SAP-C02 exam dumps

SAP-C02 practice question 251 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 251

Select 3

An organization is hosting a web application behind an Application Load Balancer (ALB) on AWS. The application has been targeted by frequent DDoS attacks and malicious traffic attempting to exploit vulnerabilities. The organization wants to enhance its security posture by implementing managed security services to detect and mitigate these threats with minimal operational overhead. Which combination of AWS services would address these requirements?

  1. A

    AWS Shield Advanced

  2. B

    AWS WAF

  3. C

    Amazon GuardDuty

  4. D

    AWS CloudTrail

  5. E

    Amazon Inspector

Show answer and explanation

Correct answers: A, B, C

Explanation

To address the organization's requirements, AWS Shield Advanced mitigates DDoS attacks, AWS WAF filters malicious web traffic, and Amazon GuardDuty detects potential threats across AWS resources. This combination provides a comprehensive and managed approach to securing the application. AWS CloudTrail and Amazon Inspector, while valuable for other use cases like auditing and vulnerability assessment, do not directly address the specific needs of DDoS mitigation, web traffic filtering, or threat detection in this scenario.

  • A. Correct.

    AWS Shield Advanced provides enhanced DDoS protection, helping to mitigate large-scale DDoS attacks. It is a managed service specifically designed for protecting applications running on AWS.

  • B. Correct.

    AWS WAF (Web Application Firewall) allows you to filter and block malicious web traffic, including SQL injection and cross-site scripting attacks. It integrates with the Application Load Balancer, making it suitable for protecting the web application.

  • C. Correct.

    Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior. It helps in identifying compromised resources or accounts and serves as a critical component of the security solution.

  • D. Incorrect.

    AWS CloudTrail is a service that provides visibility into account activity by recording API calls and related events. While it supports auditing and compliance, it does not directly mitigate or detect threats like DDoS or web vulnerabilities.

  • E. Incorrect.

    Amazon Inspector is a vulnerability management tool that assesses security and compliance risks in EC2 instances and container images. However, it is not designed to mitigate DDoS or application-layer attacks.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam