nerdexam
AmazonAmazon

SCS-C02 · Question #296

SCS-C02 Question #296: Real Exam Question with Answer & Explanation

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #296. The question stem and answer options stay visible for context.

Submitted by chen.hong· Mar 6, 2026Incident Response

Question

A company hosts its public website on Amazon EC2 instances behind an Application Load Balancer (ALB). The instances are in an EC2 Auto Scaling group across multiple Availability Zones. The website is under a DDoS attack by a specific loT device brand that is visible in the user agent. A security engineer needs to mitigate the attack without impacting the availability of the public website. What should the security engineer do to accomplish this?

Options

  • AConfigure a web ACL rule for AWS WAF to block requests with a string match condition for the
  • BConfigure an Amazon CloudFront distribution to use the ALB as an origin.
  • CConfigure an Amazon CloudFront distribution to use a new ALB as an origin.
  • DActivate AWS Shield Advanced to enable DDoS protection.

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#DDoS Protection#AWS Shield#Application Security#Incident Mitigation
Full SCS-C02 PracticeBrowse All SCS-C02 Questions