SCS-C03 · Question #146
A company runs an application on a fleet of Amazon EC2 instances. The application is accessible to users around the world. The company associates an AWS WAF web ACL with an Application Load Balancer (
Sign in or unlock SCS-C03 to reveal the answer and full explanation for question #146. The question stem and answer options stay visible for context.
Question
A company runs an application on a fleet of Amazon EC2 instances. The application is accessible to users around the world. The company associates an AWS WAF web ACL with an Application Load Balancer (ALB) that routes traffic to the EC2 instances. A security engineer is investigating a sudden increase in traffic to the application. The security engineer discovers a significant amount of potentially malicious requests coming from hundreds of IP addresses in two countries. The security engineer wants to quickly limit the potentially malicious requests but does not want to prevent legitimate users from accessing the application. Which solution will meet these requirements?
Options
- AUse AWS WAF to implement a rate-based rule for all incoming requests.
- BUse AWS WAF to implement a geographical match rule to block all incoming traffic from the two
- CEdit the ALB security group to include a geographical match rule to block all incoming traffic from
- DAdd deny rules to the ALB security group that prohibit incoming requests from the IP addresses.
Unlock SCS-C03 to see the answer
You've previewed enough free SCS-C03 questions. Unlock SCS-C03 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.