ANS-C01 exam dumps

ANS-C01 practice question 443 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 443

Select 4

Your company is hosting a multi-tier web application on AWS. The architecture includes an Application Load Balancer (ALB) in front of an auto-scaling group of EC2 instances running the web tier, and an Amazon RDS database in the backend. The application handles sensitive customer data. Which of the following threat models should you consider to secure this architecture?

  1. A

    Mitigating SQL injection attacks targeting the Amazon RDS database

  2. B

    Securing communication between the Application Load Balancer and EC2 instances using SSL/TLS

  3. C

    Defending against Distributed Denial of Service (DDoS) attacks targeting the Application Load Balancer

  4. D

    Implementing encryption for the data stored in Amazon S3 buckets

  5. E

    Preventing unauthorized access to EC2 instances by using Security Groups

Show answer and explanation

Correct answers: A, B, C, E

Explanation

This architecture involves multiple threat surfaces, including the database, the communication channels, and the instances themselves. Mitigating SQL injection (option 1) protects the database layer. Enabling SSL/TLS (option 2) secures data in transit between the ALB and EC2 instances. DDoS defenses (option 3) are essential for maintaining availability, especially for the ALB, which is exposed to the internet. Security Groups (option 5) provide instance-level access control, reducing the risk of unauthorized access. Option 4, while important in general, does not relate to this specific architecture since S3 is not mentioned.

  • A. Correct.

    Mitigating SQL injection attacks is critical because the backend Amazon RDS database is susceptible to such attacks if user inputs are not properly sanitized.

  • B. Correct.

    Securing communication between the ALB and EC2 instances using SSL/TLS ensures that data in transit is encrypted and cannot be intercepted by attackers.

  • C. Correct.

    The ALB is a potential target for DDoS attacks, and defending against such scenarios is essential to maintain application availability and performance.

  • D. Incorrect.

    While encrypting data in Amazon S3 is a best practice, this specific architecture does not mention S3 usage, so it is not directly relevant to this threat model.

  • E. Correct.

    Preventing unauthorized access to EC2 instances by configuring Security Groups is a fundamental layer of security in AWS to restrict access to only necessary sources.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam