exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 35 discussion

A company is preparing to launch a public-facing web application in the AWS Cloud. The architecture consists of Amazon EC2 instances within a VPC behind an Elastic Load Balancer (ELB). A third-party service is used for the DNS. The company's solutions architect must recommend a solution to detect and protect against large-scale DDoS attacks.
Which solution meets these requirements?

  • A. Enable Amazon GuardDuty on the account.
  • B. Enable Amazon Inspector on the EC2 instances.
  • C. Enable AWS Shield and assign Amazon Route 53 to it.
  • D. Enable AWS Shield Advanced and assign the ELB to it.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ninjawrz
Highly Voted 2 years, 2 months ago
Selected Answer: D
Answer is D C is incorrect because question says Third party DNS and route 53 is AWS proprietary
upvoted 42 times
kidomaruto
1 year, 1 month ago
Right answer, wrong explanation. You can use Route 53 with a custom domain.. it's all about the "large-scale DDOS attack".
upvoted 18 times
...
...
BoboChow
Highly Voted 2 years, 2 months ago
Selected Answer: D
AWS Shield Advanced provides expanded DDoS attack protection for your Amazon EC2 instances, Elastic Load Balancing load balancers, CloudFront distributions, Route 53 hosted zones, and AWS Global Accelerator standard accelerators.
upvoted 29 times
leonardh
1 year, 7 months ago
I´d agree as Shield Advanced is the only tier that can protect EC2 which is not possible in Standard.
upvoted 7 times
...
...
Tjazz04
Most Recent 1 week, 4 days ago
Selected Answer: D
Ans. D - Keyword - Large-scale DDoS attacks which the AWS Shield Advanced can prevent
upvoted 1 times
...
zied007
3 months, 2 weeks ago
Selected Answer: D
Answer is D
upvoted 1 times
...
PaulGa
3 months, 3 weeks ago
Selected Answer: D
Ans D. Shield (Advanced) is built for DDoS and can interface to ELB
upvoted 2 times
...
awsgeek75
11 months, 2 weeks ago
Selected Answer: D
A: GuardDuty is not for this, mostly for account monitoring for suspicious activity B: Inspector is for OS vulnerabilities C: Shield with R53 is not going to protect against DDoS D: Shield Advanced is build for DDoS protection
upvoted 6 times
awsgeek75
11 months, 2 weeks ago
Forgot to mention, C won't work because a 3rd party DNS is used and R53 is not part of the setup
upvoted 3 times
...
...
awsgeek75
11 months, 2 weeks ago
Prevent large scale DDOS attack = AWS Shield Advanced
upvoted 2 times
...
A_jaa
11 months, 2 weeks ago
Selected Answer: D
Answer-D
upvoted 1 times
...
djgodzilla
1 year ago
Selected Answer: D
- In addition to the network and transport layer protections that come with Standard, Shield Advanced provides additional detection and mitigation against large and sophisticated DDoS attacks, near real-time visibility into attacks, and integration with AWS WAF, a web application firewall. https://aws.amazon.com/shield/features/#:~:text=In%20addition%20to%20the%20network,WAF%2C%20a%20web%20application%20firewall.
upvoted 2 times
...
OmegaLambda7XL9
1 year, 1 month ago
This one got me to be honest
upvoted 3 times
...
Ruffyit
1 year, 1 month ago
Option A is incorrect because Amazon GuardDuty is a threat detection service that focuses on identifying malicious activity and unauthorized behavior within AWS accounts. While it is useful for detecting various security threats, it does not specifically address large-scale DDoS attacks. Option B is also incorrect because Amazon Inspector is a vulnerability assessment service that helps identify security issues and vulnerabilities within EC2. It does not directly protect against DDoS attacks. Option C is not the optimal choice because AWS Shield provides basic DDoS protection for resources such as Elastic IP addresses, CloudFront, and Route53 hosted zones. However, it
upvoted 4 times
Ruffyit
1 year, 1 month ago
does not provide the advanced capabilities and assistance offered by AWS Shield Advanced, which is better suited for protecting against large-scale DDoS attacks. Therefore, option D with AWS Shield Advanced and assigning the ELB to it is the recommended solution to detect and protect against large-scale DDoS attacks in the architecture described.
upvoted 3 times
...
...
Abitek007
1 year, 2 months ago
D, but can be tricky, the third party negates Route53
upvoted 1 times
...
Ak9kumar
1 year, 3 months ago
Answer D. Learn section on AWS Advanced Shield on aws.Amazon.com to help you understand this. It helped me.
upvoted 2 times
...
ishant101
1 year, 3 months ago
answer is D
upvoted 1 times
...
TariqKipkemei
1 year, 4 months ago
Selected Answer: D
DDos = AWS Shield
upvoted 2 times
...
hsinchang
1 year, 4 months ago
Selected Answer: D
large-scale DDos leads to advanced instead of standard AWS Shield.
upvoted 3 times
...
james2033
1 year, 5 months ago
Selected Answer: D
Keyword "large-scale DDoS attacks" , "Amazon EC2", "VPC", "ELB", "3rd service used for DNS". Amazon GuardDuty https://aws.amazon.com/guardduty/ Intelligent threat detection. AWS Shield https://aws.amazon.com/shield/ Automatically detect and mitigate sophisticated network-level DDoS. AWS Shield Advanced with ELB https://aws.amazon.com/about-aws/whats-new/2022/04/aws-shield-application-balancer-automatic-ddos-mitigation/ . Choose D.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago