A company’s web servers on AWS are under a Layer 3 and Layer 4 DDoS attack. Which combination of AWS services and features provides protection in this scenario? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Amazon Route 53, AWS Shield, Network Load Balancer.
Why this is the answer
For Layer 3 and Layer 4 DDoS attacks, a combination of AWS services provides robust protection. AWS Shield Standard is automatically enabled for all AWS customers and provides always-on detection and mitigation for common, most frequent network and transport layer DDoS attacks. For higher-level protection, AWS Shield Advanced offers enhanced detection and mitigation. Amazon Route 53, as a authoritative DNS service, can help by absorbing large volumes of DNS queries during a DDoS attack, preventing it from overwhelming the origin. A Network Load Balancer (NLB) operates at Layer 4 and can distribute incoming traffic across multiple targets, effectively absorbing and distributing attack traffic while maintaining high performance. AWS Certificate Manager (ACM) manages SSL/TLS certificates and is not directly involved in DDoS mitigation. Amazon S3 is object storage and does not protect against network or transport layer attacks on web servers. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, but it does not directly mitigate DDoS attacks.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed