exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 48 discussion

A company's public Application Load Balancer (ALB) recently experienced a DDoS attack. To mitigate this issue, the company deployed Amazon CloudFront in front of the ALB so that users would not directly access the Amazon EC2 instances behind the ALB.
The company discovers that some traffic is still coming directly into the ALB and is still being handled by the EC2 instances.
Which combination of steps should the company take to ensure that the EC2 instances will receive traffic only from CloudFront? (Choose two.)

  • A. Configure CloudFront to add a cache key policy to allow a custom HTTP header that CloudFront sends to the ALB.
  • B. Configure CloudFront to add a custom HTTP header to requests that CloudFront sends to the ALB.
  • C. Configure the ALB to forward only requests that contain the custom HTTP header.
  • D. Configure the ALB and CloudFront to use the X-Forwarded-For header to check client IP addresses.
  • E. Configure the ALB and CloudFront to use the same X.509 certificate that is generated by AWS Certificate Manager (ACM).
Show Suggested Answer Hide Answer
Suggested Answer: BC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
100fold
Highly Voted 1 year, 1 month ago
Selected Answer: BC
Answer is BC. https://www.examtopics.com/discussions/amazon/view/88447-exam-aws-certified-security-specialty-topic-1-question-437/
upvoted 5 times
...
FunkyFresco
Most Recent 3 months, 2 weeks ago
Selected Answer: BC
B and C.
upvoted 1 times
...
xusang
9 months, 2 weeks ago
Selected Answer: BC
Restricting access to Application Load Balancers:https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/restrict-access-to-load-balancer.html
upvoted 3 times
...
Raphaello
10 months ago
Selected Answer: BC
BC Add custom origin-request header (CloudFron > ALB), set ALB to only accept request with such HTTP header.
upvoted 1 times
...
Aamee
1 year ago
Selected Answer: BC
W/o any doubt..
upvoted 1 times
...
Daniel76
1 year ago
Selected Answer: BC
https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/example-function-add-true-client-ip-header.html https://aws.amazon.com/blogs/security/three-most-important-aws-waf-rate-based-rules/
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago