SCS-C02 exam dumps

SCS-C02 practice question 190 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 190

Single answer

An organization is using AWS to host its web application and has implemented AWS WAF (Web Application Firewall) to protect against common web exploits. The security team notices that certain IP addresses are repeatedly attempting to exploit vulnerabilities in the application. They decide to block these IP addresses for 24 hours. Which AWS WAF rule configuration should they use to implement this requirement?

  1. A

    Create a rate-based rule to block IP addresses exceeding a specific request threshold and set the action to 'Block'.

  2. B

    Create an IP set, add the malicious IP addresses to the set, and associate it with a rule configured to 'Block'.

  3. C

    Enable AWS Shield Advanced to automatically block malicious IP addresses.

  4. D

    Use a string match condition to filter requests containing malicious payloads and set the action to 'Block'.

Show answer and explanation

Correct answer: B

Explanation

To block specific IP addresses for a predefined duration, the correct approach is to create an IP set in AWS WAF, add the malicious IP addresses to the set, and associate it with a rule configured to 'Block'. This allows precise control over blocking rules and the ability to apply them for a specific time duration, such as 24 hours. Other options address different use cases, such as rate limiting or payload analysis, but do not directly achieve the given requirement.

  • A. Incorrect.

    Rate-based rules are used to block IP addresses that exceed a request threshold within a time window, not for blocking specific IPs. This option does not meet the requirement to block certain IPs explicitly for 24 hours.

  • B. Correct.

    Creating an IP set and associating it with a rule configured to 'Block' is the correct approach to explicitly block specific IP addresses. AWS WAF allows you to specify the duration for which a rule applies, such as 24 hours.

  • C. Incorrect.

    AWS Shield Advanced is used for DDoS protection, but it does not directly provide a way to block specific IP addresses in WAF. This option is not applicable to the scenario.

  • D. Incorrect.

    A string match condition is used to filter requests based on specific patterns in the request payload or headers, not for blocking specific IP addresses. This option is not relevant to the requirement.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam