AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A global media company runs a high-traffic application on AWS, using a CloudFront distribution, an Application Load Balancer, and Amazon Route 53. The company has subscribed to AWS Shield Advanced to protect against large-scale DDoS attacks. During a recent security drill, the operations team struggled to manually create effective AWS WAF rules in time to mitigate a simulated, sophisticated Layer 7 attack. The company wants a solution that provides access to specialized expertise to help create and deploy custom mitigations during such an event. What should a solutions architect recommend to meet this requirement?

  • Subscribe to a third-party managed rule set from the AWS Marketplace for AWS WAF to block sophisticated attacks.

  • Contact the AWS Shield Response Team (SRT) to get assistance in analyzing the attack pattern and creating custom AWS WAF rules.

  • Enable proactive engagement in the Shield Advanced settings to have the SRT automatically apply custom WAF rules.

  • Create an AWS Lambda function triggered by Amazon GuardDuty findings to automatically update the WAF ACLs.

AWS Certified Solutions Architect Professional SAP-C02
Design for New Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot