SCS-C02 exam dumps

SCS-C02 practice question 396 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 396

Select 4

An organization has deployed its web application on Amazon EC2 instances behind an Application Load Balancer (ALB). They notice an increasing number of unauthorized access attempts in their logs. To strengthen the security of the web application, they decide to implement AWS Web Application Firewall (WAF). Which rules or features of AWS WAF should the organization configure to address this issue effectively?

  1. A

    Use AWS Managed Rules for Common Vulnerabilities and Exposures (CVE).

  2. B

    Enable a rate-based rule to block IP addresses with high request rates.

  3. C

    Configure AWS WAF to block requests originating from specific IP addresses using an IP set.

  4. D

    Use AWS Shield Advanced to protect against Distributed Denial of Service (DDoS) attacks.

  5. E

    Create a regex pattern set to block requests containing specific malicious payloads.

Show answer and explanation

Correct answers: A, B, C, E

Explanation

AWS WAF provides various rules and features to protect web applications from unauthorized access and malicious traffic. Using AWS Managed Rules for CVE ensures protection against common vulnerabilities, while rate-based rules help mitigate brute-force or DoS attempts. IP sets allow blocking specific malicious IPs, and regex patterns can block requests with malicious payloads. However, AWS Shield Advanced is a separate service for DDoS protection and not directly related to the WAF-specific use case described in this scenario.

  • A. Correct.

    This is correct. AWS Managed Rules for Common Vulnerabilities and Exposures (CVE) can block known attack patterns and provide a baseline level of protection against common threats.

  • B. Correct.

    This is correct. A rate-based rule can mitigate brute-force or DoS attempts originating from specific IP addresses by blocking excessive traffic.

  • C. Correct.

    This is correct. IP sets allow you to block or allow requests from specific IP addresses or ranges, which is useful if you have identified malicious IPs.

  • D. Incorrect.

    This is incorrect. While AWS Shield Advanced is a powerful DDoS protection feature, it is not a direct feature of AWS WAF and does not address unauthorized access attempts specifically.

  • E. Correct.

    This is correct. Regex pattern sets can be used to detect and block requests with malicious payloads, such as SQL injection or cross-site scripting attempts.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam