NewsFlare Media’s public ALB is targeted by large volumetric DDoS attacks and by bot traffic performing credential stuffing. They want to reduce scaling costs during attacks and apply managed and rate-based rules with minimal application changes. Which two actions should the security team take? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Place the ALB behind Amazon CloudFront and protect the distribution with AWS Shield Advanced., Associate an AWS WAF web ACL with the CloudFront distribution using AWS Managed Rules and a rate-based rule..
Why this is the answer
Placing the ALB behind CloudFront and protecting it with Shield Advanced is crucial. CloudFront acts as a global CDN, caching content and absorbing a significant portion of volumetric DDoS attacks before they reach the ALB, reducing scaling costs. Shield Advanced provides enhanced DDoS protection, including always-on detection and mitigation, and offers cost protection against scaling charges during attacks. Associating an AWS WAF web ACL with the CloudFront distribution allows for managed rules to block common threats and a rate-based rule to mitigate credential stuffing by limiting requests from suspicious IPs. VPC network ACLs are stateless and difficult to manage for dynamic DDoS attacks. GuardDuty is for threat detection, not direct mitigation of DDoS or credential stuffing at the edge. Shield Standard offers basic protection, and SYN cookies are a lower-level mitigation that doesn't address credential stuffing or provide the comprehensive protection of Shield Advanced and WAF.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed