From Application Load Balancer access logs, a security engineer observes excessive requests from a single IP address. How can the engineer throttle requests from that IP without completely blocking it?
Choose an answer
Tap an option to check your answer.
Correct answer: Use AWS WAF to add a rate-based rule..
Why this is the answer
AWS WAF (Web Application Firewall) with a rate-based rule is the most effective solution. A rate-based rule allows you to specify a threshold for the number of requests allowed from a single IP address within a five-minute period. If the request rate exceeds this threshold, subsequent requests from that IP can be blocked or throttled for a configurable duration, without completely denying all access. An Application Load Balancer rule cannot directly throttle requests based on rate; it primarily routes traffic. AWS Shield primarily provides DDoS protection and does not offer granular, IP-based rate limiting for specific application traffic. Amazon Route 53 GeoLocation routing directs traffic based on the user's geographic location, not on request rates from a specific IP.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed