ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 24 - 312-40 discussion

Report
Export

An AWS customer was targeted with a series of HTTPS DDoS attacks, believed to be the largest layer 7 DDoS reported to date. Starting around 10 AM ET on March 1, 2023, more than 15,500 requests per second (rps) began targeting the AWS customer's load balancer. After 10 min, the number of requests increased to 2,50,000 rps.

This attack resembled receiving the entire daily traffic in only 10s. An AWS service was used to sense and mitigate this DDoS attack as well as prevent bad bots and application vulnerabilities. Identify which of the following AWS services can accomplish this.

A.
AWS Amazon Direct Connect
Answers
A.
AWS Amazon Direct Connect
B.
Amazon CloudFront
Answers
B.
Amazon CloudFront
C.
AWS Shield Standard
Answers
C.
AWS Shield Standard
D.
AWS EBS
Answers
D.
AWS EBS
Suggested answer: C

Explanation:

AWS Shield Standard is a managed Distributed Denial of Service (DDoS) protection service that is automatically included with AWS services such as Amazon CloudFront and Elastic Load Balancing (ELB). It provides protection against common, most frequently occurring network and transport layer DDoS attacks.

Here's how AWS Shield Standard works to mitigate such attacks:

1.Automatic Protection: AWS Shield Standard provides always-on detection and automatic inline mitigations that minimize application downtime and latency.

1.Layer 7 Protection: It offers protection against layer 7 DDoS attacks, which target the application layer and are typically more complex than infrastructure attacks.

1.Integration with AWS Services: Shield Standard is integrated with other AWS services like ELB and CloudFront, providing a seamless defense mechanism.

1.Real-Time Visibility: Customers get real-time visibility into attacks via AWS Management Console and CloudWatch.

1.Cost-Effectiveness: There is no additional charge for AWS Shield Standard; it comes included with AWS services, making it a cost-effective solution for DDoS protection.

AWS Shield's official page detailing how it provides managed DDoS protection1.

AWS documentation on best practices for DDoS resiliency, mentioning AWS Shield's role in mitigation2.

asked 18/09/2024
Vikram Panchal
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first