nerdexam
Oracle

1Z0-997 · Question #65

1Z0-997 Question #65: Real Exam Question with Answer & Explanation

The correct answer is B. Block the attacking IP address by implementing a OCI Web Application Firewall policy using Access Control Rules. WAF provides you with the ability to create and manage rules for internet threats including Cross-Site Scripting (XSS), SQL Injection and other OWASP-defined vulnerabilities. Unwanted bots can be mitigated while tactically allowed desirable bots to enter. Access rules can limit b

Question

A hospital in Austin has hosted its web based medical records portal entirely. In Oracle cloud Infrastructure (OCI) using Compute Instances for its web-tier and DB system database for its data tier. To validate compliance with Health Insurance Portability and Accountability (HIPAA), the security professional to check their systems it was found that there are a lot of unauthorized coming requests coming from a set of IP addresses originating from a country in Southeast Asia. Which option can mitigate this type of attack?

Options

  • ABlock the attacking IP address by creating by Network Security Group rule to deny access to the compute Instance where the web server Is running
  • BBlock the attacking IP address by implementing a OCI Web Application Firewall policy using Access Control Rules
  • CMitigate the attack by changing the Route fable to redirect the unauthorized traffic to a dummy Compute instance
  • DBlock the attacking IP address by creating a Security List rule to deny access to the subnet where the web server Is running

Explanation

WAF provides you with the ability to create and manage rules for internet threats including Cross-Site Scripting (XSS), SQL Injection and other OWASP-defined vulnerabilities. Unwanted bots can be mitigated while tactically allowed desirable bots to enter. Access rules can limit based on geography or the signature of the As a WAF administrator you can define explicit actions for requests that meet various conditions. Conditions use various operations and regular expressions. A rule action can be set to log and allow, detect, or block requests

Community Discussion

No community discussion yet for this question.

Full 1Z0-997 Practice