AWS Certified Solutions Architect Professional SAP-C02 Practice Question
A global media company runs a high-traffic application on AWS, using a CloudFront distribution, an Application Load Balancer, and Amazon Route 53. The company has subscribed to AWS Shield Advanced to protect against large-scale DDoS attacks. During a recent security drill, the operations team struggled to manually create effective AWS WAF rules in time to mitigate a simulated, sophisticated Layer 7 attack. The company wants a solution that provides access to specialized expertise to help create and deploy custom mitigations during such an event. What should a solutions architect recommend to meet this requirement?
Create an AWS Lambda function triggered by Amazon GuardDuty findings to automatically update the WAF ACLs.
Enable proactive engagement in the Shield Advanced settings to have the SRT automatically apply custom WAF rules.
Subscribe to a third-party managed rule set from the AWS Marketplace for AWS WAF to block sophisticated attacks.
Contact the AWS Shield Response Team (SRT) to get assistance in analyzing the attack pattern and creating custom AWS WAF rules.
The correct answer is to contact the AWS Shield Response Team (SRT). A key benefit of the AWS Shield Advanced subscription is 24/7 access to the SRT, which is a team of AWS experts who specialize in DDoS attack mitigation. During an attack, customers can engage the SRT to help analyze traffic, identify novel attack patterns, and author custom AWS WAF rules to mitigate the threat.
Enabling proactive engagement is incorrect because this feature allows the SRT to contact you if they detect a DDoS event that is impacting the health of your application (as monitored by a Route 53 health check). It is not the mechanism for you to request assistance with writing custom WAF rules. Subscribing to a third-party managed rule set is a good security practice but does not fulfill the requirement for real-time, specialized expertise to handle a novel attack pattern that the rule set may not cover. Automating WAF rule creation with GuardDuty and Lambda is a possible custom solution, but it is not the most direct or effective method provided by the Shield Advanced service for getting expert assistance during a complex attack; the SRT is the purpose-built solution for this scenario.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS Shield Advanced?
Open an interactive chat with Bash
What is the AWS Shield Response Team (SRT)?
Open an interactive chat with Bash
What are Layer 7 attacks and how does AWS WAF help mitigate them?
Open an interactive chat with Bash
AWS Certified Solutions Architect Professional SAP-C02
Design for New Solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .