nerdexam
Oracle

1Z0-997-20 · Question #131

A hospital in Austin has hosted its web based medical records portal entirely In Oracle cloud Infrastructure (OCI) using Compute Instances for its web-tier and DB system database for its data tier…

The correct answer is B. Block the attacking IP address by implementing a OCI Web Application Firewall policy using. WAF can protect any internet facing endpoint, providing consistent rule enforcement across a customer's applications. WAF provides you with the ability to create and manage rules for internet threats including Cross- Site Scripting (XSS), SQL Injection and other OWASP-defined…

Design for Security

Question

A hospital in Austin has hosted its web based medical records portal entirely In Oracle cloud Infrastructure (OCI) using Compute Instances for its web-tier and DB system database for its data tier. To validate compliance with Health Insurance Portability and Accountability (HIPAA), the security professional to check their systems it was found that there are a lot of unauthorized coming requests coming from a set of IP addresses originating from a country in Southeast Asia. Which option can mitigate this type of attack?

Options

  • ABlock the attacking IP address by creating by Network Security Group rule to deny access to the
  • BBlock the attacking IP address by implementing a OCI Web Application Firewall policy using
  • CMitigate the attack by changing the Route fable to redirect the unauthorized traffic to a dummy
  • DBlock the attacking IP address by creating a Security List rule to deny access to the subnet where

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    84% (37)
  • C
    9% (4)
  • D
    5% (2)

Explanation

WAF can protect any internet facing endpoint, providing consistent rule enforcement across a customer's applications. WAF provides you with the ability to create and manage rules for internet threats including Cross- Site Scripting (XSS), SQL Injection and other OWASP-defined vulnerabilities. Unwanted bots can be mitigated while tactically allowed desirable bots to enter. Access rules can limit based on geography or the signature of the request. As a WAF administrator you can define explicit actions for requests that meet various conditions. Conditions use various operations and regular expressions. A rule action can be set to log and allow, detect, or block requests

Topics

#Web Application Firewall#access control rules#IP blocking#HIPAA compliance

Community Discussion

No community discussion yet for this question.

Full 1Z0-997-20 Practice