Examtopics

AWS Certified Solutions Architect - Associate
  • Topic 1 Question 927

    A company is building an application in the AWS Cloud. The application is hosted on Amazon EC2 instances behind an Application Load Balancer (ALB). The company uses Amazon Route 53 for the DNS.

    The company needs a managed solution with proactive engagement to detect against DDoS attacks.

    Which solution will meet these requirements?

    • Enable AWS Config. Configure an AWS Config managed rule that detects DDoS attacks.

    • Enable AWS WAF on the ALCreate an AWS WAF web ACL with rules to detect and prevent DDoS attacks. Associate the web ACL with the ALB.

    • Store the ALB access logs in an Amazon S3 bucket. Configure Amazon GuardDuty to detect and take automated preventative actions for DDoS attacks.

    • Subscribe to AWS Shield Advanced. Configure hosted zones in Route 53. Add ALB resources as protected resources.


    シャッフルモード