nerdexam
Amazon

SOA-C02 · Question #125

A company's public website is hosted in an Amazon S3 bucket in the us-east-1 Region behind an Amazon CloudFront distribution. The company wants to ensure that the website is protected from DDoS attack

Sign in or unlock SOA-C02 to reveal the answer and full explanation for question #125. The question stem and answer options stay visible for context.

Submitted by joshua94· Mar 30, 2026Security and Compliance

Question

A company's public website is hosted in an Amazon S3 bucket in the us-east-1 Region behind an Amazon CloudFront distribution. The company wants to ensure that the website is protected from DDoS attacks. A SysOps administrator needs to deploy a solution that gives the company the ability to maintain control over the rate limit at which DDoS protections are applied. Which solution will meet these requirements?

Options

  • ADeploy a global-scoped AWS WAF web ACL with an allow default action.
  • BDeploy an AWS WAF web ACL with an allow default action in us-east-1.
  • CDeploy a global-scoped AWS WAF web ACL with a block default action.
  • DDeploy an AWS WAF web ACL with a block default action in us-east-1.

Unlock SOA-C02 to see the answer

You've previewed enough free SOA-C02 questions. Unlock SOA-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#AWS WAF#DDoS protection#CloudFront#web ACL
Full SOA-C02 Practice