Multiple Choice
As a part of building large applications in the AWS Cloud, the Solutions Architect is required to implement perimeter security protection. Applications running on AWS have the following endpoints: Application Load Balancer Amazon API Gateway regional endpoint Elastic IP address-based EC2 instances. Amazon S3 hosted websites. Classic Load Balancer The Solutions Architect must design a solution to protect all of the listed web front ends and provide the following security capabilities: DDoS protection SQL injection protection IP address whitelist/blacklist HTTP flood protection Bad bot scraper protection How should the Solutions Architect design the solution?
A) Deploy AWS WAF and AWS Shield Advanced on all web endpoints. Add AWS WAF rules to enforce the company's requirements.
B) Deploy Amazon CloudFront in front of all the endpoints. The CloudFront distribution provides perimeter protection. Add AWS Lambda-based automation to provide additional security.
C) Deploy Amazon CloudFront in front of all the endpoints. Deploy AWS WAF and AWS Shield Advanced. Add AWS WAF rules to enforce the company's requirements. Use AWS Lambda to automate and enhance the security posture.
D) Secure the endpoints by using network ACLs and security groups and adding rules to enforce the company's requirements. Use AWS Lambda to automatically update the rules.
Correct Answer:

Verified
Correct Answer:
Verified
Q802: <img src="https://d2lvgg3v3hfg70.cloudfront.net/C1091/.jpg" alt=" An organization has
Q803: A company uses Amazon S3 to store
Q804: A large global financial services company has
Q805: Does Autoscaling automatically assign tags to resources?<br>A)
Q806: IAM users do not have permission to
Q808: A company is planning to migrate an
Q809: You are designing an intrusion detection prevention
Q810: In the context of policies and permissions
Q811: AWS _supports_ environments as one of the
Q812: A company wants to migrate its corporate