SCS-C02 exam dumps

SCS-C02 practice question 193 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 193

Select 3

A media streaming company is using Amazon CloudFront to distribute its content globally. To protect its application from malicious attacks such as SQL injection, cross-site scripting, and DDoS attacks, the company wants to implement additional security measures. Which combination of AWS services and features should the company use to achieve this goal?

  1. A

    Enable AWS WAF on the CloudFront distribution and create rules to block malicious requests.

  2. B

    Use AWS Shield Standard to automatically protect against DDoS attacks.

  3. C

    Configure Amazon Route 53 to block IP addresses from specific geographic locations.

  4. D

    Set up an Elastic Load Balancer to block requests with invalid headers.

  5. E

    Enable Origin Access Control in CloudFront to restrict direct access to the origin servers.

Show answer and explanation

Correct answers: A, B, E

Explanation

To secure the media streaming application distributed via Amazon CloudFront, the company can use AWS WAF to block malicious requests and AWS Shield Standard to protect against DDoS attacks. Additionally, enabling Origin Access Control ensures that content cannot be accessed directly from the origin servers, improving security. While Amazon Route 53 and Elastic Load Balancers are important components of AWS architecture, they do not directly address the described security requirements.

  • A. Correct.

    Correct. AWS WAF can be used with CloudFront to create rules that block malicious requests, such as SQL injection or cross-site scripting attempts.

  • B. Correct.

    Correct. AWS Shield Standard provides automatic protection against DDoS attacks and is included at no extra cost with CloudFront.

  • C. Incorrect.

    Incorrect. Amazon Route 53 does not natively block IP addresses but can be used for DNS-based routing and geo-restriction when integrated with other services like WAF.

  • D. Incorrect.

    Incorrect. Elastic Load Balancers do not provide built-in functionality to block requests based on the content of HTTP headers. This would typically be handled by AWS WAF or application logic.

  • E. Correct.

    Correct. Origin Access Control (OAC) in CloudFront allows you to restrict direct access to the origin servers, ensuring that all requests go through CloudFront for additional security.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam