. Use an Amazon CloudFront distribution for both static and dynamic content. D. Use an Elastic Load Balancer with auto scaling groups at the web, app and Amazon Relational Database Service (RDS) tiers E. Add alert Amazon CloudWatch to look for high Network in and CPU utilization.
upvoted 3 times
...
[Removed]
3 years, 6 months ago
Why not use AWS Shield or AWS WAF rules? https://aws.amazon.com/shield/?whats-new-cards.sort-by=item.additionalFields.postDateTime&whats-new-cards.sort-order=desc https://aws.amazon.com/waf/faqs/ Can I use Rate-based rule to mitigate Web layer DDoS attacks? Yes. This new rules type is designed to protect you from use cases such web-layer DDoS attacks, brute force login attempts and bad bots.
upvoted 1 times
bobsmith2000
2 years, 11 months ago
AWS Shield is applied to ELB and CloudFront by default.
upvoted 1 times
...
...
pradhyumna
3 years, 6 months ago
C and E are clear choices. May be F is the 3rd one which can help to mitigate though it sounds a manual step. A and B does not help to mitigate while they improve only performance. D does not mitigate anything.
upvoted 2 times
pradhyumna
3 years, 6 months ago
thinking again, D may be right. with ELB you can start light, so your attack surface for DDOS is also less. C, D and E is the answer.
upvoted 2 times
...
...
01037
3 years, 7 months ago
I think F is also an option here. But after all I don't think it's a good question.
upvoted 2 times
...
ppshein
3 years, 7 months ago
C.D.E for me.
upvoted 2 times
...
cldy
3 years, 7 months ago
C.D.E. Correct choices. A, B & F cannot mitigate DDoS.
upvoted 3 times
...
nitinz
3 years, 7 months ago
E is not going to mitigate anything. ACD is correct.
upvoted 1 times
...
ExtHo
3 years, 7 months ago
CDE Are perfect choice
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago