ANS-C01 exam dumps

ANS-C01 practice question 446 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 446

Select 2

Your company is hosting a web application on Amazon EC2 instances behind an Application Load Balancer. Recently, the application has been experiencing a Distributed Denial of Service (DDoS) attack, causing high latency and unavailability for legitimate users. Which of the following actions should you take to mitigate this threat? (Select TWO)

  1. A

    Enable AWS Shield Advanced to provide enhanced DDoS protection.

  2. B

    Deploy AWS WAF to block malicious traffic patterns.

  3. C

    Use Auto Scaling to increase the number of EC2 instances to handle the traffic.

  4. D

    Encrypt data in transit using HTTPS to prevent unauthorized access.

  5. E

    Configure ELB access logs to analyze traffic patterns after the attack subsides.

Show answer and explanation

Correct answers: A, B

Explanation

To mitigate a DDoS attack, you need services that can detect and block malicious traffic in real time. AWS Shield Advanced provides specialized DDoS protection, while AWS WAF lets you create rules to block traffic patterns associated with the attack. Other options, such as Auto Scaling and HTTPS, are valuable for scalability and data security but do not directly address the issue at hand. ELB access logs are useful for analysis but are not a proactive mitigation strategy.

  • A. Correct.

    AWS Shield Advanced provides enhanced DDoS protection, including detection, mitigation, and cost protection against large-scale attacks. This is an essential service for mitigating DDoS attacks.

  • B. Correct.

    AWS WAF (Web Application Firewall) allows you to create rules to block or allow specific traffic patterns, helping to block malicious traffic during a DDoS attack.

  • C. Incorrect.

    Using Auto Scaling can help handle increased traffic, but it does not mitigate the root cause of the DDoS attack, which is malicious traffic overwhelming the system.

  • D. Incorrect.

    Encrypting data in transit using HTTPS is a good security practice, but it does not address the issue of DDoS mitigation.

  • E. Incorrect.

    Analyzing traffic patterns with ELB access logs is useful for post-mortem analysis, but it does not actively mitigate the ongoing DDoS attack.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam