SOA-C02 exam dumps

SOA-C02 practice question 166 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 166

Select 2

Your company is hosting a critical web application on AWS. Security requirements mandate that all incoming traffic to the application is monitored and that potential threats like SQL injection and cross-site scripting are mitigated. The solution must also ensure that unauthorized IP addresses are blocked from accessing the application. Which combination of AWS services can you use to meet these requirements?

  1. A

    AWS WAF (Web Application Firewall)

  2. B

    Amazon GuardDuty

  3. C

    AWS Shield

  4. D

    AWS Config

  5. E

    Amazon VPC Security Groups

Show answer and explanation

Correct answers: A, E

Explanation

To meet the requirements of monitoring traffic, mitigating threats like SQL injection and cross-site scripting, and blocking unauthorized IPs, you need both AWS WAF and Amazon VPC Security Groups. AWS WAF protects the application at the HTTP/HTTPS layer, while VPC security groups enforce IP-based access control at the network level. Other services, such as GuardDuty and AWS Shield, address different security concerns but are not directly applicable to the scenario described.

  • A. Correct.

    AWS WAF is specifically designed to monitor HTTP/HTTPS requests and protect web applications from common vulnerabilities like SQL injection and cross-site scripting. It is a key component of the solution.

  • B. Incorrect.

    Amazon GuardDuty is used for threat detection and monitoring AWS account activity but does not directly protect web applications from specific threats like SQL injection or block unauthorized traffic.

  • C. Incorrect.

    AWS Shield provides protection against Distributed Denial of Service (DDoS) attacks but does not handle application-specific threats like SQL injection or block unauthorized IPs.

  • D. Incorrect.

    AWS Config is a compliance and auditing tool to monitor configuration changes. It does not actively protect against application-level threats or unauthorized access.

  • E. Correct.

    Amazon VPC Security Groups can be used to block unauthorized IP addresses at the network level, complementing AWS WAF for a comprehensive security solution.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam