nerdexam
AmazonAmazon

SCS-C02 · Question #271

SCS-C02 Question #271: Real Exam Question with Answer & Explanation

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #271. The question stem and answer options stay visible for context.

Submitted by tunde_lagos· Mar 6, 2026Infrastructure Security

Question

A company website runs on Amazon EC2 instances behind an Application Load Balancer (ALB). The instances run in an Auto Scaling group across multiple Availability Zones. There is an Amazon CloudFront distribution in front of the ALB. Users are reporting performance problems. A security engineer discovers that the website is receiving a high rate of unwanted requests to the CloudFront distribution originating from a series of source IP addresses. How should the security engineer address this problem?

Options

  • AUsing AWS Shield, configure a deny rule with an IP match condition containing the source IPs of
  • BUsing Auto Scaling, configure the maximum an instance value to an increased count that will
  • CUsing an Amazon VPC NACL, configure an inbound deny rule for each source IP CIDR address
  • DUsing AWS WAF, configure a web ACL rate-based rule on the CloudFront distribution with a rate

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#AWS WAF#CloudFront#DDoS Protection#Web Application Security
Full SCS-C02 PracticeBrowse All SCS-C02 Questions