SCS-C02 exam dumps

SCS-C02 practice question 195 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 195

Select 2

Your company hosts a web application behind an Application Load Balancer (ALB) deployed with Amazon CloudFront. The application is experiencing a significant increase in malicious traffic, including SQL injection and cross-site scripting (XSS) attacks. You need to implement a solution to mitigate these attacks while ensuring legitimate traffic is not disrupted. Which combination of actions should you take?

  1. A

    Configure an AWS WAF web ACL with managed rule groups to block SQL injection and XSS.

  2. B

    Enable AWS Shield Advanced to provide DDoS protection for the CloudFront distribution.

  3. C

    Configure geolocation-based blocking in Amazon Route 53 to deny traffic from specific regions.

  4. D

    Enable CloudFront's Field-Level Encryption to protect sensitive data in transit.

  5. E

    Add a custom rule in AWS WAF to block traffic from specific IP addresses identified as malicious.

Show answer and explanation

Correct answers: A, E

Explanation

To mitigate SQL injection and XSS attacks, AWS WAF is the best tool because it is specifically designed to provide web application protection. A web ACL configured with managed rule groups can block common attack patterns, while custom rules allow fine-tuning to block specific malicious IP addresses. Other options, such as AWS Shield Advanced or CloudFront's Field-Level Encryption, address different security concerns and do not directly address the issue described in the scenario.

  • A. Correct.

    This is a correct answer. AWS WAF web ACLs with managed rule groups can effectively block common attack patterns like SQL injection and XSS without impacting legitimate traffic.

  • B. Incorrect.

    While AWS Shield Advanced provides DDoS protection, it is not specifically designed to address SQL injection or XSS attacks. This option is unrelated to the problem described.

  • C. Incorrect.

    Geolocation-based blocking in Amazon Route 53 helps restrict traffic from specific regions, but it does not directly address SQL injection or XSS attacks. This option is not relevant to the scenario.

  • D. Incorrect.

    Field-Level Encryption in CloudFront is used to encrypt sensitive fields in HTTP requests. While useful for securing data, it does not mitigate SQL injection or XSS attacks.

  • E. Correct.

    This is a correct answer. Adding custom rules in AWS WAF to block traffic from malicious IP addresses can help mitigate targeted threats from known bad actors.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam