ANS-C01 exam dumps

ANS-C01 practice question 448 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 448

Select 3

An organization has deployed a highly available web application on AWS using an Application Load Balancer (ALB) and EC2 instances in multiple Availability Zones. The application is experiencing a high number of unauthorized access attempts, such as brute force attacks, and the security team wants to mitigate these threats. Which of the following actions can help address the issue?

  1. A

    Implement AWS WAF rules to block IP addresses associated with suspicious activity.

  2. B

    Use Security Groups to restrict access to the EC2 instances to specific IP ranges.

  3. C

    Enable VPC Flow Logs to monitor and analyze network traffic patterns.

  4. D

    Configure AWS Shield Advanced to automatically block known malicious IP addresses.

  5. E

    Set up a custom Lambda function to terminate EC2 instances under attack.

Show answer and explanation

Correct answers: A, B, D

Explanation

To address common security threats like brute force attacks, leveraging AWS WAF to block suspicious traffic, configuring Security Groups to allow only trusted IP ranges, and using AWS Shield Advanced for DDoS protection are effective strategies. Together, these measures enhance the security posture of your application without compromising its availability. Monitoring tools like VPC Flow Logs are useful for analysis but do not offer direct mitigation capabilities.

  • A. Correct.

    AWS WAF (Web Application Firewall) allows you to define rules to block unwanted traffic, including IP addresses associated with unauthorized access attempts. This is an effective measure to mitigate brute force attacks.

  • B. Correct.

    Configuring Security Groups to allow traffic only from specific IP ranges is a fundamental security best practice that can help limit unauthorized access.

  • C. Incorrect.

    While VPC Flow Logs provide valuable insights into network traffic, they are primarily used for monitoring and auditing rather than directly mitigating security threats.

  • D. Correct.

    AWS Shield Advanced offers protection against DDoS attacks and includes features to block known malicious IP addresses, which helps mitigate unauthorized access attempts.

  • E. Incorrect.

    Terminating EC2 instances under attack with a Lambda function is not a recommended approach to mitigate threats like brute force attacks, as it disrupts application availability and does not address the root cause of the issue.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam