nerdexam
Amazon

SCS-C02 · Question #296

A company hosts its public website on Amazon EC2 instances behind an Application Load Balancer (ALB). The instances are in an EC2 Auto Scaling group across multiple Availability Zones. The website…

The correct answer is D. Activate AWS Shield Advanced to enable DDoS protection. See the full explanation below for the reasoning.

Submitted by chen.hong· Mar 6, 2026Incident Response

Question

A company hosts its public website on Amazon EC2 instances behind an Application Load Balancer (ALB). The instances are in an EC2 Auto Scaling group across multiple Availability Zones. The website is under a DDoS attack by a specific loT device brand that is visible in the user agent. A security engineer needs to mitigate the attack without impacting the availability of the public website. What should the security engineer do to accomplish this?

Options

  • AConfigure a web ACL rule for AWS WAF to block requests with a string match condition for the
  • BConfigure an Amazon CloudFront distribution to use the ALB as an origin.
  • CConfigure an Amazon CloudFront distribution to use a new ALB as an origin.
  • DActivate AWS Shield Advanced to enable DDoS protection.

How the community answered

(46 responses)
  • A
    9% (4)
  • B
    4% (2)
  • C
    2% (1)
  • D
    85% (39)

Topics

#DDoS Protection#AWS Shield#Application Security#Incident Mitigation

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice