Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 170 discussion

A company’s web application is running on Amazon EC2 instances behind an Application Load Balancer. The company recently changed its policy, which now requires the application to be accessed from one specific country only.

Which configuration will meet this requirement?

  • A. Configure the security group for the EC2 instances.
  • B. Configure the security group on the Application Load Balancer.
  • C. Configure AWS WAF on the Application Load Balancer in a VPC.
  • D. Configure the network ACL for the subnet that contains the EC2 instances.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
handyplazt
Highly Voted 2 years ago
Selected Answer: C
Geographic (Geo) Match Conditions in AWS WAF. This new condition type allows you to use AWS WAF to restrict application access based on the geographic location of your viewers. With geo match conditions you can choose the countries from which AWS WAF should allow access. https://aws.amazon.com/about-aws/whats-new/2017/10/aws-waf-now-supports-geographic-match/
upvoted 28 times
...
cookieMr
Highly Voted 1 year, 4 months ago
Selected Answer: C
By configuring AWS WAF on the ALB in a VPC, you can apply access control rules based on the geographic location of the incoming requests. AWS WAF allows you to create rules that include conditions based on the IP addresses' country of origin. You can specify the desired country and deny access to requests originating from any other country by leveraging AWS WAF's Geo Match feature. Option A and option B focus on network-level access control and do not provide country-specific filtering capabilities. Option D is not the ideal solution for restricting access based on country. Network ACLs primarily control traffic at the subnet level based on IP addresses and port numbers, but they do not have built-in capabilities for country-based filtering.
upvoted 5 times
...
PaulGa
Most Recent 3 weeks, 4 days ago
Selected Answer: C
Ans C - WAF with geo-match (region or country). https://docs.aws.amazon.com/waf/latest/developerguide/waf-rule-statement-type-geo-match.html
upvoted 2 times
...
PoolDead
3 months, 2 weeks ago
C --> One of the feature of WAF is Access Control: Implement IP whitelisting and blacklisting to allow or block traffic from specific IP addresses or address ranges. This can be useful for restricting access to your web application to trusted users or regions.
upvoted 3 times
...
Ruffyit
11 months, 3 weeks ago
Geographic (Geo) Match Conditions in AWS WAF. This new condition type allows you to use AWS WAF to restrict application access based on the geographic location of your viewers. With geo match conditions you can choose the countries from which AWS WAF should allow access. https://aws.amazon.com/about-aws/whats-new/2017/10/aws-waf-now-supports-geographic-match/
upvoted 4 times
...
Guru4Cloud
1 year, 3 months ago
Selected Answer: C
C. Configure AWS WAF on the Application Load Balancer in a VPC
upvoted 1 times
...
Sutariya
1 year, 3 months ago
We can use AWS WAF to configure access control rule to access from specific location.
upvoted 1 times
...
Abrar2022
1 year, 5 months ago
Configure AWS WAF for Geo Match Policy
upvoted 3 times
...
aba2s
1 year, 10 months ago
Selected Answer: C
Source from an AWS link Geographic (Geo) Match Conditions in AWS WAF. This condition type allows you to use AWS WAF to restrict application access based on the geographic location of your viewers. With geo match conditions you can choose the countries from which AWS WAF should allow access.
upvoted 3 times
...
techhb
1 year, 11 months ago
Selected Answer: C
WAF Shield Advanced for DDOS, GuardDuty is a continuous monitoring service that alerts you of potential threats, while Inspector is a one-time assessment service that provides a report of vulnerabilities and deviations from best practices.
upvoted 2 times
...
Buruguduystunstugudunstuy
1 year, 11 months ago
Selected Answer: C
To meet the requirement of allowing the web application to be accessed from one specific country only, the company should configure AWS WAF (Web Application Firewall) on the Application Load Balancer in a VPC (Option C). AWS WAF is a web application firewall service that helps protect web applications from common web exploits that could affect application availability, compromise security, or consume excessive resources. AWS WAF allows you to create rules that block or allow traffic based on the values of specific request parameters, such as IP address, HTTP header, or query string value. By configuring AWS WAF on the Application Load Balancer and creating rules that allow traffic from a specific country, the company can ensure that the web application is only accessible from that country.
upvoted 5 times
...
career360guru
1 year, 11 months ago
Selected Answer: C
OptionC. Configure WAF for Geo Match Policy
upvoted 2 times
...
Wpcorgan
1 year, 12 months ago
C is correct
upvoted 2 times
...
mricee9
2 years ago
Selected Answer: C
C https://aws.amazon.com/about-aws/whats-new/2017/10/aws-waf-now-supports-geographic-match/
upvoted 3 times
...
Nigma
2 years ago
C. WAF with ALB is the right option
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...