exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 266 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 266
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A company is undergoing a layer 3 and layer 4 DDoS attack on its web servers running on AWS.
Which combination of AWS services and features will provide protection in this scenario? (Choose three.)

  • A. Amazon Route 53
  • B. AWS Certificate Manager (ACM)
  • C. Amazon S3
  • D. AWS Shield
  • E. Elastic Load Balancer
  • F. Amazon GuardDuty
Show Suggested Answer Hide Answer
Suggested Answer: ADE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dumma
Highly Voted 3 years, 7 months ago
A D and E
upvoted 16 times
...
Radhaghosh
Highly Voted 3 years, 3 months ago
Answer A, D, E A. Amazon Route 53. --> Reduce attack Surface B. AWS Certificate Manager (ACM) --> Not relevant DDoS C. Amazon S3 --> Not relevant DDoS D. AWS Shield --> Service for DDoS E. Elastic Load Balancer --> Increase Availability F. Amazon GuardDuty --> Not relevant for DDoS
upvoted 11 times
...
Raphaello
Most Recent 1 year, 2 months ago
Selected Answer: ADE
Route 53 Shield Elastic Load Balancer ADE
upvoted 1 times
...
Raphaello
1 year, 2 months ago
Selected Answer: ADE
ADE make sense to defend against DDoS. Route 53 for flexible routing policies ELB for load balancing and absorbing large number of request Shield to protect against L3/L4 DDoS
upvoted 1 times
...
yorkicurke
1 year, 4 months ago
Selected Answer: ADF
The only deman question is making is Protection. why i prefered F over E. Some of the DDoS-related detections GuardDuty can provide include: + activity like unusual API activity or port scanning that could indicate an attacker scanning for vulnerabilities to exploit. + Instance compromise through detections like outbound denial of service activity or unusually high network traffic volumes that could point to an instance being used to launch a DDoS attack. +Account compromise through unusual infrastructure launches or API access patterns that an attacker may use to hijack AWS resources for a DDoS botnet.
upvoted 1 times
...
Maya77
2 years, 2 months ago
Selected Answer: ADE
The combination of AWS services and features that provide protection in this scenario are: A. Amazon Route 53 - This service provides DNS-based routing and can help to mitigate DDoS attacks by using health checks to identify healthy endpoints and automatically routing traffic away from any endpoints that are under attack. D. AWS Shield - This service provides protection against DDoS attacks at both the network and application layer. It can detect and mitigate attacks in real time, and is available in two tiers: AWS Shield Standard and AWS Shield Advanced. E. Elastic Load Balancer - ELB provides protection against DDoS attacks by distributing traffic across multiple instances, and by using a range of techniques to filter out malicious traffic. Note: ACM, S3, and GuardDuty are not directly related to mitigating layer 3 and layer 4 DDoS attacks.
upvoted 5 times
...
sakibmas
2 years, 4 months ago
Selected Answer: ADE
C - S3 - does not make any sense
upvoted 2 times
...
tomass222
2 years, 7 months ago
Selected Answer: ADF
Nowadays I will say that option A D and F is also right https://aws.amazon.com/premiumsupport/knowledge-center/waf-mitigate-ddos-attacks/
upvoted 1 times
tomass222
2 years, 7 months ago
sorry, my mistake, I was thinking that F option is WAF not a GD, so only option ADE are right
upvoted 1 times
...
...
sapien45
2 years, 10 months ago
Selected Answer: ADE
Reduce DDoS Risks Using Amazon Route 53 and AWS Shield https://aws.amazon.com/blogs/aws/reduce-ddos-risks-using-amazon-route-53-and-aws-shield/
upvoted 2 times
...
TigerInTheCloud
3 years, 1 month ago
Selected Answer: ADE
if missing any of these 3 answers, I will choose C as the third answer. S3 for static content web hosting with help on route53
upvoted 2 times
...
lotfi50
3 years, 2 months ago
Selected Answer: ADE
A, D and E
upvoted 2 times
...
NSF2
3 years, 3 months ago
AWS shield advance provide ddos protection to route53, LB, EC2 etc. But you don’t have to combine all of them. So, except shield, for me, others are not valid.
upvoted 1 times
...
IMAHM
3 years, 6 months ago
A, D , E
upvoted 1 times
...
kiev
3 years, 6 months ago
ADE all the way
upvoted 4 times
...
TollaMS
3 years, 7 months ago
A D and E The link provide full discerption https://aws.amazon.com/shield/?whats-new-cards.sort-by=item.additionalFields.postDateTime&whats-new-cards.sort-order=desc
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago