exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 681 discussion

Exam question from Amazon's AWS-SysOps
Question #: 681
Topic #: 1
[All AWS-SysOps Questions]

A SysOps Administrator is deploying a legacy web application on AWS. The application has four Amazon EC2 instances behind a Classic Load Balancer and stores data in an Amazon RDS instance. The legacy application has known vulnerabilities to SQL injection attacks, but the application code is no longer available to update.
What cost-effective configuration change should the Administrator make to mitigate the risk of SQL injection attacks?

  • A. Configure Amazon GuardDuty to monitor the application for SQL injection threats.
  • B. Configure AWS WAF with a Classic Load Balancer for protection against SQL injection attacks.
  • C. Replace the Classic Load Balancer with an Application Load Balancer and configure AWS WAF on the Application Load Balancer.
  • D. Configure an Amazon CloudFront distribution with the Classic Load Balancer as the origin and subscribe to AWS Shield Standard.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
Reference:
http://jayendrapatil.com/page/15/?cat=-1

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dkp
Highly Voted 1 year, 1 month ago
ans should be C. You cannot attach a WAF web ACL directly to a Classic Load Balancer as this is not supported. I would recommend migrating to the Application Load Balancer and attaching WAF to the Application Load Balancer. Alternatively you could create a CloudFront distribution that uses the Classic Load Balancer as the origin and then attach WAF to CloudFront https://forums.aws.amazon.com/thread.jspa?messageID=900985
upvoted 24 times
...
saumenP
Highly Voted 1 year, 1 month ago
C is correct, WAF works with ALB
upvoted 9 times
...
asfsdfsdf
Most Recent 8 months, 3 weeks ago
Selected Answer: C
C - CLB cant work with WAF
upvoted 1 times
...
RicardoD
1 year ago
C is answer. WAF can deal with SQL injections and can only be attached to ALB
upvoted 1 times
...
CountryGent
1 year ago
Answer is C: https://forums.aws.amazon.com/thread.jspa?messageID=900985
upvoted 1 times
...
abhishek_m_86
1 year ago
C. Replace the Classic Load Balancer with an Application Load Balancer and configure AWS WAF on the Application Load Balancer.
upvoted 3 times
...
kenkct
1 year ago
this is a tricky question. at first you will think to have WAF for CLB, but there is no WAF for CLB. ALB is cheaper than CLB, thus you should move to ALB and apply WAF. The answer is C
upvoted 5 times
...
jackdryan
1 year ago
I'll go with C
upvoted 2 times
...
Tom_tank
1 year ago
Answer is C One cannot attach a WAF web ACL directly to a Classic Load Balancer as this is not supported. AWS recommends migrating to the Application Load Balancer and attaching WAF to the Application Load Balancer. Source: https://forums.aws.amazon.com/thread.jspa?messageID=899318
upvoted 1 times
...
MFDOOM
1 year ago
C. Replace the Classic Load Balancer with an Application Load Balancer and configure AWS WAF on the Application Load Balancer.
upvoted 2 times
...
gilbertlelancelo
1 year ago
C. Replace the Classic Load Balancer with an Application Load Balancer and configure AWS WAF on the Application Load Balancer.
upvoted 1 times
...
amo82
1 year ago
c is correct, waf does not support classic elb
upvoted 2 times
...
Carupano
1 year ago
C. AWS WAF can be deployed on Amazon CloudFront, the Application Load Balancer (ALB), and Amazon API Gateway. As part of Amazon CloudFront it can be part of your Content Distribution Network (CDN) protecting your resources and content at the Edge locations. As part of the Application Load Balancer it can protect your origin web servers running behind the ALBs. As part of Amazon API Gateway, it can help secure and protect your REST APIs.
upvoted 6 times
...
kkwang
1 year, 1 month ago
I think B is enough.
upvoted 1 times
MegatonN
1 year ago
No WAF for CLB
upvoted 3 times
...
...
coolboylqy
1 year, 1 month ago
C https://aws.amazon.com/waf/faq/
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago