ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 248 - CLF-C02 discussion

Report
Export

Which AWS services or tools are designed to protect a workload from SQL injections, cross-site scripting, and DDoS attacks? (Select TWO.)

A.
VPC endpoint
Answers
A.
VPC endpoint
B.
Virtual private gateway
Answers
B.
Virtual private gateway
C.
AWS Shield Standard
Answers
C.
AWS Shield Standard
D.
AWS Config
Answers
D.
AWS Config
E.
AWS WAF
Answers
E.
AWS WAF
Suggested answer: C

Explanation:

AWS Shield Standard and AWS WAF are the AWS services or tools that are designed to protect a workload from SQL injections, cross-site scripting, and DDoS attacks. According to the AWS Shield Developer Guide, "AWS Shield is a managed Distributed Denial of Service (DDoS) protection service that safeguards applications running on AWS. AWS Shield provides always-on detection and automatic inline mitigations that minimize application downtime and latency, so there is no need to engage AWS Support to benefit from DDoS protection."5 According to the AWS WAF Developer Guide, "AWS WAF is a web application firewall that helps protect your web applications or APIs against common web exploits that may affect availability, compromise security, or consume excessive resources. AWS WAF gives you control over how traffic reaches your applications by enabling you to create security rules that block common attack patterns, such as SQL injection or cross-site scripting, and rules that filter out specific traffic patterns you define." VPC endpoint, virtual private gateway, and AWS Config are not designed to protect a workload from these types of attacks.

asked 16/09/2024
DIPESH JAISWAL
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first