nerdexam
Amazon

SCS-C02 · Question #23

A company's public Application Load Balancer (ALB) recently experienced a DDoS attack. To mitigate this issue, the company deployed Amazon CloudFront in front of the ALB so that users would not direct

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #23. The question stem and answer options stay visible for context.

Submitted by layla.eg· Mar 6, 2026Infrastructure Security

Question

A company's public Application Load Balancer (ALB) recently experienced a DDoS attack. To mitigate this issue, the company deployed Amazon CloudFront in front of the ALB so that users would not directly access the Amazon EC2 instances behind the ALB. The company discovers that some traffic is still coming directly into the ALB and is still being handled by the EC2 instances. Which combination of steps should the company take to ensure that the EC2 instances will receive traffic only from CloudFront? (Choose two.)

Options

  • AConfigure CloudFront to add a cache key policy to allow a custom HTTP header that CloudFront
  • BConfigure CloudFront to add a custom HTTP header to requests that CloudFront sends to the
  • CConfigure the ALB to forward only requests that contain the custom HTTP header.
  • DConfigure the ALB and CloudFront to use the X-Forwarded-For header to check client IP
  • EConfigure the ALB and CloudFront to use the same X.509 certificate that is generated by AWS

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#DDoS mitigation#CloudFront#ALB#custom HTTP header
Full SCS-C02 Practice