SCS-C02 exam dumps

SCS-C02 practice question 192 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 192

Select 3

An e-commerce company is using an application hosted behind an Application Load Balancer (ALB) and distributed globally using Amazon CloudFront. The company wants to protect its application from SQL injection attacks, DDoS attacks, and ensure DNS-level security. Which combination of AWS services and configurations should the company implement to achieve this goal?

  1. A

    Configure AWS WAF with a rule to block SQL injection attacks and associate it with both the ALB and CloudFront distribution.

  2. B

    Enable AWS Shield Advanced to protect against application-layer DDoS attacks and associate it with the ALB.

  3. C

    Use Route 53 with DNSSEC enabled to ensure DNS-level security for the application.

  4. D

    Implement a CloudFront Origin Access Control (OAC) to restrict access to the ALB from CloudFront only.

  5. E

    Enable ALB access logs to monitor incoming traffic for potential threats.

Show answer and explanation

Correct answers: A, B, C

Explanation

To protect the application comprehensively, the company needs to address multiple layers of security threats. AWS WAF protects against application-layer vulnerabilities such as SQL injection, AWS Shield Advanced safeguards against DDoS attacks, and Route 53 with DNSSEC ensures DNS-level security. While additional configurations like OAC and access logs improve security posture, they do not directly mitigate the required specific threats in the scenario.

  • A. Correct.

    Correct: AWS WAF allows you to create rules to block specific types of attacks, such as SQL injection. Associating WAF with both the ALB and CloudFront ensures protection at both the regional and edge levels.

  • B. Correct.

    Correct: AWS Shield Advanced provides protection against DDoS attacks, including application-layer attacks, when associated with the ALB. This ensures enhanced security against larger-scale attacks.

  • C. Correct.

    Correct: Enabling DNSSEC on Route 53 provides DNS-level security, which prevents DNS spoofing and man-in-the-middle attacks.

  • D. Incorrect.

    Incorrect: While Origin Access Control (OAC) improves security by restricting direct access to the ALB from the internet, it does not specifically address SQL injection, DDoS, or DNS-level security.

  • E. Incorrect.

    Incorrect: ALB access logs are useful for monitoring and identifying potential threats but do not actively protect against SQL injection, DDoS, or DNS-related attacks.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam