SCS-C02 · Question #188
A company has a web-based application that runs behind an Application Load Balancer (ALB). The application is experiencing a credential stuffing attack that is producing many failed login attempts. Th
Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #188. The question stem and answer options stay visible for context.
Question
A company has a web-based application that runs behind an Application Load Balancer (ALB). The application is experiencing a credential stuffing attack that is producing many failed login attempts. The attack is coming from many IP addresses. The login attempts are using a user agent string of a known mobile device emulator. A security engineer needs to implement a solution to mitigate the credential stuffing attack. The solution must still allow legitimate logins to the application. Which solution will meet these requirements?
Options
- ACreate an Amazon CloudWatch alarm that reacts to login attempts that contain the specified user
- BModify the inbound security group on the ALB to deny traffic from the IP addresses that are
- CCreate an AWS WAF web ACL for the ALB Create a custom rule that blocks requests that contain
- DCreate an AWS WAF web ACL for the ALB. Create a custom rule that allows requests from
Unlock SCS-C02 to see the answer
You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.