Question 1 · choose 1
A retailer is launching a global storefront on Amazon CloudFront with an Application Load Balancer origin. It expects large HTTP request floods during sales events. The company wants help from AWS experts during an attack and protection from the extra AWS charges that an attack could cause by scaling the application. Which solution meets these requirements?
- ARely on AWS Shield Standard and add Amazon GuardDuty to detect attacks against the load balancer and the distribution
- BSubscribe to AWS Shield Advanced for the distribution and load balancer, and add AWS WAF rate-based rules
- CPut AWS Network Firewall in the origin VPC and drop traffic from source IP addresses that send too many requests per second
- DMove the origin to a larger instance type and raise the Auto Scaling group's maximum size for sales events
Show the answer and why
ARely on AWS Shield Standard and add Amazon GuardDuty to detect attacks against the load balancer and the distribution
Incorrect
Shield Standard is automatic and free but gives no access to the Shield Response Team or cost protection. GuardDuty detects threats; it does not block request floods.
BSubscribe to AWS Shield Advanced for the distribution and load balancer, and add AWS WAF rate-based rules
Correct
Shield Advanced adds access to the Shield Response Team and cost protection for scaling charges caused by a DDoS attack, and AWS WAF rate-based rules limit floods of web requests.
CPut AWS Network Firewall in the origin VPC and drop traffic from source IP addresses that send too many requests per second
Incorrect
Network Firewall inspects traffic in a VPC, behind the edge. It offers neither the Shield Response Team nor cost protection.
DMove the origin to a larger instance type and raise the Auto Scaling group's maximum size for sales events
Incorrect
More capacity absorbs some load but increases exactly the attack-driven charges the company wants protection from.
Expert help during an attack and protection from attack-driven charges are Shield Advanced features; WAF rate-based rules handle the request floods.
AWS documentation
- Shield Advanced capabilities and options (opens in a new tab)
- Using rate-based rule statements in AWS WAF (opens in a new tab)
- AWS Shield Standard overview (opens in a new tab)
- What is Amazon GuardDuty? (opens in a new tab)
- What is AWS Network Firewall? (opens in a new tab)
- Resources that you can protect with Shield Advanced (opens in a new tab)