As a part of building large applications in the AWS Cloud, the Solutions Architect is required to implement perimeter security protection. Applications running on AWS have the following endpoints: Application Load Balancer Amazon API Gateway regional endpoint Elastic IP address-based EC2 instances. Amazon S3 hosted websites. Classic Load Balancer The Solutions Architect must design a solution to protect all of the listed web front ends and provide the following security capabilities: DDoS protection SQL injection protection IP address whitelist/blacklist HTTP flood protection Bad bot scraper protection How should the Solutions Architect design the solution?
A) Deploy AWS WAF and AWS Shield Advanced on all web endpoints. Add AWS WAF rules to enforce the company's requirements.
B) Deploy Amazon CloudFront in front of all the endpoints. The CloudFront distribution provides perimeter protection. Add AWS Lambda-based automation to provide additional security.
C) Deploy Amazon CloudFront in front of all the endpoints. Deploy AWS WAF and AWS Shield Advanced. Add AWS WAF rules to enforce the company's requirements. Use AWS Lambda to automate and enhance the security posture.
D) Secure the endpoints by using network ACLs and security groups and adding rules to enforce the company's requirements. Use AWS Lambda to automatically update the rules.
Correct Answer:
Verified
Q838: You are designing a social media site
Q839: A company that runs applications on AWS
Q840: A company manages hundreds of AWS accounts
Q841: A company runs an application that gives
Q842: A company built an ecommerce website on
Q844: A group of Amazon EC2 instances have
Q845: You are running a news website in
Q846: A scientific company needs to process text
Q847: If I write the below command, what
Q848: A financial company with multiple departments wants
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents