ANS-C01 exam dumps

ANS-C01 practice question 430 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 430

Select 2

A company is hosting a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application stores sensitive customer data, and the company wants to ensure compliance with security best practices to protect the data. Which combination of actions should the company take to secure the application and ensure compliance? (Select TWO.)

  1. A

    Configure AWS WAF to block common web exploits like SQL injection and cross-site scripting (XSS).

  2. B

    Enable ALB access logs and store them in an encrypted Amazon S3 bucket.

  3. C

    Use default security group rules to allow unrestricted inbound access to the EC2 instances for monitoring purposes.

  4. D

    Implement TLS termination at the EC2 instances to encrypt traffic between the ALB and the backend.

  5. E

    Use IAM roles with least privilege to grant EC2 instances access to required AWS resources.

Show answer and explanation

Correct answers: A, E

Explanation

To secure the application and ensure compliance, the company should use AWS WAF to protect against common web exploits and implement IAM roles with least privilege to enforce access controls. These actions directly address security vulnerabilities and align with compliance best practices. While enabling ALB access logs is important for monitoring, it does not directly secure the application. Allowing unrestricted inbound access is a security risk, and implementing TLS termination at the EC2 instances is redundant when the ALB is already managing TLS.

  • A. Correct.

    Configuring AWS WAF protects the application from common web exploits such as SQL injection and XSS. This improves security and helps ensure compliance with security best practices.

  • B. Incorrect.

    Enabling ALB access logs and storing them in an encrypted S3 bucket enhances monitoring and compliance, but it does not directly secure the application or customer data.

  • C. Incorrect.

    Using default security group rules to allow unrestricted inbound access is a security risk and violates best practices for securing sensitive data.

  • D. Incorrect.

    TLS termination at the EC2 instances is unnecessary when the ALB already handles TLS termination. It also adds complexity without improving compliance or security in this scenario.

  • E. Correct.

    Using IAM roles with least privilege ensures the EC2 instances only have the necessary access to AWS resources, reducing the risk of unauthorized access and improving security.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam