exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 927 discussion

A company is building an application in the AWS Cloud. The application is hosted on Amazon EC2 instances behind an Application Load Balancer (ALB). The company uses Amazon Route 53 for the DNS.

The company needs a managed solution with proactive engagement to detect against DDoS attacks.

Which solution will meet these requirements?

  • A. Enable AWS Config. Configure an AWS Config managed rule that detects DDoS attacks.
  • B. Enable AWS WAF on the ALCreate an AWS WAF web ACL with rules to detect and prevent DDoS attacks. Associate the web ACL with the ALB.
  • C. Store the ALB access logs in an Amazon S3 bucket. Configure Amazon GuardDuty to detect and take automated preventative actions for DDoS attacks.
  • D. Subscribe to AWS Shield Advanced. Configure hosted zones in Route 53. Add ALB resources as protected resources.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
LeonSauveterre
3 months, 3 weeks ago
Selected Answer: D
For your references: 1. AWS WAF (Web Application Firewall) - SQL injections, cross-site scripting (XSS), and other common web exploits. 2. Shield Standard - common DDoS attacks; Shield Advanced - Provides advanced DDoS protection with 24/7 support, cost protection for scaling due to attacks, and more detailed attack analytics. 3. AWS Network Firewall - Blocks unauthorized access and inspect traffic for VPCs. 4. Amazon GuardDuty - Detects threats by analyzing AWS logs like CloudTrail, DNS, and VPC Flow Logs. Identifies potential malicious activities like brute force attacks and data exfiltration. 5. AWS Macie - Helps identify and protect sensitive data like PII stored in S3 buckets.
upvoted 2 times
LeonSauveterre
3 months, 3 weeks ago
6. AWS Detective - Analyzes and visualizes security-related data to identify root causes of potential security issues. 7. AWS Config - Monitors and evaluates configurations of AWS resources to ensure compliance with security best practices. 8. AWS Inspector - Automatically scans EC2 instances and container-based workloads for known vulnerabilities. 9. AWS CloudTrail - Tracks API calls and user activity for auditing and compliance.
upvoted 2 times
...
...
AMEJack
4 months, 4 weeks ago
Selected Answer: D
Shield Advanced signals a DDoS detection and starts analyzing the traffic for an attack signature. If a signature is found, it is first tested on past traffic to reduce the risk of false positive, then if it's safe to use it, a corresponding WAF rule is placed in the previously created rule group. After a certain time, when the attack is stopped, the rule is automatically removed from the rule group. When successful, this process takes several minutes.
upvoted 2 times
...
dhewa
8 months, 1 week ago
Selected Answer: D
Tip: DDoS = Shield, SQL injection = WAF
upvoted 4 times
...
komorebi
8 months, 3 weeks ago
Selected Answer: D
Answer is D
upvoted 2 times
...
swati1508
8 months, 3 weeks ago
D for DDOS shield advance
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago