AWS Certified Solutions Architect Professional SAP-C02 Practice Question

Your organization runs a high-traffic e-commerce platform on Amazon EC2 instances behind Application Load Balancers (ALB) in two AWS Regions. During a recent incident, a large HTTP request flood saturated the ALBs, forced excessive scale-out, and increased latency for legitimate users. The security team now requires a managed, layered defense that (1) blocks malicious layer-7 traffic as close to the users as possible, (2) automatically detects and mitigates future volumetric HTTP floods with minimal operator effort, (3) maintains low-latency delivery for customers worldwide, and (4) provides real-time metrics and notifications whenever mitigations occur.

Which solution will BEST meet these requirements?

  • Associate an AWS WAF web ACL containing rate-based rules and AWS Managed Rules directly with each ALB, rely on AWS Shield Standard for DDoS protection, and configure CloudWatch alarms on ALB metrics to send Amazon SNS notifications.

  • Insert AWS Network Firewall endpoints in a dedicated security VPC, route all inbound internet traffic through the firewall, create stateless rule groups to drop excessive HTTP requests, and use CloudWatch metrics from Network Firewall for alerting.

  • Create an AWS Global Accelerator that points to Network Load Balancer endpoints in each Region, attach an AWS WAF web ACL with managed rule sets to the accelerator, enable AWS Shield Advanced on the accelerator, and configure CloudWatch alarms for notifications.

  • Put an Amazon CloudFront distribution in front of the ALBs, subscribe the account to AWS Shield Advanced, associate an AWS WAF web ACL (using AWS Managed Rules and rate-based rules) with the CloudFront distribution, enable automatic application-layer DDoS mitigation, and configure CloudWatch alarms on Shield metrics that publish to SNS.

AWS Certified Solutions Architect Professional SAP-C02
Design for New Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot