exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 236 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 236
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A company website runs on Amazon EC2 instances behind an Application Load Balancer (ALB). The instances run in an Auto Scaling group across multiple
Availability Zones. There is an Amazon CloudFront distribution in front of the ALB. Users are reporting performance problems. A security engineer discovers that the website is receiving a high rate of unwanted requests to the CloudFront distribution originating from a series of source IP addresses.
How should the security engineer address this problem?

  • A. Using AWS Shield, configure a deny rule with an IP match condition containing the source IPs of the unwanted requests.
  • B. Using Auto Scaling, configure the maximum an instance value to an increased count that will absorb the unwanted requests.
  • C. Using an Amazon VPC NACL, configure an inbound deny rule for each source IP CIDR address of the unwanted requests.
  • D. Using AWS WAF, configure a web ACL rate-based rule on the CloudFront distribution with a rate limit below that of the unwanted requests.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
cldy
Highly Voted 3 years, 7 months ago
D. Correct
upvoted 12 times
...
sanjaym
Highly Voted 3 years, 6 months ago
Answer: D
upvoted 5 times
ramozo
3 years, 6 months ago
D. https://docs.aws.amazon.com/waf/latest/developerguide/manage-protection.html For protection against attacks on Amazon CloudFront and Application Load Balancer resources, you can add AWS WAF web ACLs and rate-based rules. For information about how AWS WAF works
upvoted 2 times
...
...
pal40sg
Most Recent 1 year, 11 months ago
Selected Answer: D
D: Using AWS WAF, configure a web ACL rate-based rule on the CloudFront distribution with a rate limit below that of the unwanted requests. AWS WAF (Web Application Firewall) is a service that helps protect web applications from common web exploits and provides fine-grained control over incoming traffic. It allows you to define rules to filter and monitor web requests based on various conditions.
upvoted 1 times
...
ITGURU51
2 years ago
The security engineer can address this problem by configuring a web ACL rate based rule on the CloudFront distribution. The key here is the fact that CloudFront and AWS WAF are tightly integrated. D
upvoted 1 times
...
sapien45
2 years, 8 months ago
Selected Answer: D
WAF directly applicale on cloudfront Use Amazon S3 default encryption to be sure that objects uploaded without encryption headers (such as x-amz-server-side-encryption and x-amz-server-side-encryption-aws-kms-key-id) are encrypted by AWS KMS before they are stored in your S3 bucket. Then, use the bucket policy to be sure that objects with another encryption setting (AES-256) can't be uploaded, and that objects uploaded with AWS KMS encryption contain a key ID from your AWS account.
upvoted 2 times
...
kiev
3 years, 6 months ago
Configure WAF on Cloudfront and therefore D
upvoted 2 times
...
skipbaylessfor3
3 years, 6 months ago
Probably D A: You can't really configure Shield B: You don't really want to do this, this is unwanted traffic, not scaling for a desirable event C: I think this would block for everything in the subnet which you might not want. Plus you'd have to specify each IP individually
upvoted 4 times
...
continent34
3 years, 7 months ago
D is correct. Shield is a managed service where you can't configure anything.
upvoted 4 times
...
Ayusef
3 years, 7 months ago
Its between and A.. and D.. But this could be the beginning of a DDOS attack because they mentioned unwanted traffic.
upvoted 3 times
f4bi4n
3 years, 1 month ago
but A is not possible, so D
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago