nerdexam
AmazonAmazon

SCS-C02 · Question #427

SCS-C02 Question #427: Real Exam Question with Answer & Explanation

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #427. The question stem and answer options stay visible for context.

Submitted by kev92· Mar 6, 2026

Question

A company hosts its public website on Amazon EC2 instances behind an Application Load Balancer (ALB). The website is experiencing a global DDoS attack by a specific IoT device brand that has a unique user agent. A security engineer is creating an AWS WAF web ACL and will associate the web ACL with the ALB. The security engineer must implement a rule statement as part of the web ACL to block the requests. The rule statement must mitigate the current attack and future attacks from these IoT devices without blocking requests from customers. Which rule statement will meet these requirements?

Options

  • AUse an IP set match rule statement that includes the IP address for IoT devices from the user
  • BUse a geographic match rule statement. Configure the statement to block countries that the IoT
  • CUse a rate-based rule statement. Set a rate limit that is equal to the number of requests that are
  • DUse a string match rule statement that includes details of the IoT device brand from the user

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full SCS-C02 PracticeBrowse All SCS-C02 Questions