SCS-C02 exam dumps

SCS-C02 practice question 4 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 4

Select 3

Your organization has deployed a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application stores logs in Amazon S3 and uses AWS WAF to monitor and block malicious traffic. Recently, your security team detected a spike in suspicious activity, including SQL injection attempts. Which steps should you take to investigate and mitigate this threat?

  1. A

    Enable AWS WAF logging and analyze the logs for malicious patterns.

  2. B

    Use Amazon GuardDuty to analyze VPC flow logs and identify suspicious IP addresses.

  3. C

    Enable Amazon Macie to classify sensitive data in Amazon S3 and monitor data access patterns.

  4. D

    Deploy an AWS Config rule to assess the security configuration of the EC2 instances.

  5. E

    Create new AWS WAF rules to block specific IP addresses identified in the analysis.

Show answer and explanation

Correct answers: A, B, E

Explanation

To investigate and mitigate the SQL injection threat, you should focus on tools and actions that help identify the malicious traffic source and block it. AWS WAF logging provides insights into the nature of the attack, while Amazon GuardDuty can identify suspicious IP addresses through flow log analysis. Finally, creating new WAF rules to block identified malicious IPs helps mitigate the attack. Other options, like Amazon Macie and AWS Config, are less relevant to the specific scenario.

  • A. Correct.

    Enabling AWS WAF logging is a critical step in identifying malicious patterns in incoming traffic. This helps you understand the nature of the threat and customize mitigation strategies.

  • B. Correct.

    Amazon GuardDuty can analyze VPC flow logs to identify suspicious activity such as communication with known malicious IPs. This is highly relevant for investigating the source of the threat.

  • C. Incorrect.

    Amazon Macie focuses on data classification and monitoring S3 access patterns. While useful for identifying data breaches, it is not directly applicable to detecting or mitigating SQL injection attempts.

  • D. Incorrect.

    AWS Config assesses resource configurations for compliance. Although helpful in identifying misconfigurations, it is not directly relevant to analyzing or mitigating SQL injection threats.

  • E. Correct.

    Creating new AWS WAF rules to block malicious IP addresses based on analysis is an effective mitigation step to prevent further SQL injection attempts.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam