🔥 40% Off Crucial Exams Memberships — This Week Only

3 days, 6 hours remaining!

AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

Your company recently subscribed to AWS Shield Advanced and protected several internet-facing Application Load Balancers (ALBs). As the CloudOps engineer, you must create a recurring audit that answers two questions for management: (1) Which ALBs in the account are still not protected by Shield Advanced? (2) Have any Shield-detected DDoS events occurred on protected resources during the last 30 days? Which combination of AWS services provides the simplest way to supply this information without writing custom code?

  • Create an AWS Config rule to evaluate Shield protection and use the AWS/DDoSProtection metrics in Amazon CloudWatch to review recent DDoS incidents.

  • Deploy AWS Firewall Manager Shield policies and rely on its compliance reports, which automatically include past DDoS activity.

  • Query AWS CloudTrail logs with Amazon Athena to list protected resources and to detect DDoS-related API calls.

  • Enable AWS Security Hub; use its Findings dashboard for both Shield coverage gaps and historical DDoS events.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot