SCS-C02 exam dumps

SCS-C02 practice question 473 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 473

Single answer

A company has deployed a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The company’s security team has identified that attackers are attempting SQL injection attacks on the application. As a security engineer, you must recommend a solution to mitigate this threat. Which of the following options is the MOST effective way to protect the application from such attacks?

  1. A

    Enable AWS WAF on the Application Load Balancer and configure a managed rule group for SQL injection protection.

  2. B

    Use Amazon Inspector to scan the EC2 instances for vulnerabilities and remediate findings.

  3. C

    Configure a Network ACL to block traffic from IP addresses suspected of malicious activity.

  4. D

    Enable GuardDuty to monitor malicious activity and implement auto-remediation.

Show answer and explanation

Correct answer: A

Explanation

The most effective solution to mitigate SQL injection attacks in this scenario is to use AWS WAF with a managed rule group for SQL injection protection. AWS WAF can inspect and block malicious requests at the Application Load Balancer layer, providing comprehensive protection for the web application. Other options, like Amazon Inspector and GuardDuty, are useful for vulnerability assessment and threat monitoring but do not provide real-time defense against SQL injection attacks.

  • A. Correct.

    This is the correct answer. AWS WAF can be directly associated with the Application Load Balancer (ALB) to block SQL injection attacks using pre-configured managed rule groups for SQL injection protection.

  • B. Incorrect.

    This option is incorrect. While Amazon Inspector can help in identifying vulnerabilities in EC2 instances, it does not directly mitigate or block real-time SQL injection attacks.

  • C. Incorrect.

    This option is partially correct but not the most effective. Network ACLs can restrict traffic based on IP addresses but cannot detect or block SQL injection attacks, which require deeper inspection of HTTP requests.

  • D. Incorrect.

    This option is incorrect. GuardDuty is a threat detection service that provides monitoring and alerts but does not actively mitigate attacks like SQL injection in real time.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam