ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 328 - CLF-C02 discussion

Report
Export

A company is running its application in the AWS Cloud and wants to protect against a DDoS attack.

The company's security team wants near real-time visibility into DDoS attacks.

Which AWS service or traffic filter will meet these requirements with the MOST features for DDoS protection?

A.
AWS Shield Advanced
Answers
A.
AWS Shield Advanced
B.
AWS Shield
Answers
B.
AWS Shield
C.
Amazon GuardDuty
Answers
C.
Amazon GuardDuty
D.
Network ACLs
Answers
D.
Network ACLs
Suggested answer: A

Explanation:

AWS Shield Advanced is a managed Distributed Denial of Service (DDoS) protection service that safeguards applications running on AWS. AWS Shield Advanced provides you with 24x7 access to the AWS DDoS Response Team (DRT) and protection against DDoS attacks of any size or duration. AWS Shield Advanced also provides near real-time visibility into attacks, advanced attack mitigation capabilities, and integration with AWS WAF and AWS Firewall Manager1. AWS Shield is a standard service that provides always-on detection and automatic inline mitigations to minimize application downtime and latency, but it does not offer the same level of features and support as AWS Shield Advanced2. Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior, but it does not provide DDoS protection3. Network ACLs are stateless filters that can be associated with a subnet to control the traffic to and from the subnet, but they are not designed to protect against DDoS attacks

asked 16/09/2024
Leandro Ruwer
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first