exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 226 discussion

A company hosts its public website on Amazon EC2 instances behind an Application Load Balancer (ALB). The website is experiencing a global DDoS attack by a specific IoT device brand that has a unique user agent.

A security engineer is creating an AWS WAF web ACL and will associate the web ACL with the ALB. The security engineer must implement a rule statement as part of the web ACL to block the requests. The rule statement must mitigate the current attack and future attacks from these IoT devices without blocking requests from customers.

Which rule statement will meet these requirements?

  • A. Use an IP set match rule statement that includes the IP address for IoT devices from the user agent.
  • B. Use a geographic match rule statement. Configure the statement to block countries that the IoT devices are located in.
  • C. Use a rate-based rule statement. Set a rate limit that is equal to the number of requests that are coming from the IoT devices.
  • D. Use a string match rule statement that includes details of the IoT device brand from the user agent.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Pmktechno
3 months, 3 weeks ago
Selected Answer: D
his approach targets the unique user agent string of the IoT devices involved in the DDoS attack, effectively blocking malicious traffic while allowing legitimate requests from customers to pass through.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago