A company is undergoing a layer 3 and layer 4 DDoS attack on its web servers running on AWS. Which combination of AWS services and features will provide protection in this scenario? (Choose three.)
Answer A, D, E
A. Amazon Route 53. --> Reduce attack Surface
B. AWS Certificate Manager (ACM) --> Not relevant DDoS
C. Amazon S3 --> Not relevant DDoS
D. AWS Shield --> Service for DDoS
E. Elastic Load Balancer --> Increase Availability
F. Amazon GuardDuty --> Not relevant for DDoS
ADE make sense to defend against DDoS.
Route 53 for flexible routing policies
ELB for load balancing and absorbing large number of request
Shield to protect against L3/L4 DDoS
The only deman question is making is Protection. why i prefered F over E.
Some of the DDoS-related detections GuardDuty can provide include:
+ activity like unusual API activity or port scanning that could indicate an attacker scanning for vulnerabilities to exploit.
+ Instance compromise through detections like outbound denial of service activity or unusually high network traffic volumes that could point to an instance being used to launch a DDoS attack.
+Account compromise through unusual infrastructure launches or API access patterns that an attacker may use to hijack AWS resources for a DDoS botnet.
The combination of AWS services and features that provide protection in this scenario are:
A. Amazon Route 53 - This service provides DNS-based routing and can help to mitigate DDoS attacks by using health checks to identify healthy endpoints and automatically routing traffic away from any endpoints that are under attack.
D. AWS Shield - This service provides protection against DDoS attacks at both the network and application layer. It can detect and mitigate attacks in real time, and is available in two tiers: AWS Shield Standard and AWS Shield Advanced.
E. Elastic Load Balancer - ELB provides protection against DDoS attacks by distributing traffic across multiple instances, and by using a range of techniques to filter out malicious traffic.
Note: ACM, S3, and GuardDuty are not directly related to mitigating layer 3 and layer 4 DDoS attacks.
AWS shield advance provide ddos protection to route53, LB, EC2 etc.
But you don’t have to combine all of them.
So, except shield, for me, others are not valid.
A D and E
The link provide full discerption
https://aws.amazon.com/shield/?whats-new-cards.sort-by=item.additionalFields.postDateTime&whats-new-cards.sort-order=desc
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
dumma
Highly Voted 3 years, 7 months agoRadhaghosh
Highly Voted 3 years, 3 months agoRaphaello
Most Recent 1 year, 2 months agoRaphaello
1 year, 2 months agoyorkicurke
1 year, 4 months agoMaya77
2 years, 2 months agosakibmas
2 years, 4 months agotomass222
2 years, 7 months agotomass222
2 years, 7 months agosapien45
2 years, 10 months agoTigerInTheCloud
3 years, 1 month agolotfi50
3 years, 2 months agoNSF2
3 years, 3 months agoIMAHM
3 years, 6 months agokiev
3 years, 6 months agoTollaMS
3 years, 7 months ago