exam questions

Exam AWS Certified Solutions Architect - Professional SAP-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional SAP-C02 exam

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 388 discussion

A company is developing a web application that runs on Amazon EC2 instances in an Auto Scaling group behind a public-facing Application Load Balancer (ALB). Only users from a specific country are allowed to access the application. The company needs the ability to log the access requests that have been blocked. The solution should require the least possible maintenance.

Which solution meets these requirements?

  • A. Create an IPSet containing a list of IP ranges that belong to the specified country. Create an AWS WAF web ACL. Configure a rule to block any requests that do not originate from an IP range in the IPSet. Associate the rule with the web ACL. Associate the web ACL with the ALB.
  • B. Create an AWS WAF web ACL. Configure a rule to block any requests that do not originate from the specified country. Associate the rule with the web ACL. Associate the web ACL with the ALB.
  • C. Configure AWS Shield to block any requests that do not originate from the specified country. Associate AWS Shield with the ALB.
  • D. Create a security group rule that allows ports 80 and 443 from IP ranges that belong to the specified country. Associate the security group with the ALB.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
vibzr2023
Highly Voted 1 year, 3 months ago
Answer: B AWS WAF supports geo-matching rules, allowing you to easily block requests based on country of origin. This eliminates the need to manually manage IP ranges. Option C - Shield primarily defends against DDoS attacks and does not offer granular geo-blocking capabilities.
upvoted 6 times
...
TomTom
Most Recent 4 months, 4 weeks ago
Selected Answer: A
Why not A? Option A allows for logging of blocked requests while minimizing maintenance needs, as AWS WAF handles updates to IP ranges effectively.
upvoted 1 times
...
career360guru
1 year, 3 months ago
Selected Answer: B
Option B
upvoted 1 times
...
J0n102
1 year, 4 months ago
Selected Answer: B
Answer: B
upvoted 1 times
...
GabrielDeBiasi
1 year, 5 months ago
Selected Answer: B
B for sure
upvoted 1 times
...
Maygam
1 year, 5 months ago
Selected Answer: B
https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-type-geo-match.html
upvoted 2 times
...
devalenzuela86
1 year, 5 months ago
Selected Answer: B
B for sure
upvoted 1 times
...
cypkir
1 year, 5 months ago
Selected Answer: B
Answer: B
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago