Easy1 markMultiple Choice

AWS SAP-C02 · Question 23 · Domain 2.3: Security Controls

A company is hosting a public-facing web application on EC2 instances behind an Application Load Balancer. They want to protect the application from SQL injection, cross-site scripting (XSS), and volumetric DDoS attacks. Which combination of services provides the MOST comprehensive protection?

Answer options:

A.

Amazon GuardDuty and AWS Network Firewall.

B.

AWS WAF attached to the ALB, and AWS Shield Advanced.

C.

Security groups on the EC2 instances and AWS Shield Standard.

D.

AWS Certificate Manager (ACM) and Amazon Macie.

How to approach this question

Match Layer 7 threats (SQLi) to WAF, and DDoS threats to Shield Advanced.

Full Answer

B.AWS WAF attached to the ALB, and AWS Shield Advanced.✓ Correct
AWS WAF protects web applications from common web exploits like SQL injection and XSS. AWS Shield Advanced provides expanded DDoS attack protection for web applications running on AWS.

Common mistakes

Thinking Network Firewall can inspect HTTP payloads for SQL injection as easily as WAF.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 1

75 questions · hints · full answers · grading

More questions from this exam