A website runs on EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). An AWS WAF web ACL is associated with the ALB. The site is being targeted by application-layer attacks that cause sudden large traffic increases. WAF access logs show attacks originate from many different IP addresses. Which mitigation requires the LEAST operational overhead?
Choose an answer
Tap an option to check your answer.
Correct answer: Deploy AWS Shield Advanced in addition to AWS WAF and add the ALB as a protected resource..
Why this is the answer
Deploying AWS Shield Advanced is the most effective and operationally least burdensome solution. Shield Advanced provides enhanced DDoS protection, including automatic detection and mitigation of sophisticated application-layer attacks, and integrates seamlessly with AWS WAF. It offers 24/7 DDoS response team support and advanced metrics, significantly reducing the need for manual intervention during large-scale attacks. The other options involve more operational overhead or are less effective. CloudWatch alarms with Lambda functions to update WAF rules or route tables require custom development, maintenance, and may not scale efficiently against distributed attacks from many IPs. Analyzing logs to deny traffic by country via Route 53 is reactive, can block legitimate users, and is ineffective against attacks originating from diverse locations.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed