Question 1 · choose 3
A company with Enterprise Support protects its CloudFront distributions and Application Load Balancers with AWS Shield Advanced. Before the next peak season it wants two things in place: the Shield Response Team (SRT) must be able to review AWS WAF logs and apply mitigations in the account during an attack, and the SRT must contact the company's on-call team directly when an attack affects the health of a protected application. Which steps should the company take? (Choose THREE.)
- AAuthorize the SRT with a role that has the AWSShieldDRTAccessPolicy managed policy
- BGrant the SRT access to the S3 bucket that stores the AWS WAF web ACL logs
- CSubscribe the distributions and load balancers to AWS Shield Standard protection
- DAssociate an Amazon Route 53 health check with each protected resource
- ECreate an AWS Firewall Manager Shield Advanced policy that covers the account
- FTurn on proactive engagement and enter the on-call contacts
Show the answer and why
AAuthorize the SRT with a role that has the AWSShieldDRTAccessPolicy managed policy
Correct
This role lets the SRT make Shield Advanced and AWS WAF API calls on the company's behalf and read its AWS WAF logs.
BGrant the SRT access to the S3 bucket that stores the AWS WAF web ACL logs
Incorrect
Not needed: the SRT gains access to AWS WAF web ACL logs with the account access. Bucket access is only for other data, such as load balancer logs.
CSubscribe the distributions and load balancers to AWS Shield Standard protection
Incorrect
Shield Standard protects all AWS customers automatically at no extra charge; there is nothing to subscribe to, and it adds no SRT support.
DAssociate an Amazon Route 53 health check with each protected resource
Correct
Proactive engagement is available only for protections that have an associated health check; the SRT uses its status to decide whether to engage.
ECreate an AWS Firewall Manager Shield Advanced policy that covers the account
Incorrect
Firewall Manager applies Shield Advanced protections across accounts and resources. It neither authorizes the SRT nor sets up proactive engagement.
FTurn on proactive engagement and enter the on-call contacts
Correct
With proactive engagement, the SRT contacts the people listed when a protected resource's availability is affected.
SRT help has two separate switches: account access through the DRT role, and proactive engagement, which depends on health checks and contacts. Both require Business or Enterprise Support.
AWS documentation