Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 35 discussion

A company is preparing to launch a public-facing web application in the AWS Cloud. The architecture consists of Amazon EC2 instances within a VPC behind an Elastic Load Balancer (ELB). A third-party service is used for the DNS. The company's solutions architect must recommend a solution to detect and protect against large-scale DDoS attacks.
Which solution meets these requirements?

  • A. Enable Amazon GuardDuty on the account.
  • B. Enable Amazon Inspector on the EC2 instances.
  • C. Enable AWS Shield and assign Amazon Route 53 to it.
  • D. Enable AWS Shield Advanced and assign the ELB to it.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
ninjawrz
Highly Voted 1 year, 8 months ago
Selected Answer: D
Answer is D C is incorrect because question says Third party DNS and route 53 is AWS proprietary
upvoted 42 times
kidomaruto
8 months, 1 week ago
Right answer, wrong explanation. You can use Route 53 with a custom domain.. it's all about the "large-scale DDOS attack".
upvoted 12 times
...
...
BoboChow
Highly Voted 1 year, 8 months ago
Selected Answer: D
AWS Shield Advanced provides expanded DDoS attack protection for your Amazon EC2 instances, Elastic Load Balancing load balancers, CloudFront distributions, Route 53 hosted zones, and AWS Global Accelerator standard accelerators.
upvoted 27 times
leonardh
1 year, 1 month ago
I´d agree as Shield Advanced is the only tier that can protect EC2 which is not possible in Standard.
upvoted 7 times
...
...
awsgeek75
Most Recent 5 months, 3 weeks ago
Selected Answer: D
A: GuardDuty is not for this, mostly for account monitoring for suspicious activity B: Inspector is for OS vulnerabilities C: Shield with R53 is not going to protect against DDoS D: Shield Advanced is build for DDoS protection
upvoted 3 times
awsgeek75
5 months, 3 weeks ago
Forgot to mention, C won't work because a 3rd party DNS is used and R53 is not part of the setup
upvoted 2 times
...
...
awsgeek75
5 months, 3 weeks ago
Prevent large scale DDOS attack = AWS Shield Advanced
upvoted 1 times
...
A_jaa
5 months, 3 weeks ago
Selected Answer: D
Answer-D
upvoted 1 times
...
djgodzilla
6 months, 3 weeks ago
Selected Answer: D
- In addition to the network and transport layer protections that come with Standard, Shield Advanced provides additional detection and mitigation against large and sophisticated DDoS attacks, near real-time visibility into attacks, and integration with AWS WAF, a web application firewall. https://aws.amazon.com/shield/features/#:~:text=In%20addition%20to%20the%20network,WAF%2C%20a%20web%20application%20firewall.
upvoted 1 times
...
OmegaLambda7XL9
7 months, 3 weeks ago
This one got me to be honest
upvoted 2 times
...
Ruffyit
8 months, 1 week ago
Option A is incorrect because Amazon GuardDuty is a threat detection service that focuses on identifying malicious activity and unauthorized behavior within AWS accounts. While it is useful for detecting various security threats, it does not specifically address large-scale DDoS attacks. Option B is also incorrect because Amazon Inspector is a vulnerability assessment service that helps identify security issues and vulnerabilities within EC2. It does not directly protect against DDoS attacks. Option C is not the optimal choice because AWS Shield provides basic DDoS protection for resources such as Elastic IP addresses, CloudFront, and Route53 hosted zones. However, it
upvoted 2 times
Ruffyit
8 months, 1 week ago
does not provide the advanced capabilities and assistance offered by AWS Shield Advanced, which is better suited for protecting against large-scale DDoS attacks. Therefore, option D with AWS Shield Advanced and assigning the ELB to it is the recommended solution to detect and protect against large-scale DDoS attacks in the architecture described.
upvoted 2 times
...
...
Abitek007
9 months, 1 week ago
D, but can be tricky, the third party negates Route53
upvoted 1 times
...
Ak9kumar
9 months, 2 weeks ago
Answer D. Learn section on AWS Advanced Shield on aws.Amazon.com to help you understand this. It helped me.
upvoted 1 times
...
ishant101
10 months, 1 week ago
answer is D
upvoted 1 times
...
TariqKipkemei
11 months, 1 week ago
Selected Answer: D
DDos = AWS Shield
upvoted 2 times
...
hsinchang
11 months, 2 weeks ago
Selected Answer: D
large-scale DDos leads to advanced instead of standard AWS Shield.
upvoted 1 times
...
james2033
11 months, 3 weeks ago
Selected Answer: D
Keyword "large-scale DDoS attacks" , "Amazon EC2", "VPC", "ELB", "3rd service used for DNS". Amazon GuardDuty https://aws.amazon.com/guardduty/ Intelligent threat detection. AWS Shield https://aws.amazon.com/shield/ Automatically detect and mitigate sophisticated network-level DDoS. AWS Shield Advanced with ELB https://aws.amazon.com/about-aws/whats-new/2022/04/aws-shield-application-balancer-automatic-ddos-mitigation/ . Choose D.
upvoted 2 times
...
miki111
11 months, 3 weeks ago
Option D is the right answer for this.
upvoted 1 times
...
Kaab_B
11 months, 4 weeks ago
Selected Answer: D
DDoS extended is AWS Sheild Advance without a doubt.
upvoted 1 times
...
karloscetina007
1 year ago
A third-party service D is the answer with no doubts
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
ex Want to SAVE BIG on Certification Exam Prep?
close
ex Unlock All Exams with ExamTopics Pro 75% Off
  • arrow Choose From 1000+ Exams
  • arrow Access to 10 Exams per Month
  • arrow PDF Format Available
  • arrow Inline Discussions
  • arrow No Captcha/Robot Checks
Limited Time Offer
Ends in