A company exposes a primary API using Amazon API Gateway and Lambda functions, and some customers also access a legacy API running on a single Amazon EC2 instance. The company wants stronger protection to help prevent DoS attacks, scan for vulnerabilities, and block common exploits. What combination of AWS services should the solutions architect use to meet these security requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Use AWS WAF to protect the API Gateway API. Configure Amazon Inspector to analyze the legacy API. Configure Amazon GuardDuty to monitor for malicious attempts to access the APIs..
Why this is the answer
The correct option uses AWS WAF to protect the API Gateway API, as WAF integrates directly with API Gateway to filter malicious traffic like DoS attacks and common exploits. Amazon Inspector is suitable for analyzing the legacy API on the EC2 instance for vulnerabilities, as it can assess EC2 instances. Amazon GuardDuty monitors for malicious activity and unauthorized behavior across AWS accounts, including potential threats to APIs, but it does not block traffic directly. Incorrect options: WAF cannot directly protect an API on a standalone EC2 instance without an Application Load Balancer or CloudFront in front of it. Inspector analyzes for vulnerabilities; it does not protect or block malicious attempts. GuardDuty monitors and detects; it does not block traffic.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed