exam questions

Exam AWS Certified Solutions Architect - Professional SAP-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional SAP-C02 exam

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 248 discussion

An education company is running a web application used by college students around the world. The application runs in an Amazon Elastic Container Service (Amazon ECS) cluster in an Auto Scaling group behind an Application Load Balancer (ALB). A system administrator detects a weekly spike in the number of failed login attempts, which overwhelm the application's authentication service. All the failed login attempts originate from about 500 different IP addresses that change each week. A solutions architect must prevent the failed login attempts from overwhelming the authentication service.

Which solution meets these requirements with the MOST operational efficiency?

  • A. Use AWS Firewall Manager to create a security group and security group policy to deny access from the IP addresses.
  • B. Create an AWS WAF web ACL with a rate-based rule, and set the rule action to Block. Connect the web ACL to the ALB.
  • C. Use AWS Firewall Manager to create a security group and security group policy to allow access only to specific CIDR ranges.
  • D. Create an AWS WAF web ACL with an IP set match rule, and set the rule action to Block. Connect the web ACL to the ALB.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
totten
Highly Voted 6 months, 2 weeks ago
Selected Answer: B
Option B provides the most operational efficiency to prevent the weekly spike in failed login attempts. Here's why: AWS WAF (Web Application Firewall) with a rate-based rule allows you to monitor and block traffic based on the rate of requests from different IP addresses. The rate-based rule can help identify and block the excessive login attempts originating from a large number of IP addresses that change weekly. By blocking traffic at the ALB level using AWS WAF, the traffic doesn't reach the application, reducing the load on your authentication service. The rate-based rule can automatically adjust to changing patterns of attack without manual updates, providing an efficient solution. AWS WAF is designed for web application protection and allows you to create flexible rules to mitigate various types of attacks, making it a suitable choice for handling this scenario.
upvoted 7 times
...
career360guru
Most Recent 5 months, 1 week ago
Selected Answer: B
Using WAF with ALB is most operationally efficient. This narrows the choices down to B and D. As IP address keeps changing B is most efficient.
upvoted 3 times
...
joleneinthebackyard
5 months, 4 weeks ago
Selected Answer: B
The application should be used by users "around the world" so policies that IP based are not suitable, as you have to update set of new IPs each week. Option B has valid actions, as WAP webACL has rate-basted rule and Block Action.
upvoted 2 times
...
ggrodskiy
9 months, 1 week ago
Correct B.
upvoted 1 times
...
NikkyDicky
9 months, 3 weeks ago
Selected Answer: B
easyu B
upvoted 1 times
...
Christina666
9 months, 3 weeks ago
Selected Answer: B
B, if login hit at a certain ratio, block this IP
upvoted 1 times
...
SkyZeroZx
10 months ago
Selected Answer: B
B and not D because of "500 different IP addresses that change each week"
upvoted 2 times
...
SmileyCloud
10 months ago
Selected Answer: B
B and not D because of "500 different IP addresses that change each week"
upvoted 3 times
...
easytoo
10 months ago
b-b-b-b-b-b
upvoted 1 times
...
PhuocT
10 months, 1 week ago
yep, it's B
upvoted 1 times
...
elanelans
10 months, 1 week ago
Selected Answer: B
B Is Correct. Since IP address keeps changing, WAF can't block on IP/CIDR.
upvoted 2 times
...
bhanus
10 months, 1 week ago
Selected Answer: B
B is the answer
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago