ANS-C01 exam dumps

ANS-C01 practice question 447 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 447

Select 3

Your company is hosting a web application on Amazon EC2 instances behind an Application Load Balancer (ALB) in a public subnet. The backend database is hosted in a private subnet. Recently, you observed unusual activity, including multiple failed login attempts from various IP addresses and high traffic spikes at odd hours. Which combination of actions should you take to mitigate these security threats?

  1. A

    Enable AWS WAF on the Application Load Balancer and configure rules to block IPs with suspicious activity.

  2. B

    Enable VPC Flow Logs for both public and private subnets to analyze traffic patterns.

  3. C

    Create a Network ACL to block all inbound traffic to the public subnet except for trusted IP ranges.

  4. D

    Use AWS Shield Advanced to protect against DDoS attacks targeting the Application Load Balancer.

  5. E

    Terminate the EC2 instances and redeploy them to ensure the threats are removed.

Show answer and explanation

Correct answers: A, B, D

Explanation

The combination of AWS WAF, VPC Flow Logs, and AWS Shield Advanced provides a layered security approach to mitigate common threats such as brute force attacks, DDoS, and other suspicious traffic. AWS WAF blocks malicious requests, VPC Flow Logs enable traffic analysis, and AWS Shield Advanced protects against large-scale DDoS attacks. Blocking all inbound traffic using a Network ACL is overly restrictive and infeasible for public-facing applications, and redeploying EC2 instances does not resolve the underlying security issues.

  • A. Correct.

    Correct: Enabling AWS WAF allows you to filter and block suspicious traffic at the Application Load Balancer level, mitigating potential attacks like bot traffic or brute force login attempts.

  • B. Correct.

    Correct: VPC Flow Logs provide visibility into network traffic, helping to identify any unusual or malicious activity on both public and private subnets.

  • C. Incorrect.

    Incorrect: While Network ACLs can help control traffic, blocking all inbound traffic except trusted IPs may disrupt legitimate user access and is not a scalable solution for web applications.

  • D. Correct.

    Correct: AWS Shield Advanced provides enhanced protection against Distributed Denial of Service (DDoS) attacks, which could be the cause of high traffic spikes.

  • E. Incorrect.

    Incorrect: Terminating and redeploying EC2 instances does not address the root cause of the security threats and is not a recommended mitigation strategy.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam