AWS Certified Solutions Architect Professional SAP-C02 Practice Question

Your security operations team has detected a surge of automated credential-stuffing attempts against the /login endpoint of your global e-commerce site. The application is fronted by an Amazon CloudFront distribution that routes dynamic traffic to an Application Load Balancer in us-east-1.

Business stakeholders require that you:

  • Detect and automatically block credential-stuffing and brute-force login attempts while minimizing false positives for legitimate customers.
  • Keep protections up-to-date without analysts having to maintain custom rule logic.
  • Deploy the mitigation quickly without modifying application code, TLS certificates, DNS records, or the existing network architecture.

Which solution will BEST meet these requirements?

  • Attach an AWS WAF web ACL to the CloudFront distribution and add the AWS Bot Control managed rule group in targeted-inspection mode, overriding rule actions to CAPTCHA for all detections.

  • Create a custom AWS WAF rate-based rule that blocks any source IP sending more than 100 POST requests to /login within five minutes.

  • Enable AWS Shield Advanced on the CloudFront distribution and configure proactive engagement with the AWS Shield Response Team to stop credential-stuffing attacks.

  • Attach an AWS WAF web ACL to the CloudFront distribution and add the AWSManagedRulesATPRuleSet managed rule group, specifying the login path and credential fields, with the rule group action set to Block.

AWS Certified Solutions Architect Professional SAP-C02
Design for New Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot