exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C02 exam

Exam AWS Certified Solutions Architect - Associate SAA-C02 topic 1 question 637 discussion

A company is designing a cloud communications platform that is driven by APIs. The application is hosted on Amazon EC2 instances behind a Network Load
Balancer (NLB). The company uses Amazon API Gateway to provide external users with access to the application through APIs. The company wants to protect the platform against web exploits like SQL injection and also wants to detect and mitigate large, sophisticated DDoS attacks.
Which combination of solutions provides the MOST protection? (Choose two.)

  • A. Use AWS WAF to protect the NLB.
  • B. Use AWS Shield Advanced with the NLB.
  • C. Use AWS WAF to protect Amazon API Gateway.
  • D. Use Amazon GuardDuty with AWS Shield Standard.
  • E. Use AWS Shield Standard with Amazon API Gateway.
Show Suggested Answer Hide Answer
Suggested Answer: BC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MatAlves
7 months ago
Selected Answer: BC
You can use Shield with API. https://docs.aws.amazon.com/waf/latest/developerguide/ddos-advanced-summary-protected-resources.html WAF to protect the API Gateway, since it's exposed to external users.
upvoted 1 times
...
BECAUSE
1 year, 10 months ago
Selected Answer: BC
B and C are the answers
upvoted 1 times
...
jxp09
2 years, 6 months ago
Selected Answer: BC
WAF - ALB,API GATEWAY & CF SHIELD - Route 53, CF & Load Balancer
upvoted 2 times
...
rodriiviru
2 years, 6 months ago
Selected Answer: BC
AWS Shield Advanced provides expanded DDoS attack protection for your Amazon EC2 instances, Elastic Load Balancing load balancers, CloudFront distributions, Route 53 hosted zones, and AWS Global Accelerator standard accelerators. AWS WAF is a web application firewall that lets you monitor the HTTP and HTTPS requests that are forwarded to your protected web application resources. You can protect the following resource types: Amazon CloudFront distribution Amazon API Gateway REST API Application Load Balancer AWS AppSync GraphQL API Amazon Cognito user pool https://docs.aws.amazon.com/waf/latest/developerguide/what-is-aws-waf.html
upvoted 3 times
...
drinu89
2 years, 6 months ago
Selected Answer: BC
B : AWS Shield Advanced is used with NLB Get started protecting EC2 instances and Network Load Balancers Sign in to the AWS Management Console and navigate to the AWS WAF and AWS Shield console. Activate AWS Shield Advanced by choosing Activate AWS Shield Advanced and accepting the terms.
upvoted 2 times
...
drinu89
2 years, 6 months ago
A is wrong WAF cannot be associated with NLB. NLB operates on layer 4 and it does not have visibility into application layer [1]. WAF, however, inspects layer 7 requests, operates on a different layer. As of today, WAF work with CloudFront, the Application Load Balancer (ALB), Amazon API Gateway, and AWS AppSync [2]
upvoted 2 times
...
nymets
2 years, 7 months ago
Selected Answer: CE
AWS WAF for SQL injection and cross-site scripting (XSS) attacks. AWS Shield for DDos protection.
upvoted 3 times
...
guptatrng
2 years, 7 months ago
I think its BC
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago