nerdexam
Amazon

SCS-C03 · Question #129

A company is running a containerized application on an Amazon Elastic Container Service (Amazon ECS) cluster that uses AWS Fargate. The application runs as several ECS services. The ECS services are i

Sign in or unlock SCS-C03 to reveal the answer and full explanation for question #129. The question stem and answer options stay visible for context.

Submitted by jordan8· Mar 6, 2026Infrastructure Security

Question

A company is running a containerized application on an Amazon Elastic Container Service (Amazon ECS) cluster that uses AWS Fargate. The application runs as several ECS services. The ECS services are in individual target groups for an internet-facing Application Load Balancer (ALB). The ALB is the origin for an Amazon CloudFront distribution. An AWS WAF web ACL is associated with the CloudFront distribution. Web clients access the ECS services through the CloudFront distribution. The company learns that the web clients can bypass the web ACL and can access the ALB directly. Which solution will prevent the web clients from directly accessing the ALB?

Options

  • ACreate an AWS PrivateLink endpoint and set it as the CloudFront origin.
  • BCreate a new internal ALB and delete the internet-facing ALB.
  • CModify the ALB listener rules to allow only CloudFront IP ranges.
  • DAdd a custom X-Shared-Secret header in CloudFront and configure the ALB listener rules to

Unlock SCS-C03 to see the answer

You've previewed enough free SCS-C03 questions. Unlock SCS-C03 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#CloudFront WAF bypass#ALB listener rules#custom header#origin protection
Full SCS-C03 Practice